Compare commits

..

45 Commits

Author SHA1 Message Date
renovate-bot 07b6bbdd11 Update Helm release cloudnative-pg to v0.29.0
renovate/stability-days Updates have met minimum release age requirement
2026-07-07 11:36:46 +00:00
mrtz c9f9d78d32 Merge pull request 'Update dragonfly-operator Docker tag to v1.6.1' (#237) from renovate/dragonfly-operator-1.x into main
Reviewed-on: #237
2026-07-07 10:45:24 +00:00
Gitea Actions 67e179a494 ci(staging): deploy makai 7080a0bd-debug 2026-07-07 10:04:02 +00:00
mrtz 750d11b021 temporal: Bump to 1.5.0 2026-07-07 11:48:18 +02:00
Gitea Actions d7607dcde3 ci(staging): deploy makai d2be2d74-debug 2026-07-07 08:23:38 +00:00
Gitea Actions aa3fa4e5fb ci(prod): deploy sorcerer v2.17.1 2026-07-06 14:42:54 +00:00
Gitea Actions f37a6a4ef1 ci(prod): deploy atlantis v2.17.1 2026-07-06 14:32:09 +00:00
Gitea Actions 784d1bc983 ci(prod): deploy codex v2.17.1 2026-07-06 14:31:23 +00:00
Gitea Actions 141151a00b ci(staging): deploy atlantis 6442206c-debug 2026-07-06 14:28:28 +00:00
Gitea Actions 29d147c304 ci(staging): deploy sorcerer 6442206c-debug 2026-07-06 14:28:25 +00:00
Gitea Actions 83728881d7 ci(staging): deploy codex 6442206c-debug 2026-07-06 14:28:18 +00:00
mrtz 009890e282 umami: Bump to 3.2.0 2026-07-06 12:33:07 +02:00
mrtz 1d2f4d3e2d Merge pull request 'Update registry.k8s.io/kueue/charts/kueue Docker tag to v0.18.1' (#240) from renovate/registry.k8s.io-kueue-charts-kueue-0.x into main
Reviewed-on: #240
2026-07-06 10:30:31 +00:00
mrtz 7bb2d3c8b6 loki/tempo: Disable LGTM on tos1 2026-07-06 10:21:22 +02:00
mrtz abf3348f01 clickhouse: Don't request more than 1 cpu 2026-07-06 10:17:51 +02:00
mrtz eddd083cd0 otel: Fix formatting 2026-07-06 10:14:44 +02:00
mrtz e2a6ec8cf5 otel: Move exporters 2026-07-06 10:12:26 +02:00
mrtz 78e2acf660 clickhouse: Use NFS 2026-07-06 10:01:21 +02:00
mrtz abb0398024 clickhouse: Use nfs for now 2026-07-06 09:58:57 +02:00
mrtz 6f19c8007f clickhouse: Add hostkey 2026-07-06 09:54:35 +02:00
mrtz 35dd11d3a0 clickhouse: Add S3 cold tier and additional replicas 2026-07-06 09:52:15 +02:00
mrtz 5343526316 prometheus: Sync secret on boot 2026-07-06 09:27:19 +02:00
mrtz 24cb34c148 clickhouse: Use one DS for both logs and traces 2026-07-06 09:09:01 +02:00
Gitea Actions d6e8622d3e ci(staging): deploy makai ebc8ee24-debug 2026-07-06 06:42:01 +00:00
mrtz 5930c714c3 Merge pull request 'Update Helm release temporal to v1.4.0' (#248) from renovate/temporal-1.x into main
Reviewed-on: #248
2026-07-05 12:39:51 +00:00
mrtz e5fbce570f Merge pull request 'Update Helm release opentelemetry-collector to v0.159.1' (#247) from renovate/opentelemetry-collector-0.x into main
Reviewed-on: #247
2026-07-05 12:38:57 +00:00
renovate-bot e9e08cd8c4 Update Helm release temporal to v1.4.0
renovate/stability-days Updates have met minimum release age requirement
2026-07-05 12:38:35 +00:00
renovate-bot 63b9402351 Update Helm release opentelemetry-collector to v0.159.1
renovate/stability-days Updates have met minimum release age requirement
2026-07-05 12:38:16 +00:00
mrtz a4b28d5f47 Merge pull request 'Update Helm release argo-workflows to v1.0.18' (#246) from renovate/argo-workflows-1.x into main
Reviewed-on: #246
2026-07-05 12:37:40 +00:00
mrtz 9020797b65 clickhouse: Use headless svc 2026-07-05 09:28:14 +02:00
renovate-bot 20c8eb60aa Update Helm release argo-workflows to v1.0.18
renovate/stability-days Updates have met minimum release age requirement
2026-07-05 00:03:18 +00:00
mrtz 3ba4c25906 clickhouse: Correct indentation 2026-07-04 17:56:06 +02:00
mrtz ebe80fcef4 argo: Add clickhouse 2026-07-04 17:48:17 +02:00
mrtz 67d3ea0919 clickhouse: Add WIP deployment for otel 2026-07-04 17:45:12 +02:00
mrtz 9566f84266 atlantis: Bump katamari to 1.5.3 2026-07-02 21:06:45 +02:00
mrtz 29c01eba3a atlantis: Bump katamari to 1.5.1 2026-07-02 13:58:09 +02:00
Gitea Actions ceaa394088 ci(staging): deploy docs 72b01c0b-debug 2026-07-01 12:00:31 +00:00
Gitea Actions ec931f86d6 ci(staging): deploy atlantis 5eeef12c-debug 2026-07-01 09:39:46 +00:00
Gitea Actions 8f67789af6 ci(staging): deploy atlantis fc672ad2-debug 2026-06-28 18:21:29 +00:00
mrtz bc4b4079f2 Merge pull request 'Update Helm release openfga to v0.3.9' (#244) from renovate/openfga-0.x into main
Reviewed-on: #244
2026-06-28 16:07:26 +00:00
mrtz 952ed4a075 Merge pull request 'Update Helm release opentelemetry-collector to v0.158.2' (#245) from renovate/opentelemetry-collector-0.x into main
Reviewed-on: #245
2026-06-28 16:03:27 +00:00
renovate-bot 7dec0dbd30 Update Helm release opentelemetry-collector to v0.158.2
renovate/stability-days Updates have met minimum release age requirement
2026-06-21 21:03:22 +00:00
renovate-bot 24b7133646 Update Helm release openfga to v0.3.9
renovate/stability-days Updates have met minimum release age requirement
2026-06-21 21:03:15 +00:00
renovate-bot 9a6ee23ff4 Update registry.k8s.io/kueue/charts/kueue Docker tag to v0.18.1
renovate/stability-days Updates have not met minimum release age requirement
2026-06-16 16:47:49 +00:00
renovate-bot f0dccf7df8 Update dragonfly-operator Docker tag to v1.6.1
renovate/stability-days Updates have not met minimum release age requirement
2026-06-16 16:47:28 +00:00
40 changed files with 546 additions and 222 deletions
+2 -2
View File
@@ -4,10 +4,10 @@ description: Atlantis map and simulation service
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v1.42.29
version: v2.17.1
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v1.42.29
appVersion: v2.17.1
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
+1 -1
View File
@@ -4,7 +4,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
tag: v1.42.29
tag: v2.17.1
pullPolicy: IfNotPresent
init:
enabled: false
+2 -2
View File
@@ -13,9 +13,9 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: v1.42.29
version: v2.17.1
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "v1.42.29"
appVersion: "v2.17.1"
+1 -1
View File
@@ -10,7 +10,7 @@ image:
# This sets the pull policy for images.
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: v1.42.29
tag: v2.17.1
# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
imagePullSecrets:
- name: gitlab-pull-secret
+2 -2
View File
@@ -4,10 +4,10 @@ description: A Helm chart for Kubernetes
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v1.42.29
version: v2.17.1
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v1.42.29
appVersion: v2.17.1
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
+1 -1
View File
@@ -5,7 +5,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
tag: v1.42.29
tag: v2.17.1
pullPolicy: IfNotPresent
init:
enabled: false
+1 -1
View File
@@ -43,7 +43,7 @@ releases:
- name: argo-workflows
namespace: argocd
chart: argo/argo-workflows
version: 1.0.16
version: 1.0.18
condition: argo.workflows.enabled
missingFileHandler: Info
- name: manifests
+53
View File
@@ -0,0 +1,53 @@
bases:
- ../envs/environments.yaml.gotmpl
repositories:
- name: clickhouse
url: ghcr.io/clickhouse
oci: true
commonLabels:
tier: system
releases:
- name: clickhouse-operator
namespace: clickhouse
chart: clickhouse/clickhouse-operator-helm
version: 0.0.6
condition: clickhouse.enabled
values:
- ../values/clickhouse/values/operator.yaml.gotmpl
missingFileHandler: Info
- name: clickhouse-cluster
namespace: clickhouse
chart: clickhouse/clickhouse-cluster-helm
version: 0.0.6
condition: clickhouse.enabled
needs:
- clickhouse/clickhouse-operator
values:
- ../values/clickhouse/values/cluster.yaml.gotmpl
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/clickhouse/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: clickhouse
chart: manifests
condition: clickhouse.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/clickhouse/env.yaml.gotmpl
- ../values/clickhouse/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
command: ../bin/helmify
args:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/clickhouse/manifests
- manifests
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: dragonfly
namespace: dragonfly
chart: dragonfly/dragonfly-operator
version: v1.5.0
version: v1.6.1
condition: dragonfly.enabled
values:
- ../values/dragonfly/values/dragonfly.yaml.gotmpl
+1 -1
View File
@@ -8,7 +8,7 @@ releases:
- name: kueue
namespace: kueue-system
chart: oci://registry.k8s.io/kueue/charts/kueue
version: 0.17.3
version: 0.18.1
condition: kueue.enabled
values:
- ../values/kueue/values/values.yaml
+1 -1
View File
@@ -16,7 +16,7 @@ releases:
namespace: {{ .Environment.Name }}-openfga
{{- end }}
chart: openfga/openfga
version: 0.3.8
version: 0.3.9
condition: openfga.enabled
values:
- ../values/openfga/values/values.yaml
@@ -12,10 +12,10 @@ releases:
- name: opentelemetry-collector
namespace: otel
chart: open-telemetry/opentelemetry-collector
version: 0.158.1
version: 0.159.1
condition: otel.enabled
values:
- ../values/opentelemetry-collector/values/values.yaml
- ../values/opentelemetry-collector/values/values.yaml.gotmpl
- ../values/opentelemetry-collector/values/values-{{ .Environment.Name }}.yaml
postRenderer: ../bin/kustomizer
postRendererArgs:
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: postgres-operator
namespace: cnpg
chart: cloudnative-pg/cloudnative-pg
version: 0.28.2
version: 0.29.0
condition: postgres_operator.enabled
values:
- ../values/postgres-operator/values/postgres-operator.yaml.gotmpl
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: prometheus
namespace: prometheus
chart: prometheus/kube-prometheus-stack
version: 86.3.2
version: 86.2.0
condition: prometheus.enabled
values:
- ../values/prometheus/values/prometheus.yaml.gotmpl
+1 -1
View File
@@ -12,7 +12,7 @@ releases:
- name: temporal
namespace: temporal
chart: temporal/temporal
version: 1.2.0
version: 1.5.0
condition: temporal.enabled
missingFileHandler: Info
values:
+157 -154
View File
@@ -6,160 +6,163 @@ metadata:
namespace: argocd
spec:
clusterResourceWhitelist:
- group: '*'
kind: '*'
- group: "*"
kind: "*"
description: sys components project
destinations:
- namespace: default
server: https://kubernetes.default.svc
- namespace: argocd
server: https://kubernetes.default.svc
- namespace: kube-system
server: https://kubernetes.default.svc
- namespace: ingress-nginx
server: https://kubernetes.default.svc
- namespace: prometheus
server: https://kubernetes.default.svc
- namespace: cnpg
server: https://kubernetes.default.svc
- namespace: cert-manager
server: https://kubernetes.default.svc
- namespace: kubernetes-dashboard
server: https://kubernetes.default.svc
- namespace: rabbitmq
server: https://kubernetes.default.svc
- namespace: sealed-secrets
server: https://kubernetes.default.svc
- namespace: gitlab
server: https://kubernetes.default.svc
- namespace: thanos
server: https://kubernetes.default.svc
- namespace: linkerd
server: https://kubernetes.default.svc
- namespace: linkerd-multicluster
server: https://kubernetes.default.svc
- namespace: observability
server: https://kubernetes.default.svc
- namespace: kyverno
server: https://kubernetes.default.svc
- namespace: velero
server: https://kubernetes.default.svc
- namespace: loki
server: https://kubernetes.default.svc
- namespace: tempo
server: https://kubernetes.default.svc
- namespace: x509-exporter
server: https://kubernetes.default.svc
- namespace: mariadb-operator
server: https://kubernetes.default.svc
- namespace: dragonfly
server: https://kubernetes.default.svc
- namespace: cilium-spire
server: https://kubernetes.default.svc
- namespace: cilium-test
server: https://kubernetes.default.svc
- namespace: cilium-secrets
server: https://kubernetes.default.svc
- namespace: openfga
server: https://kubernetes.default.svc
- namespace: staging-openfga
server: https://kubernetes.default.svc
- namespace: dapr-system
server: https://kubernetes.default.svc
- namespace: rook-ceph
server: https://kubernetes.default.svc
- namespace: csi-addon-manager
server: https://kubernetes.default.svc
- namespace: headscale
server: https://kubernetes.default.svc
- namespace: drupal
server: https://kubernetes.default.svc
- namespace: otel
server: https://kubernetes.default.svc
- namespace: opentelemetry
server: https://kubernetes.default.svc
- namespace: ncps
server: https://kubernetes.default.svc
- namespace: slinky
server: https://kubernetes.default.svc
- namespace: slurm
server: https://kubernetes.default.svc
- namespace: spegel
server: https://kubernetes.default.svc
- namespace: uptime
server: https://kubernetes.default.svc
- namespace: gitea
server: https://kubernetes.default.svc
- namespace: postfix
server: https://kubernetes.default.svc
- namespace: jobset-system
server: https://kubernetes.default.svc
- namespace: ingress-haproxy
server: https://kubernetes.default.svc
- namespace: dex
server: https://kubernetes.default.svc
- namespace: cra-agent
server: https://kubernetes.default.svc
- namespace: catalyst
server: https://kubernetes.default.svc
- namespace: niks3
server: https://kubernetes.default.svc
- namespace: temporal
server: https://kubernetes.default.svc
- namespace: ingest
server: https://kubernetes.default.svc
- namespace: proteus
server: https://kubernetes.default.svc
- namespace: default
server: https://kubernetes.default.svc
- namespace: argocd
server: https://kubernetes.default.svc
- namespace: kube-system
server: https://kubernetes.default.svc
- namespace: ingress-nginx
server: https://kubernetes.default.svc
- namespace: prometheus
server: https://kubernetes.default.svc
- namespace: cnpg
server: https://kubernetes.default.svc
- namespace: cert-manager
server: https://kubernetes.default.svc
- namespace: kubernetes-dashboard
server: https://kubernetes.default.svc
- namespace: rabbitmq
server: https://kubernetes.default.svc
- namespace: sealed-secrets
server: https://kubernetes.default.svc
- namespace: gitlab
server: https://kubernetes.default.svc
- namespace: thanos
server: https://kubernetes.default.svc
- namespace: linkerd
server: https://kubernetes.default.svc
- namespace: linkerd-multicluster
server: https://kubernetes.default.svc
- namespace: observability
server: https://kubernetes.default.svc
- namespace: kyverno
server: https://kubernetes.default.svc
- namespace: velero
server: https://kubernetes.default.svc
- namespace: loki
server: https://kubernetes.default.svc
- namespace: tempo
server: https://kubernetes.default.svc
- namespace: x509-exporter
server: https://kubernetes.default.svc
- namespace: mariadb-operator
server: https://kubernetes.default.svc
- namespace: dragonfly
server: https://kubernetes.default.svc
- namespace: cilium-spire
server: https://kubernetes.default.svc
- namespace: cilium-test
server: https://kubernetes.default.svc
- namespace: cilium-secrets
server: https://kubernetes.default.svc
- namespace: openfga
server: https://kubernetes.default.svc
- namespace: staging-openfga
server: https://kubernetes.default.svc
- namespace: dapr-system
server: https://kubernetes.default.svc
- namespace: rook-ceph
server: https://kubernetes.default.svc
- namespace: csi-addon-manager
server: https://kubernetes.default.svc
- namespace: headscale
server: https://kubernetes.default.svc
- namespace: drupal
server: https://kubernetes.default.svc
- namespace: otel
server: https://kubernetes.default.svc
- namespace: opentelemetry
server: https://kubernetes.default.svc
- namespace: ncps
server: https://kubernetes.default.svc
- namespace: slinky
server: https://kubernetes.default.svc
- namespace: slurm
server: https://kubernetes.default.svc
- namespace: spegel
server: https://kubernetes.default.svc
- namespace: uptime
server: https://kubernetes.default.svc
- namespace: gitea
server: https://kubernetes.default.svc
- namespace: postfix
server: https://kubernetes.default.svc
- namespace: jobset-system
server: https://kubernetes.default.svc
- namespace: ingress-haproxy
server: https://kubernetes.default.svc
- namespace: dex
server: https://kubernetes.default.svc
- namespace: cra-agent
server: https://kubernetes.default.svc
- namespace: catalyst
server: https://kubernetes.default.svc
- namespace: niks3
server: https://kubernetes.default.svc
- namespace: temporal
server: https://kubernetes.default.svc
- namespace: ingest
server: https://kubernetes.default.svc
- namespace: proteus
server: https://kubernetes.default.svc
- namespace: clickhouse
server: https://kubernetes.default.svc
sourceRepos:
- https://argoproj.github.io/argo-helm
- https://kubernetes-sigs.github.io/metrics-server/
- https://git.oceanbox.io/platform/manifests.git
- https://git.oceanbox.io/platform/manifests
- https://git.oceanbox.io/oceanbox/manifests.git
- https://kubernetes.github.io/ingress-nginx
- https://cloudnative-pg.github.io/charts
- https://charts.jetstack.io
- https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
- https://github.com/kubernetes/dashboard
- https://bitnami-labs.github.io/sealed-secrets
- https://prometheus-community.github.io/helm-charts
- https://github.com/prometheus-community/helm-charts.git
- https://charts.gitlab.io/
- https://charts.bitnami.com/bitnami
- https://helm.linkerd.io/stable
- https://github.com/jaegertracing/jaeger-operator
- https://kyverno.github.io/kyverno/
- https://vmware-tanzu.github.io/helm-charts
- https://grafana.github.io/helm-charts
- https://charts.enix.io
- https://helm.mariadb.com/mariadb-operator
- https://helm.mariadb.com/mariadb-operator-crds
- https://helm.mariadb.com
- https://helm.cilium.io
- https://chartmuseum.github.io/charts
- https://dapr.github.io/helm-charts
- https://charts.gabe565.com
- ghcr.io/gabe565/charts
- https://open-telemetry.github.io/opentelemetry-helm-charts
- https://ghcr.io/slinkyproject/charts/slurm-operator
- https://ghcr.io/slinkyproject/charts/slurm-operator-crds
- https://bokysan.github.io/docker-postfix/
- ghcr.io/slinkyproject/charts
- ghcr.io/slinkyproject/charts/slurm-operator
- ghcr.io/slinkyproject/charts/slurm-operator-crds
- ghcr.io/spegel-org/helm-charts
- quay.io/cilium/charts
- quay.io/jetstack/charts
- quay.io/enix/charts
- registry.k8s.io/jobset/charts/jobset
- ghcr.io/dragonflydb/dragonfly-operator/helm/dragonfly-operator
- docker.gitea.com
- https://operator.mariadb.com/mariadb-enterprise-operator
- https://ot-container-kit.github.io/helm-charts
- https://operator.mariadb.com
- https://twin.github.io/helm-charts
- https://charts.dexidp.io
- public.ecr.aws/diagrid/catalyst
- ghcr.io/haproxytech/helm-charts
- https://go.temporal.io/helm-charts
- docker.io/temporalio
- https://argoproj.github.io/argo-helm
- https://kubernetes-sigs.github.io/metrics-server/
- https://git.oceanbox.io/platform/manifests.git
- https://git.oceanbox.io/platform/manifests
- https://git.oceanbox.io/oceanbox/manifests.git
- https://kubernetes.github.io/ingress-nginx
- https://cloudnative-pg.github.io/charts
- https://charts.jetstack.io
- https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
- https://github.com/kubernetes/dashboard
- https://bitnami-labs.github.io/sealed-secrets
- https://prometheus-community.github.io/helm-charts
- https://github.com/prometheus-community/helm-charts.git
- https://charts.gitlab.io/
- https://charts.bitnami.com/bitnami
- https://helm.linkerd.io/stable
- https://github.com/jaegertracing/jaeger-operator
- https://kyverno.github.io/kyverno/
- https://vmware-tanzu.github.io/helm-charts
- https://grafana.github.io/helm-charts
- https://charts.enix.io
- https://helm.mariadb.com/mariadb-operator
- https://helm.mariadb.com/mariadb-operator-crds
- https://helm.mariadb.com
- https://helm.cilium.io
- https://chartmuseum.github.io/charts
- https://dapr.github.io/helm-charts
- https://charts.gabe565.com
- ghcr.io/gabe565/charts
- https://open-telemetry.github.io/opentelemetry-helm-charts
- https://ghcr.io/slinkyproject/charts/slurm-operator
- https://ghcr.io/slinkyproject/charts/slurm-operator-crds
- https://bokysan.github.io/docker-postfix/
- ghcr.io/slinkyproject/charts
- ghcr.io/slinkyproject/charts/slurm-operator
- ghcr.io/slinkyproject/charts/slurm-operator-crds
- ghcr.io/spegel-org/helm-charts
- quay.io/cilium/charts
- quay.io/jetstack/charts
- quay.io/enix/charts
- registry.k8s.io/jobset/charts/jobset
- ghcr.io/dragonflydb/dragonfly-operator/helm/dragonfly-operator
- docker.gitea.com
- https://operator.mariadb.com/mariadb-enterprise-operator
- https://ot-container-kit.github.io/helm-charts
- https://operator.mariadb.com
- https://twin.github.io/helm-charts
- https://charts.dexidp.io
- public.ecr.aws/diagrid/catalyst
- ghcr.io/haproxytech/helm-charts
- https://go.temporal.io/helm-charts
- docker.io/temporalio
- ghcr.io/clickhouse
@@ -4,10 +4,7 @@ metadata:
name: beta-atlantis-actor-config
data:
KUEUE_NAMESPACE: "prod-queue"
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.4.4"
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.5.3"
XTRACT_QUEUE: "prod-queue"
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.4.4"
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.5.3"
PLUME_QUEUE: "prod-queue"
TEMPORAL_ADDRESS: "temporal-frontend.temporal:7233"
TEMPORAL_NAMESPACE: "beta-atlantis"
TEMPORAL_TASK_QUEUE: "atlantis"
@@ -3,9 +3,9 @@ kind: ConfigMap
metadata:
name: staging-atlantis-actor-config
data:
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.4.0"
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.5.1"
XTRACT_QUEUE: "dev-queue"
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.4.0"
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.5.1"
PLUME_QUEUE: "dev-queue"
TEMPORAL_ADDRESS: "temporal-frontend.temporal:7233"
TEMPORAL_NAMESPACE: "staging-atlantis"
@@ -1,7 +1,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
tag: 04417cca-debug
tag: 6442206c-debug
podAnnotations:
dapr.io/app-id: "staging-atlantis"
env:
@@ -0,0 +1,4 @@
clickhouse:
enabled: true
s3:
enabled: true
+27
View File
@@ -0,0 +1,27 @@
clickhouse:
enabled: false
autosync: true
clusterName: clickhouse
keeperName: clickhouse-keeper
serviceName: clickhouse-clickhouse-headless
storageClass: managed-nfs-storage
storage: 50Gi
keeperStorage: 5Gi
keeperReplicas: 3
resources:
cpuRequest: "1"
memoryRequest: 4Gi
memoryLimit: 8Gi
database: otel
user: default
credentialsSecret: clickhouse-credentials
credentialsKey: password
s3:
enabled: false
endpoint: "http://10.255.241.30:30080"
bucket: clickhouse
secret: clickhouse-s3
moveFactor: 0.2
ttl:
logs: 720h
traces: 336h
@@ -0,0 +1,42 @@
{{- if .Values.clusterConfig.argo.enabled }}
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: clickhouse
namespace: argocd
annotations:
argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
destination:
namespace: clickhouse
server: 'https://kubernetes.default.svc'
sources:
- repoURL: {{ .Values.clusterConfig.manifests }}
targetRevision: HEAD
path: helmfile.d
plugin:
name: helmfile-cmp
env:
- name: CLUSTER_NAME
value: {{ .Values.clusterConfig.cluster }}
- name: HELMFILE_ENVIRONMENT
value: default
- name: HELMFILE_FILE_PATH
value: clickhouse.yaml.gotmpl
project: sys
syncPolicy:
managedNamespaceMetadata:
labels:
component: sys
syncOptions:
- CreateNamespace=true
- ApplyOutOfSyncOnly=true
- ServerSideApply=true
{{- if .Values.clickhouse.autosync }}
automated:
prune: true
# selfHeal: false
{{- end }}
{{- end }}
@@ -0,0 +1,25 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-prometheus
namespace: clickhouse
spec:
description: Allow Grafana queries and Prometheus metric scraping
endpointSelector:
matchLabels: {}
ingress:
- fromEndpoints:
- matchLabels:
io.kubernetes.pod.namespace: prometheus
toPorts:
- ports:
- port: "9000"
protocol: TCP
- port: "8123"
protocol: TCP
- port: "8080"
protocol: TCP
- port: "9363"
protocol: TCP
{{- end }}
@@ -0,0 +1,15 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-intra
namespace: clickhouse
spec:
description: Allow all intra-namespace traffic (operator, ClickHouse servers, Keeper)
endpointSelector:
matchLabels: {}
ingress:
- fromEndpoints:
- matchLabels:
io.kubernetes.pod.namespace: clickhouse
{{- end }}
@@ -0,0 +1,21 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-otel-write
namespace: clickhouse
spec:
description: Allow the opentelemetry collector to write to ClickHouse
endpointSelector:
matchLabels: {}
ingress:
- fromEndpoints:
- matchLabels:
io.kubernetes.pod.namespace: otel
toPorts:
- ports:
- port: "9000"
protocol: TCP
- port: "8123"
protocol: TCP
{{- end }}
@@ -0,0 +1,83 @@
imageTag: "24.8"
clickhouse:
enabled: true
meta:
name: {{ .Values.clickhouse.clusterName }}
spec:
shards: 1
replicas: 1
podTemplate:
nodeHostnameKey: kubernetes.io/hostname
settings:
defaultUserPassword:
secret:
name: {{ .Values.clickhouse.credentialsSecret }}
key: {{ .Values.clickhouse.credentialsKey }}
# Single replica: no cross-replica database sync needed. The operator's sync also
# breaks on the OTel-created (non-replicated) `otel` database. Revisit for multi-replica HA.
enableDatabaseSync: false
{{- if .Values.clickhouse.s3.enabled }}
extraConfig:
storage_configuration:
disks:
s3:
type: s3
endpoint: {{ .Values.clickhouse.s3.endpoint }}/{{ .Values.clickhouse.s3.bucket }}/data/
use_environment_credentials: true
policies:
tiered:
volumes:
hot:
disk: default
cold:
disk: s3
move_factor: {{ .Values.clickhouse.s3.moveFactor }}
merge_tree:
storage_policy: tiered
{{- end }}
containerTemplate:
resources:
requests:
cpu: {{ .Values.clickhouse.resources.cpuRequest }}
memory: {{ .Values.clickhouse.resources.memoryRequest }}
limits:
memory: {{ .Values.clickhouse.resources.memoryLimit }}
{{- if .Values.clickhouse.s3.enabled }}
env:
- name: AWS_ACCESS_KEY_ID
valueFrom:
secretKeyRef:
name: {{ .Values.clickhouse.s3.secret }}
key: AWS_ACCESS_KEY_ID
- name: AWS_SECRET_ACCESS_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.clickhouse.s3.secret }}
key: AWS_SECRET_ACCESS_KEY
{{- end }}
dataVolumeClaimSpec:
accessModes:
- ReadWriteOnce
storageClassName: {{ .Values.clickhouse.storageClass }}
resources:
requests:
storage: {{ .Values.clickhouse.storage }}
keeper:
enabled: true
meta:
name: {{ .Values.clickhouse.keeperName }}
spec:
replicas: {{ .Values.clickhouse.keeperReplicas }}
podTemplate:
nodeHostnameKey: kubernetes.io/hostname
podDisruptionBudget:
maxUnavailable: 1
dataVolumeClaimSpec:
accessModes:
- ReadWriteOnce
storageClassName: {{ .Values.clickhouse.storageClass }}
resources:
requests:
storage: {{ .Values.clickhouse.keeperStorage }}
@@ -0,0 +1 @@
# clickhouse-operator-helm values (chart defaults)
+1 -1
View File
@@ -38,4 +38,4 @@ volumeMounts:
readOnly: true
subPath: appsettings.json
image:
tag: e2ec1157-debug
tag: 6442206c-debug
+1 -1
View File
@@ -1,6 +1,6 @@
fullnameOverride: staging-docs
image:
tag: "9fe77f4b-debug"
tag: "72b01c0b-debug"
ingress:
enabled: true
className: "haproxy"
+1 -1
View File
@@ -1,4 +1,4 @@
loki:
enabled: true
enabled: false
autosync: false
+1 -1
View File
@@ -1,5 +1,5 @@
loki:
enabled: true
enabled: false
autosync: true
compactor: true
s3:
+1 -1
View File
@@ -1,6 +1,6 @@
replicaCount: 1
image:
tag: "ae027c94-debug"
tag: "7080a0bd-debug"
env:
- name: APP_VERSION
value: "0.0.0"
@@ -4,6 +4,14 @@ image:
service:
type: LoadBalancer
loadBalancerIP: 10.255.241.12
{{- if .Values.clickhouse.enabled }}
extraEnvs:
- name: CH_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.clickhouse.credentialsSecret }}
key: {{ .Values.clickhouse.credentialsKey }}
{{- end }}
config:
# receivers:
# prometheus/collector:
@@ -31,6 +39,20 @@ config:
endpoint: http://loki-write-headless.loki:3100/otlp
tls:
insecure: true
{{- if .Values.clickhouse.enabled }}
clickhouse:
endpoint: tcp://{{ .Values.clickhouse.serviceName }}.clickhouse.svc:9000?dial_timeout=10s
database: {{ .Values.clickhouse.database }}
username: {{ .Values.clickhouse.user }}
password: ${env:CH_PASSWORD}
create_schema: true
logs_table_name: otel_logs
traces_table_name: otel_traces
ttl: {{ .Values.clickhouse.ttl.logs }}
timeout: 10s
retry_on_failure:
enabled: true
{{- end }}
debug/metrics:
verbosity: detailed
debug/traces:
@@ -45,8 +67,7 @@ config:
traces:
receivers: [otlp] # zipkin
processors: [batch]
exporters: [otlp]
# exporters: [otlphttp/traces,debug/traces]
exporters: [clickhouse]
metrics:
receivers: [otlp,prometheus] # prometheus/collector
processors: [batch]
@@ -55,8 +76,7 @@ config:
logs:
receivers: [otlp]
processors: [batch]
exporters: [otlphttp/logs]
# exporters: [otlphttp/logs,debug/logs]
exporters: [clickhouse]
ports:
metrics:
enabled: true
@@ -11,10 +11,7 @@ prometheus:
persistence: true
plugins:
- volkovlabs-image-panel
- marcusolsson-static-datasource
- marcusolsson-calendar-panel
- grafana-clock-panel
- redis-datasource
thanos:
enabled: true
coredns:
@@ -108,11 +108,43 @@ grafana:
defaultDashboardsEnabled: {{ .Values.prometheus.grafana.defaultDashboardsEnabled }}
deploymentStrategy:
type: Recreate
{{- if .Values.prometheus.grafana.plugins }}
{{- if .Values.prometheus.grafana.persistence }}
# This init container re-syncs the DB admin password
# to the secret before Grafana starts, so the reload can never 401 again.
extraInitContainers:
- name: sync-admin-password
image: docker.io/grafana/grafana:13.0.1-security-01
command:
- /bin/sh
- -c
- grafana cli --homepath=/usr/share/grafana admin reset-admin-password "{{ `$GF_ADMIN_PW` }}" || true
env:
- name: GF_PATHS_DATA
value: /var/lib/grafana
- name: GF_ADMIN_PW
valueFrom:
secretKeyRef:
name: prometheus-grafana
key: admin-password
volumeMounts:
- name: storage
mountPath: /var/lib/grafana
{{- end }}
{{- if or .Values.prometheus.grafana.plugins .Values.clickhouse.enabled }}
plugins:
{{- range .Values.prometheus.grafana.plugins }}
- {{ . }}
{{- end }}
{{- if .Values.clickhouse.enabled }}
- grafana-clickhouse-datasource
{{- end }}
{{- end }}
{{- if .Values.clickhouse.enabled }}
envValueFrom:
CLICKHOUSE_PASSWORD:
secretKeyRef:
name: {{ .Values.clickhouse.credentialsSecret }}
key: {{ .Values.clickhouse.credentialsKey }}
{{- end }}
grafana.ini:
server:
@@ -219,9 +251,34 @@ grafana:
createPrometheusReplicasDatasources: false
label: grafana_datasource
{{ end }}
{{- if or .Values.loki.enabled .Values.prometheus.additionalDataSources }}
{{- if or .Values.loki.enabled .Values.clickhouse.enabled .Values.prometheus.additionalDataSources }}
additionalDataSources:
{{- end }}
{{- if .Values.clickhouse.enabled }}
- name: ClickHouse
type: grafana-clickhouse-datasource
uid: clickhouse
access: proxy
editable: false
jsonData:
host: {{ .Values.clickhouse.serviceName }}.clickhouse.svc
port: 9000
protocol: native
username: {{ .Values.clickhouse.user }}
defaultDatabase: {{ .Values.clickhouse.database }}
logs:
defaultDatabase: {{ .Values.clickhouse.database }}
defaultTable: otel_logs
otelEnabled: true
otelVersion: latest
traces:
defaultDatabase: {{ .Values.clickhouse.database }}
defaultTable: otel_traces
otelEnabled: true
otelVersion: latest
secureJsonData:
password: ${CLICKHOUSE_PASSWORD}
{{- end }}
{{- if .Values.tempo.enabled }}
- name: Tempo
type: tempo
+3 -1
View File
@@ -30,11 +30,13 @@ spec:
protocol: UDP
- port: "53"
protocol: TCP
# RabbitMQ on oceanbox via NodePort (prod: 30672, staging: 31672)
# RabbitMQ on oceanbox: NodePorts (30672/31672) or MetalLB IPs on standard port 5672
- toCIDR:
- 10.255.241.0/24
toPorts:
- ports:
- port: "5672"
protocol: TCP
- port: "30672"
protocol: TCP
- port: "31672"
+1 -24
View File
@@ -1,7 +1,6 @@
# TEMPORAL_NAMESPACE : {env}-atlantis
# ARCHIVE_PVC : the queue's archive PVC (prod+beta -> prod-queue, staging -> dev-queue)
# PROTEUS_EVENTS_QUEUE : {env}-proteus-job-events (queue the env's Atlantis binding reads)
# RABBITMQ_CONNSTRING secret : the broker that env's Atlantis consumes from (prod+beta share prod)
# Status/inbox/quota now flow via Temporal activities to the Atlantis notify worker; no RabbitMQ.
# ---
# apiVersion: temporal.io/v1alpha1
# kind: WorkerDeployment
@@ -39,13 +38,6 @@
# value: prod
# - name: ARCHIVE_PVC
# value: prod-queue-ceph-archives
# - name: PROTEUS_EVENTS_QUEUE
# value: prod-proteus-job-events
# - name: RABBITMQ_CONNSTRING
# valueFrom:
# secretKeyRef:
# name: proteus-rabbitmq-prod
# key: connString
# ---
# apiVersion: temporal.io/v1alpha1
# kind: WorkerDeployment
@@ -84,14 +76,6 @@
# # beta schedules into prod-queue (same as prod), so the same archive PVC.
# - name: ARCHIVE_PVC
# value: prod-queue-ceph-archives
# - name: PROTEUS_EVENTS_QUEUE
# value: beta-proteus-job-events
# # beta shares the prod broker (its Atlantis binding uses prod-atlantis-rabbitmq).
# - name: RABBITMQ_CONNSTRING
# valueFrom:
# secretKeyRef:
# name: proteus-rabbitmq-prod
# key: connString
# ---
apiVersion: temporal.io/v1alpha1
kind: WorkerDeployment
@@ -129,10 +113,3 @@ spec:
value: staging
- name: ARCHIVE_PVC
value: dev-queue-ceph-archives
- name: PROTEUS_EVENTS_QUEUE
value: staging-proteus-job-events
- name: RABBITMQ_CONNSTRING
valueFrom:
secretKeyRef:
name: proteus-rabbitmq-staging
key: connString
+1 -1
View File
@@ -1,7 +1,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
tag: e2ec1157-debug
tag: 6442206c-debug
podAnnotations:
dapr.io/enabled: "true"
dapr.io/app-id: "staging-sorcerer"
+1 -1
View File
@@ -1,5 +1,5 @@
tempo:
enabled: true
enabled: false
autosync: false
s3:
endpoint: 10.255.241.30:30080
+1 -1
View File
@@ -6,7 +6,7 @@ image:
# -- image pull policy
# pullPolicy:
# -- Overrides the image tag
tag: "3.1.0"
tag: "3.2.0"
replicaCount: 1