Unbound Release / Check Preconditions (push) Successful in 21s
Unbound Release / Create Release (push) Skipped
pre-commit / pre-commit (push) Skipped
Unbound Release / Generate Changelog and Handle PR (push) Successful in 48s
Unbound Release / Create Tag (push) Successful in 24s
Release / release (push) Successful in 11m1s
schemas / build (push) Successful in 3m19s
schemas / check (push) Successful in 1m33s
schemas / vulnerabilities (push) Successful in 1m2s
schemas / check-release (push) Successful in 58s
schemas / deploy-prod (push) Successful in 1m22s
## Summary
`k8s/deploy.yaml` takes the image from build-tools: `image: ${IMAGE}` instead of the hard-coded `oci.unbound.se/unboundsoftware/schemas:${COMMIT}`.
`deploy` substitutes `${IMAGE}` with `<registry>/<owner>/<name>:<tag>`, where the registry comes from the build-tools config and the tag is the value `${COMMIT}` gets today. The rendered reference is unchanged. Moving off `oci.unbound.se` later becomes one change in infra.
Validated on shiny/time-service#864: merged and deployed to AWS staging and Frostmoln staging with the same image. Prerequisites, all merged:
- unboundsoftware/infra#1808: registry in `BUILDTOOLS_FROSTMOLN_STAGING`
- shiny/acctest#952: acctest pins build-tools to the Gitea registry
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Reviewed-on: https://gitea.unbound.se/unboundsoftware/schemas/pulls/986
95 lines
2.1 KiB
YAML
95 lines
2.1 KiB
YAML
apiVersion: v1
|
|
kind: ServiceAccount
|
|
metadata:
|
|
name: schemas
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: schemas
|
|
name: schemas
|
|
annotations:
|
|
kubernetes.io/change-cause: "${TIMESTAMP} Deployed commit id: ${COMMIT}"
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: schemas
|
|
strategy:
|
|
rollingUpdate:
|
|
maxSurge: 1
|
|
maxUnavailable: 1
|
|
type: RollingUpdate
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: schemas
|
|
spec:
|
|
affinity:
|
|
podAntiAffinity:
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 100
|
|
podAffinityTerm:
|
|
labelSelector:
|
|
matchExpressions:
|
|
- key: "app.kubernetes.io/name"
|
|
operator: In
|
|
values:
|
|
- schemas
|
|
topologyKey: kubernetes.io/hostname
|
|
containers:
|
|
- name: schemas
|
|
resources:
|
|
requests:
|
|
cpu: "100m"
|
|
memory: "128Mi"
|
|
limits:
|
|
memory: "768Mi"
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /health/live
|
|
port: 8080
|
|
initialDelaySeconds: 10
|
|
periodSeconds: 10
|
|
timeoutSeconds: 5
|
|
failureThreshold: 3
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /health/ready
|
|
port: 8080
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
timeoutSeconds: 5
|
|
failureThreshold: 3
|
|
imagePullPolicy: IfNotPresent
|
|
image: ${IMAGE}
|
|
ports:
|
|
- name: api
|
|
containerPort: 8080
|
|
env:
|
|
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
|
value: http://k8s-monitoring-alloy.monitoring.svc.cluster.local:4318
|
|
envFrom:
|
|
- configMapRef:
|
|
name: schemas
|
|
- secretRef:
|
|
name: schemas
|
|
restartPolicy: Always
|
|
serviceAccountName: schemas
|
|
---
|
|
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: schemas
|
|
spec:
|
|
ports:
|
|
- port: 80
|
|
name: api
|
|
protocol: TCP
|
|
targetPort: 8080
|
|
selector:
|
|
app.kubernetes.io/name: schemas
|
|
type: NodePort
|