docs: what the chart bump does to our forks, rendered rather than assumed

sorb asked the question the plan had skipped: we fork and adapt components, so
what happens to that on a chart jump. Both versions were rendered offline with
our actual values — the live HelmRelease plus the two custom ConfigMaps — and
compared side by side.

Everything survives. The fork is an ordinary value override rather than a patch
layer, and 26.8.0 knows the same keys. Our Element build is newer than the one
the chart pins anyway. The federation closure lands in the same two secrets in
both, and the preview blacklist lands in one more place in the new chart, which
is more coverage rather than a different rule.

One thing turned up on the way: custom-configs holds an 'element-values copy.yaml'
defining the same ConfigMap with different, much smaller content. It is not in
the kustomization, so it does nothing today — but adding or renaming it would
silently replace the Element configuration with an older state.
This commit is contained in:
Thore Cimbal
2026-08-21 12:00:00 +00:00
parent 974ad57528
commit 71e78fc653
+33
View File
@@ -631,3 +631,36 @@ your homeserver participates in open federation"*; unsere Föderation ist seit
⚠️ **Größte Sprengweite des Tages.** Synapse und MAS sind Nachrichten- **und**
Anmeldeweg aller Nutzer. Anders als bei Authentik gibt es hier keinen zweiten
Weg: Fällt Synapse, ist die Plattform weg.
#### Was der Chart-Sprung mit unseren Anpassungen macht — gerendert, nicht vermutet
sorbs Einwand: *„wir haben doch diverse Komponenten geforkt, angepasst und
geupdatet."* Berechtigt, und offline beweisbar. Beide Chart-Fassungen wurden mit
**unseren echten Werten** gerendert (`helm template` gegen 26.4.0 und 26.8.0,
gespeist aus dem laufenden HelmRelease plus den ConfigMaps
`ess-synapse-custom` und `ess-element-custom`) und gegenübergestellt:
| Anpassung | 26.4.0 | 26.8.0 |
|---|---|---|
| `elementWeb.image` → `rohana…/sorb/threadnet-web:v0.6.0` | ✓ | ✓ |
| `disable_custom_urls` (Oberflächen-Sperre, #0099) | ✓ | ✓ |
| `url_preview_ip_range_blacklist` inkl. `100.64.0.0/10` | 2 Stellen | **4 Stellen** |
| `federation_domain_whitelist: []` (#0060) | `Secret/matrix-stack-synapse` + `-hook`, Schlüssel `user-federation` | **dieselben beiden** |
| stabile `matrix_authentication_service`-Integration | ✓ | ✓ |
**Der Fork ist eine gewöhnliche Werte-Überschreibung**, keine Patch-Ebene — das
Chart kennt `elementWeb.image.{registry,repository,tag}` unverändert. Unsere
Element-Fassung ist mit **v0.6.0** (Upstream v1.12.26) ohnehin **neuer** als die,
die 26.8.0 vorgibt (v1.12.25); die Vorgabe wird also nicht vermisst, sondern
überschrieben.
Der Unterschied bei `100.64.0.0/10` ist kein Bedeutungswechsel: 26.8.0 schreibt
unsere Sperrliste zusätzlich ins Hook-Secret. Mehr Abdeckung, gleiche Regel.
⚠️ **Nebenfund im selben Zug:** In `apps/production/custom-configs/` liegt eine
Datei **`element-values copy.yaml`** (mit Leerzeichen im Namen, Commit
`dc17158 "fix themes"`). Sie definiert **dieselbe ConfigMap** `ess-element-custom`
wie die echte Datei, mit **anderem** Inhalt und nur 8,8 KB statt 30,7 KB. Sie
steht **nicht** im Kustomize-Bauplan und ist damit heute wirkungslos — aber wer
sie je aufnimmt oder umbenennt, ersetzt die Element-Konfiguration stillschweigend
durch einen älteren, kleineren Stand. Nicht angefasst; gehört sorb.