## Optimize CI/CD Workflows ### Changes #### build.yaml - **Merge 3 cargo steps → 1 compile pass**: `cargo build`, `cargo test`, `cargo clippy` now run in single invocation, reusing compiled artifacts - **Remove `cargo clean`**: Eliminated wasteful step that deleted artifacts before Docker build - **Add secret validation**: Registry credentials checked before login (fail-fast) #### deploy.yaml - **Skip checkout**: Removed unnecessary git clone - **Fetch SHA via Gitea API**: Query latest commit directly instead of cloning - **Reuse existing token**: Use `FORGEJO_REGISTRY_TOKEN` for Gitea API auth (already has privileges) - **Validate image exists**: Check SHA image exists before tagging as latest (prevents tagging non-existent images) - **Add secret validation**: Registry credentials checked before login (fail-fast) #### migrate.yaml - **Merge schema verification**: Schema inspect result reused in both changed + manual paths - **Fix manual trigger errors**: Manual mode now fails on first migration error (was silently masking with `|| true`) - **Track failures**: Explicit FAILED flag tracks migration errors across loop ### Benefits - **Speed**: Fewer compiles, no unnecessary clones, reuse artifacts - **Reliability**: Secret validation catches configuration issues early - **Safety**: Image existence check prevents tagging phantom images - **Clarity**: Merged steps have descriptive names, explicit error handling ### Testing - Branch: `ci/optimize-workflows` - Ready to merge to `main` after review --------- Co-authored-by: rock <[email protected]> Reviewed-on: #51 Co-authored-by: poimen <[email protected]>
48 lines
1.4 KiB
YAML
48 lines
1.4 KiB
YAML
# Local/Development configuration (plaintext, external URLs via ingress)
|
|
# Use this instead of config.yaml for local testing
|
|
# kubectl apply -f config.local.yaml
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: poimen-memory-config
|
|
namespace: poimen
|
|
labels:
|
|
app.kubernetes.io/name: poimen-memory
|
|
app.kubernetes.io/component: config
|
|
data:
|
|
# Auth mode: jwt | apikey | none (disabled for local testing)
|
|
MEM_AUTH_MODE: "none"
|
|
|
|
# Rate limiting (higher for testing)
|
|
MEM_RATE_LIMIT_INGEST: "1000"
|
|
MEM_RATE_LIMIT_QUERY: "10000"
|
|
MEM_IDEMPOTENCY_TTL_SECS: "86400"
|
|
|
|
# Embeddings
|
|
MEM_EMBEDDING_BATCH_SIZE: "32"
|
|
|
|
# Downstream services - external URLs via ingress
|
|
|
|
# LLM Service (via api.riotpiao.com ingress)
|
|
LLM_ENDPOINT: "https://api.riotpiao.com/v1/chat/completions"
|
|
LLM_API_BASE: "https://api.riotpiao.com/v1"
|
|
LLM_MODEL: "qwen:7b"
|
|
LLM_TIMEOUT_SECS: "60"
|
|
ENABLE_LLM_EXTRACTION: "true"
|
|
|
|
# OpenSearch (via ingress)
|
|
OPENSEARCH_HOST: "opensearch.riotpiao.com:443"
|
|
OPENSEARCH_SCHEME: "https"
|
|
OPENSEARCH_VERIFY_CERTS: "true"
|
|
|
|
# Authentik (via ingress - optional for local)
|
|
AUTHENTIK_ISSUER: "https://authentik.riotpiao.com/application/o/poimen/"
|
|
AUTHENTIK_VERIFY_SSL: "true"
|
|
|
|
# Temporal (via ingress)
|
|
TEMPORAL_ENDPOINT: "temporal.riotpiao.com:443"
|
|
TEMPORAL_NAMESPACE: "poimen"
|
|
|
|
# API Gateway (via ingress)
|
|
GATEWAY_URL: "https://api.riotpiao.com"
|