Skip to content

add helm charts - #114

Open
cbrady wants to merge 5 commits into
mainfrom
chris/helm-charts
Open

cbrady wants to merge 5 commits into
mainfrom
chris/helm-charts

Conversation

@cbrady

@cbrady cbrady commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@cbrady cbrady self-assigned this Jul 31, 2026
@cbrady
cbrady requested review from a team as code owners July 31, 2026 18:51
cbrady and others added 4 commits October 1, 2026 18:30
The repo is going private, so installing from a source checkout stops working
for customers. Push the packaged chart to
oci://public.ecr.aws/n5h3a7j9/charts/schematic-replicator on chart-vX.Y.Z tags,
after checking the tag matches Chart.yaml and running the chart validation.

Point the README install commands at the OCI reference, point Chart.yaml home
at the public docs instead of the repo, bump appVersion to 0.2.7, and correct
the README's description of readiness, which does not wait for the initial
load in async mode.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Model WRITER_LOCK_ACQUIRE_TIMEOUT as writerLock.acquireTimeout alongside the
other lease settings. Leave the OTEL_* exporter variables to extraEnv, as the
OpenTelemetry SDK reads more of that family than the drift check can see.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Selector-label collisions and validation false positives can produce broken deployments or misleading successful checks.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity · 2 Low severity

Open (5)
What changed in this PR

Adds a production-oriented Helm chart for deploying and publishing the Schematic Replicator.

Changes:

  • Adds configurable Kubernetes resources with validation and secure defaults.
  • Adds chart fixtures and automated validation.
  • Adds OCI chart release automation for Amazon ECR Public.
File Description
.gitignore Allows the chart directory while ignoring root binaries.
.github/​workflows/​chart.yml Validates chart and application environment compatibility.
.github/​workflows/​release-chart.yml Packages and publishes tagged chart releases.
scripts/​validate-chart.sh Lints, renders, and validates chart invariants.
deployments/​charts/​schematic-replicator/​.helmignore Excludes development files from packages.
deployments/​charts/​schematic-replicator/​Chart.yaml Defines chart metadata and versions.
deployments/​charts/​schematic-replicator/​README.md Documents installation and configuration.
deployments/​charts/​schematic-replicator/​values.yaml Defines default chart configuration.
deployments/​charts/​schematic-replicator/​templates/​_helpers.tpl Implements naming, labels, and environment rendering.
deployments/​charts/​schematic-replicator/​templates/​deployment.yaml Deploys the single-writer replicator pod.
deployments/​charts/​schematic-replicator/​templates/​NOTES.txt Provides post-install guidance.
deployments/​charts/​schematic-replicator/​templates/​secret.yaml Creates optional managed credentials.
deployments/​charts/​schematic-replicator/​templates/​service.yaml Exposes health and readiness endpoints.
deployments/​charts/​schematic-replicator/​templates/​serviceaccount.yaml Creates the optional service account.
deployments/​charts/​schematic-replicator/​templates/​validate.yaml Rejects invalid configurations.
deployments/​charts/​schematic-replicator/​ci/​cluster-values.yaml Exercises Redis cluster mode.
deployments/​charts/​schematic-replicator/​ci/​default-values.yaml Exercises minimum configuration.
deployments/​charts/​schematic-replicator/​ci/​existing-secrets-values.yaml Exercises externally managed secrets.
deployments/​charts/​schematic-replicator/​ci/​full-values.yaml Exercises optional chart settings.
deployments/​charts/​schematic-replicator/​ci/​writer-lock-disabled-values.yaml Exercises disabled writer locking.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/validate-chart.sh
Comment on lines +155 to +160
)
if [ -z "$ENV_DRIFT" ]; then
pass "env surface in sync"
else
while IFS= read -r line; do fail "$line"; done <<<"$ENV_DRIFT"
fi
Comment thread deployments/charts/schematic-replicator/templates/_helpers.tpl Outdated
Comment on lines +35 to +39
labels:
{{- include "schematic-replicator.selectorLabels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
Comment thread deployments/charts/schematic-replicator/templates/NOTES.txt Outdated
Comment thread scripts/validate-chart.sh
Comment on lines +97 to +98
assert_rejects "existingSecret without key" \
--set schematic.existingSecret=s --set schematic.existingSecretKey=""
- Fail validation when the env drift checker itself fails, instead of reading
  its empty output as "in sync".
- Quote the selector label values so numeric or boolean-looking release names
  render as strings.
- Merge podLabels under the selector labels so a user label can never make the
  pod template stop matching the Deployment and Service selectors.
- Drop the hard-coded cluster.local suffix from the client URL in NOTES; the
  <svc>.<ns>.svc form resolves on any cluster domain.
- Cover the redis.existingSecretKey guard in validate-chart.sh.
- Correct NOTES on readiness, which does not wait for the initial load in
  async mode.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants