Repository navigation
Release chart 3.15.0 for BaSyx Go 1.1.0 with ReBAC and eventing configuration - #107
Conversation
…guration - Bump appVersion to BaSyx Go 1.1.0 and the chart to 3.15.0. - Add global and per-service rebac values (enabled, subjectClaim, groupClaim, administrators) and fail rendering when ReBAC is enabled without ABAC on a supporting service. - Model all eventing settings: shared source/schema URLs, MQTT, Kafka, AMQP and the REST Event Feed. Default the MQTT client ID to the pod name so every replica connects with a unique ID. - Add general.delegatedOperationResponseMaxSizeBytes. - Extend the values schema, README and unit tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved template issues affect environment precedence, empty overrides, MQTT client IDs, and configuration checksum rollouts.
Review effort: Lite
Findings: 1
Open (4)
What changed in this PR
Updates the BaSyx Helm chart to 3.15.0 / BaSyx Go 1.1.0 with ReBAC and expanded eventing configuration.
Changes:
- Adds ReBAC, MQTT, Kafka, AMQP, and REST Event Feed settings.
- Updates schema validation, documentation, versions, and checksum tests.
- Adds delegated operation limits and MQTT client-ID defaults.
| File | Summary |
|---|---|
README.md |
Documents new configuration and upgrade guidance. |
charts/basyx/values.yaml |
Adds eventing, ReBAC, and general defaults. |
charts/basyx/values.schema.json |
Validates new configuration fields. |
charts/basyx/tests/observability_config_test.yaml |
Updates checksum expectations. |
charts/basyx/tests/eventing_rebac_config_test.yaml |
Tests eventing and ReBAC behavior. |
charts/basyx/templates/_helpers.tpl |
Renders configuration and validation logic. |
charts/basyx/Chart.yaml |
Updates chart and application versions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Resolve REBAC_ENABLED and BASYX_EVENTING_SINKS with the rendered precedence (service environment, service values, environment.common, global values) for the ReBAC/ABAC check and the MQTT client ID default. - Include rebac values in the common-config rollout checksum. - Render empty service-local lists so they clear a global list. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
aaronzi
left a comment
There was a problem hiding this comment.
Reviewed b73d1cd. Found three configuration edge cases detailed inline. Validation: helm lint, all 282 unit tests, and all 11 example values renders passed; targeted render reproductions and a Kubernetes structured-merge parser check exposed the findings. No live-cluster deployment was performed.
- Emit a single BASYX_EVENTING_MQTT_CLIENT_ID entry when a service-local empty client ID selects the pod-name default. - Evaluate templates when resolving effective environment values. - Accept raw ABAC_ENABLED from the service environment or environment.common in the ReBAC prerequisite check. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>


Updates the chart to BaSyx Go 1.1.0 and models the configuration introduced since 1.0.12.
Version
ReBAC (experimental)
rebacvalues (enabled,subjectClaim,groupClaim,administrators) rendered asREBAC_*and overridable per service via<service>.rebacEventing (experimental)
Previously only
enabled,format,sinks,outboxEnabledandtopicPrefixwere modeled, and the docs said eventing was not implemented. Now:eventing.sourceBaseUrlandeventing.schemaBaseUrleventing.mqtt.*,eventing.kafka.*andeventing.amqp.*, including TLS and credential (file) settingseventing.feed.*for the REST Event FeedGeneral
general.delegatedOperationResponseMaxSizeBytesAll new keys are rendered through one mapping-driven helper that serves both the common-config Secret and the service-local overrides.
environment.commonand<service>.environmentstill take precedence.Validation
helm lint charts/basyxvalues/helm unittest charts/basyx: 276 tests, including the neweventing_rebac_config_test.yaml. The pinned common-config checksum in the observability test is updated because the Secret now carries the new keys🤖 Generated with Claude Code