# br-sta — values-template.yaml (the operator fill-in surface)
#
# Copy this file, fill the REQUIRED fields and the credential placeholders, and
# install:
#   helm install br-sta oci://ghcr.io/lerianstudio/br-sta-helm -f values-template.yaml
#
# STYLE (canonical global-first shape): the env-wide contract lives in ONE
# `global:` block, FIRST. Set each dependency connection ONCE with its typed
# mask; the chart renders the app's native env keys from it. Do NOT repeat
# POSTGRES_*/REDIS_*/RABBITMQ_*/TRANSFER_S3_*/STREAMING_* keys under
# common.configmap: a native key there WINS over its mask and defeats it.
# Credentials go under common.secrets (use AVP <path:...> placeholders in
# GitOps), per key from a Secret you manage (common.secretRefs), or all in an
# existing Secret (common.useExistingSecret).

# --- The env-wide contract ------------------------------------------------------
global:
  # -- aws | gcp | azure presets TLS/ssl/scheme for the masks below ("" = self-managed).
  cloud: ""
  # -- production (the default) turns on the app's production gates: TLS,
  # mandatory audit transport, transfer bucket. development | develop |
  # dev | local | test are the development class (auth may be off). The license
  # (LICENSE_KEY + ORGANIZATION_IDS) is required in every environment.
  env:
    name: "production"
  datastores:
    postgres: { host: "", port: "5432", user: "br_sta", name: "br_sta", ssl: "require" }       # <- REQUIRED: host
    redis:    { host: "", tls: "true" }                                                    # <- REQUIRED: host:port
    broker:   { host: "", amqpPort: "5671", scheme: "amqps", user: "br_sta" }             # <- REQUIRED: host (or secrets.RABBITMQ_URL)
  objectStorage:
    # The transfer bucket: holds BOTH directions (outbound sources + BACEN
    # downloads). br-sisbajud reads the SAME block for its STA inbound bucket.
    # endpoint "" = native AWS S3 only; REQUIRED for SeaweedFS/MinIO/any other S3 (with usePathStyle "true").
    sta: { endpoint: "", region: "us-east-1", bucket: "", usePathStyle: "false" }          # <- REQUIRED in production: bucket
    # Audit exports (the worker writes, the manager serves downloads).
    staAuditExports: { bucket: "" }
  kms:
    vendor: "envvar"                   # envvar (hex MASTER_KEYS) | aws (KMS-wrapped MASTER_KEYS)
    # keyId: "arn:aws:kms:<region>:<account>:key/<id>"   # <- REQUIRED for vendor: aws
  auth:
    enabled: true                      # the app accepts false only in a development-class env
    host: "http://plugin-access-manager-auth.plugin-access-manager.svc.cluster.local:4000"
  streaming:
    # ON: br-sisbajud consumes br-sta's facts on lerian.streaming.br-sta, and facts
    # produced while off are never re-sent. The render fails until brokers + SASL are set.
    enabled: true
    brokers: ""                        # <- REQUIRED: host:port CSV
    tlsEnabled: true                   # <- REQUIRED with SASL (SASL over plaintext is refused); must be true with deploymentMode saas
    saslMechanism: "SCRAM-SHA-256"     # <- REQUIRED: SCRAM-SHA-256 | SCRAM-SHA-512 | PLAIN ("" = unauthenticated broker, byoc only)
    saslUsername: ""                   # <- REQUIRED: the br-sta principal (or common.secrets.STREAMING_SASL_USERNAME)
    # Both binaries create lerian.streaming.br-sta + .dlq at boot when the principal has
    # CreateTopics (denied = WARN, not a boot failure). false: IaC-provisioned topics, which must exist first.
    topicAutoProvision: true
  observability:
    enabled: false                     # true => node-local collector http://$(HOST_IP):4317
  multiTenant:
    enabled: false
    # url: "http://tenant-manager.tenant-manager.svc.cluster.local:4026"
    # redisHost: "valkey.internal"

# The images are public on GHCR. Set a pull secret only for a private mirror/registry:
# imagePullSecrets: [{name: my-registry-credential}]
imagePullSecrets: []

manager:
  image:
    tag: ""                            # optional — defaults to Chart.appVersion
  replicaCount: 2
  ingress:
    enabled: false
    className: "nginx"
    hosts:
      - host: ""
        paths:
          - path: /
            pathType: Prefix

worker:
  image:
    tag: ""                            # optional — defaults to manager.image.tag

common:
  app:
    deploymentMode: "byoc"             # byoc (your cloud) | saas (every dependency must be TLS) | local
  cors:
    allowedOrigins: ""                 # <- REQUIRED in production: your UI origins (CSV)
  server:
    tlsTerminatedUpstream: true        # TLS ends at the ingress
    trustedProxies: ""                 # ingress/LB CIDR (SERVER_TRUSTED_PROXIES)
  auth:
    trustedProxies: ""                 # same CIDR (TRUSTED_PROXIES, lib-auth client-IP forwarding)
  # Access-manager permission declaration (manager); off by default:
  # identity: { declarationEnabled: true, host: "<access-manager-idp-url>", m2mClientId: "<client-id>" }
  license:
    organizationIds: ""                # <- REQUIRED (every environment)
  bacen:
    environment: "homologation"        # production => the live BACEN STA host
  transfer:
    # Transfer outcomes reach br-sisbajud only through global.streaming: keep both on.
    schedulerEnabled: true             # the ONLY path that uploads to BACEN (worker)
    inboundEnabled: false              # BACEN-pulled files
  secrets:
    MASTER_KEYS: ""                    # <- REQUIRED: "v1:<openssl rand -hex 32>" (never rotate by replacing)
    POSTGRES_PASSWORD: ""              # <- REQUIRED for external Postgres (production + migrations)
    REDIS_PASSWORD: ""
    RABBITMQ_DEFAULT_PASS: ""          # <- REQUIRED in production (or a full RABBITMQ_URL)
    # RABBITMQ_URL: ""                 # amqps://user:pass@host:5671/vhost — replaces host/user/pass
    LICENSE_KEY: ""                    # <- REQUIRED (every environment)
    AWS_ACCESS_KEY_ID: ""              # or an IRSA / workload-identity service account
    AWS_SECRET_ACCESS_KEY: ""
    STREAMING_SASL_PASSWORD: ""        # <- REQUIRED (global.streaming.saslMechanism is set)
    STREAMING_TLS_CA_CERT: ""          # <- REQUIRED when the broker CA is not in the system pool (PEM)
    # IDP_M2M_CLIENT_SECRET: ""        # <- REQUIRED when identity.declarationEnabled
    # MULTI_TENANT_SERVICE_API_KEY: "" # <- REQUIRED when multi-tenancy is on
  # Or reference single keys of a Secret the chart does not manage (ESO/Vault);
  # a reference counts as set for the checks above:
  # secretRefs:
  #   STREAMING_SASL_PASSWORD: { name: redpanda-br-sta, key: password }
  # Or keep every credential in an operator-managed Secret:
  useExistingSecret: false
  existingSecretName: ""

serviceAccount:
  annotations: {}                      # e.g. IRSA: eks.amazonaws.com/role-arn: <role-arn>

migrations:
  enabled: true                        # single-tenant only; connection follows global.datastores.postgres

# External infra is the production path. For a fully self-contained dev install
# (PostgreSQL, Valkey, RabbitMQ, SeaweedFS, Redpanda, mock STA) use
# values-dev.yaml instead of this file.
postgresql:
  enabled: false
valkey:
  enabled: false
rabbitmq:
  enabled: false
seaweedfs:
  enabled: false
