Skip to content

POC: render-based drift detection via template digest - #1595

Open
cwrau wants to merge 1 commit into
fluxcd:mainfrom
cwrau:poc/template-digest-drift-render
Open

cwrau wants to merge 1 commit into
fluxcd:mainfrom
cwrau:poc/template-digest-drift-render

Conversation

@cwrau

@cwrau cwrau commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Not a fix, not meant to be merged. Just poking at the size of the idea from #1583, since the "mountain of complexity" pushback deserved a sanity check.

What this does

Adds an opt-in driftDetection.mode: enabledWithRender. When set, every reconciliation does a helm upgrade --dry-run=server re-render (so lookup evaluates against live cluster state, same as a real upgrade would), hashes the resulting manifest, and compares it against a new status.observedTemplateDigest. A mismatch routes into the existing OutOfSync state, so correction goes through a normal AtomicRelease upgrade, nothing new there.

What's deliberately left out

  • Tests. Zero added.
  • make generate manifests api-docs — didn't regen CRDs/docs, a single string field doesn't need it to compile, but a real PR would need it committed.
  • Envtest validation — no etcd/kube-apiserver binaries handy locally, so this is "it builds and vets clean," not "verified end-to-end against a real API server."
  • Edge cases: first-reconcile bootstrap (empty digest forces one extra upgrade, same quirk the existing post-renderer digest check already has), Install-path wiring.

Diff

5 files, ~114 lines. Core mechanism is one new function (RenderTemplateDigest) plus wiring into the existing digest-comparison block in state.go.

Marked PROOF OF CONCEPT in the code itself, happy to close this out once it's served its purpose.

🤖 Generated with Claude Code

Sizes the design discussed for detecting drift caused by Helm's
lookup function: a live re-render digest compared against the digest
of the last real release, reusing the existing OutOfSync path instead
of a new diffing mechanism. Tests intentionally omitted, this is only
meant to gauge the size of the change.

Signed-off-by: Chris Werner Rau <cwrau@cwrau.info>
Assisted-by: Claude Code/claude-sonnet-5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant