From 2a43013d88ce430e3ae7cda4dc7b97fc85b02e4b Mon Sep 17 00:00:00 2001 From: Don Kendall Date: Sat, 21 Mar 2026 23:32:49 -0400 Subject: [PATCH] fix(helm): pass GitHub App env vars to front for OAuth and installation flows (#286) The front service needs two additional env vars when GitHub integration is enabled: - GITHUB_CLIENTID: used to build the OAuth authorize URL. Without it, the redirect has client_id= (empty) and GitHub returns 404. - GITHUB_APP: the app slug, used to build the installation URL. Without it, the URL becomes /apps//installations/new which returns 404. Also adds githubIntegration.appSlug to values.yaml for the app slug. Signed-off-by: Don Kendall Co-authored-by: Claude Opus 4.6 (1M context) --- helm/huly/templates/front/deployment.yaml | 3 +++ helm/huly/values.yaml | 2 ++ 2 files changed, 5 insertions(+) diff --git a/helm/huly/templates/front/deployment.yaml b/helm/huly/templates/front/deployment.yaml index bb8c4b0..371f129 100644 --- a/helm/huly/templates/front/deployment.yaml +++ b/helm/huly/templates/front/deployment.yaml @@ -47,6 +47,9 @@ spec: {{- include "huly.envConfig" (dict "name" "LOVE_ENDPOINT" "key" "LOVE_ENDPOINT" "root" .) | nindent 12 }} {{- if .Values.githubIntegration.enabled }} {{- include "huly.envConfig" (dict "name" "GITHUB_URL" "key" "GITHUB_URL" "root" .) | nindent 12 }} + {{- include "huly.envSecret" (dict "name" "GITHUB_CLIENTID" "key" "GITHUB_APP_CLIENT_ID" "root" .) | nindent 12 }} + - name: GITHUB_APP + value: {{ .Values.githubIntegration.appSlug | quote }} {{- end }} {{- if .Values.aibot.enabled }} {{- include "huly.envConfig" (dict "name" "AI_URL" "key" "AI_URL" "root" .) | nindent 12 }} diff --git a/helm/huly/values.yaml b/helm/huly/values.yaml index 9e770f1..6ab7185 100644 --- a/helm/huly/values.yaml +++ b/helm/huly/values.yaml @@ -236,6 +236,8 @@ githubIntegration: replicas: 1 # Bot name shown on GitHub (must match the GitHub App's slug + [bot]) botName: "" + # GitHub App slug (from the app URL: github.com/apps/) + appSlug: "" # GitHub App credentials (stored in the shared secret) appId: "" clientId: ""