Conversation
|
/ok to test c5afa06 |
c5afa06 to
cb8ae8b
Compare
|
Label |
|
/ok to test cb8ae8b |
cb8ae8b to
5efe3e8
Compare
|
@krishicks I pushed a new commit solving a conflict with |
|
/ok to test 5efe3e8 |
46d70d8 to
cfae1b6
Compare
|
/ok to test cfae1b6 |
|
I added this to to 0.1.1 milestone as we're freezing what goes into 0.1.0. For this to actually land in 0.1.1 it would need to be implemented in a backwards-compatible way. Failing that this would need to be pushed to 0.2.0 which is the next release where breaking changes can get in. |
cfae1b6 to
df2e85c
Compare
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
4e1bcdb to
4329258
Compare
|
Rebased onto latest main and conflicts are resolved. @krishicks could I have the test suite re-executed with |
|
I did some analysis as the goal is to have this rolled in a backwards compatible manner. Posting my analysis: Compat check against 0.1.x: legacy server.oidc.* without role names loses RBAC on upgrade: I rendered the chart at the merge-base (b8ffe52) and at this PR's head (de1451b) with the same legacy ci/values-*.yaml overlays, then compared the parsed Regression: a values file that sets server.oidc.issuer and audience but no role names (for example The old template emitted roles_claim, admin_role and user_role only when non-empty (gateway-config.yaml L163-171), so the gateway fell back to realm_access.roles / openshell-admin / openshell-user. With explicit empty strings: Config-file values replace defaulted CLI args ( Repro: Suggested fix: in the legacy OIDC translation, add roles_claim, admin_role and user_role only when the legacy value is non-empty, as the old template did and as this PR already does for the other optional fields. Please also add a Helm test: legacy server.oidc.issuer only → gateway.toml has no admin_role, user_role or roles_claim. Another test could pin that an explicit schema-v2 admin_role = "" is still honoured. |
Summary
Migrate the Helm chart from field-by-field
gateway.tomlconstruction to the schema-v2gatewayConfigboundary while preserving the non-secret ConfigMap boundary and Helm-owned Secret, volume, and resource wiring.Related Issue
Closes #3060.
Compatibility
This implementation is backwards-compatible for 0.1.x:
sandboxRuntime,supervisor,upstreamProxy, and Kubernetes driver aliases for existing values files.gatewayConfigis authoritative whenever both the schema-v2 field and its legacy alias are supplied.gatewayConfig.Changes
Testing
mise run cimise run helm:test(170 gateway-chart tests and 5 workspace-chart tests)mise run helm:lintacross chart overlaysChecklist
Signed-off-bytrailers.