mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
* feat: introduce partition/region/ceph-cluster model across the stack
Formalize partition -> region -> {one k8s cluster, many ceph clusters} and
thread it through every layer plus a new yuctl ops CLI.
- tf: deployment/<partition>/<region>/<stack> layout; terragrunt path-parse +
state key yucca/<partition>/<region>/<stack>; per-region region.hcl (role,
site_id, datacenter, provider_code, domain); env->partition / site->region
renames (NetBird object names byte-identical); standardized per-stack
`discovery` output contract (secrets as op:// refs).
- k8s: clusters/<partition>/<region>/ (staging/austin, prod/htz-fsn1, dev/local);
role-based kustomize components (primary/secondary); hybrid cluster-settings
(TF-rendered identity + human fragment); dev-mirror folded into dev/local;
charts regrouped into charts/{apps,platform,lib,dev}.
- ci: infra.yml partition/region discovery matrix; partition-keyed path filters;
<partition>-<region> environment gates; image-versions path moves.
- ansible: inventories under <partition>-<region>/<cluster>.
- yuctl: Go/cobra CLI reading the discovery contract from TF state.
- Retire the sietch-talos libvirt VM cluster (dev@local is the k3d cluster);
ceph inventory_dirname -> <partition>-<region>/<cluster>.
Verified: mise k8s:validate green (3 clusters); yuctl go build/vet; tofu
validate pre-merge (all 9 stacks). Live-staging state migration NOT run.
* fix typo
* commit
14 lines
675 B
YAML
14 lines
675 B
YAML
# RGW user for michael. Rook writes a Secret named
|
|
# "rook-ceph-object-user-<store>-<userName>" into THIS namespace with keys
|
|
# AccessKey / SecretKey. michael (charts/michael) consumes them.
|
|
userName: michael
|
|
# CephObjectStore name + the namespace where the Rook cluster/objectstore lives.
|
|
store: yucca
|
|
clusterNamespace: rook-ceph
|
|
|
|
# RGW admin capabilities (radosgw-admin caps). Empty = a plain S3 user that can
|
|
# only manage its own buckets (michael's case). Grant read caps to a user that
|
|
# needs the RGW admin API — e.g. the metrics worker reading per-bucket usage.
|
|
# See https://rook.io/docs/rook/latest/CRDs/Object-Storage/ceph-object-store-user-crd/
|
|
capabilities: {}
|