CI / CI (pull_request) Successful in 32m52s
- config.yaml: prod config with cluster-internal DNS (LLM, OpenSearch, Authentik, Temporal, API-GW) - config.local.yaml: dev config with external URLs via ingress - deployment.yaml: remove hardcoded URIs, read all from ConfigMap envFrom - All downstream service URIs now configurable per environment - Production config encrypted with SOPS (Age-based) - Application code reads LLM_ENDPOINT, OPENSEARCH_HOST, AUTHENTIK_ISSUER, etc. from ENV - Simplifies prod/dev switching: just swap ConfigMap, no code changes
48 lines
1.4 KiB
YAML
48 lines
1.4 KiB
YAML
# Local/Development configuration (plaintext, external URLs via ingress)
|
|
# Use this instead of config.yaml for local testing
|
|
# kubectl apply -f config.local.yaml
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: poimen-memory-config
|
|
namespace: poimen
|
|
labels:
|
|
app.kubernetes.io/name: poimen-memory
|
|
app.kubernetes.io/component: config
|
|
data:
|
|
# Auth mode: jwt | apikey | none (disabled for local testing)
|
|
MEM_AUTH_MODE: "none"
|
|
|
|
# Rate limiting (higher for testing)
|
|
MEM_RATE_LIMIT_INGEST: "1000"
|
|
MEM_RATE_LIMIT_QUERY: "10000"
|
|
MEM_IDEMPOTENCY_TTL_SECS: "86400"
|
|
|
|
# Embeddings
|
|
MEM_EMBEDDING_BATCH_SIZE: "32"
|
|
|
|
# Downstream services - external URLs via ingress
|
|
|
|
# LLM Service (via api.riotpiao.com ingress)
|
|
LLM_ENDPOINT: "https://api.riotpiao.com/v1/chat/completions"
|
|
LLM_API_BASE: "https://api.riotpiao.com/v1"
|
|
LLM_MODEL: "qwen:7b"
|
|
LLM_TIMEOUT_SECS: "60"
|
|
ENABLE_LLM_EXTRACTION: "true"
|
|
|
|
# OpenSearch (via ingress)
|
|
OPENSEARCH_HOST: "opensearch.riotpiao.com:443"
|
|
OPENSEARCH_SCHEME: "https"
|
|
OPENSEARCH_VERIFY_CERTS: "true"
|
|
|
|
# Authentik (via ingress - optional for local)
|
|
AUTHENTIK_ISSUER: "https://authentik.riotpiao.com/application/o/poimen/"
|
|
AUTHENTIK_VERIFY_SSL: "true"
|
|
|
|
# Temporal (via ingress)
|
|
TEMPORAL_ENDPOINT: "temporal.riotpiao.com:443"
|
|
TEMPORAL_NAMESPACE: "poimen"
|
|
|
|
# API Gateway (via ingress)
|
|
GATEWAY_URL: "https://api.riotpiao.com"
|