Skip to content

fix: chart should render configs required by hsm-adapter - #2242

Merged
bosbaber merged 1 commit into
v1from
stephan/int-626
Sep 16, 2026
Merged

bosbaber merged 1 commit into
v1from
stephan/int-626

Conversation

@bosbaber

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions github-actions Bot added package: wallet/backend Wallet backend implementations type: test Improvements or additions to tests type: source Source changes package: boutique/backend Boutique backend implementations labels Sep 16, 2026
@bosbaber bosbaber changed the title Stephan/int 626 fix: chart should render configs required by hsm-adapter Sep 16, 2026
@bosbaber
bosbaber requested a lite review from Copilot September 16, 2026 15:06
@bosbaber
bosbaber changed the base branch from main to v1 September 16, 2026 15:06

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new config.backend.secretName setting can mislead users into a broken configuration when combined with shouldCreateSecrets: true, and should be clarified or validated to prevent creating one Secret while the pod reads another.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This PR updates the testnet-wallet Helm chart to support HSM adapter configuration and allow backend credentials to be sourced from a Secret whose name is provided externally (e.g., by a secret operator), while improving value rendering correctness for large numeric config values.

Changes:

  • Added HSM adapter configuration values and conditional ConfigMap rendering for HSM-related env vars (with render-time validation when enabled).
  • Introduced config.backend.secretName and updated backend Deployment secretKeyRef references to use it (with unit tests).
  • Quoted config.backend.cookie.ttl to avoid scientific-notation rendering in the ConfigMap.
File summaries
File Description
helm/testnet-wallet/values.yaml Adds secretName, fixes cookie TTL typing, and introduces HSM adapter configuration + deployment wiring notes.
helm/testnet-wallet/templates/configMap.backend.yaml Conditionally merges HSM adapter env vars into the backend ConfigMap and fails rendering when required HSM fields are missing.
helm/testnet-wallet/tests/deployment.backend_test.yaml Adds Helm unit tests for secretName behavior and for volume/volumeMounts overrides used by HSM TLS mounts.
helm/testnet-wallet/tests/configMap.backend_test.yaml Adds Helm unit tests verifying HSM env vars are omitted when disabled, emitted when enabled, and validated when required fields are missing.
Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread helm/testnet-wallet/values.yaml
@bosbaber
bosbaber merged commit d87fc39 into v1 Sep 16, 2026
18 of 19 checks passed
@bosbaber
bosbaber deleted the stephan/int-626 branch September 16, 2026 15:14
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

package: boutique/backend Boutique backend implementations package: wallet/backend Wallet backend implementations released on @v1 type: source Source changes type: test Improvements or additions to tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants