Repository navigation
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
enyst
left a comment
There was a problem hiding this comment.
I'm an AI agent based on Opus 5.5, helping Engel Nyst (@enyst) with project work.
I checked every added setting against replicated/config.yaml at openhands/0.70.0 in OpenHands-Cloud, where the chart and the Replicated config are versioned together. All titles and behaviors match: Keycloak admin UI password, duplicate-email check, Jira Cloud, SAML, SMTP Keycloak emails, Runtime API admin password, upgrade budget gates, ClickHouse retention, archive delay, and Agent Canvas. They're all still present in 0.74.0.
- Needs a rebase: #815 deleted
llms-full.txton main, so drop that half of the diff. - Two defaults are worth stating (see inline comments).
Prevent Duplicate Base Emailsis on by default, and the post-upgrade gate defaults toStrict, which can fail an upgrade (L757-L761, L1457-L1476).
|
|
||
| ## Authentication Security | ||
|
|
||
| Enable `Prevent Duplicate Base Emails` to reject sign-ins when another user has the same email after removing a plus-address suffix. For example, `name+test@example.com` matches `name@example.com`. Check for an existing account when investigating a rejected sign-in involving an email alias. |
There was a problem hiding this comment.
This setting defaults to on, so "Enable … to reject" reads as if it were opt-in.
| Enable `Prevent Duplicate Base Emails` to reject sign-ins when another user has the same email after removing a plus-address suffix. For example, `name+test@example.com` matches `name@example.com`. Check for an existing account when investigating a rejected sign-in involving an email alias. | |
| `Prevent Duplicate Base Emails` (on by default) rejects sign-ins when another user has the same email after removing a plus-address suffix. For example, `name+test@example.com` matches `name@example.com`. Check for an existing account when investigating a rejected sign-in involving an email alias. |
|
|
||
| | Field | Description | | ||
| |---|---| | ||
| | `Pre-upgrade Budget Preflight` | Read-only check for missing budget baselines, missing gateway members, cap drift, or a failed last sync. `Strict` blocks the upgrade when problems are found. | |
There was a problem hiding this comment.
| | `Pre-upgrade Budget Preflight` | Read-only check for missing budget baselines, missing gateway members, cap drift, or a failed last sync. `Strict` blocks the upgrade when problems are found. | | |
| | `Pre-upgrade Budget Preflight` | Read-only check for missing budget baselines, missing gateway members, cap drift, or a failed last sync. The default, `Acknowledge`, records findings; `Strict` blocks the upgrade when problems are found. | |
| | Field | Description | | ||
| |---|---| | ||
| | `Pre-upgrade Budget Preflight` | Read-only check for missing budget baselines, missing gateway members, cap drift, or a failed last sync. `Strict` blocks the upgrade when problems are found. | | ||
| | `Post-upgrade Budget Reconciliation Gate` | Reconciles organization budget policies and verifies them by readback. `Strict` marks the upgrade failed until reconciliation succeeds. `Acknowledge` records findings and lets the release proceed. | |
There was a problem hiding this comment.
| | `Post-upgrade Budget Reconciliation Gate` | Reconciles organization budget policies and verifies them by readback. `Strict` marks the upgrade failed until reconciliation succeeds. `Acknowledge` records findings and lets the release proceed. | | |
| | `Post-upgrade Budget Reconciliation Gate` | Reconciles organization budget policies and verifies them by readback. The default, `Strict`, marks the upgrade failed until reconciliation succeeds. `Acknowledge` records findings and lets the release proceed. | |
|
Agreed. Updated all three defaults: duplicate-email prevention is on, pre-upgrade checks default to Acknowledge, and post-upgrade checks default to Strict. Verified against the release configuration; upgrade behavior wasn’t live-tested. |
Document missing Admin Console settings confirmed in the Replicated 0.70 configuration: Keycloak administration, duplicate-email protection, Jira Cloud and SAML setup links, SMTP account emails, Runtime API administration, upgrade budget checks, ClickHouse diagnostic log retention, automation archive delay, and Agent Canvas.
Use 0.70 as the reference baseline and synchronize the corresponding llms-full.txt section. Defer newer controls and the sandbox-cap description pending version-specific verification.
Validation: MDX compilation, internal-link checks, generated-section synchronization, and git diff --check passed. Mintlify's full broken-link checker could not run with the installed Node 25 runtime.