E2E-1: comprehensive HelmChartUpgrade E2E coverage (both transport styles)
Summary
E2E-1 of the K8s E2E expansion. Pre-this-PR Helm action coverage was effectively zero — 3 tests skipped (Skip = "Requires helm CLI") + 1 variable-substitution test for KubernetesApi only. This PR adds 12 new test methods (~16 test cases via Theory expansion) covering KubernetesApi AND KubernetesAgent.
Coverage added
| Area | Test |
|---|---|
| Baseline | BasicChart_GeneratesUpgradeCommand |
| Namespace | WithNamespace_AppliesNamespaceFlag |
| Values files | InlineYamlValues_StagesFileAndReferencesIt |
| Security |
InlineKeyValues_GeneratedAsYamlFile_NotSetArgv — P0-Phase10.2 regression pin: secrets MUST go to inline-values.yaml, NOT --set argv (which leaks to ps / kubelet / audit) |
| YAML semantics |
DottedKeyValues_ProduceNestedYamlTree — Helm --set dot-notation correctness |
| Variable substitution | VariableSubstitution_ResolvesPlaceholdersInScript |
| Wait/timeout | WaitAndTimeoutFlags_AppendedCorrectly |
| Defaults |
ResetValuesDefaultTrue_FlagPresent + ResetValuesExplicitFalse_FlagAbsent
|
| Pass-through | AdditionalArgs_AppendedAtEnd |
| Custom binary | CustomHelmExecutable_UsedInsteadOfDefaultHelm |
| PowerShell variant | PowerShellSyntax_GeneratesPowerShellScript |
| Multi-target | MultipleTargets_EachReceivesIndependentRequest |
Most tests are [Theory] across KubernetesApi + KubernetesAgent to pin the HelmUpgradeScriptBuilder shared-impl invariant.
Pattern
DeploymentPipelineFixture (Pattern 2 in CLAUDE.md). Full pipeline runs end-to-end with CapturingExecutionStrategy intercepting both transports' execution. Inspects captured ScriptExecutionRequest.ScriptBody + DeploymentFiles. Does NOT require helm CLI on the runner — the existing Skip-marked CLI tests stay; this PR fills the actual coverage gap.
Also fixes
CapturingHalibutClientFactory was missing CreateFileTransferClient (interface drift post #283 / merge-order issue from earlier this week). Returns ThrowingFileTransferService so any pipeline test that accidentally tries file transfer fails with an actionable message pointing at the right fixture.
Test plan
-
All 13 test methods compile + the existing Squid.E2ETestsproject builds clean (was failing-to-build before this PR) -
CI runs unit + integration + tentacle suites — must stay green -
Local test run pending Kind cluster (requires Docker running locally; CI handles this)
Future E2E batches in this milestone
- E2E-2: K8s Resume-from-Checkpoint E2E (covers P0-3 + P0-5 work)
- E2E-3: K8s Idempotence E2E
- E2E-4: K8s Agent failure scenarios (real Halibut error paths)
- E2E-5 through E2E-8: multi-target / sensitive var / cancellation / namespace isolation