Install kubectl from the release binaries so it is version-stamped - #777
Closed
rparsonsbb wants to merge 2 commits into
Closed
Install kubectl from the release binaries so it is version-stamped#777rparsonsbb wants to merge 2 commits into
rparsonsbb wants to merge 2 commits into
Conversation
The kitchen sink image installed kubectl via `apt-get install kubectl`.
The same layer also adds the Google Cloud SDK apt repo, which publishes
its own `kubectl` package, so which package provides /usr/bin/kubectl is
an apt resolution outcome rather than an explicit choice. In the 3.256.0
image the resulting binary is not version-stamped:
$ kubectl version --client
Client Version: v0.0.0-master+$Format:%H$
`major` and `minor` are empty and gitVersion/gitCommit still contain the
literal git-archive placeholders. That is not parseable as a version, and
it breaks tooling that checks the kubectl client version - @pulumi/eks
calls semver.clean() on it, gets null, and dies with a TypeError that
never mentions kubectl.
Install the official release binary and verify it against the published
checksum instead, matching how aws-iam-authenticator is already installed
in this layer, and drop the now-unused Kubernetes apt repo.
Adds a test asserting kubectl reports a parseable, non-placeholder
version, since this fails silently until something tries to parse it.
julienp
force-pushed
the
fix/kubectl-version-stamped
branch
from
August 14, 2026 10:01
89edfd9 to
e1151d8
Compare
Contributor
|
Thank you! I moved the kubectl installation up to be next to the AWS CLI installation. |
Contributor
|
I re-created the PR here #781 so w can run the tests. Closing this one. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed changes
/usr/bin/kubectlin thepulumi/pulumikitchen sink image is not version-stamped:major/minorare empty andgitVersion/gitCommitstill contain the literal$Format:%H$git-archive placeholders, i.e. the binary was built without the version
-ldflags.That string is not parseable as a version, so it breaks tooling that checks the kubectl client
version.
@pulumi/ekscallssemver.clean()on it, getsnull, and throwsInvalid version. Must be a string. Got type "object".— a message that never mentions kubectl(
typeof null === "object"), which makes it expensive to trace back here. For us this presented asa fleet-wide Pulumi Deployments outage on the default runner image: every stack, every tier, no
config change, while the same program succeeded locally on identical CLI/SDK/Node versions.
Cause. kubectl came from
apt-get install kubectl, but the same layer also adds the GoogleCloud SDK apt repo two lines earlier, which publishes its own
kubectlpackage. Which packageprovides
/usr/bin/kubectlis therefore an apt resolution outcome between two repos rather than anexplicit choice.
Fix. Install the official release binary and verify it against the published checksum, matching
how
aws-iam-authenticatoris already installed in this same layer (and consistent with #681,which moved that tool to release binaries for similar reasons). The Kubernetes apt repo and keyring
setup become unused and are dropped. Version selection is unchanged in spirit — still whatever
https://dl.k8s.io/release/stable.txtreports, just the full patch version rather than truncatingto
major.minorfor the apt repo path.I ran the exact install pipeline from this diff on linux/amd64:
Test. Adds a
Kubectlsubtest toTestCLIToolTestsasserting the client version is present,free of
$Format:placeholders, and parseable. This failure mode is silent until somethingdownstream tries to parse the version, so it is worth pinning.
go vet ./...passes intests/.I could not build the image locally to run the full suite, so CI should be the judge on the build
itself. Happy to pin an explicit kubectl version (with a
# renovate:comment, likeAWS_IAM_AUTHENTICATOR_VERSION) instead of trackingstable.txtif you'd prefer that — say theword and I'll push it.
Related issues (optional)
Fixes #776.
The downstream
@pulumi/ekscrash this triggers is pulumi/pulumi-eks#2360, with a fix inpulumi/pulumi-eks#2361 so the error at least names the tool it is complaining about.