Files
yucca/kubernetes/apps/base/yucca-admin-api/helmrelease.yaml
T

76 lines
3.0 KiB
YAML

---
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/helm.toolkit.fluxcd.io/helmrelease_v2.json
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: yucca-admin-api
spec:
interval: 1h
chart:
spec:
chart: charts/apps/yucca-admin-api
# Repackage on every git revision — the in-repo charts keep a static
# version, so the default ChartVersion strategy never ships template edits.
reconcileStrategy: Revision
sourceRef:
kind: GitRepository
name: ${CHART_SOURCE:=flux-system}
namespace: flux-system
install:
remediation:
retries: 3
upgrade:
cleanupOnFail: true
remediation:
retries: 3
values:
image:
repository: ghcr.io/immich-app/yucca/yucca-admin-api
# Substituted from the image-versions ConfigMap: staging's is rewritten
# in-cluster to the latest CI build (flux-operator ResourceSet), prod's is
# release-please-stamped in git. If unset, the empty default lets the
# chart fall back to v<appVersion> — the matching release image.
tag: ${YUCCA_IMAGE_TAG:=}
# secretData nulled: replaced by the TF-provisioned `yucca-admin-api` Secret
# (OIDC_ADMIN_CLIENT_ID/SECRET) via the chart's envFrom: secretRef.
secretData: null
# Not publicly routed — reached over the NetBird overlay at
# ${YUCCA_ADMIN_HOST} (per-cluster, from cluster-settings). Admin auth uses
# the internal FUTO Zitadel (FUTO_ZITADEL_OAUTH_*_YUCCA_INTERNAL_TOOLING in
# shared_tf), not the customer ${OIDC_ISSUER}.
oidcIssuer: https://auth.internal.futo.org
oidcRedirectUri: https://${YUCCA_ADMIN_HOST}/api/auth/oidc/callback
oidcLogoutRedirectUri: https://${YUCCA_ADMIN_HOST}
env:
- name: NODE_ENV
value: production
- name: YUCCA_ADMIN_API_PORT
value: "3030"
- name: LOG_LEVEL
value: info
# Fleet topology (the yucca-topology ConfigMap the chart mounts at
# /etc/yucca) — the per-site rest_url in it replaces the old single
# RESTIC_ENDPOINT.
- name: TOPOLOGY_FILE
value: /etc/yucca/topology.json
# Pinned origin of rows created before placement columns existed.
- name: LEGACY_SITE_CODE
value: ${LEGACY_SITE_CODE}
- name: LEGACY_STORAGE_CLUSTER_CODE
value: ${LEGACY_STORAGE_CLUSTER_CODE}
- name: OTEL_METRICS
value: http://${VMAGENT_OTLP}/opentelemetry/v1/metrics
# Invite emails: real Postmark (the API URL default), token from the
# TF-provisioned Secret above; links point at the public web app.
- name: WEB_BASE_URL
value: https://${APP_DOMAIN}
# Eager invite-drop closure (yuctl invites cancel); the shared
# INTERNAL_SECRET arrives via the TF-provisioned Secret.
- name: FUTO_BACKUPS_BOT_URL
value: http://futo-backups-bot:3050
# Ad-hoc investigations (yuctl columbo investigate), same shared secret.
- name: COLUMBO_URL
value: http://columbo:3060
- name: EMAIL_FROM_ADDRESS
value: ${EMAIL_FROM_ADDRESS}