feat: roll HyperDX pods on config changes - #273
Conversation
🦋 Changeset detectedLatest commit: fa92f63 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
f7cf6b3 to
fa92f63
Compare
|
Please fix the P1 checksum-test failure before merging. The CI unit-test job reports 5 failed, 252 passed, with all five failures in The hard-coded expected hashes differ from CI's rendered hashes (e.g. baseline config expects Rest of the change looks good: annotation merge precedence is preserved, the Secret checksum is correctly guarded on
|
Summary
Motivation
HyperDX consumes
clickstack-configandclickstack-secretthroughenvFrom. Kubernetes resolves those environment variables when a pod starts, so changing only the ConfigMap or Secret duringhelm upgradeleaves existing HyperDX pods with stale startup configuration unless the Deployment pod template also changes.This follows Helm's documented
include ... | sha256sumrollout pattern. The ConfigMap and Secret manifests now share canonical named renderers with the Deployment checksums, ensuring the hashed content cannot drift from the resources Helm applies.No new values API is needed: these are chart-managed resources with deterministic rollout behavior. Arbitrary template paths or
tplevaluation in user values would be less safe and would not improve this owned-resource case.Backward compatibility
Existing
hyperdx.deployment.annotationsandhyperdx.deployment.podAnnotationsvalues remain merged with the same precedence. The generatedchecksum/clickstack-configandchecksum/clickstack-secretkeys are chart-reserved and override caller values so stale hashes cannot disable rollouts.checksum/clickstack-secretis omitted whenhyperdx.secrets: null, matching Secret rendering andenvFrombehavior. Externally managed Secret changes still require an explicit rollout because Helm cannot hash resources it does not render.The first upgrade containing this change intentionally performs a one-time HyperDX rollout because the generated annotations are added to the pod template.
Tests
helm unittest -f tests/hyperdx-rollout-checksums_test.yaml charts/clickstackhelm unittest charts/clickstack— 31 suites, 257 testshelm lint --strict charts/clickstackgit diff --check