Skip to content

BUG: VMRule CRD injects empty record: "" / alert: "" into every rule #2622

Description

@AquaOctet

Describe the bug

Rule.Record and Rule.Alert in api/operator/v1beta1/vmrule_types.go carry +kubebuilder:default="".

The API server injects the empty counterpart field into every stored rule: alerting rules get record: "", recording rules get alert: "".

The applied manifest never contains these fields, so the live object never matches the source of truth. Diff-based GitOps tooling (Argo CD and equivalents) reports every application owning a VMRule as permanently OutOfSync.

Why the defaults are no longer needed

With the list-map keys gone, nothing requires the defaults — they are residue, and their only remaining observable effect is the spurious diff.

Expected behavior

record and alert are omitempty optional fields. An applied VMRule should round-trip unchanged: no field the user did not set should appear on the stored object.

Version

First affected release is v0.73.0 (the markers are absent in v0.72.0) in v0.73.1, v0.74.0, v0.74.1 and v0.75.0-rc1, and on master.

Proposed fix

Drop +kubebuilder:default="" from Rule.Record and Rule.Alert, regen bundle. The doc comment on RuleGroup.Rules ("Rules are merged by record fields") is also stale after #2379 and can go in the same change.

Current workaround

Strip the defaults from the CRD bundle before applying, or add an ignoreDifferences entry in Argo CD for the field.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingwaiting for releaseThe change was merged to upstream, but wasn't released yet.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions