Active deprecations
featureFlags.enableSimpleAuthSecret (Helm chart)
The toggle for component-to-component bearer authentication moved from
featureFlags.enableSimpleAuthSecret to apiClientSecret.enabled. The legacy
field continues to work as an alias in chart 5.x. Setting both to conflicting
values fails the chart render.
Migration: rename the key in values.yaml.
featureFlags.enableLegacySecretSeeding and legacy Secrets (Helm chart)
Chart 5.0 moved credential seeding out of Helm templates and into the in-cluster
config-controller. The chart 4.x
api-client-secret and
thoras-timescale-password Secrets are still rendered when
featureFlags.enableLegacySecretSeeding is true (the default) so the
config-controller can migrate their values on upgrade. Nothing consumes them
afterwards. The flag and both Secrets are removed in chart 6.0.
Migration: set featureFlags.enableLegacySecretSeeding: false on fresh
installs, and on existing installs once the first 5.x upgrade has completed and
all pods are healthy. See
Legacy secret seeding.
