Repository navigation
fix: chart should render configs required by hsm-adapter - #2242
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The new config.backend.secretName setting can mislead users into a broken configuration when combined with shouldCreateSecrets: true, and should be clarified or validated to prevent creating one Secret while the pod reads another.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This PR updates the testnet-wallet Helm chart to support HSM adapter configuration and allow backend credentials to be sourced from a Secret whose name is provided externally (e.g., by a secret operator), while improving value rendering correctness for large numeric config values.
Changes:
- Added HSM adapter configuration values and conditional ConfigMap rendering for HSM-related env vars (with render-time validation when enabled).
- Introduced
config.backend.secretNameand updated backend Deployment secretKeyRef references to use it (with unit tests). - Quoted
config.backend.cookie.ttlto avoid scientific-notation rendering in the ConfigMap.
File summaries
| File | Description |
|---|---|
helm/testnet-wallet/values.yaml |
Adds secretName, fixes cookie TTL typing, and introduces HSM adapter configuration + deployment wiring notes. |
helm/testnet-wallet/templates/configMap.backend.yaml |
Conditionally merges HSM adapter env vars into the backend ConfigMap and fails rendering when required HSM fields are missing. |
helm/testnet-wallet/tests/deployment.backend_test.yaml |
Adds Helm unit tests for secretName behavior and for volume/volumeMounts overrides used by HSM TLS mounts. |
helm/testnet-wallet/tests/configMap.backend_test.yaml |
Adds Helm unit tests verifying HSM env vars are omitted when disabled, emitted when enabled, and validated when required fields are missing. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🎉 This PR is included in version 1.0.1 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
No description provided.