From 89c78bea2442ca86dd2450c26e167ac0bef85921 Mon Sep 17 00:00:00 2001 From: Jason Morrow Date: Fri, 11 Sep 2026 08:59:31 -0400 Subject: [PATCH 1/2] support the PagerDuty EU service region Self-hosted instances in the EU need their PagerDuty integration pointed at the EU OAuth and REST endpoints. The integration already had client id/secret values but hardcoded the US endpoints, so an EU-registered app could not complete OAuth. Adds three optional values to the existing integrations.pagerduty block, carried in the per-integration secret alongside the credentials so all of PagerDuty's config stays in one place and reaches pods through the secretRef that is already wired up. Nothing new is needed in the configmap. All three default to "", which the app's read_pagerduty_url treats as "use the US default" (.presence || default) -- so existing installs are unaffected. Note the app-side support landed in d169b865 (2026-09-10) and is NOT in the 2026.8.13 image this chart pins. These values render correctly but stay inert until the app image bump. --- .changes/unreleased/Feature-20260911-101500.yaml | 5 +++++ charts/opslevel/templates/opslevel/secret.yaml | 3 +++ charts/opslevel/values.yaml | 10 ++++++++++ 3 files changed, 18 insertions(+) create mode 100644 .changes/unreleased/Feature-20260911-101500.yaml diff --git a/.changes/unreleased/Feature-20260911-101500.yaml b/.changes/unreleased/Feature-20260911-101500.yaml new file mode 100644 index 0000000..01e2ab5 --- /dev/null +++ b/.changes/unreleased/Feature-20260911-101500.yaml @@ -0,0 +1,5 @@ +kind: Feature +body: Add `integrations.pagerduty.secret.appAuthorizationUrl`, `.appTokenUrl` and `.apiUrl` + so self-hosted instances can point the PagerDuty integration at a non-US service + region (e.g. EU). Leaving them blank keeps the existing US endpoints. +time: 2026-09-11T10:15:00.000000-04:00 diff --git a/charts/opslevel/templates/opslevel/secret.yaml b/charts/opslevel/templates/opslevel/secret.yaml index 5fad921..794ae25 100644 --- a/charts/opslevel/templates/opslevel/secret.yaml +++ b/charts/opslevel/templates/opslevel/secret.yaml @@ -156,6 +156,9 @@ data: PAGERDUTY_ENABLED: '{{ .Values.integrations.pagerduty.enabled | toString | b64enc }}' PAGERDUTY_APP_CLIENT_ID: '{{ required "please provide 'integrations.pagerduty.secret.usAppClientId'" .Values.integrations.pagerduty.secret.usAppClientId | b64enc }}' PAGERDUTY_APP_CLIENT_SECRET: '{{ required "please provide 'integrations.pagerduty.secret.usAppClientSecret'" .Values.integrations.pagerduty.secret.usAppClientSecret | b64enc }}' + PAGERDUTY_APP_AUTHORIZATION_URL: '{{ .Values.integrations.pagerduty.secret.appAuthorizationUrl | b64enc }}' + PAGERDUTY_APP_TOKEN_URL: '{{ .Values.integrations.pagerduty.secret.appTokenUrl | b64enc }}' + PAGERDUTY_API_URL: '{{ .Values.integrations.pagerduty.secret.apiUrl | b64enc }}' {{- end }} {{- end }} diff --git a/charts/opslevel/values.yaml b/charts/opslevel/values.yaml index 768c16e..9b80c87 100644 --- a/charts/opslevel/values.yaml +++ b/charts/opslevel/values.yaml @@ -390,6 +390,16 @@ integrations: name: "opslevel-pagerduty" usAppClientId: "" usAppClientSecret: "" + # Point at a non-US PagerDuty service region (e.g. EU). Leave blank to use the + # US endpoints -- the app falls back to its own defaults on an empty value. The + # client id/secret above must belong to an app registered in the same region. + # EU: https://app.pagerduty.com/global/oauth/authorize + appAuthorizationUrl: "" + # EU: https://app.pagerduty.com/global/oauth/token + appTokenUrl: "" + # EU: https://api.eu.pagerduty.com/ -- the trailing slash is required, the app + # uses this as an HTTP client url_prefix and appends relative paths to it. + apiUrl: "" slack: # Docs: enabled: false secret: From 2791c0c94b13d76f5c2df18c72c1ae701ad21fb7 Mon Sep 17 00:00:00 2001 From: Jason Morrow Date: Fri, 11 Sep 2026 09:20:41 -0400 Subject: [PATCH 2/2] prep 2026.9.11 release Bumps the opslevel app image to the dcdcb288 build (digest verified against ECR; all five tags on that build resolve to the same manifest, and the digest is what actually runs since the helper renders repo:tag@digest). This build contains d169b865, so the PagerDuty EU region values added in this branch take effect on merge rather than staying inert. opssight is left on f9a8f4b: its newest build has not been tagged selfhosted-production-*, and opssight routinely lags a release anyway -- 2026.5.20 shipped a February build. --- charts/opslevel/Chart.yaml | 4 ++-- charts/opslevel/values.yaml | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/charts/opslevel/Chart.yaml b/charts/opslevel/Chart.yaml index ef11beb..9d86d81 100644 --- a/charts/opslevel/Chart.yaml +++ b/charts/opslevel/Chart.yaml @@ -1,8 +1,8 @@ apiVersion: "v2" name: "opslevel" type: "application" -version: "2026.8.13" -appVersion: "2026.8.13" +version: "2026.9.11" +appVersion: "2026.9.11" description: "The OpsLevel internal developer portal helps your team ship fast without risking your software standards." home: "https://www.opslevel.com/" icon: "https://app.opslevel.com/OpsLevelLogo-Primary.svg" diff --git a/charts/opslevel/values.yaml b/charts/opslevel/values.yaml index 9b80c87..9113a2d 100644 --- a/charts/opslevel/values.yaml +++ b/charts/opslevel/values.yaml @@ -46,8 +46,8 @@ opslevel: ssrfAllowedIpRanges: [] image: repository: "746108190720.dkr.ecr.us-east-1.amazonaws.com/opslevel" - tag: "selfhosted-prod-8de7ca42-1786633441" - digest: "sha256:cd44c821513c0d4f6b52c27352f558eba77e43e20697e9378617cba953f013be" + tag: "selfhosted-prod-dcdcb288fcdcc48cc6c7fb862b19a2770c0e342c" + digest: "sha256:41956ab48026a27f9af47cf9fba90e3e2ae2fda1feff2942ad0f0c0cc43302af" account: name: "Main" username: "Alice Wonderland"