Files
yucca/kubernetes/apps/base/yucca-api/helmrelease.yaml
T

59 lines
2.1 KiB
YAML

---
# yaml-language-server: $schema=https://k8s-schemas.home-operations.com/helm.toolkit.fluxcd.io/helmrelease_v2.json
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: yucca-api
spec:
interval: 1h
chart:
spec:
chart: charts/yucca-api
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
install:
remediation:
retries: 3
upgrade:
cleanupOnFail: true
remediation:
retries: 3
values:
image:
repository: ghcr.io/immich-app/yucca/yucca-api
# Substituted by Flux postBuild from the image-versions ConfigMap (CI-bumped).
tag: ${YUCCA_IMAGE_TAG}
# Migration Job assumes the dev image layout; dist-only prod image migrates
# at boot. Re-enable once the Job has a prod-compatible command.
migration:
enabled: false
# secretData nulled: the chart's dev fixture (JWT + OIDC placeholders) is
# replaced by the TF-provisioned `yucca-api` Secret (JWT_PRIVATE_KEY +
# OIDC_CLIENT_ID/SECRET), picked up via the chart's envFrom: secretRef.
secretData: null
# Real IdP (no mock-oidc). Chart maps these onto explicit env (which beats
# envFrom). Redirects target the staging ingress domain.
# TODO(ingress): confirm callback host once envoy-gateway + DNS land.
oidcIssuer: ${OIDC_ISSUER}
oidcRedirectUri: https://${APP_DOMAIN}/api/auth/oidc/callback
oidcLogoutRedirectUri: https://${APP_DOMAIN}
# Full replacement of the chart's dev env: production mode, no
# *_ALLOW_INSECURE (real HTTPS issuer), OTLP to the in-cluster agents.
env:
- name: NODE_ENV
value: production
- name: YUCCA_API_PORT
value: "3020"
- name: LOG_LEVEL
value: info
# OIDC_DEVICE_CLIENT_ID comes from the yucca-api Secret (envFrom) — a
# numeric id via postBuild substitution gets coerced to a float and breaks.
- name: OIDC_DEVICE_ISSUER
value: ${OIDC_ISSUER}
- name: RESTIC_ENDPOINT
value: https://${GW_HOST}
- name: OTEL_METRICS
value: http://${VMAGENT_OTLP}/opentelemetry/v1/metrics