Skip to content

Refresh Workbench snapshot baselines and mount PAM files in sorted order - #955

Open
khusmann wants to merge 2 commits into
mainfrom
refresh-workbench-snapshots
Open

khusmann wants to merge 2 commits into
mainfrom
refresh-workbench-snapshots

Conversation

@khusmann

@khusmann khusmann commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Part of #952 (second item: refresh the baselines).

With the generator repaired in #950, this regenerates the Workbench snapshot baselines. It also fixes a nondeterministic render that surfaced while doing so, because a baseline that differs from run to run can't be compared.

Baseline refresh

The .lock files dated from roughly Workbench 2023.06.0. They still contained the graphite exporter, r-session-complete and the rstudio/rstudio-workbench:ubuntu2204-2023.06.0 image, and lacked positron.conf, metrics-port and the sessions init container. They had also been hand-patched while the generator was broken, so they didn't match any chart version that ever shipped.

All 16 baselines are regenerated with just snapshot-rsw && just snapshot-rsw-lock (+8,168 / −3,838 lines). The diff is large but mechanical. It's the current chart's output for each lint/ values file, and there's nothing to review line by line. snapshot/ is in .helmignore, so this commit on its own needs no version bump.

Nondeterministic PAM mount order

_helpers.tpl built the rstudio-pam volume mounts from keys .Values.config.pam. Sprig's keys returns keys in Go map order, which is randomized, so when more than one PAM file is configured, the order of the mounts changes between renders. complex-values.yaml has two PAM files, and its snapshot flipped between two consecutive runs.

This affects users too, not just the tests. A different mount order is a different pod spec, so a helm upgrade with no configuration change can restart Workbench pods for anyone with two or more config.pam files.

The fix pipes the keys through sortAlpha. Workbench goes to 0.22.4, with a NEWS entry.

Verification

  • A new unit test (should mount pam files in sorted order…) sets 12 PAM files in scrambled order and asserts the mounts by position.
    • Twelve keys, not five: with five, the unsorted template came out sorted by chance in 5 of 20 renders; with 12, in 0 of 20.
    • With the fix reverted, the test failed 3 of 3 runs. With the fix, it passes.
  • just snapshot-rsw run three times gives byte-identical output, and just snapshot-rsw-diff reports "All snapshots match their .lock baselines".
  • make lint passes for all 15 lint/ values files, and just test rstudio-workbench passes all 174 tests.
  • Baselines were generated with Helm v4.2.4.

Follow-up

The third item in #952 is running the snapshot diff in CI. That can go next, now that the baselines are current and deterministic.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The deterministic rendering fix is correct, tested, documented, versioned, and reflected consistently in the refreshed baselines.

Review effort: Balanced
Findings: None

What changed in this PR

Refreshes Workbench snapshot baselines for issue #952 and makes PAM volume mounts deterministic.

Changes:

  • Sorts PAM filenames before rendering volume mounts.
  • Adds regression coverage for stable mount ordering.
  • Bumps the chart to 0.22.4 and regenerates all 16 snapshots.
File Description
charts/​rstudio-workbench/​templates/​_helpers.tpl Sorts PAM mount keys.
charts/​rstudio-workbench/​tests/​deployment_test.yaml Tests deterministic PAM ordering.
charts/​rstudio-workbench/​Chart.yaml Bumps chart version.
charts/​rstudio-workbench/​NEWS.md Documents the fix.
charts/​rstudio-workbench/​README.md Updates generated version references.
charts/​rstudio-workbench/​snapshot/​complex-values.yaml.lock Refreshes complex baseline.
charts/​rstudio-workbench/​snapshot/​default-sa-values.yaml.lock Refreshes default-SA baseline.
charts/​rstudio-workbench/​snapshot/​default.yaml.lock Refreshes default baseline.
charts/​rstudio-workbench/​snapshot/​empty-values.yaml.lock Refreshes empty-values baseline.
charts/​rstudio-workbench/​snapshot/​ingress-values.yaml.lock Refreshes ingress baseline.
charts/​rstudio-workbench/​snapshot/​ingress2-values.yaml.lock Refreshes alternate ingress baseline.
charts/​rstudio-workbench/​snapshot/​launcher-template-values.yaml.lock Refreshes launcher-template baseline.
charts/​rstudio-workbench/​snapshot/​license-file-secret-values.yaml.lock Refreshes secret license-file baseline.
charts/​rstudio-workbench/​snapshot/​license-file-values.yaml.lock Refreshes license-file baseline.
charts/​rstudio-workbench/​snapshot/​license-server-values.yaml.lock Refreshes license-server baseline.
charts/​rstudio-workbench/​snapshot/​license-values.yaml.lock Refreshes license baseline.
charts/​rstudio-workbench/​snapshot/​other-complex-values.yaml.lock Refreshes secondary complex baseline.
charts/​rstudio-workbench/​snapshot/​overrides-values-new.yaml.lock Refreshes newer overrides baseline.
charts/​rstudio-workbench/​snapshot/​overrides-values.yaml.lock Refreshes legacy overrides baseline.
charts/​rstudio-workbench/​snapshot/​simple-profiles-values.yaml.lock Refreshes profile baseline.
charts/​rstudio-workbench/​snapshot/​simple-values.yaml.lock Refreshes simple baseline.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants