feat(yucca): multi-site placement and public /meta (#381)

This commit is contained in:
Antoine Lecompte
2026-07-30 08:29:29 -04:00
committed by GitHub
parent 046aacb6b1
commit 5a73550573
74 changed files with 1935 additions and 111 deletions
@@ -9,4 +9,9 @@
(dict "name" "POSTGRES_PASSWORD" "valueFrom" (dict "secretKeyRef" (dict "name" (printf "%s-app" .Values.postgresClusterName) "key" "password")))
)) }}
{{- $_ := set .Values "envFrom" (list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .)))) }}
{{- $topology := (lookup "v1" "ConfigMap" .Release.Namespace "yucca-topology") | default dict }}
{{- $topologyData := (get $topology "data") | default dict }}
{{- $_ := set .Values "podAnnotations" (merge
(dict "yucca.futo.org/topology-checksum" (sha256sum (toJson $topologyData)))
(.Values.podAnnotations | default dict)) }}
{{- include "yucca-common.deployment" . }}
+19 -2
View File
@@ -20,6 +20,17 @@ ports:
service:
type: ClusterIP
# The GitOps-owned topology document (sites + storage clusters), validated and
# hot-reloaded on access. Same ConfigMap and mount as yucca-api.
volumes:
- name: topology
configMap:
name: yucca-topology
volumeMounts:
- name: topology
mountPath: /etc/yucca
readOnly: true
# CNPG-managed postgres Cluster name (shares yucca-api's database)
postgresClusterName: yucca-db
@@ -56,8 +67,14 @@ env:
value: debug
- name: OIDC_ADMIN_ALLOW_INSECURE
value: "true"
- name: RESTIC_ENDPOINT
value: http://yucca-michael:3010
# Fleet topology — replaces the old single RESTIC_ENDPOINT: the restic
# gateway is now a per-site field in this file (rest_url), not one global URL.
- name: TOPOLOGY_FILE
value: /etc/yucca/topology.json
- name: LEGACY_SITE_CODE
value: local
- name: LEGACY_STORAGE_CLUSTER_CODE
value: local-dev
- name: OTEL_METRICS
value: http://victoria-metrics:8428/opentelemetry/v1/metrics
- name: OTEL_LOGGING
@@ -13,4 +13,9 @@ takes the LAST envFrom source, so these act as overrides. */}}
{{- $_ := set .Values "envFrom" (concat
(list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .))))
(.Values.extraEnvFrom | default (list))) }}
{{- $topology := (lookup "v1" "ConfigMap" .Release.Namespace "yucca-topology") | default dict }}
{{- $topologyData := (get $topology "data") | default dict }}
{{- $_ := set .Values "podAnnotations" (merge
(dict "yucca.futo.org/topology-checksum" (sha256sum (toJson $topologyData)))
(.Values.podAnnotations | default dict)) }}
{{- include "yucca-common.deployment" . }}
+22 -2
View File
@@ -25,6 +25,20 @@ ports:
service:
type: ClusterIP
# The GitOps-owned topology document (sites + storage clusters), validated and
# hot-reloaded on access — see TOPOLOGY_FILE below. Rendered per cluster by
# kubernetes/apps/base/topology; dev/k3d gets the literal copy from
# kubernetes/apps/dev/local/yucca/topology. Same mount in yucca-admin-api and
# yucca-metrics-worker.
volumes:
- name: topology
configMap:
name: yucca-topology
volumeMounts:
- name: topology
mountPath: /etc/yucca
readOnly: true
# CNPG-managed postgres Cluster name (see umbrella chart)
postgresClusterName: yucca-db
@@ -78,8 +92,14 @@ env:
value: "device client ID"
- name: OIDC_DEVICE_ALLOW_INSECURE
value: "true"
- name: RESTIC_ENDPOINT
value: http://yucca-michael:3010
# Fleet topology — replaces the old single RESTIC_ENDPOINT: the restic
# gateway is now a per-site field in this file (rest_url), not one global URL.
- name: TOPOLOGY_FILE
value: /etc/yucca/topology.json
- name: LEGACY_SITE_CODE
value: local
- name: LEGACY_STORAGE_CLUSTER_CODE
value: local-dev
# mock-oidc issues <sub>@example.test for any sub, so dev logins pass the
# beta email allowlist.
- name: ALLOWED_EMAIL_DOMAINS
@@ -1,5 +1,5 @@
{{- $_ := set .Values "env" (concat .Values.env (list
(dict "name" "RADOS_ENDPOINT" "value" .Values.radosEndpoint)
(dict "name" "TOPOLOGY_FILE" "value" "/etc/yucca/topology.json")
(dict "name" "RADOS_ACCESS_KEY_ID" "valueFrom" (dict "secretKeyRef" (dict "name" .Values.radosSecretName "key" "AccessKey")))
(dict "name" "RADOS_SECRET_ACCESS_KEY" "valueFrom" (dict "secretKeyRef" (dict "name" .Values.radosSecretName "key" "SecretKey")))
(dict "name" "POSTGRES_HOST" "valueFrom" (dict "secretKeyRef" (dict "name" (printf "%s-app" .Values.postgresClusterName) "key" "host")))
@@ -14,6 +14,13 @@ the worker needs is explicit env above — deployments that null secretData
(staging/prod) provide no Secret at all, and Optional=false would wedge the
pod in CreateContainerConfigError. */}}
{{- $_ := set .Values "envFrom" (concat
(list (dict "secretRef" (dict "name" (include "yucca-common.fullname" .) "optional" true)))
(list
(dict "secretRef" (dict "name" (include "yucca-common.fullname" .) "optional" true))
(dict "secretRef" (dict "name" .Values.radosSecretName)))
(.Values.extraEnvFrom | default (list))) }}
{{- $topology := (lookup "v1" "ConfigMap" .Release.Namespace "yucca-topology") | default dict }}
{{- $topologyData := (get $topology "data") | default dict }}
{{- $_ := set .Values "podAnnotations" (merge
(dict "yucca.futo.org/topology-checksum" (sha256sum (toJson $topologyData)))
(.Values.podAnnotations | default dict)) }}
{{- include "yucca-common.deployment" . }}
+21 -5
View File
@@ -22,13 +22,25 @@ ports:
# CNPG-managed postgres Cluster name (shares yucca-api's database)
postgresClusterName: yucca-db
# Rook-Ceph RGW endpoint + the object-user Secret holding AccessKey/SecretKey.
# A dedicated RGW user (charts/ceph-objectuser via the yucca-metrics-object-user
# release) with admin read caps, so the worker can pull per-bucket stats from the
# RGW admin API — michael is a plain S3 user without those caps.
radosEndpoint: http://rook-ceph-rgw-yucca.rook-ceph.svc:80
# RGW admin endpoints come from the hot-reloaded topology file (ConfigMap
# yucca-topology, rgw_admin_endpoint per storage cluster). The object-user Secret holds the
# fallback AccessKey/SecretKey pair — a dedicated RGW user (charts/ceph-objectuser
# via the yucca-metrics-object-user release) with admin read caps, so the worker
# can pull per-bucket stats from the RGW admin API — michael is a plain S3 user
# without those caps. Per-cluster creds override via
# RADOS_ACCESS_KEY_ID_<CODE>/RADOS_SECRET_ACCESS_KEY_<CODE> keys in that same
# Secret (envFrom exposes them under those exact names).
radosSecretName: rook-ceph-object-user-yucca-metrics
volumes:
- name: topology
configMap:
name: yucca-topology
volumeMounts:
- name: topology
mountPath: /etc/yucca
readOnly: true
# Static dev secrets (overridden in dev via the yucca-dev-env extraEnvFrom
# layer, in prod via ExternalSecret)
secretData:
@@ -42,6 +54,10 @@ extraEnvFrom: []
env:
- name: NODE_ENV
value: development
- name: LEGACY_SITE_CODE
value: local
- name: LEGACY_STORAGE_CLUSTER_CODE
value: local-dev
- name: YUCCA_METRICS_WORKER_PORT
value: "3040"
- name: LOG_LEVEL