Skip to content

feat(components): check the ingress class the chart requests on OpenShift (budctl 0.3.2) - #3

Merged
dittops merged 2 commits into
mainfrom
claude/openshift-ingress-class
Sep 15, 2026
Merged

dittops merged 2 commits into
mainfrom
claude/openshift-ingress-class

Conversation

@dittops

@dittops dittops commented Sep 15, 2026

Copy link
Copy Markdown
Member

Why

On OpenShift, components.ingress checked the Ingress Operator and the default IngressController, but never the class the chart's Ingresses name. The Bud charts default to ingress.className: traefik and ingress.isTraefik: true. An OpenShift install missing the overrides therefore passed this check, while the router turned none of its Ingresses into Routes and the sync failed on Traefik Middleware objects.

Changes

  • OpenShift: compare the rendered Ingresses' class with the cluster's IngressClasses.
    • Missing class → BLOCK.
    • Class served by a controller other than the router (openshift.io/ingress-to-route) → RISK.
    • openshift-default → PASS, and says so.
  • Any cluster: BLOCK when the render contains Traefik objects and the cluster serves no Traefik API. The sync would stop with "no matches for kind"; an ingress-nginx cluster fails the same way.
  • Without a render: the pass names the values to set on OpenShift. If values were given but the chart did not render, it says that instead of "no --values".
  • components.ingress depends on config, so --only components still renders.
  • Remedies use the charts' real key, ingress.className (not global.ingress.className), and the stale "OpenShift has no IngressClass" comment is corrected.
  • After fix(registry): stop requiring registry.cn-hangzhou.aliyuncs.com for HAMi #2 merges, this branch is rebased and gets the budctl 0.3.2 commit (installer pin).

Verification

7 new tests (5 fail on the pre-change code); full suite passes. Against a single-node OpenShift 4.22 cluster with the published bud 1.2.8 chart:

Values Result
none PASS, names ingress.className: openshift-default / ingress.isTraefik: false
infra values.openshift.yaml PASS: requests openshift-default, served by the router
chart defaults BLOCK: 3 Traefik Middlewares the cluster does not serve (the server-side dry run rejects them too)
className: traefik, isTraefik: false BLOCK: IngressClass traefik does not exist (the dry run does not catch this one)

🤖 Generated with Claude Code

Ditto P S and others added 2 commits September 15, 2026 12:14
…hift

components.ingress on OpenShift verified the Ingress Operator and the default
IngressController, and never looked at the class the chart's Ingresses name. The
Bud charts default to ingress.className: traefik and ingress.isTraefik: true, so
an OpenShift install without the overrides passed this check while the router
turned none of its Ingresses into Routes and the sync failed on Traefik objects.

- On OpenShift, compare the rendered Ingresses' class with the cluster's
  IngressClasses: a missing class blocks, a class served by a controller other
  than the router (openshift.io/ingress-to-route) is a risk, and
  openshift-default passes and says so.
- On any cluster, block when the render contains Traefik objects (Middleware)
  and the cluster serves no Traefik API: the sync stops at the first one with
  "no matches for kind". The same failure hits an ingress-nginx cluster.
- Without a render, the pass names the values to set on OpenShift; when values
  were given but the chart did not render, it says that instead.
- components.ingress depends on config, so `--only components` still renders.
- Remedies name the charts' real key, ingress.className, not
  global.ingress.className; the stale "OpenShift has no IngressClass" comment
  is corrected.

Verified against a single-node OpenShift 4.22 cluster with the published bud
1.2.8 chart: infra's values.openshift.yaml passes, the chart defaults block on
three Traefik Middlewares, and className traefik blocks on the missing class.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@dittops
dittops force-pushed the claude/openshift-ingress-class branch from 3c5fa9f to 0a5e9da Compare September 15, 2026 06:46
@dittops
dittops merged commit 21758cf into main Sep 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant