Repository navigation
fix(deploy): run kubectl plugins only through kubectl - #409
Merged
alexey-igrychev merged 2 commits intoOct 7, 2026
Merged
Conversation
…n other commands `werf kubectl` passed the whole werf argv to kubectl's plugin lookup. kubectl builds the plugin name from every word after the binary, so the lookup searched PATH for kubectl-kubectl-<name> and `werf kubectl argo rollouts` never found kubectl-argo-rollouts. The lookup also runs while the command tree is built, on every werf invocation, so `werf <name>` executed a kubectl-<name> binary from PATH instead of the werf command. Pass the lookup only the arguments after the kubectl command path, including the WERF_SELF_INVOCATION_COMMAND prefix of an embedding binary such as `d8 dk kubectl`. Any other command passes no arguments, which disables the lookup. Signed-off-by: Yuriy Losev <yuriy.losev@flant.com>
Exercise NewCmd in subprocesses with isolated plugin executables so reverting its argument wiring fails regression tests. Preserve the v2 kubectl exact-name lookup for create plugins and keep test helpers consistent with repository conventions. Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
werf kubectl and ignore them in other commands
Collaborator
|
Review and verification at c14808b:
Limitations: full task format/task lint cannot complete their Docker-based Prettier step because the local Docker daemon is unavailable. The selected Docker build e2e also fails for that missing daemon; it is not reported as passing. Windows execution and the real embedding application were not exercised. External CI/environment blockers are excluded from merge gating at the maintainer's explicit request. |
alexey-igrychev
added a commit
that referenced
this pull request
Oct 8, 2026
🤖 I have created a release *beep* *boop* --- ## [2.81.3-dk.1](v2.81.1-dk.1...v2.81.3-dk.1) (2026-10-08) ### Bug Fixes * **build, stages:** make from:scratch images usable by buildah builds ([werf#8025](https://github.com/deckhouse/delivery-kit/issues/8025)) ([cbd1157](cbd1157)) * **build:** prevent intermittent Buildah initialization failures ([werf#8039](https://github.com/deckhouse/delivery-kit/issues/8039)) ([5ba0d9d](5ba0d9d)) * **build:** stop rejecting initialized nested submodules ([werf#8037](https://github.com/deckhouse/delivery-kit/issues/8037)) ([d139887](d139887)) * **deploy:** preserve kubectl env defaults and command syntax ([werf#8035](https://github.com/deckhouse/delivery-kit/issues/8035)) ([cca9f53](cca9f53)) * **deploy:** run kubectl plugins only through kubectl ([#409](#409)) ([dd6d573](dd6d573)) * **deploy:** run kubectl plugins only through kubectl ([werf#8031](https://github.com/deckhouse/delivery-kit/issues/8031)) ([b860ae9](b860ae9)) * **giterminism:** preserve user worktrees in dev mode ([werf#8043](https://github.com/deckhouse/delivery-kit/issues/8043)) ([dc4360b](dc4360b)) * **host-cleanup:** reclaim abandoned tmp data from older releases ([werf#8029](https://github.com/deckhouse/delivery-kit/issues/8029)) ([dfc2aed](dfc2aed)) ### Miscellaneous Chores * **release:** force release 2.81.3-dk.1 ([0f8f56d](0f8f56d)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backport of #408 to
2. Withkubectl-argo-rolloutson PATH,werf kubectl argo rollouts get rollout demonow runs the plugin withget rollout demo. Commands outsidewerf kubectlno longer execute kubectl plugins while constructing the command tree.What
kubectlcommand prefix and preserves plugin arguments.WERF_SELF_INVOCATION_COMMAND=dk, the embedding invocationd8 dk kubectl argo rollouts getrunskubectl-argo-rollouts get; commands outside that path do not trigger lookup.create:werf kubectl create hellocan runkubectl-create-hello, butcreate hello demolooks forkubectl-create-hello-demoinstead of passingdemoto the shorter plugin name.Why
Kubectl expects the binary name followed by its own command arguments, but werf passed its entire argument vector. The extra command prefix prevented intended plugin lookup, while eager command construction could execute a plugin for an unrelated werf command.