Skip to content

feat: add Helm linting and chart verification GitHub Actions workflow - #3

Open
strawbs1 wants to merge 83 commits into
mainfrom
dev
Open

strawbs1 wants to merge 83 commits into
mainfrom
dev

Conversation

@strawbs1

Copy link
Copy Markdown
Collaborator

No description provided.

justinstimatze and others added 30 commits August 24, 2026 20:25
Templates agent-service's own deploy/k8s/{app,proxy,networkpolicy}.yaml raw manifests
into a Helm chart (no redesign — same two-plane split, security contexts, resource
limits, health probes, NetworkPolicy rules), wires it into Argo staging/production
via a dedicated agent-service namespace, and adds a public ingress entry for
agent-app only (never agent-proxy, which holds the real model credential).

See the PR description for the open decisions this introduces (first NetworkPolicy
in the repo, first non-experiment namespace, NetworkPolicy-enforcement caveat on
stock EKS, the two Secrets that need to exist before first sync).
Adversarial review caught two real issues:

- app.port was a values.yaml/schema knob that moved every K8s-side reference
  (containerPort, both probes, the Service, the NetworkPolicy) but never
  reached the container itself — the image's CMD hardcodes --port 8731 with
  no PORT env var read. An override would have silently broken readiness
  forever. Now passes an explicit command:, matching proxy's own pattern.
- agent-app has no Ingress-direction NetworkPolicy, which is new exposure
  this PR introduces (the raw manifests never had a public Ingress in front
  of it). A podSelector rule wouldn't actually restrict ALB traffic anyway
  (target-type: ip traffic doesn't carry a matchable pod identity) — documented
  that the real gate is the ALB's own Security Group, not something this
  chart can enforce, so nobody mistakes an absent policy for an oversight.
…orepo move

image.repository was still ghcr.io/REPLACE_ME/agent-service. agent-service's
release workflow (now living in aipotluck.org's own .github/workflows/,
after the monorepo merge) hardcodes ghcr.io/currentai-org/agent-service
rather than relying on ${{ github.repository }} — this chart needs to
match that exact string.

Also notes in the README that agent-service is now a subdirectory of
currentai-org/aipotluck.org, not its own standalone repo, so the
deploy/README.md and deploy/k8s/*.yaml paths this README points at are
relative to that repo's root.
…e agent-service with external secrets integration
…agent-service/argo-gitops

# Conflicts:
#	charts/agent-service/values.yaml
…, Qwen-SEA-LION, and Apertus-v1.5 with `access_groups` and API details
…ment, creation, and deletion events in staging apps
…org models with `access_groups` and API details
…mmented configurations for swiss-ai Apertus-v1.5-70b
…nce, and Traefik pollInterval configurability in Helm chart
…ki compatibility and update Grafana dashboard queries
…N-v4.5-27B-IT model configurations with API key support in Helm chart
…ct access for multiple Qwen models, and add Bielik model support with API key configuration in Helm chart
…ation and database name override in Helm chart
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants