PipeCD - Analysis Stage Template Rendering Fix

Fixed a critical bug in PipeCD's analysis stage: template variables were not filled in for the THRESHOLD and PREVIOUS strategies, so raw template text showed up in logs and queries.

I contributed to PipeCD, a CNCF Sandbox GitOps continuous deployment tool. I fixed a bug where some analysis strategies did not fill in template variables, so logs and queries showed raw template text instead of real values.

What is PipeCD?

PipeCD is a CNCF Sandbox project. It provides GitOps continuous deployment for Kubernetes, ECS, Lambda, and other platforms. It supports progressive delivery (rolling out changes step by step) with features like canary deployments, blue-green deployments, and automated analysis stages that watch metrics during a deployment.

The Problem

PipeCD's analysis stage supports different strategies for monitoring deployments: CANARY_BASELINE, THRESHOLD, and PREVIOUS. The CANARY_BASELINE strategy correctly turned template variables like {{ .App.Name }} into real values. But the THRESHOLD and PREVIOUS strategies showed the raw template text in logs and queries.

This mismatch meant:

  • Users saw confusing template variables in logs instead of real application names
  • Monitoring queries still contained raw template text like {{ .App.Name }}
  • The strategies behaved differently from each other, which broke user expectations
  • Debugging deployments was much harder because the template text carried no meaning

My Solution

I found and fixed the root cause in metrics_analyzer.go:

Before: Only the CANARY_BASELINE strategy called renderQuery() to process templates
After: All strategies (CANARY_BASELINE, THRESHOLD, PREVIOUS) now use renderQuery() in the same way

The fix was small and focused:

  • Updated the THRESHOLD strategy to call renderQuery before running queries
  • Updated the PREVIOUS strategy to call renderQuery before running queries
  • Made all analysis stage strategies behave the same way
  • No breaking changes - purely a bug fix that made things work as users expected

Review Process

The review was collaborative and thorough:

Warashi (PipeCD maintainer) gave great guidance:

  • Helped find the exact place of the issue and the right approach to fix it
  • Asked for proper commit signing, a security best practice for the project
  • Tested the changes with real PipeCD deployments
  • Shared before/after screenshots showing the fix working in production
  • Approved the change after testing it

ffjlabo did the final review and merged the PR, confirming it met all project standards.

Technical Impact

The fix makes all analysis strategies behave the same way:

  • ✅ Users now see real application names instead of {{ .App.Name }}
  • ✅ Monitoring queries run with real values (e.g., actual service names, namespaces)
  • ✅ All analysis strategies fill in templates in the same way
  • ✅ Debugging is easier for PipeCD users across all deployment strategies
  • ✅ The quick cherry-pick into the v0.52.2 release shows it mattered to users

Community Recognition

The fix was quickly cherry-picked into the v0.52.2 release, which shows how much it mattered for existing users. The PipeCD maintainers encouraged me to keep contributing, and that led to several more contributions in documentation and tooling.

Links: Pull Request #6010 • Issue #6005 • Repository