Skip to content

Render namespaceFilter and netobs exclusions in the Edge ConfigMap (0.6.0) #17

Description

@stelioschar

Context

The NOFire AI Edge reads several settings that the chart's ConfigMap template never renders. If you set them through Helm values, nothing happens and nothing says so.

  • config.kube.namespaceFilter.mode and config.kube.namespaceFilter.namespaces (Edge kube.namespaceFilter, internal/edge/config/config.go). The docs advertise namespace allow/deny scoping as a feature (edge/introduction.mdx, edge/configuration.mdx#namespace-scope).
  • config.netobs.excludeNamespaces and config.netobs.edgeExistenceTtl (Edge netobs.excludeNamespaces and netobs.edgeExistenceTtl). edge/network-observability.mdx documents both, and says excludeNamespaces is seeded from the namespaceFilter deny-list.

To check this, render chart 0.5.2 with --set config.kube.namespaceFilter.mode=allow --set 'config.kube.namespaceFilter.namespaces={a,b}'. The nofire-edge-config ConfigMap has no namespaceFilter key. templates/configmap.yaml writes only configPath, resyncInterval, clusterName and resources under kube, and five fixed keys under netobs.

Chart 0.6.0 (#13) does not add these either.

We found this while writing the BYOC and GitOps install docs (NOFireAI/docs#42, NOFireAI/docs#43). Until a chart that renders these keys ships, edge/configuration.mdx carries a "Not passed through by chart 0.5.2" note on namespace scoping.

Related, same template: setting only config.services.address makes helm template fail with a nil pointer, because templates/configmap.yaml reads .Values.config.services.tls.enabled and the other services.* sub-keys without defaults.

Success criteria

  • config.kube.namespaceFilter.mode and .namespaces render into the Edge ConfigMap when set, and are left out when unset, so the Edge default (no filtering) applies.
  • config.netobs.excludeNamespaces and config.netobs.edgeExistenceTtl render when set and are left out when unset.
  • Setting config.services.address alone renders, with the chart defaulting the other services.* keys.
  • values.yaml documents the new keys, with commented examples.
  • helm lint and helm template pass with and without the new keys, and an Edge pod with an allow filter graphs only the listed namespaces.
  • Chart 0.5.3 is published.
  • The dashboard's EDGE_CHART_VERSION and the docs' version pin are bumped to 0.5.3.
  • The "Not passed through by chart 0.5.2" notes in edge/configuration.mdx are removed.

Proposal

In templates/configmap.yaml, add guarded blocks, for example {{- with .Values.config.kube.namespaceFilter }} emitting "namespaceFilter": {"mode": ..., "namespaces": [...]}. Do the same for the two netobs keys, so an unset value keeps the Edge's own default. Give the services.* sub-keys default fallbacks matching the Edge defaults.

Release it as a 0.5.3 patch, independent of #13 (0.6.0).

Activity

  1. added theissue type on Oct 7, 2026
  2. changed the title [-]Render namespaceFilter and netobs exclusions in the Edge ConfigMap (0.5.3)[/-] [+]Render namespaceFilter and netobs exclusions in the Edge ConfigMap (0.6.0)[/+] on Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions