From 1beb8d34c2217e6fe2f1538f4ad25f063f63151c Mon Sep 17 00:00:00 2001 From: Jarvis Date: Tue, 29 Sep 2026 07:19:25 +0000 Subject: [PATCH 1/5] feat(aisix): render the gateway's startup config from an explicit config block Every gateway setting the chart deploys is now declared in values.yaml and reaches the gateway as its config file through a ConfigMap, in both modes. `config:` mirrors the gateway's startup file key for key at the gateway's own defaults; the chart fills the keys it owns (listen addresses, listeners, rate-limit backend, the control-plane connection, the standalone resources file, admin) and rejects them under config:. Credentials never enter the ConfigMap: the control-plane mTLS bundle is mounted as files (managed.cp_*_file), the rate-limit Redis URL stays a secretKeyRef env var, and the new configSecrets block wires the other credential-bearing keys from Secrets. extraEnvVars is documented as system-level only; AISIX_* variables there still override the file. The pod template always carries checksum/config and checksum/secret, so a config change or a chart-managed Secret change rolls the pods in both modes. CI checks config: against api7/aisix config.reference.json at the chart's appVersion and boots the appVersion image on the rendered file in both modes. --- .github/scripts/aisix-config-boot.sh | 97 ++++++++++ .github/scripts/check-aisix-config-drift.py | 99 +++++++++++ .github/workflows/ci.yaml | 8 + AGENTS.md | 12 ++ charts/aisix/README.md | 116 ++++++++++-- charts/aisix/README.md.gotmpl | 63 +++++-- charts/aisix/ci/config-values.yaml | 34 ++++ charts/aisix/config-policy.yaml | 41 +++++ charts/aisix/templates/_helpers.tpl | 140 +++++++++++++-- charts/aisix/templates/configmap.yaml | 17 +- charts/aisix/templates/deployment.yaml | 102 ++++------- charts/aisix/templates/secret.yaml | 2 +- charts/aisix/values.yaml | 188 +++++++++++++++++++- 13 files changed, 805 insertions(+), 114 deletions(-) create mode 100755 .github/scripts/aisix-config-boot.sh create mode 100644 .github/scripts/check-aisix-config-drift.py create mode 100644 charts/aisix/ci/config-values.yaml create mode 100644 charts/aisix/config-policy.yaml diff --git a/.github/scripts/aisix-config-boot.sh b/.github/scripts/aisix-config-boot.sh new file mode 100755 index 0000000..32c5008 --- /dev/null +++ b/.github/scripts/aisix-config-boot.sh @@ -0,0 +1,97 @@ +#!/usr/bin/env bash +# Boot the gateway image the chart deploys (its appVersion) on the config file +# the chart renders, in both modes, with charts/aisix/ci/config-values.yaml +# setting list-typed keys through `config`. +# +# Standalone must come up and answer /livez. Control-plane mode has no control +# plane to reach here, so it must get past loading the config file and fail +# only once it acts on the connection. Override the image with AISIX_IMAGE. +set -euo pipefail + +chart=charts/aisix +app=$(awk '/^appVersion:/ {gsub(/"/, "", $2); print $2}' "$chart/Chart.yaml") +image=${AISIX_IMAGE:-docker.io/api7/aisix:$app} +work=$(mktemp -d) +chmod 755 "$work" +run_id=$$ +trap 'docker rm -f "aisix-cfgboot-standalone-$run_id" "aisix-cfgboot-managed-$run_id" >/dev/null 2>&1 || true; rm -rf "$work"' EXIT + +# extract