Skip to content

fix(adapter): set the Helm managed-fields owner for drift detection - #26

Merged
ssyno merged 1 commit into
mainfrom
fix/adapter-managed-fields-manager
Sep 30, 2026
Merged

ssyno merged 1 commit into
mainfrom
fix/adapter-managed-fields-manager

Conversation

@ssyno

@ssyno ssyno commented Sep 29, 2026 •

Copy link
Copy Markdown

What

SetupHelmReconciler passes ControllerName as the reconciler FieldManager but never sets Helm's package-level kube.ManagedFieldsManager, which action.Diff uses as the field owner for the drift-detection dry-run. Upstream sets it in its own main.go (kube.ManagedFieldsManager = controllerName), which embedding callers such as the agent never run. This does the same thing in the adapter.

Effect today

With driftDetection.mode: warn on any HelmRelease the dry-run is rejected and the release goes Ready=False StateError: "PatchOptions fieldManager: Required value: is required". Reproduced on a dev regional (navy-aura, reloader) through PatchRegionalClusterAppConfig, reverted afterwards. OPS-1256.

Side effect, checked

Without the variable Helm falls back to the binary name, so objects on regionals are currently owned by the field manager qdrant-cloud-agent. After this change Helm applies and the drift dry-run both use helm-controller, the same name upstream uses. That is safe: install and upgrade always run server-side apply with ForceConflicts (internal/action/install.go), and the drift dry-run uses client.ForceOwnership (fluxcd/pkg/ssa/jsondiff), so ownership moves on the next apply without conflicts and identical values produce no drift. Verified the conflict shape with a server-side dry-run as helm-controller over a live release manifest, with and without --force-conflicts. Nothing in the addons or resource-protection charts keys on the manager name.

Checked

go build ./..., go vet ./adapter/, kind e2e green. FOSSA is red on every PR here, the repo has no token for the inherited scan workflow. Re-test on the same regional once the agent picks up the tagged version, expecting a Drifted=True condition and a DriftDetected event without touching Ready.

The adapter passes ControllerName as the reconciler FieldManager but never
sets helm's package-level kube.ManagedFieldsManager, which action.Diff uses
as the field owner for the drift-detection dry-run. Upstream sets it in its
own main, which embedding callers never run. With driftDetection on, the
dry-run fails with 'fieldManager: Required value' and the release goes
Ready=False.
@ssyno
ssyno merged commit 4267604 into main Sep 30, 2026
4 of 5 checks passed
@ssyno
ssyno deleted the fix/adapter-managed-fields-manager branch September 30, 2026 14:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant