fix(helm): preserve STS serviceName + networkPolicy.egress back-compat

Greptile flagged two real upgrade-breaking changes vs the prior chart:

1. statefulset-postgresql spec.serviceName flipped from <name>-postgresql
   to <name>-postgresql-headless. spec.serviceName is immutable, so any
   existing install would hit 'Forbidden: updates to statefulset spec ...'
   on helm upgrade. Revert to the original name (the headless Service in
   services.yaml is added alongside, not as a swap).

2. networkPolicy.egress changed from a list to a map ({extraRules, exceptCidrs}),
   silently dropping any custom egress list set by existing users. Restore
   the original list semantics for networkPolicy.egress and move cloud-metadata
   blocking to a sibling top-level field networkPolicy.egressExceptCidrs.

Adds NOTES.txt upgrade-notes entry covering both + the ESO v1→v1beta1 default
flip (functionally a no-op, but worth surfacing).
This commit is contained in:
Waleed Latif
2026-05-12 13:45:30 -07:00
parent 05892f74f2
commit d5c2e8ef5d
5 changed files with 36 additions and 20 deletions
+10 -1
View File
@@ -81,7 +81,16 @@ Your release is named {{ .Release.Name }} in namespace {{ .Release.Namespace }}.
# Upgrade after changing values # Upgrade after changing values
helm upgrade {{ .Release.Name }} ./helm/sim --namespace {{ .Release.Namespace }} -f your-values.yaml helm upgrade {{ .Release.Name }} ./helm/sim --namespace {{ .Release.Namespace }} -f your-values.yaml
5. Where to go next: 5. Upgrade notes (read before upgrading from a chart version released before this one):
* externalSecrets.apiVersion default is "v1beta1" (was "v1"). v1beta1 is
supported by every ESO release from v0.7+ through current. If you're on
ESO v0.17+ and want the graduated v1 API, set externalSecrets.apiVersion: "v1".
* networkPolicy.egress remains a list of custom egress rules (unchanged).
Cloud-metadata CIDR blocking is now configured via networkPolicy.egressExceptCidrs
(defaults to AWS/GCP/Azure IMDS + ECS task metadata).
6. Where to go next:
* Production checklist: helm/sim/README.md (search "Production checklist") * Production checklist: helm/sim/README.md (search "Production checklist")
* Troubleshooting: helm/sim/README.md (search "Troubleshooting") * Troubleshooting: helm/sim/README.md (search "Troubleshooting")
+5 -5
View File
@@ -107,14 +107,14 @@ spec:
- ipBlock: - ipBlock:
cidr: 0.0.0.0/0 cidr: 0.0.0.0/0
except: except:
{{- range (default (list "169.254.169.254/32" "169.254.170.2/32") .Values.networkPolicy.egress.exceptCidrs) }} {{- range (default (list "169.254.169.254/32" "169.254.170.2/32") .Values.networkPolicy.egressExceptCidrs) }}
- {{ . | quote }} - {{ . | quote }}
{{- end }} {{- end }}
ports: ports:
- protocol: TCP - protocol: TCP
port: 443 port: 443
# Allow custom egress rules # Allow custom egress rules
{{- with .Values.networkPolicy.egress.extraRules }} {{- with .Values.networkPolicy.egress }}
{{- toYaml . | nindent 2 }} {{- toYaml . | nindent 2 }}
{{- end }} {{- end }}
@@ -189,14 +189,14 @@ spec:
- ipBlock: - ipBlock:
cidr: 0.0.0.0/0 cidr: 0.0.0.0/0
except: except:
{{- range (default (list "169.254.169.254/32" "169.254.170.2/32") .Values.networkPolicy.egress.exceptCidrs) }} {{- range (default (list "169.254.169.254/32" "169.254.170.2/32") .Values.networkPolicy.egressExceptCidrs) }}
- {{ . | quote }} - {{ . | quote }}
{{- end }} {{- end }}
ports: ports:
- protocol: TCP - protocol: TCP
port: 443 port: 443
# Allow custom egress rules # Allow custom egress rules
{{- with .Values.networkPolicy.egress.extraRules }} {{- with .Values.networkPolicy.egress }}
{{- toYaml . | nindent 2 }} {{- toYaml . | nindent 2 }}
{{- end }} {{- end }}
{{- end }} {{- end }}
@@ -296,7 +296,7 @@ spec:
- ipBlock: - ipBlock:
cidr: 0.0.0.0/0 cidr: 0.0.0.0/0
except: except:
{{- range (default (list "169.254.169.254/32" "169.254.170.2/32") .Values.networkPolicy.egress.exceptCidrs) }} {{- range (default (list "169.254.169.254/32" "169.254.170.2/32") .Values.networkPolicy.egressExceptCidrs) }}
- {{ . | quote }} - {{ . | quote }}
{{- end }} {{- end }}
ports: ports:
@@ -90,7 +90,12 @@ metadata:
labels: labels:
{{- include "sim.postgresql.labels" . | nindent 4 }} {{- include "sim.postgresql.labels" . | nindent 4 }}
spec: spec:
serviceName: {{ include "sim.fullname" . }}-postgresql-headless # Must remain {{ include "sim.fullname" . }}-postgresql (not the -headless
# name) — spec.serviceName is immutable on a StatefulSet, and the prior
# chart shipped with this value. Changing it would break `helm upgrade` for
# every existing install with `Forbidden: updates to statefulset spec ...`.
# The headless Service in services.yaml is added alongside, not as a swap.
serviceName: {{ include "sim.fullname" . }}-postgresql
replicas: 1 replicas: 1
minReadySeconds: 10 minReadySeconds: 10
podManagementPolicy: OrderedReady podManagementPolicy: OrderedReady
+2 -2
View File
@@ -128,10 +128,10 @@ tests:
- protocol: TCP - protocol: TCP
port: 3000 port: 3000
- it: egress.extraRules are appended to both app and realtime NetworkPolicies - it: networkPolicy.egress (custom rules) are appended to both app and realtime NetworkPolicies
set: set:
<<: *defaults <<: *defaults
networkPolicy.egress.extraRules: networkPolicy.egress:
- to: [] - to: []
ports: ports:
- protocol: TCP - protocol: TCP
+13 -11
View File
@@ -954,7 +954,7 @@ monitoring:
# to each other and to required external services (DNS, HTTPS) while blocking # to each other and to required external services (DNS, HTTPS) while blocking
# everything else. The egress block additionally blacklists cloud metadata # everything else. The egress block additionally blacklists cloud metadata
# endpoints (169.254.169.254/32, 169.254.170.2/32) by default — extend # endpoints (169.254.169.254/32, 169.254.170.2/32) by default — extend
# egress.exceptCidrs with your cluster's API server CIDR for tighter isolation. # egressExceptCidrs with your cluster's API server CIDR for tighter isolation.
# Your CNI must support NetworkPolicy (Calico, Cilium, GKE Dataplane V2, etc.). # Your CNI must support NetworkPolicy (Calico, Cilium, GKE Dataplane V2, etc.).
networkPolicy: networkPolicy:
enabled: false enabled: false
@@ -973,16 +973,18 @@ networkPolicy:
# Custom ingress rules appended to the policy # Custom ingress rules appended to the policy
ingress: [] ingress: []
# Egress configuration # Custom egress rules appended to the policy.
egress: # Kept as a top-level list (not a map) for backward compatibility with the
# CIDRs excluded from broad HTTPS (443) egress. # pre-1.0 chart that shipped `networkPolicy.egress: []`. Existing values
# Defaults block AWS/GCP/Azure IMDS (169.254.169.254/32) and ECS task metadata # files continue to work without changes.
# (169.254.170.2/32). Add your cluster's API server CIDR for stronger isolation. egress: []
exceptCidrs:
- "169.254.169.254/32" # CIDRs excluded from broad HTTPS (443) egress.
- "169.254.170.2/32" # Defaults block AWS/GCP/Azure IMDS (169.254.169.254/32) and ECS task metadata
# Custom egress rules appended to the policy # (169.254.170.2/32). Add your cluster's API server CIDR for stronger isolation.
extraRules: [] egressExceptCidrs:
- "169.254.169.254/32"
- "169.254.170.2/32"
# Shared storage for enterprise workflows requiring data sharing between pods # Shared storage for enterprise workflows requiring data sharing between pods
sharedStorage: sharedStorage: