# Two teams (this one and 03-team-payments.yaml) so the demo shows # per-team isolation -- separate incident lists, separate escalation # ladders, separate alert sources -- rather than one team standing in for # everything. A team carries its own escalation ladder and dead man's # switches; alert sources are separate objects (04-alertsource-*.yaml) # because each owns a webhook Secret. apiVersion: terdut.ryuvia.com/v1alpha1 kind: TerdutTeam metadata: name: terdutteam-platform spec: # serverRef.namespace omitted: both this and terdut-operator-demo (01-server.yaml) # live in whatever namespace you apply this directory into, which is the # common case and needs no allowedTeams consent on the TerdutServer side # (DESIGN.md §4.1, §4.6). serverRef: name: terdut-operator-demo displayName: Platform # No oidc block: this demo is password-login only (01-server.yaml). # The whole ladder, replaced as one unit. username is required iff kind is # "user" (CEL validation at apply time). The server resolves it, so a # username it does not know yet leaves this team at Reason: UnknownUser # until that person exists -- run-demo.sh creates alice for exactly that. escalation: repeatCount: 2 fallbackTopic: platform-fallback levels: - timeout: 5m targets: - kind: user username: alice - timeout: 10m targets: - kind: oncall # Dead man's switches, by name. fire-alerts.sh's "heartbeat" scenario sends # a matching alert; stop sending it and terdut-server itself opens an # incident once `timeout` passes with no heartbeat. A switch on the server # that is not listed here is removed. deadmanSwitches: - name: platform-watchdog matcher: "alertname=PlatformWatchdog" timeout: 15m severity: critical