Files
buzz/deploy/charts/buzz/templates/NOTES.txt
T
cls 9dfa06ffee
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled
feat: import Chinese-localized Buzz source snapshot
Signed-off-by: cls_宁波本机 <908705107@qq.com>
2026-08-13 18:34:25 +08:00

94 lines
6.5 KiB
Plaintext

══════════════════════════════════════════════════════════════════════════════
Buzz {{ .Chart.AppVersion }} — release "{{ .Release.Name }}" (namespace {{ .Release.Namespace }})
══════════════════════════════════════════════════════════════════════════════
▶ Relay URL
{{ .Values.relayUrl }}
▶ Owner pubkey
{{ .Values.ownerPubkey }}
{{- if not .Values.ownerPubkey }}
⚠ ownerPubkey is empty — this is only valid when relay.requireRelayMembership=false.
{{- end }}
▶ Health
kubectl -n {{ .Release.Namespace }} port-forward svc/{{ include "buzz.fullname" . }} 8080:{{ .Values.service.healthPort }}
curl http://localhost:8080/_readiness
{{ if not .Values.ingress.enabled }}{{ if not .Values.httproute.enabled }}
▶ Networking
Neither ingress nor Gateway API HTTPRoute is enabled. Expose the relay
through your own gateway, then ensure clients reach .Values.relayUrl
({{ .Values.relayUrl }}) over wss://. Long-lived WebSocket connections
require generous proxy read/send timeouts (≥ 1h).
{{ end }}{{ end }}
──────────────────────────────────────────────────────────────────────────────
Profile
──────────────────────────────────────────────────────────────────────────────
{{ if or .Values.postgresql.enabled .Values.redis.enabled .Values.minio.enabled }}
⚠ QUICKSTART / EVALUATION PROFILE
{{ if .Values.postgresql.enabled }}- In-cluster Postgres subchart (CloudPirates){{ end }}
{{ if .Values.redis.enabled }}- In-cluster Redis subchart (CloudPirates){{ end }}
{{ if .Values.minio.enabled }}- In-cluster MinIO (eval-only, single replica; bucket "{{ .Values.s3.bucket }}" created by a bundled init Job){{ end }}
- Chart auto-generates secrets via the `lookup` pattern. This is NOT
GitOps-safe — secrets will silently rotate under ArgoCD/Flux. For
production, see examples/argocd-app.yaml or examples/flux-helmrelease.yaml.
{{ else }}
✓ PRODUCTION PROFILE
External Postgres, Redis (if enabled), S3.
{{ if .Values.secrets.existingSecret }}- Secrets sourced from: {{ .Values.secrets.existingSecret }}{{ end }}
{{ end }}
──────────────────────────────────────────────────────────────────────────────
Backups — save these
──────────────────────────────────────────────────────────────────────────────
1. BUZZ_RELAY_PRIVATE_KEY — relay identity. Rotating it = identity change;
federation peers will treat the relay as a new identity.
2. PostgreSQL database{{ if .Values.postgresql.enabled }} ({{ .Release.Name }}-postgresql PVC){{ end }}
3. S3 bucket "{{ .Values.s3.bucket }}" — media blobs
4. Git PVC ({{ include "buzz.fullname" . }}-git) — repo on-disk state
5. Owner private key (held by the operator, NOT the chart) — restore by
re-installing with the same ownerPubkey.
──────────────────────────────────────────────────────────────────────────────
Degradation warnings
──────────────────────────────────────────────────────────────────────────────
{{- if not .Values.relay.requireAuthToken }}
⚠ relay.requireAuthToken=false — REST API bypasses token auth. Production
should set this to true.
{{- end }}
{{- if not .Values.relay.requireRelayMembership }}
⚠ relay.requireRelayMembership=false — relay is OPEN. Anyone can publish.
{{- end }}
{{- if not .Values.migrate.autoMigrate }}
⚠ migrate.autoMigrate=false — relay startup will NOT run sqlx migrations.
You must run `buzz-admin migrate` against the database before every
`helm install` / `helm upgrade`, or pods will start against an unmigrated
schema. Readiness probes only verify DB connectivity, not schema freshness.
{{- end }}
{{- if or .Values.secrets.relayPrivateKey .Values.secrets.gitHookHmacSecret }}
⚠ Inline secret values are set in values.yaml
({{ if .Values.secrets.relayPrivateKey }}secrets.relayPrivateKey{{ end }}{{ if and .Values.secrets.relayPrivateKey .Values.secrets.gitHookHmacSecret }}, {{ end }}{{ if .Values.secrets.gitHookHmacSecret }}secrets.gitHookHmacSecret{{ end }}).
Inline overrides leak secrets into git history and CI logs. Move them to a
Kubernetes Secret and reference it via secrets.existingSecret — see
examples/secret-sample.yaml.
{{- end }}
{{- if not .Values.secrets.existingSecret }}
{{- if not (or .Values.postgresql.enabled .Values.redis.enabled) }}
⚠ Chart-managed Secret is in use (no secrets.existingSecret). This is fine
for `helm install` / `helm upgrade` but NOT safe under GitOps tools that
`helm template` to render manifests — the `lookup` function returns empty
in that mode and secrets will silently rotate. Use existingSecret for
ArgoCD / Flux.
{{- end }}
{{- end }}
──────────────────────────────────────────────────────────────────────────────
Useful commands
──────────────────────────────────────────────────────────────────────────────
kubectl -n {{ .Release.Namespace }} get pods -l app.kubernetes.io/instance={{ .Release.Name }}
kubectl -n {{ .Release.Namespace }} logs -l app.kubernetes.io/instance={{ .Release.Name }} --tail=200
kubectl -n {{ .Release.Namespace }} rollout status deployment/{{ include "buzz.fullname" . }}