Files
yucca/charts/apps/yucca-api/values.yaml
T
Antoine Lecompte c6985d902c feat(all): introduce partition/region/ceph-cluster model across the stack (#222)
* feat: introduce partition/region/ceph-cluster model across the stack

Formalize partition -> region -> {one k8s cluster, many ceph clusters} and
thread it through every layer plus a new yuctl ops CLI.

- tf: deployment/<partition>/<region>/<stack> layout; terragrunt path-parse +
  state key yucca/<partition>/<region>/<stack>; per-region region.hcl (role,
  site_id, datacenter, provider_code, domain); env->partition / site->region
  renames (NetBird object names byte-identical); standardized per-stack
  `discovery` output contract (secrets as op:// refs).
- k8s: clusters/<partition>/<region>/ (staging/austin, prod/htz-fsn1, dev/local);
  role-based kustomize components (primary/secondary); hybrid cluster-settings
  (TF-rendered identity + human fragment); dev-mirror folded into dev/local;
  charts regrouped into charts/{apps,platform,lib,dev}.
- ci: infra.yml partition/region discovery matrix; partition-keyed path filters;
  <partition>-<region> environment gates; image-versions path moves.
- ansible: inventories under <partition>-<region>/<cluster>.
- yuctl: Go/cobra CLI reading the discovery contract from TF state.
- Retire the sietch-talos libvirt VM cluster (dev@local is the k3d cluster);
  ceph inventory_dirname -> <partition>-<region>/<cluster>.

Verified: mise k8s:validate green (3 clusters); yuctl go build/vet; tofu
validate pre-merge (all 9 stacks). Live-staging state migration NOT run.

* fix typo

* commit
2026-06-29 08:40:29 -04:00

88 lines
2.9 KiB
YAML

replicas: 1
# Stable in-cluster name, independent of the Helm release name. This keeps
# service DNS identical whether rendered by Tilt (dev) or Flux (prod, per-app
# release names).
fullnameOverride: yucca-api
image:
repository: k3d-registry.localhost:5000/yucca-api
tag: dev
pullPolicy: IfNotPresent
ports:
- name: http
containerPort: 3020
service:
type: ClusterIP
# CNPG-managed postgres Cluster name (see umbrella chart)
postgresClusterName: yucca-db
# OIDC provider in-cluster service
oidcIssuer: http://yucca-mock-oidc:8092
oidcRedirectUri: http://localhost:5173/api/auth/oidc/callback
oidcLogoutRedirectUri: http://localhost:5173
# DEV FIXTURES — not secrets. This is the project's well-known local-dev
# keypair (the same one committed in .mise/tasks/*/env); yucca-api signs
# device/restic JWTs with it and michael verifies with the matching public key.
# It must never protect anything real. Prod replaces this whole block with
# ExternalSecrets (1Password) — see kubernetes/README.md.
secretData:
JWT_PRIVATE_KEY: |
-----BEGIN PRIVATE KEY-----
MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgCla79+Sip4o2hZ1K
nQJYp2xU/nsCJmRoZmvXjeX6cW+hRANCAASkubBRIE7Sns/VS8ZF5XEVO8CwJ+AZ
Ls1C0ncCcmRhqKA7UxLknn0ji5FcKaku1zBOhxQYcxFVmsYtAxZ1ljgN
-----END PRIVATE KEY-----
OIDC_CLIENT_ID: "client ID"
OIDC_CLIENT_SECRET: "client secret"
# Extra envFrom sources appended AFTER the chart's own secret — for duplicate
# keys the last source wins, so this is the override hook. Tilt points it at
# the yucca-dev-env Secret (built from a gitignored root .env, op:// refs
# resolved via the 1Password CLI); prod can point it at an ExternalSecret.
# NB: explicit `env` entries below always beat envFrom — env vars the chart
# pins there (OIDC_ISSUER & co) are overridden via their Helm values instead.
extraEnvFrom: []
env:
- name: NODE_ENV
value: development
- name: YUCCA_API_PORT
value: "3020"
- name: LOG_LEVEL
value: debug
- name: OIDC_ALLOW_INSECURE
value: "true"
# Device-flow OIDC (required by yucca-api env schema; points at mock-oidc's
# registered device client).
- name: OIDC_DEVICE_ISSUER
value: http://yucca-mock-oidc:8092
- name: OIDC_DEVICE_CLIENT_ID
value: "device client ID"
- name: OIDC_DEVICE_ALLOW_INSECURE
value: "true"
- name: RESTIC_ENDPOINT
value: http://yucca-michael:3010
- name: OTEL_METRICS
value: http://victoria-metrics:8428/opentelemetry/v1/metrics
- name: OTEL_LOGGING
value: http://victoria-logs:9428/insert/opentelemetry/v1/logs
# Probes keep `tilt ci`/Flux honest: without them a crash-looping dev process
# still counts as Ready (this masked two real bugs). The startupProbe budgets
# for the dev watcher's first boot; no livenessProbe so dev never restart-loops.
startupProbe:
tcpSocket: { port: http }
periodSeconds: 5
failureThreshold: 60
readinessProbe:
tcpSocket: { port: http }
periodSeconds: 10
migration:
enabled: false