Skip to content

fix(platform): render a lab-registry component chart through its host port - #511

Merged
teemow merged 1 commit into
mainfrom
fix/component-chart-lab-registry
Oct 10, 2026
Merged

teemow merged 1 commit into
mainfrom
fix/component-chart-lab-registry

Conversation

@teemow

@teemow teemow commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Problem

agentlab platform could not install a component chart pushed into the lab registry. An overlay with components.<name>.repository: oci://<cluster>-registry:5000/charts and insecure: true stopped at "Side-loading the platform images". The host-side render of the component chart tried to resolve <cluster>-registry with the host's DNS, and only the kind network knows that name. No repository value worked for both the host render and Flux.

Proposed solution

  • The host-side render of a component release whose OCIRepository names the lab registry by its kind-network name goes through the registry's host-published port (localhost:<platform.devRegistryPort>) over plain HTTP. The connectivity chart of a chartPath lab is pushed through the same address. The HelmRelease keeps the kind-network URL, which source-controller can reach. The boot log names both addresses.
  • An OCIRepository's spec.insecure now reaches the host render as plain HTTP, for the tag listing and the chart pull alike.
  • When the registry does not answer on the host port, the boot stops before the install. The refusal names the registry container and the host address it tried, not the host's DNS.
  • docs/platform.md gains a section, "An unreleased component chart", with the push and the overlay.

Acceptance criteria

  • An overlay pointing components.kagent at oci://<cluster>-registry:5000/charts with insecure: true installs with agentlab platform, its HelmRelease Ready and platform-test green (lab proof below).
  • The docs name the path for an unreleased component chart.
  • Unit tests: the mapping, spec.insecure, the plain-HTTP render and tag list, and the refusal wording.

Proof (agentlab, this branch's binary)

  • The released kagent 1.7.0 chart, unchanged, pushed with helm push … oci://localhost:5001/charts --plain-http (digest sha256:aca6c5e4…). Overlay: components.kagent.repository: oci://agentlab-registry:5000/charts, insecure: true, versionRange: "1.7.0".
  • agentlab platform: exit 0, rendered 17 of 17 component charts.
  • OCIRepository kagent: oci://agentlab-registry:5000/charts/kagent, insecure=true, artifact 1.7.0@sha256:aca6c5e4…. HelmRelease kagent: Ready=True, history[0].ociDigest is the pushed digest.
  • agentlab platform-test: exit 0, all PASS.
  • Overlay removed and agentlab platform re-run: kagent back on the gsoci chart 1.7.0 (sha256:02f633a3…), Ready.

Closes #509

Written by an agent.

@teemow
teemow requested a review from a team as a code owner October 10, 2026 22:59
@teemow
teemow merged commit d7ef09e into main Oct 10, 2026
6 checks passed
@teemow
teemow deleted the fix/component-chart-lab-registry branch October 10, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

platform: a component chart from the lab registry fails the host-side render

1 participant