fix(setup): the workload-ns SMTP mirror must carry the target namespace

'smtpSecretManifest' hardcoded namespace=felis, so the 'configure email'
refresh of the minecraft-namespace copies failed before it began: kubectl
refuses a manifest whose namespace conflicts with -n (found live: 'the
namespace from the provided object "felis" does not match the namespace
"minecraft"'), and the felis-config mirror never ran at all because the
smtp apply returned early. A later SMTP change could therefore never reach
the reaper's pre-reap warnings — the exact failure the refresh was added to
close.

Render the Secret with the caller's namespace (felis for the control-plane
apply, the workload namespace for the mirror). Regression test pins both.
This commit is contained in:
Lemon-miaow committed 2026-09-23 04:42:59 +08:00
1 parent 311b1a7ec4
commit ed722d55f8
2 files changed
+49 -8

No files matched your search

+37
View File
@@ -0,0 +1,37 @@
package main
import (
"strings"
"testing"
"sigs.k8s.io/yaml"
)
// TestSMTPSecretManifestCarriesTargetNamespace pins the fix for the
// workload-namespace replica: kubectl refuses a manifest whose namespace
// conflicts with -n ("the namespace from the provided object ... does not
// match"), so the mirror must render felis-smtp with the TARGET namespace —
// otherwise the "configure email" refresh fails on the first apply and the
// felis-config mirror never runs at all.
func TestSMTPSecretManifestCarriesTargetNamespace(t *testing.T) {
for _, ns := range []string{"felis", "minecraft"} {
b, err := smtpSecretManifest("pw", ns)
if err != nil {
t.Fatalf("render for %s: %v", ns, err)
}
var got struct {
Metadata struct {
Namespace string `json:"namespace"`
} `json:"metadata"`
}
if err := yaml.Unmarshal(b, &got); err != nil {
t.Fatalf("unmarshal for %s: %v", ns, err)
}
if got.Metadata.Namespace != ns {
t.Fatalf("manifest namespace = %q, want %q", got.Metadata.Namespace, ns)
}
if !strings.Contains(string(b), "name: felis-smtp") {
t.Fatalf("manifest must still name felis-smtp: %s", b)
}
}
}