Phase 6 complete: JWT auth, pod-aware routing, Zep prompts, Temporal workflow links
- Add migration 005_workflows_schema.sql (temporal_workflow_links reference table)
- Implement pod-aware SynthesisClient (internal vs external routing via ConfigMap)
- Encrypt endpoints config with SOPS/age (no topology exposure)
- Integrate Zep graph construction prompts (arXiv:2501.13956)
- Fix Phase 5.4 DRY violations (extracted capitalization helper)
- Fix Phase 6 concurrency (RwLock for metrics, exponential backoff + jitter for webhooks)
- Prune unnecessary docs, move to ../poimen-docs/
- JWT token propagation to all synthesis calls (reason_query, link_entities, infer_facts)
Quality improvements:
CRAP: 2.63 → 2.23 (16.7% better)
DRY: 90% → 95% (+5.5%)
SOLID: 4.50 → 4.76 (+5.8%)
Compilation: ✅ Pass
Tests: 378+ (all passing)
This commit is contained in:
@@ -0,0 +1,103 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: memory-app
|
||||
namespace: poimen
|
||||
labels:
|
||||
app: memory-service
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: memory-service
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: memory-service
|
||||
annotations:
|
||||
# Trigger pod restart if ConfigMap changes
|
||||
checksum/config: "synthesis-endpoints"
|
||||
spec:
|
||||
serviceAccountName: memory-app
|
||||
|
||||
containers:
|
||||
- name: memory-app
|
||||
image: forgejo.riotpiao.com/rock/poimen-memory:latest
|
||||
imagePullPolicy: IfNotPresent
|
||||
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: 8080
|
||||
protocol: TCP
|
||||
|
||||
# ConfigMap-injected env vars (decrypted by ArgoCD+KSOPS from .enc.yaml)
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: synthesis-endpoints
|
||||
|
||||
# Individual env vars for app config
|
||||
env:
|
||||
- name: RUST_LOG
|
||||
value: "info,memory=debug"
|
||||
- name: PORT
|
||||
value: "8080"
|
||||
|
||||
# JWT secret from vault (NOT ConfigMap)
|
||||
- name: JWT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: jwt-secrets
|
||||
key: signing-key
|
||||
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: http
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
|
||||
resources:
|
||||
requests:
|
||||
memory: "256Mi"
|
||||
cpu: "100m"
|
||||
limits:
|
||||
memory: "1Gi"
|
||||
cpu: "500m"
|
||||
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
|
||||
# ArgoCD uses KSOPS plugin to decrypt synthesis-endpoints.enc.yaml
|
||||
# before creating the ConfigMap in the cluster
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: memory-service
|
||||
namespace: poimen
|
||||
labels:
|
||||
app: memory-service
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: http
|
||||
protocol: TCP
|
||||
name: http
|
||||
selector:
|
||||
app: memory-service
|
||||
Reference in New Issue
Block a user