Deployment & Settings Changes - v1.74.0
Release Date: 2026-10-07
Upgrade order
- Back up the database and retain the deployed images, chart values, and signing-key Secret.
- Review confirmed booking references with the read-only query below. Resolve duplicates through your supported booking workflow before applying V122.
- Retain the configured editor RSA key resources. Helm installations use the existing
<release>-rsaSecret withprivate-keyandpublic-keyentries. The new frontend runtime reads the matching public key as a PEM file at/keys/public-key; custom installations mount it there or pointCORE_PUBLIC_KEY_FILEat it. - Set the editor mail host and sender address; see Editor mail settings. If your Helm values set
editor.ingress.apiPathsor your own reverse proxy fronts the editor, route/mediato editor-service; see Editor routes. Write each apostrophe in editor settings once; see Settings that contain an apostrophe. - Upgrade editor-service and let Flyway complete V121–V127. Verify readiness and migration success before starting the new booking-service: booking-service reads
event.end_datebut does not apply the migrations. - Upgrade booking-service, editor frontend, converter, and renderer assets. For custom deployment tooling, gate booking-service startup on migration completion; do not assume a shared Helm upgrade orders the pods. The Docker Compose bundle for this release applies this gate; see Docker Compose.
- Check editor load, save, publish, image conversion, and a test booking. Reopen venue-shape charts and review geometry before saving them.
Database changes
Flyway runs these migrations at editor-service startup.
| Migration | Effect | Upgrade consideration |
|---|---|---|
V121__event_end_date |
Adds and backfills event.end_date; a trigger keeps it synchronized with legacy kill_after. |
Editor-service must migrate the database before the new booking-service starts. The backfill updates every event row inside the migration transaction, so event reads and writes wait until it commits. |
V122__booking_session_reference_and_properties |
Adds nullable session JSON properties, a reference index, and a unique index for confirmed references per event. | Requires no duplicate non-null references among confirmed sessions of the same event. Indexes are concurrent; the migration uses executeInTransaction=false. |
V123__venue_shape_dispersion |
Adds nullable venue_shape.dispersion, constrained to 0–1. |
The editor presents the value as 0–100. |
V124__venue_shape_corner |
Adds nullable venue_shape.corner, accepting round or chamfer. |
Older library readers decline version 2 snapshots. |
V125__shape_corners |
Adds nullable shape.corners JSON data. |
Exports using polygon corner data need the matching editor version. |
V126__schema_row_label_style |
Adds nullable schema.row_label_style, which holds the map’s row label style. |
None. |
V127__revoke_platform_role_sessions |
Ends the current sessions of super-admin and global-admin accounts at their next token refresh. | These users sign in again with their password after the upgrade. |
Before V122, an operator runs this query against the intended database in a read-only session:
SELECT event_id, reference, count(*)
FROM booking_session
WHERE state = 'CONFIRMED' AND reference IS NOT NULL
GROUP BY event_id, reference
HAVING count(*) > 1;
An empty result satisfies the duplicate-reference preflight at that moment. Coordinate writers that could create duplicates until the uniqueness index is in place. Do not delete bookings to make the migration pass. If a concurrent index build fails, it leaves an invalid index behind. The migration creates its indexes with IF NOT EXISTS, so a retry skips that index: inspect Flyway history and the index state, and drop the invalid index before retrying. A database restore or Flyway repair is an operator decision.
Editor frontend runtime
The editor frontend image runs Node and serves the editor core next to the static files. Custom installations must use the new image entrypoint and provide its public key; serving only static frontend files does not supply the core service. The core service is served at /core on the frontend web port (PORT, default 8081) and requires a valid editor token from every caller. Without the public-key file the frontend logs an error at startup and refuses every core call; a file that does not hold a readable public key stops the frontend at startup. Editor-service signs each of its calls with a short-lived token from its configured private key and calls the core at seatmap.services.core.url. The default, http://127.0.0.1:8081/, reaches the frontend container of the same Helm pod; where the two run outside one pod, for example as separate Docker Compose services, set SEATMAP_SERVICES_CORE_URL to the frontend’s address, and where they run on different hosts, keep the host clocks synchronized. Keep the metrics listener internal: CORE_METRICS_PORT, default 9091, must differ from PORT.
The chart mounts public-key from the existing RSA Secret read-only at /keys/public-key. Frontend readiness and liveness probes use /healthz. A draining instance stops accepting core work and completes or times out in-flight jobs before exit.
| Helm value | Default | Requirement |
|---|---|---|
editor.frontend.coreWorkers |
1 |
Positive whole number; increase CPU and memory allocation when increasing workers. |
editor.frontend.jobTimeoutMs |
20000 |
Positive whole number of milliseconds; bounds a core job. |
editor.frontend.drainTimeoutMs |
15000 |
Positive whole number of milliseconds; leave at least 5 seconds below pod termination grace. |
editor.terminationGracePeriodSeconds |
30 |
Positive whole number of seconds; must accommodate the drain deadline and exit work. |
Numeric values must be at most 2147483647. Omitted or null values use the chart defaults. The chart rejects an insufficient grace period and derives SEATMAP_SERVICES_CORE_READ_TIMEOUT from the job timeout with five seconds of headroom, rounded down to whole seconds.
Outside Helm, configure CORE_WORKERS, CORE_JOB_TIMEOUT_MS, and CORE_DRAIN_TIMEOUT_MS, and align the backend’s core read timeout with the frontend job deadline. Allocate frontend resources through global.resources.frontend in Helm. The chart fixes one worker by default; the runtime can choose a worker count automatically when CORE_WORKERS is absent.
Docker Compose
The Docker Compose bundle for this release provides the same runtime without Helm. Existing Compose installations move to it with the bundle’s upgrade guide. The guide keeps a database volume that already runs Postgres 16 and moves an older one to Postgres 16 with a dump and restore.
The editor and editor-client services run as ordinary services on the bundle’s network, and editor-service reaches the editor core at http://editor-client:8081/ through SEATMAP_SERVICES_CORE_URL.
A one-shot setup service generates the installation’s RSA key pair in the editor-keys volume on the first start and keeps it on later starts. Editor-service reads file:/keys/private-key and file:/keys/public-key, and the frontend reads /keys/public-key to check the tokens editor-service signs for its core calls. Users sign in again once after the first start of the new bundle.
On the editor host, nginx sends /api, /swagger-ui, /preview, /media, /ws, /webjars, and /v3 to editor-service on port 8080, /backgrounds/ and /storage/ to the converter, and every other path to the frontend on port 8081. It does not expose /actuator/, and it is the only service that publishes host ports. Both editor containers use stop_grace_period: 30s, because the drain deadline is longer than the Compose default stop timeout of 10 seconds. Booking-service starts once editor-service reports healthy, which happens after the migrations complete.
The converter runs the converter-service image on port 3000 with its Valkey queue and CPU_CLAIM_DELAY_MS=0, and its API_KEY matches the editor’s SEATMAP_SERVICES_PREVIEW_API_KEY. Valkey replaces Redis and requires a password. For installations that keep their own compose file, the upgrade guide lists the settings of older bundles to delete and the settings that replace them.
Editor routes
Editor-service serves the bitmap backgrounds that the editor draws under a chart, at /media/ on the editor host. The chart’s default editor.ingress.apiPaths route /media to editor-service. A values file that sets editor.ingress.apiPaths replaces the whole default list, so add /media to it. Installations behind their own reverse proxy send /media on the editor host to editor-service on port 8080 with the path unchanged.
Editor mail settings
Password-reset email goes through the mail server the deployment configures. Set SEATMAP_MAIL_HOST, SEATMAP_MAIL_PORT, SEATMAP_MAIL_STRATEGY, SEATMAP_MAIL_USERNAME, SEATMAP_MAIL_PASSWORD, and SEATMAP_RESET_FROMMAIL on editor-service. The port defaults to 587, an empty strategy follows from the port as described after the table, and the other settings have no default. Leave the username and password empty when the mail server accepts mail without signing in.
SEATMAP_MAIL_STRATEGY |
Connection | Usual port |
|---|---|---|
SMTPS |
Implicit TLS | 465 |
SMTP_TLS |
STARTTLS, required | 587 |
SMTP |
STARTTLS when the server offers it, otherwise unencrypted; trusted networks only | 25 or 587 |
Left empty, the strategy is SMTPS on port 465 and SMTP_TLS on any other port; set it for a server that uses implicit TLS on another port.
When SEATMAP_MAIL_HOST or SEATMAP_RESET_FROMMAIL is empty, or SEATMAP_MAIL_PASSWORD is set without SEATMAP_MAIL_USERNAME, editor-service logs one warning at startup, and a password-reset request answers HTTP 503 without sending email. The reset page then tells the user that password reset by email is not set up and to contact their administrator.
Helm sets these variables from the following values:
| Helm value | Variable | Default |
|---|---|---|
global.mail.host |
SEATMAP_MAIL_HOST |
Empty |
global.mail.port |
SEATMAP_MAIL_PORT |
587 |
global.mail.strategy |
SEATMAP_MAIL_STRATEGY |
Empty: the variable is not set |
global.mail.fromAddress |
SEATMAP_RESET_FROMMAIL |
Empty |
secrets.mail.username |
SEATMAP_MAIL_USERNAME |
Empty |
secrets.mail.password |
SEATMAP_MAIL_PASSWORD |
Empty |
The chart refuses to render when global.mail.strategy is not one of the three strategies, in any letter case, or when a mail secret is not a string; quote a numeric password in the values file or pass it with --set-string. It trims surrounding whitespace from the mail secrets.
Before upgrading a Helm installation, set global.mail.host and global.mail.fromAddress in its values when they are not set there yet: the chart no longer has defaults for them. Delete global.mail.socket.port from your values files; the chart no longer reads it. Installations outside Helm and Docker Compose set SEATMAP_MAIL_HOST and SEATMAP_RESET_FROMMAIL, which no longer have defaults either. The Docker Compose bundle sets all of these from the MAIL_* settings in its .env, with MAIL_STRATEGY empty by default.
Settings that contain an apostrophe
Editor-service uses its settings exactly as written, apostrophes included. This covers the first-run settings, such as the first administrator’s password and organization and the default user password, the Google Maps keys, the mail and password-reset settings, and the service, preview, metrics, and federation URLs. A value written with a doubled apostrophe so that editor-service would start now keeps both apostrophes: write the apostrophe once, as in Children's Theatre.
The Helm chart stores the database, Redis, security, first-run, converter, object storage, Google Maps, and federation secrets exactly as given, including apostrophes, quotes, spaces, and #. Remove quoting that was added inside a secret value so that the chart would install, such as '\'' in place of an apostrophe or quotes around the whole value. In the Docker Compose bundle’s .env, follow the quoting rules in the bundle’s install guide.
Booking configuration
| Helm value | Default | Effect |
|---|---|---|
global.bookingSessions.enabled |
true |
Enables the booking-session flow. |
global.bookingSessions.maxSeats |
10 |
Session seat limit. |
global.bookingSessions.ttlSeconds |
900 |
Session lifetime. |
global.bookingSessions.pendingGraceSeconds |
600 |
Pending-payment grace period. |
global.series.enabled |
true |
Enables the series endpoints. |
Existing integrations that reuse one reference for several confirmed sessions of the same event must change that behavior before using this version. See the backend API guide for confirmation and release semantics.
Converter configuration
When converter.enabled is true, converter.cpu.enabled defaults to true and controls the CPU converter instance independently of converter.gpu.enabled. Keep at least one suitable worker enabled when conversion is required. With converter.gpu.enabled: false, the chart sends the CPU worker a claim delay of 0; otherwise converter.config.async.cpuClaimDelayMs (default 5000) gives a GPU worker a head start. Installations outside Helm that run only CPU workers set CPU_CLAIM_DELAY_MS=0.
Editor-service and converter startup logs report the configured S3 public base URL and its configuration source. Check that the reported URL is reachable by the intended clients.
Editor super-admin role
A global administrator gives a user the super-admin role in the editor admin panel, in the Platform Roles section of the user’s page. If no account on your installation holds the global-admin role, contact Seatmap.pro support.
Editor-service ignores SEATMAP_FIRST_RUN_SUPER_ADMIN, and the Helm chart no longer has editor.config.seatmap.firstRun.superAdmin; the chart sets the variable to an empty value. Installations outside Helm that may start an earlier editor-service image set it to an empty value too. Existing super-admin assignments are unchanged. After the upgrade, review which accounts show Super Admin in the Roles column of the admin panel’s Users list, and remove the role from accounts that should not hold it.
Autologin accounts
Autologin accepts organization accounts only. An account with the super-admin or global-admin role gets HTTP 403 and must sign in to the Editor with its own password. An integration that autologins as such an account needs a regular organization account instead.
Saved charts and rollback
Review sections that follow venue shapes before saving: corner spacing, row-label placement, and rounded outlines are recomputed by the new editor. Existing booking SVGs keep their saved geometry until another save. Row label fonts are part of each chart’s stored booking background, so a chart shows the new fonts after its next save; Reset Images on an organization’s Generated Images tab in the Admin Panel regenerates the backgrounds of all its charts. Title-size persistence uses the existing section-properties JSON and needs no additional migration.
Keep a tested backup and the previous deployment artifacts. Do not remove the RSA Secret during rollback. The migrations add fields and indexes and update some existing rows, but that alone does not establish application rollback compatibility: older editors do not understand the new library snapshot and polygon corner formats. Retain pre-upgrade chart exports if those layouts must remain usable by an older editor.