Skip to content

fix(kustomize): match image names using SplitImageName to support registry ports and digests (#29970) - #29978

Merged
crenshaw-dev merged 2 commits into
argoproj:masterfrom
jdymitarai:fix-kustomize-image-match-registry-port
Oct 7, 2026
Merged

crenshaw-dev merged 2 commits into
argoproj:masterfrom
jdymitarai:fix-kustomize-image-match-registry-port

Conversation

@jdymitarai

@jdymitarai jdymitarai commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #29970

Previously, KustomizeImage.Match used delim() which split on the first colon, causing images with registry ports (e.g., registry.example.com:5000/team/foo:1.0) to be truncated to just the registry host (registry.example.com). As a result, argocd app set or unset --kustomize-image incorrectly matched and overwritten or deleted unrelated images sharing the same registry port, and digest overrides failed to replace existing tags. This fix compares the old image name prefix when = is present, and otherwise uses kutil.SplitImageName from sigs.k8s.io/kustomize/api to accurately extract the image name without tags, digests, or port truncation. Unit tests covering registry ports, tags, digests, and CLI unsetting have been added.

Checklist:

  • Either (a) I've created an enhancement proposal and discussed it with the community, (b) this is a bug fix, or (c) this does not need to be in the release notes.
  • The title of the PR states what changed and the related issues number (used for the release note).
  • The title of the PR conforms to the Title of the PR
  • I've included "Closes [ISSUE #]" or "Fixes [ISSUE #]" in the description to automatically close the associated issue.
  • I've updated both the CLI and UI to expose my feature, or I plan to submit a second PR with them.
  • I have signed off all my commits as required by DCO
  • I have written unit and/or e2e tests for my change. PRs without these are unlikely to be merged.
  • My build is green.
  • I have added a brief description of why this PR is necessary and/or what this PR solves.

Summary by CodeRabbit

  • Bug Fixes
    • Improved Kustomize image matching when unsetting or updating images, including images with registry ports, distinct image paths, tags, or digests.
    • Unsetting an image by its repository-and-tag prefix now removes the matching image while retaining other images and correctly reports that an update was made.
    • Updating an image with a registry port now replaces only the matching image. Digest-form images also correctly match their tag-form counterparts.

@jdymitarai
jdymitarai requested review from a team as code owners October 3, 2026 05:08
@bunnyshell

bunnyshell Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

❌ Preview Environment deleted from Bunnyshell

Available commands (reply to this comment):

  • 🚀 /bns:deploy to deploy the environment

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c914d3e9-7815-460b-8ba2-8b2c167412eb
📥 Commits

Reviewing files that changed from the base of the PR and between ab2be6e and e325d24.

📒 Files selected for processing (1)
  • go.mod

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

KustomizeImage.Match now compares normalized image names, using Kustomize parsing when the image has no =. Tests cover registry ports, distinct image paths, tag-to-digest matching, image merging, and CLI unset behavior.

Changes

Kustomize image matching

Layer / File(s) Summary
Normalize image identity and verify matching
pkg/apis/application/v1alpha1/types.go, pkg/apis/application/v1alpha1/types_test.go, cmd/argocd/commands/app_test.go, go.mod
KustomizeImage.Match compares the text before = or the image name parsed by Kustomize. Tests cover registry ports, distinct image paths, tag-to-digest matching, image merging, and unsetting an image by a shorter prefix. The Kustomize API is a direct dependency.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: crenshaw-dev, alexmt

Merge Risk: ⚪ Minimal · up to e325d

The change aligns image updates and unsets with the intended image-name matching behavior. No concrete merge-blocking risk is evident from the reviewed changes.

Architecture Summary

Architecture risk: 🔵 Low · up to ab2be

The change affects 3 systems.

Changed systems: pkg, cmd, go.mod

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — pkg (service) was modified; 2 changed files map to changed impact.
  • observed — cmd (service) was modified; 1 changed file maps to changed impact.
  • observed — go.mod (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in cmd/argocd/commands/app_test.go: Test_unset adds coverage for removing registry.example.com:5000/team/bar:1.0 when the unset filter is the shorter prefix registry.example.com:5000/team/bar; it asserts the operation reports an update, does not report nothing to unset, and preserves the other image.
  • observed — Modified behavior in pkg/apis/application/v1alpha1/types.go: Adds the Kustomize utility package import under the local alias kutil.
  • observed — Modified behavior in pkg/apis/application/v1alpha1/types.go: Adds imageName, which returns the text before = when present or the Kustomize-parsed image name otherwise. KustomizeImage.Match now compares those normalized names, replacing delimiter selection from the searched image and splitting both inputs on that delimiter.
  • observed — Modified behavior in pkg/apis/application/v1alpha1/types_test.go: TestKustomizeImage_Match adds assertions covering registry-port image matching, path mismatches, and tag-pattern matches against digest references.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main Kustomize image-matching fix and identifies issue #29970.
Description check ✅ Passed The description explains the bug, solution, affected commands, linked issue, and tests. It follows the template for the required core items, although several non-critical checklist entries are omitted…
Linked Issues check ✅ Passed Issue #29970 requires image matching by the text before = or by Kustomize's parsed image name. KustomizeImage.Match now applies these rules. Tests cover registry ports, distinct image paths, merge…
Out of Scope Changes check ✅ Passed The kustomize/api dependency change supports the required SplitImageName behavior. The implementation and unit tests directly support issue #29970. No unrelated change is demonstrated.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

@codecov

codecov Bot commented Oct 3, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

…istry ports and digests

Previously, KustomizeImage.Match used delim() which cut at the first colon, treating registry host:port addresses as image names and misidentifying sha256 digests. This caused app set and unset --kustomize-image to overwrite or remove unrelated images from the same registry port, and prevented digest overrides from replacing tags. This fix compares the old image name prefix when '=' is present, and otherwise uses kutil.SplitImageName to accurately extract the image repository name.

Signed-off-by: jdymitarai <o10040115@gmail.com>
@jdymitarai
jdymitarai force-pushed the fix-kustomize-image-match-registry-port branch from 77fc02c to ab2be6e Compare October 4, 2026 00:18

@crenshaw-dev crenshaw-dev left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm! Can you merge and fix the go.mod conflict?

@crenshaw-dev crenshaw-dev added cherry-pick/3.3 Candidate for cherry picking into the 3.3 release cherry-pick/3.4 cherry-pick/3.5 cherry-pick/3.6 Candidate for cherry picking into the 3.6 release branch labels Oct 7, 2026
@codecov

codecov Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (master@021797f). Learn more about missing BASE report.
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff            @@
##             master   #29978   +/-   ##
=========================================
  Coverage          ?   72.32%           
=========================================
  Files             ?      434           
  Lines             ?    56289           
  Branches          ?        0           
=========================================
  Hits              ?    40709           
  Misses            ?    15580           
  Partials          ?        0           
Flag Coverage Δ
e2e 30.77% <0.00%> (?)
unit-tests 68.37% <100.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@jdymitarai

Copy link
Copy Markdown
Contributor Author

@crenshaw-dev Merged upstream/master and resolved the go.mod conflict (kept controller-runtime v0.25.2 from master and ran go mod tidy). Ready for merge, thank you!

@crenshaw-dev
crenshaw-dev enabled auto-merge (squash) October 7, 2026 21:58
@crenshaw-dev
crenshaw-dev merged commit 2a1daf3 into argoproj:master Oct 7, 2026
30 of 31 checks passed
@argo-cd-cherry-pick-bot

Copy link
Copy Markdown

❌ Cherry-pick failed for 3.3. Please check the workflow logs for details.

@argo-cd-cherry-pick-bot

Copy link
Copy Markdown

❌ Cherry-pick failed for 3.6. Please check the workflow logs for details.

@argo-cd-cherry-pick-bot

Copy link
Copy Markdown

❌ Cherry-pick failed for 3.4. Please check the workflow logs for details.

@argo-cd-cherry-pick-bot

Copy link
Copy Markdown

❌ Cherry-pick failed for 3.5. Please check the workflow logs for details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cherry-pick/3.3 Candidate for cherry picking into the 3.3 release cherry-pick/3.4 cherry-pick/3.5 cherry-pick/3.6 Candidate for cherry picking into the 3.6 release branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

argocd app set/unset --kustomize-image picks the wrong image when the registry has a port

2 participants