Skip to main content

AEROSIM-TS-48

Project task

Package Nebula and Singularity Helm charts

Lintable Helm charts render Web and API workloads with explicit immutable image selection, probes, ingress paths, configuration, and secret references.

AEROSIM-TS-48Canonical ID TASK-0048
Verified flow state
Done
Owner
AeroSim Architecture and Delivery
Component
Delivery packaging — Helm charts
Repository
corp-v1-aerosim/corp-v1-aerosim

Delivery scope

Package one AeroSim chart with Nebula and Singularity Deployments/Services, immutable image repository and digest values, Web and API probes, root,/api,/socket.io ingress routing, non-secret ConfigMap values, and existing Secret references validated by values.schema.json. Primary files: charts/aerosim/Chart.yaml, charts/aerosim/values.yaml, charts/aerosim/values.schema.json, charts/aerosim/templates/web-deployment.yaml, charts/aerosim/templates/api-deployment.yaml, charts/aerosim/templates/services.yaml, charts/aerosim/templates/ingress.yaml, charts/aerosim/templates/secret-references.yaml, tests/helm/aerosim-chart.test.mjs.

Implementation contract

Implementation artifacts

  • charts/aerosim/Chart.yaml
  • charts/aerosim/values.yaml
  • charts/aerosim/values.schema.json
  • charts/aerosim/templates/web-deployment.yaml
  • charts/aerosim/templates/api-deployment.yaml
  • charts/aerosim/templates/services.yaml
  • charts/aerosim/templates/ingress.yaml
  • charts/aerosim/templates/secret-references.yaml
  • tests/helm/aerosim-chart.test.mjs

Inputs

  • Helm values containing web.image.digest and api.image.digest as sha256 digests
  • Ingress host, Keycloak public settings, API URLs, and names of pre-existing Kubernetes Secrets

Outputs

  • Rendered Kubernetes manifests for Web/API Deployments, Services, Ingress, ConfigMaps, and Secret references
  • Linted chart archive whose workloads select images by digest

Failure boundaries

  • helm lint/template fails for mutable tags, absent digest, plaintext credential values, missing secret names, or invalid probe paths/ports.
  • Rendered manifests fail policy tests if containers run privileged/root or omit required resource requests and limits.

Excluded scope

  • Secret creation, cluster issuer installation, database provisioning, autoscaling, and service-mesh policy are not included in this chart.

Verification steps

  • helm lint charts/aerosim && helm template aerosim charts/aerosim --values tests/helm/values.valid.yaml > /tmp/aerosim-rendered.yaml
  • node --test tests/helm/aerosim-chart.test.mjs; run mutable-tag, plaintext-secret, and missing-digest fixtures.

Traceability

Requirements

Dependencies

UI/UX applicability

non_visual

This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.

Acceptance evidence

Verified delivery: application PR #90 reviewed head 5c19b9a849f74cef0e14ca72d16b89cee1d3b4e4 passed exact-head application validation run 3936, merged as 2aa78654d59b116ed240edec1337c1247597f210, and integration runs 3940, 3941, 3942, and 3943 succeeded. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.

Current evidence boundary

No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.