github cloudposse/atmos v1.231.0-rc.1

pre-release3 hours ago
feat(helm): native Helm server-side apply conflict control @aknysh (#3252) ## what
  • Expose two Helm 4 server-side apply controls on native Helm components:
    • server_side_apply (auto | true | false) - selects the apply method.
    • force_conflicts (boolean, opt-in, default off) - resolves field-ownership conflicts by overwriting the contested fields and becoming their sole manager.
  • Settable on the release-wide release policy and on the per-phase install / upgrade blocks (rejected on delete, which has no server-side apply surface).
  • Add --server-side-apply (bare value selects true) and --force-conflicts flags to the apply and deploy operations.
  • Resolve both through the existing release-policy path: built-in default (unset) → release-wide → per-phase → CLI flag, validated before any chart download or cluster mutation.
  • Plumb to the Helm 4 actions honoring the shape difference (action.Install.ServerSideApply is a bool; action.Upgrade.ServerSideApply is a string). When unset, Atmos sets nothing, so behavior is byte-for-byte unchanged.
  • Model both keys in the manifest and stack-config JSON schemas.
  • Docs, blog post, and roadmap milestone added; PRD marked Implemented.

why

  • Helm 4 applies releases with Kubernetes server-side apply by default, where every field of a managed object is owned by a field manager. An apply that writes a field already owned by a different manager - a controller reconciling the same object, or an object whose managedFields ledger was orphaned - fails with a conflict.
  • Atmos set no conflict-resolution option, so the only remedy was out-of-band cluster surgery (kubectl apply --server-side --force-conflicts or hand-editing managedFields) followed by a re-run. That breaks dependency-ordered rollouts and cannot be remediated in CI.
  • Enabling force_conflicts clears the conflict through the normal atmos helm apply path, so the release reaches a successful state and its dependents proceed. It is opt-in because forcing overrides other field managers, so the default leaves conflicts fatal and visible.

references

Summary by CodeRabbit

Summary by CodeRabbit

  • New Features
    • Configure Helm server-side apply as auto, true, or false in release, install, and upgrade settings.
    • Use --server-side-apply and the opt-in --force-conflicts flags with apply and deploy; CLI options override stack settings.
    • Allow forced resolution of server-side apply conflicts, which can transfer field ownership. Without it, conflicts remain errors.
  • Bug Fixes
    • Reject incompatible settings, such as enabling forced conflicts while explicitly disabling server-side apply.
  • Documentation
    • Added guidance and examples for configuring server-side apply and conflict handling.

Don't miss a new atmos release

NewReleases is sending notifications on new releases.