Skip to content

Unable to Upgrade Stackrox using terraform #12056

Description

@jseiser

This happens with every release. I wanted to post here to see if there is anything we can do before we spend the time reverting.

Process

  1. We Install Helm Charts with Terraform.
  2. We generated the stackrox-init-bundle.yaml out of band since stackrox doesnt support using cert-manager
  3. We pull down the values from stackrox-init-bundle.yaml and pass them in as inputs to secured-cluster-services

This works, stackrox is up and running.

  1. We bump Chart versions
  2. secured-cluster-services will error out every time with the follow
│ Error: malformed chart or values: 
│ 	templates/: template: stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml:1:4: executing "stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml" at <include "srox.init" .>: error calling include: template: stackrox-secured-cluster-services/templates/_init.tpl:114:3: executing "srox.init" at <include "srox.getStorageClasses" (list $)>: error calling include: template: stackrox-secured-cluster-services/templates/_storage_classes.tpl:20:12: executing "srox.getStorageClasses" at <include "srox.safeLookup" (list $ $lookupResult "storage.k8s.io/v1" "StorageClass" "" "")>: error calling include: template: stackrox-secured-cluster-services/templates/_lookup.tpl:18:7: executing "srox.safeLookup" at <include "srox._doLookup" (list $ $testOut "v1" "ServiceAccount" $._rox._namespace "default")>: error calling include: template: stackrox-secured-cluster-services/templates/_lookup.tpl:39:9: executing "srox._doLookup" at <tpl "{{ $_ := set .out \"result\" (lookup .apiVersion .kind .ns .name) }}" $tplArgs>: error calling tpl: error during tpl function execution for "{{ $_ := set .out \"result\" (lookup .apiVersion .kind .ns .name) }}": template: stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml:1:53: executing "stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml" at <.ns>: wrong type for value; expected string; got interface {}
│ 
│   with helm_release.stackrox-secured-cluster-services,
│   on main.tf line 66, in resource "helm_release" "stackrox-secured-cluster-services":
│   66: resource "helm_release" "stackrox-secured-cluster-services" {
│ 
╵
  1. We have to uninstall and re-install everything and it works again.

The values file itself, with TF templating. Note, 90% of the values is just removing SeLinux ( doesnt work on bottle rocket) and removing the node affinities ( do not work in EKS )

meta:
  namespaceOverride: stackrox

clusterName: ${cluster_name}

scanner:
  disable: true

scannerV4:
  disable: false
  indexer:
    affinity:
      nodeAffinity:
        preferredDuringSchedulingIgnoredDuringExecution: []
  matcher:
      affinity:
          nodeAffinity:
              preferredDuringSchedulingIgnoredDuringExecution: []
  db:
    affinity:
      nodeAffinity:
        preferredDuringSchedulingIgnoredDuringExecution: []

ca:
  cert: |
      ${indent(6,ca_cert)}
sensor:
  serviceTLS:
    cert: |
        ${indent(8,sensor_cert)}
    key: |
        ${indent(8,sensor_key)}
  affinity:
     nodeAffinity:
       preferredDuringSchedulingIgnoredDuringExecution: []
admissionControl:
  serviceTLS:
    cert: |
        ${indent(8,admissioncontrol_cert)}
    key: |
        ${indent(8,admissioncontrol_key)}
  affinity:
     nodeAffinity:
       preferredDuringSchedulingIgnoredDuringExecution: []
collector:
  serviceTLS:
    cert: |
        ${indent(8,collector_cert)}
    key: |
        ${indent(8,collector_key)}
  disableSELinuxOptions: true

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions