Repository navigation
fix(edge): support media connector stream destinations in 111-assets - #849
Merged
Merged
Conversation
- add optional path to stream destinations and omit unset settings - sync 111-assets ci/terraform namespaced_assets with the component - move media examples and 508 README to streams with Storage paths - fix device examples and credential references to the component schema 🎥 - Generated by Copilot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Alain Uyidi (auyidi1)
requested review from
a team,
Marcel Bindseil (bindsi) and
Katrien De Graeve (katriendg)
October 5, 2026 20:22
📚 Documentation Health ReportGenerated on: 2026-10-05 21:42:53 UTC 📈 Documentation Statistics
🏗️ Three-Tree Architecture Status
🔍 Quality Metrics
This report is automatically generated by the Documentation Automation workflow. |
📚 Documentation Health ReportGenerated on: 2026-10-07 17:40:25 UTC 📈 Documentation Statistics
🏗️ Three-Tree Architecture Status
🔍 Quality Metrics
This report is automatically generated by the Documentation Automation workflow. |
8 of 29 tasks
kgmwang1
reviewed
Oct 7, 2026
kgmwang1
left a comment
Contributor
There was a problem hiding this comment.
I tested this against my cluster and everything looks great.
kgmwang1
approved these changes
Oct 7, 2026
Alain Uyidi (auyidi1)
added a commit
that referenced
this pull request
Oct 8, 2026
#863) # Pull Request ## Description Fixes the critical Grype finding that currently fails Security Scan on every pull request: `shell-quote` 1.10.0 ([GHSA-pqg4-j6r4-53mv](GHSA-pqg4-j6r4-53mv), fixed in 1.11.0). The package is a transitive dependency of `launch-editor` in `docs/docusaurus`. * `docs/docusaurus/package.json`: the existing `shell-quote` override goes from `^1.8.4` to `^1.11.0`. * `docs/docusaurus/package-lock.json`: only the `node_modules/shell-quote` entry changes, to 1.11.0, with its registry tarball and integrity. Regenerating the full lockfile with the local npm version would have rewritten unrelated `libc` fields, so I left those alone. ## Related Issue None. Security Scan fails on `main`-based PRs, including #846, #847, #849, and #851. ## Type of Change - [x] Bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] Blueprint modification or addition - [ ] Component modification or addition - [ ] Documentation update - [ ] CI/CD pipeline change - [x] Other (please describe): dependency security update ## Testing Performed - [ ] Terraform plan/apply - [ ] Blueprint deployment test - [ ] Unit tests - [ ] Integration tests - [ ] Bug fix includes regression test (see [Test Policy](docs/contributing/testing-validation.md)) - [x] Manual validation - [x] Other: Grype scan ## Validation Steps 1. `npm ci --dry-run --ignore-scripts` in `docs/docusaurus` accepts the lockfile. 2. `grype dir:. --config .grype.yaml --fail-on high`, the Security Scan threshold, exits 0. 3. `shell-quote` 1.11.0 has no runtime dependencies and the same `engines` (`node >= 0.4`). ## Checklist - [ ] I have updated the documentation accordingly - [ ] I have added tests to cover my changes - [ ] All new and existing tests passed - [ ] I have run `terraform fmt` on all Terraform code - [ ] I have run `terraform validate` on all Terraform code - [ ] I have run `az bicep format` on all Bicep code - [ ] I have run `az bicep build` to validate all Bicep code - [x] I have checked for any sensitive data/tokens that should not be committed - [x] Lint checks pass (run applicable linters for changed file types) ## Security Review - [x] No credentials, secrets, or tokens are hardcoded or logged - [ ] RBAC and identity changes follow least-privilege principles - [ ] No new network exposure or public endpoints introduced without justification - [x] Dependency additions or updates have been reviewed for known vulnerabilities - [ ] Container image changes use pinned digests or SHA references Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
📚 Documentation Health ReportGenerated on: 2026-10-08 11:33:25 UTC 📈 Documentation Statistics
🏗️ Three-Tree Architecture Status
🔍 Quality Metrics
This report is automatically generated by the Documentation Automation workflow. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Description
Lets
111-assetsexpress media connector file-system tasks, and moves the media connector examples and the 508 README to the documentedstreamsformat.Configure the media connector configures tasks as asset streams. Each stream has a
streamConfiguration(taskType,autostart,format,snapshotsPerSecond,duration) and a destination:Mqttwithtopic, orStoragewithpath. This PR fixes four problems:111-assetscouldn't express aStoragedestination. The stream destination type allowed onlytopic,retain, andqos. Terraform silently droppedpath, and Bicep warned withBCP037.alert-dataflow.tfvars.exampleused the olddatasetsformat. They also used settings the media connector doesn't document (intervalSeconds,quality,storagePath,durationSeconds), and paths like/clips, which the connector can't write. Learn requires a mounted volume root or a path under/tmp.namespaced_devices. They usedendpoint,target_address, andusername_secret_ref, and pointed to amedia-connector-assets.tfvars.examplethat doesn't exist.111-assetsCI wrapper'snamespaced_assetsvariable had drifted from the component. It had noevent_groupsormanagement_groupsand used old field names, so Terraform would silently drop ONVIF PTZ actions and event groups. This was noted as a follow-up in feat(edge): add ONVIF camera guide and hardened PTZ check script #847.Related Issue
Follow-up to #847 and #848.
Type of Change
Implementation Details
namespaced_assets[].streams[].destinations[].configurationadds optionalpath.main.tfnow omits unset destination settings instead of sending them asnull.AssetStreamDestinationtype adds optionalpath;AssetStream.destinationsuses it. Dataset destinations are unchanged.full-multi-node-cluster,minimum-single-node-cluster, anddual-peered-single-node-clusterkeepnamespaced_assetsidentical to the component. The Bicep blueprints import the component types.src/100-edge/111-assets/ci/terraformnamespaced_assetsis replaced with the component definition.alert-dataflow.tfvars.example: media assets now usestreams:Storagepaths under/tmp, with a comment explaining that the blueprint's connector templates don't mount a volume;<secret>/<key>form.Storagepath rules are explained.az iot ops ns asset media stream add, because the RTSP media server settings vary by connector version.ms.datechanges to ISO format; feat(application): add continuous recording to 503 media capture service #848 makes the same edit.npm run tf-docsandnpm run bicep-docs.Testing Performed
Validation Steps
terraform fmt -check,terraform init -backend=false, andterraform validatepass for the component and the CI wrapper. TFLint with.tflint.hclpasses for the component, the CI wrapper, and the three blueprints.terraform planon a root module with everyfull-multi-node-clustervariable definition:alert-dataflow.tfvars.exampleand each of the five new HCL snippets in the 508 README;main.tfuses, that request bodies carry onlypathforStoragedestinations and only the set fields forMqttdestinations.terraform fmt -check.bicep buildpasses for the111-assetscomponent and CI wrapper and for thefull-multi-node-cluster,minimum-single-node-cluster, andonly-edge-iot-opsblueprints.bicep build-paramswith aStoragedestination compiles and passespaththrough. Onmain, the same parameters warn withBCP037.bicep formatleavestypes.bicepunchanged.scripts/tf-docs-check.shandscripts/bicep-docs-check.shreport no pending updates.Checklist
terraform fmton all Terraform codeterraform validateon all Terraform codeaz bicep formaton all Bicep codeaz bicep buildto validate all Bicep codeSecurity Review
Additional Notes
/tmp.