From c9cca510d222eae38d4e43ceb72cde00fffcb9dd Mon Sep 17 00:00:00 2001 From: Dmitry Kondratyev Date: Tue, 8 Sep 2026 18:10:48 -0400 Subject: [PATCH 1/2] Allow scaleFromZero with a custom Envoy configuration The chart no longer refuses scaleFromZero.enabled together with envoy.external_config.load_from_configmap. A custom configuration is responsible for the clusters, Lua filter and routes that the generated one would have added. The Lua ConfigMap is now created for external configs as well; the Envoy Deployment mounts it whenever the filter is enabled, so without it the pod could not start. Co-Authored-By: Claude Opus 5 --- docs/configuration-guide.rst | 10 +++++----- helm/supersonic/templates/envoy/admission.yaml | 3 --- helm/supersonic/templates/envoy/configmaps.yaml | 2 +- 3 files changed, 6 insertions(+), 9 deletions(-) diff --git a/docs/configuration-guide.rst b/docs/configuration-guide.rst index 8fe2d7fe..2b3e40b3 100644 --- a/docs/configuration-guide.rst +++ b/docs/configuration-guide.rst @@ -163,10 +163,10 @@ default configuration completely (the configuration file must be supplied as a C configmap_name: external-envoy-config configmap_key: envoy.yaml -.. warning:: - - ``scaleFromZero.enabled`` cannot be used with ``envoy.external_config.load_from_configmap``. - Scale-from-zero injects Envoy clusters and a Lua filter that an external ConfigMap would replace. +``scaleFromZero`` and the prometheus-based rate limiter work with an external +configuration only if it carries the clusters, Lua filter and routes that the generated +configuration would have added (see ``templates/envoy/configmaps.yaml``); the chart does +not check for them. 5. (Optional) Configure Rate Limiting in Envoy Proxy ====================================================== @@ -408,7 +408,7 @@ count. Helm upgrades keep the live ScaledObject ``minReplicaCount`` so they do n interrupt an active hold. The hold deadline is stored as an annotation on the ScaledObject, so the admission sidecars of multiple Envoy replicas share one hold and none can release a peer's active hold. ``scaleFromZero`` requires ``keda.enabled`` and -``envoy.enabled``, and cannot be used with an external Envoy ConfigMap. +``envoy.enabled``. Do not set ``keda.zeroIdleReplicas: true`` together with ``minReplicaCount: 0``. ``zeroIdleReplicas`` sets KEDA ``idleReplicaCount`` to 0 and cannot scale from 0 back to 1 diff --git a/helm/supersonic/templates/envoy/admission.yaml b/helm/supersonic/templates/envoy/admission.yaml index 03b7860b..bfdf5d39 100644 --- a/helm/supersonic/templates/envoy/admission.yaml +++ b/helm/supersonic/templates/envoy/admission.yaml @@ -5,9 +5,6 @@ {{- if not .Values.envoy.enabled }} {{- fail "scaleFromZero.enabled requires envoy.enabled" }} {{- end }} -{{- if .Values.envoy.external_config.load_from_configmap }} -{{- fail "scaleFromZero.enabled is incompatible with envoy.external_config.load_from_configmap" }} -{{- end }} apiVersion: v1 kind: ServiceAccount metadata: diff --git a/helm/supersonic/templates/envoy/configmaps.yaml b/helm/supersonic/templates/envoy/configmaps.yaml index fa74e4fb..7b14cd79 100644 --- a/helm/supersonic/templates/envoy/configmaps.yaml +++ b/helm/supersonic/templates/envoy/configmaps.yaml @@ -303,7 +303,7 @@ data: {{- end }} --- -{{- if and (include "supersonic.luaFilterEnabled" .) (not .Values.envoy.external_config.load_from_configmap) }} +{{- if (include "supersonic.luaFilterEnabled" .) }} {{- /* Create a ConfigMap for the Lua filter */}} apiVersion: v1 kind: ConfigMap From 7ad02a2b74ae1402bbcd61624d39c153d371ccea Mon Sep 17 00:00:00 2001 From: Dmitry Kondratyev Date: Mon, 7 Sep 2026 10:21:08 -0400 Subject: [PATCH 2/2] Pin kube-prometheus-stack in CI and the README install steps The Prometheus Operator install floats on whatever prometheus-community/kube-prometheus-stack is latest. 90.0.0, published between 2026-09-05 and 2026-09-07, made the control-plane ServiceMonitors authenticate via a Secret that is only rendered when prometheus.enabled and prometheus.serviceAccount.create are both true. These call sites pass prometheus.enabled=false -- they want the operator and its CRDs, nothing else -- so templating now fails: The control-plane ServiceMonitors authenticate by default with the Secret created by prometheus.serviceAccount.createTokenSecret, which is only rendered when prometheus.enabled and prometheus.serviceAccount.create are also true. Bisected: 89.2.4 and every earlier release template fine with these flags; 90.0.0 is the first that does not. Pinning 89.2.4 keeps CI reproducible and matches how the chart's own dependencies are pinned. 89.2.4 still ships the servicemonitors CRD and the operator Deployment, which is all these steps need. The alternative -- tracking latest and disabling every control-plane exporter (kubelet, kubeApiServer, kubeControllerManager, kubeScheduler, kubeProxy, kubeEtcd, coreDns) -- also works on 90.0.0 but adds seven flags to each call site and would not protect against the next upstream change. This break is independent of this branch: it fails identically on main, which has not run CI since 90.0.0 was published. Co-Authored-By: Claude Opus 5 (cherry picked from commit 444bdc334d9c9c83bde6c99b11b07abf6eab6491) --- .github/workflows/ci-external-config.yaml | 2 +- .github/workflows/ci-full.yaml | 2 +- .github/workflows/ci-local.sh | 1 + README.md | 2 +- helm/supersonic/README.md | 2 +- 5 files changed, 5 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci-external-config.yaml b/.github/workflows/ci-external-config.yaml index a0072e49..7fcf9af4 100644 --- a/.github/workflows/ci-external-config.yaml +++ b/.github/workflows/ci-external-config.yaml @@ -34,7 +34,7 @@ jobs: helm repo add prometheus-community https://prometheus-community.github.io/helm-charts helm repo update kubectl create namespace monitoring - helm install prometheus-operator prometheus-community/kube-prometheus-stack --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false + helm install prometheus-operator prometheus-community/kube-prometheus-stack --version 89.2.4 --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false - name: Install KEDA Autoscaler run: | diff --git a/.github/workflows/ci-full.yaml b/.github/workflows/ci-full.yaml index 9416fc7d..6811db2a 100644 --- a/.github/workflows/ci-full.yaml +++ b/.github/workflows/ci-full.yaml @@ -34,7 +34,7 @@ jobs: helm repo add prometheus-community https://prometheus-community.github.io/helm-charts helm repo update kubectl create namespace monitoring - helm install prometheus-operator prometheus-community/kube-prometheus-stack --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false + helm install prometheus-operator prometheus-community/kube-prometheus-stack --version 89.2.4 --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false - name: Install KEDA Autoscaler run: | diff --git a/.github/workflows/ci-local.sh b/.github/workflows/ci-local.sh index 7f255758..6bc72588 100644 --- a/.github/workflows/ci-local.sh +++ b/.github/workflows/ci-local.sh @@ -53,6 +53,7 @@ helm repo add prometheus-community https://prometheus-community.github.io/helm-c helm repo update kubectl create namespace monitoring helm install prometheus-operator prometheus-community/kube-prometheus-stack \ + --version 89.2.4 \ --namespace monitoring \ --set prometheusOperator.createCustomResource=false \ --set defaultRules.create=false \ diff --git a/README.md b/README.md index 45a9fe60..6d77631c 100644 --- a/README.md +++ b/README.md @@ -55,7 +55,7 @@ Currently, SuperSONIC supports the following functionality: helm repo add prometheus-community https://prometheus-community.github.io/helm-charts helm repo update kubectl create namespace monitoring - helm install prometheus-operator prometheus-community/kube-prometheus-stack --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false + helm install prometheus-operator prometheus-community/kube-prometheus-stack --version 89.2.4 --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false ``` - [KEDA](https://keda.sh) CRDs (only if using autoscaling) diff --git a/helm/supersonic/README.md b/helm/supersonic/README.md index 45a9fe60..6d77631c 100644 --- a/helm/supersonic/README.md +++ b/helm/supersonic/README.md @@ -55,7 +55,7 @@ Currently, SuperSONIC supports the following functionality: helm repo add prometheus-community https://prometheus-community.github.io/helm-charts helm repo update kubectl create namespace monitoring - helm install prometheus-operator prometheus-community/kube-prometheus-stack --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false + helm install prometheus-operator prometheus-community/kube-prometheus-stack --version 89.2.4 --namespace monitoring --set prometheusOperator.createCustomResource=false --set defaultRules.create=false --set alertmanager.enabled=false --set prometheus.enabled=false --set grafana.enabled=false ``` - [KEDA](https://keda.sh) CRDs (only if using autoscaling)