rapp-canned-prompts/manifests/migration.yaml
tegwick 8dc6257d93 Publish the image, pin it by digest, and request the database
RCP-WP-0002-T01 done. Published
forgejo.coulomb.social/coulomb/canned-prompts:0.1.0 and pinned
sha256:e0ded3c7fe25... in declarations/rapp.yaml and both manifests.

Pinned by digest rather than tag: a tag can be moved, and
live-image-digest-match would then pass against something that is no longer
what this repo reviewed. Verified after the push by fetching the manifest back
by digest rather than trusting the push output.

readiness_state draft -> declared. Not deployed, so not `deployed`.

T02 requested rather than performed. rapp-postgres now carries
consumers/canned-prompts.yaml against its documented PostgresConsumer shape,
and its agent has the request. `make provision-consumers`, which mints the
OpenBao credentials, was deliberately not run: credential issuance belongs to
that repo's operator, and running it from the consuming side would take a
decision that is not this repo's, however available the script is.

T03 and T04 move to wait behind it.

Also corrected a check of my own: I briefly read the cluster list as lacking
platform-pg-2 and suspected the manifests targeted a host that does not exist.
That was my own truncated output. platform-pg-2 is present and healthy, and the
postgres-client label matches what sbom-nexus actually carries in the cluster
rather than only what its repo says.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 388925@bnt-lap001
Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-07 08:43:35 +02:00

63 lines
2.1 KiB
YAML

# Schema migration as a Job, not an init container and not a start-up hook.
# Running migrations at start-up races between replicas and couples a rollback
# of the code to a rollback of the schema. The Job name carries the target
# revision so a re-apply at the same revision is a no-op rather than a rerun.
apiVersion: batch/v1
kind: Job
metadata:
name: canned-prompts-schema-migration-0002
namespace: canned-prompts
labels:
app.kubernetes.io/name: canned-prompts-migration
app.kubernetes.io/component: migration
spec:
backoffLimit: 2
ttlSecondsAfterFinished: 86400
template:
metadata:
labels:
app.kubernetes.io/name: canned-prompts-migration
spec:
automountServiceAccountToken: false
restartPolicy: Never
securityContext:
runAsNonRoot: true
runAsUser: 10001
runAsGroup: 10001
fsGroup: 10001
seccompProfile:
type: RuntimeDefault
containers:
- name: migrate
image: forgejo.coulomb.social/coulomb/canned-prompts@sha256:e0ded3c7fe2548c910445deaa31ec42e84f129a92aa324841e231a53fee1f123
command: ["alembic"]
args: ["upgrade", "head"]
workingDir: /app
env:
# The migration role owns the schema; the runtime role does not.
- name: CANNED_PROMPTS_DATABASE_URL_FILE
value: /var/run/secrets/postgres-migration/url
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
readOnlyRootFilesystem: true
resources:
requests:
cpu: 25m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumeMounts:
- name: postgres-migration
mountPath: /var/run/secrets/postgres-migration
readOnly: true
volumes:
- name: postgres-migration
secret:
defaultMode: 0440
secretName: canned-prompts-postgres-migration
items:
- key: url
path: url