System VariableSet Registry Variables
In an air-gapped deployment, the AIWorkloads that PaletteAI deploys must resolve their images and charts from the internal Zot registry. To make that registry available to workload templates without manual setup, PaletteAI injects a set of registry variables into the system VariableSet named mural-variables. Workload profiles reference these variables with the {{ var.<name> }} macro syntax.
This page describes the injected variables and how PaletteAI manages them. For the broader variable system, refer to Variables.
Injected Variables
PaletteAI derives most values from the chart-rendered oci-registry-hub Secret in the built-in namespace. While a variable remains PaletteAI-managed, its value reflects the deployed Zot registry configuration.
| Variable | Description |
|---|---|
zot-endpoint | Zot registry endpoint for air-gapped AIWorkloads. |
zot-insecure | Whether the Zot registry connection is insecure (non-TLS HTTP). |
zot-repository | Zot registry repository for AIWorkload content. |
zot-ca | PEM-encoded CA certificate of the Zot registry. |
zot-username | Username for the Zot registry. |
zot-password | Password for the Zot registry. |
zot-cert-secret-name | Name of the Secret holding the Zot registry CA certificate in the workload namespace. |
zot-auth-secret-name | Name of the Secret holding the Zot registry credentials in the workload namespace. |
Air-gapped profile bundles wire the two secret-name variables into the certSecretRef and secretRef of the Flux OCIRepository resources they render, so the secret names stay configurable instead of being hardcoded in every bundle.
Registry-derived variables are injected only when the registry configuration provides a value. For example, a TLS-enabled registry without basic authentication produces no zot-username, zot-password, or zot-auth-secret-name variables. zot-cert-secret-name is always injected, because its value is the fixed platform CA secret name that PaletteAI propagates into workload namespaces; zot-auth-secret-name is injected only when the registry configuration names an auth secret.
Injection only adds and refreshes variables; it never removes them. A fresh installation with the OCI registry disabled therefore has no Zot variables, but if the registry is disabled after injection and its Secret disappears, the previously injected variables remain in mural-variables.
How Injection Behaves
Injection is a convenience for air-gapped deployments, not a bootstrap dependency:
- Injection runs during system reconciliation. A missing registry Secret is a no-op. An empty endpoint only skips
zot-endpoint; the other variables are still injected when their values are available. An injection problem is logged and skipped so that the default VariableSet is always ensured. - On an upgrade from a pre-migration installation, injection is deferred while the legacy platform-namespace
mural-variablesVariableSet still has variables and the system VariableSet is empty. The system VariableSet namespace migration copies those variables into the system VariableSet, after which injection proceeds; the legacy VariableSet is preserved in the platform namespace and is not deleted. A missingzot-endpointright after an upgrade can therefore mean the migration is still pending rather than a problem with injection. - PaletteAI never overwrites a variable of the same name that it did not write. If you create or edit
zot-endpointyourself, your value survives every subsequent reconciliation. - PaletteAI watches the registry Secret and refreshes variables that remain PaletteAI-managed when it rotates, for example after a certificate renewal, credential rotation, or endpoint move.
- None of the injected variables are locked. You can override any of them at the namespace or workload scope, and a namespace-scoped or workload-scoped value wins over the system default.
Edit an Injected Variable
Injected variables carry a provenance marker and a value hash in their description. When you edit an injected variable, the hash no longer matches the value, and PaletteAI treats the variable as user-owned from that point on: it stops refreshing that variable's value. To return a variable to PaletteAI management, delete the variable. The next reconciliation re-injects it only if the corresponding registry value is available; otherwise the variable stays absent until that value appears.
If you need a different value without losing automatic refreshes, override the variable at the namespace or workload scope instead of editing the system VariableSet.