Commit Graph
30 Commits
Author SHA1 Message Date
Story Crater Bot c354876178 test: add comprehensive TemporalWorker tests
Queue reconciliation:
- TemporalWorker creation when label present
- Namespace label validation
- Kubernetes name validation
- Cleanup on Queue deletion

Validation helpers:
- isValidTemporalNamespace (8 cases)
- validateKubernetesName (9 cases)

TemporalWorker controller:
- Deployment creation and updates
- Env var injection including TEMPORAL_TASK_QUEUE
- Status tracking
- Delete handling
2026-07-11 07:30:33 -07:00
Story Crater Bot 68672c72e9 fix: wrap TemporalWorker reconciler errors with context 2026-07-11 07:30:18 -07:00
Story Crater Bot 317396e785 feat: add TemporalWorker auto-provisioning from Queue labels
- Validate temporal namespace and Kubernetes names
- Configurable via env vars: KMSVC_TEMPORAL_NAMESPACE, KMSVC_TEMPORAL_WORKER_IMAGE
- Set ownerReference for cascade deletion and lifecycle management
- Use CreateOrUpdate for spec propagation (idempotent)
- Clean up TemporalWorker on Queue deletion
2026-07-11 07:30:13 -07:00
Story Crater BotandClaude Haiku 4.5 6577efc100 feat: add TemporalWorker CRD and controller
Add TemporalWorker CRD definition with full status tracking and
TemporalWorkerReconciler that manages Deployment lifecycle:
- Auto-generate DeepCopy methods via kubebuilder markers
- Controller creates/updates Deployments matching worker spec
- Injects TEMPORAL_FRONTEND_ADDRESS and TEMPORAL_NAMESPACE env vars
- Tracks replica count and ready status
- Handles graceful deletion via finalizer

Design document (TEMPORAL_INTEGRATION.md) describes three-phase roadmap:
- Phase 1 (MVP): Manual TemporalWorker CRD creation
- Phase 2: Auto-provisioning from Queue labels
- Phase 3: Autoscaling based on queue depth

Co-Authored-By: Claude Haiku 4.5 <[email protected]>
2026-07-11 07:29:34 -07:00
riotpiaole 674fbb6bfe fix: consolidate all modules under homelab org for cross-repo resolution 2026-07-04 08:28:00 -07:00
riotpiaole 43ab2092df ci: add comprehensive CI workflow for server and operator 2026-07-04 07:44:55 -07:00
riotpiaole c7eeed2617 feat: stamp Queue shard status with availability zones
Resolves each shard topic's replica broker IDs (internal/kafka.Admin.
ReplicaBrokerIDs) to the topology.kubernetes.io/zone labels of the nodes
hosting those brokers (ZoneLocator), and writes the result into
ShardStatus.AvailabilityZones each reconcile. Uses mgr.GetAPIReader()
rather than the cached client for the Pod/Node lookups, since the cached
client would otherwise require cluster-wide list/watch RBAC on Pods just
to serve occasional point Gets.
2026-06-22 17:30:26 -07:00
riotpiaole 1ff1ecd563 fix: update kafaka server to kmsvc.riotpiao.homelab.com 2026-06-22 13:05:32 -07:00
riotpiaole c7961d2599 test: add end-to-end queue send/receive/delete smoke test script
Creates a Queue CRD, port-forwards to management-service, fetches an
Authentik client_credentials token, then exercises send/receive/delete
through kmsvc-cli before tearing the queue down.
2026-06-22 12:23:39 -07:00
riotpiaole 9fa5420b22 fix: queue-operator dropped reconcile namespace and overflowed hash-range status
main.go called Reconcile(ctx, req.Name) without req.Namespace, so the
Get against the namespaced Queue CRD always 404'd and was silently
swallowed as success -- no shard topics or Redis state were ever created.

Separately, ShardStatus.HashRangeStart/End were uint32, but controller-gen
maps that to OpenAPI format:int32, whose max (2147483647) is smaller than
FullHashRangeEnd (0xFFFFFFFF), so the apiserver rejected every status
update with the (misleadingly empty-looking) "must be of type integer with
format int32" error. Widened to int64, regenerated the CRD, and synced the
chart's bundled copy.
2026-06-22 12:23:23 -07:00
riotpiaole 173a4935ab fix: pin Kafka broker storage to a 2-replica class sized for current cluster
The default "longhorn" StorageClass requests 3 replicas, but the homelab
cluster currently has only 2 schedulable nodes, so the 3rd replica could
never be scheduled and volumes stayed permanently degraded. Adds
longhorn-kafka (numberOfReplicas: 2) and reduces broker PVC size so 3 broker
volumes' replicas fit within each node's remaining Longhorn scheduling
headroom. Revert to "longhorn" once a 3rd node joins.
2026-06-22 12:23:12 -07:00
riotpiaole 3dda969784 fix: align GOMEMLIMIT with pod memory limits and force fresh image pulls
Go's GC doesn't respect cgroup memory limits on its own, risking OOMKill
under load; set GOMEMLIMIT to ~90% of each deployment's resources.limits.memory.
Also switch imagePullPolicy to Always so :latest tags aren't served stale
from node-local cache after a new push.
2026-06-22 12:22:55 -07:00
riotpiaole 00d06c12bc feat: add ArgoCD app-of-apps manifests for homelab GitOps deployment
Root application + project plus per-component Application CRs (Strimzi
operator, Kafka cluster, Redis, queue CRD/operator, management-service).
2026-06-22 12:22:38 -07:00
riotpiaole f2566e6f89 build: pin docker builds to linux/amd64 and trust homelab CA at runtime
Building on arm64 Mac without GOOS/GOARCH produced amd64 node "exec format
error". The homelab CA was only trusted in the build stage, so the final
distroless runtime couldn't verify Authentik's TLS cert during OIDC discovery.
2026-06-22 12:21:38 -07:00
riotpiaole 8904203266 fix: consolidate helmfile into one file; expose gRPC externally for kmsvc-cli
Cross-file `needs:` across separate nested helmfiles didn't resolve in
Helmfile v1 (releases defined in sibling files weren't visible to each
other's dependency graph) -- confirmed live against the homelab cluster:
kafka-cluster failed with "depend(s) on an undefined release" even though
strimzi-operator had just been installed successfully by a sibling file.
Collapsed releases.d/*.gotmpl into a single helmfile.yaml.gotmpl so the
whole release graph is resolved together.

Also add a second Ingress (management-service-grpc, backend-protocol: GRPC)
scoped to the QueueService gRPC path prefix on the same host/port as the
REST ingress. kmsvc-cli dials --server directly via gRPC (default
kmsvc.homelab.internal:443 per its README), so raw gRPC needs an external
path too, not just REST -- the original "gRPC stays internal" default
didn't account for the CLI's own connection model.

Add Dockerfile.queue-operator (existed for cmd/server only before).
2026-06-22 07:11:58 -07:00
riotpiaole 2519e726b2 fix: use sqs namespace in queue-operator ClusterRoleBinding
Aligns the standalone config/rbac manifest with the sqs namespace used
throughout the new k8s/ Helm charts.
2026-06-22 06:32:09 -07:00
riotpiaole 918ba9393f feat: add Helmfile-managed k8s charts for tasks 10-13
Local charts: kafka-cluster (Strimzi Kafka+KafkaNodePool CRs, 3-replica KRaft
topology, 5Gi memory cap, Longhorn storage, pod anti-affinity), queue-crd
(Queue CRD + queue-operator Deployment/RBAC), management-service
(Deployment/Service/ConfigMap/HPA/Ingress, REST exposed externally via
cert-manager-issued TLS, raw gRPC kept cluster-internal per design.md §7a).

helmfile.yaml.gotmpl + releases.d/*.gotmpl wire strimzi-operator ->
kafka-cluster -> redis -> {queue-crd, management-service} via `needs:`.
Directory is releases.d, not helmfile.d as originally sketched in design.md
section 7b: Helmfile v1 treats a literal "helmfile.d" directory as a special
auto-discovery mode that conflicts with an explicit top-level helmfile.yaml.
Files use .gotmpl (required by Helmfile v1 for {{ }}-templated files) and
each declares its own environments: block, since nested helmfiles don't
inherit the parent's resolved values in this version.

Namespace is sqs throughout. environments/homelab.yaml carries no secrets.
Validated locally via helm lint/helm template (all 3 charts) and
`helmfile -e homelab build` (dependency ordering + value substitution) — no
cluster contact made. Live apply is a separate, explicitly-confirmed step.
2026-06-22 06:31:41 -07:00
riotpiaole fd69e33a98 build: add Dockerfile for the message-plane server
Multi-stage build (golang:1.26 -> distroless/static-nonroot), CGO disabled,
GOPRIVATE set for the kmsvc-proto module fetch.
2026-06-22 06:30:31 -07:00
riotpiaole 26b6922ad4 feat: implement gRPC server + grpc-gateway wiring (task 9)
Assembles tasks 1/6/7/8 into a runnable cmd/server binary: QueueServiceServer
handlers translating kafkamgmt.v1 proto to internal/core/queue's plain Go
types, a lazy per-queue Kafka consumer registry for ReceiveMessage, and a
Redis-scan-based queue discovery loop that starts a reaper goroutine per
queue (queue lifecycle isn't exposed over gRPC, so this is the server's only
signal). Promotes kmsvc-proto to a direct go.mod dependency.

Handler-level integration tests run against kfake+miniredis (same documented
tradeoff as tasks 5-7's envtest/testcontainers substitution), exercising
send->receive->delete through the real QueueServiceServer implementation.
2026-06-22 06:30:25 -07:00
riotpiaole b3be1f929a refactor: consume kmsvc-proto as a Go module instead of local generation
Remove local proto/, buf.yaml, buf.gen.yaml, and generated
internal/api/v1/*.pb.go. The message-plane contract now lives in the
sibling repo kmsvc-proto (forgejo.riotpiao.homelab.com/rock/kmsvc-proto),
fetched via go get — no local buf/protoc plugin install needed.

Nothing in this repo imported internal/api/v1 yet, so this is a clean
swap with no call-site changes.
2026-06-21 19:47:43 -07:00
riotpiaole ef7b54710d feat(auth): add Authentik JWT validation shared by gRPC and REST
JWKS caching via lestrrat-go/jwx, signature/iss/aud/exp validation, and
a single gRPC interceptor that grpc-gateway's forwarded headers make
work identically for REST callers.
2026-06-21 18:55:23 -07:00
riotpiaole 5d3dc23e81 chore: gitignore local Claude Code project settings 2026-06-21 18:29:59 -07:00
riotpiaole 1373b9e548 feat(reaper): add redelivery/DLQ sweep
Per-queue ticker that scans vis_index for expired in-flight messages and
drives each through the atomic reap.lua check-and-act, routing maxed-out
messages to their queue's configured DLQ via the existing SendMessage
path. Safe to run from multiple replicas against the same queue.
2026-06-21 17:08:48 -07:00
riotpiaole b1f039ae25 feat(queue): add message-plane core logic for send/receive/delete/visibility
Implements SendMessage (size cap, FIFO dedup, shard routing), ReceiveMessage
(long-poll loop across active+closing shards, FIFO per-group exclusivity
gating, redelivery hand-out), DeleteMessage (ack + low-watermark offset
advancement), and ChangeMessageVisibility against the Redis state layer
and a real Kafka producer/consumer.
2026-06-21 17:08:24 -07:00
riotpiaole 3ac4083a68 feat(operator): add queue-operator CRD reconciler with shard split/drain
Reconciles Queue CRs into Kafka topics + Redis shard-map/queue-meta state:
creates shard-0 on first reconcile, splits a shard's hash range into two
children once its split threshold is crossed, drains and closes a parent
shard once its consumer group has fully caught up and its retention
window has elapsed, and tears down every shard's topic + Redis state on
deletion. Includes the manager entrypoint (cmd/queue-operator) and RBAC.
2026-06-21 17:08:17 -07:00
riotpiaole a04c76a684 feat(redis): add shard-aware key schema, Lua scripts, and atomic ops
Implements the kmsvc: key schema (inflight, pending/watermark keyed by
shard+partition, vis_index, dedup, fifo_lock, queue meta, shard map) plus
the atomic reap/ack Lua scripts used for safe multi-replica redelivery
and DLQ routing.
2026-06-21 17:05:38 -07:00
riotpiaole b704d401a1 feat(kafka): add shard-aware topology, admin, and client layer
Topic naming (kmsvc.{queue}.shard-{id} / .fifo.shard-{id} / .dlq.shard-{id}),
hash-range shard selection/splitting (murmur2-based, matching Kafka's
default partitioner), and topic admin/producer/consumer client
constructors shared by the operator and the message-plane.
2026-06-21 16:59:54 -07:00
riotpiaole 70e992bd96 feat(crd): add Queue CRD types and generated manifest
QueueSpec/QueueStatus model the shard-based (Kinesis-style hash-range
splitting) queue lifecycle object, with the controller-gen-generated
deepcopy and CRD YAML.
2026-06-21 16:59:47 -07:00
riotpiaole d38ce2ac92 feat(proto): define message-plane gRPC/REST API
Adds queue_service.proto (SendMessage, SendMessageBatch, ReceiveMessage,
DeleteMessage, DeleteMessageBatch, ChangeMessageVisibility(Batch)) with
grpc-gateway REST annotations, plus the generated Go server/client and
gateway stubs.
2026-06-21 16:59:41 -07:00
riotpiaole db02d0fa7f chore: scaffold Go module, codegen tooling, and shared runtime config
Sets up go.mod/go.sum, buf (proto codegen) configuration, and the
env-driven Config shared by the message-plane server and queue-operator.
2026-06-21 16:59:35 -07:00