Problem: LLM_API_URL hardcoded to external HTTPS endpoint
- https://api.riotpiao.com/v1/chat/completions (TLS hairpin through nginx)
- Not externalizable for CI or environment-specific deployment
Solution: Move to SOPS-encrypted ConfigMap with in-cluster endpoint
- LLM_API_URL: http://api-gateway.api.svc.cluster.local:8080/v1/chat/completions
- No TLS overhead, direct cluster communication
- Encrypted for security (SOPS + age key)
- Externalizable: CI can update values without app redeployment
Changes:
1. Create configmap.enc.yaml (SOPS-encrypted)
- Data: LLM_API_URL, LLM_MODEL
- Encrypted with .sops.yaml age key
2. Update deployment.yaml
- Change from 'value:' to 'valueFrom: configMapKeyRef'
- Reference portfolio-llm-config ConfigMap
3. Update kustomization.yaml
- Add configmap.enc.yaml to resources
- Add sops: version: 3 for decryption
Benefits:
- ArgoCD auto-decrypts via SOPS before applying
- CI can auto-patch ConfigMap without app changes
- Environment-specific config (dev/staging/prod)
- Secrets encrypted in git (never plain text)