Compare commits

...

102 Commits

Author SHA1 Message Date
renovate-bot 685104ee30 Update cert-manager Docker tag to v1.21.0
renovate/stability-days Updates have not met minimum release age requirement
2026-07-26 00:04:07 +00:00
Gitea Actions 015b9d5833 ci(prod): deploy atlantis v2.22.0 2026-07-24 16:23:26 +00:00
Gitea Actions 624743d7d1 ci(prod): deploy codex v2.22.0 2026-07-24 16:22:47 +00:00
Gitea Actions 60168571fe ci(staging): deploy atlantis 29de0c67-debug 2026-07-24 16:22:30 +00:00
Gitea Actions 1ed8bc13a1 ci(prod): deploy sorcerer v2.22.0 2026-07-24 16:21:29 +00:00
mrtz 95a8d3291a proteus: Bump concurrent activites to 10 2026-07-24 15:25:25 +02:00
Gitea Actions 3de27b278b ci(staging): deploy proteus 7b97e45c-debug 2026-07-24 13:08:12 +00:00
mrtz 0e8585572c chore(proteus): Bump staging to 2.21.0 2026-07-24 14:52:17 +02:00
mrtz 24f1f2fd2c proteus/sorcerer: Clean up unused env's 2026-07-24 14:21:27 +02:00
mrtz 8e410f761a proteus: Deploy for staging 2026-07-24 14:10:42 +02:00
Gitea Actions 16178cf2d6 ci(staging): deploy atlantis 9138d67d-debug 2026-07-24 11:33:34 +00:00
Gitea Actions 15fe5001b2 ci(staging): deploy codex 9138d67d-debug 2026-07-24 11:32:35 +00:00
Gitea Actions be09398708 ci(staging): deploy sorcerer 9138d67d-debug 2026-07-24 11:31:18 +00:00
Gitea Actions 06a7d1b923 ci(staging): deploy makai e926ae4b-debug 2026-07-24 07:24:44 +00:00
Gitea Actions 5b868f2c5c ci(prod): deploy atlantis v2.21.0 2026-07-23 15:23:32 +00:00
Gitea Actions b4a0195b23 ci(prod): deploy codex v2.21.0 2026-07-23 15:22:57 +00:00
Gitea Actions b5ee9f199b ci(prod): deploy sorcerer v2.21.0 2026-07-23 15:21:44 +00:00
Gitea Actions 6357a0908d ci(staging): deploy atlantis 7be05d4b-debug 2026-07-23 15:19:46 +00:00
Gitea Actions eb7d30ca6c ci(prod): deploy atlantis v2.20.0 2026-07-23 15:14:32 +00:00
Gitea Actions 15ef00e534 ci(staging): deploy atlantis dfc45d69-debug 2026-07-23 15:14:04 +00:00
Gitea Actions 00657dcd34 ci(prod): deploy codex v2.20.0 2026-07-23 15:13:59 +00:00
Gitea Actions aad04e120b ci(prod): deploy sorcerer v2.20.0 2026-07-23 15:12:32 +00:00
mrtz 59d8e157e2 fix: Migrate Hanna 2026-07-23 13:29:20 +02:00
Gitea Actions b7a4c814b3 ci(staging): deploy makai 015bc3c1-debug 2026-07-23 07:45:34 +00:00
Gitea Actions 5de65dd94b ci(staging): deploy makai 57120337-debug 2026-07-23 07:26:06 +00:00
mrtz 560d199980 Merge pull request 'Update spegel Docker tag to v0.7.3' (#252) from renovate/spegel-0.x into main
Reviewed-on: #252
2026-07-21 17:42:06 +00:00
mrtz c548b3e15f chore(ingest): Bump to 0.1.6 2026-07-21 14:02:30 +02:00
mrtz b5c24dc26f feat: Add uptermd chart 2026-07-21 14:00:23 +02:00
Gitea Actions 7369ad3c8a ci(staging): deploy makai cccb5bb6-debug 2026-07-21 11:27:21 +00:00
Gitea Actions d0f54c9033 ci(staging): deploy atlantis 72a2d2a8-debug 2026-07-21 10:53:56 +00:00
Gitea Actions 2badb27df6 ci(prod): deploy atlantis v2.19.0 2026-07-21 10:50:22 +00:00
Gitea Actions a446325956 ci(staging): deploy atlantis ab7e2d90-debug 2026-07-21 10:50:03 +00:00
Gitea Actions eff44720a4 ci(prod): deploy codex v2.19.0 2026-07-21 10:49:52 +00:00
Gitea Actions 235fc7b95b ci(prod): deploy sorcerer v2.19.0 2026-07-21 10:48:26 +00:00
Gitea Actions ddcf43420e ci(staging): deploy atlantis fbc42464-debug 2026-07-21 10:45:29 +00:00
Gitea Actions e46b148a8f ci(staging): deploy makai b070a7e1-debug 2026-07-21 10:10:52 +00:00
Gitea Actions 8888bf63d9 ci(staging): deploy docs 511c128c-debug 2026-07-20 12:04:23 +00:00
Gitea Actions cd2983c683 ci(staging): deploy makai 8cd68c76-debug 2026-07-20 11:48:32 +00:00
Gitea Actions c684615012 ci(staging): deploy docs 2be5a0d0-debug 2026-07-20 09:28:46 +00:00
Gitea Actions ad9bb1eaf9 ci(staging): deploy makai bb0277b2-debug 2026-07-20 09:19:12 +00:00
Gitea Actions 658d09c113 ci(staging): deploy makai 6237a83d-debug 2026-07-20 09:02:59 +00:00
Gitea Actions 1ffcdca37e ci(staging): deploy makai f9688883-debug 2026-07-20 08:55:29 +00:00
mrtz 5be14ba40d Merge pull request 'Update Helm release umami to v7.10.10' (#259) from renovate/umami-7.x into main
Reviewed-on: #259
2026-07-19 08:51:28 +00:00
mrtz df7c242782 Merge pull request 'Update kubernetes-ingress Docker tag to v1.52.1' (#251) from renovate/kubernetes-ingress-1.x into main
Reviewed-on: #251
2026-07-19 08:51:05 +00:00
mrtz 0344d7207c Merge pull request 'Update Helm release argo-workflows to v1.0.19' (#258) from renovate/argo-workflows-1.x into main
Reviewed-on: #258
2026-07-19 08:50:52 +00:00
renovate-bot c51971f31e Update Helm release umami to v7.10.10
renovate/stability-days Updates have met minimum release age requirement
2026-07-19 00:03:39 +00:00
renovate-bot f7d6f95fa2 Update Helm release argo-workflows to v1.0.19
renovate/stability-days Updates have met minimum release age requirement
2026-07-19 00:03:12 +00:00
Gitea Actions d26d1f13b3 ci(staging): deploy docs 43010743-debug 2026-07-17 12:58:29 +00:00
Gitea Actions d4db2c5fe4 ci(staging): deploy docs cdffe8bf-debug 2026-07-17 12:39:35 +00:00
Gitea Actions 55d65c6537 ci(staging): deploy docs a9f5dfd5-debug 2026-07-17 12:27:14 +00:00
Gitea Actions 08e28d5d1a ci(staging): deploy makai 311b182e-debug 2026-07-17 10:52:47 +00:00
Gitea Actions 06ecb840c5 ci(staging): deploy docs 4c54936f-debug 2026-07-17 10:47:21 +00:00
Gitea Actions f71a42850f ci(staging): deploy docs b4e2925a-debug 2026-07-17 10:37:10 +00:00
Gitea Actions a00b2bc41d ci(staging): deploy docs eb25dfd3-debug 2026-07-17 07:58:23 +00:00
Gitea Actions 47131ab623 ci(staging): deploy docs 7bef33c2-debug 2026-07-17 07:52:35 +00:00
Gitea Actions 460e91e89c ci(staging): deploy docs a8230dda-debug 2026-07-17 07:46:44 +00:00
Gitea Actions 9a6c286256 ci(staging): deploy makai fcb6dc37-debug 2026-07-17 06:51:42 +00:00
Gitea Actions 282cd9286f ci(staging): deploy makai 55f38e78-debug 2026-07-16 18:18:48 +00:00
Gitea Actions b27a419158 ci(staging): deploy makai 10e6952d-debug 2026-07-16 08:35:24 +00:00
Gitea Actions a7ccd3b123 ci(staging): deploy makai 8ac265da-debug 2026-07-16 08:10:57 +00:00
Gitea Actions d4e0d09fa9 ci(prod): deploy atlantis v2.18.0 2026-07-15 09:02:38 +00:00
Gitea Actions 323b710a0b ci(prod): deploy codex v2.18.0 2026-07-15 09:02:06 +00:00
Gitea Actions 626d9125fa ci(staging): deploy atlantis 79c4cf19-debug 2026-07-15 09:01:39 +00:00
Gitea Actions 41dd40c7b6 ci(prod): deploy sorcerer v2.18.0 2026-07-15 09:00:45 +00:00
mrtz 5f3a97c525 Merge pull request 'Update Helm release kube-prometheus-stack to v86.3.2' (#242) from renovate/kube-prometheus-stack-86.x into main
Reviewed-on: #242
2026-07-15 06:46:03 +00:00
Gitea Actions b5468a1100 ci(staging): deploy makai 5d6b8f14-debug 2026-07-14 15:31:32 +00:00
Gitea Actions f07ac5158c ci(staging): deploy makai 8393da43-debug 2026-07-14 08:28:41 +00:00
Gitea Actions 892e326a8d ci(staging): deploy makai e251c9d0-debug 2026-07-14 08:03:03 +00:00
Gitea Actions 4dda76f6a5 ci(staging): deploy atlantis 3806978d-debug 2026-07-14 07:43:04 +00:00
Gitea Actions 3f255816b1 ci(staging): deploy makai e8bb3758-debug 2026-07-14 07:22:18 +00:00
Gitea Actions 9477342a70 ci(staging): deploy makai ec64143a-debug 2026-07-13 16:30:25 +00:00
Gitea Actions 3f6e99c34f ci(staging): deploy makai 1f554dbc-debug 2026-07-13 16:20:49 +00:00
Gitea Actions 5c72985801 ci(staging): deploy makai cb4d768e-debug 2026-07-13 13:56:17 +00:00
mrtz 8a88f21e14 ingest: Bump to 0.1.5 2026-07-13 15:38:38 +02:00
Gitea Actions bd3bbf66ec ci(staging): deploy makai 6d2a40fc-debug 2026-07-13 13:34:14 +00:00
mrtz dac7f16f04 argocd: Pass dex env correctly 2026-07-13 09:29:28 +02:00
mrtz acf97bb584 Merge pull request 'Update Helm release argo-cd to v9.7.1' (#253) from renovate/argo-cd-9.x into main
Reviewed-on: #253
2026-07-13 05:46:41 +00:00
mrtz 9fccca2284 Merge pull request 'Update Helm release openfga to v0.3.10' (#250) from renovate/openfga-0.x into main
Reviewed-on: #250
2026-07-12 09:07:26 +00:00
mrtz dede8518f2 Merge pull request 'Update Helm release plugin-barman-cloud to v0.7.0' (#238) from renovate/plugin-barman-cloud-0.x into main
Reviewed-on: #238
2026-07-12 09:06:31 +00:00
mrtz 7d26a7ec39 ingest: Bump to 0.1.4 2026-07-09 22:25:50 +02:00
Gitea Actions 3ba39a584e ci(staging): deploy makai 49eca59f-debug 2026-07-09 10:31:30 +00:00
Gitea Actions bff34addae ci(staging): deploy docs 6f4cfb45-debug 2026-07-09 09:24:51 +00:00
mrtz 421c7b4a7c ingest: Bump to 0.1.3 2026-07-09 10:36:48 +02:00
mrtz e09f1c19ce ingest: Bump to 0.1.2 2026-07-09 10:05:08 +02:00
mrtz a5498c0954 temporal: Support huge cookie 2026-07-08 22:57:31 +02:00
mrtz 3cc00d5a83 temporal: Add argo annotations 2026-07-08 22:47:57 +02:00
mrtz 06960f3a1d temporal: Add HA setup 2026-07-08 22:42:59 +02:00
mrtz ec5e227994 hel1: Allow mx.itpartner.no 2026-07-08 15:46:20 +02:00
mrtz 78fb7c27d9 gitea: Bump to 1.26.4 2026-07-08 15:41:26 +02:00
mrtz dfe6fa412b gitea: Add mail 2026-07-08 15:36:29 +02:00
Gitea Actions 9ec7603348 ci(staging): deploy makai 1d24620c-debug 2026-07-08 13:25:47 +00:00
mrtz 026f6dccb8 ingest: Remove norkyst from F# 2026-07-08 11:21:39 +02:00
mrtz d3c3ba2191 ingest: Move norkyst to python 2026-07-08 11:17:10 +02:00
Gitea Actions ab9bb43beb ci(staging): deploy makai 71d56217-debug 2026-07-07 14:50:29 +00:00
mrtz d46bbca804 Merge pull request 'Update Helm release velero to v12.1.0' (#255) from renovate/velero-12.x into main
Reviewed-on: #255
2026-07-07 11:43:55 +00:00
renovate-bot 50e5a2952e Update Helm release velero to v12.1.0
renovate/stability-days Updates have met minimum release age requirement
2026-07-07 11:38:32 +00:00
renovate-bot 764a922dbe Update Helm release argo-cd to v9.7.1
renovate/stability-days Updates have met minimum release age requirement
2026-07-07 11:36:20 +00:00
renovate-bot 288a474c85 Update spegel Docker tag to v0.7.3
renovate/stability-days Updates have not met minimum release age requirement
2026-07-07 11:36:13 +00:00
renovate-bot 3a4bb4d0d7 Update kubernetes-ingress Docker tag to v1.52.1
renovate/stability-days Updates have not met minimum release age requirement
2026-07-07 11:36:05 +00:00
renovate-bot 836b1078fb Update Helm release openfga to v0.3.10
renovate/stability-days Updates have met minimum release age requirement
2026-07-07 11:35:57 +00:00
renovate-bot 754c43340e Update Helm release kube-prometheus-stack to v86.3.2
renovate/stability-days Updates have met minimum release age requirement
2026-06-28 00:03:39 +00:00
renovate-bot 10542a23bf Update Helm release plugin-barman-cloud to v0.7.0
renovate/stability-days Updates have met minimum release age requirement
2026-06-16 16:47:34 +00:00
52 changed files with 517 additions and 175 deletions
+2 -2
View File
@@ -4,10 +4,10 @@ description: Atlantis map and simulation service
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v2.17.1
version: v2.22.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v2.17.1
appVersion: v2.22.0
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
+1 -1
View File
@@ -4,7 +4,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
tag: v2.17.1
tag: v2.22.0
pullPolicy: IfNotPresent
init:
enabled: false
+2 -2
View File
@@ -13,9 +13,9 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: v2.17.1
version: v2.22.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "v2.17.1"
appVersion: "v2.22.0"
+1 -1
View File
@@ -10,7 +10,7 @@ image:
# This sets the pull policy for images.
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: v2.17.1
tag: v2.22.0
# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
imagePullSecrets:
- name: gitlab-pull-secret
+2 -2
View File
@@ -4,10 +4,10 @@ description: A Helm chart for Kubernetes
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
version: v2.17.1
version: v2.22.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application.
appVersion: v2.17.1
appVersion: v2.22.0
dependencies:
- name: diagrid-dashboard
version: "0.1.0"
+1 -1
View File
@@ -5,7 +5,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
tag: v2.17.1
tag: v2.22.0
pullPolicy: IfNotPresent
init:
enabled: false
+2 -2
View File
@@ -15,7 +15,7 @@ releases:
- name: argocd
namespace: argocd
chart: argo/argo-cd
version: 9.5.21
version: 9.7.1
condition: argo.enabled
values:
- ../values/argo/values/argocd.yaml.gotmpl
@@ -43,7 +43,7 @@ releases:
- name: argo-workflows
namespace: argocd
chart: argo/argo-workflows
version: 1.0.18
version: 1.0.19
condition: argo.workflows.enabled
missingFileHandler: Info
- name: manifests
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: cert-manager
namespace: cert-manager
chart: cert-manager/cert-manager
version: v1.20.2
version: v1.21.0
condition: cert_manager.enabled
values:
- ../values/cert-manager/values/cert-manager.yaml.gotmpl
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: ingress-haproxy
namespace: ingress-haproxy
chart: haproxytech/kubernetes-ingress
version: 1.52.0
version: 1.52.1
condition: haproxy.enabled
values:
- ../values/ingress-haproxy/values/ingress-haproxy.yaml.gotmpl
+1 -1
View File
@@ -16,7 +16,7 @@ releases:
namespace: {{ .Environment.Name }}-openfga
{{- end }}
chart: openfga/openfga
version: 0.3.9
version: 0.3.10
condition: openfga.enabled
values:
- ../values/openfga/values/values.yaml
+1 -1
View File
@@ -27,7 +27,7 @@ releases:
- name: plugin-barman-cloud
namespace: cnpg
chart: cloudnative-pg/plugin-barman-cloud
version: 0.6.0
version: 0.7.0
condition: postgres_operator.enabled
values:
- ../values/postgres-operator/values/plugin-barman-cloud.yaml.gotmpl
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: prometheus
namespace: prometheus
chart: prometheus/kube-prometheus-stack
version: 86.2.0
version: 86.3.2
condition: prometheus.enabled
values:
- ../values/prometheus/values/prometheus.yaml.gotmpl
+1
View File
@@ -15,6 +15,7 @@ releases:
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/proteus/env.yaml.gotmpl
- ../values/proteus/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
- ../values/proteus/values/values-staging.yaml
hooks:
- events: [ prepare, cleanup ]
showlogs: true
+1 -1
View File
@@ -13,7 +13,7 @@ releases:
- name: spegel
namespace: spegel
chart: spegel/spegel
version: 0.7.1
version: 0.7.3
condition: spegel.enabled
values:
- ../values/spegel/values/spegel.yaml.gotmpl
+1 -1
View File
@@ -14,7 +14,7 @@ releases:
- name: umami
namespace: analytics
chart: umami/umami
version: 7.9.4
version: 7.10.10
condition: umami.enabled
values:
- ../values/umami/values/values.yaml
+43
View File
@@ -0,0 +1,43 @@
bases:
- ../envs/environments.yaml.gotmpl
repositories:
- name: upterm
url: https://upterm.dev
commonLabels:
tier: system
releases:
- name: uptermd
namespace: uptermd
chart: upterm/uptermd
version: 0.2.0
condition: uptermd.enabled
values:
- ../values/uptermd/values/values.yaml
- ../values/uptermd/values/values-{{ .Environment.Name }}.yaml
postRenderer: ../bin/kustomizer
postRendererArgs:
- ../values/uptermd/kustomize/{{ .Environment.Name }}
missingFileHandler: Info
- name: manifests
namespace: uptermd
chart: manifests
condition: uptermd.enabled
missingFileHandler: Info
values:
- ../values/env.yaml
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
- ../values/uptermd/env.yaml.gotmpl
- ../values/uptermd/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
hooks:
- events: [ prepare, cleanup ]
showlogs: true
command: ../bin/helmify
args:
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
- '{{`{{ .Release.Chart }}`}}'
- '{{`{{ .Environment.Name }}`}}'
- ../values/uptermd/manifests
- manifests
+1 -1
View File
@@ -15,7 +15,7 @@ releases:
- name: velero
namespace: velero
chart: velero/velero
version: 12.0.3
version: 12.1.0
condition: velero.enabled
values:
- ../values/velero/values/velero.yaml.gotmpl
+1
View File
@@ -27,5 +27,6 @@ argocd:
image: "git.oceanbox.io/platform/manifests/helmfile-cmp:latest"
imagePullSecrets:
- gitlab-pull-secret
webhookSecret: ""
additional_rbac_settings:
- g, "eb17a659-4ce6-41bc-9153-d9b117c44479", role:org-admin
+8 -21
View File
@@ -49,8 +49,8 @@ configs:
name: {{ .name }}
config:
issuer: https://login.microsoftonline.com/{{ .tenant }}/v2.0
clientID: ${{ .name | replace "-" "_" }}_client_id
clientSecret: ${{ .name | replace "-" "_" }}_client_secret
clientID: ${{ .secret_ref.name }}:client_id
clientSecret: ${{ .secret_ref.name }}:client_secret
insecureSkipEmailVerified: true
requestedIDTokenClaims:
groups:
@@ -62,7 +62,7 @@ configs:
- email
- groups
staticClients:
- id: ${{ .name | replace "-" "_" }}_client_id
- id: ${{ .secret_ref.name }}:client_id
name: Kubernetes
# These are kubectl oidc plugin internal URLs
redirectURIs:
@@ -99,6 +99,11 @@ configs:
argo-helm:
type: helm
url: https://argoproj.github.io/argo-helm
{{- if .Values.argocd.webhookSecret }}
secret:
extra:
webhook.gitea.secret: {{ .Values.argocd.webhookSecret }}
{{- end }}
# UI changes based on env
styles: |
/* blue, orange, red depending on env */
@@ -129,29 +134,11 @@ controller:
cpu: {{ .Values.argocd.resources.controller.cpu | default "250m" }}
memory: {{ .Values.argocd.resources.controller.memory | default "1000Mi" }}
# Mount azure ca as file for SAML auth
dex:
metrics:
enabled: true
serviceMonitor:
enabled: true
{{- with .Values.clusterConfig.oidc }}
env:
{{- range . }}
{{- if eq .group "devel" }}
- name: {{ .name | replace "-" "_" }}_client_secret
valueFrom:
secretKeyRef:
name: {{ .secret_ref.name }}
key: client_secret
- name: {{ .name | replace "-" "_" }}_client_id
valueFrom:
secretKeyRef:
name: {{ .secret_ref.name }}
key: client_id
{{- end }}
{{- end }}
{{- end }}
redis:
metrics:
@@ -3,10 +3,6 @@ kind: ConfigMap
metadata:
name: staging-atlantis-actor-config
data:
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.5.1"
XTRACT_QUEUE: "dev-queue"
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.5.1"
PLUME_QUEUE: "dev-queue"
TEMPORAL_ADDRESS: "temporal-frontend.temporal:7233"
TEMPORAL_ADDRESS: "temporal-grpc.ekman.oceanbox.io:443"
TEMPORAL_TLS: "true"
TEMPORAL_NAMESPACE: "staging-atlantis"
TEMPORAL_TASK_QUEUE: "atlantis"
@@ -0,0 +1,18 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-temporal
namespace: {{ .Release.Namespace }}
spec:
endpointSelector:
matchLabels:
app.kubernetes.io/name: atlantis
egress:
- toFQDNs:
- matchName: temporal-grpc.ekman.oceanbox.io
toPorts:
- ports:
- port: "443"
protocol: TCP
{{- end }}
@@ -1,7 +1,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
tag: 6442206c-debug
tag: 29de0c67-debug
podAnnotations:
dapr.io/app-id: "staging-atlantis"
env:
+1 -1
View File
@@ -38,4 +38,4 @@ volumeMounts:
readOnly: true
subPath: appsettings.json
image:
tag: 6442206c-debug
tag: 9138d67d-debug
+1 -1
View File
@@ -1,6 +1,6 @@
fullnameOverride: staging-docs
image:
tag: "72b01c0b-debug"
tag: "511c128c-debug"
ingress:
enabled: true
className: "haproxy"
+10 -4
View File
@@ -3,7 +3,7 @@ replicaCount: 1
image:
registry: "docker.gitea.com"
repository: gitea
tag: "1.26.2"
tag: "1.26.4"
resources:
requests:
@@ -75,10 +75,11 @@ gitea:
USERNAME: "nickname"
mailer:
ENABLED: true
FROM: "gitea@oceanbox.io"
PROTOCOL: "smtp"
SMTP_ADDR: "postfix-mail.postfix.svc.cluster.local"
FROM: "\"Oceanbox Gitea\" <no-reply@oceanbox.io>"
PROTOCOL: "smtp+starttls"
SMTP_ADDR: "mx.itpartner.no"
SMTP_PORT: 587
USER: "no-reply@oceanbox.io"
database:
DB_TYPE: postgres
MAX_OPEN_CONNS: 90
@@ -104,6 +105,11 @@ gitea:
secretKeyRef:
name: gitea-s3
key: secret_key
- name: GITEA__mailer__PASSWD
valueFrom:
secretKeyRef:
name: gitea-smtp
key: password
- name: GITEA__DATABASE__PASSWD
valueFrom:
secretKeyRef:
+1 -1
View File
@@ -118,6 +118,7 @@ configMaps:
"elianne.ersdal@oceanbox.io",
"hanskristian.djuve@oceanbox.io",
"erlend.mundal@oceanbox.io",
"hanna.fagrell@oceanbox.io",
],
"group:manager": [
"svenn.hanssen@oceanbox.io",
@@ -130,7 +131,6 @@ configMaps:
"group:intern": [
"haavahak@stud.ntnu.no",
"haavahak@ntnu.no",
"hanna.fagrell@oceanbox.io",
],
"group:ceph": [
"jonas.juselius@oceanbox.io",
@@ -19,7 +19,7 @@ spec:
runAsGroup: 0
containers:
- name: ingest-py
image: git.oceanbox.io/oceanbox/churn/ingest-py:v2.3.11
image: git.oceanbox.io/oceanbox/churn/ingest-py:v0.1.6
resources:
requests:
memory: 512Mi
@@ -19,7 +19,7 @@ spec:
runAsGroup: 0
containers:
- name: ingest
image: git.oceanbox.io/oceanbox/churn/ingest:v2.3.11
image: git.oceanbox.io/oceanbox/churn/ingest:v0.1.6
resources:
requests:
memory: 512Mi
+1 -1
View File
@@ -1,6 +1,6 @@
replicaCount: 1
image:
tag: "7080a0bd-debug"
tag: "e926ae4b-debug"
env:
- name: APP_VERSION
value: "0.0.0"
+3 -10
View File
@@ -16,9 +16,6 @@ spec:
- ports:
- port: "7233"
protocol: TCP
# k8s API server (for batch/v1 Job create/poll/delete)
- toEntities:
- kube-apiserver
# DNS
- toEndpoints:
- matchLabels:
@@ -30,15 +27,11 @@ spec:
protocol: UDP
- port: "53"
protocol: TCP
# RabbitMQ on oceanbox: NodePorts (30672/31672) or MetalLB IPs on standard port 5672
# OTel collector (tos1 LoadBalancer 10.255.241.12) for Temporal traces, exported cross-cluster
- toCIDR:
- 10.255.241.0/24
- 10.255.241.12/32
toPorts:
- ports:
- port: "5672"
protocol: TCP
- port: "30672"
protocol: TCP
- port: "31672"
- port: "4317"
protocol: TCP
{{- end }}
+37
View File
@@ -0,0 +1,37 @@
apiVersion: v1
kind: PersistentVolume
metadata:
name: pv-proteus-ceph-archives
spec:
accessModes:
- ReadWriteMany
capacity:
storage: 1Gi
csi:
driver: rook-ceph.cephfs.csi.ceph.com
nodeStageSecretRef:
name: rook-csi-cephfs-node
namespace: rook-ceph
volumeAttributes:
clusterID: rook-ceph
fsName: data
rootPath: /
staticVolume: "true"
volumeHandle: pv-proteus-ceph-archives
persistentVolumeReclaimPolicy: Retain
volumeMode: Filesystem
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: proteus-ceph-archives
namespace: proteus
spec:
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1Gi
storageClassName: ""
volumeMode: Filesystem
volumeName: pv-proteus-ceph-archives
-55
View File
@@ -1,55 +0,0 @@
# TODO: the SA the temporal-worker-controller assigns to the pod (assumed `default`).
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: proteus-dev-queue
namespace: dev-queue
rules:
- apiGroups: ["batch"]
resources: ["jobs"]
verbs: ["create", "delete", "get", "list", "watch"]
- apiGroups: [""]
resources: ["pods", "pods/log"]
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: proteus-dev-queue
namespace: dev-queue
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: proteus-dev-queue
subjects:
- kind: ServiceAccount
name: default
namespace: proteus
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: proteus-prod-queue
namespace: prod-queue
rules:
- apiGroups: ["batch"]
resources: ["jobs"]
verbs: ["create", "delete", "get", "list", "watch"]
- apiGroups: [""]
resources: ["pods", "pods/log"]
verbs: ["get", "list"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: proteus-prod-queue
namespace: prod-queue
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: proteus-prod-queue
subjects:
- kind: ServiceAccount
name: default
namespace: proteus
+72 -17
View File
@@ -1,14 +1,10 @@
# TEMPORAL_NAMESPACE : {env}-atlantis
# ARCHIVE_PVC : the queue's archive PVC (prod+beta -> prod-queue, staging -> dev-queue)
# Status/inbox/quota now flow via Temporal activities to the Atlantis notify worker; no RabbitMQ.
# ---
# apiVersion: temporal.io/v1alpha1
# kind: WorkerDeployment
# metadata:
# name: proteus-prod
# namespace: proteus
# spec:
# replicas: 1
# replicas: 2
# workerOptions:
# temporalNamespace: prod-atlantis
# connectionRef:
@@ -21,14 +17,20 @@
# securityContext:
# runAsUser: 0
# runAsGroup: 0
# volumes:
# - name: archives
# persistentVolumeClaim:
# claimName: proteus-ceph-archives
# containers:
# - name: proteus
# image: git.oceanbox.io/oceanbox/poseidon/proteus:CHANGEME
# image: git.oceanbox.io/oceanbox/poseidon/proteus:v2.17.0
# resources:
# requests:
# memory: 256Mi
# limits:
# cpu: "1"
# memory: 1Gi
# limits:
# cpu: "2"
# memory: 4Gi
# env:
# - name: TEMPORAL_TASK_QUEUES
# value: plume,xtract
@@ -38,6 +40,32 @@
# value: prod
# - name: ARCHIVE_PVC
# value: prod-queue-ceph-archives
# - name: MAX_CONCURRENT_ACTIVITIES
# value: "2"
# - name: OTEL_EXPORTER_OTLP_ENDPOINT
# value: http://10.255.241.12:4317
# volumeMounts:
# - name: archives
# mountPath: /data
# ports:
# - name: health
# containerPort: 8080
# livenessProbe:
# httpGet:
# path: /healthz
# port: health
# initialDelaySeconds: 20
# periodSeconds: 15
# timeoutSeconds: 5
# failureThreshold: 6
# readinessProbe:
# httpGet:
# path: /readyz
# port: health
# initialDelaySeconds: 5
# periodSeconds: 15
# timeoutSeconds: 5
# failureThreshold: 3
# ---
# apiVersion: temporal.io/v1alpha1
# kind: WorkerDeployment
@@ -73,10 +101,9 @@
# value: beta-atlantis
# - name: APP_ENV
# value: beta
# # beta schedules into prod-queue (same as prod), so the same archive PVC.
# - name: ARCHIVE_PVC
# value: prod-queue-ceph-archives
# ---
---
apiVersion: temporal.io/v1alpha1
kind: WorkerDeployment
metadata:
@@ -96,20 +123,48 @@ spec:
securityContext:
runAsUser: 0
runAsGroup: 0
volumes:
- name: archives
persistentVolumeClaim:
claimName: proteus-ceph-archives
containers:
- name: proteus
image: git.oceanbox.io/oceanbox/poseidon/proteus:v2.17.0
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
resources:
requests:
memory: 256Mi
limits:
cpu: 500m
memory: 1Gi
limits:
cpu: "2"
memory: 4Gi
env:
- name: TEMPORAL_TASK_QUEUES
value: plume,xtract
- name: TEMPORAL_NAMESPACE
value: staging-atlantis
- name: APP_ENV
value: staging
- name: ARCHIVE_PVC
value: dev-queue-ceph-archives
- name: MAX_CONCURRENT_ACTIVITIES
value: "10"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: http://10.255.241.12:4317
volumeMounts:
- name: archives
mountPath: /data
ports:
- name: health
containerPort: 8080
livenessProbe:
httpGet:
path: /healthz
port: health
initialDelaySeconds: 20
periodSeconds: 15
timeoutSeconds: 5
failureThreshold: 6
readinessProbe:
httpGet:
path: /readyz
port: health
initialDelaySeconds: 5
periodSeconds: 15
timeoutSeconds: 5
failureThreshold: 3
@@ -0,0 +1,3 @@
image:
repository: git.oceanbox.io/oceanbox/poseidon/proteus
tag: 7b97e45c-debug
@@ -22,9 +22,4 @@
value:
secretRef:
name: staging-sorcerer-env
- op: add
path: /spec/template/spec/containers/0/envFrom/-
value:
configMapRef:
name: staging-sorcerer-kueue-config
@@ -1,7 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: staging-sorcerer-kueue-config
data:
KUEUE_NAMESPACE: "dev-queue"
KUEUE_ARCHIVE_PVC: "dev-queue-ceph-archives"
@@ -19,7 +19,6 @@ resources:
- configurations.yaml
- keyvault.yaml
- rbac.yaml
- kueue-config.yaml
- secretstore.yaml
- statestore.yaml
- tracing.yaml
@@ -8,7 +8,6 @@ rules:
- ""
resourceNames:
- staging-sorcerer-appsettings
- staging-sorcerer-kueue-config
resources:
- configmaps
verbs:
@@ -24,24 +23,6 @@ rules:
verbs:
- get
- watch
- apiGroups:
- jobset.x-k8s.io
resources:
- jobsets
verbs:
- create
- delete
- get
- list
- watch
- apiGroups:
- ""
resources:
- pods
- pods/log
verbs:
- get
- list
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
+1 -1
View File
@@ -1,7 +1,7 @@
replicaCount: 1
image:
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
tag: 6442206c-debug
tag: 9138d67d-debug
podAnnotations:
dapr.io/enabled: "true"
dapr.io/app-id: "staging-sorcerer"
@@ -0,0 +1,17 @@
{{- if .Values.clusterConfig.cilium.enabled }}
apiVersion: cilium.io/v2
kind: CiliumClusterwideNetworkPolicy
metadata:
name: allow-itpartner-mail-egress
spec:
endpointSelector: {}
egress:
- toFQDNs:
- matchName: mx.itpartner.no
toPorts:
- ports:
- port: "587"
protocol: TCP
- port: "465"
protocol: TCP
{{- end }}
+1 -1
View File
@@ -1,6 +1,6 @@
temporal:
enabled: true
autosync: false
autosync: true
ingress: true
grpcIngress: true
workerController: true
+2
View File
@@ -8,6 +8,8 @@ metadata:
cert-manager.io/cluster-issuer: {{ .Values.clusterConfig.ingress_clusterissuer }}
nginx.ingress.kubernetes.io/backend-protocol: HTTP
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
nginx.ingress.kubernetes.io/proxy-busy-buffers-size: "24k"
oceanbox.io/expose: internal
labels:
app.kubernetes.io/name: temporal
@@ -60,4 +60,19 @@ spec:
protocol: UDP
- port: "53"
protocol: TCP
---
apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
name: allow-web-oidc-login
namespace: temporal
spec:
description: Allow Temporal Web UI OIDC login to Entra ID
endpointSelector:
matchLabels:
app.kubernetes.io/component: web
egress:
- toFQDNs:
- matchName: login.microsoftonline.com
- matchPattern: '*.microsoftonline.com'
{{- end }}
+12 -1
View File
@@ -12,9 +12,20 @@ spec:
initdb:
database: temporal
owner: temporal
# headroom for ~240 server connections (30/pod x 8 pods) plus CNPG's own
postgresql:
parameters:
max_connections: "300"
resources:
requests:
cpu: 500m
memory: 1Gi
limits:
cpu: "2"
memory: 2Gi
storage:
resizeInUseVolumes: true
size: 10Gi
size: 20Gi
---
apiVersion: postgresql.cnpg.io/v1
kind: Database
+125 -1
View File
@@ -1,8 +1,11 @@
server:
replicaCount: 2
config:
logLevel: "info"
persistence:
defaultStore: default
visibilityStore: visibility
# immutable after first deploy
numHistoryShards: 512
datastores:
default:
@@ -20,7 +23,7 @@ server:
maxConns: 20
maxIdleConns: 20
maxConnLifetime: "1h"
# TODO: migrate visibility to Elasticsearch for advanced visibility search.
# NOTE: Postgres 12+ gives advanced visibility; no Elasticsearch needed.
visibility:
sql:
createDatabase: false
@@ -41,8 +44,129 @@ server:
timerType: histogram
listenAddress: "0.0.0.0:9090"
metrics:
serviceMonitor:
enabled: true
interval: 30s
resources:
requests:
cpu: 250m
memory: 512Mi
limits:
cpu: "1"
memory: 1Gi
frontend:
podDisruptionBudget:
maxUnavailable: 1
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: temporal
app.kubernetes.io/instance: temporal
app.kubernetes.io/component: frontend
history:
resources:
requests:
cpu: 250m
memory: 768Mi
limits:
cpu: "1"
memory: 1536Mi
podDisruptionBudget:
maxUnavailable: 1
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: temporal
app.kubernetes.io/instance: temporal
app.kubernetes.io/component: history
matching:
podDisruptionBudget:
maxUnavailable: 1
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: temporal
app.kubernetes.io/instance: temporal
app.kubernetes.io/component: matching
worker:
podDisruptionBudget:
maxUnavailable: 1
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: temporal
app.kubernetes.io/instance: temporal
app.kubernetes.io/component: worker
# no persistent debug pod; use temporalio/admin-tools on demand
admintools:
enabled: false
web:
enabled: true
replicaCount: 2
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
cpu: 250m
memory: 256Mi
podDisruptionBudget:
maxUnavailable: 1
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: temporal
app.kubernetes.io/instance: temporal
app.kubernetes.io/component: web
# NOTE: native OIDC SSO via Entra ID (same oceanbox-oidc secret as Grafana); gates UI login only
additionalEnv:
- name: TEMPORAL_AUTH_ENABLED
value: "true"
- name: TEMPORAL_AUTH_TYPE
value: "oidc"
- name: TEMPORAL_AUTH_PROVIDER_URL
value: "https://login.microsoftonline.com/3f737008-e9a0-4485-9d27-40329d288089/v2.0"
- name: TEMPORAL_AUTH_CLIENT_ID
valueFrom:
secretKeyRef:
name: oceanbox-oidc
key: client_id
- name: TEMPORAL_AUTH_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oceanbox-oidc
key: client_secret
- name: TEMPORAL_AUTH_CALLBACK_URL
value: "https://temporal.ekman.oceanbox.io/auth/sso/callback"
- name: TEMPORAL_AUTH_SCOPES
value: "openid,profile,email,offline_access"
schema:
useHelmHooks: false
# NOTE: run as an ArgoCD sync hook so the controller-mutated Job isn't diffed and stays OutOfSync forever
jobAnnotations:
argocd.argoproj.io/hook: Sync
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
+2
View File
@@ -0,0 +1,2 @@
uptermd:
enabled: true
+3
View File
@@ -0,0 +1,3 @@
uptermd:
enabled: false
autosync: false
@@ -0,0 +1,4 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- _manifest.yaml
@@ -0,0 +1,24 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- target:
kind: Ingress
name: uptermd
patch: |
$patch: delete
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: uptermd
- target:
group: cert-manager.io
kind: Issuer
name: uptermd-letsencrypt
patch: |
$patch: delete
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: uptermd-letsencrypt
+30
View File
@@ -0,0 +1,30 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: uptermd
namespace: uptermd
labels:
app.kubernetes.io/name: uptermd
annotations:
cert-manager.io/cluster-issuer: ca-issuer
haproxy.org/backend-protocol: h1
haproxy.org/timeout-tunnel: "3600s"
haproxy.org/timeout-client: "3600s"
haproxy.org/timeout-server: "3600s"
spec:
ingressClassName: haproxy
rules:
- host: upterm.hel1.obx
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: uptermd
port:
number: 80
tls:
- hosts:
- upterm.hel1.obx
secretName: uptermd-tls
+37
View File
@@ -0,0 +1,37 @@
{{- if .Values.clusterConfig.argo.enabled }}
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: uptermd
namespace: argocd
spec:
destination:
namespace: uptermd
server: 'https://kubernetes.default.svc'
sources:
- repoURL: {{ .Values.clusterConfig.manifests }}
targetRevision: HEAD
path: helmfile.d
plugin:
name: helmfile-cmp
env:
- name: CLUSTER_NAME
value: {{ .Values.clusterConfig.cluster }}
- name: HELMFILE_ENVIRONMENT
value: default
- name: HELMFILE_FILE_PATH
value: uptermd.yaml.gotmpl
project: sys
syncPolicy:
managedNamespaceMetadata:
labels:
component: sys
syncOptions:
- CreateNamespace=true
- ApplyOutOfSyncOnly=true
- ServerSideApply=true
{{- if .Values.uptermd.autosync }}
automated:
prune: true
{{- end }}
{{- end }}
+20
View File
@@ -0,0 +1,20 @@
replicaCount: 1
websocket:
enabled: true
service:
type: ClusterIP
resources:
limits:
memory: 512Mi
requests:
cpu: 100m
memory: 512Mi
# No SSH host key is provided, so uptermd generates an ephemeral one on each
# pod start
host_keys: {}
authorized_keys: []