mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
90 lines
2.9 KiB
YAML
90 lines
2.9 KiB
YAML
replicas: 1
|
|
|
|
# Stable in-cluster name, independent of the Helm release name. This keeps
|
|
# service DNS identical whether rendered by Tilt (dev) or Flux (prod, per-app
|
|
# release names).
|
|
fullnameOverride: yucca-api
|
|
|
|
image:
|
|
repository: k3d-registry.localhost:5000/yucca-api
|
|
tag: dev
|
|
pullPolicy: IfNotPresent
|
|
|
|
ports:
|
|
- name: http
|
|
containerPort: 3020
|
|
|
|
service:
|
|
type: ClusterIP
|
|
|
|
# CNPG-managed postgres Cluster name (see umbrella chart)
|
|
postgresClusterName: yucca-db
|
|
|
|
# OIDC provider in-cluster service
|
|
oidcIssuer: http://yucca-mock-oidc:8092
|
|
oidcRedirectUri: http://localhost:5173/api/auth/oidc/callback
|
|
oidcLogoutRedirectUri: http://localhost:5173
|
|
|
|
# DEV FIXTURES — not secrets. This is the project's well-known local-dev
|
|
# keypair (the same one committed in .mise/tasks/*/env); yucca-api signs
|
|
# device/restic JWTs with it and michael verifies with the matching public key.
|
|
# It must never protect anything real. Prod replaces this whole block with
|
|
# ExternalSecrets (1Password) — see kubernetes/README.md.
|
|
secretData:
|
|
JWT_PRIVATE_KEY: |
|
|
-----BEGIN PRIVATE KEY-----
|
|
MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgCla79+Sip4o2hZ1K
|
|
nQJYp2xU/nsCJmRoZmvXjeX6cW+hRANCAASkubBRIE7Sns/VS8ZF5XEVO8CwJ+AZ
|
|
Ls1C0ncCcmRhqKA7UxLknn0ji5FcKaku1zBOhxQYcxFVmsYtAxZ1ljgN
|
|
-----END PRIVATE KEY-----
|
|
OIDC_CLIENT_ID: "client ID"
|
|
OIDC_CLIENT_SECRET: "client secret"
|
|
|
|
# Extra envFrom sources appended AFTER the chart's own secret — for duplicate
|
|
# keys the last source wins, so this is the override hook. Tilt points it at
|
|
# the yucca-dev-env Secret (built from a gitignored root .env, op:// refs
|
|
# resolved via the 1Password CLI); prod can point it at an ExternalSecret.
|
|
# NB: explicit `env` entries below always beat envFrom — env vars the chart
|
|
# pins there (OIDC_ISSUER & co) are overridden via their Helm values instead.
|
|
extraEnvFrom: []
|
|
|
|
env:
|
|
- name: NODE_ENV
|
|
value: development
|
|
- name: YUCCA_API_PORT
|
|
value: "3020"
|
|
- name: LOG_LEVEL
|
|
value: debug
|
|
- name: OIDC_ALLOW_INSECURE
|
|
value: "true"
|
|
# Device-flow OIDC (required by yucca-api env schema; points at mock-oidc's
|
|
# registered device client).
|
|
- name: OIDC_DEVICE_ISSUER
|
|
value: http://yucca-mock-oidc:8092
|
|
- name: OIDC_DEVICE_CLIENT_ID
|
|
value: "device client ID"
|
|
- name: OIDC_DEVICE_ALLOW_INSECURE
|
|
value: "true"
|
|
- name: RESTIC_API_HOST
|
|
value: yucca-michael
|
|
- name: RESTIC_API_PORT
|
|
value: "3010"
|
|
- name: OTEL_METRICS
|
|
value: http://victoria-metrics:8428/opentelemetry/v1/metrics
|
|
- name: OTEL_LOGGING
|
|
value: http://victoria-logs:9428/insert/opentelemetry/v1/logs
|
|
|
|
# Probes keep `tilt ci`/Flux honest: without them a crash-looping dev process
|
|
# still counts as Ready (this masked two real bugs). The startupProbe budgets
|
|
# for the dev watcher's first boot; no livenessProbe so dev never restart-loops.
|
|
startupProbe:
|
|
tcpSocket: { port: http }
|
|
periodSeconds: 5
|
|
failureThreshold: 60
|
|
readinessProbe:
|
|
tcpSocket: { port: http }
|
|
periodSeconds: 10
|
|
|
|
migration:
|
|
enabled: false
|