k8s-and-chill/rendered/envs/production/ocis/deployment-appregistry.yaml
Felix Wolf 2ea94241af fix(ocis): Move secret generation to PreSync init Job
Removes all 13 Helm-generated secrets from rendered output and instead
generates them at deploy time via an init Job. The Job creates secrets
with random credentials only if they don't already exist, ensuring
idempotent deploys. Runs as ArgoCD PreSync hook so secrets are ready
before oCIS pods start.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 13:27:17 +02:00

112 lines
3.2 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
annotations:
a8r.io/repository: ssh://git@git.tr1ceracop.de:222/gitea_admin/k8s-and-chill.git
labels:
app.kubernetes.io/instance: ocis
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: ocis
app.kubernetes.io/version: 7.1.4
helm.sh/chart: ocis-0.7.0
name: appregistry
namespace: ocis
spec:
replicas: 1
selector:
matchLabels:
app: appregistry
strategy:
rollingUpdate:
maxSurge: 25%
maxUnavailable: 25%
type: RollingUpdate
template:
metadata:
annotations:
checksum/config: 0dffa4f8f27458fef0dec7d83ed4cc950c3d3793ad1ac0a3a3139ee3a8715bf0
labels:
app: appregistry
app.kubernetes.io/instance: ocis
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: ocis
app.kubernetes.io/version: 7.1.4
helm.sh/chart: ocis-0.7.0
spec:
containers:
- args:
- app-registry
- server
command:
- ocis
env:
- name: MICRO_REGISTRY
value: nats-js-kv
- name: MICRO_REGISTRY_ADDRESS
value: nats:9233
- name: APP_REGISTRY_LOG_COLOR
value: "false"
- name: APP_REGISTRY_LOG_LEVEL
value: info
- name: APP_REGISTRY_LOG_PRETTY
value: "false"
- name: APP_REGISTRY_TRACING_ENABLED
value: "false"
- name: APP_REGISTRY_TRACING_TYPE
value: jaeger
- name: APP_REGISTRY_TRACING_ENDPOINT
value: null
- name: APP_REGISTRY_TRACING_COLLECTOR
value: null
- name: APP_REGISTRY_DEBUG_PPROF
value: "false"
- name: APP_REGISTRY_GRPC_ADDR
value: 0.0.0.0:9242
- name: APP_REGISTRY_DEBUG_ADDR
value: 0.0.0.0:9243
- name: APP_REGISTRY_JWT_SECRET
valueFrom:
secretKeyRef:
key: jwt-secret
name: ocis-jwt-secret
image: owncloud/ocis:7.1.4
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
httpGet:
path: /healthz
port: metrics-debug
initialDelaySeconds: 60
periodSeconds: 20
timeoutSeconds: 10
name: appregistry
ports:
- containerPort: 9242
name: grpc
- containerPort: 9243
name: metrics-debug
resources:
requests:
cpu: 10m
memory: 64Mi
securityContext:
readOnlyRootFilesystem: true
runAsGroup: 1000
runAsNonRoot: true
runAsUser: 1000
volumeMounts:
- mountPath: /tmp
name: tmp-volume
- mountPath: /etc/ocis
name: configs
nodeSelector: {}
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
volumes:
- emptyDir: {}
name: tmp-volume
- configMap:
name: appregistry-config
name: configs