feat(deploy): bootstrap deploy/.env and add auth-enabled flag (FLPATH-4806) - #46
Conversation
PR Summary by QodoBootstrap deploy secrets and support auth-enabled E2E stacks
AI Description
Diagram
High-Level Assessment
Files changed (6)
|
Code Review by Qodo
1.
|
testetson22
left a comment
There was a problem hiding this comment.
PR body points at control-plane #60; thread also references #66. In-repo docs don’t state a hard dependency on merged externalized deploy/.env.
| Location | Lines | What |
|---|---|---|
| GitHub PR #46 description | ~191–192 | “Depends on: control-plane#60 …” |
README.md |
38–39 | Mentions bootstrap from .env.example; no issue/PR pin |
scripts/deploy-dcm.sh |
649–652 | Fails if deploy/.env.example missing (needs control-plane with FLPATH-4806 layout) |
|
Most of my feedback is clarity-focused. Functionally everything seems fine, we just might end up with some confusion, particularly if an agent is trying to run through the scripts, parse docs, etc. |
…-4806) Align utilities E2E deploy with control-plane externalized compose credentials: bootstrap deploy/.env after clone, wire --auth-enabled and Jenkins AUTH_DISABLED env through compose auth profile, and forward auth flags from run-e2e.sh. Signed-off-by: Chad Crum <ccrum@redhat.com> Co-authored-by: Cursor <cursoragent@cursor.com>
Signed-off-by: Chad Crum <ccrum@redhat.com>
01d7087 to
1e9821f
Compare
Signed-off-by: Chad Crum <ccrum@redhat.com>
gciavarrini
left a comment
There was a problem hiding this comment.
Only 2 minor comments, not blockers
Signed-off-by: Chad Crum <ccrum@redhat.com>
…ATH-4806) (#66) ## Summary - Require pre-created Kubernetes SecretRefs for Helm database and authentication credentials instead of inline values or chart-managed credential Secrets. - Update the bundled Keycloak realm import to use `${AUTH_PROXY_SECRET}` and `${DCM_DEV_USER_PASSWORD}` placeholders. - Document the required database, pull, auth, and kubeconfig Secrets and update schema verification cases. ## Related PRs - #60 - companion Compose credential and subsystem test-secret changes. - dcm-project/utilities#46 - companion utilities deployment secret bootstrap and auth flag changes. ## Expected CI failure The **Helm chart** job is expected to fail on this PR until the companion changes land. PR #60 updates `deploy/keycloak/realm-export.json` (the Compose source) but intentionally leaves `deploy/helm/dcm/files/realm-export.json` unchanged; this PR updates the Helm copy. While either PR is tested alone, `helm-chart-verify-sync` reports a stale or mismatched realm file. Once PRs #60 and #46 are merged, the Helm CI test is expected to pass. ## Issue https://redhat.atlassian.net/browse/FLPATH-4806 --------- Signed-off-by: Chad Crum <ccrum@redhat.com> Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
Aligns utilities deploy and E2E harness with control-plane compose externalized secrets (dcm-project/control-plane#60).
deploy/.envfrom.env.exampleafter cloning control-plane, upserting DB credentials andAUTH_DISABLED--auth-enabledflag todeploy-dcm.sh(composeauthprofile + Keycloak/JWT vars in.env)--auth-enabledand--keycloak-urlfromrun-e2e.shfor Jenkins compatibilityvalidate-scripts.yamlhelp checks and update docsJira: FLPATH-4806
Depends on: control-plane#60 (
flpath-4806-compose-externalize-secrets) — deploy against that branch or merged main with externalized secrets.