Story 16.3 — Kubernetes Secrets, TLS, ESO compatibility - #6
Merged
Conversation
Add Secret key-name contract + per-key overrides + envFrom, Secret-backed federation→sidecar creds (CONFIG_FORCE_*), TLS-at-Ingress termination + Ingress template, secret-backend docs and example manifests (SealedSecrets/ESO), and secret-auth + ingress-tls goldens. Same path/repo rewrites as prior stories. Closes #5 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add single-cluster / three-region / heterogeneous-ready example overlays (each with README + ASCII diagram + install command + SHOW CATALOGS expectation) and their per-example goldens. three-region and heterogeneous-ready renders are byte-identical by design; the duckdb-attach source marker (3 vs 0) is the only discriminator. Same path/repo rewrites as prior stories. Closes #7 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add the chart-repo CI workflow (.github/workflows/federation-helm.yml) plus the deploy-es.sh / install-sealed-secrets.sh scripts, and the helm test smoke Job. CI redesigned for the chart-only repo: the sbt build-images job is replaced by an image-availability probe that docker-pulls the PUBLIC DockerHub federation + sidecar images and kind-loads them; live-install jobs are gated on image publication and skip-with-warning until published (OQ-1). JFROG creds + setup-java/setup-sbt removed. All static-validation gates (lint, template+kubeconform, golden diff, zero kind:Secret, duckdb-attach discriminator) run unconditionally. Trigger paths updated to softclient4es-federation/**. Smoke = ADBC GetCatalogs (1/3/3 per example). README CI section + Chart.yaml metadata rewritten to match (softclient4es.dev, softclient4es-helm sources, public DockerHub images, private-repo references removed). Closes #9 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add the canonical operator guide (softclient4es-federation/docs/operator-guide.md) that ships with the chart: prerequisites, single-cluster + multi-cluster paths, configuration reference, secret-backend chooser, licensing quota, migration, upgrades/rollback, troubleshooting + SRE incident-triage walkthrough. Authoritative copy — mirror language and private-repo references removed; working-directory convention uses softclient4es-federation/. Same Chart.yaml/README/CI rewrites as prior stories (softclient4es.dev metadata, public DockerHub images, chart-only CI). Closes #12 Refs #11 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Story 16.6 — Operator guide
Story 16.5 — helm test smoke + comprehensive CI/CD
Story 16.4 — Topology examples
fupelaqu
marked this pull request as ready for review
June 23, 2026 11:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds Secret-by-name referencing (chart renders ZERO
kind: Secret): ES/sidecar-auth/license/TLS key-name contract, per-key overrides, envFrom mode, Secret-backed federation→sidecar creds (CONFIG_FORCE_* via Typesafe Configoverride_with_env_vars), TLS-at-Ingress termination + Ingress template, secret-backend docs (raw/SealedSecrets/ESO/Vault) and example manifests.Static gates: helm lint OK (base + 3 fixtures), kubeconform OK (3/9/7/8 resources valid), all four goldens (default, two-sidecars, secret-auth, ingress-tls) match unchanged, zero
kind: Secretrendered.Stacked on Story 16.2 (base:
feature/16.2). Part of the Epic-16 stacked chart chain. Live kind installs pull the public DockerHub images and are gated until published (OQ-1).Closes #5
🤖 Generated with Claude Code