Skip to content

fix(opencode): use resource-scoped server-side apply for large config - #126

Merged
xnoto merged 2 commits into
mainfrom
fix/opencode-config-server-side-apply
Oct 5, 2026
Merged

xnoto merged 2 commits into
mainfrom
fix/opencode-config-server-side-apply

Conversation

@xnoto

@xnoto xnoto commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Corrective opencode-server 0.5.2 release after #125: the expanded ConfigMap exceeds the Kubernetes client-side last-applied annotation limit and blocks Argo reconciliation. Add ServerSideApply=true only to the production ConfigMap; retain every primary protocol byte.

Type of change

  • Bug fix
  • GitOps desired state (chart)
  • Documentation
  • CI / reusable workflow (existing rendering assertions only)

Validation

  • Required pull-request checks pass
  • Generated/packaged files retain their canonical ownership

Adversarial/security/DevOps reviews ADVANCE; QA COVERED; release READY. Deployed Argo controller digest maps to Quay v2.14.15, whose versioned upstream documentation supports this resource-level option for large resources. No migration-disable, Replace, Force, or application-wide SSA option is added.

CI is authoritative; no local validation ran. Existing hygiene, Helm, static policy, source/archive and Python rendering checks must pass. Historical fixture applies exactly the annotation addition, preserving full rendered-resource equality including the derived Deployment checksum; nothing is ignored.

Impact and rollout

Owner approved implement, merge when ready, and rollout. Five files change: production ConfigMap metadata, Chart.yaml, Makefile version/archive assertions, README, existing Python rendering test. Image/appVersion 2.0.22, prompts, ConfigMap data, pilot configuration, models, workflows, PVCs, Secrets, permissions and networking remain unchanged.

Merge triggers main validation and immutable GHCR 0.5.2 publication, then the generated cluster version-pin PR. The parent must update that PR’s existing exact chart/protocol assertion to (0.5.2, 2) before required checks can pass. Verify artifact publication before consuming merge, then root/child reconciliation and new pod/config delivery separately. Existing Recreate strategy entails brief downtime. No manual live patches or sync actions are needed or authorized here.

Rollback selects a prior published chart and matching assertion through reviewed GitOps. 0.5.1 cannot be overwritten and remains known to hit the annotation limit; 0.5.0 is the previous working configuration. Runtime knowledge adherence remains unverified; waived synthetic diagnostic stays stopped.

Safety and secrets

  • No plaintext secrets, state, credentials, private records, kubeconfigs or sensitive logs
  • No local OpenTofu operations
  • Effects and rollback described above

Materially AI-authored. All Critical/High review findings are resolved.

PR CI 37284150966 passed test, detect and package at b63f8e3f.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Chart CI passed

Repository hygiene and Helm validation passed. View the workflow run.

@xnoto
xnoto merged commit 16bf435 into main Oct 5, 2026
4 checks passed
@xnoto
xnoto deleted the fix/opencode-config-server-side-apply branch October 5, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant