# k8s/temporal/temporal-values.yaml # Temporal — workflow engine for story-crater backend async task orchestration. # Chart: temporal/temporal v1.6.0 from https://go.temporal.io/helm-charts # # Uses Cassandra for default store (workflow history/events) # Uses Elasticsearch for visibility store (namespace/workflow queries) # This is the chart's native, well-tested configuration. # ── Sub-charts ──── # Cassandra and Elasticsearch deployed as dependencies cassandra: enabled: true replicas: 3 cluster: seedSize: 1 port: 9042 # Spread replicas across nodes to avoid single-node bottleneck affinity: podAntiAffinity: preferredDuringSchedulingIgnoredDuringExecution: - weight: 100 podAffinityTerm: labelSelector: matchLabels: app: cassandra release: temporal topologyKey: kubernetes.io/hostname elasticsearch: enabled: true replicas: 1 auth: enabled: false env: cluster.name: temporal discovery.type: single-node resources: requests: memory: "512Mi" cpu: "250m" limits: memory: "1Gi" cpu: "500m" postgresql: enabled: false # ── Disable schema auto-setup (will initialize manually) ───────── jobs: autoSetup: enabled: false # ── Temporal server config (Cassandra + Elasticsearch persistence) ────────────────────────────── server: replicaCount: 1 jobService: enabled: false # Spread frontend/history/matching/worker across nodes instead of letting # them stack on whichever node the scheduler prefers (was: 59 of ~80 # cluster pods on talos-cp-1 alone). History's ringpop gossip join was # timing out because 3 of its 4 peers sat on that overloaded node. affinity: podAntiAffinity: preferredDuringSchedulingIgnoredDuringExecution: - weight: 100 podAffinityTerm: labelSelector: matchLabels: app.kubernetes.io/instance: temporal topologyKey: kubernetes.io/hostname config: logLevel: "info" persistence: defaultStore: default visibilityStore: visibility numHistoryShards: 512 datastores: default: # Cassandra for workflow history/events cassandra: hosts: "temporal-cassandra-0.temporal-cassandra.temporal.svc.cluster.local,temporal-cassandra-1.temporal-cassandra.temporal.svc.cluster.local,temporal-cassandra-2.temporal-cassandra.temporal.svc.cluster.local" port: 9042 keyspace: temporal user: cassandra password: "" replicationFactor: 3 consistency: default: consistency: LOCAL_QUORUM serialConsistency: LOCAL_SERIAL maxConnsPerHost: 32 visibility: # Elasticsearch for visibility store (workflow queries) elasticsearch: url: "http://elasticsearch.temporal.svc.cluster.local:9200" scheme: http logLevel: info bulkProcessor: bulkActions: 1000 service: type: ClusterIP # ── Temporal Web UI ──────────────────────────────────────────────────────── web: replicaCount: 1 service: type: ClusterIP # ── Ingress ──────────────────────────────────────────────────────── # Note: ingress is disabled here. Instead, we route via oauth2-proxy. # The ingress is applied separately as k8s/temporal/temporal-ingress-oauth2.yaml # which terminates TLS and routes to oauth2-proxy service. ingress: enabled: false # ── Monitoring ──────────────────────────────────────────────────────── prometheus: enabled: false