Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
6244f7e
feat(rhdh-upgrade-helper): add AI-assisted 1.x→2.x chart migration
rm3l Oct 8, 2026
2186ee1
docs(rhdh-upgrade-helper): clarify migration never modifies original …
rm3l Oct 8, 2026
7c11f05
feat(rhdh-upgrade-helper): support multiple input values files
rm3l Oct 8, 2026
ef6804a
feat(rhdh-upgrade-helper): add --to flag for versioned output filenames
rm3l Oct 8, 2026
7e28c01
fix: remove unused imports and sort import block
rm3l Oct 8, 2026
191f6a4
style: apply ruff format to migration script and judges
rm3l Oct 8, 2026
16c3618
chore(rhdh-upgrade-helper): remove provisional 2.1 release notes
rm3l Oct 8, 2026
cfbdee2
refactor(rhdh-upgrade-helper): rename 1.x/2.x to 1.y/2.y
rm3l Oct 8, 2026
e936881
style(rhdh-upgrade-helper): use sentence case for headings
rm3l Oct 8, 2026
60e257b
fix(rhdh-upgrade-helper): improve helm validation commands
rm3l Oct 8, 2026
fd1cb73
fix(rhdh-upgrade-helper): proactively clear image digest for non-defa…
rm3l Oct 8, 2026
90db0cb
feat(rhdh-upgrade-helper): flag janus-idp template refs and simplify …
rm3l Oct 8, 2026
232603d
fix(rhdh-upgrade-helper): skip RHDH Local recommendation for chart mi…
rm3l Oct 8, 2026
77a902c
fix(rhdh-upgrade-helper): place review comments inline next to corres…
rm3l Oct 8, 2026
c166128
fix(rhdh-upgrade-helper): improve janus-idp template review comment
rm3l Oct 8, 2026
04a22df
docs(rhdh-upgrade-helper): centralize chart version resolution in wor…
rm3l Oct 8, 2026
4472bb7
refactor(rhdh-upgrade-helper): write output next to original and drop…
rm3l Oct 8, 2026
1ccda6c
feat(rhdh-upgrade-helper): rewrite .Values refs, strip chart defaults…
rm3l Oct 9, 2026
cf0caf5
refactor(rhdh-upgrade-helper): comment out chart defaults instead of …
rm3l Oct 9, 2026
53421f5
feat(rhdh-upgrade-helper): gate chart migration on supported versions
rm3l Oct 9, 2026
3dec2a2
refactor(rhdh-upgrade-helper): deduplicate skill reference against up…
rm3l Oct 9, 2026
596a0d3
fix(rhdh-upgrade-helper): address PR review feedback
rm3l Oct 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
category: deterministic
rationale: Simple 1.y values with only deterministic mappings. All keys should migrate cleanly.
Comment thread
rm3l marked this conversation as resolved.
expected_mappings:
image.registry: registry.redhat.io
image.repository: rhdh/rhdh-hub-rhel9
image.tag: "1.10"
replicaCount: 2
nodeSelector:
node-role.kubernetes.io/worker: ""
resources.limits.memory: 4Gi
serviceAccount.create: true
serviceAccount.name: rhdh-sa
service.type: ClusterIP
service.port: 7007
postgresql.enabled: true
openshift.clusterRouterBase: apps.ocp.example.com
host: rhdh.apps.ocp.example.com
dynamicPlugins.includes: null
auth.backend.enabled: true
openshift.route.enabled: true
openshift.route.tls.termination: edge
expected_ambiguous_areas: []
expected_removed: []
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
fixture: simple-1y-values.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
category: ambiguous
rationale: >
Complex 1.y values with ingress, args, extraEnvFrom, auth secret, init containers,
networkPolicy, Lightspeed/IA, and Orchestrator. All ambiguous areas should be
flagged with MIGRATION-REVIEW markers.
expected_ambiguous_areas:
- ingress
- args
- extraEnvFrom
- authSecret
- initContainers
- networkPolicy
- intelligentAssistant
- orchestrator
expected_mappings:
image.registry: registry.redhat.io
replicaCount: 3
deploymentAnnotations:
deployment.kubernetes.io/revision: "1"
commandOverride: null
extraEnv: null
autoscaling.enabled: true
autoscaling.maxReplicas: 10
podDisruptionBudget.create: true
metrics.serviceMonitor.enabled: true
catalogIndex.image.tag: "1.10"
expected_removed:
- upstream.backstage.containerPorts.backend
- upstream.backstage.installDir
- upstream.diagnosticMode
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
fixture: complex-1y-values.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
category: removed
rationale: >
Verify that values with no 2.y equivalent are removed from output and
reported in the migration report.
expected_removed:
- upstream.backstage.containerPorts.backend
- upstream.backstage.installDir
- upstream.diagnosticMode
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
fixture: complex-1y-values.yaml
35 changes: 35 additions & 0 deletions eval/rhdh-upgrade-helper/chart-migration/eval.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: rhdh-upgrade-helper-chart-migration
description: Verify the chart values migration script correctly transforms 1.y values to 2.y structure.

execution:
mode: case
timeout: 120
parallelism: 2

dataset:
path: cases
schema: |
Each case contains input.yaml with fixture_path and expected outcomes,
and annotations.yaml with the expected results.

judges:
- name: deterministic_accuracy
description: All deterministic key mappings are applied correctly.
module: eval.rhdh-upgrade-helper.chart-migration.judges
function: check_deterministic_mappings
- name: ambiguous_detection
description: Ambiguous areas are flagged with MIGRATION-REVIEW markers, not silently transformed.
module: eval.rhdh-upgrade-helper.chart-migration.judges
function: check_ambiguous_detection
- name: removed_values
description: Removed values are excluded from output and reported.
module: eval.rhdh-upgrade-helper.chart-migration.judges
function: check_removed_values
- name: no_data_loss
description: No customer values are silently dropped during migration.
module: eval.rhdh-upgrade-helper.chart-migration.judges
function: check_no_data_loss
- name: valid_yaml
description: Output is valid YAML that can be parsed without errors.
module: eval.rhdh-upgrade-helper.chart-migration.judges
function: check_valid_yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,175 @@
# Complex 1.y values file with ambiguous areas
upstream:
backstage:
image:
registry: registry.redhat.io
repository: rhdh/rhdh-hub-rhel9
tag: "1.10"
replicas: 3
annotations:
deployment.kubernetes.io/revision: "1"
command:
- node
args:
- "--max-old-space-size=8192"
extraEnvVars:
- name: LOG_LEVEL
value: debug
- name: NODE_OPTIONS
value: "--max-http-header-size=32768"
extraEnvVarsSecrets:
- rhdh-github-token
- rhdh-gitlab-token
extraEnvVarsCM:
- rhdh-feature-flags
extraVolumes:
- name: custom-certs
secret:
secretName: custom-ca-bundle
extraVolumeMounts:
- name: custom-certs
mountPath: /etc/pki/tls/certs/custom
initContainers:
- name: install-dynamic-plugins
resources:
limits:
memory: 2Gi
securityContext:
runAsNonRoot: true
env:
- name: NPM_CONFIG_REGISTRY
value: https://npm.internal.example.com
- name: custom-init
image: busybox:1.36
command: ["sh", "-c", "echo hello"]
resources:
limits:
memory: 8Gi
cpu: "4"
autoscaling:
enabled: true
minReplicas: 2
maxReplicas: 10
pdb:
create: true
minAvailable: 1
containerPorts:
backend: 7007
installDir: /opt/app-root/src
serviceAccount:
create: true
name: rhdh-sa
automountServiceAccountToken: true
service:
type: ClusterIP
ports:
backend: 7007
annotations:
service.beta.kubernetes.io/aws-load-balancer-internal: "true"
ingress:
enabled: true
className: nginx
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
host: rhdh.example.com
path: /
extraHosts:
- name: rhdh-alt.example.com
path: /
tls:
enabled: true
secretName: rhdh-tls
extraTls:
- hosts:
- rhdh-alt.example.com
secretName: rhdh-alt-tls
networkPolicy:
enabled: true
ingressRules:
customRules:
- from:
- namespaceSelector:
matchLabels:
team: platform
egressRules:
denyConnectionsToExternal: false
postgresql:
enabled: true
image:
tag: "15.8"
auth:
existingSecret: rhdh-db-secret
metrics:
serviceMonitor:
enabled: true
interval: 30s
labels:
release: prometheus
diagnosticMode:
enabled: false
httpRoute:
enabled: false

global:
clusterRouterBase: apps.ocp.example.com
host: rhdh.example.com
dynamic:
includes:
- dynamic-plugins.default.yaml
plugins:
- package: ./dynamic-plugins/dist/backstage-plugin-catalog-backend-module-gitlab-dynamic
disabled: false
- package: oci://registry.access.redhat.com/rhdh/backstage-community-plugin-argocd@sha256:abc123
disabled: false
auth:
backend:
enabled: true
existingSecret: rhdh-auth-secret
lightspeed:
enabled: true
sidecar:
image: "quay.io/ai/lightspeed-service:1.5.0"
resources:
limits:
memory: 2Gi
imagePullPolicy: Always
configMaps:
- name: lightspeed-config
- name: lightspeed-stack
- name: lightspeed-profile
secret:
create: true
name: lightspeed-api-key
plugins:
- package: oci://registry.access.redhat.com/rhdh/lightspeed-plugin:1.0
disabled: false
catalogIndex:
image:
registry: registry.redhat.io
repository: rhdh/rhdh-catalog-index
tag: "1.10"

route:
enabled: true
host: rhdh.apps.ocp.example.com
tls:
enabled: true
termination: edge
certificate: |
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----

orchestrator:
sonataflowPlatform:
externalDBsecretRef: orch-db-secret
externalDBName: sonataflow
externalDBHost: postgres.internal.example.com
externalDBPort: "5432"
initContainerImage: "registry.redhat.io/rhdh/sonataflow-init:1.0"
createDBJobImage: "registry.redhat.io/rhdh/sonataflow-init:1.0"
dataIndexImage: "registry.redhat.io/rhdh/data-index:1.0"
jobServiceImage: "registry.redhat.io/rhdh/job-service:1.0"
dbCreationJobBackoffLimit: 6
dbCreationJobTTLSecondsAfterFinished: 600
dbCreationJobActiveDeadlineSeconds: 300
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
# Simple 1.y values file with deterministic mappings only
upstream:
backstage:
image:
registry: registry.redhat.io
repository: rhdh/rhdh-hub-rhel9
tag: "1.10"
replicas: 2
podAnnotations:
sidecar.istio.io/inject: "true"
nodeSelector:
node-role.kubernetes.io/worker: ""
resources:
limits:
memory: 4Gi
cpu: "2"
requests:
memory: 2Gi
cpu: "1"
serviceAccount:
create: true
name: rhdh-sa
service:
type: ClusterIP
ports:
backend: 7007
postgresql:
enabled: true
image:
tag: "15.8"
auth:
existingSecret: rhdh-db-secret

global:
clusterRouterBase: apps.ocp.example.com
host: rhdh.apps.ocp.example.com
dynamic:
includes:
- dynamic-plugins.default.yaml
plugins:
- package: ./dynamic-plugins/dist/backstage-plugin-catalog-backend-module-gitlab-dynamic
disabled: false
auth:
backend:
enabled: true
value: supersecret123

route:
enabled: true
host: rhdh.apps.ocp.example.com
tls:
enabled: true
termination: edge
Loading
Loading