Add Railiance staged-promotion overlay for flex-auth
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

FLEX-WP-0011 T01/T02: railiance.app.v1 contract, independently pinned
Helm values for tenant-engine and user-engine, isolated canary cycle
(deploy/observe/promote/rollback), and emergency kubectl path retained.
T03 waits on the custodian drain-plan row.
This commit is contained in:
tegwick 2026-08-16 01:32:31 +02:00
parent 804251514c
commit 1d58f13eb8
19 changed files with 634 additions and 14 deletions

View file

@ -0,0 +1,20 @@
{{- define "flex-auth.image" -}}
{{- if not .Values.image.digest }}
{{- fail "image.digest is required (digest_policy=required); do not deploy by tag" }}
{{- end }}
{{- printf "%s@%s" .Values.image.repository .Values.image.digest -}}
{{- end -}}
{{- define "flex-auth.name" -}}
{{- required "name is required" .Values.name -}}
{{- end -}}
{{- define "flex-auth.selectorLabels" -}}
app.kubernetes.io/name: {{ include "flex-auth.name" . }}
{{- end -}}
{{- define "flex-auth.labels" -}}
{{ include "flex-auth.selectorLabels" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/part-of: flex-auth
{{- end -}}

View file

@ -0,0 +1,48 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "flex-auth.name" . }}
labels:
{{- include "flex-auth.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "flex-auth.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "flex-auth.labels" . | nindent 8 }}
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: flex-auth
image: {{ include "flex-auth.image" . }}
imagePullPolicy: {{ .Values.image.pullPolicy }}
args:
{{- toYaml .Values.args | nindent 12 }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
livenessProbe:
httpGet:
path: {{ .Values.health.path }}
port: http
periodSeconds: 20
readinessProbe:
httpGet:
path: {{ .Values.health.path }}
port: http
periodSeconds: 5
resources:
{{- toYaml .Values.resources | nindent 12 }}
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true

View file

@ -0,0 +1,29 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "flex-auth.name" . }}
labels:
{{- include "flex-auth.labels" . | nindent 4 }}
spec:
podSelector:
matchLabels:
{{- include "flex-auth.selectorLabels" . | nindent 6 }}
policyTypes:
- Ingress
- Egress
egress: []
{{- if .Values.consumer.isolated }}
ingress: []
{{- else }}
ingress:
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: {{ required "consumer.namespace is required when not isolated" .Values.consumer.namespace }}
podSelector:
matchLabels:
app.kubernetes.io/name: {{ required "consumer.podName is required when not isolated" .Values.consumer.podName }}
ports:
- port: {{ .Values.service.port }}
protocol: TCP
{{- end }}

View file

@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "flex-auth.name" . }}
labels:
{{- include "flex-auth.labels" . | nindent 4 }}
spec:
selector:
{{- include "flex-auth.selectorLabels" . | nindent 4 }}
ports:
- name: http
port: {{ .Values.service.port }}
targetPort: http