mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 21:37:50 +08:00
121 lines
4.1 KiB
YAML
121 lines
4.1 KiB
YAML
# 2 replicas + a PDB (templates/pdb.yaml): michael is the production restic
|
|
# gateway — a single replica turns every node drain into interrupted backups.
|
|
# Stateless S3 proxy, safe to run N-way.
|
|
replicas: 2
|
|
|
|
# Generous requests, deliberately huge memory limits (never CPU-limit).
|
|
resources:
|
|
requests: { cpu: 250m, memory: 256Mi }
|
|
limits: { memory: 4Gi }
|
|
|
|
# Stable in-cluster name, independent of the Helm release name (dev == prod).
|
|
fullnameOverride: yucca-michael
|
|
|
|
image:
|
|
repository: k3d-registry.localhost:5000/michael
|
|
tag: dev
|
|
pullPolicy: IfNotPresent
|
|
|
|
ports:
|
|
- name: http
|
|
containerPort: 3010
|
|
|
|
service:
|
|
type: ClusterIP
|
|
|
|
# Michael reads the same topology as the API. Every declared storage cluster
|
|
# is therefore routable before the API can mint a token for it.
|
|
volumes:
|
|
- name: topology
|
|
configMap:
|
|
name: yucca-topology
|
|
volumeMounts:
|
|
- name: topology
|
|
mountPath: /etc/yucca
|
|
readOnly: true
|
|
|
|
# OPT-IN dev verification key — the public half of the project's well-known
|
|
# local-dev keypair (see charts/yucca-api/values.yaml + .mise/tasks/*/env).
|
|
# Renders into the Secret ONLY when useDevKeypair is true (dev/local overlay).
|
|
# Default false: with no key provided the Secret doesn't render and the pod
|
|
# fails loudly, instead of silently trusting tokens anyone can mint with the
|
|
# committed private half. Prod provides the real key via ExternalSecret.
|
|
useDevKeypair: false
|
|
devJwtPublicKey: |
|
|
-----BEGIN PUBLIC KEY-----
|
|
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEpLmwUSBO0p7P1UvGReVxFTvAsCfg
|
|
GS7NQtJ3AnJkYaigO1MS5J59I4uRXCmpLtcwTocUGHMRVZrGLQMWdZY4DQ==
|
|
-----END PUBLIC KEY-----
|
|
|
|
env:
|
|
- name: RESTIC_API_PORT
|
|
value: "3010"
|
|
- name: LOG_LEVEL
|
|
value: debug
|
|
# S3 object store = Rook-Ceph RGW. michael creates one bucket per restic
|
|
# repository, so it needs a full RGW user (CephObjectStoreUser via
|
|
# charts/ceph-objectuser), NOT a bucket-scoped ObjectBucketClaim. Rook writes
|
|
# the user's keys into this namespace as rook-ceph-object-user-<store>-<user>.
|
|
# Must match the dev topology's cluster code (ConfigMap yucca-topology /
|
|
# topology.dev.json): yucca-api mints restic tokens with
|
|
# storageCluster=local-dev,
|
|
# and michael fails closed on cluster codes it does not front.
|
|
- name: S3_DEFAULT_CLUSTER
|
|
value: local-dev
|
|
- name: SITE_CODE
|
|
value: local
|
|
- name: S3_TOPOLOGY_FILE
|
|
value: /etc/yucca/topology.json
|
|
- name: S3_ENDPOINT
|
|
value: http://rook-ceph-rgw-yucca.rook-ceph.svc:80
|
|
- name: S3_ACCESS_KEY_ID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: rook-ceph-object-user-yucca-michael
|
|
key: AccessKey
|
|
- name: S3_SECRET_ACCESS_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: rook-ceph-object-user-yucca-michael
|
|
key: SecretKey
|
|
- name: S3_REGION
|
|
value: us-east-1
|
|
- name: S3_FORCE_PATH_STYLE
|
|
value: "true"
|
|
# Built-in S3 load balancing. Dev has a single RGW behind a ClusterIP, so the
|
|
# DNS source resolves to one backend (kube-proxy still spreads behind the
|
|
# VIP) — this exercises the pool/health-probe/per-backend-metrics path in
|
|
# dev. Plain HTTP to Rook RGW, which accepts any signing host, so no
|
|
# host-pinning or TLS skip is needed (unlike staging's bare-metal RGW).
|
|
- name: S3_BACKEND_SOURCE
|
|
value: dns
|
|
- name: S3_BACKEND_DNS_HOST
|
|
value: rook-ceph-rgw-yucca.rook-ceph.svc
|
|
# S3_BACKEND_SCHEME/PORT are intentionally omitted: michael derives them from
|
|
# S3_ENDPOINT (http -> 80), so a DNS source only needs the host configured.
|
|
- name: S3_PROBE_BUCKET
|
|
value: michael-rgw-healthcheck
|
|
- name: OTLP_METRICS_ENDPOINT
|
|
value: victoria-metrics:8428
|
|
- name: OTLP_METRICS_URL_PATH
|
|
value: /opentelemetry/v1/metrics
|
|
- name: OTLP_LOGS_ENDPOINT
|
|
value: victoria-logs:9428
|
|
- name: OTLP_LOGS_URL_PATH
|
|
value: /insert/opentelemetry/v1/logs
|
|
|
|
envFrom:
|
|
- secretRef:
|
|
name: yucca-michael
|
|
|
|
# Probes keep `tilt ci`/Flux honest: michael runs under air in dev, which keeps
|
|
# the container "Running" even when the binary fatals on boot. The TCP probe
|
|
# surfaces that as NotReady. No livenessProbe (air restarts are normal in dev).
|
|
startupProbe:
|
|
tcpSocket: { port: http }
|
|
periodSeconds: 2
|
|
failureThreshold: 90
|
|
readinessProbe:
|
|
tcpSocket: { port: http }
|
|
periodSeconds: 10
|