apiVersion: v1 kind: Namespace metadata: name: approval-engine labels: kubernetes.io/metadata.name: approval-engine railiance.io/workload-class: platform --- apiVersion: v1 kind: Service metadata: name: approval-engine namespace: approval-engine spec: selector: app.kubernetes.io/name: approval-engine ports: - {name: http, port: 8080, targetPort: http, protocol: TCP} --- apiVersion: apps/v1 kind: StatefulSet metadata: name: approval-engine namespace: approval-engine spec: serviceName: approval-engine replicas: 1 podManagementPolicy: OrderedReady updateStrategy: {type: OnDelete} selector: matchLabels: app.kubernetes.io/name: approval-engine template: metadata: labels: app.kubernetes.io/name: approval-engine spec: securityContext: runAsNonRoot: true runAsUser: 10001 fsGroup: 10001 seccompProfile: {type: RuntimeDefault} initContainers: - name: migrate image: forgejo.coulomb.social/coulomb/approval-engine@sha256:REPLACE_WITH_RELEASE_DIGEST args: ["migrate", "--db", "/data/approvals.sqlite"] securityContext: allowPrivilegeEscalation: false capabilities: {drop: ["ALL"]} readOnlyRootFilesystem: true volumeMounts: - {name: data, mountPath: /data} - {name: tmp, mountPath: /tmp} containers: - name: approval-engine image: forgejo.coulomb.social/coulomb/approval-engine@sha256:REPLACE_WITH_RELEASE_DIGEST args: - serve - --production - --db - /data/approvals.sqlite - --host - 0.0.0.0 - --port - "8080" - --tenant - platform - --jwt-issuer - https://auth.netkingdom.local - --jwt-audience - approval-engine - --jwks-url - http://key-cape.sso.svc.cluster.local:8080/jwks - --audit-url - http://audit-core.audit-core.svc.cluster.local:8080 - --audit-token-file - /var/run/secrets/approval-engine/audit-token ports: - {name: http, containerPort: 8080} resources: requests: {cpu: 50m, memory: 64Mi} limits: {cpu: 500m, memory: 256Mi} securityContext: allowPrivilegeEscalation: false capabilities: {drop: ["ALL"]} readOnlyRootFilesystem: true startupProbe: httpGet: {path: /healthz, port: http} periodSeconds: 3 failureThreshold: 20 readinessProbe: httpGet: {path: /readyz, port: http} periodSeconds: 10 timeoutSeconds: 2 livenessProbe: httpGet: {path: /healthz, port: http} periodSeconds: 20 timeoutSeconds: 2 volumeMounts: - {name: data, mountPath: /data} - {name: tmp, mountPath: /tmp} - name: audit-token mountPath: /var/run/secrets/approval-engine readOnly: true volumes: - name: tmp emptyDir: {} - name: audit-token secret: secretName: approval-engine-audit defaultMode: 0440 volumeClaimTemplates: - metadata: name: data spec: accessModes: ["ReadWriteOnce"] resources: requests: {storage: 1Gi}