--- apiVersion: apps/v1 kind: Deployment metadata: name: memory-app namespace: poimen labels: app: memory-service spec: replicas: 2 selector: matchLabels: app: memory-service template: metadata: labels: app: memory-service annotations: # Trigger pod restart if ConfigMap changes checksum/config: "synthesis-endpoints" spec: serviceAccountName: memory-app containers: - name: memory-app image: forgejo.riotpiao.com/rock/poimen-memory:latest imagePullPolicy: IfNotPresent ports: - name: http containerPort: 8080 protocol: TCP # ConfigMap-injected env vars (decrypted by ArgoCD+KSOPS from .enc.yaml) envFrom: - configMapRef: name: synthesis-endpoints # Individual env vars for app config env: - name: RUST_LOG value: "info,memory=debug" - name: PORT value: "8080" # JWT secret from vault (NOT ConfigMap) - name: JWT_SECRET valueFrom: secretKeyRef: name: jwt-secrets key: signing-key livenessProbe: httpGet: path: /health port: http initialDelaySeconds: 10 periodSeconds: 30 readinessProbe: httpGet: path: /health port: http initialDelaySeconds: 5 periodSeconds: 10 resources: requests: memory: "256Mi" cpu: "100m" limits: memory: "1Gi" cpu: "500m" securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true runAsNonRoot: true runAsUser: 1000 capabilities: drop: - ALL # ArgoCD uses KSOPS plugin to decrypt synthesis-endpoints.enc.yaml # before creating the ConfigMap in the cluster --- apiVersion: v1 kind: Service metadata: name: memory-service namespace: poimen labels: app: memory-service spec: type: ClusterIP ports: - port: 80 targetPort: http protocol: TCP name: http selector: app: memory-service