Description
When I add a ServiceTemplate which has a failing k8s constraint to a CD, I expect validation to fail but it does not.
The validation only fails if I set --enable-webhook=false. This case also has a bug see [bug] k8s constraint ineffective #2304 for details.
Expected
I was expecting the validation to fail even for the default --enable-webhook=true case.
Steps to Reproduce
Create a ClusterTemplate with .spec.k8sVersion=v1.32.8.
Now create a CD with this ClusterTemplate and wait for it to successfully provision.
Now create a ServiceTemplate with spec.k8sConstraint="<v1.30" so that it fails the ClusterTemplate's k8s version.
❌ Even though the k8s constraint should fail, the CD's status shows no validation failure and the service is successfully deployed on the target cluster:
➜ ~ kubectl -n kcm-system get clusterdeployment wali-dev-1 -o yaml
apiVersion: k0rdent.mirantis.com/v1beta1
kind: ClusterDeployment
metadata:
annotations:
kubectl.kubernetes.io/last-applied-configuration: |
{" apiVersion" :" k0rdent.mirantis.com/v1beta1" ," kind" :" ClusterDeployment" ," metadata" :{" annotations" :{}," labels" :{" owner" :" dev-team" }," name" :" wali-dev-1" ," namespace" :" kcm-system" }," spec" :{" config" :{" clusterIdentity" :{" name" :" aws-cluster-identity" ," namespace" :" kcm-system" }," controlPlane" :{" amiID" :" ami-0eb9fdcf0d07bd5ef" ," instanceProfile" :" control-plane.cluster-api-provider-aws.sigs.k8s.io" ," instanceType" :" t3.small" }," controlPlaneNumber" :1," publicIP" :true," region" :" ca-central-1" ," worker" :{" amiID" :" ami-0eb9fdcf0d07bd5ef" ," instanceProfile" :" nodes.cluster-api-provider-aws.sigs.k8s.io" ," instanceType" :" t3.small" }," workersNumber" :1}," credential" :" aws-cluster-identity-cred" ," serviceSpec" :{" provider" :{" name" :" ksm-projectsveltos" }," services" :[{" name" :" nginx" ," namespace" :" nginx" ," template" :" ingress-nginx-4-13-0" }]}," template" :" aws-standalone-cp-1-0-20-dev" }}
creationTimestamp: " 2025-12-23T19:45:33Z"
finalizers:
- k0rdent.mirantis.com/cluster-deployment
generation: 2
labels:
k0rdent.mirantis.com/component: kcm
owner: dev-team
name: wali-dev-1
namespace: kcm-system
resourceVersion: " 17449"
uid: ba1f3d0d-569d-4794-b10d-1bcaea204bb1
spec:
config:
clusterIdentity:
name: aws-cluster-identity
namespace: kcm-system
controlPlane:
amiID: ami-0eb9fdcf0d07bd5ef
instanceProfile: control-plane.cluster-api-provider-aws.sigs.k8s.io
instanceType: t3.small
controlPlaneNumber: 1
publicIP: true
region: ca-central-1
worker:
amiID: ami-0eb9fdcf0d07bd5ef
instanceProfile: nodes.cluster-api-provider-aws.sigs.k8s.io
instanceType: t3.small
workersNumber: 1
credential: aws-cluster-identity-cred
ipamClaim: {}
propagateCredentials: true
serviceSpec:
continueOnError: false
priority: 100
provider:
name: ksm-projectsveltos
services:
- name: nginx
namespace: nginx
template: ingress-nginx-4-13-0
stopOnConflict: false
syncMode: Continuous
template: aws-standalone-cp-1-0-20-dev
status:
conditions:
- lastTransitionTime: " 2025-12-23T19:45:33Z"
message: " "
observedGeneration: 2
reason: Succeeded
status: " True"
type: CredentialReady
- lastTransitionTime: " 2025-12-23T19:45:35Z"
message: Helm install succeeded for release kcm-system/wali-dev-1.v1 with chart
aws-standalone-cp@1.0.20
reason: InstallSucceeded
status: " True"
type: HelmReleaseReady
- lastTransitionTime: " 2025-12-23T19:45:33Z"
message: " "
observedGeneration: 2
reason: Succeeded
status: " True"
type: HelmChartReady
- lastTransitionTime: " 2025-12-23T19:45:33Z"
message: " "
observedGeneration: 2
reason: Succeeded
status: " True"
type: TemplateReady
- lastTransitionTime: " 2025-12-23T20:01:41Z"
message: Object is ready
reason: Succeeded
status: " True"
type: Ready
- lastTransitionTime: " 2025-12-23T19:45:33Z"
message: " "
observedGeneration: 2
reason: Succeeded
status: " True"
type: ClusterDataSourceReady
- lastTransitionTime: " 2025-12-23T20:01:41Z"
message: 1/1
reason: Succeeded
status: " True"
type: ServicesInReadyState
- lastTransitionTime: " 2025-12-23T19:51:20Z"
message: " "
observedGeneration: 2
reason: InfoReported
status: " True"
type: CAPIClusterSummary
k8sVersion: v1.32.8
observedGeneration: 2
services:
- lastStateTransitionTime: " 2025-12-23T20:01:41Z"
name: nginx
namespace: nginx
state: Deployed
template: ingress-nginx-4-13-0
type: Helm
version: 4.13.0
servicesUpgradePaths:
- availableUpgrades:
- versions:
- name: ingress-nginx-4-13-0
version: ingress-nginx-4-13-0
name: nginx
namespace: nginx
template: ingress-nginx-4-13-0
Description
--enable-webhook=false. This case also has a bug see [bug] k8s constraint ineffective #2304 for details.Expected
I was expecting the validation to fail even for the default
--enable-webhook=truecase.Steps to Reproduce
.spec.k8sVersion=v1.32.8.spec.k8sConstraint="<v1.30"so that it fails the ClusterTemplate's k8s version.