Skip to content

fix(pipelinesascode): Fix validating-webhook panic when PAC Settings is nil (PAC disabled). - #4195

Merged
tekton-robot merged 1 commit into
tektoncd:mainfrom
jkhelil:fix/pac-nil-settings-validate-v2
Oct 5, 2026
Merged

tekton-robot merged 1 commit into
tektoncd:mainfrom
jkhelil:fix/pac-nil-settings-validate-v2

Conversation

@jkhelil

@jkhelil jkhelil commented Oct 2, 2026

Copy link
Copy Markdown
Member

Changes

Fix validating-webhook panic when PAC Settings is nil (PAC disabled).

Fixes #4057
Supersedes #4065

Submitter Checklist

  • Run make test lint before submitting a PR
  • Includes tests (if functionality changed/added)
  • Includes docs (if user facing)
  • Commit messages follow commit message best practices

Release Notes

Fix validating webhook panic when disabling PipelinesAsCode in TektonConfig.

Fixes tektoncd#4057

Signed-off-by: Jawed khelil <jkhelil@redhat.com>
@tekton-robot tekton-robot added the release-note Denotes a PR that will be considered when it comes time to generate release notes. label Oct 2, 2026
@tekton-robot tekton-robot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Oct 2, 2026
@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 27.79%. Comparing base (605c4bf) to head (1e94869).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4195   +/-   ##
=======================================
  Coverage   27.78%   27.79%           
=======================================
  Files         477      477           
  Lines       25688    25691    +3     
=======================================
+ Hits         7137     7140    +3     
  Misses      17822    17822           
  Partials      729      729           
Flag Coverage Δ
unit-tests 27.79% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tekton-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: vdemeester

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 2, 2026
@jkhelil

jkhelil commented Oct 2, 2026

Copy link
Copy Markdown
Member Author

Reproducer Before fix

KO_DOCKER_REPO=quay.io/jkhelil make apply

kubectl delete tektonconfig config --ignore-not-found

kubectl apply -f - <<'EOF'
apiVersion: operator.tekton.dev/v1alpha1
kind: TektonConfig
metadata:
  name: config
spec:
  profile: all
  targetNamespace: tekton-pipelines
  platforms:
    kubernetes:
      pipelinesAsCode:
        enable: false
EOF

kubectl logs -n tekton-operator deploy/tekton-operator-webhook --tail=100
{"level":"error","timestamp":"2026-10-02T08:49:48.091Z","logger":"tekton-operator-webhook","caller":"webhook/webhook.go:300","msg":"http: panic serving 10.244.0.1:9592: assignment to entry in nil map\ngoroutine 662 [running]:\nnet/http.(*conn).serve.func1()\n\tnet/http/server.go:1939 +0xbb\npanic({0x38d76b8?, 0x3bb3740?})\n\truntime/panic.go:859 +0x125\ngithub.com/openshift-pipelines/pipelines-as-code/pkg/params/settings.getHubCatalogs(0x2b14488820b0, 0x7?, 0x0, 0x3beb520)\n\tgithub.com/openshift-pipelines/pipelines-as-code@v0.49.0/pkg/params/settings/default.go:21 +0xaf\ngithub.com/openshift-pipelines/pipelines-as-code/pkg/params/settings.SyncConfig(0x2b14488820b0, 0x2b1448c71db0, 0x0, 0x2b1448c72000, 0x6abf702c?)\n\tgithub.com/openshift-pipelines/pipelines-as-code@v0.49.0/pkg/params/settings/config.go:122 +0x49\ngithub.com/tektoncd/operator/pkg/apis/operator/v1alpha1.(*PACSettings).validate(0x2b144825a1e8, 0x2b14488820b0, {0x1e38519, 0x29})\n\tgithub.com/tektoncd/operator/pkg/apis/operator/v1alpha1/openshiftpipelinesascode_validation.go:58 +0x245\ngithub.com/tektoncd/operator/pkg/apis/operator/v1alpha1.(*TektonConfig).Validate(0x2b1448c6a008, {0x3b326b8, 0x2b1448b6a780})\n\tgithub.com/tektoncd/operator/pkg/apis/operator/v1alpha1/tektonconfig_validation.go:81 +0x6c5\nknative.dev/pkg/webhook/resourcesemantics/validation.validate({0x3b326b8, 0x2b1448b6a780}, {0x3b328b0, 0x2b1448c6a008}, 0x2b144822cb60)\n\tknative.dev/pkg@v0.0.0-20260622140654-39ebae2ee2dc/webhook/resourcesemantics/validation/validation_admit.go:190 +0x115\nknative.dev/pkg/webhook/resourcesemantics/validation.(*reconciler).Admit(0x2b14487f7520, {0x3b326b8, 0x2b1448b6a3f0}, 0x2b144822cb60)\n\tknative.dev/pkg@v0.0.0-20260622140654-39ebae2ee2dc/webhoo

After fix

kubectl delete tektonconfig config --ignore-not-found

kubectl apply -f - <<'EOF'
apiVersion: operator.tekton.dev/v1alpha1
kind: TektonConfig
metadata:
  name: config
spec:
  profile: all
  targetNamespace: tekton-pipelines
  platforms:
    kubernetes:
      pipelinesAsCode:
        enable: false
EOF

/w/r/g/s/tek/operator fix/pac-nil-settings-validate-v2 *20 ?1 > kubectl logs -n tekton-operator deploy/tekton-operator-webhook --tail=10

{"level":"info","timestamp":"2026-10-02T08:57:31.417Z","logger":"tekton-operator-webhook","caller":"configutil/config.go:66","msg":"updating value for field BitbucketCloudCheckSourceIP: from 'false' to 'true'","knative.dev/pod":"tekton-operator-webhook-5885dfd749-brn4z","knative.dev/kind":"operator.tekton.dev/v1alpha1, Kind=TektonConfig","knative.dev/namespace":"","knative.dev/name":"config","knative.dev/operation":"UPDATE","knative.dev/resource":"operator.tekton.dev/v1alpha1, Resource=tektonconfigs","knative.dev/subresource":"status","knative.dev/userinfo":"system:serviceaccount:tekton-operator:tekton-operator"}
{"level":"info","timestamp":"2026-10-02T08:57:31.417Z","logger":"tekton-operator-webhook","caller":"configutil/config.go:66","msg":"updating value for field SecretAutoCreation: from 'false' to 'true'","knative.dev/pod":"tekton-operator-webhook-5885dfd749-brn4z","knative.dev/kind":"operator.tekton.dev/v1alpha1, Kind=TektonConfig","knative.dev/namespace":"","knative.dev/name":"config","knative.dev/operation":"UPDATE","knative.dev/resource":"operator.tekton.dev/v1alpha1, Resource=tektonconfigs","knative.dev/subresource":"status","knative.dev/userinfo":"system:serviceaccount:tekton-operator:tekton-operator"}
{

@jkhelil jkhelil changed the title fix(pipelinesascode): guard nil Settings in validate fix(pipelinesascode): Fix validating-webhook panic when PAC Settings is nil (PAC disabled). Oct 2, 2026
@pratap0007

Copy link
Copy Markdown
Contributor

/lgtm

@tekton-robot tekton-robot added the lgtm Indicates that a PR is ready to be merged. label Oct 5, 2026
@tekton-robot
tekton-robot merged commit 95a7ea9 into tektoncd:main Oct 5, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cannot disable PipelinesAsCode in TektonConfig: validating webhook panics with "assignment to entry in nil map"

4 participants