From edcef7541805c448af19ca3fe6ae7a17f63ecbb7 Mon Sep 17 00:00:00 2001 From: AI-Agent Date: Mon, 1 Jun 2026 00:04:31 +0000 Subject: [PATCH] docs: add VIN Decoder namespace steps to operator runbook Adds a dedicated Phase 4-A section to docs/operator-runbook.md covering all four operator manual tasks needed to bring up the VIN Decoder namespace: - Step 4A-1: Create vin-decoder namespace - Step 4A-2: gitea-registry imagePullSecret in vin-decoder (issue #127) - Step 4A-3: rapidapi-proxy-secret placeholder in vin-decoder (issue #128) - Step 4A-4: GITEA_TOKEN Actions secret in vin-decoder repo (issue #126) - Step 4A-5: RAPIDAPI_VIN_API_ID + RAPIDAPI_VIN_VERSION_ID Actions secrets (issue #139) Also updates: - Phase 3 Step 3-A: adds leeworks-agents/vin-decoder to the GITEA_TOKEN repo list - Phase 4 DNS table: adds vin.leeworks.dev as the 8th subdomain (issue #150) - Phase 5 rapidapi-proxy-secret block: adds vin-decoder command - Phase 5: adds VIN Decoder pricing tier table (issue #151) - Dependency Summary: reflects VIN Decoder additions throughout Commands are consistent with docs/secrets-checklist.md items #11-#13. kustomize build flux/ still passes. Closes leeworks-agents/api-company#154 --- docs/operator-runbook.md | 113 ++++++++++++++++++++++++++++++++++++--- 1 file changed, 106 insertions(+), 7 deletions(-) diff --git a/docs/operator-runbook.md b/docs/operator-runbook.md index 06ce502..0e3ede8 100644 --- a/docs/operator-runbook.md +++ b/docs/operator-runbook.md @@ -2,7 +2,7 @@ **Audience:** Human operator (0xWheatyz) **Purpose:** Ordered, copy-paste-ready guide to bring the full `api-company` stack live. -**Last updated:** 2026-05-26 +**Last updated:** 2026-06-01 **Closes:** leeworks-agents/api-company#50 --- @@ -165,6 +165,7 @@ Repos to configure: - `leeworks-agents/zip-enrichment` - `leeworks-agents/holidays` - `leeworks-agents/air-quality` +- `leeworks-agents/vin-decoder` (see also Phase 4-A Step 4) **For each repo:** Repo → Settings → Actions → Secrets → Add Secret - **Name:** `GITEA_TOKEN` @@ -186,9 +187,9 @@ kubectl create secret generic gitea-image-automation-token \ --- -## Phase 4 — DNS for API services (issue #33) +## Phase 4 — DNS for API services (issues #33, #106, #150) -Add DNS A records for all seven leeworks.dev subdomains (all point to the same +Add DNS A records for **all eight** leeworks.dev subdomains (all point to the same cluster ingress IP): | Hostname | Target | @@ -196,6 +197,7 @@ cluster ingress IP): | `zip.leeworks.dev` | `` | | `holidays.leeworks.dev` | `` | | `aqi.leeworks.dev` | `` | +| `vin.leeworks.dev` | `` | | `docs.leeworks.dev` | `` | | `grafana.leeworks.dev` | `` | | `status.leeworks.dev` | `` | @@ -204,7 +206,7 @@ cluster ingress IP): Verify DNS propagation: ```bash -for host in zip holidays aqi docs grafana status registry; do +for host in zip holidays aqi vin docs grafana status registry; do echo -n "${host}.leeworks.dev: " dig ${host}.leeworks.dev +short done @@ -215,6 +217,76 @@ propagates (typically minutes, up to 48 h). --- +--- + +## Phase 4-A — VIN Decoder namespace setup (issues #126, #127, #128, #139) + +Before VIN Decoder pods can start, the following manual steps are required. +Do these alongside Phase 3 (they are independent of the DNS batch): + +### Step 4A-1 — Create `vin-decoder` namespace + +```bash +kubectl create namespace vin-decoder --dry-run=client -o yaml | kubectl apply -f - +``` + +### Step 4A-2 — Create `gitea-registry` imagePullSecret in `vin-decoder` namespace (issue #127) + +Reuse the same Gitea token with `read:packages` scope from secrets checklist item #8. + +```bash +kubectl create secret docker-registry gitea-registry \ + --namespace=vin-decoder \ + --docker-server=registry.leeworks.dev \ + --docker-username=leeworks-agents \ + --docker-password= \ + --docker-email=agent@leeworks.dev +``` + +Verify: +```bash +kubectl get secret gitea-registry -n vin-decoder -o jsonpath='{.type}' +# Expected: kubernetes.io/dockerconfigjson +``` + +### Step 4A-3 — Create `rapidapi-proxy-secret` in `vin-decoder` namespace (issue #128) + +**Now (placeholder — unblocks deploy testing):** +```bash +kubectl create secret generic rapidapi-proxy-secret \ + --namespace=vin-decoder \ + --from-literal=X-RapidAPI-Proxy-Secret=PLACEHOLDER_REPLACE_AFTER_RAPIDAPI_LISTING +``` + +**After VIN Decoder is listed on RapidAPI (Phase 5), update with real secret:** +```bash +kubectl create secret generic rapidapi-proxy-secret \ + -n vin-decoder \ + --from-literal=X-RapidAPI-Proxy-Secret= \ + --save-config --dry-run=client -o yaml | kubectl apply -f - +``` + +### Step 4A-4 — Add `GITEA_TOKEN` Actions secret to `leeworks-agents/vin-decoder` repo (issue #126) + +Gitea → `leeworks-agents/vin-decoder` → Settings → Secrets and Variables → Actions +- **Name:** `GITEA_TOKEN` +- **Value:** Gitea personal access token with `write:packages` scope + +Verify it appears in the repo's Actions Secrets list before the next push to `main`. + +### Step 4A-5 — Add RapidAPI VIN secrets to `leeworks-agents/api-company` Actions (issue #139) + +> **Blocked** — requires VIN Decoder to be listed on RapidAPI first (issue #131 tracker; operator action required). + +Once the VIN Decoder listing is live: + +Gitea → `leeworks-agents/api-company` → Settings → Secrets and Variables → Actions + +| Secret name | Where to find it | +|---------------------------|------------------| +| `RAPIDAPI_VIN_API_ID` | RapidAPI dashboard → VIN Decoder listing → Overview | +| `RAPIDAPI_VIN_VERSION_ID` | RapidAPI dashboard → VIN Decoder listing → Versions tab | + ## Phase 5 — RapidAPI + PayPal (issue #44, #19) > **Blocked on operator being 18+ for PayPal.** Complete when eligible. @@ -241,8 +313,25 @@ kubectl create secret generic rapidapi-proxy-secret \ kubectl create secret generic rapidapi-proxy-secret \ -n air-quality \ --from-literal=X-RapidAPI-Proxy-Secret= + +# vin-decoder (updates the placeholder secret from Phase 4-A Step 3) +kubectl create secret generic rapidapi-proxy-secret \ + -n vin-decoder \ + --from-literal=X-RapidAPI-Proxy-Secret= \ + --save-config --dry-run=client -o yaml | kubectl apply -f - ``` +Also configure VIN Decoder pricing tiers on RapidAPI (issue #151): + +| Tier | Monthly Price | Request Limit | Rate Limit | +|-------|---------------|----------------|-------------| +| Free | $0 | 100 req/mo | 5 req/min | +| Basic | $9 | 5,000 req/mo | 60 req/min | +| Pro | $19 | 20,000 req/mo | 200 req/min | +| Ultra | $49 | 100,000 req/mo | 500 req/min | + +Confirm VIN Decoder revenue flows through the same PayPal account as the other 3 APIs. + --- ## Quick Verification Checklist @@ -287,12 +376,22 @@ Phase 2: Service secrets (runner-token, grafana-admin, gatus-webhook, registry) Phase 3: CI secrets + image-automation token └─► images build, push, and auto-update → API services deploy + (includes leeworks-agents/vin-decoder GITEA_TOKEN — Step 3-A) -Phase 4: DNS records +Phase 4: DNS records (8 subdomains including vin.leeworks.dev) └─► HTTPS certs issued → public URLs go live -Phase 5: RapidAPI + PayPal - └─► revenue enabled +Phase 4-A: VIN Decoder namespace setup (#126, #127, #128) + 4A-1: vin-decoder namespace created + 4A-2: gitea-registry imagePullSecret in vin-decoder (#127) + 4A-3: rapidapi-proxy-secret placeholder in vin-decoder (#128) + 4A-4: GITEA_TOKEN Actions secret in vin-decoder repo (#126) + 4A-5: RAPIDAPI_VIN_API_ID + RAPIDAPI_VIN_VERSION_ID Actions secrets (#139) + [blocked on VIN Decoder RapidAPI listing] + └─► VIN Decoder pods start; CI can push images + +Phase 5: RapidAPI + PayPal (all 4 APIs including VIN Decoder; issue #151) + └─► revenue enabled for all 4 APIs ``` ---