Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ env:
# Values that are marked Required in the chart. Without them the chart fails
# fast with a clear `required` error, so CI must provide dummies.
REQUIRED_VALUES: >-
--set services.icc.database_url=postgres://user:pass@db:5432/icc
--set services.icc.database_url=postgres://user:pass@db:5432
--set services.icc.valkey.apps_url=redis://valkey:6379/0
--set services.icc.valkey.icc_url=redis://valkey:6379/1
--set services.icc.prometheus.url=http://prometheus:9090
Expand Down Expand Up @@ -49,6 +49,9 @@ jobs:
fi
echo "OK: chart fails fast when required values are missing"

- name: 'Database URL compatibility'
run: bash test/database-urls.sh

- name: 'Install kubeconform'
run: |
curl -sSL -o /tmp/kubeconform.tar.gz \
Expand Down
16 changes: 12 additions & 4 deletions MANUAL.md
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,13 @@ be accessible to the user in `database_url`. ICC applies its schema migrations
automatically when it starts. A `workflow` database is only needed if you
deploy the optional workflow service.

For an existing installation with different database names or credentials, set
the complete URLs under `services.icc.database_urls` instead. Supported keys
are `activities`, `cluster_manager`, `cold_storage`, `compliance`,
`control_plane`, `cron`, `scaler`, `trafficante`, `traffic_inspector`, and
`user_manager`. Exact URLs take precedence over `database_url`. See
`MIGRATING-v3-to-v4.md` for the v3 mapping.

For Enterprise installs, also add the registry credentials and the Enterprise
image references. Without the `image` overrides the chart pulls the public
Docker Hub images and the pull secret has no effect. Use the repositories and
Expand Down Expand Up @@ -112,7 +119,7 @@ EOF

```sh
helm install platformatic oci://ghcr.io/platformatic/helm \
--version "^4.1.0" \
--version "^4.2.0" \
--namespace platformatic --create-namespace \
-f my-values.yaml -f my-secrets.yaml
```
Expand Down Expand Up @@ -154,7 +161,7 @@ kubectl port-forward -n platformatic svc/icc 8080:80

```sh
helm upgrade platformatic oci://ghcr.io/platformatic/helm \
--version "^4.1.0" -n platformatic \
--version "^4.2.0" -n platformatic \
-f my-values.yaml -f my-secrets.yaml \
--wait --timeout 10m

Expand All @@ -168,8 +175,9 @@ helm uninstall platformatic -n platformatic

## Troubleshooting

- `services.icc.database_url is required` (or valkey / prometheus): a required
value is missing from `my-values.yaml`. See section 2.
- `services.icc.database_urls.<name> or services.icc.database_url is required`
(or valkey / prometheus): a required value is missing from `my-values.yaml`.
See section 2.
- `chart requires kubeVersion: >= 1.30.0-0`: your cluster (or Helm's default
capabilities) is below 1.30. Upgrade the cluster.
- `no matches for kind "PodMonitor"` (or `"ServiceMonitor"`): the Prometheus
Expand Down
50 changes: 40 additions & 10 deletions MIGRATING-v3-to-v4.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,8 +76,19 @@ services:
deploy: true
public_url: https://icc.example.com

# Base PostgreSQL URL without a database name.
database_url: postgres://USER:PASSWORD@HOST:5432
# Preserve the complete URLs from the v3 ICC secrets. Database names and
# credentials do not need to change. See the PostgreSQL mapping below.
database_urls:
activities: postgres://ACTIVITIES_USER:PASSWORD@HOST:5432/ACTIVITIES_DB
cluster_manager: postgres://CLUSTER_MANAGER_USER:PASSWORD@HOST:5432/CLUSTER_MANAGER_DB
cold_storage: postgres://COLD_STORAGE_USER:PASSWORD@HOST:5432/COLD_STORAGE_DB
compliance: postgres://COMPLIANCE_USER:PASSWORD@HOST:5432/COMPLIANCE_DB
control_plane: postgres://CONTROL_PLANE_USER:PASSWORD@HOST:5432/CONTROL_PLANE_DB
cron: postgres://CRON_USER:PASSWORD@HOST:5432/CRON_DB
scaler: postgres://SCALER_USER:PASSWORD@HOST:5432/SCALER_DB
trafficante: postgres://TRAFFICANTE_USER:PASSWORD@HOST:5432/TRAFFICANTE_DB
traffic_inspector: postgres://TRAFFIC_INSPECTOR_USER:PASSWORD@HOST:5432/TRAFFIC_INSPECTOR_DB
user_manager: postgres://USER_MANAGER_USER:PASSWORD@HOST:5432/USER_MANAGER_DB

valkey:
apps_url: redis://VALKEY_HOST:6379/0
Expand Down Expand Up @@ -185,18 +196,37 @@ one login method must be enabled for users to sign in.

### PostgreSQL

v3 accepted a complete URL for each ICC database. v4 accepts one URL prefix and
appends the database name for each ICC service. For example:
Preserve the complete v3 database URLs under `database_urls`. This keeps the
existing database names, users, passwords, and permissions:

| v3 `services.icc.secrets` key | v4 `services.icc.database_urls` key |
| --- | --- |
| `PLT_ACTIVITIES_DATABASE_URL` | `activities` |
| `PLT_CLUSTER_MANAGER_DATABASE_URL` | `cluster_manager` |
| `PLT_COLD_STORAGE_DATABASE_URL` | `cold_storage` |
| `PLT_COMPLIANCE_DATABASE_URL` | `compliance` |
| `PLT_CONTROL_PLANE_DATABASE_URL` | `control_plane` |
| `PLT_CRON_DATABASE_URL` | `cron` |
| `PLT_SCALER_DATABASE_URL` | `scaler` |
| `PLT_TRAFFICANTE_DATABASE_URL` | `trafficante` |
| `PLT_TRAFFIC_INSPECTOR_DATABASE_URL` | `traffic_inspector` |
| `PLT_USER_MANAGER_DATABASE_URL` | `user_manager` |

If Traffic Inspector and Trafficante used the same URL in v3, omit
`traffic_inspector`; it falls back to the `trafficante` URL.

Installations where every database already uses one role and the standard v4
database names may use a single URL prefix instead:

```yaml
database_url: postgres://icc:secret@postgres.example.com:5432
```

The base URL must not contain a database name or a trailing slash. The required
databases are `activities`, `risk_cold_storage`, `control_plane`, `cron`,
`scaler`, `trafficante`, `user_manager`, `cluster_manager`, and `compliance`.
They must exist and be accessible to the configured role. ICC applies its schema
migrations automatically when it starts. The `workflow` database is not used
The base URL must not contain a database name or trailing slash. The chart
appends `activities`, `risk_cold_storage`, `control_plane`, `cron`, `scaler`,
`trafficante`, `user_manager`, `cluster_manager`, and `compliance`. Exact URLs
take precedence over the base URL, so both forms can be combined. ICC applies
schema migrations automatically when it starts. No Workflow URL is required
while `services.workflow.deploy` is `false`.

### Valkey and login
Expand Down Expand Up @@ -276,7 +306,7 @@ Use the same Helm release name and release namespace as v3. Pin the exact v4
chart version that you tested.

```sh
CHART_VERSION=4.1.0
CHART_VERSION=4.2.0

helm upgrade "$RELEASE" oci://ghcr.io/platformatic/helm \
--version "$CHART_VERSION" \
Expand Down
3 changes: 2 additions & 1 deletion README-ENTERPRISE.md
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,8 @@ production-ready set of values except for the `secrets` portion.
| `services.icc.image.pullPolicy` | When to pull an image update | IfNotPresent | No |
| `services.icc.log_level` | The level to log ICC services | warn | No |
| `services.icc.public_url` | The URL to access Intelligent Command Center (Note: ingress and domain must be configured by the user | "" | Yes |
| `services.icc.database_url` | The database connection string | "" | Yes |
| `services.icc.database_url` | Base database connection string used when an exact URL is not set | "" | Conditional |
| `services.icc.database_urls` | Exact connection strings keyed by ICC database service | {} | Conditional |
| `services.icc.valkey.apps_url` | Valkey connection string | "" | Yes |
| `services.icc.valkey.icc_url` | Valkey connection string | "" | Yes |
| `services.icc.prometheus.url` | Prometheus API URL | "" | Yes |
Expand Down
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,8 @@ production-ready set of values except for the `secrets` portion.
| `services.icc.image.pullPolicy` | When to pull an image update | IfNotPresent | No |
| `services.icc.log_level` | The level to log ICC services | warn | No |
| `services.icc.public_url` | The URL to access Intelligent Command Center (Note: ingress and domain must be configured by the user | "" | Yes |
| `services.icc.database_url` | The database connection string | "" | Yes |
| `services.icc.database_url` | Base database connection string used when an exact URL is not set | "" | Conditional |
| `services.icc.database_urls` | Exact connection strings keyed by ICC database service | {} | Conditional |
| `services.icc.valkey.apps_url` | Valkey connection string | "" | Yes |
| `services.icc.valkey.icc_url` | Valkey connection string | "" | Yes |
| `services.icc.prometheus.url` | Prometheus API URL | "" | Yes |
Expand Down
2 changes: 1 addition & 1 deletion chart/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
apiVersion: v2
name: helm
version: 4.1.0
version: 4.2.0
kubeVersion: ">= 1.30.0-0"
description: Platformatic microservices
type: application
Expand Down
36 changes: 33 additions & 3 deletions chart/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -96,8 +96,38 @@ platformatic
NodePort
{{- end }}

{{/* ICC databases */}}
{{/* Using trafficante database name so that we an safely upgrade existing users */}}
{{/* ICC database connection names */}}
{{- define "service.icc.databases" -}}
activities risk_cold_storage control_plane cron scaler trafficante user_manager cluster_manager compliance workflow
activities cluster_manager cold_storage compliance control_plane cron scaler trafficante traffic_inspector user_manager
{{- end }}

{{/* Database name appended to the base URL when no exact URL is configured */}}
{{- define "service.icc.databaseName" -}}
{{- $database := index . 0 -}}
{{- if eq $database "cold_storage" -}}
risk_cold_storage
{{- else if eq $database "traffic_inspector" -}}
trafficante
{{- else -}}
{{- $database -}}
{{- end -}}
{{- end }}

{{/* Resolve an exact database URL, falling back to the shared base URL */}}
{{- define "service.icc.databaseUrl" -}}
{{- $root := index . 0 -}}
{{- $database := index . 1 -}}
{{- $urls := $root.Values.services.icc.database_urls | default (dict) -}}
{{- $url := get $urls $database -}}
{{- if and (not $url) (eq $database "traffic_inspector") -}}
{{- $url = get $urls "trafficante" -}}
{{- end -}}
{{- if $url -}}
{{- $url -}}
{{- else -}}
{{- $message := printf "services.icc.database_urls.%s or services.icc.database_url is required" $database -}}
{{- $base := required $message $root.Values.services.icc.database_url -}}
{{- $name := include "service.icc.databaseName" (list $database) -}}
{{- printf "%s/%s" $base $name -}}
{{- end -}}
{{- end }}
11 changes: 0 additions & 11 deletions chart/templates/deployment/_icc.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -265,17 +265,6 @@ spec:
name: icc-valkey
key: apps

- name: PLT_COLD_STORAGE_DATABASE_URL
valueFrom:
secretKeyRef:
name: icc-databases
key: "risk_cold_storage"
- name: PLT_TRAFFIC_INSPECTOR_DATABASE_URL
valueFrom:
secretKeyRef:
name: icc-databases
key: trafficante

{{- range (include "service.icc.databases" . | trim | split " ") }}
- name: {{ printf "PLT_%s_DATABASE_URL" (upper .) }}
valueFrom:
Expand Down
8 changes: 7 additions & 1 deletion chart/templates/secrets.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,13 @@ metadata:
{{- include "application.labels" $ | nindent 4 }}
data:
{{- range (include "service.icc.databases" . | trim | split " ") }}
"{{ . }}": {{ printf "%s/%s" (required "services.icc.database_url is required" $.Values.services.icc.database_url) . | b64enc }}
"{{ . }}": {{ include "service.icc.databaseUrl" (list $ .) | b64enc }}
{{- end }}
# Compatibility alias used by chart 4.1 deployments.
"risk_cold_storage": {{ include "service.icc.databaseUrl" (list $ "cold_storage") | b64enc }}
{{- $databaseUrls := .Values.services.icc.database_urls | default (dict) }}
{{- if or (and .Values.services.workflow .Values.services.workflow.deploy) .Values.services.icc.database_url (get $databaseUrls "workflow") }}
"workflow": {{ include "service.icc.databaseUrl" (list $ "workflow") | b64enc }}
{{- end }}

{{/* Setup valkey */}}
Expand Down
22 changes: 19 additions & 3 deletions chart/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -137,11 +137,27 @@ services:
# https://example.com/icc
#public_url: ""

# The URL to access the ICC database
# Makes sure to include any required credentials and/or port number
# Required: must be set at install time
# Base URL used to derive all ICC database URLs. Do not include a database
# name or trailing slash. Required unless all required exact URLs are set.
database_url: ""

# Exact URLs for installations with separate database credentials or names.
# An exact URL takes precedence over database_url. traffic_inspector falls
# back to the trafficante exact URL when it is not set.
#database_urls:
# activities: ""
# cluster_manager: ""
# cold_storage: ""
# compliance: ""
# control_plane: ""
# cron: ""
# scaler: ""
# trafficante: ""
# traffic_inspector: ""
# user_manager: ""
# workflow: "" # Required only when services.workflow.deploy is true
database_urls: {}

# URLs to valkey for ICC caching systems
# Required: both must be set at install time
valkey:
Expand Down
Loading
Loading