feat: roll HyperDX pods on config changes - #273
Open
bsosnader wants to merge 1 commit into
Open
Conversation
🦋 Changeset detectedLatest commit: fa92f63 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
bsosnader
force-pushed
the
brsosnad/investigate-values-only-checksums
branch
from
August 31, 2026 18:13
f7cf6b3 to
fa92f63
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Motivation
HyperDX consumes
clickstack-configandclickstack-secretthroughenvFrom. Kubernetes resolves those environment variables when a pod starts, so changing only the ConfigMap or Secret duringhelm upgradeleaves existing HyperDX pods with stale startup configuration unless the Deployment pod template also changes.This follows Helm's documented
include ... | sha256sumrollout pattern. The ConfigMap and Secret manifests now share canonical named renderers with the Deployment checksums, ensuring the hashed content cannot drift from the resources Helm applies.No new values API is needed: these are chart-managed resources with deterministic rollout behavior. Arbitrary template paths or
tplevaluation in user values would be less safe and would not improve this owned-resource case.Backward compatibility
Existing
hyperdx.deployment.annotationsandhyperdx.deployment.podAnnotationsvalues remain merged with the same precedence. The generatedchecksum/clickstack-configandchecksum/clickstack-secretkeys are chart-reserved and override caller values so stale hashes cannot disable rollouts.checksum/clickstack-secretis omitted whenhyperdx.secrets: null, matching Secret rendering andenvFrombehavior. Externally managed Secret changes still require an explicit rollout because Helm cannot hash resources it does not render.The first upgrade containing this change intentionally performs a one-time HyperDX rollout because the generated annotations are added to the pod template.
Tests
helm unittest -f tests/hyperdx-rollout-checksums_test.yaml charts/clickstackhelm unittest charts/clickstack— 31 suites, 257 testshelm lint --strict charts/clickstackgit diff --check