RollingUpdate maxSurge cannot schedule a second 50m pod on a node
packed to 99% CPU requests. Recreate replaces in place; the Service
already has no ready endpoints.
Image sha256:ec15f63d… is commit bc3d80f. Local release check passed
against disposable Postgres. No schema migration. Live Ready still
depends on a fresh runtime lease from ESO/OpenBao.
Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
773 B
773 B
railiance01 package
Target: railiance01 only. The workstation kubeconfig that talks to that API
is the k3s-api-railiance01 tunnel (local port 16444).
~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite
the server port or export a copy before applying.
Apply order is documented in docs/operator-runbook.md. Do not apply the
Deployment until:
- The image digest is pinned (currently
sha256:ec15f63d…from commitbc3d80f). - Secrets
audit-core-database,audit-core-database-migrate, andaudit-core-sendersexist. ConfigMapaudit-core-senders-scopeis applied (deploy/senders-scope.yaml) before the Deployment mounts it. - Job
audit-core-migratehas completed.
make image-build
make deploy-dry-run