Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 53466186b8 | |||
| 8d5ae5ee31 | |||
| 82c9f70a01 | |||
| 68a1524dca | |||
| bf19fb1cf5 | |||
| 54cd793d5e | |||
| 58eba5f342 | |||
| ae978a0bb3 | |||
| 01bfe2693a |
@@ -1,6 +1,6 @@
|
|||||||
# Company Status
|
# Company Status
|
||||||
|
|
||||||
_Last updated: 2026-05-26 (agent cycle)_
|
_Last updated: 2026-05-26 (agent cycle — evening)_
|
||||||
|
|
||||||
## APIs
|
## APIs
|
||||||
| API | Spec | Code | Deployed | Listed on RapidAPI | Paying Users | MRR |
|
| API | Spec | Code | Deployed | Listed on RapidAPI | Paying Users | MRR |
|
||||||
@@ -18,8 +18,17 @@ Legend: [x]=done, [~]=in-progress, [ ]=not started
|
|||||||
- **Container registry:** Gitea built-in registry selected; docs/registry.md committed — PENDING Gitea packages enabled (issue #4)
|
- **Container registry:** Gitea built-in registry selected; docs/registry.md committed — PENDING Gitea packages enabled (issue #4)
|
||||||
- **Prometheus + Grafana:** Flux HelmRelease at `flux/monitoring/` — PENDING Flux wiring + Grafana secret (issue #7)
|
- **Prometheus + Grafana:** Flux HelmRelease at `flux/monitoring/` — PENDING Flux wiring + Grafana secret (issue #7)
|
||||||
- **Gatus status page:** Flux HelmRelease at `flux/monitoring/gatus-helmrelease.yaml` — PENDING Flux wiring (issue #8)
|
- **Gatus status page:** Flux HelmRelease at `flux/monitoring/gatus-helmrelease.yaml` — PENDING Flux wiring (issue #8)
|
||||||
|
- **API service manifests (NEW):** `flux/zip-enrichment/`, `flux/holidays/`, `flux/air-quality/` scaffolded (PR #48, closes #46)
|
||||||
|
|
||||||
## Completed This Cycle (2026-05-26)
|
## Completed This Cycle (2026-05-26 Evening)
|
||||||
|
- **#50** — `docs/operator-runbook.md` added: ordered phase-by-phase manual for operator. PR #52 merged.
|
||||||
|
- **#51** — Flux image automation: `ImageRepository` + `ImagePolicy` + `ImageUpdateAutomation` for all three API services; setter markers added to HelmReleases. PR #52 merged. `kustomize build flux/ = PASS`.
|
||||||
|
|
||||||
|
## Completed Previous Cycle (2026-05-26 PM)
|
||||||
|
- **#46** — Scaffolded Flux deployment manifests for all three API services (zip-enrichment, holidays, air-quality). PR #48 merged.
|
||||||
|
|
||||||
|
## Completed Previous Cycle (2026-05-26 AM)
|
||||||
|
- **#43** — secrets-checklist.md added (closed, PR #45)
|
||||||
- **#36** — Cluster audit committed to `docs/cluster-audit.md` (closed)
|
- **#36** — Cluster audit committed to `docs/cluster-audit.md` (closed)
|
||||||
- **#40** — Legal docs (ToS, Privacy Policy, AUP) under `docs/legal/` (closed)
|
- **#40** — Legal docs (ToS, Privacy Policy, AUP) under `docs/legal/` (closed)
|
||||||
- **#37** — docs-site Astro skeleton with Redoc pages; `npm run build` passes (closed)
|
- **#37** — docs-site Astro skeleton with Redoc pages; `npm run build` passes (closed)
|
||||||
@@ -28,33 +37,23 @@ Legend: [x]=done, [~]=in-progress, [ ]=not started
|
|||||||
- **#34** — Cluster audit PR merged
|
- **#34** — Cluster audit PR merged
|
||||||
|
|
||||||
## Flux Manifests (kustomize build flux/ = PASS)
|
## Flux Manifests (kustomize build flux/ = PASS)
|
||||||
All flux manifests validate successfully. Deployed components pending Flux activation:
|
All flux manifests validate successfully. Added this cycle:
|
||||||
|
- `flux/image-automation/` — ImageRepository + ImagePolicy + ImageUpdateAutomation for zip-enrichment, holidays, air-quality
|
||||||
|
- Image setter markers (`# {"$imagepolicy": ...}`) added to all three service HelmReleases
|
||||||
|
|
||||||
|
Previously deployed components pending Flux activation:
|
||||||
- `gitea-runner` namespace + HelmRelease (gitea-act-runner chart)
|
- `gitea-runner` namespace + HelmRelease (gitea-act-runner chart)
|
||||||
- `monitoring` namespace + kube-prometheus-stack HelmRelease
|
- `monitoring` namespace + kube-prometheus-stack HelmRelease
|
||||||
- `monitoring` Gatus HelmRelease (status.leeworks.dev, 90-day retention)
|
- `monitoring` Gatus HelmRelease (status.leeworks.dev, 90-day retention)
|
||||||
- `docs-site` HelmRelease (docs.leeworks.dev)
|
- `docs-site` HelmRelease (docs.leeworks.dev)
|
||||||
|
- `zip-enrichment` namespace + HelmRelease (zip.leeworks.dev) + rapidapi-proxy-secret placeholder ← NEW
|
||||||
|
- `holidays` namespace + HelmRelease (holidays.leeworks.dev) + rapidapi-proxy-secret placeholder ← NEW
|
||||||
|
- `air-quality` namespace + HelmRelease (aqi.leeworks.dev) + rapidapi-proxy-secret placeholder ← NEW
|
||||||
|
|
||||||
## Blockers (human operator action required)
|
## Blockers (human operator action required)
|
||||||
1. **Add api-company GitRepository+Kustomization to 0xWheatyz/Talos** at `testing1/first-cluster/cluster/flux/` — reference manifests ready in `flux/api-company-source/`
|
1. **Create `0xWheatyz/api-company` repo on Gitea** — every ship cycle fails until this exists (#41, #47)
|
||||||
2. **Create `gitea-leeworks-agents-token` secret** in `flux-system` namespace (HTTPS token for Gitea)
|
2. **Add api-company GitRepository+Kustomization to 0xWheatyz/Talos** at `testing1/first-cluster/cluster/flux/` — reference manifests ready in `flux/api-company-source/` (#2)
|
||||||
3. **Create `gitea-runner-token` secret** in `gitea-runner` namespace (Gitea Admin → Actions → Runners → New Runner)
|
3. **Create `gitea-leeworks-agents-token` secret** in `flux-system` namespace (HTTPS token for Gitea)
|
||||||
4. **Enable Gitea packages** (`[packages] ENABLED=true` in app.ini) + DNS record `registry.leeworks.dev` → Gitea ingress
|
4. **Create `gitea-runner-token` secret** in `gitea-runner` namespace (Gitea Admin → Actions → Runners → New Runner) (#3)
|
||||||
5. **Create Grafana admin secret** in `monitoring` namespace (`GRAFANA_ADMIN_PASSWORD`)
|
5. **Enable Gitea packages** (for container registry at `registry.leeworks.dev`) (#4)
|
||||||
6. **Create Slack webhook secret** in `monitoring` namespace for Gatus alerts
|
6. **RapidAPI + PayPal setup** — manual, gated on operator turning 18 (#19, #44)
|
||||||
7. **DNS A records** for all 6 subdomains (zip, holidays, aqi, docs, status, registry) → cluster ingress IP (issue #33)
|
|
||||||
|
|
||||||
## API Repos Status
|
|
||||||
- `zip-enrichment`: Phase 3 server in progress (Fastify scaffold, routes, CI workflows)
|
|
||||||
- `holidays`: Phase 3 server in progress (Fastify scaffold, business-day routes)
|
|
||||||
- `air-quality`: Phase 1 in progress (openapi.yaml, Dockerfile)
|
|
||||||
|
|
||||||
## Revenue
|
|
||||||
- Gross MRR: $0
|
|
||||||
- Net MRR (after ~26.5% fees): $0
|
|
||||||
- Target: $100/mo net
|
|
||||||
- Gap: $100
|
|
||||||
|
|
||||||
## Next actions
|
|
||||||
1. **Human operator:** unblock infrastructure (items 1-7 above)
|
|
||||||
2. Once runner + Flux are live: API repo CI will build/push images and deploy to cluster
|
|
||||||
3. Phase 1→2→3 completion across zip-enrichment, holidays, air-quality repos
|
|
||||||
|
|||||||
@@ -0,0 +1,299 @@
|
|||||||
|
# Operator Runbook
|
||||||
|
|
||||||
|
**Audience:** Human operator (0xWheatyz)
|
||||||
|
**Purpose:** Ordered, copy-paste-ready guide to bring the full `api-company` stack live.
|
||||||
|
**Last updated:** 2026-05-26
|
||||||
|
**Closes:** leeworks-agents/api-company#50
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
The agent has committed all Flux manifests and documentation. The only remaining
|
||||||
|
work is a set of manual steps that require Gitea admin access, `kubectl` access to
|
||||||
|
the `testing1` cluster, and external service accounts (RapidAPI, Slack, PayPal).
|
||||||
|
|
||||||
|
Work through these phases **in order** — each phase unblocks the next.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 0 — Create upstream repo (unblocks all ship cycles)
|
||||||
|
|
||||||
|
> **Why first?** Every agent deployment cycle fails to open a PR to upstream
|
||||||
|
> because `0xWheatyz/api-company` does not yet exist. This one step unblocks
|
||||||
|
> all automated deployments. See issues #41, #47.
|
||||||
|
|
||||||
|
### Step 0-A — Create `0xWheatyz/api-company` on Gitea
|
||||||
|
|
||||||
|
1. Log into Gitea as `0xWheatyz`.
|
||||||
|
2. **+** → **New Repository**.
|
||||||
|
3. Owner: `0xWheatyz`, Name: `api-company`.
|
||||||
|
4. Visibility: Public (or Private — your choice).
|
||||||
|
5. **Do not** initialise with a README.
|
||||||
|
6. Click **Create Repository**.
|
||||||
|
|
||||||
|
Once created, the agent's next ship cycle will open a deployment PR automatically.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 1 — Wire Flux to this repo (unblocks all GitOps reconciliation)
|
||||||
|
|
||||||
|
> **Why second?** Until Flux watches `leeworks-agents/api-company`, none of the
|
||||||
|
> manifests in `flux/` are applied to the cluster. See issue #2.
|
||||||
|
|
||||||
|
### Step 1-A — Create `gitea-leeworks-agents-token` secret in `flux-system`
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# In Gitea: User Settings → Applications → Generate Token
|
||||||
|
# Scopes: read:repository (read-only is sufficient for Flux)
|
||||||
|
# Copy the token, then:
|
||||||
|
|
||||||
|
kubectl create secret generic gitea-leeworks-agents-token \
|
||||||
|
-n flux-system \
|
||||||
|
--from-literal=username=leeworks-agents \
|
||||||
|
--from-literal=password=<GITEA_TOKEN>
|
||||||
|
```
|
||||||
|
|
||||||
|
### Step 1-B — Copy Flux source + kustomization into 0xWheatyz/Talos
|
||||||
|
|
||||||
|
Reference manifests are at `flux/api-company-source/` in this repo.
|
||||||
|
Copy them verbatim to:
|
||||||
|
|
||||||
|
```
|
||||||
|
0xWheatyz/Talos:testing1/first-cluster/cluster/flux/api-company-source/
|
||||||
|
├── gitrepository.yaml
|
||||||
|
└── kustomization.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
You can do this via the Gitea web editor or locally:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd /path/to/Talos-checkout
|
||||||
|
mkdir -p testing1/first-cluster/cluster/flux/api-company-source
|
||||||
|
# copy the two files from api-company/flux/api-company-source/
|
||||||
|
git add .
|
||||||
|
git commit -m "feat: wire Flux GitRepository + Kustomization for api-company"
|
||||||
|
git push origin main
|
||||||
|
```
|
||||||
|
|
||||||
|
**Verify reconciliation (after ~5 minutes):**
|
||||||
|
```bash
|
||||||
|
flux get sources git -n flux-system
|
||||||
|
flux get kustomizations -n flux-system
|
||||||
|
```
|
||||||
|
|
||||||
|
Both `api-company` entries should show `Ready = True`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 2 — Secrets for already-staged services
|
||||||
|
|
||||||
|
Once Flux is watching the repo, it will attempt to reconcile all `flux/`
|
||||||
|
sub-directories. The HelmReleases will stall on missing secrets. Create them:
|
||||||
|
|
||||||
|
### Step 2-A — `gitea-runner-token` (unblocks Gitea Actions runner, issue #3)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# In Gitea: Admin Panel → Site Administration → Actions → Runners
|
||||||
|
# → Create new Runner → copy registration token
|
||||||
|
|
||||||
|
kubectl create secret generic gitea-runner-token \
|
||||||
|
-n gitea-runner \
|
||||||
|
--from-literal=token=<RUNNER_REGISTRATION_TOKEN>
|
||||||
|
```
|
||||||
|
|
||||||
|
**Verify:**
|
||||||
|
```bash
|
||||||
|
kubectl get pods -n gitea-runner
|
||||||
|
# Then check Gitea Admin → Actions → Runners — runner should appear Online
|
||||||
|
```
|
||||||
|
|
||||||
|
### Step 2-B — `grafana-admin` (unblocks Grafana, issue #7)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic grafana-admin \
|
||||||
|
-n monitoring \
|
||||||
|
--from-literal=admin-password=<CHOOSE_STRONG_PASSWORD>
|
||||||
|
```
|
||||||
|
|
||||||
|
Grafana URL: `https://grafana.leeworks.dev` (login: `admin` / `<PASSWORD>`)
|
||||||
|
|
||||||
|
### Step 2-C — `gatus-slack-webhook` (unblocks Gatus alerts, issue #8)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Create an incoming webhook at: https://api.slack.com/messaging/webhooks
|
||||||
|
|
||||||
|
kubectl create secret generic gatus-slack-webhook \
|
||||||
|
-n monitoring \
|
||||||
|
--from-literal=url=https://hooks.slack.com/services/YOUR/WEBHOOK/URL
|
||||||
|
```
|
||||||
|
|
||||||
|
Gatus URL: `https://status.leeworks.dev`
|
||||||
|
|
||||||
|
### Step 2-D — Enable Gitea packages + registry DNS (issue #4)
|
||||||
|
|
||||||
|
**4a — Enable packages in Gitea `app.ini`:**
|
||||||
|
```ini
|
||||||
|
[packages]
|
||||||
|
ENABLED = true
|
||||||
|
```
|
||||||
|
Restart Gitea after editing `app.ini`.
|
||||||
|
|
||||||
|
**4b — Add DNS A record:**
|
||||||
|
```
|
||||||
|
registry.leeworks.dev → <cluster ingress IP>
|
||||||
|
```
|
||||||
|
|
||||||
|
Find the ingress IP:
|
||||||
|
```bash
|
||||||
|
kubectl get svc -n ingress-nginx
|
||||||
|
```
|
||||||
|
|
||||||
|
See `docs/registry.md` for additional context.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 3 — Enable CI image push (unblocks API service deployments)
|
||||||
|
|
||||||
|
Once the runner is online and the registry is reachable, CI pipelines can build
|
||||||
|
and push container images.
|
||||||
|
|
||||||
|
### Step 3-A — Add `GITEA_TOKEN` Actions Secret to each repo
|
||||||
|
|
||||||
|
Repos to configure:
|
||||||
|
- `leeworks-agents/api-company`
|
||||||
|
- `leeworks-agents/zip-enrichment`
|
||||||
|
- `leeworks-agents/holidays`
|
||||||
|
- `leeworks-agents/air-quality`
|
||||||
|
|
||||||
|
**For each repo:** Repo → Settings → Actions → Secrets → Add Secret
|
||||||
|
- **Name:** `GITEA_TOKEN`
|
||||||
|
- **Value:** Gitea personal access token with `write:packages` scope
|
||||||
|
|
||||||
|
### Step 3-B — Create image-automation token secret (issue #51)
|
||||||
|
|
||||||
|
The agent has added `ImageRepository` + `ImagePolicy` + `ImageUpdateAutomation`
|
||||||
|
manifests to `flux/image-automation/`. Flux will automatically update image tags
|
||||||
|
in HelmReleases when CI pushes new images — but it needs write access to commit
|
||||||
|
back:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic gitea-image-automation-token \
|
||||||
|
-n flux-system \
|
||||||
|
--from-literal=username=leeworks-agents \
|
||||||
|
--from-literal=password=<GITEA_TOKEN_WITH_WRITE_REPO>
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 4 — DNS for API services (issue #33)
|
||||||
|
|
||||||
|
Add DNS A records for all six leeworks.dev subdomains (all point to the same
|
||||||
|
cluster ingress IP):
|
||||||
|
|
||||||
|
| Hostname | Target |
|
||||||
|
|-------------------------|------------------------|
|
||||||
|
| `zip.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
| `holidays.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
| `aqi.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
| `docs.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
| `grafana.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
| `status.leeworks.dev` | `<cluster ingress IP>` |
|
||||||
|
|
||||||
|
cert-manager will obtain Let's Encrypt certificates automatically once DNS
|
||||||
|
propagates (typically minutes, up to 48 h).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 5 — RapidAPI + PayPal (issue #44, #19)
|
||||||
|
|
||||||
|
> **Blocked on operator being 18+ for PayPal.** Complete when eligible.
|
||||||
|
|
||||||
|
1. Create accounts on [rapidapi.com](https://rapidapi.com) and [paypal.com](https://www.paypal.com).
|
||||||
|
2. Link PayPal to RapidAPI as the payout method.
|
||||||
|
3. Submit each API to the RapidAPI marketplace using `docs/rapidapi-listings.md`.
|
||||||
|
4. Configure paid tiers per `ROADMAP.md`.
|
||||||
|
|
||||||
|
After submission, RapidAPI generates a `X-RapidAPI-Proxy-Secret` per API. Create:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# zip-enrichment
|
||||||
|
kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
-n zip-enrichment \
|
||||||
|
--from-literal=X-RapidAPI-Proxy-Secret=<VALUE>
|
||||||
|
|
||||||
|
# holidays
|
||||||
|
kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
-n holidays \
|
||||||
|
--from-literal=X-RapidAPI-Proxy-Secret=<VALUE>
|
||||||
|
|
||||||
|
# air-quality
|
||||||
|
kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
-n air-quality \
|
||||||
|
--from-literal=X-RapidAPI-Proxy-Secret=<VALUE>
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Quick Verification Checklist
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Flux overall health
|
||||||
|
flux get all -A
|
||||||
|
|
||||||
|
# API service pods
|
||||||
|
kubectl get pods -n zip-enrichment
|
||||||
|
kubectl get pods -n holidays
|
||||||
|
kubectl get pods -n air-quality
|
||||||
|
|
||||||
|
# Ingress + TLS
|
||||||
|
kubectl get ingress -A
|
||||||
|
kubectl get certificates -A
|
||||||
|
|
||||||
|
# Gitea runner
|
||||||
|
kubectl get pods -n gitea-runner
|
||||||
|
|
||||||
|
# Monitoring stack
|
||||||
|
kubectl get pods -n monitoring
|
||||||
|
|
||||||
|
# Image automation
|
||||||
|
flux get imagepolicies -A
|
||||||
|
flux get imagerepositories -A
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Dependency Summary
|
||||||
|
|
||||||
|
```
|
||||||
|
Phase 0: Create 0xWheatyz/api-company repo
|
||||||
|
└─► unblocks agent deployment PRs to upstream
|
||||||
|
|
||||||
|
Phase 1: Wire Flux (gitea-token secret + Talos manifests)
|
||||||
|
└─► all flux/ manifests reconcile
|
||||||
|
|
||||||
|
Phase 2: Service secrets (runner-token, grafana-admin, gatus-webhook, registry)
|
||||||
|
└─► runner online, monitoring live, registry reachable
|
||||||
|
|
||||||
|
Phase 3: CI secrets + image-automation token
|
||||||
|
└─► images build, push, and auto-update → API services deploy
|
||||||
|
|
||||||
|
Phase 4: DNS records
|
||||||
|
└─► HTTPS certs issued → public URLs go live
|
||||||
|
|
||||||
|
Phase 5: RapidAPI + PayPal
|
||||||
|
└─► revenue enabled
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Related Documents
|
||||||
|
|
||||||
|
| Document | Purpose |
|
||||||
|
|----------|---------|
|
||||||
|
| `docs/secrets-checklist.md` | Full checklist of all required secrets |
|
||||||
|
| `docs/registry.md` | Container registry architecture decision |
|
||||||
|
| `docs/cluster-audit.md` | Node/namespace/ingress inventory |
|
||||||
|
| `docs/rapidapi-listings.md` | RapidAPI marketplace submission details |
|
||||||
|
| `ROADMAP.md` | Full project roadmap and milestones |
|
||||||
|
| `STATUS.md` | Current cycle status and blockers |
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Placeholder: inject the RapidAPI Proxy Secret here once ESO is deployed.
|
||||||
|
# Replace with a real ExternalSecret once leeworks-agents/api-company#2 and
|
||||||
|
# the external-secrets operator are running in the cluster.
|
||||||
|
#
|
||||||
|
# Example (uncomment and fill in secretStore name):
|
||||||
|
#
|
||||||
|
# apiVersion: external-secrets.io/v1beta1
|
||||||
|
# kind: ExternalSecret
|
||||||
|
# metadata:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# namespace: air-quality
|
||||||
|
# spec:
|
||||||
|
# refreshInterval: 1h
|
||||||
|
# secretStoreRef:
|
||||||
|
# name: <your-secret-store>
|
||||||
|
# kind: ClusterSecretStore
|
||||||
|
# target:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# creationPolicy: Owner
|
||||||
|
# data:
|
||||||
|
# - secretKey: X-RapidAPI-Proxy-Secret
|
||||||
|
# remoteRef:
|
||||||
|
# key: rapidapi/air-quality
|
||||||
|
# property: proxy-secret
|
||||||
|
#
|
||||||
|
# Until then, create manually:
|
||||||
|
# kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
# --from-literal=X-RapidAPI-Proxy-Secret=<value> \
|
||||||
|
# -n air-quality
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: raw
|
||||||
|
version: ">=0.2.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: bedag
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 60m
|
||||||
|
values:
|
||||||
|
resources:
|
||||||
|
- apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: air-quality
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: air-quality
|
||||||
|
spec:
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry
|
||||||
|
containers:
|
||||||
|
- name: air-quality
|
||||||
|
image: registry.leeworks.dev/air-quality/server:latest # {"$imagepolicy": "flux-system:air-quality"}
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
env:
|
||||||
|
- name: RAPIDAPI_PROXY_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: rapidapi-proxy-secret
|
||||||
|
key: X-RapidAPI-Proxy-Secret
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: air-quality
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 3000
|
||||||
|
- apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: air-quality
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- aqi.leeworks.dev
|
||||||
|
secretName: air-quality-tls
|
||||||
|
rules:
|
||||||
|
- host: aqi.leeworks.dev
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: air-quality
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- externalsecret.yaml
|
||||||
|
- helmrelease.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Placeholder: inject the RapidAPI Proxy Secret here once ESO is deployed.
|
||||||
|
# Replace with a real ExternalSecret once leeworks-agents/api-company#2 and
|
||||||
|
# the external-secrets operator are running in the cluster.
|
||||||
|
#
|
||||||
|
# Example (uncomment and fill in secretStore name):
|
||||||
|
#
|
||||||
|
# apiVersion: external-secrets.io/v1beta1
|
||||||
|
# kind: ExternalSecret
|
||||||
|
# metadata:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# namespace: holidays
|
||||||
|
# spec:
|
||||||
|
# refreshInterval: 1h
|
||||||
|
# secretStoreRef:
|
||||||
|
# name: <your-secret-store>
|
||||||
|
# kind: ClusterSecretStore
|
||||||
|
# target:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# creationPolicy: Owner
|
||||||
|
# data:
|
||||||
|
# - secretKey: X-RapidAPI-Proxy-Secret
|
||||||
|
# remoteRef:
|
||||||
|
# key: rapidapi/holidays
|
||||||
|
# property: proxy-secret
|
||||||
|
#
|
||||||
|
# Until then, create manually:
|
||||||
|
# kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
# --from-literal=X-RapidAPI-Proxy-Secret=<value> \
|
||||||
|
# -n holidays
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: raw
|
||||||
|
version: ">=0.2.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: bedag
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 60m
|
||||||
|
values:
|
||||||
|
resources:
|
||||||
|
- apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: holidays
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: holidays
|
||||||
|
spec:
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry
|
||||||
|
containers:
|
||||||
|
- name: holidays
|
||||||
|
image: registry.leeworks.dev/holidays/server:latest # {"$imagepolicy": "flux-system:holidays"}
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
env:
|
||||||
|
- name: RAPIDAPI_PROXY_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: rapidapi-proxy-secret
|
||||||
|
key: X-RapidAPI-Proxy-Secret
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: holidays
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 3000
|
||||||
|
- apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: holidays
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- holidays.leeworks.dev
|
||||||
|
secretName: holidays-tls
|
||||||
|
rules:
|
||||||
|
- host: holidays.leeworks.dev
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: holidays
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- externalsecret.yaml
|
||||||
|
- helmrelease.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# ImagePolicy: select the latest semver tag from each ImageRepository.
|
||||||
|
# Tags pushed by CI should follow semver (e.g. v1.2.3) or use "latest" —
|
||||||
|
# the semver policy picks up any vX.Y.Z tag. The "latest" alias keeps
|
||||||
|
# things working before formal releases are tagged.
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImagePolicy
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
imageRepositoryRef:
|
||||||
|
name: zip-enrichment
|
||||||
|
policy:
|
||||||
|
semver:
|
||||||
|
range: ">=0.1.0"
|
||||||
|
---
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImagePolicy
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
imageRepositoryRef:
|
||||||
|
name: holidays
|
||||||
|
policy:
|
||||||
|
semver:
|
||||||
|
range: ">=0.1.0"
|
||||||
|
---
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImagePolicy
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
imageRepositoryRef:
|
||||||
|
name: air-quality
|
||||||
|
policy:
|
||||||
|
semver:
|
||||||
|
range: ">=0.1.0"
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
# Flux image-reflector-controller watches these registries for new image tags.
|
||||||
|
# Requires: flux-system/gitea-image-automation-token secret (see docs/operator-runbook.md)
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImageRepository
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
image: registry.leeworks.dev/zip-enrichment/server
|
||||||
|
interval: 5m
|
||||||
|
secretRef:
|
||||||
|
name: gitea-leeworks-agents-token
|
||||||
|
---
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImageRepository
|
||||||
|
metadata:
|
||||||
|
name: holidays
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
image: registry.leeworks.dev/holidays/server
|
||||||
|
interval: 5m
|
||||||
|
secretRef:
|
||||||
|
name: gitea-leeworks-agents-token
|
||||||
|
---
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImageRepository
|
||||||
|
metadata:
|
||||||
|
name: air-quality
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
image: registry.leeworks.dev/air-quality/server
|
||||||
|
interval: 5m
|
||||||
|
secretRef:
|
||||||
|
name: gitea-leeworks-agents-token
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
# ImageUpdateAutomation: when an ImagePolicy selects a new tag, this object
|
||||||
|
# instructs Flux to open a commit on the api-company repo updating the
|
||||||
|
# image reference in the relevant HelmRelease values.
|
||||||
|
#
|
||||||
|
# The GitRepository used here is the api-company source (flux-system/api-company).
|
||||||
|
# Flux needs write access; create the token secret first:
|
||||||
|
# kubectl create secret generic gitea-image-automation-token \
|
||||||
|
# -n flux-system \
|
||||||
|
# --from-literal=username=leeworks-agents \
|
||||||
|
# --from-literal=password=<TOKEN_WITH_WRITE_REPO>
|
||||||
|
# Then patch the api-company GitRepository to reference it (or reuse
|
||||||
|
# gitea-leeworks-agents-token if that token also has write:repository scope).
|
||||||
|
apiVersion: image.toolkit.fluxcd.io/v1beta2
|
||||||
|
kind: ImageUpdateAutomation
|
||||||
|
metadata:
|
||||||
|
name: api-company
|
||||||
|
namespace: flux-system
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
sourceRef:
|
||||||
|
kind: GitRepository
|
||||||
|
name: api-company
|
||||||
|
git:
|
||||||
|
checkout:
|
||||||
|
ref:
|
||||||
|
branch: main
|
||||||
|
commit:
|
||||||
|
author:
|
||||||
|
email: agent@leeworks.dev
|
||||||
|
name: Flux Image Automation
|
||||||
|
messageTemplate: |
|
||||||
|
chore(image): update {{range .Updated.Images}}{{.Repository}}:{{.NewTag}} {{end}}
|
||||||
|
push:
|
||||||
|
branch: main
|
||||||
|
update:
|
||||||
|
path: ./flux
|
||||||
|
strategy: Setters
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- imagerepositories.yaml
|
||||||
|
- imagepolicies.yaml
|
||||||
|
- imageupdateautomation.yaml
|
||||||
@@ -4,3 +4,7 @@ resources:
|
|||||||
- gitea-runner
|
- gitea-runner
|
||||||
- monitoring
|
- monitoring
|
||||||
- docs-site
|
- docs-site
|
||||||
|
- zip-enrichment
|
||||||
|
- holidays
|
||||||
|
- air-quality
|
||||||
|
- image-automation
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
# Placeholder: inject the RapidAPI Proxy Secret here once ESO is deployed.
|
||||||
|
# Replace with a real ExternalSecret once leeworks-agents/api-company#2 and
|
||||||
|
# the external-secrets operator are running in the cluster.
|
||||||
|
#
|
||||||
|
# Example (uncomment and fill in secretStore name):
|
||||||
|
#
|
||||||
|
# apiVersion: external-secrets.io/v1beta1
|
||||||
|
# kind: ExternalSecret
|
||||||
|
# metadata:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# namespace: zip-enrichment
|
||||||
|
# spec:
|
||||||
|
# refreshInterval: 1h
|
||||||
|
# secretStoreRef:
|
||||||
|
# name: <your-secret-store>
|
||||||
|
# kind: ClusterSecretStore
|
||||||
|
# target:
|
||||||
|
# name: rapidapi-proxy-secret
|
||||||
|
# creationPolicy: Owner
|
||||||
|
# data:
|
||||||
|
# - secretKey: X-RapidAPI-Proxy-Secret
|
||||||
|
# remoteRef:
|
||||||
|
# key: rapidapi/zip-enrichment
|
||||||
|
# property: proxy-secret
|
||||||
|
#
|
||||||
|
# Until then, create manually:
|
||||||
|
# kubectl create secret generic rapidapi-proxy-secret \
|
||||||
|
# --from-literal=X-RapidAPI-Proxy-Secret=<value> \
|
||||||
|
# -n zip-enrichment
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: raw
|
||||||
|
version: ">=0.2.0"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: bedag
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 60m
|
||||||
|
values:
|
||||||
|
resources:
|
||||||
|
- apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: zip-enrichment
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: zip-enrichment
|
||||||
|
spec:
|
||||||
|
imagePullSecrets:
|
||||||
|
- name: gitea-registry
|
||||||
|
containers:
|
||||||
|
- name: zip-enrichment
|
||||||
|
image: registry.leeworks.dev/zip-enrichment/server:latest # {"$imagepolicy": "flux-system:zip-enrichment"}
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
env:
|
||||||
|
- name: RAPIDAPI_PROXY_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: rapidapi-proxy-secret
|
||||||
|
key: X-RapidAPI-Proxy-Secret
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 256Mi
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 30
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 3000
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: zip-enrichment
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 3000
|
||||||
|
- apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
|
namespace: zip-enrichment
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- zip.leeworks.dev
|
||||||
|
secretName: zip-enrichment-tls
|
||||||
|
rules:
|
||||||
|
- host: zip.leeworks.dev
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: zip-enrichment
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- externalsecret.yaml
|
||||||
|
- helmrelease.yaml
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: zip-enrichment
|
||||||
Reference in New Issue
Block a user