CI / CI (push) Successful in 15m28s
## Problem JWT validation failing with `error decoding response body: expected value at line 6 column 1`. Root cause: `AUTHENTIK_ISSUER` pointed to slug `poimen-memory` which returns 404 on OIDC discovery. Slug was renamed to `poimen` in Authentik. Secondary issue: auth env vars were set via `kubectl set env` (not in git), so every ArgoCD sync reverted them. ## Changes - **k8s/app/config.yaml** — ConfigMap for non-sensitive env (auth mode, rate limits, OpenSearch/Obsidian URLs) - **k8s/app/auth.enc.yaml** — SOPS-encrypted Secret with `AUTHENTIK_ISSUER`, `AUTHENTIK_AUDIENCE`, `JWT_CACHE_TTL_SECS` - **k8s/app/secret-generator.yaml** — KSOPS generator for ArgoCD decryption - **k8s/app/deployment.yaml** — `envFrom` referencing ConfigMap + Secret - **k8s/app/kustomization.yaml** — Added config.yaml + KSOPS generator - **k8s/app/opensearch-deployment.yaml** — Updated JWKS/issuer URLs to `poimen` slug ## Rollout Reloader (`--auto-reload-all=true`) triggers rolling restart when ConfigMap/Secret change. Merge and ArgoCD sync handles everything.Reviewed-on: rock/poimen-memory#40 Co-authored-by: rock <[email protected]>
116 lines
3.3 KiB
YAML
116 lines
3.3 KiB
YAML
# Poimen Memory API Server
|
|
# Serves 7 HTTP endpoints for memory ingest, query, and management.
|
|
# Connects to memory-db (pgvector) for persistent storage.
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: poimen-memory
|
|
namespace: poimen
|
|
labels:
|
|
app.kubernetes.io/name: poimen-memory
|
|
app.kubernetes.io/component: api-server
|
|
spec:
|
|
replicas: 2
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: poimen-memory
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: poimen-memory
|
|
spec:
|
|
serviceAccountName: poimen-memory
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 1000
|
|
runAsGroup: 999
|
|
fsGroup: 999
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
containers:
|
|
- name: memory
|
|
image: forgejo.riotpiao.com/rock/poimen-memory:latest
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
readOnlyRootFilesystem: true
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
imagePullPolicy: Always
|
|
ports:
|
|
- containerPort: 8080
|
|
name: http
|
|
env:
|
|
# Database connection (from CNPG auto-generated secret)
|
|
- name: DATABASE_HOST
|
|
value: "memory-db-rw.poimen.svc.cluster.local"
|
|
- name: DATABASE_PORT
|
|
value: "5432"
|
|
- name: DATABASE_NAME
|
|
value: "memory"
|
|
- name: DATABASE_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: memory-db-app
|
|
key: username
|
|
- name: DATABASE_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: memory-db-app
|
|
key: password
|
|
- name: DATABASE_URL
|
|
value: "postgresql://$(DATABASE_USER):$(DATABASE_PASSWORD)@$(DATABASE_HOST):$(DATABASE_PORT)/$(DATABASE_NAME)?sslmode=disable"
|
|
# LLM Gateway API key
|
|
- name: MEM_API_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: poimen-memory-secrets
|
|
key: llm-api-key
|
|
# Server config (from ConfigMap)
|
|
- name: MEM_PORT
|
|
value: "8080"
|
|
- name: MEM_HOME
|
|
value: "/tmp"
|
|
envFrom:
|
|
- configMapRef:
|
|
name: poimen-memory-config
|
|
- secretRef:
|
|
name: poimen-memory-auth
|
|
args:
|
|
- serve
|
|
- --port
|
|
- "8080"
|
|
- --api-key
|
|
- "$(MEM_API_KEY)"
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 128Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 512Mi
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /health
|
|
port: http
|
|
initialDelaySeconds: 10
|
|
periodSeconds: 30
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /health
|
|
port: http
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
volumeMounts:
|
|
- name: tmp
|
|
mountPath: /tmp
|
|
volumes:
|
|
- name: tmp
|
|
emptyDir:
|
|
sizeLimit: 64Mi
|
|
# Tolerate control-plane nodes
|
|
tolerations:
|
|
- key: node-role.kubernetes.io/control-plane
|
|
operator: Exists
|
|
effect: NoSchedule
|