mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
* feat: introduce partition/region/ceph-cluster model across the stack
Formalize partition -> region -> {one k8s cluster, many ceph clusters} and
thread it through every layer plus a new yuctl ops CLI.
- tf: deployment/<partition>/<region>/<stack> layout; terragrunt path-parse +
state key yucca/<partition>/<region>/<stack>; per-region region.hcl (role,
site_id, datacenter, provider_code, domain); env->partition / site->region
renames (NetBird object names byte-identical); standardized per-stack
`discovery` output contract (secrets as op:// refs).
- k8s: clusters/<partition>/<region>/ (staging/austin, prod/htz-fsn1, dev/local);
role-based kustomize components (primary/secondary); hybrid cluster-settings
(TF-rendered identity + human fragment); dev-mirror folded into dev/local;
charts regrouped into charts/{apps,platform,lib,dev}.
- ci: infra.yml partition/region discovery matrix; partition-keyed path filters;
<partition>-<region> environment gates; image-versions path moves.
- ansible: inventories under <partition>-<region>/<cluster>.
- yuctl: Go/cobra CLI reading the discovery contract from TF state.
- Retire the sietch-talos libvirt VM cluster (dev@local is the k3d cluster);
ceph inventory_dirname -> <partition>-<region>/<cluster>.
Verified: mise k8s:validate green (3 clusters); yuctl go build/vet; tofu
validate pre-merge (all 9 stacks). Live-staging state migration NOT run.
* fix typo
* commit
88 lines
2.9 KiB
YAML
88 lines
2.9 KiB
YAML
replicas: 1
|
|
|
|
# Stable in-cluster name, independent of the Helm release name. This keeps
|
|
# service DNS identical whether rendered by Tilt (dev) or Flux (prod, per-app
|
|
# release names).
|
|
fullnameOverride: yucca-api
|
|
|
|
image:
|
|
repository: k3d-registry.localhost:5000/yucca-api
|
|
tag: dev
|
|
pullPolicy: IfNotPresent
|
|
|
|
ports:
|
|
- name: http
|
|
containerPort: 3020
|
|
|
|
service:
|
|
type: ClusterIP
|
|
|
|
# CNPG-managed postgres Cluster name (see umbrella chart)
|
|
postgresClusterName: yucca-db
|
|
|
|
# OIDC provider in-cluster service
|
|
oidcIssuer: http://yucca-mock-oidc:8092
|
|
oidcRedirectUri: http://localhost:5173/api/auth/oidc/callback
|
|
oidcLogoutRedirectUri: http://localhost:5173
|
|
|
|
# DEV FIXTURES — not secrets. This is the project's well-known local-dev
|
|
# keypair (the same one committed in .mise/tasks/*/env); yucca-api signs
|
|
# device/restic JWTs with it and michael verifies with the matching public key.
|
|
# It must never protect anything real. Prod replaces this whole block with
|
|
# ExternalSecrets (1Password) — see kubernetes/README.md.
|
|
secretData:
|
|
JWT_PRIVATE_KEY: |
|
|
-----BEGIN PRIVATE KEY-----
|
|
MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgCla79+Sip4o2hZ1K
|
|
nQJYp2xU/nsCJmRoZmvXjeX6cW+hRANCAASkubBRIE7Sns/VS8ZF5XEVO8CwJ+AZ
|
|
Ls1C0ncCcmRhqKA7UxLknn0ji5FcKaku1zBOhxQYcxFVmsYtAxZ1ljgN
|
|
-----END PRIVATE KEY-----
|
|
OIDC_CLIENT_ID: "client ID"
|
|
OIDC_CLIENT_SECRET: "client secret"
|
|
|
|
# Extra envFrom sources appended AFTER the chart's own secret — for duplicate
|
|
# keys the last source wins, so this is the override hook. Tilt points it at
|
|
# the yucca-dev-env Secret (built from a gitignored root .env, op:// refs
|
|
# resolved via the 1Password CLI); prod can point it at an ExternalSecret.
|
|
# NB: explicit `env` entries below always beat envFrom — env vars the chart
|
|
# pins there (OIDC_ISSUER & co) are overridden via their Helm values instead.
|
|
extraEnvFrom: []
|
|
|
|
env:
|
|
- name: NODE_ENV
|
|
value: development
|
|
- name: YUCCA_API_PORT
|
|
value: "3020"
|
|
- name: LOG_LEVEL
|
|
value: debug
|
|
- name: OIDC_ALLOW_INSECURE
|
|
value: "true"
|
|
# Device-flow OIDC (required by yucca-api env schema; points at mock-oidc's
|
|
# registered device client).
|
|
- name: OIDC_DEVICE_ISSUER
|
|
value: http://yucca-mock-oidc:8092
|
|
- name: OIDC_DEVICE_CLIENT_ID
|
|
value: "device client ID"
|
|
- name: OIDC_DEVICE_ALLOW_INSECURE
|
|
value: "true"
|
|
- name: RESTIC_ENDPOINT
|
|
value: http://yucca-michael:3010
|
|
- name: OTEL_METRICS
|
|
value: http://victoria-metrics:8428/opentelemetry/v1/metrics
|
|
- name: OTEL_LOGGING
|
|
value: http://victoria-logs:9428/insert/opentelemetry/v1/logs
|
|
|
|
# Probes keep `tilt ci`/Flux honest: without them a crash-looping dev process
|
|
# still counts as Ready (this masked two real bugs). The startupProbe budgets
|
|
# for the dev watcher's first boot; no livenessProbe so dev never restart-loops.
|
|
startupProbe:
|
|
tcpSocket: { port: http }
|
|
periodSeconds: 5
|
|
failureThreshold: 60
|
|
readinessProbe:
|
|
tcpSocket: { port: http }
|
|
periodSeconds: 10
|
|
|
|
migration:
|
|
enabled: false
|