Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions bot-ts/src/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,8 @@ spec:
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: redis-pvc
spec:
accessModes:
Expand All @@ -150,6 +152,7 @@ spec:
labels:
app: bot-ts
spec:
terminationGracePeriodSeconds: 90
containers:
- name: bot-ts
image: ghcr.io/polinetworkorg/telegram@sha256:aa7203181e578cbc48e9fe1c8a011dc89f49f7a21137be6124051f727bb814fb
Expand Down
4 changes: 4 additions & 0 deletions influxdb/src/deployment.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: influxdb-config-pvc
spec:
accessModes:
Expand All @@ -13,6 +15,8 @@ spec:
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: influxdb-data-pvc
spec:
accessModes:
Expand Down
2 changes: 2 additions & 0 deletions monitoring/src/deployment-grafana.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: grafana-pvc
spec:
storageClassName: longhorn
Expand Down
2 changes: 2 additions & 0 deletions monitoring/src/deployment-prometheus.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: prometheus-pvc
spec:
storageClassName: longhorn
Expand Down
11 changes: 11 additions & 0 deletions postgres/src/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@ metadata:
name: postgres
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app: postgres
Expand Down Expand Up @@ -77,6 +79,15 @@ spec:
name: azure-kv
key: db-pass
optional: false
readinessProbe:
exec:
command:
- sh
- -c
- pg_isready -h 127.0.0.1 -U "$POSTGRES_USER" -d "$POSTGRES_DB"
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
volumeMounts:
- mountPath: /var/lib/postgresql/data
name: postgresdata
Expand Down
2 changes: 2 additions & 0 deletions redis/src/deployment.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: redis-pvc
spec:
accessModes:
Expand Down
15 changes: 15 additions & 0 deletions tests/workload-manifests.test.rb
Original file line number Diff line number Diff line change
Expand Up @@ -58,4 +58,19 @@ def init_container(resource, name)
raise "Grafana memory request must cover its observed working set" unless grafana.dig("resources", "requests", "memory") == "768Mi"
raise "Grafana must use Recreate with its single-writer PVC" unless grafana_deployment.dig("spec", "strategy", "type") == "Recreate"

postgres_deployment = deployment("postgres/src/deployment.yaml", "postgres")
postgres = container(postgres_deployment, "postgres")
raise "PostgreSQL must keep a single writer during rollout" unless postgres_deployment.dig("spec", "strategy", "type") == "Recreate"
raise "PostgreSQL must report database readiness" unless postgres.dig("readinessProbe", "exec", "command").last.include?("pg_isready")
raise "Do not restart PostgreSQL automatically on probe failures" if postgres["livenessProbe"]

claims = Dir.glob(File.join(ROOT, "**/src/*.yaml")).flat_map do |path|
YAML.load_stream(File.read(path)).compact.select { |doc| doc["kind"] == "PersistentVolumeClaim" }
end
claims.each do |claim|
next unless claim.dig("spec", "storageClassName") == "longhorn"
options = claim.dig("metadata", "annotations", "argocd.argoproj.io/sync-options").to_s.split(",")
raise "Argo must retain #{claim.dig("metadata", "name")}" unless ["Prune=false", "Delete=false"].all? { |option| options.include?(option) }
end

puts "workload manifest checks passed"
2 changes: 2 additions & 0 deletions uptime-kuma/src/deployment.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
annotations:
argocd.argoproj.io/sync-options: Prune=false,Delete=false
name: uptime-pvc
spec:
accessModes:
Expand Down