Repository navigation
fix: copy ConfigMap binaryData to primary - #1977
Open
bryantvolk wants to merge 1 commit into
Open
bryantvolk wants to merge 1 commit into
bryantvolk wants to merge 1 commit into
Conversation
CreatePrimaryConfigs built the primary ConfigMap from data alone, so keys stored in binaryData (for example a PKCS12 trust bundle) were missing from the primary pods. The primary copy now carries binaryData too. Copying never starts a canary analysis. Change detection for binaryData is opt-in through the new -enable-config-binary-data-tracking flag (Helm value configTracking.binaryData), so upgrading does not start unwanted canary runs. The ConfigMap checksum stays byte-identical to the previous checksum of data unless the flag is on and binaryData is present. In that case binaryData is hashed as bytes, so distinct invalid UTF-8 values cannot collide. Fixes fluxcd#1774 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Bryant Volk <bryant.volk@nominal.io>
bryantvolk
force-pushed
the
fix/configmap-binary-data
branch
from
September 30, 2026 17:19
97d656f to
6ad80ad
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1774
Why
CreatePrimaryConfigsbuilds the-primaryConfigMap fromdataonly. Keys inbinaryDataare missing from primary pods. For example, a trust bundle shipped as PKCS12 inbinaryDataexists in canary pods but not in primary pods. The checksum also readsdataonly, so an edit tobinaryDataalone never starts a canary analysis.This PR always copies
binaryDatato the primary ConfigMap. Change detection forbinaryDatais opt-in through a new flag, as requested in the review of #1781.Scope
CreatePrimaryConfigscopiesBinaryData. This is not gated, because a copy never starts a canary analysis.ConfigTracker.TrackBinaryDatafield, set by the-enable-config-binary-data-trackingflag (defaultfalse) and the Helm valueconfigTracking.binaryData.configMapChecksumreturnschecksum(config.Data), the same value as before, unless tracking is on andbinaryDatais not empty. In that case it hashesdataandbinaryDatatogether, withbinaryDataas[]byte.charts/flagger/README.mdand the config tracking section ofdocs/gitbook/usage/how-it-works.md.Tradeoffs
datatomap[string][]bytebefore hashing, which changes the checksum of every ConfigMap even with the flag off. That starts the canary runs the flag exists to prevent. This PR keeps existing checksums unchanged. Turning the flag on only starts runs for ConfigMaps that containbinaryData.binaryDatais broken in every configuration.Blast Radius
Every ConfigMap that Flagger tracks. After upgrade, the next promotion copies
binaryDatainto primary ConfigMaps that lacked it. No checksum changes, so no canary analysis starts on upgrade. Turning the flag on or off starts one analysis for each ConfigMap that containsbinaryData, because its checksum changes.Verification
TestConfigTracker_ConfigMapBinaryDatafails on the old behavior:The test also fails for each of these changes, applied one at a time:
The copy is gated on the flag.
The checksum ignores the flag, or drops the empty
binaryDatacheck.binaryDatais hashed as strings, so0xffand0xfecollide.datais left out of the hash whenbinaryDatais present.datais hashed asmap[string][]byte, as in Feat: support tracking binaryData in CM #1929.go test ./...passes.CGO_ENABLED=0 go build ./cmd/flaggerpasses forGOOS=linuxandGOOS=darwin.helm lint charts/flaggerpasses.helm templateemits-enable-config-binary-data-tracking=trueonly with--set configTracking.binaryData=true, and renders without error with--set configTracking=null.🤖 Generated with Claude Code