ci: optimize build + deploy + migrate workflows (#51)
## Optimize CI/CD Workflows ### Changes #### build.yaml - **Merge 3 cargo steps → 1 compile pass**: `cargo build`, `cargo test`, `cargo clippy` now run in single invocation, reusing compiled artifacts - **Remove `cargo clean`**: Eliminated wasteful step that deleted artifacts before Docker build - **Add secret validation**: Registry credentials checked before login (fail-fast) #### deploy.yaml - **Skip checkout**: Removed unnecessary git clone - **Fetch SHA via Gitea API**: Query latest commit directly instead of cloning - **Reuse existing token**: Use `FORGEJO_REGISTRY_TOKEN` for Gitea API auth (already has privileges) - **Validate image exists**: Check SHA image exists before tagging as latest (prevents tagging non-existent images) - **Add secret validation**: Registry credentials checked before login (fail-fast) #### migrate.yaml - **Merge schema verification**: Schema inspect result reused in both changed + manual paths - **Fix manual trigger errors**: Manual mode now fails on first migration error (was silently masking with `|| true`) - **Track failures**: Explicit FAILED flag tracks migration errors across loop ### Benefits - **Speed**: Fewer compiles, no unnecessary clones, reuse artifacts - **Reliability**: Secret validation catches configuration issues early - **Safety**: Image existence check prevents tagging phantom images - **Clarity**: Merged steps have descriptive names, explicit error handling ### Testing - Branch: `ci/optimize-workflows` - Ready to merge to `main` after review --------- Co-authored-by: rock <[email protected]> Reviewed-on: #51 Co-authored-by: poimen <[email protected]>
This commit was merged in pull request #51.
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
# Local/Development configuration (plaintext, external URLs via ingress)
|
||||
# Use this instead of config.yaml for local testing
|
||||
# kubectl apply -f config.local.yaml
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: poimen-memory-config
|
||||
namespace: poimen
|
||||
labels:
|
||||
app.kubernetes.io/name: poimen-memory
|
||||
app.kubernetes.io/component: config
|
||||
data:
|
||||
# Auth mode: jwt | apikey | none (disabled for local testing)
|
||||
MEM_AUTH_MODE: "none"
|
||||
|
||||
# Rate limiting (higher for testing)
|
||||
MEM_RATE_LIMIT_INGEST: "1000"
|
||||
MEM_RATE_LIMIT_QUERY: "10000"
|
||||
MEM_IDEMPOTENCY_TTL_SECS: "86400"
|
||||
|
||||
# Embeddings
|
||||
MEM_EMBEDDING_BATCH_SIZE: "32"
|
||||
|
||||
# Downstream services - external URLs via ingress
|
||||
|
||||
# LLM Service (via api.riotpiao.com ingress)
|
||||
LLM_ENDPOINT: "https://api.riotpiao.com/v1/chat/completions"
|
||||
LLM_API_BASE: "https://api.riotpiao.com/v1"
|
||||
LLM_MODEL: "qwen:7b"
|
||||
LLM_TIMEOUT_SECS: "60"
|
||||
ENABLE_LLM_EXTRACTION: "true"
|
||||
|
||||
# OpenSearch (via ingress)
|
||||
OPENSEARCH_HOST: "opensearch.riotpiao.com:443"
|
||||
OPENSEARCH_SCHEME: "https"
|
||||
OPENSEARCH_VERIFY_CERTS: "true"
|
||||
|
||||
# Authentik (via ingress - optional for local)
|
||||
AUTHENTIK_ISSUER: "https://authentik.riotpiao.com/application/o/poimen/"
|
||||
AUTHENTIK_VERIFY_SSL: "true"
|
||||
|
||||
# Temporal (via ingress)
|
||||
TEMPORAL_ENDPOINT: "temporal.riotpiao.com:443"
|
||||
TEMPORAL_NAMESPACE: "poimen"
|
||||
|
||||
# API Gateway (via ingress)
|
||||
GATEWAY_URL: "https://api.riotpiao.com"
|
||||
Reference in New Issue
Block a user