carvel-dev / carvel-dev/kapp-controller
Introduce CEL based validation in App spec for SA and Cluster
- Dominant language
- Go
- Stars
- 323
- Forks
- 127
- Avg merge
- 2d 16h
- Merged PRs (30d)
- 4
Description
**Describe the problem/challenge you have**
Tried creating an App CR with no service account or cluster specified. The resource got created, but reconcile errored stating:
`Reconcile failed: Preparing kapp: Expected service account or cluster specified`. The [documentation](https://carvel.dev/kapp-controller/docs/v0.48.x/app-spec/) states that both of them are optional fields, hence as a user I'm unaware that one of them needs to be specified.
**Describe the solution you'd like**
Based on the conversation [here](https://kubernetes.slack.com/archives/CH8KCCKA5/p1698351828408469?thread_ts=1698350082.438849&cid=CH8KCCKA5), it does make sense to either have the user specify the target cluster where App CR needs to be installed, or the sa which needs to be used to install it in the same cluster. However, running this validation after the resource is created is not necessary (refer: https://github.com/carvel-dev/kapp-controller/blob/5b1294bdf60107c9ff20b79e519abaefd71c4682/pkg/kubeconfig/kubeconfig.go#L75). This can also be done on the admission control level before an App CR is created.
Solution: Add CEL based validation to ensure that one of them are specified.
**Anything else you would like to add:**
None
---
Vote on this request
This is an invitation to the community to vote on issues, to help us prioritize our backlog. Use the "smiley face" up to the right of this comment to vote.
👍 "I would like to see this addressed as soon as possible"
👎 "There are other more important things to focus on right now"
We are also happy to receive and review Pull Requests if you want to help working on this issue.
Contributor guide
Assessment
This issue has not been assessed yet.