hindsight: Phase C manifests (multi-source app wave 8, external pgvector PG, ES from 1Password, chart-native ingress)
- application.yaml: single multi-source Application (openviking pattern), wave 8, chart v0.9.1 via path: + $values/values.yaml - values.yaml: postgresql.enabled=false (external), existingSecret, LLM env (astro-orbiter:8001, Qwen3.8-27B-Q4_K_M), native ingress cosmic-rewind.local.mk-labs.cloud (api /health /v1 /mcp /ext, cp /) - externalsecret.yaml: hindsight-credentials from 1Password mk-labs/hindsight - namespace.yaml, postgres-pvc.yaml (10Gi nfs-emporium), deployment-postgres.yaml (ankane/pgvector pinned by digest), service-postgres.yaml (hindsight-postgres:5432)
This commit is contained in:
91
cluster/applications/hindsight/values.yaml
Normal file
91
cluster/applications/hindsight/values.yaml
Normal file
@@ -0,0 +1,91 @@
|
||||
# ============================================================================
|
||||
# Hindsight — helm values (Phase C). Consumed by the ArgoCD Application source 1
|
||||
# via `helm.valueFiles: ["$values/values.yaml"]` (openviking multi-source pattern).
|
||||
#
|
||||
# Design decisions (all verified against chart v0.9.1 + rendered output):
|
||||
# - Chart is the single source for the app (api, control-plane, services,
|
||||
# probes, ingress). We do NOT hand-roll Deployments/Services.
|
||||
# - Postgres is EXTERNAL (separate Deployment in this dir, firecrawl pattern)
|
||||
# => postgresql.enabled: false, external.* points at hindsight-postgres:5432.
|
||||
# - Secrets come from 1Password via ExternalSecret => existingSecret:
|
||||
# hindsight-credentials. The chart does envFrom(secretRef) so
|
||||
# HINDSIGHT_API_LLM_API_KEY / HINDSIGHT_API_MCP_AUTH_TOKEN are injected
|
||||
# automatically; POSTGRES_PASSWORD is a secretKeyRef that K8s expands into
|
||||
# HINDSIGHT_API_DATABASE_URL (verified with a live envFrom test pod).
|
||||
# - LLM is the local OpenAI-compatible astro-orbiter endpoint (VLAN service
|
||||
# `astro-orbiter:8001`), model pinned to the bare id (no `openai/` prefix —
|
||||
# that form 404s on the local router).
|
||||
# - Ingress is driven through the chart's NATIVE ingress template (approved
|
||||
# plan: "Ingress driven through values.yaml"). api.service.port=8888,
|
||||
# controlPlane.service.port=3000.
|
||||
# - Image tag defaults to .Values.version (root) when api.image.tag is unset,
|
||||
# so version: "0.9.1" pins the API image to 0.9.1.
|
||||
# ============================================================================
|
||||
|
||||
version: "0.9.1"
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# External PostgreSQL (chart's bundled postgresql is disabled).
|
||||
# password is the K8s env expansion `$(POSTGRES_PASSWORD)` — the chart defines
|
||||
# POSTGRES_PASSWORD as a secretKeyRef (hindsight-credentials / postgres-password)
|
||||
# earlier in the same container, so K8s substitutes it at container start.
|
||||
# ----------------------------------------------------------------------------
|
||||
postgresql:
|
||||
enabled: false
|
||||
external:
|
||||
host: hindsight-postgres
|
||||
port: 5432
|
||||
username: hindsight
|
||||
database: hindsight
|
||||
password: $(POSTGRES_PASSWORD)
|
||||
|
||||
# ExternalSecret (from 1Password) that the chart injects via envFrom(secretRef).
|
||||
# Keys it must expose: postgres-password, HINDSIGHT_API_LLM_API_KEY,
|
||||
# HINDSIGHT_API_MCP_AUTH_TOKEN. See externalsecret.yaml in this dir.
|
||||
existingSecret: hindsight-credentials
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# API container environment (explicit env entries; the chart renders this map
|
||||
# to individual env vars). LLM points at the local astro-orbiter OpenAI-
|
||||
# compatible server. HINDSIGHT_API_LLM_API_KEY is NOT set here — it comes from
|
||||
# the existingSecret via envFrom.
|
||||
# ----------------------------------------------------------------------------
|
||||
api:
|
||||
env:
|
||||
HINDSIGHT_API_LLM_BASE_URL: "http://astro-orbiter:8001/v1"
|
||||
HINDSIGHT_API_LLM_PROVIDER: "openai"
|
||||
HINDSIGHT_API_LLM_MODEL: "Qwen3.8-27B-Q4_K_M"
|
||||
|
||||
# ----------------------------------------------------------------------------
|
||||
# Ingress via the chart's native template.
|
||||
# /health,/v1,/mcp,/ext -> api:8888 (longest-prefix wins in nginx)
|
||||
# / -> controlPlane:3000
|
||||
# TLS secret hindsight-tls provisioned by the letsencrypt-prod issuer.
|
||||
# ----------------------------------------------------------------------------
|
||||
ingress:
|
||||
enabled: true
|
||||
className: "nginx"
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: "letsencrypt-prod"
|
||||
hosts:
|
||||
- host: cosmic-rewind.local.mk-labs.cloud
|
||||
paths:
|
||||
- path: /health
|
||||
pathType: Prefix
|
||||
service: api
|
||||
- path: /v1
|
||||
pathType: Prefix
|
||||
service: api
|
||||
- path: /mcp
|
||||
pathType: Prefix
|
||||
service: api
|
||||
- path: /ext
|
||||
pathType: Prefix
|
||||
service: api
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
service: controlPlane
|
||||
tls:
|
||||
- hosts:
|
||||
- cosmic-rewind.local.mk-labs.cloud
|
||||
secretName: hindsight-tls
|
||||
Reference in New Issue
Block a user