audit-core/deploy
tegwick cf8c740b1b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Switch receiver rollout to Recreate and pin bounded-readyz image
RollingUpdate maxSurge cannot schedule a second 50m pod on a node
packed to 99% CPU requests. Recreate replaces in place; the Service
already has no ready endpoints.

Image sha256:ec15f63d… is commit bc3d80f. Local release check passed
against disposable Postgres. No schema migration. Live Ready still
depends on a fresh runtime lease from ESO/OpenBao.

Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
2026-09-14 23:01:23 +02:00
..
attest-cronjob.yaml Pin factory-compatible audit receiver release 2026-09-11 06:48:47 +02:00
audit-core.yaml Switch receiver rollout to Recreate and pin bounded-readyz image 2026-09-14 23:01:23 +02:00
clustersecretstore.yaml Read mounted DB credentials from a Kubernetes snapshot 2026-08-13 12:25:32 +02:00
externalsecret-senders.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
externalsecrets.yaml Stand up railiance01 receiver without founder bao kv put 2026-08-13 10:27:13 +02:00
migrate-job.yaml Switch receiver rollout to Recreate and pin bounded-readyz image 2026-09-14 23:01:23 +02:00
networkpolicies.yaml AUDIT-WP-0009 T02/T10 — schedule attestation, and make the §5 check total 2026-09-10 16:39:20 +02:00
README.md Switch receiver rollout to Recreate and pin bounded-readyz image 2026-09-14 23:01:23 +02:00
senders-scope.json AUDIT-WP-0010 T01/T03/T04 — admit tenant-engine, and the envelope does not match 2026-09-10 16:34:45 +02:00
senders-scope.yaml AUDIT-WP-0010 T01/T03/T04 — admit tenant-engine, and the envelope does not match 2026-09-10 16:34:45 +02:00

railiance01 package

Target: railiance01 only. The workstation kubeconfig that talks to that API is the k3s-api-railiance01 tunnel (local port 16444). ~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite the server port or export a copy before applying.

Apply order is documented in docs/operator-runbook.md. Do not apply the Deployment until:

  1. The image digest is pinned (currently sha256:ec15f63d… from commit bc3d80f).
  2. Secrets audit-core-database, audit-core-database-migrate, and audit-core-senders exist. ConfigMap audit-core-senders-scope is applied (deploy/senders-scope.yaml) before the Deployment mounts it.
  3. Job audit-core-migrate has completed.
make image-build
make deploy-dry-run