Repository navigation
feat(automation): provision the KV store secret for Replicated installs - #1326
Conversation
The automation service only offers its key-value store when AUTOMATION_KV_SECRET is set, and nothing in the chart or the Replicated manifests set it. On a self-hosted install a run therefore gets no AUTOMATION_KV_TOKEN, so automations that keep state between runs - every run starts in a fresh sandbox there - either fail or repeat their work. Provision it the way the git sync secret is: a hidden, generated KOTS config item, passed to the openhands-secrets chart, rendered as the automation-kv-secret Secret, and referenced from the automation pods as an optional secretKeyRef so installs without the Secret keep starting with the store off. The item joins secretsChecksum. Refs OHE-3160
Merge order (OHE-3160)This PR is one of four that together bring the automation templates to OpenHands Cloud and Enterprise. Please merge them in this order:
Required
Recommended
After merging
|
The secrets chart renders the Secret only when automations are enabled, and the automation chart reads it through an optional reference so pods start before the secret exists.
jpshackelford
left a comment
There was a problem hiding this comment.
Thanks @hieptl — this matches what I was independently writing up in #1327 (now closed, ~8h apart). Core wiring looks right and the fleet-deploy evidence is more than I had. A few carryovers from #1327:
Requested changes
1. Bump chart versions. Subchart values changed; without the bump, Replicated release packaging, helm dep update, and consumers pinning by version won't register this as a new release. Neither Chart.yaml is in the diff, so leaving these here rather than inline:
charts/openhands-secrets/Chart.yaml:0.1.24→0.1.25charts/openhands/Chart.yaml:0.74.0→0.74.1
2. Add AUTOMATION_KV_SECRET to SECRET_PRESENCE in charts/openhands/templates/troubleshoot/support-bundle.yaml (also not in the diff, so dropping here):
- "AUTOMATION_WEBHOOK_SECRET", "AUTOMATIONS_SERVICE_KEY",
+ "AUTOMATION_WEBHOOK_SECRET", "AUTOMATION_KV_SECRET", "AUTOMATIONS_SERVICE_KEY",Supportability: a Replicated support bundle should answer "is KV configured on this install?" in one line. Without this, the exact bug this PR fixes (KV silently off because the secret was never wired) is invisible in any future bundle, and we'd be asking customers to re-run bundles after we notice KV endpoints 503ing. One-char diff; big diagnostic payoff.
Nit
One inline comment on replicated/config.yaml suggesting a rotation warning in the help text, modelled on litellm_salt_key's precedent.
Sidebar: pre-existing secretsChecksum arity bug
Unrelated to this PR but worth linking so it isn't lost: the printf format in replicated/openhands.yaml only has 45 %s placeholders, so inserting at position 32 shifts trailing args off the hash. Doesn't affect AUTOMATION_KV_SECRET itself (position 32 is inside the hashed range), but tracked in #1328 — either PR can land first.
This review was posted by an AI agent (OpenHands) on behalf of @jpshackelford.
Changing the key after install makes the state automations already keep in the KV store unreadable, the same failure mode the LiteLLM salt key help text already warns about.
A support bundle could not tell whether the KV store was configured on an install. The existing config snapshot runs in the openhands pod, which never receives AUTOMATION_KV_SECRET, so the presence check runs in the automation pod that actually reads it.
|
Thanks for the careful review @jpshackelford, and for carrying the points over from #1327. Going through each one: 1. Chart version bumps: left as they areIn this repo the chart
The concern behind the request is still covered, as far as I can tell: the If you would still prefer a manual bump I am happy to add it. I just did not want to work against the release flow. 2.
|
jpshackelford
left a comment
There was a problem hiding this comment.
Thanks again for the great work on this!
Great catch also about properly detecting the secret and adding it to the support bundle. You were right to put the check in the automation pod rather than extending the openhands SECRET_PRESENCE list.
Looking forward to being able to use this myself!
|
🚀 Released in openhands/0.75.0. |
Description
The automation service only offers its key-value store when
AUTOMATION_KV_SECRETis set, and nothing in the chart or the Replicated manifests set it. On a self-hosted install:GET /api/automation/v1/capabilitiesdoes not listkvStore;AUTOMATION_KV_TOKEN.Every run starts in a fresh sandbox there, so an automation that keeps state between runs has nowhere to put it. The automation templates that track work across runs (issue polling, GitHub code review and issue-to-PR dispatch, the Jira poller) either fail or repeat their work.
This provisions the secret the same way the git sync secret is provisioned (#1213):
replicated/config.yaml: hidden, generatedautomation_kv_secretpassword item.replicated/secrets.yaml: passes it to theopenhands-secretschart when automations are enabled.charts/openhands-secrets:config.automation_kv_secretvalue and theautomation-kv-secretSecret (keykv-secret).charts/openhands/charts/automation:kvSecretFromSecretvalue and anAUTOMATION_KV_SECRETenv entry on the automation pods. ThesecretKeyRefis optional, so an install without the Secret keeps starting with the store off.charts/openhands/values.yaml: mirrorskvSecretFromSecretunderautomation:.replicated/openhands.yaml: the item joinssecretsChecksum.charts/openhands/templates/troubleshoot/support-bundle.yaml: a newapp/automation-config-snapshotcollector reports whetherAUTOMATION_KV_SECRETis set (set/empty_or_unset, never the value), so a support bundle shows whether the KV store is configured. It runs in the automation pod, the only pod that receives the variable.Checks run locally:
helm unittest charts/openhands(182 passed),helm unittest charts/openhands/charts/automation(26 passed) andhelm unittest charts/openhands-secrets(12 passed), including the three new suites below.python3 scripts/check_secret_checksum.py: all 46 password fields covered.pytest scripts/test_keycloak_realm_template.py scripts/test_openhands_secrets_template.py scripts/test_replicated_resolver_label.py: 29 passed.helm templaterenders the Secret only whenautomation.enabledis true, and the env entry on both the migrate and the automation containers.Deployed to the Replicated fleet VM
shared-4(clean install) with the OHE test procedure, together with the related changes:hieple/deploy-2026-10-01(ac80547) ismainplus:AUTOMATION_KV_SECRET);automationpinned tosha-03687e7(feat: support agent profiles in cloud mode automation#541; image revision label 03687e70dfc0);agent-canvaspinned tosha-9f60167(feat(automations): show templates on cloud backends and offer native git integrations OpenHands#17830; image revision label 9f601672d942), which ships the extensions npm package at feat(automations): run the automation templates on OpenHands Cloud and Enterprise extensions#712's head (bf7e3212);EXTENSIONS_REF: hieptl/ohe-3160underglobal.agentServerEnv, so sandboxes load the skills from the extensions branch.hieple/deploy-2026-10-01. The fleet run succeeded: https://github.com/OpenHands/infra/actions/runs/36819742198https://app.shared-4.replicated.all-hands-testing.devwithout signing in:/server_info:app_version1.67.0,sdk_version1.49.6./api/automation/healthand/api/automation/ready: 200./api/automation/openapi.jsonreports version 1.16.0; the chart's default image is 1.15.1, so the pinned build is the one running./canvas/bundle (278 assets) contains the script bundles of the extensions branch (CloudConversations,_deliver_cloud, the$AUTH_HEADERskill text) and the Canvas changes (mcp-native-panel, thecloud-providers-configuredquery).GET /api/automation/v1/capabilities(expected to listagentProfilesandkvStore), a preflight with a profile selected, and an end-to-end run of a template.Helm Chart Checklist
Additional Notes
charts/openhands-secrets/tests/automation_kv_secret_test.yaml(no Secret when automations are disabled; the value under the key the automation chart reads) andcharts/openhands/charts/automation/tests/kv_secret_env_test.yaml(the env entry with its optional secret reference; no entry when the reference is unset), andcharts/openhands/tests/automation_support_bundle_test.yaml(the support bundle collector targets the automation pod and is left out when automations are disabled).RandomString 32produces.Demo Video
demo.mov