# The one TerdutServer this whole demo runs against. Everything else in # this directory (teams, escalation rules, dead man's switches, alert # sources) references it by name. # # The operator never creates any ingress/HTTPRoute for this TerdutServer -- # that's a permanent non-goal (DESIGN.md ยง1, NetworkingSpec's own doc # comment), not a missing feature. This demo reaches it only by # port-forwarding its Service, same name as this object (see README.md); # see ../networking for worked examples of exposing it yourself instead. apiVersion: terdut.ryuvia.com/v1alpha1 kind: TerdutServer metadata: name: terdut-operator-demo spec: image: repository: git.ryuvia.com/niklas/terdut-server # v0.36.0 is the floor now that replicas below is 2 (this demo pins # the current release, v0.43.0, so it shows the current web UI too): that # release put the sweeper, the notifier and the migration runner each # behind a Postgres advisory lock, and gave incident creation its own # conflict resolution, which is what makes a second replica safe # instead of racing the first. (Still carries v0.34.0's fix too -- # callerMayManageServiceAccount, so an instance-scoped service account # can adopt/rotate a key on a team-scoped account it didn't just create # in the same call -- without which terdutteam-* can wedge permanently # on the crash-window race this demo hit live, niklas/terdut-operator#3.) tag: v0.43.0 # Matches this CRD's own spec.replicas default (v0.4.0) -- stated # explicitly, like every other field in this file, rather than left to # the default. RollingUpdate follows automatically; this operator does # not expose Strategy as a spec field. replicas: 2 networking: hostname: terdut-operator-demo.example servicePort: 8080 database: dsn: "postgres://terdut@terdut-operator-demo-postgres:5432/terdut?sslmode=disable" passwordSecretRef: name: terdut-operator-demo-postgres key: password sweeper: staleAfter: 6h archiveAfter: 168h # No oidc block: password login only, so there's nothing external to # register a redirect URI with before this demo can sign in. passwordLogin: true