Crds first - #2005
Merged
Merged
Crds first#2005
Conversation
When a `PolicyRef` (including `remoteURL` pointing at an OCI image) contains both CustomResourceDefinitions and custom resources that depend on them, Sveltos deploys objects in the order they appear in the manifest. If a CR precedes its CRD in the file, the CR fails to apply because the type isn't registered yet. Without `continueOnError`, that failure aborts the deployment before the CRD (which appears later in the same file) is ever applied. Every retry replays the same order and fails the same way, so a new cluster never progresses past that object. Unlike `kustomizationRefs`, where the `resources:` list in a `kustomization.yaml` already gives users an explicit way to order the CRD before its CRs, `policyRefs` sources (ConfigMap, Secret, GitRepository, OCIRepository, Bucket, remoteURL) offer no such mechanism. The author has no lever to fix ordering inside a third-party manifest. Add `partitionCRDsFirst`, a stable partition that moves every CustomResourceDefinition ahead of other resources while preserving relative order within each group. It's called once in `deployContent`, right after patches are applied and before the push/pull-mode branch, so it covers every `policyRefs` source for both push-mode (`deployUnstructured`) and pull-mode (`pullmode.StageResourcesForDeployment`) clusters, since both consume the same ordered list. It's a no-op whenever CRDs already come first or none are present. `kustomizationRefs` is intentionally left untouched, with a comment explaining why.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When a
PolicyRef(includingremoteURLpointing at an OCI image) contains both CustomResourceDefinitions and custom resources that depend on them, Sveltos deploys objects in the order they appear in the manifest. If a CR precedes its CRD in the file, the CR fails to apply because the type isn't registered yet. WithoutcontinueOnError, that failure aborts the deployment before the CRD (which appears later in the same file) is ever applied. Every retry replays the same order and fails the same way, so a new cluster never progresses past that object.Unlike
kustomizationRefs, where theresources:list in akustomization.yamlalready gives users an explicit way to order the CRD before its CRs,policyRefssources (ConfigMap, Secret, GitRepository, OCIRepository, Bucket, remoteURL) offer no such mechanism. The author has no lever to fix ordering inside a third-party manifest.Add
partitionCRDsFirst, a stable partition that moves every CustomResourceDefinition ahead of other resources while preserving relative order within each group. It's called once indeployContent, right after patches are applied and before the push/pull-mode branch, so it covers everypolicyRefssource for both push-mode (deployUnstructured) and pull-mode (pullmode.StageResourcesForDeployment) clusters, since both consume the same ordered list.It's a no-op whenever CRDs already come first or none are present.
kustomizationRefsis intentionally left untouched, with a comment explaining why.