Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

settings.py flaps between reconciles: needsMigrationSetting depends on map iteration order

Open Beginner friendly
#1,691 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 4 days

@fontaineajulien is already working on this.

Since Oct 5, 2026.

  • #1692 by @fontaineajulien — open

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
go

Research direction

Read controllers/repo_manager/secret.go, starting with needsMigrationSetting() and how it uses MigrationSettingsList(). Check for related tests before making changes. Done means the generated settings.py is stable across reconciles and every setting set to true is written.

Written by the indexing model from the issue text.

Description

Version
Operator 1.3.0. The same code is on main.

Describe the bug
needsMigrationSetting() in controllers/repo_manager/secret.go builds part of settings.py by ranging over MigrationSettingsList(), which is a Go map, and it returns at the first setting that is false.

Go randomizes map iteration order. With redirect_to_object_storage: true and hide_guarded_distributions: false, REDIRECT_TO_OBJECT_STORAGE = True is written on some reconciles and missing on others. With both settings true, the two lines swap order.

So the <name>-server Secret changes between reconciles. The operator logs The Data from Secret pulp-server has been modified! Reconciling ... and Reprovisioning pulpcore pods to get the new settings ..., and rolls the api, content and worker Deployments. The rollout triggers more reconciles, each with roughly a 50% chance of flipping the Secret again, so the loop sustains itself. We saw it run for minutes after a single CR change, and once it ran for days, creating tens of thousands of ReplicaSets.

There is a second effect. Depending on the order, a true setting can be dropped from settings.py entirely, so REDIRECT_TO_OBJECT_STORAGE is sometimes not applied.

To Reproduce

  1. Set redirect_to_object_storage: true and leave hide_guarded_distributions unset.
  2. Change anything on the CR to trigger a reconcile.
  3. Watch the operator logs and kubectl get rs.

Expected behavior
settings.py is identical on every reconcile, and each true setting is written.

Additional context
Fix: iterate over sorted keys, and continue instead of return on a false setting. PR to follow.

Dominant language
Go
Stars
88
Forks
68
Avg merge
3d 3h
Merged PRs (30d)
1

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from pulp/pulp-operator

All issues in pulp/pulp-operator

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.