2026-09-23 20:01:30 +02:00
|
|
|
# REFERENCE ONLY - DO NOT APPLY. Not the runtime source of truth (ADR-0015).
|
2026-09-28 12:40:03 +02:00
|
|
|
# Only historical tenant-engine objects remain, pending its owner's disposition.
|
|
|
|
|
# Live tenant-engine differs in image, storage, strategy, environment and egress.
|
|
|
|
|
# The obsolete flex-auth objects were removed under NK-WP-0039-T04.
|
|
|
|
|
# Authoritative flex-auth declarations (repository: coulomb/flex-auth):
|
|
|
|
|
# values/tenant-engine.yaml
|
|
|
|
|
# values/user-engine.yaml
|
|
|
|
|
# Rendered by that repository's charts/flex-auth, including caller enforcement.
|
|
|
|
|
# See README.md for owner links, retained runtime names and the remaining gate.
|
2026-08-09 01:39:57 +02:00
|
|
|
apiVersion: v1
|
|
|
|
|
kind: Namespace
|
|
|
|
|
metadata: {name: tenant-engine, labels: {net-kingdom/component: tenant-engine}}
|
|
|
|
|
---
|
|
|
|
|
apiVersion: v1
|
|
|
|
|
kind: PersistentVolumeClaim
|
|
|
|
|
metadata: {name: tenant-engine-data, namespace: tenant-engine}
|
|
|
|
|
spec: {accessModes: [ReadWriteOnce], resources: {requests: {storage: 1Gi}}}
|
|
|
|
|
---
|
|
|
|
|
apiVersion: apps/v1
|
|
|
|
|
kind: Deployment
|
|
|
|
|
metadata: {name: tenant-engine, namespace: tenant-engine}
|
|
|
|
|
spec:
|
|
|
|
|
replicas: 1
|
|
|
|
|
strategy: {type: Recreate}
|
|
|
|
|
selector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
|
|
|
|
template:
|
|
|
|
|
metadata: {labels: {app.kubernetes.io/name: tenant-engine}}
|
|
|
|
|
spec:
|
|
|
|
|
automountServiceAccountToken: false
|
|
|
|
|
securityContext: {runAsNonRoot: true, fsGroup: 10001, seccompProfile: {type: RuntimeDefault}}
|
|
|
|
|
containers:
|
|
|
|
|
- name: tenant-engine
|
|
|
|
|
image: forgejo.coulomb.social/coulomb/tenant-engine@sha256:2249e8c6ee44ae36081cddc52daf9c3f63acd18a95a5d620ab4fa7ac85149207
|
|
|
|
|
ports: [{name: http, containerPort: 8090}]
|
|
|
|
|
env:
|
|
|
|
|
- {name: TENANT_ENGINE_DATABASE_PATH, value: /data/tenant-engine.db}
|
|
|
|
|
- {name: TENANT_ENGINE_FLEX_AUTH_URL, value: "http://flex-auth-tenant-engine.flex-auth.svc.cluster.local:8080"}
|
|
|
|
|
volumeMounts: [{name: data, mountPath: /data}]
|
|
|
|
|
securityContext: {allowPrivilegeEscalation: false, capabilities: {drop: ["ALL"]}, readOnlyRootFilesystem: true}
|
|
|
|
|
resources: {requests: {cpu: 25m, memory: 48Mi}, limits: {cpu: 300m, memory: 192Mi}}
|
|
|
|
|
readinessProbe: {httpGet: {path: /health, port: http}, periodSeconds: 5}
|
|
|
|
|
livenessProbe: {httpGet: {path: /health, port: http}, periodSeconds: 20}
|
|
|
|
|
volumes: [{name: data, persistentVolumeClaim: {claimName: tenant-engine-data}}]
|
|
|
|
|
---
|
|
|
|
|
apiVersion: v1
|
|
|
|
|
kind: Service
|
|
|
|
|
metadata: {name: tenant-engine, namespace: tenant-engine}
|
|
|
|
|
spec: {selector: {app.kubernetes.io/name: tenant-engine}, ports: [{name: http, port: 8090, targetPort: http}]}
|
|
|
|
|
---
|
|
|
|
|
apiVersion: networking.k8s.io/v1
|
|
|
|
|
kind: NetworkPolicy
|
|
|
|
|
metadata: {name: tenant-engine, namespace: tenant-engine}
|
|
|
|
|
spec:
|
|
|
|
|
podSelector: {matchLabels: {app.kubernetes.io/name: tenant-engine}}
|
|
|
|
|
policyTypes: [Ingress, Egress]
|
|
|
|
|
ingress:
|
|
|
|
|
- from:
|
|
|
|
|
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: user-engine}}
|
|
|
|
|
podSelector: {matchLabels: {app.kubernetes.io/name: user-engine}}
|
|
|
|
|
ports: [{protocol: TCP, port: 8090}]
|
|
|
|
|
egress:
|
|
|
|
|
- to:
|
|
|
|
|
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: flex-auth}}
|
|
|
|
|
podSelector: {matchLabels: {app.kubernetes.io/name: flex-auth-tenant-engine}}
|
|
|
|
|
ports: [{protocol: TCP, port: 8080}]
|
|
|
|
|
- to:
|
|
|
|
|
- namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: kube-system}}
|
|
|
|
|
ports: [{protocol: UDP, port: 53}, {protocol: TCP, port: 53}]
|