Files
schemas/k8s/deploy.yaml
argoyle 6beb46a657
Unbound Release / Check Preconditions (push) Successful in 21s
Unbound Release / Create Release (push) Skipped
pre-commit / pre-commit (push) Skipped
Unbound Release / Generate Changelog and Handle PR (push) Successful in 48s
Unbound Release / Create Tag (push) Successful in 24s
Release / release (push) Successful in 11m1s
schemas / build (push) Successful in 3m19s
schemas / check (push) Successful in 1m33s
schemas / vulnerabilities (push) Successful in 1m2s
schemas / check-release (push) Successful in 58s
schemas / deploy-prod (push) Successful in 1m22s
chore(k8s): take the image reference from build-tools (#986)
## Summary

`k8s/deploy.yaml` takes the image from build-tools: `image: ${IMAGE}` instead of the hard-coded `oci.unbound.se/unboundsoftware/schemas:${COMMIT}`.

`deploy` substitutes `${IMAGE}` with `<registry>/<owner>/<name>:<tag>`, where the registry comes from the build-tools config and the tag is the value `${COMMIT}` gets today. The rendered reference is unchanged. Moving off `oci.unbound.se` later becomes one change in infra.

Validated on shiny/time-service#864: merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
- unboundsoftware/infra#1808: registry in `BUILDTOOLS_FROSTMOLN_STAGING`
- shiny/acctest#952: acctest pins build-tools to the Gitea registry

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Reviewed-on: https://gitea.unbound.se/unboundsoftware/schemas/pulls/986
2026-10-02 22:40:05 +00:00

95 lines
2.1 KiB
YAML

apiVersion: v1
kind: ServiceAccount
metadata:
name: schemas
---
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
app.kubernetes.io/name: schemas
name: schemas
annotations:
kubernetes.io/change-cause: "${TIMESTAMP} Deployed commit id: ${COMMIT}"
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: schemas
strategy:
rollingUpdate:
maxSurge: 1
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app.kubernetes.io/name: schemas
spec:
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchExpressions:
- key: "app.kubernetes.io/name"
operator: In
values:
- schemas
topologyKey: kubernetes.io/hostname
containers:
- name: schemas
resources:
requests:
cpu: "100m"
memory: "128Mi"
limits:
memory: "768Mi"
livenessProbe:
httpGet:
path: /health/live
port: 8080
initialDelaySeconds: 10
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /health/ready
port: 8080
initialDelaySeconds: 5
periodSeconds: 5
timeoutSeconds: 5
failureThreshold: 3
imagePullPolicy: IfNotPresent
image: ${IMAGE}
ports:
- name: api
containerPort: 8080
env:
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: http://k8s-monitoring-alloy.monitoring.svc.cluster.local:4318
envFrom:
- configMapRef:
name: schemas
- secretRef:
name: schemas
restartPolicy: Always
serviceAccountName: schemas
---
apiVersion: v1
kind: Service
metadata:
name: schemas
spec:
ports:
- port: 80
name: api
protocol: TCP
targetPort: 8080
selector:
app.kubernetes.io/name: schemas
type: NodePort