This happens with every release. I wanted to post here to see if there is anything we can do before we spend the time reverting.
Process
- We Install Helm Charts with Terraform.
- We generated the
stackrox-init-bundle.yaml out of band since stackrox doesnt support using cert-manager
- We pull down the values from
stackrox-init-bundle.yaml and pass them in as inputs to secured-cluster-services
This works, stackrox is up and running.
- We bump Chart versions
secured-cluster-services will error out every time with the follow
│ Error: malformed chart or values:
│ templates/: template: stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml:1:4: executing "stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml" at <include "srox.init" .>: error calling include: template: stackrox-secured-cluster-services/templates/_init.tpl:114:3: executing "srox.init" at <include "srox.getStorageClasses" (list $)>: error calling include: template: stackrox-secured-cluster-services/templates/_storage_classes.tpl:20:12: executing "srox.getStorageClasses" at <include "srox.safeLookup" (list $ $lookupResult "storage.k8s.io/v1" "StorageClass" "" "")>: error calling include: template: stackrox-secured-cluster-services/templates/_lookup.tpl:18:7: executing "srox.safeLookup" at <include "srox._doLookup" (list $ $testOut "v1" "ServiceAccount" $._rox._namespace "default")>: error calling include: template: stackrox-secured-cluster-services/templates/_lookup.tpl:39:9: executing "srox._doLookup" at <tpl "{{ $_ := set .out \"result\" (lookup .apiVersion .kind .ns .name) }}" $tplArgs>: error calling tpl: error during tpl function execution for "{{ $_ := set .out \"result\" (lookup .apiVersion .kind .ns .name) }}": template: stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml:1:53: executing "stackrox-secured-cluster-services/templates/upgrader-serviceaccount.yaml" at <.ns>: wrong type for value; expected string; got interface {}
│
│ with helm_release.stackrox-secured-cluster-services,
│ on main.tf line 66, in resource "helm_release" "stackrox-secured-cluster-services":
│ 66: resource "helm_release" "stackrox-secured-cluster-services" {
│
╵
- We have to uninstall and re-install everything and it works again.
The values file itself, with TF templating. Note, 90% of the values is just removing SeLinux ( doesnt work on bottle rocket) and removing the node affinities ( do not work in EKS )
meta:
namespaceOverride: stackrox
clusterName: ${cluster_name}
scanner:
disable: true
scannerV4:
disable: false
indexer:
affinity:
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution: []
matcher:
affinity:
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution: []
db:
affinity:
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution: []
ca:
cert: |
${indent(6,ca_cert)}
sensor:
serviceTLS:
cert: |
${indent(8,sensor_cert)}
key: |
${indent(8,sensor_key)}
affinity:
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution: []
admissionControl:
serviceTLS:
cert: |
${indent(8,admissioncontrol_cert)}
key: |
${indent(8,admissioncontrol_key)}
affinity:
nodeAffinity:
preferredDuringSchedulingIgnoredDuringExecution: []
collector:
serviceTLS:
cert: |
${indent(8,collector_cert)}
key: |
${indent(8,collector_key)}
disableSELinuxOptions: true
This happens with every release. I wanted to post here to see if there is anything we can do before we spend the time reverting.
Process
stackrox-init-bundle.yamlout of band since stackrox doesnt support using cert-managerstackrox-init-bundle.yamland pass them in as inputs tosecured-cluster-servicesThis works, stackrox is up and running.
secured-cluster-serviceswill error out every time with the followThe values file itself, with TF templating. Note, 90% of the values is just removing SeLinux ( doesnt work on bottle rocket) and removing the node affinities ( do not work in EKS )