Compare commits
6 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ae978a0bb3 | |||
| 01bfe2693a | |||
| 091c5cd089 | |||
| 997bf7bb12 | |||
| f7aef173ff | |||
| c899450f56 |
@@ -1,6 +1,6 @@
|
|||||||
# Company Status
|
# Company Status
|
||||||
|
|
||||||
_Last updated: 2026-05-25 (agent cycle)_
|
_Last updated: 2026-05-26 (agent cycle)_
|
||||||
|
|
||||||
## APIs
|
## APIs
|
||||||
| API | Spec | Code | Deployed | Listed on RapidAPI | Paying Users | MRR |
|
| API | Spec | Code | Deployed | Listed on RapidAPI | Paying Users | MRR |
|
||||||
@@ -19,7 +19,15 @@ Legend: [x]=done, [~]=in-progress, [ ]=not started
|
|||||||
- **Prometheus + Grafana:** Flux HelmRelease at `flux/monitoring/` — PENDING Flux wiring + Grafana secret (issue #7)
|
- **Prometheus + Grafana:** Flux HelmRelease at `flux/monitoring/` — PENDING Flux wiring + Grafana secret (issue #7)
|
||||||
- **Gatus status page:** Flux HelmRelease at `flux/monitoring/gatus-helmrelease.yaml` — PENDING Flux wiring (issue #8)
|
- **Gatus status page:** Flux HelmRelease at `flux/monitoring/gatus-helmrelease.yaml` — PENDING Flux wiring (issue #8)
|
||||||
|
|
||||||
## Flux Manifests (`kustomize build flux/` = PASS)
|
## Completed This Cycle (2026-05-26)
|
||||||
|
- **#36** — Cluster audit committed to `docs/cluster-audit.md` (closed)
|
||||||
|
- **#40** — Legal docs (ToS, Privacy Policy, AUP) under `docs/legal/` (closed)
|
||||||
|
- **#37** — docs-site Astro skeleton with Redoc pages; `npm run build` passes (closed)
|
||||||
|
- **#39** — SEO blog posts (ZIP, Holidays, Air Quality) in `docs-site/src/pages/blog/` (closed)
|
||||||
|
- **#38** — Gitea Actions CI workflow (`.gitea/workflows/build-docs.yaml`) + Dockerfile (closed)
|
||||||
|
- **#34** — Cluster audit PR merged
|
||||||
|
|
||||||
|
## Flux Manifests (kustomize build flux/ = PASS)
|
||||||
All flux manifests validate successfully. Deployed components pending Flux activation:
|
All flux manifests validate successfully. Deployed components pending Flux activation:
|
||||||
- `gitea-runner` namespace + HelmRelease (gitea-act-runner chart)
|
- `gitea-runner` namespace + HelmRelease (gitea-act-runner chart)
|
||||||
- `monitoring` namespace + kube-prometheus-stack HelmRelease
|
- `monitoring` namespace + kube-prometheus-stack HelmRelease
|
||||||
@@ -33,6 +41,7 @@ All flux manifests validate successfully. Deployed components pending Flux activ
|
|||||||
4. **Enable Gitea packages** (`[packages] ENABLED=true` in app.ini) + DNS record `registry.leeworks.dev` → Gitea ingress
|
4. **Enable Gitea packages** (`[packages] ENABLED=true` in app.ini) + DNS record `registry.leeworks.dev` → Gitea ingress
|
||||||
5. **Create Grafana admin secret** in `monitoring` namespace (`GRAFANA_ADMIN_PASSWORD`)
|
5. **Create Grafana admin secret** in `monitoring` namespace (`GRAFANA_ADMIN_PASSWORD`)
|
||||||
6. **Create Slack webhook secret** in `monitoring` namespace for Gatus alerts
|
6. **Create Slack webhook secret** in `monitoring` namespace for Gatus alerts
|
||||||
|
7. **DNS A records** for all 6 subdomains (zip, holidays, aqi, docs, status, registry) → cluster ingress IP (issue #33)
|
||||||
|
|
||||||
## API Repos Status
|
## API Repos Status
|
||||||
- `zip-enrichment`: Phase 3 server in progress (Fastify scaffold, routes, CI workflows)
|
- `zip-enrichment`: Phase 3 server in progress (Fastify scaffold, routes, CI workflows)
|
||||||
@@ -46,6 +55,6 @@ All flux manifests validate successfully. Deployed components pending Flux activ
|
|||||||
- Gap: $100
|
- Gap: $100
|
||||||
|
|
||||||
## Next actions
|
## Next actions
|
||||||
1. **Human operator:** unblock infrastructure (items 1-6 above)
|
1. **Human operator:** unblock infrastructure (items 1-7 above)
|
||||||
2. Once runner + Flux are live: API repo CI will build/push images and deploy to cluster
|
2. Once runner + Flux are live: API repo CI will build/push images and deploy to cluster
|
||||||
3. Phase 1→2→3 completion across zip-enrichment, holidays, air-quality repos
|
3. Phase 1→2→3 completion across zip-enrichment, holidays, air-quality repos
|
||||||
|
|||||||
@@ -0,0 +1,167 @@
|
|||||||
|
# Kubernetes Secrets Checklist
|
||||||
|
|
||||||
|
All infrastructure blockers reduce to creating six Kubernetes secrets and one Gitea Actions secret.
|
||||||
|
Follow this list top-to-bottom; each step unblocks the next.
|
||||||
|
|
||||||
|
**Human operator only** — the agent cannot log into Gitea's admin panel or run `kubectl` in the cluster.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Checklist
|
||||||
|
|
||||||
|
- [ ] 1. `gitea-leeworks-agents-token` (flux-system) — unblocks Flux GitRepository auth
|
||||||
|
- [ ] 2. `gitea-runner-token` (gitea-runner) — unblocks Gitea Actions runner registration
|
||||||
|
- [ ] 3. `grafana-admin` (monitoring) — unblocks Grafana login
|
||||||
|
- [ ] 4. `gatus-slack-webhook` (monitoring) — unblocks Gatus alert notifications
|
||||||
|
- [ ] 5. `GITEA_TOKEN` in each API repo's Actions Secrets — unblocks CI image push
|
||||||
|
- [ ] 6. Gitea packages enabled + DNS record for `registry.leeworks.dev` — unblocks image push to registry
|
||||||
|
- [ ] 7. Add api-company Flux source + kustomization to 0xWheatyz/Talos — unblocks all GitOps reconciliation
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Secret Details
|
||||||
|
|
||||||
|
### 1. `gitea-leeworks-agents-token`
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|-----------|-------|
|
||||||
|
| Name | `gitea-leeworks-agents-token` |
|
||||||
|
| Namespace | `flux-system` |
|
||||||
|
| Purpose | Flux `GitRepository` authenticates to Gitea over HTTPS to pull `leeworks-agents/api-company` |
|
||||||
|
| Source | Gitea web UI → User Settings → Applications → Generate Token (scopes: `read:repository`) |
|
||||||
|
| Unblocks | Issue #2 (Flux GitRepository + Kustomization for api-company) |
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic gitea-leeworks-agents-token \
|
||||||
|
-n flux-system \
|
||||||
|
--from-literal=username=leeworks-agents \
|
||||||
|
--from-literal=password=<GITEA_TOKEN>
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### 2. `gitea-runner-token`
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|-----------|-------|
|
||||||
|
| Name | `gitea-runner-token` |
|
||||||
|
| Namespace | `gitea-runner` |
|
||||||
|
| Purpose | The `gitea-act-runner` HelmRelease reads this token to register the runner with Gitea |
|
||||||
|
| Source | Gitea Admin Panel → Site Administration → Actions → Runners → **Create new Runner** — copy registration token |
|
||||||
|
| Unblocks | Issue #3 (gitea-act-runner Flux deployment) |
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic gitea-runner-token \
|
||||||
|
-n gitea-runner \
|
||||||
|
--from-literal=token=<RUNNER_TOKEN>
|
||||||
|
```
|
||||||
|
|
||||||
|
After creating the secret, Flux reconciles the `gitea-act-runner` HelmRelease and the runner appears as **Online** in Gitea Admin → Actions → Runners.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### 3. `grafana-admin`
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|-----------|-------|
|
||||||
|
| Name | `grafana-admin` |
|
||||||
|
| Namespace | `monitoring` |
|
||||||
|
| Purpose | Sets the Grafana `admin` user password on first boot |
|
||||||
|
| Source | Choose a strong password and store it in a password manager |
|
||||||
|
| Unblocks | Issue #7 (Prometheus + Grafana HelmRelease) |
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic grafana-admin \
|
||||||
|
-n monitoring \
|
||||||
|
--from-literal=admin-password=<PASSWORD>
|
||||||
|
```
|
||||||
|
|
||||||
|
Grafana will be accessible at `https://grafana.leeworks.dev` (login: `admin` / `<PASSWORD>`).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### 4. `gatus-slack-webhook`
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|-----------|-------|
|
||||||
|
| Name | `gatus-slack-webhook` |
|
||||||
|
| Namespace | `monitoring` |
|
||||||
|
| Purpose | Gatus posts downtime alerts to a Slack channel via incoming webhook |
|
||||||
|
| Source | Slack → Your workspace → Apps → Incoming Webhooks → Add to Slack → copy webhook URL |
|
||||||
|
| Unblocks | Issue #8 (Gatus status page at `status.leeworks.dev`) |
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic gatus-slack-webhook \
|
||||||
|
-n monitoring \
|
||||||
|
--from-literal=url=https://hooks.slack.com/services/YOUR/WEBHOOK/URL
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### 5. `GITEA_TOKEN` — Gitea Actions Secret (per repo)
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|----------|-------|
|
||||||
|
| Name | `GITEA_TOKEN` |
|
||||||
|
| Scope | Gitea Actions Secret — set in each repo's Settings, **not** a Kubernetes secret |
|
||||||
|
| Purpose | CI workflows use this token to push container images to `registry.leeworks.dev` |
|
||||||
|
| Source | Same token as step 1, or a dedicated CI token with `write:packages` scope |
|
||||||
|
| Unblocks | CI pipelines for all three API repos |
|
||||||
|
|
||||||
|
Set in Gitea web UI for **each** of these repos:
|
||||||
|
- `leeworks-agents/api-company`
|
||||||
|
- `leeworks-agents/zip-enrichment`
|
||||||
|
- `leeworks-agents/holidays`
|
||||||
|
- `leeworks-agents/air-quality`
|
||||||
|
|
||||||
|
Path: **Repo → Settings → Actions → Secrets → Add Secret**
|
||||||
|
- Name: `GITEA_TOKEN`
|
||||||
|
- Value: `<GITEA_TOKEN>`
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### 6. Enable Gitea Packages + DNS for `registry.leeworks.dev`
|
||||||
|
|
||||||
|
This is a Gitea instance configuration step, not a Kubernetes secret.
|
||||||
|
|
||||||
|
| Step | Action |
|
||||||
|
|------|--------|
|
||||||
|
| 6a | Enable packages in Gitea `app.ini`: set `[packages] ENABLED = true` then restart Gitea |
|
||||||
|
| 6b | Add DNS A record: `registry.leeworks.dev` → cluster ingress IP |
|
||||||
|
|
||||||
|
Find cluster ingress IP:
|
||||||
|
```bash
|
||||||
|
kubectl get svc -n ingress-nginx
|
||||||
|
```
|
||||||
|
|
||||||
|
See `docs/registry.md` for context on why the Gitea built-in registry was chosen.
|
||||||
|
|
||||||
|
Unblocks: Issue #4 (container registry), and transitively all CI image-push workflows.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### 7. Add api-company Flux Source + Kustomization to 0xWheatyz/Talos
|
||||||
|
|
||||||
|
Reference manifests are already committed at `flux/api-company-source/` in this repo.
|
||||||
|
The operator must copy them into the Talos cluster repo so FluxCD picks them up:
|
||||||
|
|
||||||
|
```
|
||||||
|
0xWheatyz/Talos:testing1/first-cluster/cluster/flux/api-company-source/
|
||||||
|
```
|
||||||
|
|
||||||
|
Unblocks: Issue #2 (Flux reconciliation of all `flux/` manifests in this repo).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Dependency Order
|
||||||
|
|
||||||
|
```
|
||||||
|
7 (Flux wiring) → all flux/ resources reconcile
|
||||||
|
1 (gitea-leeworks-token) → Flux can pull this repo over HTTPS
|
||||||
|
2 (gitea-runner-token) → runner online → CI runs
|
||||||
|
3 (grafana-admin) → Grafana login works
|
||||||
|
4 (gatus-slack-webhook) → Gatus alerting works
|
||||||
|
5 + 6 (GITEA_TOKEN + registry packages) → CI pushes images → API services deploy
|
||||||
|
```
|
||||||
|
|
||||||
|
Once all seven items are complete, the full stack (runner, registry, Prometheus, Grafana, Gatus, docs-site, three API services) reconciles automatically via FluxCD with no further manual steps.
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Placeholder: inject the RapidAPI Proxy Secret here once ESO is deployed.
|
||||||
|
# Replace with a real ExternalSecret once leeworks-agents/api-company#2 and
|
||||||
|
# the external-secrets operator are running in the cluster.
|
||||||
|
#
|
||||||
|
# Example (uncomment and fill in secretStore name):
|
||||||
|
#
|
||||||
|
# apiVersion: external-secrets.io/v1beta1
|
||||||
|
# kind: ExternalSecret
|
||||||
|
# metadata:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# namespace: air-quality
|
||||||
|
# spec:
|
||||||
|
# refreshInterval: 1h
|
||||||
|
# secretStoreRef:
|
||||||
|
# name: <your-secret-store>
|
||||||
|
# kind: ClusterSecretStore
|
||||||
|
# target:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# creationPolicy: Owner
|
||||||
|
# data:
|
||||||
|
# - secretKey: X-RapidAPI-Proxy-Secret
|
||||||
|
# remoteRef:
|
||||||
|
# key: rapidapi/air-quality
|
||||||
|
# property: proxy-secret
|
||||||
|
#
|
||||||
|
# Until then, create manually:
|
||||||
|
# kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
# --from-literal=X-RapidAPI-Proxy-Secret=<value> \
|
||||||
|
# -n air-quality
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: raw
|
||||||
|
version: ">=0.2.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: bedag
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 60m
|
||||||
|
values:
|
||||||
|
resources:
|
||||||
|
- apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: air-quality
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: air-quality
|
||||||
|
spec:
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry
|
||||||
|
containers:
|
||||||
|
- name: air-quality
|
||||||
|
image: registry.leeworks.dev/air-quality/server:latest
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
env:
|
||||||
|
- name: RAPIDAPI_PROXY_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: rapidapi-proxy-secret
|
||||||
|
key: X-RapidAPI-Proxy-Secret
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: air-quality
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 3000
|
||||||
|
- apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- aqi.leeworks.dev
|
||||||
|
secretName: air-quality-tls
|
||||||
|
rules:
|
||||||
|
- host: aqi.leeworks.dev
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: air-quality
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- externalsecret.yaml
|
||||||
|
- helmrelease.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Placeholder: inject the RapidAPI Proxy Secret here once ESO is deployed.
|
||||||
|
# Replace with a real ExternalSecret once leeworks-agents/api-company#2 and
|
||||||
|
# the external-secrets operator are running in the cluster.
|
||||||
|
#
|
||||||
|
# Example (uncomment and fill in secretStore name):
|
||||||
|
#
|
||||||
|
# apiVersion: external-secrets.io/v1beta1
|
||||||
|
# kind: ExternalSecret
|
||||||
|
# metadata:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# namespace: holidays
|
||||||
|
# spec:
|
||||||
|
# refreshInterval: 1h
|
||||||
|
# secretStoreRef:
|
||||||
|
# name: <your-secret-store>
|
||||||
|
# kind: ClusterSecretStore
|
||||||
|
# target:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# creationPolicy: Owner
|
||||||
|
# data:
|
||||||
|
# - secretKey: X-RapidAPI-Proxy-Secret
|
||||||
|
# remoteRef:
|
||||||
|
# key: rapidapi/holidays
|
||||||
|
# property: proxy-secret
|
||||||
|
#
|
||||||
|
# Until then, create manually:
|
||||||
|
# kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
# --from-literal=X-RapidAPI-Proxy-Secret=<value> \
|
||||||
|
# -n holidays
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: raw
|
||||||
|
version: ">=0.2.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: bedag
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 60m
|
||||||
|
values:
|
||||||
|
resources:
|
||||||
|
- apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: holidays
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: holidays
|
||||||
|
spec:
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry
|
||||||
|
containers:
|
||||||
|
- name: holidays
|
||||||
|
image: registry.leeworks.dev/holidays/server:latest
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
env:
|
||||||
|
- name: RAPIDAPI_PROXY_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: rapidapi-proxy-secret
|
||||||
|
key: X-RapidAPI-Proxy-Secret
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: holidays
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 3000
|
||||||
|
- apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- holidays.leeworks.dev
|
||||||
|
secretName: holidays-tls
|
||||||
|
rules:
|
||||||
|
- host: holidays.leeworks.dev
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: holidays
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- externalsecret.yaml
|
||||||
|
- helmrelease.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
@@ -4,3 +4,6 @@ resources:
|
|||||||
- gitea-runner
|
- gitea-runner
|
||||||
- monitoring
|
- monitoring
|
||||||
- docs-site
|
- docs-site
|
||||||
|
- zip-enrichment
|
||||||
|
- holidays
|
||||||
|
- air-quality
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Placeholder: inject the RapidAPI Proxy Secret here once ESO is deployed.
|
||||||
|
# Replace with a real ExternalSecret once leeworks-agents/api-company#2 and
|
||||||
|
# the external-secrets operator are running in the cluster.
|
||||||
|
#
|
||||||
|
# Example (uncomment and fill in secretStore name):
|
||||||
|
#
|
||||||
|
# apiVersion: external-secrets.io/v1beta1
|
||||||
|
# kind: ExternalSecret
|
||||||
|
# metadata:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# namespace: zip-enrichment
|
||||||
|
# spec:
|
||||||
|
# refreshInterval: 1h
|
||||||
|
# secretStoreRef:
|
||||||
|
# name: <your-secret-store>
|
||||||
|
# kind: ClusterSecretStore
|
||||||
|
# target:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# creationPolicy: Owner
|
||||||
|
# data:
|
||||||
|
# - secretKey: X-RapidAPI-Proxy-Secret
|
||||||
|
# remoteRef:
|
||||||
|
# key: rapidapi/zip-enrichment
|
||||||
|
# property: proxy-secret
|
||||||
|
#
|
||||||
|
# Until then, create manually:
|
||||||
|
# kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
# --from-literal=X-RapidAPI-Proxy-Secret=<value> \
|
||||||
|
# -n zip-enrichment
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: raw
|
||||||
|
version: ">=0.2.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: bedag
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 60m
|
||||||
|
values:
|
||||||
|
resources:
|
||||||
|
- apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: zip-enrichment
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: zip-enrichment
|
||||||
|
spec:
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry
|
||||||
|
containers:
|
||||||
|
- name: zip-enrichment
|
||||||
|
image: registry.leeworks.dev/zip-enrichment/server:latest
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
env:
|
||||||
|
- name: RAPIDAPI_PROXY_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: rapidapi-proxy-secret
|
||||||
|
key: X-RapidAPI-Proxy-Secret
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: zip-enrichment
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 3000
|
||||||
|
- apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- zip.leeworks.dev
|
||||||
|
secretName: zip-enrichment-tls
|
||||||
|
rules:
|
||||||
|
- host: zip.leeworks.dev
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: zip-enrichment
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- externalsecret.yaml
|
||||||
|
- helmrelease.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
Reference in New Issue
Block a user