Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix(chart): address review on image helpers and shared RBAC naming
Review feedback:

- Document where the image repositories come from: they are the
  ko-published binary slugs from the v0.81.0 release assets and the
  tag follows Chart.AppVersion; if a release renames the slugs, all
  three (operator/webhook/proxy-webhook) must be updated together.
  Also flatten the indentation inside the image helpers to match the
  chart style.

- Fullname-prefix the shared tekton-operator-info Role/RoleBinding
  and tekton-config-read-role ClusterRole/ClusterRoleBinding so two
  chart installs in one cluster no longer collide on cluster-scoped
  names (previously literal). The Role's resourceNames entry stays
  the literal tekton-operator-info: it refers to the ConfigMap that
  tkn version reads, which keeps its fixed name.

Upgrading from a released chart leaves the literal-named objects
stale (helm cannot delete names that no longer appear in templates);
see the PR description for the exact kubectl cleanup commands.

Signed-off-by: Abdullah Alaqeel <[email protected]>
Assisted-by: GLM (via opencode)
  • Loading branch information
aqeelat committed Sep 4, 2026
commit 42b857837b8809d16ee526f6cb049d1006c28e79
27 changes: 15 additions & 12 deletions charts/tekton-operator/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -110,17 +110,20 @@ tektonconfig,tektonpipeline,tektontrigger,tektonchain,tektonresult,tektondashboa
{{- end -}}
{{- end -}}

{{/* Image repositories are the ko-published binary slugs from the v0.81.0
release assets; the tag follows Chart.AppVersion. If a release renames
the slugs, update all three (operator/webhook/proxy-webhook). */}}
{{- define "tekton-operator.operator-image" -}}
{{- $tag := default .Chart.AppVersion .Values.operator.image.tag -}}
{{- $image := "" -}}
{{- if .Values.operator.image.repository -}}
{{- $image = .Values.operator.image.repository }}
{{- else -}}
{{- if .Values.openshift.enabled -}}
{{- $image = "ghcr.io/tektoncd/operator/operator-1d69a75f22dd094880847eac907fb2c1" -}}
{{- else -}}
{{- $image = "ghcr.io/tektoncd/operator/operator-303303c315a48490ba6517859ef65b77" -}}
{{- end -}}
{{- $image = "ghcr.io/tektoncd/operator/operator-1d69a75f22dd094880847eac907fb2c1" -}}
{{- else -}}
{{- $image = "ghcr.io/tektoncd/operator/operator-303303c315a48490ba6517859ef65b77" -}}
{{- end -}}
{{- end -}}
{{- printf "%s:%s" $image $tag -}}
{{- end -}}
Expand All @@ -140,10 +143,10 @@ tektonconfig,tektonpipeline,tektontrigger,tektonchain,tektonresult,tektondashboa
{{- $image = .Values.webhook.image.repository }}
{{- else -}}
{{- if .Values.openshift.enabled -}}
{{- $image = "ghcr.io/tektoncd/operator/webhook-340ad78e88ca5477447aa144fedfe1a1" -}}
{{- else -}}
{{- $image = "ghcr.io/tektoncd/operator/webhook-f2bb711aa8f0c0892856a4cbf6d9ddd8" -}}
{{- end -}}
{{- $image = "ghcr.io/tektoncd/operator/webhook-340ad78e88ca5477447aa144fedfe1a1" -}}
{{- else -}}
{{- $image = "ghcr.io/tektoncd/operator/webhook-f2bb711aa8f0c0892856a4cbf6d9ddd8" -}}
{{- end -}}
{{- end -}}
{{- printf "%s:%s" $image $tag -}}
{{- end -}}
Expand All @@ -163,10 +166,10 @@ tektonconfig,tektonpipeline,tektontrigger,tektonchain,tektonresult,tektondashboa
{{- $image = .Values.webhookProxy.image.repository }}
{{- else -}}
{{- if .Values.openshift.enabled -}}
{{- $image = "ghcr.io/tektoncd/operator/proxy-webhook-f8f95c9cea9508fe8915ae3d012d15fb" -}}
{{- else -}}
{{- $image = "ghcr.io/tektoncd/operator/proxy-webhook-f6167da7bc41b96a27c5529f850e63d1" -}}
{{- end -}}
{{- $image = "ghcr.io/tektoncd/operator/proxy-webhook-f8f95c9cea9508fe8915ae3d012d15fb" -}}
{{- else -}}
{{- $image = "ghcr.io/tektoncd/operator/proxy-webhook-f6167da7bc41b96a27c5529f850e63d1" -}}
{{- end -}}
{{- end -}}
{{- printf "%s:%s" $image $tag -}}
{{- end -}}
12 changes: 6 additions & 6 deletions charts/tekton-operator/templates/common-rbac.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: tekton-operator-info
name: {{ include "tekton-operator.fullname" . }}-info
labels:
{{- include "tekton-operator.labels" . | nindent 4 }}
rules:
Expand All @@ -22,11 +22,11 @@ kind: RoleBinding
metadata:
labels:
app.kubernetes.io/instance: default
name: tekton-operator-info
name: {{ include "tekton-operator.fullname" . }}-info
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: tekton-operator-info
name: {{ include "tekton-operator.fullname" . }}-info
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: Group
Expand All @@ -35,7 +35,7 @@ subjects:
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tekton-config-read-role
name: {{ include "tekton-operator.fullname" . }}-config-read-role
labels:
{{- include "tekton-operator.labels" . | nindent 4 }}
rules:
Expand All @@ -51,11 +51,11 @@ rules:
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tekton-config-read-rolebinding
name: {{ include "tekton-operator.fullname" . }}-config-read-rolebinding
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tekton-config-read-role
name: {{ include "tekton-operator.fullname" . }}-config-read-role
subjects:
- apiGroup: rbac.authorization.k8s.io
kind: Group
Expand Down
Loading