audit-core/deploy
tegwick 3a7d63e18f
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook
VaultDynamicSecret pulls database/creds/* so a rotating lease is not frozen
into KV. Runtime sets AUDIT_CORE_AUTO_MIGRATE=0; schema is a Job with the
migration lease. Image base is digest-pinned. Namespace and NetworkPolicies
are on the cluster; Deployment waits for the attended OpenBao ESO token.
2026-08-13 00:58:49 +02:00
..
audit-core.yaml Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
clustersecretstore.yaml Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
externalsecrets.yaml Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
migrate-job.yaml Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
networkpolicies.yaml Add deployment manifests, custody-class guard and request counters 2026-08-10 17:42:43 +02:00
README.md Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00
vaultdynamicsecrets.yaml Prepare railiance01 delivery: dynamic leases, migrate Job, operator runbook 2026-08-13 00:58:49 +02:00

railiance01 package

Target: railiance01 only. The workstation kubeconfig that talks to that API is the k3s-api-railiance01 tunnel (local port 16444). ~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite the server port or export a copy before applying.

Apply order is documented in docs/operator-runbook.md. Do not apply the Deployment until:

  1. The image digest is pinned (not REPLACE_AT_RELEASE).
  2. Secrets audit-core-database, audit-core-database-migrate, and audit-core-senders exist.
  3. Job audit-core-migrate has completed.
make image-build
make deploy-dry-run