Skip to content

Amend ADR 0015: the chart now mounts M-Pesa credentials as files - #243

Closed
Deval123 wants to merge 1 commit into
mainfrom
docs/adr-0015-chart-amendment
Closed

Deval123 wants to merge 1 commit into
mainfrom
docs/adr-0015-chart-amendment

Conversation

@Deval123

Copy link
Copy Markdown
Owner

What changed

This amends one statement in docs/adr/0015-credentials-read-at-use.md that is no longer accurate. It is documentation only, and the decision it records is unchanged.

The ADR said: "The Helm chart does not gain this yet. It passes every credential as a variable from a Secret reference." Since 2026-09-25 the chart mounts the passkey, Consumer Key and Consumer Secret as files by default, so the credentials reach the gateway in the form it re-reads.

The amendment follows CONTRIBUTING.md's Amending an ADR:

  • The original sentence stays, with an inline marker (¹) beneath it pointing to the amendment, for a reader who never reaches the foot of the file.
  • A dated ## Amendment, 2026-09-25 section says what is no longer accurate and what still stands. It points to charts/nkap/README.md, M-Pesa, instead of restating how the chart does it.
  • The heading names no issue. The convention's form is — <issue>, but no issue was closed by this change.

What it deliberately does not say

It does not say that a chart deployment now gains rotation without a restart. Whether a cluster's own Secret update reaches the running pod, and how quickly, is still not measured. The amendment says so, and says the chart only no longer stands in the way.

The Assumed, not measured here line is left exactly as written. It is still accurate, and the amendment names it rather than marking it. A marker there would flag a sentence that isn't wrong.

Nothing else in the ADR changed. This closes no issue.

ADR 0015 said the Helm chart does not gain the use-time re-read
because it passes every credential as a variable. Since 2026-09-25
the chart mounts the three M-Pesa credentials as files by default, so
that sentence is no longer accurate.

It is amended the way this repository amends a published statement:
the original sentence stays, marked inline, and a dated section at
the foot says what changed and points to the chart README rather than
restating how the chart does it. The assumption beneath it is kept
exactly as written: whether a cluster's Secret update reaches the pod
is still not measured, so the amendment does not say a chart
deployment gains rotation without a restart.

Signed-off-by: Devalère <28451130+Deval123@users.noreply.github.com>
@Deval123

Copy link
Copy Markdown
Owner Author

Superseded by #245, which amends ADR 0015 once, covering both the chart and the gate. This one says the credentials reach the gateway in the form it re-reads: true of the form, and false of the effect until #245 -- the gate compared a modification time a Kubernetes Secret update was measured to leave unchanged (#244). Two dated amendments, one of them misleading, is worse than one.

@Deval123 Deval123 closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant