feat: import Chinese-localized Buzz source snapshot
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
Signed-off-by: cls_宁波本机 <908705107@qq.com>
This commit is contained in:
@@ -0,0 +1,8 @@
|
||||
apiVersion: v2
|
||||
# Published to oci://ghcr.io/block/buzz/charts via push-chart-release/<version>
|
||||
# branches (see docs/push-gateway-deployment.md, "Gateway chart release").
|
||||
name: buzz-push-gateway
|
||||
description: Public capability-gated APNs last-hop gateway for Buzz
|
||||
version: 0.1.0
|
||||
appVersion: "0.1.0"
|
||||
type: application
|
||||
@@ -0,0 +1,13 @@
|
||||
{{- define "push.name" -}}{{ .Release.Name }}-buzz-push-gateway{{- end }}
|
||||
{{- define "push.labels" -}}
|
||||
app.kubernetes.io/name: buzz-push-gateway
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
{{- define "push.runtimeLabels" -}}
|
||||
{{ include "push.labels" . }}
|
||||
app.kubernetes.io/component: runtime
|
||||
{{- end }}
|
||||
{{- define "push.migrationLabels" -}}
|
||||
{{ include "push.labels" . }}
|
||||
app.kubernetes.io/component: migration
|
||||
{{- end }}
|
||||
@@ -0,0 +1,65 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
labels: {{- include "push.runtimeLabels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
strategy: { type: RollingUpdate, rollingUpdate: { maxSurge: 1, maxUnavailable: 0 } }
|
||||
selector:
|
||||
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels: {{- include "push.runtimeLabels" . | nindent 8 }}
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
terminationGracePeriodSeconds: 60
|
||||
securityContext: { runAsNonRoot: true, runAsUser: 65532, runAsGroup: 65532, fsGroup: 65532, seccompProfile: { type: RuntimeDefault } }
|
||||
{{- with .Values.image.pullSecrets }}
|
||||
imagePullSecrets: {{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: gateway
|
||||
image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ required "image.tag or image.digest is required" .Values.image.tag }}{{ end }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities: { drop: [ALL] } }
|
||||
ports:
|
||||
- { name: public, containerPort: 8080 }
|
||||
- { name: health, containerPort: 8081 }
|
||||
env:
|
||||
- { name: BUZZ_PUSH_BIND_ADDR, value: "0.0.0.0:8080" }
|
||||
- { name: BUZZ_PUSH_HEALTH_ADDR, value: "0.0.0.0:8081" }
|
||||
- { name: BUZZ_PUSH_PUBLIC_DELIVERY_URL, value: {{ .Values.publicDeliveryUrl | quote }} }
|
||||
- { name: BUZZ_PUSH_MAX_GRANT_LIFETIME_SECONDS, value: {{ .Values.maxGrantLifetimeSeconds | quote }} }
|
||||
- { name: BUZZ_PUSH_ENABLED_PROFILES, value: {{ .Values.enabledProfiles | quote }} }
|
||||
- { name: BUZZ_PUSH_APP_ATTEST_APP_ID, value: {{ .Values.appAttestAppId | quote }} }
|
||||
- { name: BUZZ_PUSH_APP_ATTEST_ROOT_CERT_PATH, value: /run/buzz/app-attest/root.pem }
|
||||
- { name: BUZZ_PUSH_APNS_KEY_PATH, value: /run/buzz/apns/provider.p8 }
|
||||
{{- range $name := list "DATABASE_URL" "BUZZ_PUSH_APNS_KEY_ID" "BUZZ_PUSH_APNS_TEAM_ID" "BUZZ_PUSH_APNS_TOPIC" "BUZZ_PUSH_GRANT_KEYS" "BUZZ_PUSH_TOKEN_KEYS" }}
|
||||
- name: {{ $name }}
|
||||
valueFrom: { secretKeyRef: { name: {{ $.Values.existingSecret }}, key: {{ $name }} } }
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- { name: app-attest-root, mountPath: /run/buzz/app-attest, readOnly: true }
|
||||
- { name: apns-key, mountPath: /run/buzz/apns, readOnly: true }
|
||||
livenessProbe: { httpGet: { path: /_liveness, port: health }, periodSeconds: 10, timeoutSeconds: 3, failureThreshold: 3 }
|
||||
readinessProbe: { httpGet: { path: /_readiness, port: health }, periodSeconds: 5, timeoutSeconds: 3, failureThreshold: 3 }
|
||||
startupProbe: { httpGet: { path: /_liveness, port: health }, periodSeconds: 2, failureThreshold: 60 }
|
||||
resources: {{- toYaml .Values.resources | nindent 12 }}
|
||||
volumes:
|
||||
- name: app-attest-root
|
||||
secret: { secretName: {{ .Values.appAttestRoot.secretName }}, items: [{ key: {{ .Values.appAttestRoot.secretKey }}, path: root.pem }] }
|
||||
- name: apns-key
|
||||
secret: { secretName: {{ .Values.apnsKey.secretName }}, items: [{ key: {{ .Values.apnsKey.secretKey }}, path: provider.p8 }] }
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector: {{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
tolerations: {{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
affinity: {{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.topologySpreadConstraints }}
|
||||
topologySpreadConstraints: {{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,14 @@
|
||||
{{- if .Values.httpRoute.enabled }}
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
spec:
|
||||
parentRefs: {{- toYaml .Values.httpRoute.parentRefs | nindent 4 }}
|
||||
hostnames: {{- toYaml .Values.httpRoute.hostnames | nindent 4 }}
|
||||
rules:
|
||||
- matches:
|
||||
- path: { type: PathPrefix, value: / }
|
||||
backendRefs:
|
||||
- { name: {{ include "push.name" . }}, port: {{ .Values.service.port }} }
|
||||
{{- end }}
|
||||
@@ -0,0 +1,33 @@
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}-migrate
|
||||
labels: {{- include "push.migrationLabels" . | nindent 4 }}
|
||||
annotations:
|
||||
helm.sh/hook: pre-install,pre-upgrade
|
||||
helm.sh/hook-weight: "-5"
|
||||
helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded
|
||||
spec:
|
||||
backoffLimit: 3
|
||||
template:
|
||||
metadata:
|
||||
labels: {{- include "push.migrationLabels" . | nindent 8 }}
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
automountServiceAccountToken: false
|
||||
securityContext: { runAsNonRoot: true, runAsUser: 65532, runAsGroup: 65532, fsGroup: 65532, seccompProfile: { type: RuntimeDefault } }
|
||||
{{- with .Values.image.pullSecrets }}
|
||||
imagePullSecrets: {{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: migrate
|
||||
image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ required "image.tag or image.digest is required" .Values.image.tag }}{{ end }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
args: ["--migrate-only"]
|
||||
securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities: { drop: [ALL] } }
|
||||
env:
|
||||
- name: BUZZ_PUSH_RUNTIME_DATABASE_ROLE
|
||||
value: {{ .Values.migration.runtimeDatabaseRole | quote }}
|
||||
- name: DATABASE_URL
|
||||
valueFrom: { secretKeyRef: { name: {{ .Values.migration.existingSecret }}, key: {{ .Values.migration.databaseUrlKey }} } }
|
||||
resources: {{- toYaml .Values.migration.resources | nindent 12 }}
|
||||
@@ -0,0 +1,28 @@
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}-migration
|
||||
labels: {{- include "push.migrationLabels" . | nindent 4 }}
|
||||
annotations:
|
||||
# Hooks precede ordinary manifests. Keep this policy alive until the next
|
||||
# release's before-hook-creation cleanup so it covers the later Job hook.
|
||||
helm.sh/hook: pre-install,pre-upgrade
|
||||
helm.sh/hook-weight: "-10"
|
||||
helm.sh/hook-delete-policy: before-hook-creation
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels: {{- include "push.migrationLabels" . | nindent 6 }}
|
||||
policyTypes: [Ingress, Egress]
|
||||
ingress: []
|
||||
egress:
|
||||
- to:
|
||||
- namespaceSelector:
|
||||
matchLabels: {{- toYaml .Values.networkPolicy.dns.namespaceSelector | nindent 14 }}
|
||||
podSelector:
|
||||
matchLabels: {{- toYaml .Values.networkPolicy.dns.podSelector | nindent 14 }}
|
||||
ports: [{ port: 53, protocol: UDP }, { port: 53, protocol: TCP }]
|
||||
- to:
|
||||
{{- range .Values.networkPolicy.postgresEgressCidrs }}
|
||||
- ipBlock: { cidr: {{ . }} }
|
||||
{{- end }}
|
||||
ports: [{ port: 5432, protocol: TCP }]
|
||||
@@ -0,0 +1,42 @@
|
||||
{{- if .Values.networkPolicy.enabled }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
|
||||
policyTypes: [Ingress, Egress]
|
||||
ingress:
|
||||
- ports: [{ port: 8080, protocol: TCP }]
|
||||
{{- if .Values.networkPolicy.monitoring.enabled }}
|
||||
{{- if or (not .Values.networkPolicy.monitoring.namespaceSelector) (not .Values.networkPolicy.monitoring.podSelector) }}
|
||||
{{- fail "networkPolicy.monitoring.enabled requires non-empty namespaceSelector and podSelector so 8081 scrape ingress is scoped, never blanket" }}
|
||||
{{- end }}
|
||||
# Scoped scrape access to the private health/metrics port. Off by default so
|
||||
# 8081 has no pod ingress; when enabled the operator names their scraper.
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels: {{- toYaml .Values.networkPolicy.monitoring.namespaceSelector | nindent 14 }}
|
||||
podSelector:
|
||||
matchLabels: {{- toYaml .Values.networkPolicy.monitoring.podSelector | nindent 14 }}
|
||||
ports: [{ port: 8081, protocol: TCP }]
|
||||
{{- end }}
|
||||
egress:
|
||||
- to:
|
||||
- namespaceSelector:
|
||||
matchLabels: {{- toYaml .Values.networkPolicy.dns.namespaceSelector | nindent 14 }}
|
||||
podSelector:
|
||||
matchLabels: {{- toYaml .Values.networkPolicy.dns.podSelector | nindent 14 }}
|
||||
ports: [{ port: 53, protocol: UDP }, { port: 53, protocol: TCP }]
|
||||
- to:
|
||||
{{- range .Values.networkPolicy.apnsEgressCidrs }}
|
||||
- ipBlock: { cidr: {{ . }} }
|
||||
{{- end }}
|
||||
ports: [{ port: 443, protocol: TCP }]
|
||||
- to:
|
||||
{{- range .Values.networkPolicy.postgresEgressCidrs }}
|
||||
- ipBlock: { cidr: {{ . }} }
|
||||
{{- end }}
|
||||
ports: [{ port: 5432, protocol: TCP }]
|
||||
{{- end }}
|
||||
@@ -0,0 +1,10 @@
|
||||
{{- if .Values.podDisruptionBudget.enabled }}
|
||||
apiVersion: policy/v1
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
spec:
|
||||
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
|
||||
selector:
|
||||
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,19 @@
|
||||
{{- if .Values.podMonitor.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PodMonitor
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
labels: {{- include "push.runtimeLabels" . | nindent 4 }}
|
||||
{{- with .Values.podMonitor.labels }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
selector:
|
||||
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
|
||||
podMetricsEndpoints:
|
||||
# Scrape the private health port only; /metrics is never on the public Service.
|
||||
- port: health
|
||||
path: /metrics
|
||||
interval: {{ .Values.podMonitor.interval }}
|
||||
scrapeTimeout: {{ .Values.podMonitor.scrapeTimeout }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,89 @@
|
||||
{{- if .Values.prometheusRule.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: PrometheusRule
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
labels: {{- include "push.labels" . | nindent 4 }}
|
||||
{{- with .Values.prometheusRule.labels }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
groups:
|
||||
- name: buzz-push-gateway
|
||||
rules:
|
||||
# Sustained configuration faults mean the provider credential/topic is
|
||||
# unhealthy; no endpoint is being invalidated but nothing is delivering.
|
||||
- alert: PushGatewayConfigurationFault
|
||||
expr: |
|
||||
sum(rate(push_gateway_apns_deliveries_total{outcome="configuration_fault"}[5m])) > 0
|
||||
for: 10m
|
||||
labels: { severity: critical }
|
||||
annotations:
|
||||
summary: Push gateway APNs configuration faults
|
||||
description: >-
|
||||
APNs is returning configuration faults (bad/expired provider token
|
||||
or topic). Deliveries are failing without invalidating endpoints.
|
||||
See runbook: check the APNs .p8 key, key id, team id, and topic.
|
||||
# Authority store unavailable at admission = durable dependency is down.
|
||||
- alert: PushGatewayAdmissionUnavailable
|
||||
expr: |
|
||||
sum(rate(push_gateway_admissions_total{result="unavailable"}[5m])) > 0
|
||||
for: 5m
|
||||
labels: { severity: critical }
|
||||
annotations:
|
||||
summary: Push gateway authority store unavailable
|
||||
description: >-
|
||||
authorize_delivery is returning Unavailable — the PostgreSQL
|
||||
authority store is unreachable or failing. Check DB connectivity
|
||||
and the pod's postgres egress NetworkPolicy.
|
||||
# Readiness failing on the authority cause = the pod will be pulled from
|
||||
# rotation; alert before all replicas drop out.
|
||||
- alert: PushGatewayReadinessAuthorityFailing
|
||||
expr: |
|
||||
sum(rate(push_gateway_readiness_failures_total{cause="authority"}[5m])) > 0
|
||||
for: 5m
|
||||
labels: { severity: warning }
|
||||
annotations:
|
||||
summary: Push gateway readiness failing on authority
|
||||
description: >-
|
||||
Readiness probes are failing because the authority store check
|
||||
fails. Replicas will be removed from the Service. Investigate DB
|
||||
health before capacity drops below the PodDisruptionBudget.
|
||||
# The retention reaper sweeps expired rows every 5m; a single transient
|
||||
# failure self-heals on the next tick. Alert on repeated failure —
|
||||
# at least two sweeps failing within ~30m (six ticks) — which grows the
|
||||
# bounded crash-before-release window and leaks storage.
|
||||
- alert: PushGatewayReaperFailing
|
||||
expr: |
|
||||
sum(increase(push_gateway_reaper_failures_total[30m])) >= 2
|
||||
for: 5m
|
||||
labels: { severity: warning }
|
||||
annotations:
|
||||
summary: Push gateway retention reaper failing
|
||||
description: >-
|
||||
The retention reaper has failed at least twice within 30m (it runs
|
||||
every 5m). Expired delivery reservations are not being swept,
|
||||
growing the bounded-until-expiry window. Check DB write availability.
|
||||
# High sustained fraction of retryable APNs outcomes indicates APNs
|
||||
# throttling or degradation. The ratio is a true fraction over the
|
||||
# window (increase = counts, not per-second rate), gated by a minimum
|
||||
# sample count so a couple of retries at trivial volume cannot trip it.
|
||||
- alert: PushGatewayHighApnsRetryRate
|
||||
expr: |
|
||||
(
|
||||
sum(increase(push_gateway_apns_deliveries_total{outcome="retry"}[10m]))
|
||||
/ sum(increase(push_gateway_apns_deliveries_total[10m]))
|
||||
> {{ .Values.prometheusRule.apnsRetryRatioThreshold }}
|
||||
)
|
||||
and
|
||||
sum(increase(push_gateway_apns_deliveries_total[10m])) >= {{ .Values.prometheusRule.apnsRetryMinSamples }}
|
||||
for: 15m
|
||||
labels: { severity: warning }
|
||||
annotations:
|
||||
summary: Push gateway high APNs retry ratio
|
||||
description: >-
|
||||
The retryable fraction of APNs attempts over a 10m window
|
||||
(429/500/503), above a minimum sample count, has exceeded the
|
||||
configured threshold continuously for 15m. APNs may be throttling
|
||||
or degraded; deliveries are delayed but not lost.
|
||||
{{- end }}
|
||||
@@ -0,0 +1,9 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "push.name" . }}
|
||||
labels: {{- include "push.runtimeLabels" . | nindent 4 }}
|
||||
spec:
|
||||
selector: {{- include "push.runtimeLabels" . | nindent 4 }}
|
||||
ports:
|
||||
- { name: https, port: {{ .Values.service.port }}, targetPort: public }
|
||||
@@ -0,0 +1,30 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
python3 - <<'PY'
|
||||
from pathlib import Path
|
||||
import yaml
|
||||
|
||||
auto_path = Path('.github/workflows/auto-tag-on-release-pr-merge.yml')
|
||||
publish_path = Path('.github/workflows/push-gateway-helm-chart.yml')
|
||||
auto_text = auto_path.read_text()
|
||||
publish_text = publish_path.read_text()
|
||||
# Parse first, then pin the cross-workflow strings whose agreement makes this a
|
||||
# reachable lane rather than an orphan publisher.
|
||||
yaml.safe_load(auto_text)
|
||||
yaml.safe_load(publish_text)
|
||||
for needle in (
|
||||
'push-chart-release/*)',
|
||||
'VERSION="${BRANCH#push-chart-release/}"',
|
||||
'TAG_PREFIX="push-chart-v"',
|
||||
'DISPATCH="push-gateway-helm-chart"',
|
||||
'push-gateway-helm-chart) WORKFLOW="push-gateway-helm-chart.yml"',
|
||||
):
|
||||
assert needle in auto_text, f'missing auto-tag gateway chart contract: {needle}'
|
||||
for needle in (
|
||||
'tags: ["push-chart-v[0-9]*"]',
|
||||
'version="${INPUT_VERSION:-${REF_NAME#push-chart-v}}"',
|
||||
'refs/tags/push-chart-v${version}^{commit}',
|
||||
'deploy/charts/buzz-push-gateway',
|
||||
):
|
||||
assert needle in publish_text, f'missing gateway chart publisher contract: {needle}'
|
||||
PY
|
||||
@@ -0,0 +1,150 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
out=$(mktemp); production_out=$(mktemp)
|
||||
trap 'rm -f "$out" "$production_out"' EXIT
|
||||
|
||||
# Defaults must lint and render without parameter injection.
|
||||
helm lint deploy/charts/buzz-push-gateway >/dev/null
|
||||
helm template push deploy/charts/buzz-push-gateway >"$out"
|
||||
# Production values must attach push.buzz.xyz to an explicit Gateway.
|
||||
production_args=(
|
||||
-f deploy/charts/buzz-push-gateway/values-production.yaml
|
||||
--set 'image.digest=sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa'
|
||||
--set 'appAttestAppId=REALTEAM.xyz.buzz'
|
||||
--set 'httpRoute.parentRefs[0].name=production-gateway'
|
||||
--set 'httpRoute.parentRefs[0].namespace=gateway-system'
|
||||
--set 'networkPolicy.postgresEgressCidrs[0]=10.42.0.0/16'
|
||||
)
|
||||
helm lint deploy/charts/buzz-push-gateway "${production_args[@]}" >/dev/null
|
||||
helm template push deploy/charts/buzz-push-gateway "${production_args[@]}" >"$production_out"
|
||||
|
||||
python3 - "$out" "$production_out" <<'PY'
|
||||
import sys,yaml
|
||||
xs=list(yaml.safe_load_all(open(sys.argv[1])))
|
||||
svc=next(x for x in xs if x and x.get('kind')=='Service')
|
||||
assert [p['targetPort'] for p in svc['spec']['ports']]==['public']
|
||||
d=next(x for x in xs if x and x.get('kind')=='Deployment')
|
||||
j=next(x for x in xs if x and x.get('kind')=='Job')
|
||||
runtime={'app.kubernetes.io/name':'buzz-push-gateway','app.kubernetes.io/instance':'push','app.kubernetes.io/component':'runtime'}
|
||||
migration={**runtime,'app.kubernetes.io/component':'migration'}
|
||||
assert svc['spec']['selector']==runtime
|
||||
assert d['spec']['selector']['matchLabels']==runtime
|
||||
assert d['spec']['template']['metadata']['labels']==runtime
|
||||
assert j['spec']['template']['metadata']['labels']==migration
|
||||
assert svc['spec']['selector'] != j['spec']['template']['metadata']['labels']
|
||||
jenv={e['name']:e for e in j['spec']['template']['spec']['containers'][0]['env']}
|
||||
assert jenv['BUZZ_PUSH_RUNTIME_DATABASE_ROLE']['value']=='buzz_push_gateway_runtime'
|
||||
assert 'valueFrom' in jenv['DATABASE_URL']
|
||||
assert j['spec']['template']['spec']['containers'][0]['args']==['--migrate-only']
|
||||
assert j['metadata']['annotations']=={
|
||||
'helm.sh/hook':'pre-install,pre-upgrade',
|
||||
'helm.sh/hook-weight':'-5',
|
||||
'helm.sh/hook-delete-policy':'before-hook-creation,hook-succeeded',
|
||||
}
|
||||
env={e['name'] for e in d['spec']['template']['spec']['containers'][0]['env']}
|
||||
required={'DATABASE_URL','BUZZ_PUSH_APNS_KEY_ID','BUZZ_PUSH_APNS_TEAM_ID','BUZZ_PUSH_APNS_TOPIC','BUZZ_PUSH_GRANT_KEYS','BUZZ_PUSH_TOKEN_KEYS','BUZZ_PUSH_MAX_GRANT_LIFETIME_SECONDS'}
|
||||
assert required <= env
|
||||
assert d['spec']['replicas'] >= 2
|
||||
assert not any(x and x.get('kind')=='HTTPRoute' for x in xs)
|
||||
# Observability is opt-in: default render exposes no scrape CRDs and 8081 stays
|
||||
# free of pod ingress (only 8080 is reachable).
|
||||
assert not any(x and x.get('kind') in ('PodMonitor','PrometheusRule') for x in xs)
|
||||
nps=[x for x in xs if x and x.get('kind')=='NetworkPolicy']
|
||||
np=next(x for x in nps if x['metadata']['name']=='push-buzz-push-gateway')
|
||||
migration_np=next(x for x in nps if x['metadata']['name']=='push-buzz-push-gateway-migration')
|
||||
assert np['spec']['podSelector']['matchLabels']==runtime
|
||||
assert migration_np['spec']['podSelector']['matchLabels']==migration
|
||||
assert migration_np['metadata']['annotations']=={
|
||||
'helm.sh/hook':'pre-install,pre-upgrade',
|
||||
'helm.sh/hook-weight':'-10',
|
||||
'helm.sh/hook-delete-policy':'before-hook-creation',
|
||||
}
|
||||
assert int(migration_np['metadata']['annotations']['helm.sh/hook-weight']) < int(j['metadata']['annotations']['helm.sh/hook-weight'])
|
||||
assert migration_np['spec']['ingress']==[]
|
||||
assert migration_np['spec']['policyTypes']==['Ingress','Egress']
|
||||
migration_ports={p['port'] for rule in migration_np['spec']['egress'] for p in rule.get('ports',[])}
|
||||
assert migration_ports=={53,5432}, migration_ports
|
||||
assert all(p['port'] != 443 for rule in migration_np['spec']['egress'] for p in rule.get('ports',[]))
|
||||
ingress_ports={p['port'] for rule in np['spec']['ingress'] for p in rule.get('ports',[])}
|
||||
assert ingress_ports=={8080}, ingress_ports
|
||||
production=list(yaml.safe_load_all(open(sys.argv[2])))
|
||||
route=next(x for x in production if x and x.get('kind')=='HTTPRoute')
|
||||
assert route['spec']['parentRefs']
|
||||
assert 'push.buzz.xyz' in route['spec']['hostnames']
|
||||
PY
|
||||
|
||||
# Enabling a route without a Gateway attachment must fail schema validation.
|
||||
if helm template push deploy/charts/buzz-push-gateway --set httpRoute.enabled=true >/dev/null 2>&1; then
|
||||
echo 'expected httpRoute.enabled=true without parentRefs to fail' >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# The checked-in production contract is intentionally undeployable until CI or
|
||||
# the release system supplies an immutable digest and environment-owned values.
|
||||
if helm template push deploy/charts/buzz-push-gateway -f deploy/charts/buzz-push-gateway/values-production.yaml >/dev/null 2>&1; then
|
||||
echo 'expected uninjected production values to fail' >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Enabling observability renders the scrape CRDs and adds a scoped 8081 ingress
|
||||
# keyed to the named monitoring source — never a blanket 8081 rule.
|
||||
monitoring_out=$(mktemp); trap 'rm -f "$out" "$production_out" "$monitoring_out"' EXIT
|
||||
helm template push deploy/charts/buzz-push-gateway \
|
||||
--set podMonitor.enabled=true \
|
||||
--set prometheusRule.enabled=true \
|
||||
--set networkPolicy.monitoring.enabled=true \
|
||||
--set 'networkPolicy.monitoring.namespaceSelector.kubernetes\.io/metadata\.name=monitoring' \
|
||||
--set 'networkPolicy.monitoring.podSelector.app\.kubernetes\.io/name=prometheus' \
|
||||
>"$monitoring_out"
|
||||
|
||||
python3 - "$monitoring_out" <<'PY'
|
||||
import sys,yaml
|
||||
xs=list(yaml.safe_load_all(open(sys.argv[1])))
|
||||
pm=next(x for x in xs if x and x.get('kind')=='PodMonitor')
|
||||
ep=pm['spec']['podMetricsEndpoints'][0]
|
||||
assert ep['port']=='health' and ep['path']=='/metrics', ep
|
||||
assert next(x for x in xs if x and x.get('kind')=='PrometheusRule')['spec']['groups']
|
||||
np=next(x for x in xs if x and x.get('kind')=='NetworkPolicy' and x['metadata']['name']=='push-buzz-push-gateway')
|
||||
mon=[r for r in np['spec']['ingress'] if {p['port'] for p in r.get('ports',[])}=={8081}]
|
||||
assert len(mon)==1, 'exactly one scoped 8081 ingress rule'
|
||||
frm=mon[0]['from'][0]
|
||||
# 8081 ingress must be scoped by both selectors, never empty/blanket.
|
||||
assert frm['namespaceSelector']['matchLabels'] and frm['podSelector']['matchLabels'], frm
|
||||
PY
|
||||
|
||||
# Negative: monitoring enabled with default empty selectors must fail (would
|
||||
# otherwise render a blanket 8081 rule matching all namespaces/pods).
|
||||
if helm template push deploy/charts/buzz-push-gateway \
|
||||
--set podMonitor.enabled=true \
|
||||
--set networkPolicy.monitoring.enabled=true >/dev/null 2>&1; then
|
||||
echo 'expected monitoring.enabled with empty selectors to fail' >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Negative: scrape flags must be coupled. PodMonitor without ingress = an
|
||||
# unreachable scraper; ingress without a PodMonitor = an open hole with no
|
||||
# scraper. Both mismatches must fail schema validation.
|
||||
if helm template push deploy/charts/buzz-push-gateway \
|
||||
--set podMonitor.enabled=true \
|
||||
--set 'networkPolicy.monitoring.namespaceSelector.kubernetes\.io/metadata\.name=monitoring' \
|
||||
--set 'networkPolicy.monitoring.podSelector.app\.kubernetes\.io/name=prometheus' \
|
||||
>/dev/null 2>&1; then
|
||||
echo 'expected podMonitor.enabled without monitoring ingress to fail' >&2
|
||||
exit 1
|
||||
fi
|
||||
if helm template push deploy/charts/buzz-push-gateway \
|
||||
--set networkPolicy.monitoring.enabled=true \
|
||||
--set 'networkPolicy.monitoring.namespaceSelector.kubernetes\.io/metadata\.name=monitoring' \
|
||||
--set 'networkPolicy.monitoring.podSelector.app\.kubernetes\.io/name=prometheus' \
|
||||
>/dev/null 2>&1; then
|
||||
echo 'expected monitoring ingress without podMonitor.enabled to fail' >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Negative: retry-ratio threshold is a fraction; a value > 1 must fail schema.
|
||||
if helm template push deploy/charts/buzz-push-gateway \
|
||||
--set prometheusRule.enabled=true \
|
||||
--set prometheusRule.apnsRetryRatioThreshold=2 >/dev/null 2>&1; then
|
||||
echo 'expected apnsRetryRatioThreshold=2 to fail' >&2
|
||||
exit 1
|
||||
fi
|
||||
@@ -0,0 +1,15 @@
|
||||
# Required environment-owned values are deliberately invalid/empty here. A
|
||||
# production renderer must inject all of them; CI proves omission fails.
|
||||
image:
|
||||
tag: ""
|
||||
digest: ""
|
||||
appAttestAppId: ""
|
||||
httpRoute:
|
||||
enabled: true
|
||||
parentRefs: []
|
||||
hostnames:
|
||||
- push.buzz.xyz
|
||||
networkPolicy:
|
||||
apnsEgressCidrs:
|
||||
- 0.0.0.0/0
|
||||
postgresEgressCidrs: []
|
||||
@@ -0,0 +1,334 @@
|
||||
{
|
||||
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||
"type": "object",
|
||||
"additionalProperties": true,
|
||||
"properties": {
|
||||
"replicaCount": {
|
||||
"type": "integer",
|
||||
"minimum": 2
|
||||
},
|
||||
"existingSecret": {
|
||||
"type": "string",
|
||||
"minLength": 1
|
||||
},
|
||||
"publicDeliveryUrl": {
|
||||
"const": "https://push.buzz.xyz/v1/deliveries/apns"
|
||||
},
|
||||
"maxGrantLifetimeSeconds": {
|
||||
"type": "integer",
|
||||
"minimum": 1,
|
||||
"maximum": 31536000
|
||||
},
|
||||
"appAttestAppId": {
|
||||
"type": "string",
|
||||
"minLength": 1
|
||||
},
|
||||
"httpRoute": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"enabled",
|
||||
"parentRefs",
|
||||
"hostnames"
|
||||
],
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"parentRefs": {
|
||||
"type": "array"
|
||||
},
|
||||
"hostnames": {
|
||||
"type": "array",
|
||||
"contains": {
|
||||
"const": "push.buzz.xyz"
|
||||
}
|
||||
}
|
||||
},
|
||||
"allOf": [
|
||||
{
|
||||
"if": {
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enabled"
|
||||
]
|
||||
},
|
||||
"then": {
|
||||
"properties": {
|
||||
"parentRefs": {
|
||||
"minItems": 1
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"networkPolicy": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"enabled",
|
||||
"apnsEgressCidrs",
|
||||
"postgresEgressCidrs",
|
||||
"dns"
|
||||
],
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
},
|
||||
"apnsEgressCidrs": {
|
||||
"type": "array",
|
||||
"minItems": 1
|
||||
},
|
||||
"postgresEgressCidrs": {
|
||||
"type": "array",
|
||||
"minItems": 1
|
||||
},
|
||||
"dns": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"namespaceSelector",
|
||||
"podSelector"
|
||||
]
|
||||
},
|
||||
"monitoring": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"enabled",
|
||||
"namespaceSelector",
|
||||
"podSelector"
|
||||
],
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"namespaceSelector": {
|
||||
"type": "object"
|
||||
},
|
||||
"podSelector": {
|
||||
"type": "object"
|
||||
}
|
||||
},
|
||||
"allOf": [
|
||||
{
|
||||
"if": {
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enabled"
|
||||
]
|
||||
},
|
||||
"then": {
|
||||
"properties": {
|
||||
"namespaceSelector": {
|
||||
"minProperties": 1
|
||||
},
|
||||
"podSelector": {
|
||||
"minProperties": 1
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"podMonitor": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"enabled"
|
||||
],
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"type": "boolean"
|
||||
}
|
||||
}
|
||||
},
|
||||
"prometheusRule": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"enabled"
|
||||
],
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"apnsRetryRatioThreshold": {
|
||||
"type": "number",
|
||||
"exclusiveMinimum": 0,
|
||||
"maximum": 1
|
||||
},
|
||||
"apnsRetryMinSamples": {
|
||||
"type": "integer",
|
||||
"minimum": 1
|
||||
}
|
||||
}
|
||||
},
|
||||
"image": {
|
||||
"type": "object",
|
||||
"required": [
|
||||
"repository"
|
||||
],
|
||||
"properties": {
|
||||
"repository": {
|
||||
"type": "string",
|
||||
"minLength": 1
|
||||
},
|
||||
"tag": {
|
||||
"type": "string"
|
||||
},
|
||||
"digest": {
|
||||
"type": "string",
|
||||
"pattern": "^$|^sha256:[0-9a-f]{64}$"
|
||||
}
|
||||
},
|
||||
"anyOf": [
|
||||
{
|
||||
"properties": {
|
||||
"tag": {
|
||||
"minLength": 1
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
"properties": {
|
||||
"digest": {
|
||||
"pattern": "^sha256:[0-9a-f]{64}$"
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"migration": {
|
||||
"type": "object",
|
||||
"additionalProperties": false,
|
||||
"required": [
|
||||
"existingSecret",
|
||||
"databaseUrlKey",
|
||||
"runtimeDatabaseRole",
|
||||
"resources"
|
||||
],
|
||||
"properties": {
|
||||
"existingSecret": {
|
||||
"type": "string",
|
||||
"minLength": 1
|
||||
},
|
||||
"databaseUrlKey": {
|
||||
"type": "string",
|
||||
"minLength": 1
|
||||
},
|
||||
"runtimeDatabaseRole": {
|
||||
"type": "string",
|
||||
"pattern": "^[a-zA-Z_][a-zA-Z0-9_]{0,62}$"
|
||||
},
|
||||
"resources": {
|
||||
"type": "object"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"replicaCount",
|
||||
"existingSecret",
|
||||
"publicDeliveryUrl",
|
||||
"maxGrantLifetimeSeconds",
|
||||
"appAttestAppId",
|
||||
"httpRoute",
|
||||
"image",
|
||||
"migration"
|
||||
],
|
||||
"allOf": [
|
||||
{
|
||||
"$comment": "Scraping opt-in is coupled: a PodMonitor and its scoped 8081 ingress must be enabled together, so we never render a scraper that cannot reach the port nor an ingress hole with no scraper.",
|
||||
"if": {
|
||||
"properties": {
|
||||
"podMonitor": {
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enabled"
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"podMonitor"
|
||||
]
|
||||
},
|
||||
"then": {
|
||||
"properties": {
|
||||
"networkPolicy": {
|
||||
"properties": {
|
||||
"monitoring": {
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enabled"
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"monitoring"
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"networkPolicy"
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"if": {
|
||||
"properties": {
|
||||
"networkPolicy": {
|
||||
"properties": {
|
||||
"monitoring": {
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enabled"
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"monitoring"
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"networkPolicy"
|
||||
]
|
||||
},
|
||||
"then": {
|
||||
"properties": {
|
||||
"podMonitor": {
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"const": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"enabled"
|
||||
]
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"podMonitor"
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,92 @@
|
||||
replicaCount: 2
|
||||
image:
|
||||
repository: ghcr.io/block/buzz-push-gateway
|
||||
# `main` is published by the push-gateway lane on every main push.
|
||||
tag: main
|
||||
digest: ""
|
||||
pullPolicy: IfNotPresent
|
||||
pullSecrets: []
|
||||
existingSecret: buzz-push-gateway
|
||||
# DDL-capable credentials are used only by the pre-install/pre-upgrade migration
|
||||
# Job. Runtime DATABASE_URL in existingSecret should have DML-only privileges.
|
||||
migration:
|
||||
existingSecret: buzz-push-gateway-migrations
|
||||
databaseUrlKey: DATABASE_URL
|
||||
# Existing LOGIN role used by runtime DATABASE_URL. Migrations grant it only
|
||||
# CONNECT plus DML on the six gateway tables in this dedicated database.
|
||||
runtimeDatabaseRole: buzz_push_gateway_runtime
|
||||
resources:
|
||||
requests: {cpu: 50m, memory: 64Mi}
|
||||
limits: {cpu: 250m, memory: 128Mi}
|
||||
publicDeliveryUrl: https://push.buzz.xyz/v1/deliveries/apns
|
||||
maxGrantLifetimeSeconds: 2592000
|
||||
enabledProfiles: buzz-ios-production
|
||||
# Example App Attest identifier. Production MUST override this with the exact
|
||||
# Apple TEAMID.bundle-id value (see values-production.yaml).
|
||||
appAttestAppId: TEAMID.xyz.buzz
|
||||
appAttestRoot:
|
||||
secretName: buzz-push-gateway
|
||||
secretKey: app-attest-root.pem
|
||||
apnsKey:
|
||||
secretName: buzz-push-gateway
|
||||
secretKey: apns-provider.p8
|
||||
service:
|
||||
port: 8080
|
||||
httpRoute:
|
||||
# Disabled by default so a generic install cannot claim an unattached route.
|
||||
# Production enables this with an explicit Gateway parentRef.
|
||||
enabled: false
|
||||
parentRefs: []
|
||||
hostnames: [push.buzz.xyz]
|
||||
resources:
|
||||
requests: {cpu: 100m, memory: 128Mi}
|
||||
limits: {cpu: "1", memory: 512Mi}
|
||||
podDisruptionBudget:
|
||||
enabled: true
|
||||
minAvailable: 1
|
||||
networkPolicy:
|
||||
enabled: true
|
||||
# Kubernetes NetworkPolicy cannot allow DNS names. Production operators must
|
||||
# narrow these CIDRs to their PostgreSQL/NAT destinations where supported.
|
||||
apnsEgressCidrs: [0.0.0.0/0]
|
||||
# Override with the actual database network. This example private range is
|
||||
# intentionally separate from broad APNs HTTPS egress.
|
||||
postgresEgressCidrs: [10.0.0.0/8]
|
||||
dns:
|
||||
namespaceSelector:
|
||||
kubernetes.io/metadata.name: kube-system
|
||||
podSelector:
|
||||
k8s-app: kube-dns
|
||||
# Scoped ingress to the private metrics port (8081). Off by default so 8081
|
||||
# has no pod ingress at all; enable only alongside podMonitor and name the
|
||||
# scraper's namespace/pod so reachability stays narrow.
|
||||
monitoring:
|
||||
enabled: false
|
||||
namespaceSelector: {}
|
||||
podSelector: {}
|
||||
# Prometheus-operator PodMonitor scraping the private /metrics on port 8081.
|
||||
# Off by default; requires networkPolicy.monitoring to also be enabled.
|
||||
podMonitor:
|
||||
enabled: false
|
||||
interval: 30s
|
||||
scrapeTimeout: 10s
|
||||
labels: {}
|
||||
# Prometheus-operator alerting rules. Off by default.
|
||||
prometheusRule:
|
||||
enabled: false
|
||||
labels: {}
|
||||
# Retryable-outcome fraction (0..1] that fires PushGatewayHighApnsRetryRate.
|
||||
apnsRetryRatioThreshold: 0.25
|
||||
# Minimum APNs attempts in the 10m window before the retry-ratio alert can
|
||||
# fire, so a couple of retries at trivial volume cannot trip it.
|
||||
apnsRetryMinSamples: 20
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
affinity: {}
|
||||
topologySpreadConstraints:
|
||||
- maxSkew: 1
|
||||
topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: buzz-push-gateway
|
||||
Reference in New Issue
Block a user