carvel-dev / carvel-dev/kbld

Add support for hermetic mode, where registry is never contacted and all images expected to be preResolved

Open
#195 1 comment 0 reactions 0 assignees View on GitHub
carvel accepted enhancement priority/unprioritized-backlog
Dominant language
Go
Stars
329
Forks
52
PR merge metrics
No merged PRs in 30d

Description

**Describe the problem/challenge you have**

when used together with `ytt`, `kbld` must be applied after templating is done , which often happens just before the deploy. If some images are missing from the imageLock file, then they are implicitly resolved, leading potentially to a non reproducible deploys and arguably defeating the purpose of this tool.

**Describe the solution you'd like**
Add a new flag `--hermetic=true`, which makes `kbld` fail when it encounters not preresolved image.

---
Vote on this request

This is an invitation to the community to vote on issues, to help us prioritize our backlog. Use the "smiley face" up to the right of this comment to vote.

👍 "I would like to see this addressed as soon as possible"
👎 "There are other more important things to focus on right now"

We are also happy to receive and review Pull Requests if you want to help working on this issue.

Contributor guide

Open the contributing guide

Research direction

The issue names no files or tests; start at the CLI flag handling and the imageLock/preResolved image-resolution path. Done means a hermetic flag prevents registry contact and fails when an expected image is missing from the imageLock, while preResolved images continue to work.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
cli, devops
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.