From c11145a90e28935f497a4b9631fa89a61b21a793 Mon Sep 17 00:00:00 2001 From: Simon Koudijs Date: Tue, 6 Oct 2026 05:54:20 +0000 Subject: [PATCH] docs(upgrading): say which kustomize panics on an invalid images: name The entry said kustomize panics inside the build on `- name: "ngin["`. Since kustomize api v0.21.2, which the analyzer now builds with, it treats an uncompilable name as matching nothing instead. Flux's kustomize-controller still pins v0.21.1 and still panics. The refusal is unchanged; the entry now gives the reason that holds for both. Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/UPGRADING.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/UPGRADING.md b/docs/UPGRADING.md index 6d6cb31d..041a945f 100644 --- a/docs/UPGRADING.md +++ b/docs/UPGRADING.md @@ -2348,11 +2348,12 @@ controller could deploy: refused: nothing was built, nothing failed, and the folder passed. It is now built, and kustomize says *"cycle detected"*; - an `images:` entry whose `name:` is not a valid **regular expression** — `- name: "ngin["`. - A kustomization `name:` is a regex, not a literal string, and kustomize compiles it without - checking the compile error, so such an entry does not fail the build, it **panics** inside - it. We refuse the folder before the build rather than hand it over. (Note the corollary, - which is not new but is easy to miss: `- name: "ngin."` **matches** `nginx`, because it is - a regex.) + A kustomization `name:` is a regex, not a literal string. Kustomize up to api v0.21.1, the + version Flux's kustomize-controller builds with, compiles it without checking the compile + error and **panics** inside the build; from v0.21.2 it treats the name as matching nothing. + Either way the entry does not do what it says, so we refuse the folder before the build. + (Note the corollary, which is not new but is easy to miss: `- name: "ngin."` **matches** + `nginx`, because it is a regex.) **Why this is a safety fix, not just strictness.** The override chain, and therefore the write-fan-in guard, is derived from the render. A root that does not build yields no chain,