2
0

agent.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533
  1. package helm
  2. import (
  3. "bytes"
  4. "context"
  5. "fmt"
  6. "runtime/debug"
  7. "strconv"
  8. "strings"
  9. "time"
  10. "github.com/pkg/errors"
  11. "github.com/porter-dev/porter/internal/helm/loader"
  12. "github.com/stefanmcshane/helm/pkg/action"
  13. "github.com/stefanmcshane/helm/pkg/chart"
  14. "github.com/stefanmcshane/helm/pkg/release"
  15. "github.com/stefanmcshane/helm/pkg/storage/driver"
  16. "golang.org/x/oauth2"
  17. corev1 "k8s.io/api/core/v1"
  18. v1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  19. "k8s.io/helm/pkg/chartutil"
  20. "github.com/porter-dev/porter/api/types"
  21. "github.com/porter-dev/porter/internal/kubernetes"
  22. "github.com/porter-dev/porter/internal/models"
  23. "github.com/porter-dev/porter/internal/repository"
  24. )
  25. // Agent is a Helm agent for performing helm operations
  26. type Agent struct {
  27. ActionConfig *action.Configuration
  28. K8sAgent *kubernetes.Agent
  29. }
  30. // ListReleases lists releases based on a ListFilter
  31. func (a *Agent) ListReleases(
  32. namespace string,
  33. filter *types.ReleaseListFilter,
  34. ) ([]*release.Release, error) {
  35. lsel := fmt.Sprintf("owner=helm,status in (%s)", strings.Join(filter.StatusFilter, ","))
  36. // list secrets
  37. secretList, err := a.K8sAgent.Clientset.CoreV1().Secrets(namespace).List(
  38. context.Background(),
  39. v1.ListOptions{
  40. LabelSelector: lsel,
  41. },
  42. )
  43. if err != nil {
  44. return nil, err
  45. }
  46. // before decoding to helm release, only keep the latest releases for each chart
  47. latestMap := make(map[string]corev1.Secret)
  48. for _, secret := range secretList.Items {
  49. relName, relNameExists := secret.Labels["name"]
  50. if !relNameExists {
  51. continue
  52. }
  53. id := fmt.Sprintf("%s/%s", secret.Namespace, relName)
  54. if currLatest, exists := latestMap[id]; exists {
  55. // get version
  56. currVersionStr, currVersionExists := currLatest.Labels["version"]
  57. versionStr, versionExists := secret.Labels["version"]
  58. if versionExists && currVersionExists {
  59. currVersion, currErr := strconv.Atoi(currVersionStr)
  60. version, err := strconv.Atoi(versionStr)
  61. if currErr == nil && err == nil && currVersion < version {
  62. latestMap[id] = secret
  63. }
  64. }
  65. } else {
  66. latestMap[id] = secret
  67. }
  68. }
  69. chartList := []string{}
  70. res := make([]*release.Release, 0)
  71. for _, secret := range latestMap {
  72. rel, isErr, err := kubernetes.ParseSecretToHelmRelease(secret, chartList)
  73. if !isErr && err == nil {
  74. res = append(res, rel)
  75. }
  76. }
  77. return res, nil
  78. }
  79. // GetRelease returns the info of a release.
  80. func (a *Agent) GetRelease(
  81. name string,
  82. version int,
  83. getDeps bool,
  84. ) (*release.Release, error) {
  85. // Namespace is already known by the RESTClientGetter.
  86. cmd := action.NewGet(a.ActionConfig)
  87. cmd.Version = version
  88. release, err := cmd.Run(name)
  89. if err != nil {
  90. return nil, err
  91. }
  92. if getDeps && release.Chart != nil && release.Chart.Metadata != nil {
  93. for _, dep := range release.Chart.Metadata.Dependencies {
  94. // only search for dependency if it passes the condition specified in Chart.yaml
  95. if dep.Enabled {
  96. depExists := false
  97. for _, currDep := range release.Chart.Dependencies() {
  98. // we just case on name for now -- there might be edge cases we're missing
  99. // but this will cover 99% of cases
  100. if dep != nil && currDep != nil && dep.Name == currDep.Name() {
  101. depExists = true
  102. break
  103. }
  104. }
  105. if !depExists {
  106. depChart, err := loader.LoadChartPublic(dep.Repository, dep.Name, dep.Version)
  107. if err != nil {
  108. return nil, fmt.Errorf("Error retrieving chart dependency %s/%s-%s: %s", dep.Repository, dep.Name, dep.Version, err.Error())
  109. }
  110. release.Chart.AddDependency(depChart)
  111. }
  112. }
  113. }
  114. }
  115. return release, err
  116. }
  117. // DeleteReleaseRevision deletes a specific revision of a release
  118. func (a *Agent) DeleteReleaseRevision(
  119. name string,
  120. version int,
  121. ) error {
  122. _, err := a.ActionConfig.Releases.Delete(name, version)
  123. return err
  124. }
  125. // GetReleaseHistory returns a list of charts for a specific release
  126. func (a *Agent) GetReleaseHistory(
  127. name string,
  128. ) ([]*release.Release, error) {
  129. cmd := action.NewHistory(a.ActionConfig)
  130. return cmd.Run(name)
  131. }
  132. type UpgradeReleaseConfig struct {
  133. Name string
  134. Values map[string]interface{}
  135. Cluster *models.Cluster
  136. Repo repository.Repository
  137. Registries []*models.Registry
  138. // Optional, if chart should be overriden
  139. Chart *chart.Chart
  140. // Optional, if chart is part of a Porter Stack
  141. StackName string
  142. StackRevision uint
  143. }
  144. // UpgradeRelease upgrades a specific release with new values.yaml
  145. func (a *Agent) UpgradeRelease(
  146. conf *UpgradeReleaseConfig,
  147. values string,
  148. doAuth *oauth2.Config,
  149. disablePullSecretsInjection bool,
  150. ignoreDependencies bool,
  151. ) (*release.Release, error) {
  152. valuesYaml, err := chartutil.ReadValues([]byte(values))
  153. if err != nil {
  154. return nil, fmt.Errorf("Values could not be parsed: %v", err)
  155. }
  156. conf.Values = valuesYaml
  157. return a.UpgradeReleaseByValues(conf, doAuth, disablePullSecretsInjection, ignoreDependencies)
  158. }
  159. // UpgradeReleaseByValues upgrades a release by unmarshaled yaml values
  160. func (a *Agent) UpgradeReleaseByValues(
  161. conf *UpgradeReleaseConfig,
  162. doAuth *oauth2.Config,
  163. disablePullSecretsInjection bool,
  164. ignoreDependencies bool,
  165. ) (*release.Release, error) {
  166. // grab the latest release
  167. rel, err := a.GetRelease(conf.Name, 0, !ignoreDependencies)
  168. if err != nil {
  169. return nil, fmt.Errorf("Could not get release to be upgraded: %v", err)
  170. }
  171. ch := rel.Chart
  172. if conf.Chart != nil {
  173. ch = conf.Chart
  174. }
  175. cmd := action.NewUpgrade(a.ActionConfig)
  176. cmd.Namespace = rel.Namespace
  177. cmd.PostRenderer, err = NewPorterPostrenderer(
  178. conf.Cluster,
  179. conf.Repo,
  180. a.K8sAgent,
  181. rel.Namespace,
  182. conf.Registries,
  183. doAuth,
  184. disablePullSecretsInjection,
  185. )
  186. if err != nil {
  187. return nil, err
  188. }
  189. if conf.StackName != "" && conf.StackRevision > 0 {
  190. conf.Values["stack"] = map[string]interface{}{
  191. "enabled": true,
  192. "name": conf.StackName,
  193. "revision": conf.StackRevision,
  194. }
  195. }
  196. res, err := cmd.Run(conf.Name, ch, conf.Values)
  197. if err != nil {
  198. // refer: https://github.com/helm/helm/blob/release-3.8/pkg/action/action.go#L62
  199. // issue tracker: https://github.com/helm/helm/issues/4558
  200. if err.Error() == "another operation (install/upgrade/rollback) is in progress" {
  201. secretList, err := a.K8sAgent.Clientset.CoreV1().Secrets(rel.Namespace).List(
  202. context.Background(),
  203. v1.ListOptions{
  204. LabelSelector: fmt.Sprintf("owner=helm,status in (pending-install, pending-upgrade, pending-rollback),name=%s", rel.Name),
  205. },
  206. )
  207. if err != nil {
  208. return nil, fmt.Errorf("Upgrade failed: %w", err)
  209. }
  210. if len(secretList.Items) > 0 {
  211. mostRecentSecret := secretList.Items[0]
  212. for i := 1; i < len(secretList.Items); i += 1 {
  213. oldVersion, _ := strconv.Atoi(mostRecentSecret.Labels["version"])
  214. newVersion, _ := strconv.Atoi(secretList.Items[i].Labels["version"])
  215. if oldVersion < newVersion {
  216. mostRecentSecret = secretList.Items[i]
  217. }
  218. }
  219. if time.Since(mostRecentSecret.CreationTimestamp.Time) >= time.Minute {
  220. helmSecrets := driver.NewSecrets(a.K8sAgent.Clientset.CoreV1().Secrets(rel.Namespace))
  221. rel.Info.Status = release.StatusFailed
  222. err = helmSecrets.Update(mostRecentSecret.GetName(), rel)
  223. if err != nil {
  224. return nil, fmt.Errorf("Upgrade failed: %w", err)
  225. }
  226. // retry upgrade
  227. res, err = cmd.Run(conf.Name, ch, conf.Values)
  228. if err != nil {
  229. return nil, fmt.Errorf("Upgrade failed: %w", err)
  230. }
  231. return res, nil
  232. } else {
  233. // ask the user to wait for about a minute before retrying for the above fix to kick in
  234. return nil, fmt.Errorf("another operation (install/upgrade/rollback) is in progress. If this error persists, please wait for 60 seconds to force an upgrade")
  235. }
  236. }
  237. } else if strings.Contains(err.Error(), "current release manifest contains removed kubernetes api(s)") || strings.Contains(err.Error(), "resource mapping not found for name") {
  238. // ref: https://helm.sh/docs/topics/kubernetes_apis/#updating-api-versions-of-a-release-manifest
  239. // in this case, we manually update the secret containing the new manifests
  240. secretList, err := a.K8sAgent.Clientset.CoreV1().Secrets(rel.Namespace).List(
  241. context.Background(),
  242. v1.ListOptions{
  243. LabelSelector: fmt.Sprintf("owner=helm,name=%s", rel.Name),
  244. },
  245. )
  246. if err != nil {
  247. return nil, fmt.Errorf("Upgrade failed: %w", err)
  248. }
  249. if len(secretList.Items) > 0 {
  250. mostRecentSecret := secretList.Items[0]
  251. for i := 1; i < len(secretList.Items); i += 1 {
  252. oldVersion, _ := strconv.Atoi(mostRecentSecret.Labels["version"])
  253. newVersion, _ := strconv.Atoi(secretList.Items[i].Labels["version"])
  254. if oldVersion < newVersion {
  255. mostRecentSecret = secretList.Items[i]
  256. }
  257. }
  258. // run the equivalent of `helm template` to get the manifest string for the new release
  259. installCmd := action.NewInstall(a.ActionConfig)
  260. installCmd.ReleaseName = conf.Name
  261. installCmd.Namespace = rel.Namespace
  262. installCmd.DryRun = true
  263. installCmd.Replace = true
  264. installCmd.ClientOnly = false
  265. installCmd.IncludeCRDs = true
  266. newRelDryRun, err := installCmd.Run(ch, conf.Values)
  267. if err != nil {
  268. return nil, err
  269. }
  270. oldManifestBuffer := bytes.NewBufferString(rel.Manifest)
  271. newManifestBuffer := bytes.NewBufferString(newRelDryRun.Manifest)
  272. versionMapper := &DeprecatedAPIVersionMapper{}
  273. updatedManifestBuffer, err := versionMapper.Run(oldManifestBuffer, newManifestBuffer)
  274. if err != nil {
  275. return nil, err
  276. }
  277. rel.Manifest = updatedManifestBuffer.String()
  278. helmSecrets := driver.NewSecrets(a.K8sAgent.Clientset.CoreV1().Secrets(rel.Namespace))
  279. err = helmSecrets.Update(mostRecentSecret.GetName(), rel)
  280. if err != nil {
  281. return nil, fmt.Errorf("Upgrade failed: %w", err)
  282. }
  283. res, err := cmd.Run(conf.Name, ch, conf.Values)
  284. if err != nil {
  285. return nil, fmt.Errorf("Upgrade failed: %w", err)
  286. }
  287. return res, nil
  288. }
  289. }
  290. return nil, fmt.Errorf("Upgrade failed: %w", err)
  291. }
  292. return res, nil
  293. }
  294. // InstallChartConfig is the config required to install a chart
  295. type InstallChartConfig struct {
  296. Chart *chart.Chart
  297. Name string
  298. Namespace string
  299. Values map[string]interface{}
  300. Cluster *models.Cluster
  301. Repo repository.Repository
  302. Registries []*models.Registry
  303. }
  304. // InstallChartFromValuesBytes reads the raw values and calls Agent.InstallChart
  305. func (a *Agent) InstallChartFromValuesBytes(
  306. conf *InstallChartConfig,
  307. values []byte,
  308. doAuth *oauth2.Config,
  309. disablePullSecretsInjection bool,
  310. ) (*release.Release, error) {
  311. valuesYaml, err := chartutil.ReadValues(values)
  312. if err != nil {
  313. return nil, fmt.Errorf("Values could not be parsed: %v", err)
  314. }
  315. conf.Values = valuesYaml
  316. return a.InstallChart(conf, doAuth, disablePullSecretsInjection)
  317. }
  318. // InstallChart installs a new chart
  319. func (a *Agent) InstallChart(
  320. conf *InstallChartConfig,
  321. doAuth *oauth2.Config,
  322. disablePullSecretsInjection bool,
  323. ) (*release.Release, error) {
  324. defer func() {
  325. if r := recover(); r != nil {
  326. fmt.Println("stacktrace from panic: \n" + string(debug.Stack()))
  327. }
  328. }()
  329. cmd := action.NewInstall(a.ActionConfig)
  330. if cmd.Version == "" && cmd.Devel {
  331. cmd.Version = ">0.0.0-0"
  332. }
  333. cmd.ReleaseName = conf.Name
  334. cmd.Namespace = conf.Namespace
  335. cmd.Timeout = 300 * time.Second
  336. if err := checkIfInstallable(conf.Chart); err != nil {
  337. return nil, err
  338. }
  339. var err error
  340. cmd.PostRenderer, err = NewPorterPostrenderer(
  341. conf.Cluster,
  342. conf.Repo,
  343. a.K8sAgent,
  344. conf.Namespace,
  345. conf.Registries,
  346. doAuth,
  347. disablePullSecretsInjection,
  348. )
  349. if err != nil {
  350. return nil, err
  351. }
  352. if req := conf.Chart.Metadata.Dependencies; req != nil {
  353. for _, dep := range req {
  354. depChart, err := loader.LoadChartPublic(dep.Repository, dep.Name, dep.Version)
  355. if err != nil {
  356. return nil, fmt.Errorf("error retrieving chart dependency %s/%s-%s: %s", dep.Repository, dep.Name, dep.Version, err.Error())
  357. }
  358. conf.Chart.AddDependency(depChart)
  359. }
  360. }
  361. return cmd.Run(conf.Chart, conf.Values)
  362. }
  363. // UpgradeInstallChart installs a new chart if it doesn't exist, otherwise it upgrades it
  364. func (a *Agent) UpgradeInstallChart(
  365. conf *InstallChartConfig,
  366. doAuth *oauth2.Config,
  367. disablePullSecretsInjection bool,
  368. ) (*release.Release, error) {
  369. defer func() {
  370. if r := recover(); r != nil {
  371. fmt.Println("stacktrace from panic: \n" + string(debug.Stack()))
  372. }
  373. }()
  374. cmd := action.NewUpgrade(a.ActionConfig)
  375. cmd.Install = true
  376. if cmd.Version == "" && cmd.Devel {
  377. cmd.Version = ">0.0.0-0"
  378. }
  379. cmd.Namespace = conf.Namespace
  380. cmd.Timeout = 300 * time.Second
  381. if err := checkIfInstallable(conf.Chart); err != nil {
  382. return nil, err
  383. }
  384. var err error
  385. cmd.PostRenderer, err = NewPorterPostrenderer(
  386. conf.Cluster,
  387. conf.Repo,
  388. a.K8sAgent,
  389. conf.Namespace,
  390. conf.Registries,
  391. doAuth,
  392. disablePullSecretsInjection,
  393. )
  394. if err != nil {
  395. return nil, err
  396. }
  397. if req := conf.Chart.Metadata.Dependencies; req != nil {
  398. for _, dep := range req {
  399. depChart, err := loader.LoadChartPublic(dep.Repository, dep.Name, dep.Version)
  400. if err != nil {
  401. return nil, fmt.Errorf("error retrieving chart dependency %s/%s-%s: %s", dep.Repository, dep.Name, dep.Version, err.Error())
  402. }
  403. conf.Chart.AddDependency(depChart)
  404. }
  405. }
  406. return cmd.Run(conf.Name, conf.Chart, conf.Values)
  407. }
  408. // UninstallChart uninstalls a chart
  409. func (a *Agent) UninstallChart(
  410. name string,
  411. ) (*release.UninstallReleaseResponse, error) {
  412. cmd := action.NewUninstall(a.ActionConfig)
  413. return cmd.Run(name)
  414. }
  415. // RollbackRelease rolls a release back to a specified revision/version
  416. func (a *Agent) RollbackRelease(
  417. name string,
  418. version int,
  419. ) error {
  420. cmd := action.NewRollback(a.ActionConfig)
  421. cmd.Version = version
  422. return cmd.Run(name)
  423. }
  424. // ------------------------ Helm agent helper functions ------------------------ //
  425. // checkIfInstallable validates if a chart can be installed
  426. // Application chart type is only installable
  427. func checkIfInstallable(ch *chart.Chart) error {
  428. switch ch.Metadata.Type {
  429. case "", "application":
  430. return nil
  431. }
  432. return errors.Errorf("%s charts are not installable", ch.Metadata.Type)
  433. }