rapp-canned-prompts/manifests/runtime.yaml
tegwick 8dc6257d93 Publish the image, pin it by digest, and request the database
RCP-WP-0002-T01 done. Published
forgejo.coulomb.social/coulomb/canned-prompts:0.1.0 and pinned
sha256:e0ded3c7fe25... in declarations/rapp.yaml and both manifests.

Pinned by digest rather than tag: a tag can be moved, and
live-image-digest-match would then pass against something that is no longer
what this repo reviewed. Verified after the push by fetching the manifest back
by digest rather than trusting the push output.

readiness_state draft -> declared. Not deployed, so not `deployed`.

T02 requested rather than performed. rapp-postgres now carries
consumers/canned-prompts.yaml against its documented PostgresConsumer shape,
and its agent has the request. `make provision-consumers`, which mints the
OpenBao credentials, was deliberately not run: credential issuance belongs to
that repo's operator, and running it from the consuming side would take a
decision that is not this repo's, however available the script is.

T03 and T04 move to wait behind it.

Also corrected a check of my own: I briefly read the cluster list as lacking
platform-pg-2 and suspected the manifests targeted a host that does not exist.
That was my own truncated output. platform-pg-2 is present and healthy, and the
postgres-client label matches what sbom-nexus actually carries in the cluster
rather than only what its repo says.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bjefh8NUiEiahN4JLwoSKM

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 388925@bnt-lap001
Assistant-Session: 3507023f-e0fd-4a1e-9d90-a0d4217d1502
2026-09-07 08:43:35 +02:00

169 lines
4.8 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: canned-prompts
namespace: canned-prompts
labels:
app.kubernetes.io/name: canned-prompts
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: canned-prompts
template:
metadata:
labels:
app.kubernetes.io/name: canned-prompts
app.kubernetes.io/part-of: canned-prompts
spec:
automountServiceAccountToken: false
serviceAccountName: canned-prompts
securityContext:
runAsNonRoot: true
runAsUser: 10001
runAsGroup: 10001
fsGroup: 10001
seccompProfile:
type: RuntimeDefault
containers:
- name: canned-prompts
image: forgejo.coulomb.social/coulomb/canned-prompts@sha256:e0ded3c7fe2548c910445deaa31ec42e84f129a92aa324841e231a53fee1f123
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 8000
env:
# The URL arrives as a mounted file, never as an env var: an env var
# holding a password shows up in `kubectl describe`, in crash dumps,
# and to anything that can read /proc.
- name: CANNED_PROMPTS_DATABASE_URL_FILE
value: /var/run/secrets/postgres-runtime/url
- name: CANNED_PROMPTS_PUBLISH_TOKEN_FILE
value: /var/run/secrets/publish/token
- name: CANNED_PROMPTS_TENANT
value: railiance
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
readOnlyRootFilesystem: true
readinessProbe:
httpGet:
path: /readyz
port: http
periodSeconds: 5
livenessProbe:
# /healthz deliberately checks only that the process is up. Pointing
# liveness at a database-dependent path would restart every replica
# during a database blip, turning a brief outage into an outage plus
# a thundering herd.
httpGet:
path: /healthz
port: http
periodSeconds: 20
startupProbe:
httpGet:
path: /readyz
port: http
failureThreshold: 30
periodSeconds: 2
resources:
requests:
cpu: 25m
memory: 96Mi
limits:
cpu: 500m
memory: 384Mi
volumeMounts:
- name: postgres-runtime
mountPath: /var/run/secrets/postgres-runtime
readOnly: true
- name: publish
mountPath: /var/run/secrets/publish
readOnly: true
volumes:
- name: postgres-runtime
secret:
defaultMode: 0440
secretName: canned-prompts-postgres-runtime
items:
- key: url
path: url
- name: publish
secret:
defaultMode: 0440
secretName: canned-prompts-publish-token
optional: true
items:
- key: token
path: token
---
apiVersion: v1
kind: Service
metadata:
name: canned-prompts
namespace: canned-prompts
spec:
# ClusterIP only. No Ingress, no LoadBalancer: this registry is reachable
# from inside the cluster and nowhere else, which is what
# `private-service-only` in the smoke contract asserts.
type: ClusterIP
selector:
app.kubernetes.io/name: canned-prompts
ports:
- name: http
port: 8000
targetPort: http
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: canned-prompts
namespace: canned-prompts
automountServiceAccountToken: false
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: canned-prompts-default-deny
namespace: canned-prompts
spec:
podSelector: {}
policyTypes: [Ingress, Egress]
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: canned-prompts-runtime
namespace: canned-prompts
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: canned-prompts
policyTypes: [Ingress, Egress]
ingress:
- from:
- namespaceSelector: {}
ports:
- protocol: TCP
port: 8000
egress:
# PostgreSQL and DNS only. The service fetches nothing: a package arrives
# by publish, never by the registry reaching out, so it needs no egress to
# the internet and is not given any.
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: databases
ports:
- protocol: TCP
port: 5432
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
ports:
- protocol: UDP
port: 53
- protocol: TCP
port: 53