carvel-dev / carvel-dev/kapp-controller

Introduce CEL based validation in App spec for SA and Cluster

Open
#1,380 3 comments 10 reactions 1 assignee Claimed by @prembhaskal View on GitHub
carvel-accepted enhancement
Dominant language
Go
Stars
323
Forks
127
Avg merge
2d 16h
Merged PRs (30d)
4

Description

**Describe the problem/challenge you have**

Tried creating an App CR with no service account or cluster specified. The resource got created, but reconcile errored stating:
`Reconcile failed: Preparing kapp: Expected service account or cluster specified`. The [documentation](https://carvel.dev/kapp-controller/docs/v0.48.x/app-spec/) states that both of them are optional fields, hence as a user I'm unaware that one of them needs to be specified.

**Describe the solution you'd like**

Based on the conversation [here](https://kubernetes.slack.com/archives/CH8KCCKA5/p1698351828408469?thread_ts=1698350082.438849&cid=CH8KCCKA5), it does make sense to either have the user specify the target cluster where App CR needs to be installed, or the sa which needs to be used to install it in the same cluster. However, running this validation after the resource is created is not necessary (refer: https://github.com/carvel-dev/kapp-controller/blob/5b1294bdf60107c9ff20b79e519abaefd71c4682/pkg/kubeconfig/kubeconfig.go#L75). This can also be done on the admission control level before an App CR is created.

Solution: Add CEL based validation to ensure that one of them are specified.

**Anything else you would like to add:**

None

---
Vote on this request

This is an invitation to the community to vote on issues, to help us prioritize our backlog. Use the "smiley face" up to the right of this comment to vote.

👍 "I would like to see this addressed as soon as possible"
👎 "There are other more important things to focus on right now"

We are also happy to receive and review Pull Requests if you want to help working on this issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.