Prepare scoped GitOps adoption and tested immutable image releases
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 7s
Build and Publish Container Image / build-and-push (push) Successful in 2m18s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
tegwick 2026-09-27 13:50:16 +02:00
parent 5d5ee84d70
commit c12a8fbcfb
12 changed files with 2585 additions and 731 deletions

30
scripts/render_gitops.py Normal file
View file

@ -0,0 +1,30 @@
"""Render only the reviewed application resource set, excluding jobs and custody."""
import argparse
from pathlib import Path
import yaml
ROOT=Path(__file__).resolve().parents[1]
MANAGED={
'ConfigMap': ['actcore-runtime-config','actcore-external-activity-definitions','actcore-report-schemas','actcore-ops-service-inventory'],
'Service': ['actcore-api','actcore-worker-metrics'],
'Deployment': ['actcore-api','actcore-worker','actcore-event-router'],
}
class Dumper(yaml.SafeDumper): pass
def strings(d,v): return d.represent_scalar('tag:yaml.org,2002:str',v,style='|' if '\n' in v else None)
Dumper.add_representer(str,strings)
def render():
docs=list(yaml.safe_load_all((ROOT/'k8s/railiance/20-runtime.yaml').read_text()))
selected=[]
for kind,names in MANAGED.items():
for name in names:
matches=[d for d in docs if d and d['kind']==kind and d['metadata']['name']==name]
if len(matches)!=1: raise ValueError(f'expected exactly one {kind}/{name}')
d=matches[0]
if d['metadata'].get('namespace')!='activity-core': raise ValueError('namespace outside grant')
selected.append(d)
return '# Generated by scripts/render_gitops.py; do not edit directly.\n'+'---\n'.join(yaml.dump(d,Dumper=Dumper,sort_keys=False) for d in selected)
if __name__=='__main__':
parser=argparse.ArgumentParser(); parser.add_argument('--check',action='store_true'); args=parser.parse_args()
path=ROOT/'k8s/gitops/runtime.yaml'; text=render()
if args.check:
if path.read_text()!=text: raise SystemExit('GitOps projection stale; run scripts/render_gitops.py')
else: path.write_text(text)