access-engine/charts/flex-auth/templates/_helpers.tpl
tegwick fa278674c1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Pin caller-auth digest in warn on independently rollable overlay pins
The sanctioned Helm chart could not promote ADR 0004 at all, and the
emergency manifests selected enforce. That made a FLEX-WP-0011 apply
either a no-op or a global 401. First production pin is now warn, per
consumer, on CI digest sha256:138aa347… . Enforce stays a later
per-consumer flip so USER-WP-0023-T03 can close without waiting on
tenant-engine.
2026-08-19 12:31:08 +02:00

35 lines
1.2 KiB
Smarty

{{- define "flex-auth.image" -}}
{{- if not .Values.image.digest }}
{{- fail "image.digest is required (digest_policy=required); do not deploy by tag" }}
{{- end }}
{{- printf "%s@%s" .Values.image.repository .Values.image.digest -}}
{{- end -}}
{{- define "flex-auth.name" -}}
{{- required "name is required" .Values.name -}}
{{- end -}}
{{- define "flex-auth.selectorLabels" -}}
app.kubernetes.io/name: {{ include "flex-auth.name" . }}
{{- end -}}
{{- define "flex-auth.labels" -}}
{{ include "flex-auth.selectorLabels" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/part-of: flex-auth
{{- end -}}
{{- define "flex-auth.callerAuth.mode" -}}
{{- $mode := "disabled" -}}
{{- if and (hasKey .Values "callerAuth") .Values.callerAuth (hasKey .Values.callerAuth "mode") .Values.callerAuth.mode -}}
{{- $mode = .Values.callerAuth.mode -}}
{{- end -}}
{{- if not (has $mode (list "disabled" "warn" "enforce")) -}}
{{- fail (printf "callerAuth.mode must be disabled, warn, or enforce; got %q" $mode) -}}
{{- end -}}
{{- $mode -}}
{{- end -}}
{{- define "flex-auth.callerAuth.enabled" -}}
{{- if has (include "flex-auth.callerAuth.mode" .) (list "warn" "enforce") -}}true{{- else -}}false{{- end -}}
{{- end -}}