Files
buzz/deploy/charts/buzz-push-gateway/values.yaml
T
cls 9dfa06ffee
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
feat: import Chinese-localized Buzz source snapshot
Signed-off-by: cls_宁波本机 <908705107@qq.com>
2026-08-13 18:34:25 +08:00

93 lines
3.2 KiB
YAML

replicaCount: 2
image:
repository: ghcr.io/block/buzz-push-gateway
# `main` is published by the push-gateway lane on every main push.
tag: main
digest: ""
pullPolicy: IfNotPresent
pullSecrets: []
existingSecret: buzz-push-gateway
# DDL-capable credentials are used only by the pre-install/pre-upgrade migration
# Job. Runtime DATABASE_URL in existingSecret should have DML-only privileges.
migration:
existingSecret: buzz-push-gateway-migrations
databaseUrlKey: DATABASE_URL
# Existing LOGIN role used by runtime DATABASE_URL. Migrations grant it only
# CONNECT plus DML on the six gateway tables in this dedicated database.
runtimeDatabaseRole: buzz_push_gateway_runtime
resources:
requests: {cpu: 50m, memory: 64Mi}
limits: {cpu: 250m, memory: 128Mi}
publicDeliveryUrl: https://push.buzz.xyz/v1/deliveries/apns
maxGrantLifetimeSeconds: 2592000
enabledProfiles: buzz-ios-production
# Example App Attest identifier. Production MUST override this with the exact
# Apple TEAMID.bundle-id value (see values-production.yaml).
appAttestAppId: TEAMID.xyz.buzz
appAttestRoot:
secretName: buzz-push-gateway
secretKey: app-attest-root.pem
apnsKey:
secretName: buzz-push-gateway
secretKey: apns-provider.p8
service:
port: 8080
httpRoute:
# Disabled by default so a generic install cannot claim an unattached route.
# Production enables this with an explicit Gateway parentRef.
enabled: false
parentRefs: []
hostnames: [push.buzz.xyz]
resources:
requests: {cpu: 100m, memory: 128Mi}
limits: {cpu: "1", memory: 512Mi}
podDisruptionBudget:
enabled: true
minAvailable: 1
networkPolicy:
enabled: true
# Kubernetes NetworkPolicy cannot allow DNS names. Production operators must
# narrow these CIDRs to their PostgreSQL/NAT destinations where supported.
apnsEgressCidrs: [0.0.0.0/0]
# Override with the actual database network. This example private range is
# intentionally separate from broad APNs HTTPS egress.
postgresEgressCidrs: [10.0.0.0/8]
dns:
namespaceSelector:
kubernetes.io/metadata.name: kube-system
podSelector:
k8s-app: kube-dns
# Scoped ingress to the private metrics port (8081). Off by default so 8081
# has no pod ingress at all; enable only alongside podMonitor and name the
# scraper's namespace/pod so reachability stays narrow.
monitoring:
enabled: false
namespaceSelector: {}
podSelector: {}
# Prometheus-operator PodMonitor scraping the private /metrics on port 8081.
# Off by default; requires networkPolicy.monitoring to also be enabled.
podMonitor:
enabled: false
interval: 30s
scrapeTimeout: 10s
labels: {}
# Prometheus-operator alerting rules. Off by default.
prometheusRule:
enabled: false
labels: {}
# Retryable-outcome fraction (0..1] that fires PushGatewayHighApnsRetryRate.
apnsRetryRatioThreshold: 0.25
# Minimum APNs attempts in the 10m window before the retry-ratio alert can
# fire, so a couple of retries at trivial volume cannot trip it.
apnsRetryMinSamples: 20
nodeSelector: {}
tolerations: []
affinity: {}
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: buzz-push-gateway