Conversation
ADR 0015 said the Helm chart does not gain the use-time re-read because it passes every credential as a variable. Since 2026-09-25 the chart mounts the three M-Pesa credentials as files by default, so that sentence is no longer accurate. It is amended the way this repository amends a published statement: the original sentence stays, marked inline, and a dated section at the foot says what changed and points to the chart README rather than restating how the chart does it. The assumption beneath it is kept exactly as written: whether a cluster's Secret update reaches the pod is still not measured, so the amendment does not say a chart deployment gains rotation without a restart. Signed-off-by: Devalère <28451130+Deval123@users.noreply.github.com>
Owner
Author
|
Superseded by #245, which amends ADR 0015 once, covering both the chart and the gate. This one says the credentials reach the gateway in the form it re-reads: true of the form, and false of the effect until #245 -- the gate compared a modification time a Kubernetes Secret update was measured to leave unchanged (#244). Two dated amendments, one of them misleading, is worse than one. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
This amends one statement in
docs/adr/0015-credentials-read-at-use.mdthat is no longer accurate. It is documentation only, and the decision it records is unchanged.The ADR said: "The Helm chart does not gain this yet. It passes every credential as a variable from a Secret reference." Since 2026-09-25 the chart mounts the passkey, Consumer Key and Consumer Secret as files by default, so the credentials reach the gateway in the form it re-reads.
The amendment follows
CONTRIBUTING.md's Amending an ADR:## Amendment, 2026-09-25section says what is no longer accurate and what still stands. It points tocharts/nkap/README.md, M-Pesa, instead of restating how the chart does it.— <issue>, but no issue was closed by this change.What it deliberately does not say
It does not say that a chart deployment now gains rotation without a restart. Whether a cluster's own Secret update reaches the running pod, and how quickly, is still not measured. The amendment says so, and says the chart only no longer stands in the way.
The Assumed, not measured here line is left exactly as written. It is still accurate, and the amendment names it rather than marking it. A marker there would flag a sentence that isn't wrong.
Nothing else in the ADR changed. This closes no issue.