Install kubectl from the release binaries so it is version-stamped - #781
Open
julienp wants to merge 2 commits into
Open
Install kubectl from the release binaries so it is version-stamped#781julienp wants to merge 2 commits into
julienp wants to merge 2 commits into
Conversation
The kitchen sink image installed kubectl via `apt-get install kubectl`.
The same layer also adds the Google Cloud SDK apt repo, which publishes
its own `kubectl` package, so which package provides /usr/bin/kubectl is
an apt resolution outcome rather than an explicit choice. In the 3.256.0
image the resulting binary is not version-stamped:
$ kubectl version --client
Client Version: v0.0.0-master+$Format:%H$
`major` and `minor` are empty and gitVersion/gitCommit still contain the
literal git-archive placeholders. That is not parseable as a version, and
it breaks tooling that checks the kubectl client version - @pulumi/eks
calls semver.clean() on it, gets null, and dies with a TypeError that
never mentions kubectl.
Install the official release binary and verify it against the published
checksum instead, matching how aws-iam-authenticator is already installed
in this layer, and drop the now-unused Kubernetes apt repo.
Adds a test asserting kubectl reports a parseable, non-placeholder
version, since this fails silently until something tries to parse it.
There was a problem hiding this comment.
✅ No issues found
About Unblocked
Unblocked has been set up to automatically review your team's pull requests to identify genuine bugs and issues.
📖 Documentation — Learn more in our docs.
💬 Ask questions — Mention @unblocked to request a review or summary, or ask follow-up questions.
👍 Give feedback — React to comments with 👍 or 👎 to help us improve.
⚙️ Customize — Adjust settings in your preferences.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Companion to #777 so CI
runs with repo secrets — fork PRs can't access the ESC OIDC token. All credit to @rparsonsbb. Fixes #776.