replicas: 1 and tag: v0.34.0 were both correct when written, but the CRD's own default moved to 2 in v0.4.0 (same release this demo is meant to show off), and v0.34.0 predates v0.36.0's advisory locks that make a second replica safe instead of racing the first. Left as-is, the demo would have been the one place in this repo demonstrating the exact unsafe combination the CRD's own doc comment warns against: more than one replica against an image that doesn't guard the sweeper/notifier/migration-runner singletons. replicas is now stated explicitly as 2 rather than dropped to pick up the default silently, matching every other field in this file's own habit of spelling out what it depends on. tag moves to v0.36.0 specifically -- the first version where the lock landed -- with the comment keeping v0.34.0's original reasoning (the service-account race fix) alongside the new one, since v0.36.0 still carries that fix forward. Co-authored-by: Claude <noreply@anthropic.com>
Terdut operator
Aims to expose most config as CRD's, so end users can self-service over gitops.
See DESIGN.md for the full design: CRD catalog and specs,
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
relationship to charts/terdut-server. This README stays a short pitch; the
open questions it used to carry are now resolved decisions there (§2).
CRD's
terdutServers
Creates a server — Deployment, Service, database wiring, bootstrap, operator
credentials, and allowedTeams consent for cross-namespace teams. See
DESIGN.md §4.1, §4.6.
terdutTeams
- team name
- oidc groups
serverRef— explicit reference to itsTerdutServer, may be in a different namespace (one team owns the server, others self-service a team against it), gated by thatTerdutServer's ownallowedTeamsfield (DESIGN.md §2, §4.1, §4.2, §4.6)
terdutEscalationrules
- rule
teamRef— explicit reference to itsTerdutTeam(DESIGN.md §2, §4.3)
terdutDeadmansswitches
- rule
teamRef(DESIGN.md §4.4)
terdutAlertSources
teamRef(DESIGN.md §4.5)- URL/key are generated by the server at creation and surfaced only via a generated Secret, never set explicitly
Demo
examples/demo wires one of every CRD above together
— two teams, each with an escalation rule, a dead man's switch and an
alert source — plus a script that fires synthetic Alertmanager webhooks
at it, so you can watch real incidents open, escalate and resolve without
a real Alertmanager anywhere in the picture.