From 1016f1a7cb076f4ebbac3907e9ab72eb9c800ef8 Mon Sep 17 00:00:00 2001 From: Alan Walsh Date: Mon, 9 Mar 2026 17:18:55 -0400 Subject: [PATCH 1/4] feat(ardac1prd): pin image tags to 2026.03 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- ardac1prd/portal.ardac.org/values.yaml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/ardac1prd/portal.ardac.org/values.yaml b/ardac1prd/portal.ardac.org/values.yaml index 2ead25b..81e5612 100644 --- a/ardac1prd/portal.ardac.org/values.yaml +++ b/ardac1prd/portal.ardac.org/values.yaml @@ -36,6 +36,8 @@ ambassador: arborist: enabled: true + image: + tag: "2026.03" externalSecrets: dbcreds: "ardac1prd-default-arborist-creds" @@ -44,6 +46,8 @@ argo-wrapper: audit: enabled: true + image: + tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::742378880825:role/gen3_service/ardac1prd-default-audit-sa" @@ -53,6 +57,8 @@ audit: aws-es-proxy: enabled: true + image: + tag: "2026.03" esEndpoint: "vpc-ardac1prd-gen3-metadata-34ztrt3iey3wvgd36nrpf5gk5m.us-east-1.es.amazonaws.com" externalSecrets: awsCreds: "ardac1prd-default-aws-es-proxy-creds" @@ -69,6 +75,8 @@ dicom-viewer: fence: enabled: true + image: + tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::742378880825:role/gen3_service/ardac1prd-default-fence-sa" @@ -100,6 +108,8 @@ grafana: guppy: enabled: true + image: + tag: "2026.03" indices: - index: ardac_case type: case @@ -120,6 +130,8 @@ guppy: hatchery: enabled: true + image: + tag: "2026.03" hatchery: sidecarContainer: @@ -176,6 +188,8 @@ hatchery: indexd: enabled: true + image: + tag: "2026.03" defaultPrefix: "dg.XXXX/" externalSecrets: dbcreds: "ardac1prd-default-indexd-creds" @@ -183,6 +197,8 @@ indexd: manifestservice: enabled: true + image: + tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::742378880825:role/gen3_service/ardac1prd-default-manifestservice-sa" @@ -197,6 +213,8 @@ metadata: peregrine: enabled: true + image: + tag: "2026.03" externalSecrets: dbcreds: "ardac1prd-default-peregrine-creds" @@ -1482,9 +1500,13 @@ requestor: revproxy: enabled: true + image: + tag: "2026.03" sheepdog: enabled: true + image: + tag: "2026.03" replicaCount: 5 externalSecrets: dbcreds: "ardac1prd-default-sheepdog-creds" @@ -1497,6 +1519,8 @@ sower: wts: enabled: true + image: + tag: "2026.03" externalSecrets: dbcreds: "ardac1prd-default-wts-creds" createWtsOidcClientSecret: false From 83c440bb4136430808df0845d244660e5d18a7b2 Mon Sep 17 00:00:00 2001 From: Alan Walsh Date: Mon, 9 Mar 2026 17:26:22 -0400 Subject: [PATCH 2/4] feat(ardac1dmo): pin image tags to 2026.03 for gen3 services Add explicit image.tag: 2026.03 for all enabled services whose upstream chart defaults are empty or master. Services with specific version defaults (ambassador: 1.4.2, metadata: feat_es-7) and the custom portal image are left unchanged. Services updated: arborist, audit, aws-es-proxy, fence, hatchery (including fence sidecar), indexd, manifestservice, peregrine, revproxy, sheepdog, wts Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- ardac1dmo/demo.ardac.org/values.yaml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/ardac1dmo/demo.ardac.org/values.yaml b/ardac1dmo/demo.ardac.org/values.yaml index c79e439..bf44d28 100644 --- a/ardac1dmo/demo.ardac.org/values.yaml +++ b/ardac1dmo/demo.ardac.org/values.yaml @@ -35,6 +35,8 @@ ambassador: arborist: enabled: true + image: + tag: "2026.03" externalSecrets: dbcreds: "ardac1dmo-default-arborist-creds" @@ -43,6 +45,8 @@ argo-wrapper: audit: enabled: true + image: + tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::613495871066:role/gen3_service/ardac1dmo-default-audit-sa" @@ -52,6 +56,8 @@ audit: aws-es-proxy: enabled: true + image: + tag: "2026.03" esEndpoint: "vpc-ardac1dmo-gen3-metadata-r5fevwf45ert54xbwhb3omlvsm.us-east-1.es.amazonaws.com" externalSecrets: awsCreds: "ardac1dmo-default-aws-es-proxy-creds" @@ -69,6 +75,8 @@ dicom-viewer: fence: enabled: true + image: + tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::613495871066:role/gen3_service/ardac1dmo-default-fence-sa" @@ -103,6 +111,11 @@ guppy: hatchery: enabled: true + image: + tag: "2026.03" + fence: + image: + tag: "2026.03" hatchery: sidecarContainer: @@ -156,6 +169,8 @@ hatchery: indexd: enabled: true + image: + tag: "2026.03" defaultPrefix: "dg.XXXX/" externalSecrets: dbcreds: "ardac1dmo-default-indexd-creds" @@ -164,6 +179,8 @@ indexd: manifestservice: enabled: true + image: + tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::613495871066:role/gen3_service/ardac1dmo-default-manifestservice-sa" @@ -178,6 +195,8 @@ metadata: peregrine: enabled: true + image: + tag: "2026.03" externalSecrets: dbcreds: "ardac1dmo-default-peregrine-creds" @@ -1220,9 +1239,13 @@ requestor: revproxy: enabled: true + image: + tag: "2026.03" sheepdog: enabled: true + image: + tag: "2026.03" replicaCount: 5 externalSecrets: dbcreds: "ardac1dmo-default-sheepdog-creds" @@ -1235,6 +1258,8 @@ sower: wts: enabled: true + image: + tag: "2026.03" externalSecrets: dbcreds: "ardac1dmo-default-wts-creds" createWtsOidcClientSecret: false From 7b30b3f1318f44a28d5c368c76f58d8ce2ba3dd7 Mon Sep 17 00:00:00 2001 From: Alan Walsh Date: Mon, 9 Mar 2026 17:34:26 -0400 Subject: [PATCH 3/4] revert: restore ardac1prd/portal.ardac.org/values.yaml to main Accidentally modified this file in previous commit. Only ardac1dmo changes were intended. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- ardac1prd/portal.ardac.org/values.yaml | 24 ------------------------ 1 file changed, 24 deletions(-) diff --git a/ardac1prd/portal.ardac.org/values.yaml b/ardac1prd/portal.ardac.org/values.yaml index 81e5612..2ead25b 100644 --- a/ardac1prd/portal.ardac.org/values.yaml +++ b/ardac1prd/portal.ardac.org/values.yaml @@ -36,8 +36,6 @@ ambassador: arborist: enabled: true - image: - tag: "2026.03" externalSecrets: dbcreds: "ardac1prd-default-arborist-creds" @@ -46,8 +44,6 @@ argo-wrapper: audit: enabled: true - image: - tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::742378880825:role/gen3_service/ardac1prd-default-audit-sa" @@ -57,8 +53,6 @@ audit: aws-es-proxy: enabled: true - image: - tag: "2026.03" esEndpoint: "vpc-ardac1prd-gen3-metadata-34ztrt3iey3wvgd36nrpf5gk5m.us-east-1.es.amazonaws.com" externalSecrets: awsCreds: "ardac1prd-default-aws-es-proxy-creds" @@ -75,8 +69,6 @@ dicom-viewer: fence: enabled: true - image: - tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::742378880825:role/gen3_service/ardac1prd-default-fence-sa" @@ -108,8 +100,6 @@ grafana: guppy: enabled: true - image: - tag: "2026.03" indices: - index: ardac_case type: case @@ -130,8 +120,6 @@ guppy: hatchery: enabled: true - image: - tag: "2026.03" hatchery: sidecarContainer: @@ -188,8 +176,6 @@ hatchery: indexd: enabled: true - image: - tag: "2026.03" defaultPrefix: "dg.XXXX/" externalSecrets: dbcreds: "ardac1prd-default-indexd-creds" @@ -197,8 +183,6 @@ indexd: manifestservice: enabled: true - image: - tag: "2026.03" serviceAccount: annotations: eks.amazonaws.com/role-arn: "arn:aws:iam::742378880825:role/gen3_service/ardac1prd-default-manifestservice-sa" @@ -213,8 +197,6 @@ metadata: peregrine: enabled: true - image: - tag: "2026.03" externalSecrets: dbcreds: "ardac1prd-default-peregrine-creds" @@ -1500,13 +1482,9 @@ requestor: revproxy: enabled: true - image: - tag: "2026.03" sheepdog: enabled: true - image: - tag: "2026.03" replicaCount: 5 externalSecrets: dbcreds: "ardac1prd-default-sheepdog-creds" @@ -1519,8 +1497,6 @@ sower: wts: enabled: true - image: - tag: "2026.03" externalSecrets: dbcreds: "ardac1prd-default-wts-creds" createWtsOidcClientSecret: false From 9fb7c89a99082ba17967363f358acd1c6dc97b1e Mon Sep 17 00:00:00 2001 From: Alan Walsh Date: Mon, 9 Mar 2026 17:39:12 -0400 Subject: [PATCH 4/4] feat(ardac1dmo): add explicit image repositories for pinned services Add image.repository alongside image.tag for all 11 services updated with the 2026.03 tag, making the full image reference visible and easily editable in values.yaml. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- ardac1dmo/demo.ardac.org/values.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/ardac1dmo/demo.ardac.org/values.yaml b/ardac1dmo/demo.ardac.org/values.yaml index bf44d28..fdc7c9a 100644 --- a/ardac1dmo/demo.ardac.org/values.yaml +++ b/ardac1dmo/demo.ardac.org/values.yaml @@ -36,6 +36,7 @@ ambassador: arborist: enabled: true image: + repository: "quay.io/cdis/arborist" tag: "2026.03" externalSecrets: dbcreds: "ardac1dmo-default-arborist-creds" @@ -46,6 +47,7 @@ argo-wrapper: audit: enabled: true image: + repository: "quay.io/cdis/audit-service" tag: "2026.03" serviceAccount: annotations: @@ -57,6 +59,7 @@ audit: aws-es-proxy: enabled: true image: + repository: "quay.io/cdis/aws-es-proxy" tag: "2026.03" esEndpoint: "vpc-ardac1dmo-gen3-metadata-r5fevwf45ert54xbwhb3omlvsm.us-east-1.es.amazonaws.com" externalSecrets: @@ -76,6 +79,7 @@ dicom-viewer: fence: enabled: true image: + repository: "quay.io/cdis/fence" tag: "2026.03" serviceAccount: annotations: @@ -112,9 +116,11 @@ guppy: hatchery: enabled: true image: + repository: "quay.io/cdis/hatchery" tag: "2026.03" fence: image: + repository: "quay.io/cdis/fence" tag: "2026.03" hatchery: @@ -170,6 +176,7 @@ hatchery: indexd: enabled: true image: + repository: "quay.io/cdis/indexd" tag: "2026.03" defaultPrefix: "dg.XXXX/" externalSecrets: @@ -180,6 +187,7 @@ indexd: manifestservice: enabled: true image: + repository: "quay.io/cdis/manifestservice" tag: "2026.03" serviceAccount: annotations: @@ -196,6 +204,7 @@ metadata: peregrine: enabled: true image: + repository: "quay.io/cdis/peregrine" tag: "2026.03" externalSecrets: dbcreds: "ardac1dmo-default-peregrine-creds" @@ -1240,11 +1249,13 @@ requestor: revproxy: enabled: true image: + repository: "quay.io/cdis/nginx" tag: "2026.03" sheepdog: enabled: true image: + repository: "quay.io/cdis/sheepdog" tag: "2026.03" replicaCount: 5 externalSecrets: @@ -1259,6 +1270,7 @@ sower: wts: enabled: true image: + repository: "quay.io/cdis/workspace-token-service" tag: "2026.03" externalSecrets: dbcreds: "ardac1dmo-default-wts-creds"