state-hub/deploy/railiance/apps/helm/state-hub-values.yaml
tegwick d8e1810359
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
pin registrar guard retirement deployment
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 19:36:35 +02:00

57 lines
2 KiB
YAML

# Production values for the State Hub Railiance chart handoff.
# Non-secret values only. DATABASE_URL comes from the Secret `state-hub-env`.
namespace:
create: false
image:
repository: forgejo.coulomb.social/coulomb/state-hub
tag: "main-5dd04dc"
ingress:
enabled: false
# MCP layer on central (CUST-WP-0067-T08). Enabled together with the image tag
# above: MCP_HOST landed in main-6c1262e, and enabling this on an older image
# would deploy a pod that binds loopback and never becomes reachable.
# ClusterIP only — no ingress, same reason the API's is disabled.
mcp:
enabled: true
config:
# This deployment is the authoritative hub. Callers verify this rather than
# trusting that whatever answered on a port is central (CUST-WP-0067-T03).
instanceRole: primary
instanceLabel: railiance01
sbomNexusUrl: "http://sbom-nexus.sbom-nexus.svc.cluster.local:8010"
# Reversible T04 read cutover; set back to `legacy` to roll back.
sbomNexusReadMode: nexus
# Reversible T04 write cutover; set back to `legacy` to roll back future writes.
sbomNexusWriteMode: nexus
resources:
# The single 4-core node currently has less than 250m unallocated. Keep enough
# headroom for maxSurge=1 so State Hub can roll without an outage.
requests:
cpu: 100m
memory: 512Mi
limits:
cpu: 1000m
memory: 2Gi
sweep:
# RMGR-WP-0005-T11: disabled while railiance01 checkouts still target the
# stale gitea-remote lineage. Re-enable only after the governed remote
# reconciliation and registrar preflight are complete.
enabled: false
# Present in the live release but previously missing here, so deploying from
# this file alone silently dropped it. Inert while enabled is false.
hostname: 239.62.205.92.host.secureserver.net
hostPath: /home/tegwick
sshHostPath: /home/tegwick/.ssh
# Forge read credential (STATE-WP-0084-T02). Coordinates only — the token lives
# in OpenBao at platform/workloads/state-hub/forge-derivation and reaches the
# pod through Kubernetes auth, never through this file or a Secret.
forgeRead:
enabled: true