ADORSYS-GIS / ADORSYS-GIS/ai-helm

A release-please bump of a file:// library chart leaves 41 dependents with a stale Chart.lock and breaks chart publishing on main

オープン
#1,089 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Go Template
スター
3
フォーク
1
平均マージ
19時間 24分
マージ済み PR(30日)
80

説明

### Context

Merging the release-please PR #888 (2026-09-02, `15cfbecb`) broke **Publish Charts to OCI** and **Release Helm Charts** on `main`:

```
Error: can't get a valid version for dependency common
```

Mechanism: release-please bumped `charts/common/Chart.yaml` `2.31.4 → 2.31.5` and touched no `Chart.lock`. **41 charts** pin `common` through `repository: file://../common`, and `helm dependency build` — the command both workflows run — refuses to re-resolve a lock whose pinned version no longer exists. `helm dependency update` would; `build` will not, by design.

This is **latent in the pipeline**, not specific to #888: it fires every time release-please bumps a `file://` library chart (`common`, `bjw-template`, …), because nothing regenerates the dependents' locks. It went unnoticed until now because `common` had not been bumped by a release since the locks were introduced. ArgoCD deploys from the OCI path (ADR-0055), so the failure blocks every chart deploy until someone relocks by hand — which is what #1088 does for this instance.

### Acceptance Criteria

1. A `common` (or any `file://` library) version bump on `main` cannot leave a dependent's `Chart.lock` stale. Either:
- (a) release-please's `extra-files` / a post-release job runs `helm dependency update` for every dependent and commits the locks in the same release PR, or
- (b) `publish-charts-oci.yml` and `release-helm-charts.yml` run `helm dependency update` instead of `build` for `file://`-only dependencies, with a CI assertion that the resulting lock matches what is committed (so drift is caught on the PR, not on `main`).
2. A test proves it: bump `common` on a branch without relocking → CI fails **on the PR** with a message naming the stale charts, not on `main` after merge.
3. The fix is recorded in `docs/` next to the ADR-0055 publish path so the next person hitting "can't get a valid version" finds it.

### Out of Scope

The one-off relock for 2.31.5 (#1088). Changing how `common` is versioned.

### Human accountable owner

@stephane-segning

### AI Usage Declaration

- [x] AI-assisted — diagnosed and drafted by Claude Code (Fable 5.1) after merging #888 on the maintainer's instruction; the failure, the 41-lock count and the `build`-vs-`update` behaviour were re-verified by the maintainer before filing.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Read publish-charts-oci.yml and release-helm-charts.yml first, then inspect the dependent charts' Chart.yaml and Chart.lock files and the release-please configuration used by PR #888. Reproduce the stale-lock case by bumping common without relocking. Done means PR CI names every stale dependent, the release or publish path handles file:// dependencies safely, and the ADR-0055-adjacent docs explain the behavior.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github-actions, helm, kubernetes
領域
ci-cd, devops, documentation, release
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
明確に書かれている
初心者へのやさしさ
52/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。