Skip to content

fix(edge): support media connector stream destinations in 111-assets - #849

Merged
Alain Uyidi (auyidi1) merged 3 commits into
mainfrom
fix/media-stream-destinations
Oct 8, 2026
Merged

Alain Uyidi (auyidi1) merged 3 commits into
mainfrom
fix/media-stream-destinations

Conversation

@auyidi1

Copy link
Copy Markdown
Contributor

Pull Request

Description

Lets 111-assets express media connector file-system tasks, and moves the media connector examples and the 508 README to the documented streams format.

Configure the media connector configures tasks as asset streams. Each stream has a streamConfiguration (taskType, autostart, format, snapshotsPerSecond, duration) and a destination: Mqtt with topic, or Storage with path. This PR fixes four problems:

  • 111-assets couldn't express a Storage destination. The stream destination type allowed only topic, retain, and qos. Terraform silently dropped path, and Bicep warned with BCP037.
  • The 508 README and alert-dataflow.tfvars.example used the old datasets format. They also used settings the media connector doesn't document (intervalSeconds, quality, storagePath, durationSeconds), and paths like /clips, which the connector can't write. Learn requires a mounted volume root or a path under /tmp.
  • The 508 README device examples didn't match namespaced_devices. They used endpoint, target_address, and username_secret_ref, and pointed to a media-connector-assets.tfvars.example that doesn't exist.
  • The 111-assets CI wrapper's namespaced_assets variable had drifted from the component. It had no event_groups or management_groups and used old field names, so Terraform would silently drop ONVIF PTZ actions and event groups. This was noted as a follow-up in feat(edge): add ONVIF camera guide and hardened PTZ check script #847.

Related Issue

Follow-up to #847 and #848.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Blueprint modification or addition
  • Component modification or addition
  • Documentation update
  • CI/CD pipeline change
  • Other (please describe):

Implementation Details

  • Component (Terraform): namespaced_assets[].streams[].destinations[].configuration adds optional path. main.tf now omits unset destination settings instead of sending them as null.
  • Component (Bicep): a new exported AssetStreamDestination type adds optional path; AssetStream.destinations uses it. Dataset destinations are unchanged.
  • Blueprints: full-multi-node-cluster, minimum-single-node-cluster, and dual-peered-single-node-cluster keep namespaced_assets identical to the component. The Bicep blueprints import the component types.
  • CI wrapper: src/100-edge/111-assets/ci/terraform namespaced_assets is replaced with the component definition.
  • alert-dataflow.tfvars.example: media assets now use streams:
    • snapshots to MQTT;
    • a 30-second MKV clip and snapshots to Storage paths under /tmp, with a comment explaining that the blueprint's connector templates don't mount a volume;
    • credential references in <secret>/<key> form.
  • 508 README:
    • Device, asset, and scenario examples are rewritten to the component schema.
    • The task-type table lists the documented settings and destinations.
    • Storage path rules are explained.
    • The live-streaming scenario uses az iot ops ns asset media stream add, because the RTSP media server settings vary by connector version.
    • The README's ms.date changes to ISO format; feat(application): add continuous recording to 503 media capture service #848 makes the same edit.
  • Generated READMEs are regenerated with npm run tf-docs and npm run bicep-docs.

Testing Performed

  • Terraform plan/apply
  • Blueprint deployment test
  • Unit tests
  • Integration tests
  • Bug fix includes regression test (see Test Policy)
  • Manual validation
  • Other: Bicep build and parameter compilation; TFLint

Validation Steps

  1. terraform fmt -check, terraform init -backend=false, and terraform validate pass for the component and the CI wrapper. TFLint with .tflint.hcl passes for the component, the CI wrapper, and the three blueprints.
  2. terraform plan on a root module with every full-multi-node-cluster variable definition:
    • accepts alert-dataflow.tfvars.example and each of the five new HCL snippets in the 508 README;
    • shows, via the same expression main.tf uses, that request bodies carry only path for Storage destinations and only the set fields for Mqtt destinations.
    • The example and the new snippets also pass terraform fmt -check.
  3. Bicep:
    • bicep build passes for the 111-assets component and CI wrapper and for the full-multi-node-cluster, minimum-single-node-cluster, and only-edge-iot-ops blueprints.
    • bicep build-params with a Storage destination compiles and passes path through. On main, the same parameters warn with BCP037.
    • bicep format leaves types.bicep unchanged.
  4. scripts/tf-docs-check.sh and scripts/bicep-docs-check.sh report no pending updates.
  5. markdownlint, markdown-table-formatter, cspell, and markdown-link-check pass for the 508 README. Gitleaks finds no leaks.

Checklist

  • I have updated the documentation accordingly
  • I have added tests to cover my changes
  • All new and existing tests passed
  • I have run terraform fmt on all Terraform code
  • I have run terraform validate on all Terraform code
  • I have run az bicep format on all Bicep code
  • I have run az bicep build to validate all Bicep code
  • I have checked for any sensitive data/tokens that should not be committed
  • Lint checks pass (run applicable linters for changed file types)

Security Review

  • No credentials, secrets, or tokens are hardcoded or logged
  • RBAC and identity changes follow least-privilege principles
  • No new network exposure or public endpoints introduced without justification
  • Dependency additions or updates have been reviewed for known vulnerabilities
  • Container image changes use pinned digests or SHA references

Additional Notes

  • Not deployed to a live cluster.
  • Possible follow-up: let the Akri connector template module mount a volume, so file-system tasks can write to persistent storage instead of /tmp.

- add optional path to stream destinations and omit unset settings
- sync 111-assets ci/terraform namespaced_assets with the component
- move media examples and 508 README to streams with Storage paths
- fix device examples and credential references to the component schema

🎥 - Generated by Copilot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

📚 Documentation Health Report

Generated on: 2026-10-05 21:42:53 UTC

📈 Documentation Statistics

Category File Count
Main Documentation 223
Infrastructure Components 232
Blueprints 40
GitHub Resources 26
AI Assistant Guides (Copilot) 17
Total 538

🏗️ Three-Tree Architecture Status

  • ✅ Bicep Documentation Tree: Auto-generated navigation
  • ✅ Terraform Documentation Tree: Auto-generated navigation
  • ✅ README Documentation Tree: Manual README organization

🔍 Quality Metrics

  • Frontmatter Validation:
    success
  • Link Validation: success

This report is automatically generated by the Documentation Automation workflow.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

📚 Documentation Health Report

Generated on: 2026-10-07 17:40:25 UTC

📈 Documentation Statistics

Category File Count
Main Documentation 223
Infrastructure Components 232
Blueprints 40
GitHub Resources 26
AI Assistant Guides (Copilot) 17
Total 538

🏗️ Three-Tree Architecture Status

  • ✅ Bicep Documentation Tree: Auto-generated navigation
  • ✅ Terraform Documentation Tree: Auto-generated navigation
  • ✅ README Documentation Tree: Manual README organization

🔍 Quality Metrics

  • Frontmatter Validation:
    success
  • Link Validation: success

This report is automatically generated by the Documentation Automation workflow.

@kgmwang1 kgmwang1 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I tested this against my cluster and everything looks great.

Alain Uyidi (auyidi1) added a commit that referenced this pull request Oct 8, 2026
#863)

# Pull Request

## Description

Fixes the critical Grype finding that currently fails Security Scan on
every pull request: `shell-quote` 1.10.0
([GHSA-pqg4-j6r4-53mv](GHSA-pqg4-j6r4-53mv),
fixed in 1.11.0). The package is a transitive dependency of
`launch-editor` in `docs/docusaurus`.

* `docs/docusaurus/package.json`: the existing `shell-quote` override
goes from `^1.8.4` to `^1.11.0`.
* `docs/docusaurus/package-lock.json`: only the
`node_modules/shell-quote` entry changes, to 1.11.0, with its registry
tarball and integrity. Regenerating the full lockfile with the local npm
version would have rewritten unrelated `libc` fields, so I left those
alone.

## Related Issue

None. Security Scan fails on `main`-based PRs, including #846, #847,
#849, and #851.

## Type of Change

- [x] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] Blueprint modification or addition
- [ ] Component modification or addition
- [ ] Documentation update
- [ ] CI/CD pipeline change
- [x] Other (please describe): dependency security update

## Testing Performed

- [ ] Terraform plan/apply
- [ ] Blueprint deployment test
- [ ] Unit tests
- [ ] Integration tests
- [ ] Bug fix includes regression test (see [Test
Policy](docs/contributing/testing-validation.md))
- [x] Manual validation
- [x] Other: Grype scan

## Validation Steps

1. `npm ci --dry-run --ignore-scripts` in `docs/docusaurus` accepts the
lockfile.
2. `grype dir:. --config .grype.yaml --fail-on high`, the Security Scan
threshold, exits 0.
3. `shell-quote` 1.11.0 has no runtime dependencies and the same
`engines` (`node >= 0.4`).

## Checklist

- [ ] I have updated the documentation accordingly
- [ ] I have added tests to cover my changes
- [ ] All new and existing tests passed
- [ ] I have run `terraform fmt` on all Terraform code
- [ ] I have run `terraform validate` on all Terraform code
- [ ] I have run `az bicep format` on all Bicep code
- [ ] I have run `az bicep build` to validate all Bicep code
- [x] I have checked for any sensitive data/tokens that should not be
committed
- [x] Lint checks pass (run applicable linters for changed file types)

## Security Review

- [x] No credentials, secrets, or tokens are hardcoded or logged
- [ ] RBAC and identity changes follow least-privilege principles
- [ ] No new network exposure or public endpoints introduced without
justification
- [x] Dependency additions or updates have been reviewed for known
vulnerabilities
- [ ] Container image changes use pinned digests or SHA references

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

📚 Documentation Health Report

Generated on: 2026-10-08 11:33:25 UTC

📈 Documentation Statistics

Category File Count
Main Documentation 223
Infrastructure Components 232
Blueprints 40
GitHub Resources 26
AI Assistant Guides (Copilot) 17
Total 538

🏗️ Three-Tree Architecture Status

  • ✅ Bicep Documentation Tree: Auto-generated navigation
  • ✅ Terraform Documentation Tree: Auto-generated navigation
  • ✅ README Documentation Tree: Manual README organization

🔍 Quality Metrics

  • Frontmatter Validation:
    success
  • Link Validation: success

This report is automatically generated by the Documentation Automation workflow.

@auyidi1
Alain Uyidi (auyidi1) merged commit f2552fe into main Oct 8, 2026
48 checks passed
@auyidi1
Alain Uyidi (auyidi1) deleted the fix/media-stream-destinations branch October 8, 2026 11:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants