Repository navigation
[SPARK-59504] Use enabled key convention in Helm values.yaml while honoring legacy enable
#825
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -106,14 +106,34 @@ List of Spark workload namespaces. If not provied in values, use the same namesp | ||||||||||||||||||||||
| {{- end }} | |||||||||||||||||||||||
| {{- end }} | |||||||||||||||||||||||
|
|
|||||||||||||||||||||||
| {{/* | |||||||||||||||||||||||
| Whether the operator pod NetworkPolicy is enabled. The legacy key | |||||||||||||||||||||||
| {operatorDeployment.networkPolicy.enable} is deprecated but still honored: the feature is | |||||||||||||||||||||||
| enabled when either key is true. | |||||||||||||||||||||||
| */}} | |||||||||||||||||||||||
| {{- define "spark-operator.networkPolicy.enabled" -}} | |||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Finding 4. An alternative that keeps the legacy key working and still lets with networkPolicy:
# Default: false. The legacy key `enable` is deprecated and will be removed in chart
# 2.0.0. It is honored when `enabled` is not set.
enabled:I rendered this variant on all six key combinations, and
The cost is that Honest counter-argument: |
|||||||||||||||||||||||
| {{- $np := .Values.operatorDeployment.networkPolicy -}} | |||||||||||||||||||||||
| {{- if or $np.enabled $np.enable }}true{{ else }}false{{ end -}} | |||||||||||||||||||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Finding 1. That is the layered-values shape people actually use, a checked-in base values file plus The rule is stated in |
|||||||||||||||||||||||
| {{- end }} | |||||||||||||||||||||||
|
|
|||||||||||||||||||||||
| {{/* | |||||||||||||||||||||||
| Whether dynamic config (hot properties loading) is enabled. The legacy key | |||||||||||||||||||||||
| {operatorConfiguration.dynamicConfig.enable} is deprecated but still honored: the feature is | |||||||||||||||||||||||
| enabled when either key is true. | |||||||||||||||||||||||
| */}} | |||||||||||||||||||||||
| {{- define "spark-operator.dynamicConfig.enabled" -}} | |||||||||||||||||||||||
| {{- $dc := .Values.operatorConfiguration.dynamicConfig -}} | |||||||||||||||||||||||
| {{- if or $dc.enabled $dc.enable }}true{{ else }}false{{ end -}} | |||||||||||||||||||||||
| {{- end }} | |||||||||||||||||||||||
|
|
|||||||||||||||||||||||
| {{/* | |||||||||||||||||||||||
| Default property overrides | |||||||||||||||||||||||
| */}} | |||||||||||||||||||||||
| {{- define "spark-operator.defaultPropertyOverrides" -}} | |||||||||||||||||||||||
| # Runtime resolved properties | |||||||||||||||||||||||
| spark.kubernetes.operator.namespace={{ .Release.Namespace }} | |||||||||||||||||||||||
| spark.kubernetes.operator.name={{- include "spark-operator.name" . }} | |||||||||||||||||||||||
| spark.kubernetes.operator.dynamicConfig.enabled={{ .Values.operatorConfiguration.dynamicConfig.enable }} | |||||||||||||||||||||||
| spark.kubernetes.operator.dynamicConfig.enabled={{ include "spark-operator.dynamicConfig.enabled" . }} | |||||||||||||||||||||||
| spark.kubernetes.operator.dynamicConfig.source={{ .Values.operatorConfiguration.dynamicConfig.source }} | |||||||||||||||||||||||
| spark.kubernetes.operator.metrics.port={{ include "spark-operator.metricsPort" . }} | |||||||||||||||||||||||
| spark.kubernetes.operator.health.probePort={{ include "spark-operator.probePort" . }} | |||||||||||||||||||||||
|
|
|||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -173,7 +173,7 @@ metadata: | |
| {{- template "spark-operator.operatorRbacRules" $ }} | ||
| --- | ||
| {{- end }} | ||
| {{- if and .Values.operatorConfiguration.dynamicConfig.enable (eq .Values.operatorConfiguration.dynamicConfig.source "configMap") }} | ||
| {{- if and (eq (include "spark-operator.dynamicConfig.enabled" .) "true") (eq .Values.operatorConfiguration.dynamicConfig.source "configMap") }} | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Finding 3. Pre-existing, and a follow-up rather than something for this PR. The doc entry also credits it with covering leader election. That is actually handled by the Since this PR is auditing |
||
| apiVersion: rbac.authorization.k8s.io/v1 | ||
| kind: Role | ||
| metadata: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -94,7 +94,9 @@ operatorDeployment: | |
| # operator pod is denied. Note that this requires a CNI plugin with NetworkPolicy support, | ||
| # and that egress traffic is not restricted. | ||
| networkPolicy: | ||
| enable: false | ||
| # The legacy key `enable` is deprecated and will be removed in chart 2.0.0 (SPARK-59533). | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Finding 7. The deprecation is announced in four files, but Now that The chart has no A follow-up PR is fine if you would rather keep this one to the rename. |
||
| # It is still honored: the NetworkPolicy is created when either `enabled` or `enable` is true. | ||
| enabled: false | ||
| # List of NetworkPolicyPeer(s) allowed to reach the metrics port, e.g. the Prometheus | ||
| # scraper. When empty, ingress to the metrics port is denied. | ||
| metricsIngress: [ ] | ||
|
|
@@ -218,8 +220,10 @@ operatorConfiguration: | |
| metrics.properties: |+ | ||
| # Metrics Properties Overrides | ||
| dynamicConfig: | ||
| # Enable this for hot properties loading. | ||
| enable: false | ||
| # Enable this for hot properties loading. The legacy key `enable` is deprecated and will be | ||
| # removed in chart 2.0.0 (SPARK-59533). It is still honored: hot properties loading is | ||
| # enabled when either `enabled` or `enable` is true. | ||
| enabled: false | ||
| # Source of the dynamic config overrides when enabled. Supported values: | ||
| # configMap - (default) watch a ConfigMap via a Kubernetes informer. Requires the operator | ||
| # to have RBAC to read ConfigMaps (created by this chart). | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -133,7 +133,8 @@ following table: | |
| | operatorConfiguration.spark-operator.properties | The default operator configuration. | | | ||
| | operatorConfiguration.metrics.properties | The default operator metrics (sink) configuration. | | | ||
| | operatorConfiguration.dynamicConfig.create | If set to true, a config map would be created & watched by operator as source of truth for hot properties loading. | false | | ||
| | operatorConfiguration.dynamicConfig.enable | If set to true, operator would honor the created config map as source of truth for hot properties loading. | false | | ||
| | operatorConfiguration.dynamicConfig.enabled | If set to true, operator would honor the created config map as source of truth for hot properties loading. | false | | ||
| | operatorConfiguration.dynamicConfig.enable | Deprecated, use `operatorConfiguration.dynamicConfig.enabled`. Still honored: `enable: true` wins over `enabled: false`. Removed in chart 2.0.0 (SPARK-59533). | | | ||
| | operatorConfiguration.dynamicConfig.annotations | Annotations to be applied for the dynamicConfig resources. | `"helm.sh/resource-policy": keep` | | ||
| | operatorConfiguration.dynamicConfig.data | Data field (key-value pairs) that acts as hot properties in the config map. | `spark.kubernetes.operator.reconciler.intervalSeconds: "60"` | | ||
|
|
||
|
|
@@ -154,7 +155,7 @@ for the operator pod: | |
| ```yaml | ||
| operatorDeployment: | ||
| networkPolicy: | ||
| enable: true | ||
| enabled: true | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Finding 2. The deprecation of One sentence after this block covers it: The legacy key `operatorDeployment.networkPolicy.enable` is deprecated in favour of
`enabled` and will be removed in chart `2.0.0`. It is still honored: the NetworkPolicy
is created when either key is `true`. |
||
| metricsIngress: | ||
| - namespaceSelector: | ||
| matchLabels: | ||
|
|
@@ -174,6 +175,12 @@ Note that this requires a CNI plugin that enforces NetworkPolicy; on clusters wi | |
| a plugin the policy is silently ignored. Egress traffic of the operator (Kubernetes API | ||
| server, DNS) is not restricted by this policy. | ||
|
|
||
| The legacy key `operatorDeployment.networkPolicy.enable` is deprecated in favor of `enabled` | ||
| and will be removed in chart `2.0.0` ([SPARK-59533](https://issues.apache.org/jira/browse/SPARK-59533)). | ||
| It is still honored: the NetworkPolicy is created when either key is `true`, so a stale | ||
| `enable: true` in a base values file wins over `enabled: false` and must be removed to turn | ||
| the feature off. The same rule applies to `operatorConfiguration.dynamicConfig.enable`. | ||
|
|
||
| ## Operator Health(Liveness) Probe with Sentinel Resource | ||
|
|
||
| Learning | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Finding 6. This step pins the ON direction for both legacy keys. Nothing pins the OFF direction, here or in the Helm Tests job — the
network-policygroup installs withenabled: true, and no test asserts the NetworkPolicy is absent.That gap matters because the helpers return the strings
"true"/"false", so every callsite has to spell outeq (include "...") "true". A future gated resource written as{{- if include "spark-operator.networkPolicy.enabled" . }}renders unconditionally, since"false"is a non-empty string and therefore truthy. I checked that on this head with a probe template: the naiveiftakes the truthy branch on default values.The four callsites today all get it right. But with the helper mutated to
{{- if or $np.enabled $np.enable }}true{{ else }}true{{ end -}}— a stuck-on toggle —helm lint --strictand both of the new assertions still pass. These two fail on that mutation and pass on this head:Worth using
if ... then exit 1; firather than! ... | grep -q. The step has noshell:key, so it runs underbash -ewithoutpipefail, andbashexempts a!-inverted command from-e. I confirmed that! helm template ... | grep -q 'kind: NetworkPolicy'exits 0 and the script keeps going even when the NetworkPolicy is rendered.