mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
38 lines
1.6 KiB
YAML
38 lines
1.6 KiB
YAML
---
|
|
# TF-RENDERED — do not hand-edit (hand-maintained until the talos stack renders
|
|
# it; values match what TF would derive). Keys are DISJOINT from the human
|
|
# cluster-settings + CI image-versions ConfigMaps.
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: cluster-settings-generated
|
|
namespace: flux-system
|
|
data:
|
|
# Cluster identity (derived: yucca_<partition>_<region>).
|
|
CLUSTER_NAME: yucca_prod_htz_fsn1
|
|
CLUSTER_ROLE: primary
|
|
# Telemetry identity tags (cluster = short cluster name; site; env). The
|
|
# netops vmagent stamps its own set (cluster=netops, spice jobs cluster=spice).
|
|
METRICS_CLUSTER_LABEL: father
|
|
METRICS_SITE_LABEL: htz-fsn1
|
|
METRICS_ENV_LABEL: prod
|
|
|
|
# Per-service ingress hostnames. web (apex; /api routes to yucca-api) on the
|
|
# app gateway; rest.htz-fsn1. (michael, restic) on the dedicated gw-proxy
|
|
# gateway (own cert — outside the *.APP_DOMAIN wildcard).
|
|
APP_DOMAIN: backups.futo.cloud
|
|
GW_HOST: rest.htz-fsn1.backups.futo.cloud
|
|
|
|
# Spice RGW (Ceph S3): round-robin DNS across all 48 nodes' fabric VLAN-120
|
|
# IPs (prod/global/dns), reached over the FABRIC — the spine routes
|
|
# kube↔cls1-public (fabric stack public_routing). Self-signed cert, so
|
|
# consumers skip TLS verify. S3_HOST is the schemeless form for michael's
|
|
# DNS-based backend LB (S3_BACKEND_DNS_HOST).
|
|
S3_ENDPOINT: https://s3.prod.fsn1.htz.futo.cloud
|
|
S3_HOST: s3.prod.fsn1.htz.futo.cloud
|
|
|
|
# Observability egress (apps -> agents -> o11y's MESH vmauth over NetBird,
|
|
# unauthenticated; see apps/prod/htz-fsn1/observability).
|
|
VMAGENT_OTLP: vmagent-yucca.observability.svc:8429
|
|
VLOGS_REMOTE_URL: https://vmauth.o11y.futo.network/insert/native
|