Skip to content

ci: decouple chart version from the deployed image version - #63

Draft
me-bender[bot] wants to merge 1 commit into
mainfrom
bender/chart-version-unlink
Draft

me-bender[bot] wants to merge 1 commit into
mainfrom
bender/chart-version-unlink

Conversation

@me-bender

@me-bender me-bender Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Decouple the chart version from the deployed image version

The Bump Version workflow set Chart.yaml's .version to the dispatch
input — the same value used for the deployed image tags. That tied the
chart's own version to the image version it ships, so the two could never
share a number without colliding.

This change separates the two:

  • Image tags in charts/lunar/values.yaml (hub, operator,
    operator.initImage, operator.sidecarImage, grafana) still follow the
    dispatch input — they point at the image version being deployed.
  • Chart.yaml .version now auto-bumps its own patch on each run,
    independent of the input. A bump that only re-points the deployed image is,
    by definition, a chart patch.

The image release can still trigger this bump automatically; the two version
lines are simply no longer linked. A run logs Chart X.Y.Z -> X.Y.(Z+1)
alongside the image version it set.

Notes

  • The release branch / PR title / commit now key off the chart version
    (release/chart-<version>), not the input.
  • If the current Chart.yaml version isn't X.Y.Z, the workflow fails fast
    rather than guessing a bump.

Keep the image tags following the dispatch input while the chart auto-bumps
its own patch, so the chart version and the deployed component version are
independent.
@me-bender
me-bender Bot requested a review from brandonSc June 25, 2026 11:58
@lunar-internal

lunar-internal Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

🌒 Earthly Lunar

✅ 16 Passing

The checks marked as (🔀 required) need to pass before merging is allowed.

  • ✅ max-severity sca-critical.max-severity - Ensures no findings at or above the configured severity threshold.
    Configure min_severity to set the threshold (critical, high, medium, low).
    (🔀 required)

  • ✅ branch-protection-enabled vcs.branch-protection-enabled - Requires branch protection rules to be enabled on the default branch.
    Branch protection is the foundation for all other VCS security controls.

  • ✅ build-tagged container.build-tagged - Requires container builds to use an explicit image tag via -t/--tag.
    Untagged builds produce anonymous images that cannot be tracked or deployed.

13 more...
  • ✅ changelog-exists changelog.changelog-exists - Verifies that a CHANGELOG file exists in the repository root. Detects
    common variants (CHANGELOG.md, CHANGELOG, CHANGES.md, HISTORY.md,
    RELEASES.md). Intended for repos that ship versioned releases — apply
    via lunar-config on: targeting (e.g. public-only) rather than blanketly.
    Reads from .repo.changelog.

  • ✅ codeowners-catchall repo-hygiene.codeowners-catchall - Requires a default catch-all rule (*) in CODEOWNERS so that every file
    in the repository has at least one owner.

  • ✅ codeowners-exists repo-hygiene.codeowners-exists - Requires a CODEOWNERS file to be present in the repository.
    Checks standard locations: root, .github/, or docs/.

  • ✅ codeowners-valid repo-hygiene.codeowners-valid - Validates that the CODEOWNERS file has correct syntax.
    Checks that all owner references use valid formats (@user, @org/team, or email).

  • ✅ disallow-force-push vcs.disallow-force-push - Prohibits force pushes to protected branches to preserve commit history.
    Force pushes can destroy audit trails and cause data loss.

  • ✅ executed sca.executed - Verifies that SCA scanning was executed on the component.
    Fails if no scanner has written to .sca.

  • ✅ instruction-file-exists ai.instruction-file-exists - Verifies that an agent instruction file exists at the repository root. Checks
    ai.instructions.all[] which is populated by the ai collector (AGENTS.md) and
    tool-specific collectors via array append (CLAUDE.md, CODEX.md, GEMINI.md).
    Passes if any entry exists.

  • ✅ max-severity sca-high.max-severity - Ensures no findings at or above the configured severity threshold.
    Configure min_severity to set the threshold (critical, high, medium, low).

  • ✅ no-latest container.no-latest - Prevents use of the :latest tag (explicit or implicit) in base images.
    Using :latest creates non-reproducible builds and makes debugging difficult.

  • ✅ readme-exists repo-hygiene.readme-exists - Verifies that a README file exists in the repository root.
    Every repository should have basic documentation for discoverability.

  • ✅ require-default-branch vcs.require-default-branch - Validates the default branch name matches the required name (default "main").
    Helps standardize branch naming across repositories.

  • ✅ require-pull-request vcs.require-pull-request - Requires all changes to go through pull requests before merging.
    Prevents direct pushes to protected branches without review.

  • ✅ stable-tags container.stable-tags - Requires base images to use stable tags: digests (sha256:...) or full semver (1.2.3).
    Partial versions like "node:20" can change unexpectedly and break builds.

More Details

@brandonSc

Copy link
Copy Markdown
Contributor

Bender do we still need this?

@me-bender

me-bender Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Short answer: only if you still want the chart version actually independent of the deployed image version.

Where things stand:

  • The release-side validation that used to block a release when a same-version chart tag existed has already been removed upstream — so releases aren't blocked anymore.
  • But main's bump-and-pr.yml still sets chart .version = the deployed image version. Grafana: deploy to external server #76 (July 11) re-touched this workflow and now documents the two as "kept in lockstep" — i.e. main currently treats coupled versions as intended.
  • This PR is the only thing that makes the chart self-version (auto-bump its own patch, independent). It's gone stale in the meantime: it now conflicts with main and would need a rebase to land.

My take: the blocking problem is already solved, and main now documents lockstep as intentional — so unless you specifically want independent chart versioning, this is superseded and I'd close it. Say the word and I'll close it; if you'd rather keep the decouple, I'll rebase and reconcile it against #76.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant