Skip to content

feat: Deploy a function from a git repository without a local copy - #4064

Draft
gauron99 wants to merge 3 commits into
knative:mainfrom
gauron99:push-zwpsoszkmytz
Draft

gauron99 wants to merge 3 commits into
knative:mainfrom
gauron99:push-zwpsoszkmytz

Conversation

@gauron99

@gauron99 gauron99 commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Changes

  • 🎁 func deploy --remote --source <url> reads the function from the repository in memory and no longer needs a local copy of it. --revision (or <url>#<revision>) and --source-dir select the revision and directory to read it from.
  • 🎁 Add fn.NewFunctionFromGit, which loads a function from a git repository at a branch, tag or full commit hash with a depth-one fetch into memory: nothing is checked out or written to disk. The function has no Root and carries the commit it was read at (Build.Source.Commit, in memory only). Library users such as the operator can use it the same way.
  • 🐛 The cluster builds exactly the commit the function was read at, not whatever the branch points to by then, and labels the image with it.
  • 🧹 A deployment by reference writes nothing locally: neither func.yaml nor the build stamp. To change such a function, clone the repository, edit it and deploy the working tree.
  • 🧹 The function is deployed as configured by the func.yaml committed in the repository. Of the flags which configure a function only --builder, --registry, --registry-insecure and --namespace apply (flag or environment variable). --namespace must match the namespace the committed func.yaml names, if any. Any other such flag, and --confirm, is an error instead of being silently ignored by the cluster.
  • 🧹 Only a repository given with --source or FUNC_SOURCE is deployed by reference. One set in the local func.yaml (build.source) is built with the local function's settings, as before.
  • 🧹 Migrations take the serialized function instead of re-reading func.yaml from f.Root, so a function without a Root can be migrated, and is never migrated from the func.yaml of the current directory. Validate no longer requires a Root; Write does.
  • 🧹 The remote e2e tests deploy from an empty directory instead of cloning the repository first.

/kind enhancement
Fixes #3203

func deploy --remote --source <url> no longer needs a local copy of the function: it reads the function from the repository (at --revision and in --source-dir) and the cluster builds the commit it read.
Action required: such a deployment writes nothing locally, deploys the function as configured by the func.yaml committed in the repository, and accepts only `--builder`, `--registry`, `--registry-insecure` and `--namespace` of the flags which configure a function. Other flags such as `--env` or `--deployer`, and `--confirm`, are rejected: set them in the repository's func.yaml. A repository set in the local func.yaml (`build.source`) keeps the previous behaviour.

@knative-prow

knative-prow Bot commented Sep 24, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@knative-prow knative-prow Bot added kind/enhancement Feature additions or improvements to existing do-not-merge/work-in-progress 🤖 PR should not merge because it is a work in progress. labels Sep 24, 2026
@gauron99
gauron99 requested a balanced review from Copilot September 24, 2026 21:37
@knative-prow knative-prow Bot added the size/XXL 🤖 PR changes 1000+ lines, ignoring generated files. label Sep 24, 2026
@knative-prow

knative-prow Bot commented Sep 24, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: gauron99

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prow knative-prow Bot added the approved 🤖 PR has been approved by an approver from all required OWNERS files. label Sep 24, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The remote path bypasses required validation, and legal quoted Git refs can produce malformed Tekton YAML.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Enables remote deployment directly from a Git repository without a local checkout.

Changes:

  • Loads and migrates func.yaml from a resolved Git commit in memory.
  • Pins Tekton builds to that commit and avoids local writes.
  • Restricts applicable deployment flags and expands unit/E2E coverage.
File Description
pkg/​testing/​testing.go Adds Git repository test fixture.
pkg/​pipelines/​tekton/​templates.go Pins pipeline revision and supports rootless functions.
pkg/​pipelines/​tekton/​templates_test.go Tests rootless templates and revisions.
pkg/​pipelines/​tekton/​templates_s2i.go Quotes S2I Git revisions.
pkg/​pipelines/​tekton/​templates_pack.go Quotes Pack Git revisions.
pkg/​pipelines/​tekton/​pipelines_provider.go Validates rootless source availability.
pkg/​functions/​function.go Decouples validation from filesystem roots.
pkg/​functions/​function_source.go Records the resolved commit in memory.
pkg/​functions/​function_migrations.go Migrates from serialized YAML bytes.
pkg/​functions/​function_git.go Implements in-memory Git loading.
pkg/​functions/​function_git_test.go Tests revisions, directories, and migrations.
pkg/​functions/​client.go Reuses loaded bytes during migration.
e2e/​e2e_remote_test.go Removes local checkout requirements.
docs/​reference/​func_deploy.md Documents deployment-by-reference behavior.
cmd/​deploy.go Adds the rootless remote deployment path.
cmd/​deploy_test.go Covers flags, defaults, and no-write behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread cmd/deploy.go
Comment thread pkg/pipelines/tekton/templates_pack.go Outdated
Comment thread pkg/pipelines/tekton/templates_s2i.go Outdated
@gauron99
gauron99 requested review from lkingland and a balanced review from Copilot and removed request for dsimansk and jrangelramos September 25, 2026 07:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Local state can still affect or be mutated by reference deployments, and multi-branch fixtures advertise the wrong default branch.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
Resolved since last review (3)

Comment thread cmd/deploy.go
Comment thread cmd/deploy.go Outdated
Comment on lines +1080 to +1082
// The client is configured by cfg, whose defaults came from the current
// directory.
cfg.Builder, cfg.Registry, cfg.RegistryInsecure = f.Build.Builder, f.Registry, f.RegistryInsecure
Comment thread pkg/testing/testing.go
git(work, "checkout", "-q", "-b", name, "main")
heads[name] = commit(branches[name], name)
}
git(root, "clone", "-q", "--bare", work, "repository.git")
@knative-prow-robot knative-prow-robot added the needs-rebase Cannot be merged due to conflicts with HEAD. label Sep 28, 2026
fn.NewFunctionFromGit reads the func.yaml at a revision (branch, tag or
full commit hash) of a git repository into memory: a depth-one fetch
into go-git memory storage, nothing on disk. The function has no Root.
Its Build.Source is where it was read from, and Build.Source.Commit
(in memory only, never stored) the commit the revision resolved to.

Migrations now take the serialized function instead of re-reading
func.yaml from f.Root: a function without a Root could otherwise not be
migrated, or would be migrated from the func.yaml of the current
directory. Migrate still reads f.Root, so NewFunction is unchanged.

A function read from git is parsed more strictly than NewFunction does:
a func.yaml which does not unmarshal cleanly is an error.

Validate no longer requires a Root, Write does.
A function read from its git repository has no Root. The pipeline
provider now requires a Root only to upload sources, and does not look
for Pipeline or PipelineRun overrides in a project directory it does
not have.

Such a function carries the commit it was read at. The cluster fetches
exactly that commit, not whatever the branch points to by then, and
labels the image with it. Without a Root, the label is no longer taken
from whatever repository func happens to run in. Anything else is
fetched and labelled as before.

The revision is quoted in the PipelineRun: a commit hash can read as a
YAML number.
Fixes knative#3203

`func deploy --remote --source <url>` no longer needs a local copy of
the function. It reads the function from the repository in memory, at
the revision given with --revision or as the URL's fragment, in the
directory given with --source-dir, and the cluster builds the commit it
was read at. Nothing is written locally: to change such a function,
clone the repository, edit it and deploy the working tree.

The cluster deploys the function as configured by the func.yaml
committed there, so of the flags which configure a function only
--builder, --registry, --registry-insecure and --namespace apply,
flag or environment variable alike. --namespace must match the
namespace the func.yaml names, if any. Any other such flag is an error
rather than silently ignored, and there are no prompts. Settings the
func.yaml leaves empty default as for any function, not to those of a
function in the current directory.

Only a repository given with --source or FUNC_SOURCE is deployed by
reference. One set in the local func.yaml (build.source) is built with
the local function's settings, as before.
@knative-prow-robot knative-prow-robot removed the needs-rebase Cannot be merged due to conflicts with HEAD. label Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved 🤖 PR has been approved by an approver from all required OWNERS files. do-not-merge/work-in-progress 🤖 PR should not merge because it is a work in progress. kind/enhancement Feature additions or improvements to existing size/XXL 🤖 PR changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remote builds require checkout

3 participants