feat(helm): native Helm server-side apply conflict control @aknysh (#3252)
## what- Expose two Helm 4 server-side apply controls on native Helm components:
server_side_apply(auto|true|false) - selects the apply method.force_conflicts(boolean, opt-in, default off) - resolves field-ownership conflicts by overwriting the contested fields and becoming their sole manager.
- Settable on the release-wide
releasepolicy and on the per-phaseinstall/upgradeblocks (rejected ondelete, which has no server-side apply surface). - Add
--server-side-apply(bare value selectstrue) and--force-conflictsflags to theapplyanddeployoperations. - Resolve both through the existing release-policy path: built-in default (unset) → release-wide → per-phase → CLI flag, validated before any chart download or cluster mutation.
- Plumb to the Helm 4 actions honoring the shape difference (
action.Install.ServerSideApplyis a bool;action.Upgrade.ServerSideApplyis a string). When unset, Atmos sets nothing, so behavior is byte-for-byte unchanged. - Model both keys in the manifest and stack-config JSON schemas.
- Docs, blog post, and roadmap milestone added; PRD marked Implemented.
why
- Helm 4 applies releases with Kubernetes server-side apply by default, where every field of a managed object is owned by a field manager. An apply that writes a field already owned by a different manager - a controller reconciling the same object, or an object whose
managedFieldsledger was orphaned - fails with a conflict. - Atmos set no conflict-resolution option, so the only remedy was out-of-band cluster surgery (
kubectl apply --server-side --force-conflictsor hand-editingmanagedFields) followed by a re-run. That breaks dependency-ordered rollouts and cannot be remediated in CI. - Enabling
force_conflictsclears the conflict through the normalatmos helm applypath, so the release reaches a successful state and its dependents proceed. It is opt-in because forcing overrides other field managers, so the default leaves conflicts fatal and visible.
references
- PRD:
docs/prd/native-helm-force-conflicts.md - Docs: native Helm release lifecycle
- Kubernetes Server-Side Apply: conflicts and field management
- Builds on #2667 (native Helm release lifecycle)
Summary by CodeRabbit
Summary by CodeRabbit
- New Features
- Configure Helm server-side apply as
auto,true, orfalsein release, install, and upgrade settings. - Use
--server-side-applyand the opt-in--force-conflictsflags withapplyanddeploy; CLI options override stack settings. - Allow forced resolution of server-side apply conflicts, which can transfer field ownership. Without it, conflicts remain errors.
- Configure Helm server-side apply as
- Bug Fixes
- Reject incompatible settings, such as enabling forced conflicts while explicitly disabling server-side apply.
- Documentation
- Added guidance and examples for configuring server-side apply and conflict handling.