Conversation
|
Skipping CI for Draft Pull Request. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: gauron99 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The remote path bypasses required validation, and legal quoted Git refs can produce malformed Tekton YAML.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Enables remote deployment directly from a Git repository without a local checkout.
Changes:
- Loads and migrates
func.yamlfrom a resolved Git commit in memory. - Pins Tekton builds to that commit and avoids local writes.
- Restricts applicable deployment flags and expands unit/E2E coverage.
| File | Description |
|---|---|
pkg/testing/testing.go |
Adds Git repository test fixture. |
pkg/pipelines/tekton/templates.go |
Pins pipeline revision and supports rootless functions. |
pkg/pipelines/tekton/templates_test.go |
Tests rootless templates and revisions. |
pkg/pipelines/tekton/templates_s2i.go |
Quotes S2I Git revisions. |
pkg/pipelines/tekton/templates_pack.go |
Quotes Pack Git revisions. |
pkg/pipelines/tekton/pipelines_provider.go |
Validates rootless source availability. |
pkg/functions/function.go |
Decouples validation from filesystem roots. |
pkg/functions/function_source.go |
Records the resolved commit in memory. |
pkg/functions/function_migrations.go |
Migrates from serialized YAML bytes. |
pkg/functions/function_git.go |
Implements in-memory Git loading. |
pkg/functions/function_git_test.go |
Tests revisions, directories, and migrations. |
pkg/functions/client.go |
Reuses loaded bytes during migration. |
e2e/e2e_remote_test.go |
Removes local checkout requirements. |
docs/reference/func_deploy.md |
Documents deployment-by-reference behavior. |
cmd/deploy.go |
Adds the rootless remote deployment path. |
cmd/deploy_test.go |
Covers flags, defaults, and no-write behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
c983357 to
ca3e051
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Local state can still affect or be mutated by reference deployments, and multi-branch fixtures advertise the wrong default branch.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 3
Open (3)
| // The client is configured by cfg, whose defaults came from the current | ||
| // directory. | ||
| cfg.Builder, cfg.Registry, cfg.RegistryInsecure = f.Build.Builder, f.Registry, f.RegistryInsecure |
| git(work, "checkout", "-q", "-b", name, "main") | ||
| heads[name] = commit(branches[name], name) | ||
| } | ||
| git(root, "clone", "-q", "--bare", work, "repository.git") |
fn.NewFunctionFromGit reads the func.yaml at a revision (branch, tag or full commit hash) of a git repository into memory: a depth-one fetch into go-git memory storage, nothing on disk. The function has no Root. Its Build.Source is where it was read from, and Build.Source.Commit (in memory only, never stored) the commit the revision resolved to. Migrations now take the serialized function instead of re-reading func.yaml from f.Root: a function without a Root could otherwise not be migrated, or would be migrated from the func.yaml of the current directory. Migrate still reads f.Root, so NewFunction is unchanged. A function read from git is parsed more strictly than NewFunction does: a func.yaml which does not unmarshal cleanly is an error. Validate no longer requires a Root, Write does.
A function read from its git repository has no Root. The pipeline provider now requires a Root only to upload sources, and does not look for Pipeline or PipelineRun overrides in a project directory it does not have. Such a function carries the commit it was read at. The cluster fetches exactly that commit, not whatever the branch points to by then, and labels the image with it. Without a Root, the label is no longer taken from whatever repository func happens to run in. Anything else is fetched and labelled as before. The revision is quoted in the PipelineRun: a commit hash can read as a YAML number.
Fixes knative#3203 `func deploy --remote --source <url>` no longer needs a local copy of the function. It reads the function from the repository in memory, at the revision given with --revision or as the URL's fragment, in the directory given with --source-dir, and the cluster builds the commit it was read at. Nothing is written locally: to change such a function, clone the repository, edit it and deploy the working tree. The cluster deploys the function as configured by the func.yaml committed there, so of the flags which configure a function only --builder, --registry, --registry-insecure and --namespace apply, flag or environment variable alike. --namespace must match the namespace the func.yaml names, if any. Any other such flag is an error rather than silently ignored, and there are no prompts. Settings the func.yaml leaves empty default as for any function, not to those of a function in the current directory. Only a repository given with --source or FUNC_SOURCE is deployed by reference. One set in the local func.yaml (build.source) is built with the local function's settings, as before.
ca3e051 to
78a8d01
Compare

Changes
func deploy --remote --source <url>reads the function from the repository in memory and no longer needs a local copy of it.--revision(or<url>#<revision>) and--source-dirselect the revision and directory to read it from.fn.NewFunctionFromGit, which loads a function from a git repository at a branch, tag or full commit hash with a depth-one fetch into memory: nothing is checked out or written to disk. The function has no Root and carries the commit it was read at (Build.Source.Commit, in memory only). Library users such as the operator can use it the same way.--builder,--registry,--registry-insecureand--namespaceapply (flag or environment variable).--namespacemust match the namespace the committed func.yaml names, if any. Any other such flag, and--confirm, is an error instead of being silently ignored by the cluster.--sourceorFUNC_SOURCEis deployed by reference. One set in the local func.yaml (build.source) is built with the local function's settings, as before.f.Root, so a function without a Root can be migrated, and is never migrated from the func.yaml of the current directory.Validateno longer requires a Root;Writedoes./kind enhancement
Fixes #3203