feat: import Chinese-localized Buzz source snapshot
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled

Signed-off-by: cls_宁波本机 <908705107@qq.com>
This commit is contained in:
2026-08-13 18:34:25 +08:00
parent 61c3fa1df9
commit 9dfa06ffee
3785 changed files with 1085458 additions and 2 deletions
@@ -0,0 +1,13 @@
{{- define "push.name" -}}{{ .Release.Name }}-buzz-push-gateway{{- end }}
{{- define "push.labels" -}}
app.kubernetes.io/name: buzz-push-gateway
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}
{{- define "push.runtimeLabels" -}}
{{ include "push.labels" . }}
app.kubernetes.io/component: runtime
{{- end }}
{{- define "push.migrationLabels" -}}
{{ include "push.labels" . }}
app.kubernetes.io/component: migration
{{- end }}
@@ -0,0 +1,65 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "push.name" . }}
labels: {{- include "push.runtimeLabels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
strategy: { type: RollingUpdate, rollingUpdate: { maxSurge: 1, maxUnavailable: 0 } }
selector:
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
template:
metadata:
labels: {{- include "push.runtimeLabels" . | nindent 8 }}
spec:
automountServiceAccountToken: false
terminationGracePeriodSeconds: 60
securityContext: { runAsNonRoot: true, runAsUser: 65532, runAsGroup: 65532, fsGroup: 65532, seccompProfile: { type: RuntimeDefault } }
{{- with .Values.image.pullSecrets }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: gateway
image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ required "image.tag or image.digest is required" .Values.image.tag }}{{ end }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities: { drop: [ALL] } }
ports:
- { name: public, containerPort: 8080 }
- { name: health, containerPort: 8081 }
env:
- { name: BUZZ_PUSH_BIND_ADDR, value: "0.0.0.0:8080" }
- { name: BUZZ_PUSH_HEALTH_ADDR, value: "0.0.0.0:8081" }
- { name: BUZZ_PUSH_PUBLIC_DELIVERY_URL, value: {{ .Values.publicDeliveryUrl | quote }} }
- { name: BUZZ_PUSH_MAX_GRANT_LIFETIME_SECONDS, value: {{ .Values.maxGrantLifetimeSeconds | quote }} }
- { name: BUZZ_PUSH_ENABLED_PROFILES, value: {{ .Values.enabledProfiles | quote }} }
- { name: BUZZ_PUSH_APP_ATTEST_APP_ID, value: {{ .Values.appAttestAppId | quote }} }
- { name: BUZZ_PUSH_APP_ATTEST_ROOT_CERT_PATH, value: /run/buzz/app-attest/root.pem }
- { name: BUZZ_PUSH_APNS_KEY_PATH, value: /run/buzz/apns/provider.p8 }
{{- range $name := list "DATABASE_URL" "BUZZ_PUSH_APNS_KEY_ID" "BUZZ_PUSH_APNS_TEAM_ID" "BUZZ_PUSH_APNS_TOPIC" "BUZZ_PUSH_GRANT_KEYS" "BUZZ_PUSH_TOKEN_KEYS" }}
- name: {{ $name }}
valueFrom: { secretKeyRef: { name: {{ $.Values.existingSecret }}, key: {{ $name }} } }
{{- end }}
volumeMounts:
- { name: app-attest-root, mountPath: /run/buzz/app-attest, readOnly: true }
- { name: apns-key, mountPath: /run/buzz/apns, readOnly: true }
livenessProbe: { httpGet: { path: /_liveness, port: health }, periodSeconds: 10, timeoutSeconds: 3, failureThreshold: 3 }
readinessProbe: { httpGet: { path: /_readiness, port: health }, periodSeconds: 5, timeoutSeconds: 3, failureThreshold: 3 }
startupProbe: { httpGet: { path: /_liveness, port: health }, periodSeconds: 2, failureThreshold: 60 }
resources: {{- toYaml .Values.resources | nindent 12 }}
volumes:
- name: app-attest-root
secret: { secretName: {{ .Values.appAttestRoot.secretName }}, items: [{ key: {{ .Values.appAttestRoot.secretKey }}, path: root.pem }] }
- name: apns-key
secret: { secretName: {{ .Values.apnsKey.secretName }}, items: [{ key: {{ .Values.apnsKey.secretKey }}, path: provider.p8 }] }
{{- with .Values.nodeSelector }}
nodeSelector: {{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations: {{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.affinity }}
affinity: {{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.topologySpreadConstraints }}
topologySpreadConstraints: {{- toYaml . | nindent 8 }}
{{- end }}
@@ -0,0 +1,14 @@
{{- if .Values.httpRoute.enabled }}
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: {{ include "push.name" . }}
spec:
parentRefs: {{- toYaml .Values.httpRoute.parentRefs | nindent 4 }}
hostnames: {{- toYaml .Values.httpRoute.hostnames | nindent 4 }}
rules:
- matches:
- path: { type: PathPrefix, value: / }
backendRefs:
- { name: {{ include "push.name" . }}, port: {{ .Values.service.port }} }
{{- end }}
@@ -0,0 +1,33 @@
apiVersion: batch/v1
kind: Job
metadata:
name: {{ include "push.name" . }}-migrate
labels: {{- include "push.migrationLabels" . | nindent 4 }}
annotations:
helm.sh/hook: pre-install,pre-upgrade
helm.sh/hook-weight: "-5"
helm.sh/hook-delete-policy: before-hook-creation,hook-succeeded
spec:
backoffLimit: 3
template:
metadata:
labels: {{- include "push.migrationLabels" . | nindent 8 }}
spec:
restartPolicy: Never
automountServiceAccountToken: false
securityContext: { runAsNonRoot: true, runAsUser: 65532, runAsGroup: 65532, fsGroup: 65532, seccompProfile: { type: RuntimeDefault } }
{{- with .Values.image.pullSecrets }}
imagePullSecrets: {{ toYaml . | nindent 8 }}
{{- end }}
containers:
- name: migrate
image: "{{ .Values.image.repository }}{{ if .Values.image.digest }}@{{ .Values.image.digest }}{{ else }}:{{ required "image.tag or image.digest is required" .Values.image.tag }}{{ end }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
args: ["--migrate-only"]
securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true, capabilities: { drop: [ALL] } }
env:
- name: BUZZ_PUSH_RUNTIME_DATABASE_ROLE
value: {{ .Values.migration.runtimeDatabaseRole | quote }}
- name: DATABASE_URL
valueFrom: { secretKeyRef: { name: {{ .Values.migration.existingSecret }}, key: {{ .Values.migration.databaseUrlKey }} } }
resources: {{- toYaml .Values.migration.resources | nindent 12 }}
@@ -0,0 +1,28 @@
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "push.name" . }}-migration
labels: {{- include "push.migrationLabels" . | nindent 4 }}
annotations:
# Hooks precede ordinary manifests. Keep this policy alive until the next
# release's before-hook-creation cleanup so it covers the later Job hook.
helm.sh/hook: pre-install,pre-upgrade
helm.sh/hook-weight: "-10"
helm.sh/hook-delete-policy: before-hook-creation
spec:
podSelector:
matchLabels: {{- include "push.migrationLabels" . | nindent 6 }}
policyTypes: [Ingress, Egress]
ingress: []
egress:
- to:
- namespaceSelector:
matchLabels: {{- toYaml .Values.networkPolicy.dns.namespaceSelector | nindent 14 }}
podSelector:
matchLabels: {{- toYaml .Values.networkPolicy.dns.podSelector | nindent 14 }}
ports: [{ port: 53, protocol: UDP }, { port: 53, protocol: TCP }]
- to:
{{- range .Values.networkPolicy.postgresEgressCidrs }}
- ipBlock: { cidr: {{ . }} }
{{- end }}
ports: [{ port: 5432, protocol: TCP }]
@@ -0,0 +1,42 @@
{{- if .Values.networkPolicy.enabled }}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: {{ include "push.name" . }}
spec:
podSelector:
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
policyTypes: [Ingress, Egress]
ingress:
- ports: [{ port: 8080, protocol: TCP }]
{{- if .Values.networkPolicy.monitoring.enabled }}
{{- if or (not .Values.networkPolicy.monitoring.namespaceSelector) (not .Values.networkPolicy.monitoring.podSelector) }}
{{- fail "networkPolicy.monitoring.enabled requires non-empty namespaceSelector and podSelector so 8081 scrape ingress is scoped, never blanket" }}
{{- end }}
# Scoped scrape access to the private health/metrics port. Off by default so
# 8081 has no pod ingress; when enabled the operator names their scraper.
- from:
- namespaceSelector:
matchLabels: {{- toYaml .Values.networkPolicy.monitoring.namespaceSelector | nindent 14 }}
podSelector:
matchLabels: {{- toYaml .Values.networkPolicy.monitoring.podSelector | nindent 14 }}
ports: [{ port: 8081, protocol: TCP }]
{{- end }}
egress:
- to:
- namespaceSelector:
matchLabels: {{- toYaml .Values.networkPolicy.dns.namespaceSelector | nindent 14 }}
podSelector:
matchLabels: {{- toYaml .Values.networkPolicy.dns.podSelector | nindent 14 }}
ports: [{ port: 53, protocol: UDP }, { port: 53, protocol: TCP }]
- to:
{{- range .Values.networkPolicy.apnsEgressCidrs }}
- ipBlock: { cidr: {{ . }} }
{{- end }}
ports: [{ port: 443, protocol: TCP }]
- to:
{{- range .Values.networkPolicy.postgresEgressCidrs }}
- ipBlock: { cidr: {{ . }} }
{{- end }}
ports: [{ port: 5432, protocol: TCP }]
{{- end }}
@@ -0,0 +1,10 @@
{{- if .Values.podDisruptionBudget.enabled }}
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: {{ include "push.name" . }}
spec:
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
selector:
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
{{- end }}
@@ -0,0 +1,19 @@
{{- if .Values.podMonitor.enabled }}
apiVersion: monitoring.coreos.com/v1
kind: PodMonitor
metadata:
name: {{ include "push.name" . }}
labels: {{- include "push.runtimeLabels" . | nindent 4 }}
{{- with .Values.podMonitor.labels }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
selector:
matchLabels: {{- include "push.runtimeLabels" . | nindent 6 }}
podMetricsEndpoints:
# Scrape the private health port only; /metrics is never on the public Service.
- port: health
path: /metrics
interval: {{ .Values.podMonitor.interval }}
scrapeTimeout: {{ .Values.podMonitor.scrapeTimeout }}
{{- end }}
@@ -0,0 +1,89 @@
{{- if .Values.prometheusRule.enabled }}
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: {{ include "push.name" . }}
labels: {{- include "push.labels" . | nindent 4 }}
{{- with .Values.prometheusRule.labels }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
groups:
- name: buzz-push-gateway
rules:
# Sustained configuration faults mean the provider credential/topic is
# unhealthy; no endpoint is being invalidated but nothing is delivering.
- alert: PushGatewayConfigurationFault
expr: |
sum(rate(push_gateway_apns_deliveries_total{outcome="configuration_fault"}[5m])) > 0
for: 10m
labels: { severity: critical }
annotations:
summary: Push gateway APNs configuration faults
description: >-
APNs is returning configuration faults (bad/expired provider token
or topic). Deliveries are failing without invalidating endpoints.
See runbook: check the APNs .p8 key, key id, team id, and topic.
# Authority store unavailable at admission = durable dependency is down.
- alert: PushGatewayAdmissionUnavailable
expr: |
sum(rate(push_gateway_admissions_total{result="unavailable"}[5m])) > 0
for: 5m
labels: { severity: critical }
annotations:
summary: Push gateway authority store unavailable
description: >-
authorize_delivery is returning Unavailable — the PostgreSQL
authority store is unreachable or failing. Check DB connectivity
and the pod's postgres egress NetworkPolicy.
# Readiness failing on the authority cause = the pod will be pulled from
# rotation; alert before all replicas drop out.
- alert: PushGatewayReadinessAuthorityFailing
expr: |
sum(rate(push_gateway_readiness_failures_total{cause="authority"}[5m])) > 0
for: 5m
labels: { severity: warning }
annotations:
summary: Push gateway readiness failing on authority
description: >-
Readiness probes are failing because the authority store check
fails. Replicas will be removed from the Service. Investigate DB
health before capacity drops below the PodDisruptionBudget.
# The retention reaper sweeps expired rows every 5m; a single transient
# failure self-heals on the next tick. Alert on repeated failure —
# at least two sweeps failing within ~30m (six ticks) — which grows the
# bounded crash-before-release window and leaks storage.
- alert: PushGatewayReaperFailing
expr: |
sum(increase(push_gateway_reaper_failures_total[30m])) >= 2
for: 5m
labels: { severity: warning }
annotations:
summary: Push gateway retention reaper failing
description: >-
The retention reaper has failed at least twice within 30m (it runs
every 5m). Expired delivery reservations are not being swept,
growing the bounded-until-expiry window. Check DB write availability.
# High sustained fraction of retryable APNs outcomes indicates APNs
# throttling or degradation. The ratio is a true fraction over the
# window (increase = counts, not per-second rate), gated by a minimum
# sample count so a couple of retries at trivial volume cannot trip it.
- alert: PushGatewayHighApnsRetryRate
expr: |
(
sum(increase(push_gateway_apns_deliveries_total{outcome="retry"}[10m]))
/ sum(increase(push_gateway_apns_deliveries_total[10m]))
> {{ .Values.prometheusRule.apnsRetryRatioThreshold }}
)
and
sum(increase(push_gateway_apns_deliveries_total[10m])) >= {{ .Values.prometheusRule.apnsRetryMinSamples }}
for: 15m
labels: { severity: warning }
annotations:
summary: Push gateway high APNs retry ratio
description: >-
The retryable fraction of APNs attempts over a 10m window
(429/500/503), above a minimum sample count, has exceeded the
configured threshold continuously for 15m. APNs may be throttling
or degraded; deliveries are delayed but not lost.
{{- end }}
@@ -0,0 +1,9 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "push.name" . }}
labels: {{- include "push.runtimeLabels" . | nindent 4 }}
spec:
selector: {{- include "push.runtimeLabels" . | nindent 4 }}
ports:
- { name: https, port: {{ .Values.service.port }}, targetPort: public }