mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
feat(yucca): multi-site placement and public /meta (#381)
This commit is contained in:
@@ -9,4 +9,9 @@
|
||||
(dict "name" "POSTGRES_PASSWORD" "valueFrom" (dict "secretKeyRef" (dict "name" (printf "%s-app" .Values.postgresClusterName) "key" "password")))
|
||||
)) }}
|
||||
{{- $_ := set .Values "envFrom" (list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .)))) }}
|
||||
{{- $topology := (lookup "v1" "ConfigMap" .Release.Namespace "yucca-topology") | default dict }}
|
||||
{{- $topologyData := (get $topology "data") | default dict }}
|
||||
{{- $_ := set .Values "podAnnotations" (merge
|
||||
(dict "yucca.futo.org/topology-checksum" (sha256sum (toJson $topologyData)))
|
||||
(.Values.podAnnotations | default dict)) }}
|
||||
{{- include "yucca-common.deployment" . }}
|
||||
|
||||
@@ -20,6 +20,17 @@ ports:
|
||||
service:
|
||||
type: ClusterIP
|
||||
|
||||
# The GitOps-owned topology document (sites + storage clusters), validated and
|
||||
# hot-reloaded on access. Same ConfigMap and mount as yucca-api.
|
||||
volumes:
|
||||
- name: topology
|
||||
configMap:
|
||||
name: yucca-topology
|
||||
volumeMounts:
|
||||
- name: topology
|
||||
mountPath: /etc/yucca
|
||||
readOnly: true
|
||||
|
||||
# CNPG-managed postgres Cluster name (shares yucca-api's database)
|
||||
postgresClusterName: yucca-db
|
||||
|
||||
@@ -56,8 +67,14 @@ env:
|
||||
value: debug
|
||||
- name: OIDC_ADMIN_ALLOW_INSECURE
|
||||
value: "true"
|
||||
- name: RESTIC_ENDPOINT
|
||||
value: http://yucca-michael:3010
|
||||
# Fleet topology — replaces the old single RESTIC_ENDPOINT: the restic
|
||||
# gateway is now a per-site field in this file (rest_url), not one global URL.
|
||||
- name: TOPOLOGY_FILE
|
||||
value: /etc/yucca/topology.json
|
||||
- name: LEGACY_SITE_CODE
|
||||
value: local
|
||||
- name: LEGACY_STORAGE_CLUSTER_CODE
|
||||
value: local-dev
|
||||
- name: OTEL_METRICS
|
||||
value: http://victoria-metrics:8428/opentelemetry/v1/metrics
|
||||
- name: OTEL_LOGGING
|
||||
|
||||
@@ -13,4 +13,9 @@ takes the LAST envFrom source, so these act as overrides. */}}
|
||||
{{- $_ := set .Values "envFrom" (concat
|
||||
(list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .))))
|
||||
(.Values.extraEnvFrom | default (list))) }}
|
||||
{{- $topology := (lookup "v1" "ConfigMap" .Release.Namespace "yucca-topology") | default dict }}
|
||||
{{- $topologyData := (get $topology "data") | default dict }}
|
||||
{{- $_ := set .Values "podAnnotations" (merge
|
||||
(dict "yucca.futo.org/topology-checksum" (sha256sum (toJson $topologyData)))
|
||||
(.Values.podAnnotations | default dict)) }}
|
||||
{{- include "yucca-common.deployment" . }}
|
||||
|
||||
@@ -25,6 +25,20 @@ ports:
|
||||
service:
|
||||
type: ClusterIP
|
||||
|
||||
# The GitOps-owned topology document (sites + storage clusters), validated and
|
||||
# hot-reloaded on access — see TOPOLOGY_FILE below. Rendered per cluster by
|
||||
# kubernetes/apps/base/topology; dev/k3d gets the literal copy from
|
||||
# kubernetes/apps/dev/local/yucca/topology. Same mount in yucca-admin-api and
|
||||
# yucca-metrics-worker.
|
||||
volumes:
|
||||
- name: topology
|
||||
configMap:
|
||||
name: yucca-topology
|
||||
volumeMounts:
|
||||
- name: topology
|
||||
mountPath: /etc/yucca
|
||||
readOnly: true
|
||||
|
||||
# CNPG-managed postgres Cluster name (see umbrella chart)
|
||||
postgresClusterName: yucca-db
|
||||
|
||||
@@ -78,8 +92,14 @@ env:
|
||||
value: "device client ID"
|
||||
- name: OIDC_DEVICE_ALLOW_INSECURE
|
||||
value: "true"
|
||||
- name: RESTIC_ENDPOINT
|
||||
value: http://yucca-michael:3010
|
||||
# Fleet topology — replaces the old single RESTIC_ENDPOINT: the restic
|
||||
# gateway is now a per-site field in this file (rest_url), not one global URL.
|
||||
- name: TOPOLOGY_FILE
|
||||
value: /etc/yucca/topology.json
|
||||
- name: LEGACY_SITE_CODE
|
||||
value: local
|
||||
- name: LEGACY_STORAGE_CLUSTER_CODE
|
||||
value: local-dev
|
||||
# mock-oidc issues <sub>@example.test for any sub, so dev logins pass the
|
||||
# beta email allowlist.
|
||||
- name: ALLOWED_EMAIL_DOMAINS
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
{{- $_ := set .Values "env" (concat .Values.env (list
|
||||
(dict "name" "RADOS_ENDPOINT" "value" .Values.radosEndpoint)
|
||||
(dict "name" "TOPOLOGY_FILE" "value" "/etc/yucca/topology.json")
|
||||
(dict "name" "RADOS_ACCESS_KEY_ID" "valueFrom" (dict "secretKeyRef" (dict "name" .Values.radosSecretName "key" "AccessKey")))
|
||||
(dict "name" "RADOS_SECRET_ACCESS_KEY" "valueFrom" (dict "secretKeyRef" (dict "name" .Values.radosSecretName "key" "SecretKey")))
|
||||
(dict "name" "POSTGRES_HOST" "valueFrom" (dict "secretKeyRef" (dict "name" (printf "%s-app" .Values.postgresClusterName) "key" "host")))
|
||||
@@ -14,6 +14,13 @@ the worker needs is explicit env above — deployments that null secretData
|
||||
(staging/prod) provide no Secret at all, and Optional=false would wedge the
|
||||
pod in CreateContainerConfigError. */}}
|
||||
{{- $_ := set .Values "envFrom" (concat
|
||||
(list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .) "optional" true)))
|
||||
(list
|
||||
(dict "secretRef" (dict "name" (include "yucca-common.fullname" .) "optional" true))
|
||||
(dict "secretRef" (dict "name" .Values.radosSecretName)))
|
||||
(.Values.extraEnvFrom | default (list))) }}
|
||||
{{- $topology := (lookup "v1" "ConfigMap" .Release.Namespace "yucca-topology") | default dict }}
|
||||
{{- $topologyData := (get $topology "data") | default dict }}
|
||||
{{- $_ := set .Values "podAnnotations" (merge
|
||||
(dict "yucca.futo.org/topology-checksum" (sha256sum (toJson $topologyData)))
|
||||
(.Values.podAnnotations | default dict)) }}
|
||||
{{- include "yucca-common.deployment" . }}
|
||||
|
||||
@@ -22,13 +22,25 @@ ports:
|
||||
# CNPG-managed postgres Cluster name (shares yucca-api's database)
|
||||
postgresClusterName: yucca-db
|
||||
|
||||
# Rook-Ceph RGW endpoint + the object-user Secret holding AccessKey/SecretKey.
|
||||
# A dedicated RGW user (charts/ceph-objectuser via the yucca-metrics-object-user
|
||||
# release) with admin read caps, so the worker can pull per-bucket stats from the
|
||||
# RGW admin API — michael is a plain S3 user without those caps.
|
||||
radosEndpoint: http://rook-ceph-rgw-yucca.rook-ceph.svc:80
|
||||
# RGW admin endpoints come from the hot-reloaded topology file (ConfigMap
|
||||
# yucca-topology, rgw_admin_endpoint per storage cluster). The object-user Secret holds the
|
||||
# fallback AccessKey/SecretKey pair — a dedicated RGW user (charts/ceph-objectuser
|
||||
# via the yucca-metrics-object-user release) with admin read caps, so the worker
|
||||
# can pull per-bucket stats from the RGW admin API — michael is a plain S3 user
|
||||
# without those caps. Per-cluster creds override via
|
||||
# RADOS_ACCESS_KEY_ID_<CODE>/RADOS_SECRET_ACCESS_KEY_<CODE> keys in that same
|
||||
# Secret (envFrom exposes them under those exact names).
|
||||
radosSecretName: rook-ceph-object-user-yucca-metrics
|
||||
|
||||
volumes:
|
||||
- name: topology
|
||||
configMap:
|
||||
name: yucca-topology
|
||||
volumeMounts:
|
||||
- name: topology
|
||||
mountPath: /etc/yucca
|
||||
readOnly: true
|
||||
|
||||
# Static dev secrets (overridden in dev via the yucca-dev-env extraEnvFrom
|
||||
# layer, in prod via ExternalSecret)
|
||||
secretData:
|
||||
@@ -42,6 +54,10 @@ extraEnvFrom: []
|
||||
env:
|
||||
- name: NODE_ENV
|
||||
value: development
|
||||
- name: LEGACY_SITE_CODE
|
||||
value: local
|
||||
- name: LEGACY_STORAGE_CLUSTER_CODE
|
||||
value: local-dev
|
||||
- name: YUCCA_METRICS_WORKER_PORT
|
||||
value: "3040"
|
||||
- name: LOG_LEVEL
|
||||
|
||||
Reference in New Issue
Block a user