You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
helm: nats.auth.enabled defaults to true. Upgrading restarts NATS and rolls sie-config, the gateway, and the workers; pods that have not rolled yet are refused until they do, and memory-backed queued work is lost as on any NATS restart. To avoid the gap, upgrade once with nats.auth.allowAnonymous=true, then again without it. helm upgrade --reuse-values now fails the render because the reused NATS values lack the server wiring; use --reset-then-reuse-values or -f. With an external NATS server (nats.install=false), set nats.auth.existingSecrets.{config,gateway,worker} and create the users, or set nats.auth.enabled=false. nats-box and the NATS helm test pod are disabled by default. Credentials embedded in SIE_NATS_URL are not used.
helm: values-aws.yaml, values-gke.yaml, and values-aks.yaml no longer enable the gateway Ingress, so a plain upgrade with them removes the existing host-less, TLS-less Ingress. A gateway Ingress now renders only with gateway auth (gateway.auth.mode=static with gateway.auth.tokenSecretName), the oauth2-proxy edge on ingress-nginx, or ingress.allowUnauthenticated=true, and only with TLS or ingress.allowPlaintext=true; set both opt-ins to keep the previous catch-all Ingress. A LoadBalancer or NodePort gateway Service needs gateway auth or gateway.service.allowUnauthenticated=true. POST /v1/pools now rejects a warm floor above SIE_GATEWAY_POOL_MAX_MINIMUM_WORKER_COUNT (default 4) or a TTL above SIE_GATEWAY_POOL_MAX_TTL_S (default 3600) with 400, a pool beyond SIE_GATEWAY_MAX_POOLS (default 64) or named default with 403. The Python and TypeScript SDKs now send SIE_API_KEY when no API key is passed and the base URL has the same origin as SIE_BASE_URL; pass an empty API key to opt out.
config: the gateway no longer receives the sie-config admin token, so with gateway auth enabled its admin routes (POST, PUT and DELETE under /v1/pools, /v1/admin and /v1/configs) answer 403 until gateway.auth.adminTokenSecretName is set. sie-config, gateway and worker sidecar images older than this chart do not work with the split tokens.
Features
examples: add document-to-markdown-olmocr, LightOnOCR-2-1B on all of olmOCR-Bench (#441) (934a2a6)
examples: add support-assistant-policy, the /chat support-rules run (#438) (533ed0f)
generation: report prefix-cache hits as usage.prompt_tokens_details.cached_tokens (#386) (c125504)
helm: authenticate every NATS connection with per-component users (#421) (60f30ab)