Skip to content

feat(crunchy): stop after helm when dry_run is set - #70

Merged
DerekRoberts merged 2 commits into
mainfrom
feat/crunchy-dry-run
Oct 1, 2026
Merged

DerekRoberts merged 2 commits into
mainfrom
feat/crunchy-dry-run

Conversation

@DerekRoberts

@DerekRoberts DerekRoberts commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

A hidden DEBUG_MODE dry-run still waited for the database and patched PR users, so validation crashed.

dry_run runs helm upgrade --dry-run=server --hide-secret --install and exits 0 before the ready check. Server-side dry-run submits the chart for API checks. Secret resources are omitted from the output. It still renders when triggers would skip an already-deployed release, and it does not self-heal (that path deletes the PostgresCluster). The add-user and remove-user steps are skipped. A failed helm dry-run still fails the script.

Closes #58

A hidden DEBUG_MODE dry-run still waited for the database and patched PR users, so validation crashed. dry_run validates with helm and exits before those steps.

Closes #58
Copilot AI balanced review requested due to automatic review settings October 1, 2026 10:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Helm command neither performs the promised server-side validation nor prevents rendered S3 secrets from reaching logs.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds a first-class Crunchy database dry-run mode that renders Helm resources without deployment or user changes.

Changes:

  • Adds and documents the dry_run input.
  • Skips deployment side effects and readiness checks.
  • Adds tests for dry-run behavior and failures.
File Description
crunchy/​scripts/​deploy_db.sh Implements dry-run execution and early exit.
crunchy/​action.yml Wires the input and skips user changes.
crunchy/​README.md Documents dry-run behavior.
.github/​tests/​crunchy/​deploy_db.bats Tests dry-run paths.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread crunchy/scripts/deploy_db.sh Outdated
Comment thread crunchy/scripts/deploy_db.sh Outdated
--dry-run=server submits the chart for API checks. --hide-secret omits Secret resources from the output. --debug is omitted because it prints user-supplied values.
@DerekRoberts DerekRoberts self-assigned this Oct 1, 2026
@DerekRoberts
DerekRoberts merged commit bcf3f57 into main Oct 1, 2026
12 checks passed
@DerekRoberts
DerekRoberts deleted the feat/crunchy-dry-run branch October 1, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

feat: implement a fully-functional dry_run validation input

2 participants