Skip to content

Reject TaskRun taskRef with custom task kind but no apiVersion - #10457

Open
lopster568 wants to merge 1 commit into
tektoncd:mainfrom
lopster568:taskref-kind-requires-apiversion
Open

lopster568 wants to merge 1 commit into
tektoncd:mainfrom
lopster568:taskref-kind-requires-apiversion

Conversation

@lopster568

@lopster568 lopster568 commented Jul 22, 2026 •

Copy link
Copy Markdown

Changes

Setting taskRef.kind to a non-default value without taskRef.apiVersion currently passes admission validation. TaskRef.IsCustomTask() requires both fields to be set, so such a ref is not treated as a Custom Task, and the resolver ignores the kind entirely: the TaskRun runs an ordinary namespaced Task when one with that name exists, or fails at resolution with a confusing tasks.tekton.dev "foo" not found error. #6505 added the Pipeline-level checks for this (pipeline task taskRef and embedded taskSpec); the issue notes the standalone TaskRun taskRef case was left open.

This adds the pairing check to TaskRef.Validate in v1 and v1beta1, reusing the pre-existing "custom task ref must specify apiVersion" error from the Pipeline-level custom task validation. The Pipeline path is unaffected: PipelineTask.Validate routes non-default kinds to validateCustomTask before TaskRef.Validate is reached, so no duplicate errors. An explicit kind: Task without apiVersion stays valid, since the defaulting webhook writes kind: Task into every non-resolver taskRef. The reverse case (apiVersion set, kind empty) is deliberately not rejected: such refs resolve as namespaced Tasks today and rejecting them would break working configs. Also corrects examples/v1/taskruns/beta/emit-array-results.yaml, which set kind: task (lowercase) on an ordinary task reference and would have been rejected by the new check.

docs/taskruns.md documents only taskRef.name for TaskRuns, taskRef.kind is not documented there, so no doc change is included.

Fixes #6557

Submitter Checklist

As the author of this PR, please check off the items in this checklist:

  • Has Docs if any changes are user facing, including updates to minimum requirements e.g. Kubernetes version bumps
  • Has Tests included if any functionality added or changed
  • pre-commit Passed
  • Follows the commit message standard
  • Meets the Tekton contributor standards (including functionality, content, code)
  • Has a kind label. You can add one by adding a comment on this PR that contains /kind <type>. Valid types are bug, cleanup, design, documentation, feature, flake, misc, question, tep
  • Release notes block below has been updated with any user facing changes (API changes, bug fixes, changes requiring upgrade notices or deprecation warnings). See some examples of good release notes.
  • Release notes contains the string "action required" if the change requires additional action from users switching to the new release

Release Notes

Fixes a bug which let a TaskRun taskRef set kind to a value other than "Task" without an apiVersion. The kind was silently ignored: the TaskRun ran a namespaced Task with the same name when one existed, or failed at resolution with a confusing not-found error. After this change, creating such a TaskRun fails admission in v1 and v1beta1 with "custom task ref must specify apiVersion", the same validation already applied to taskRefs inside pipelineTasks.
Action Required: TaskRun manifests that set kind: ClusterTask (removed in v1.0) or a wrong-case value such as kind: task will now be rejected. Remove kind or set it to "Task" for ordinary task references, and set apiVersion for Custom Task references.

Copilot AI review requested due to automatic review settings July 22, 2026 12:01
@tekton-robot tekton-robot added the release-note-action-required Denotes a PR that introduces potentially breaking changes that require user action. label Jul 22, 2026
@tekton-robot
tekton-robot requested review from khrm and vdemeester July 22, 2026 12:01
@linux-foundation-easycla

linux-foundation-easycla Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: lopster568 / name: Roshan (ded12a6)

@tekton-robot tekton-robot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Jul 22, 2026
@lopster568

Copy link
Copy Markdown
Author

/kind bug

@tekton-robot tekton-robot added the kind/bug Categorizes issue or PR as related to a bug. label Jul 22, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds admission-time validation for TaskRun.spec.taskRef to reject a non-default taskRef.kind when taskRef.apiVersion is missing, aligning TaskRun behavior with existing Pipeline-level custom-task validation and preventing confusing “not found” resolution errors.

Changes:

  • Add TaskRef.Validate checks in both v1 and v1beta1 to require apiVersion when kind is non-default.
  • Add unit tests covering the newly invalid case and ensuring the explicit default kind remains valid.
  • Fix an example TaskRun that used kind: task (lowercase) so it remains valid under the new validation.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.

Show a summary per file
File Description
pkg/apis/pipeline/v1beta1/taskref_validation.go Reject non-default kind without apiVersion for v1beta1 TaskRefs.
pkg/apis/pipeline/v1beta1/taskref_validation_test.go Add valid/invalid cases for the new v1beta1 validation rule.
pkg/apis/pipeline/v1/taskref_validation.go Reject non-default kind without apiVersion for v1 TaskRefs.
pkg/apis/pipeline/v1/taskref_validation_test.go Add valid/invalid cases for the new v1 validation rule.
examples/v1/taskruns/beta/emit-array-results.yaml Update TaskRun example to use kind: Task (capitalized).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@vdemeester vdemeester left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SGTM, but we will need a very good release-note entry as it could possibly break users isn't it ?

@lopster568

Copy link
Copy Markdown
Author

Updated the release note to spell out who is affected and what to change. In practice that is leftover kind: ClusterTask manifests and wrong-case values like kind: task, which are accepted today and will be rejected at admission after this change. I modeled the note on the one in #9588, a similar validation tightening shipped as a bug fix with an action required entry.

@tekton-robot

Copy link
Copy Markdown
Collaborator

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: vdemeester

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@tekton-robot tekton-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 15, 2026
@vdemeester

Copy link
Copy Markdown
Member

/retest

@vdemeester

Copy link
Copy Markdown
Member

cc @tektoncd/core-maintainers

A TaskRef that sets kind to a non-default value without apiVersion is
not recognized as a Custom Task reference (IsCustomTask requires both
fields), and the resolver ignores the kind entirely: the ref resolves
as an ordinary namespaced Task when one exists, or fails at runtime
with a confusing not-found error. Validate the pairing at admission
time in TaskRef.Validate for v1 and v1beta1, mirroring the custom task
validation Pipelines already perform, and correct the one example that
set a lowercase kind on an ordinary task reference.

Fixes tektoncd#6557

Signed-off-by: Roshan <rosh.s568@gmail.com>
@lopster568
lopster568 force-pushed the taskref-kind-requires-apiversion branch from ded12a6 to 7fc1d86 Compare September 18, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. kind/bug Categorizes issue or PR as related to a bug. release-note-action-required Denotes a PR that introduces potentially breaking changes that require user action. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Taskrun's taskref setting kind but without apiversion should be considered as validation error

4 participants