Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
57 lines
2 KiB
YAML
57 lines
2 KiB
YAML
# Production values for the State Hub Railiance chart handoff.
|
|
# Non-secret values only. DATABASE_URL comes from the Secret `state-hub-env`.
|
|
|
|
namespace:
|
|
create: false
|
|
|
|
image:
|
|
repository: forgejo.coulomb.social/coulomb/state-hub
|
|
tag: "main-5dd04dc"
|
|
|
|
ingress:
|
|
enabled: false
|
|
|
|
# MCP layer on central (CUST-WP-0067-T08). Enabled together with the image tag
|
|
# above: MCP_HOST landed in main-6c1262e, and enabling this on an older image
|
|
# would deploy a pod that binds loopback and never becomes reachable.
|
|
# ClusterIP only — no ingress, same reason the API's is disabled.
|
|
mcp:
|
|
enabled: true
|
|
|
|
config:
|
|
# This deployment is the authoritative hub. Callers verify this rather than
|
|
# trusting that whatever answered on a port is central (CUST-WP-0067-T03).
|
|
instanceRole: primary
|
|
instanceLabel: railiance01
|
|
sbomNexusUrl: "http://sbom-nexus.sbom-nexus.svc.cluster.local:8010"
|
|
# Reversible T04 read cutover; set back to `legacy` to roll back.
|
|
sbomNexusReadMode: nexus
|
|
# Reversible T04 write cutover; set back to `legacy` to roll back future writes.
|
|
sbomNexusWriteMode: nexus
|
|
|
|
resources:
|
|
# The single 4-core node currently has less than 250m unallocated. Keep enough
|
|
# headroom for maxSurge=1 so State Hub can roll without an outage.
|
|
requests:
|
|
cpu: 100m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: 1000m
|
|
memory: 2Gi
|
|
|
|
sweep:
|
|
# RMGR-WP-0005-T11: disabled while railiance01 checkouts still target the
|
|
# stale gitea-remote lineage. Re-enable only after the governed remote
|
|
# reconciliation and registrar preflight are complete.
|
|
enabled: false
|
|
# Present in the live release but previously missing here, so deploying from
|
|
# this file alone silently dropped it. Inert while enabled is false.
|
|
hostname: 239.62.205.92.host.secureserver.net
|
|
hostPath: /home/tegwick
|
|
sshHostPath: /home/tegwick/.ssh
|
|
|
|
# Forge read credential (STATE-WP-0084-T02). Coordinates only — the token lives
|
|
# in OpenBao at platform/workloads/state-hub/forge-derivation and reaches the
|
|
# pod through Kubernetes auth, never through this file or a Secret.
|
|
forgeRead:
|
|
enabled: true
|