-
Notifications
You must be signed in to change notification settings - Fork 595
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
HelmRelease install & upgrade timeout regex prevent release uninstallation #3227
Comments
The setting is this restrictive because otherwise arbitrary timeouts can cause a denial of service. In case you would be using a controller with 4 workers, and multiple (malicious) release are added with an extremely high timeout this would block any other release from being processed. See GHSA-f4p5-x4vc-mh4v for more information. My first question to address the issue with your release specifically is if it really takes this much time to run any release action? In case this is true, my advise would be to set it to |
Our use-case is indeed in "edge" environnement that, due to poor connectivity, may may take a long time to reconcile a release. We can of-course reduce it to 59m, but:
I understand our use-case is uncommon, and we'll most likely use your work around short term, but I feel this limitation should be either fixed or documented :) |
Describe the bug
I have an HelmReleases installed with install & upgrade set as following:
Which worked perfectly well with older flux version (0.26.0)
Now, we're trying to upgrade to latest flux version (0.35.0), and we're facing issues uninstalling such HelmRelease.
The HelmRelease resource itself is reporting reconciliation failure:
reconciliation failed: Operation cannot be fulfilled on helmreleases.helm.toolkit.fluxcd.io "ad-server": the object has been modified; please apply your changes to the latest version and try again
When checking the HelmController logs, following error is raised:
From my understanding, the timeouts we provide are compliant with the new regex
'^([0-9]+(\\.[0-9]+)?(ms|s|m))+$'
, but it is internally converted to 1h0m0s, which is not.My questions are following:
Thanks!
Steps to reproduce
Expected behavior
We expect the helmRelease to be properly uninstalled.
Screenshots and recordings
No response
OS / Distro
Ubuntu 20.04
Flux version
v0.35.0
Flux check
N/A
Git provider
No response
Container Registry provider
No response
Additional context
No response
Code of Conduct
The text was updated successfully, but these errors were encountered: