AEROSIM-TS-48
Package Nebula and Singularity Helm charts
Lintable Helm charts render Web and API workloads with explicit immutable image selection, probes, ingress paths, configuration, and secret references.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-52
- Component
- Delivery packaging — Helm charts
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Package one AeroSim chart with Nebula and Singularity Deployments/Services, immutable image repository and digest values, Web and API probes, root,/api,/socket.io ingress routing, non-secret ConfigMap values, and existing Secret references validated by values.schema.json. Primary files: charts/aerosim/Chart.yaml, charts/aerosim/values.yaml, charts/aerosim/values.schema.json, charts/aerosim/templates/web-deployment.yaml, charts/aerosim/templates/api-deployment.yaml, charts/aerosim/templates/services.yaml, charts/aerosim/templates/ingress.yaml, charts/aerosim/templates/secret-references.yaml, tests/helm/aerosim-chart.test.mjs.
Implementation contract
Implementation artifacts
- charts/aerosim/Chart.yaml
- charts/aerosim/values.yaml
- charts/aerosim/values.schema.json
- charts/aerosim/templates/web-deployment.yaml
- charts/aerosim/templates/api-deployment.yaml
- charts/aerosim/templates/services.yaml
- charts/aerosim/templates/ingress.yaml
- charts/aerosim/templates/secret-references.yaml
- tests/helm/aerosim-chart.test.mjs
Inputs
- Helm values containing web.image.digest and api.image.digest as sha256 digests
- Ingress host, Keycloak public settings, API URLs, and names of pre-existing Kubernetes Secrets
Outputs
- Rendered Kubernetes manifests for Web/API Deployments, Services, Ingress, ConfigMaps, and Secret references
- Linted chart archive whose workloads select images by digest
Failure boundaries
- helm lint/template fails for mutable tags, absent digest, plaintext credential values, missing secret names, or invalid probe paths/ports.
- Rendered manifests fail policy tests if containers run privileged/root or omit required resource requests and limits.
Excluded scope
- Secret creation, cluster issuer installation, database provisioning, autoscaling, and service-mesh policy are not included in this chart.
Verification steps
- helm lint charts/aerosim && helm template aerosim charts/aerosim --values tests/helm/values.valid.yaml > /tmp/aerosim-rendered.yaml
- node --test tests/helm/aerosim-chart.test.mjs; run mutable-tag, plaintext-secret, and missing-digest fixtures.
Traceability
Dependencies
- AEROSIM-TS-47Canonical ID: TASK-0047
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #90 reviewed head 5c19b9a849f74cef0e14ca72d16b89cee1d3b4e4 passed exact-head application validation run 3936, merged as 2aa78654d59b116ed240edec1337c1247597f210, and integration runs 3940, 3941, 3942, and 3943 succeeded. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.