HELM upgrade/install issue with azure pipelines

Viewed 113

I am trying to create a new namespace and install release name in azure pipelines, but my pipelines are getting timed-out after an hour.

Here's the code:

- task: HelmDeploy@0 
  displayName: Dry run for upgrade 
  inputs: 
    connectionType: $(connectionType) 
    azureSubscription: $(azureServiceConnection) 
    azureResourceGroup: $(azureResourceGroup) 
    kubernetesCluster: $(kubernetesCluster) 
    namespace: '$(namespace)' 
    command: 'upgrade' 
    chartType: 'Name' 
    chartName: $(chartName) 
    releaseName: $(releaseName) 
    valueFile: $(valueFile) 
    install: true 
    waitForExecution: true 
    arguments: '--timeout 1h0m0s --create-namespace --install'

Can someone help with this case?

1 Answers

The answer (which took me about a day of reading the docs to work out as I had the same issue) is simply that your HelmDeploy task requires internal Admin RBAC permissions.

The absolute easiest way to fix your code is to add useClusterAdmin: true to your HelmDeploy@0 task e.g. add the last line:

- task: HelmDeploy@0 
  displayName: Dry run for upgrade 
  inputs: 
    connectionType: $(connectionType) 
    azureSubscription: $(azureServiceConnection) 
    azureResourceGroup: $(azureResourceGroup) 
    kubernetesCluster: $(kubernetesCluster)
    namespace: '$(namespace)' 
    command: 'upgrade' 
    chartType: 'Name' 
    chartName: $(chartName) 
    releaseName: $(releaseName) 
    valueFile: $(valueFile) 
    install: true 
    waitForExecution: true 
    arguments: '--timeout 1h0m0s --create-namespace --install'
    useClusterAdmin: true

For clarity, this will bypass your cluster's RBAC permissions. If you wanted something more granular, then referring to this dicussion, you'd have to not use the dedicated HelmDeploy task, and use AzureCLI@2 with helm upgrade ....

Related