refactor(deploy): externalize compose credentials and subsystem test secrets (FLPATH-4806) - #60
Conversation
ca0c17e to
e08fd2f
Compare
PR Summary by QodoExternalize Compose and subsystem test credentials
AI Description
Diagram
High-Level Assessment
Files changed (12)
|
Code Review by Qodo
1.
|
|
@chadcrum fyi — once this merges, |
@vkolodny I'll update those today. |
8cba8ca to
6beae86
Compare
|
@gciavarrini would you mind approving unless there is anything else? thanks! |
51c7c97 to
a79e68e
Compare
…secrets (FLPATH-4806) Move deploy and subsystem test credentials into gitignored .env files and update Compose, subsystem tests, and documentation to use the shared configuration. Gate Keycloak behind AUTH=true, keep compose and Helm realm artifacts intentionally separate for the companion Helm change, and fix the auth subsystem setup to use the configured PostgreSQL credentials. https://redhat.atlassian.net/browse/FLPATH-4806 Signed-off-by: Chad Crum <ccrum@redhat.com>
398460d to
95d13c8
Compare
…hart-sync) The helm-chart CI check compares deploy/helm/dcm/files/realm-export.json against deploy/keycloak/realm-export.json; upstream dcm-project#60 changed the source without re-syncing the copy. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MKx3FVWeYTVMrrn1aFtczf
…ATH-4806) (#66) ## Summary - Require pre-created Kubernetes SecretRefs for Helm database and authentication credentials instead of inline values or chart-managed credential Secrets. - Update the bundled Keycloak realm import to use `${AUTH_PROXY_SECRET}` and `${DCM_DEV_USER_PASSWORD}` placeholders. - Document the required database, pull, auth, and kubeconfig Secrets and update schema verification cases. ## Related PRs - #60 - companion Compose credential and subsystem test-secret changes. - dcm-project/utilities#46 - companion utilities deployment secret bootstrap and auth flag changes. ## Expected CI failure The **Helm chart** job is expected to fail on this PR until the companion changes land. PR #60 updates `deploy/keycloak/realm-export.json` (the Compose source) but intentionally leaves `deploy/helm/dcm/files/realm-export.json` unchanged; this PR updates the Helm copy. While either PR is tested alone, `helm-chart-verify-sync` reports a stale or mismatched realm file. Once PRs #60 and #46 are merged, the Helm CI test is expected to pass. ## Issue https://redhat.atlassian.net/browse/FLPATH-4806 --------- Signed-off-by: Chad Crum <ccrum@redhat.com> Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
Externalize deploy and subsystem test credentials from committed Compose configuration.
deploy/.env.test/subsystem/.env..env.examplefiles and Makefile setup prerequisites.authCompose profile viaAUTH=true..envfiles explicitly for Compose interpolation.CI note
The Helm chart job is expected to fail until the companion Helm change synchronizes the generated realm file. This PR intentionally updates the Compose realm file without updating the Helm copy.
https://redhat.atlassian.net/browse/FLPATH-4806