From fc95ab92ac155dc888b8903a86dd459e7888d545 Mon Sep 17 00:00:00 2001 From: marcopiraccini Date: Mon, 28 Sep 2026 16:58:41 +0200 Subject: [PATCH 1/2] feat: invite user and dev login Signed-off-by: marcopiraccini --- README.md | 5 +++++ profiles/development.yaml | 13 +++++++++++++ schemas/v4/profile.js | 8 +++++++- tests/profile-schema.test.js | 5 ++++- 4 files changed, 29 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 4b6942f..29cd835 100644 --- a/README.md +++ b/README.md @@ -417,6 +417,11 @@ This profile: - Sets `DEV_K8S=true` to enable Platformatic DB service file watching - Uses the same base image (`node:22.20.0-alpine`) as production for native module compatibility - Enables ICC skew protection, so `desk deploy` creates a separate versioned workload for every deploy (see [`deploy`](#deploy)) +- Adds a development-only "Log in as" to the ICC login page, next to GitHub, + to test teams and permissions with several users: log in with GitHub as the + super-admin (an email in `GITHUB_OAUTH_VALID_EMAILS`), invite test accounts + in Settings > Users, then use "Log in as" with their emails. It bypasses + authentication, so it is for local clusters only When code changes are made in the local repositories, the services will automatically reload. diff --git a/profiles/development.yaml b/profiles/development.yaml index 9082a0a..46ac486 100644 --- a/profiles/development.yaml +++ b/profiles/development.yaml @@ -62,6 +62,8 @@ platformatic: default_routing_mode: query # query | cookie; per-app override in ICC settings icc_jobs: enable: true + invite_users: + enable: true # "Invite users" in Settings > Users (chart > 4.3.0) login_methods: google: @@ -74,6 +76,17 @@ platformatic: client_id: "{{ GITHUB_OAUTH_CLIENT_ID }}" client_secret: "{{ GITHUB_OAUTH_CLIENT_SECRET }}" valid_emails: "{{ GITHUB_OAUTH_VALID_EMAILS }}" + # Development-only "Log in as" on the login page: signs in as any + # existing account by email, to test teams and permissions with + # several users. Adds `dev` to VITE_SUPPORTED_LOGINS. + dev: + enable: true + + env: + # Turns on the gateway route behind "Log in as" (GET /api/login/dev). + # It bypasses authentication: local clusters only. + - name: PLT_DEV_LOGIN_AS + value: "true" log_level: info diff --git a/schemas/v4/profile.js b/schemas/v4/profile.js index 5e45091..209178e 100644 --- a/schemas/v4/profile.js +++ b/schemas/v4/profile.js @@ -76,7 +76,13 @@ const IccSpecificSchema = Type.Object({ client_secret: Type.Optional(Type.String()), valid_emails: Type.Optional(Type.String()) }))), - secrets: Type.Optional(Type.Record(Type.String(), Type.String())) + secrets: Type.Optional(Type.Record(Type.String(), Type.String())), + // Extra environment variables for the ICC container, appended by the + // chart after its own. Declared here because parsing drops unknown keys. + env: Type.Optional(Type.Array(Type.Object({ + name: Type.String(), + value: Type.String() + }))) }) const ImagePullSecretSchema = Type.Object({ diff --git a/tests/profile-schema.test.js b/tests/profile-schema.test.js index 7ad584c..75daa4a 100644 --- a/tests/profile-schema.test.js +++ b/tests/profile-schema.test.js @@ -68,7 +68,10 @@ test('parse a full v4 profile', async t => { }, secrets: { icc_session: 'aaaaaaaaaaaaaaaaaaaaaaaa' - } + }, + env: [ + { name: 'PLT_DEV_LOGIN_AS', value: 'true' } + ] }, machinist: { From ec269db2a150f8bb0178e9fe14b948818b2b8763 Mon Sep 17 00:00:00 2001 From: marcopiraccini Date: Thu, 1 Oct 2026 14:23:46 +0200 Subject: [PATCH 2/2] helm v4.4.0 Signed-off-by: marcopiraccini --- charts/v4/config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/charts/v4/config.yaml b/charts/v4/config.yaml index e2d5a12..b1e0994 100644 --- a/charts/v4/config.yaml +++ b/charts/v4/config.yaml @@ -24,7 +24,7 @@ cluster: dependencies: platformatic/helm: location: 'oci://ghcr.io/platformatic/helm' - version: '4.3.0' + version: '4.4.0' releaseName: 'platformatic' namespace: 'platformatic'