Skip to content

Install kubectl from the release binaries so it is version-stamped - #781

Open
julienp wants to merge 2 commits into
mainfrom
fix-kubectl-version-stamped
Open

Install kubectl from the release binaries so it is version-stamped#781
julienp wants to merge 2 commits into
mainfrom
fix-kubectl-version-stamped

Conversation

@julienp

@julienp julienp commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Companion to #777 so CI
runs with repo secrets — fork PRs can't access the ESC OIDC token. All credit to @rparsonsbb. Fixes #776.

rparsonsbb and others added 2 commits August 12, 2026 12:57
The kitchen sink image installed kubectl via `apt-get install kubectl`.
The same layer also adds the Google Cloud SDK apt repo, which publishes
its own `kubectl` package, so which package provides /usr/bin/kubectl is
an apt resolution outcome rather than an explicit choice. In the 3.256.0
image the resulting binary is not version-stamped:

    $ kubectl version --client
    Client Version: v0.0.0-master+$Format:%H$

`major` and `minor` are empty and gitVersion/gitCommit still contain the
literal git-archive placeholders. That is not parseable as a version, and
it breaks tooling that checks the kubectl client version - @pulumi/eks
calls semver.clean() on it, gets null, and dies with a TypeError that
never mentions kubectl.

Install the official release binary and verify it against the published
checksum instead, matching how aws-iam-authenticator is already installed
in this layer, and drop the now-unused Kubernetes apt repo.

Adds a test asserting kubectl reports a parseable, non-placeholder
version, since this fails silently until something tries to parse it.

@unblocked unblocked Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No issues found

About Unblocked

Unblocked has been set up to automatically review your team's pull requests to identify genuine bugs and issues.

📖 Documentation — Learn more in our docs.

💬 Ask questions — Mention @unblocked to request a review or summary, or ask follow-up questions.

👍 Give feedback — React to comments with 👍 or 👎 to help us improve.

⚙️ Customize — Adjust settings in your preferences.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

kubectl in the pulumi/pulumi image is an unstamped build (v0.0.0-master+$Format:%H$), breaking @pulumi/eks

2 participants