CI / CI (pull_request) Successful in 32m52s
- config.yaml: prod config with cluster-internal DNS (LLM, OpenSearch, Authentik, Temporal, API-GW) - config.local.yaml: dev config with external URLs via ingress - deployment.yaml: remove hardcoded URIs, read all from ConfigMap envFrom - All downstream service URIs now configurable per environment - Production config encrypted with SOPS (Age-based) - Application code reads LLM_ENDPOINT, OPENSEARCH_HOST, AUTHENTIK_ISSUER, etc. from ENV - Simplifies prod/dev switching: just swap ConfigMap, no code changes