# The one TerdutServer this whole demo runs against. Everything else in # this directory (teams, escalation rules, dead man's switches, alert # sources) references it by name. # # The operator never creates any ingress/HTTPRoute for this TerdutServer -- # that's a permanent non-goal (DESIGN.md ยง1, NetworkingSpec's own doc # comment), not a missing feature. This demo reaches it only by # port-forwarding its Service, same name as this object (see README.md); # see ../networking for worked examples of exposing it yourself instead. apiVersion: terdut.ryuvia.com/v1alpha1 kind: TerdutServer metadata: name: terdut-operator-demo spec: image: repository: git.ryuvia.com/niklas/terdut-server # v0.34.0: fixes callerMayManageServiceAccount so an instance-scoped # service account can adopt/rotate a key on a team-scoped account it # didn't just create in the same call -- without this, terdutteam-* # can wedge permanently on exactly the crash-window race this demo # hit live (niklas/terdut-operator#3). tag: v0.34.0 replicas: 1 networking: hostname: terdut-operator-demo.example servicePort: 8080 database: dsn: "postgres://terdut@terdut-operator-demo-postgres:5432/terdut?sslmode=disable" passwordSecretRef: name: terdut-operator-demo-postgres key: password sweeper: staleAfter: 6h archiveAfter: 168h # No oidc block: password login only, so there's nothing external to # register a redirect URI with before this demo can sign in. passwordLogin: true