Skip to content

Release chart 3.15.0 for BaSyx Go 1.1.0 with ReBAC and eventing configuration - #107

Merged
aaronzi merged 3 commits into
eclipse-basyx:mainfrom
aaronzi:release/basyx-go-1.1.0
Sep 28, 2026
Merged

aaronzi merged 3 commits into
eclipse-basyx:mainfrom
aaronzi:release/basyx-go-1.1.0

Conversation

@aaronzi

@aaronzi aaronzi commented Sep 28, 2026

Copy link
Copy Markdown
Member

Updates the chart to BaSyx Go 1.1.0 and models the configuration introduced since 1.0.12.

Note: BaSyx Go 1.1.0 is not released yet. Merge this PR after the 1.1.0 images are published; until then the default image tags do not resolve.

Version

  • bumps the chart version to 3.15.0
  • sets the chart app version to 1.1.0
  • updates the README image-tag example and adds an upgrade note for 3.15.0

ReBAC (experimental)

  • new global rebac values (enabled, subjectClaim, groupClaim, administrators) rendered as REBAC_* and overridable per service via <service>.rebac
  • rendering fails when ReBAC is enabled on a service without ABAC, matching the BaSyx Go startup check. Company Lookup and Digital Twin Registry are exempt because they do not support ReBAC
  • README section on setup, Keycloak group claims and supported services

Eventing (experimental)

Previously only enabled, format, sinks, outboxEnabled and topicPrefix were modeled, and the docs said eventing was not implemented. Now:

  • eventing.sourceBaseUrl and eventing.schemaBaseUrl
  • eventing.mqtt.*, eventing.kafka.* and eventing.amqp.*, including TLS and credential (file) settings
  • eventing.feed.* for the REST Event Feed
  • the MQTT client ID defaults to the pod name, so every replica of every service connects with a unique ID
  • the schema validates sinks, MQTT QoS, Kafka SASL mechanisms and batch size

General

  • adds general.delegatedOperationResponseMaxSizeBytes

All new keys are rendered through one mapping-driven helper that serves both the common-config Secret and the service-local overrides. environment.common and <service>.environment still take precedence.

Validation

  • helm lint charts/basyx
  • linted and rendered all example values under values/
  • helm unittest charts/basyx: 276 tests, including the new eventing_rebac_config_test.yaml. The pinned common-config checksum in the observability test is updated because the Secret now carries the new keys
  • rendered a deployment with MQTT, Kafka, AMQP, the feed and ReBAC enabled, and checked the resulting env against the BaSyx Go config loader

🤖 Generated with Claude Code

…guration

- Bump appVersion to BaSyx Go 1.1.0 and the chart to 3.15.0.
- Add global and per-service rebac values (enabled, subjectClaim,
  groupClaim, administrators) and fail rendering when ReBAC is enabled
  without ABAC on a supporting service.
- Model all eventing settings: shared source/schema URLs, MQTT, Kafka,
  AMQP and the REST Event Feed. Default the MQTT client ID to the pod name
  so every replica connects with a unique ID.
- Add general.delegatedOperationResponseMaxSizeBytes.
- Extend the values schema, README and unit tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aaronzi
aaronzi requested review from antesch and a lite review from Copilot September 28, 2026 14:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved template issues affect environment precedence, empty overrides, MQTT client IDs, and configuration checksum rollouts.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity

Open (4)
What changed in this PR

Updates the BaSyx Helm chart to 3.15.0 / BaSyx Go 1.1.0 with ReBAC and expanded eventing configuration.

Changes:

  • Adds ReBAC, MQTT, Kafka, AMQP, and REST Event Feed settings.
  • Updates schema validation, documentation, versions, and checksum tests.
  • Adds delegated operation limits and MQTT client-ID defaults.
File Summary
README.md Documents new configuration and upgrade guidance.
charts/​basyx/​values.yaml Adds eventing, ReBAC, and general defaults.
charts/​basyx/​values.schema.json Validates new configuration fields.
charts/​basyx/​tests/​observability_config_test.yaml Updates checksum expectations.
charts/​basyx/​tests/​eventing_rebac_config_test.yaml Tests eventing and ReBAC behavior.
charts/​basyx/​templates/​_helpers.tpl Renders configuration and validation logic.
charts/​basyx/​Chart.yaml Updates chart and application versions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread charts/basyx/templates/_helpers.tpl Outdated
Comment thread charts/basyx/templates/_helpers.tpl
Comment thread charts/basyx/templates/_helpers.tpl Outdated
Comment thread charts/basyx/templates/_helpers.tpl Outdated
- Resolve REBAC_ENABLED and BASYX_EVENTING_SINKS with the rendered
  precedence (service environment, service values, environment.common,
  global values) for the ReBAC/ABAC check and the MQTT client ID default.
- Include rebac values in the common-config rollout checksum.
- Render empty service-local lists so they clear a global list.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@aaronzi aaronzi left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed b73d1cd. Found three configuration edge cases detailed inline. Validation: helm lint, all 282 unit tests, and all 11 example values renders passed; targeted render reproductions and a Kubernetes structured-merge parser check exposed the findings. No live-cluster deployment was performed.

Comment thread charts/basyx/templates/_helpers.tpl Outdated
Comment thread charts/basyx/templates/_helpers.tpl Outdated
Comment thread charts/basyx/templates/_helpers.tpl Outdated
- Emit a single BASYX_EVENTING_MQTT_CLIENT_ID entry when a service-local
  empty client ID selects the pod-name default.
- Evaluate templates when resolving effective environment values.
- Accept raw ABAC_ENABLED from the service environment or
  environment.common in the ReBAC prerequisite check.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aaronzi
aaronzi merged commit 821262a into eclipse-basyx:main Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants