mirror of
https://github.com/dredx/prole.git
synced 2026-09-23 12:03:59 +00:00
74 lines
4.0 KiB
Plaintext
74 lines
4.0 KiB
Plaintext
feat: full GKE/prod deployment pipeline from UI to Artifact Registry
|
|
|
|
## GCP / Cluster Environment Screen
|
|
- Auto-populate Cloud tab from conf/prod/gcp.cfg on screen open (org_id,
|
|
billing_account, billing_project, project_id)
|
|
- gcloud auth validity checked on screen startup; friendly modal dialog
|
|
streams gcloud auth login output live so user never leaves the app
|
|
- Live GKE cluster browser: fetches clusters via gcloud container clusters
|
|
list, displays with checkmark selector, auto-selects saved cluster
|
|
- Selecting a cluster runs get-credentials, sets KUBECONFIG/KUBECONTEXT,
|
|
and syncs the region dropdown to the selected cluster's location
|
|
- Region dropdown populated live from gcloud compute regions list with
|
|
checkmark on currently selected region; graceful fallback when offline
|
|
- New 'GCP Storage' tab with workload->StorageClass mapping (CNPG->premium-rwo,
|
|
Redis/Monitoring->standard-rwo, Garage->garage-hdd) and Fetch from Cluster
|
|
- Provider readonly field styled correctly (no solid-black on macOS)
|
|
- Stale knoe.cfg/conf/knoe.cfg symlinks removed; all config I/O now
|
|
resolves env-specific paths via knoe_conf.entrypoint_path()
|
|
|
|
## GKE Autopilot Compatibility (Common Services)
|
|
- Synology iSCSI StorageClass and static PVs guarded behind KNOE_MODE!=k8s
|
|
in init_openbao.sh (GKE Autopilot forbids hostPath/iSCSI volumes)
|
|
- In-cluster Docker registry (hostPath) skipped in k8s mode; GCP Artifact
|
|
Registry used instead
|
|
- Kong renamed knoe-svc-kong in k8s mode; all health-check kubectl calls in
|
|
init_common_services.sh and status_common_services.sh updated accordingly
|
|
- DNS endpoints switched from *.knoe.org to *.knoe.dev in k8s mode
|
|
(api.knoe.dev, git.knoe.dev, svc.knoe.dev); ingress uses gce class
|
|
- New GKE-clean Kong manifests under deploy/opentofu/k8s/manifests/knoe/:
|
|
no k3s node affinity, explicit Autopilot resource requests/limits
|
|
|
|
## Garage S3 Store (GKE)
|
|
- New garage-statefulset-gcp.yaml targeting garage-hdd StorageClass
|
|
(pd-standard, avoids SSD_TOTAL_GB quota exhaustion in us-west3)
|
|
- New storageclass-gcp-hdd.yaml (pd-standard, Retain, WaitForFirstConsumer)
|
|
- GCP StorageClass manifests skipped on re-runs (Autopilot built-ins are
|
|
immutable; skip-if-exists guard added)
|
|
- PVC deletion guard extended to cover any storageClass (not just synology)
|
|
so stale claims are cleaned before StatefulSet recreation
|
|
|
|
## Topology (GKE Autopilot)
|
|
- DaemonSet collector skipped in prod mode (forbidden in kube-system by
|
|
GKE Warden); Kubernetes-only node facts path used instead
|
|
- All ready GKE nodes assumed cnpg-eligible and monitoring-eligible without
|
|
taint/synology-mount checks (skip_collector + assume_nodes_eligible flags)
|
|
|
|
## KUBECONFIG / kubectl (k8s mode)
|
|
- actions.py: new elif mode==k8s branch sets KUBECONFIG=~/.kube/config
|
|
and injects KUBECONTEXT from knoe_cfg_data into script env
|
|
- _build_kubectl_cmd falls back to Global.KUBECONTEXT when
|
|
init_cluster.selected_kubectx is empty
|
|
- _activate_selected_gke_cluster persists KUBECONFIG/KUBECONTEXT to
|
|
knoe_cfg_data and saves knoe.cfg immediately after get-credentials
|
|
|
|
## Database Build Screen (GKE)
|
|
- Registry display shows correct Artifact Registry URL
|
|
(<region>-docker.pkg.dev/<project>/<namespace>/knoe-db) in green
|
|
- Build+push: gcloud auth configure-docker, auto-creates AR repository
|
|
named after SERVICE_NAMESPACE (e.g. knoe-system) if missing, then
|
|
docker tag + push; falls back to gcr.io if region unavailable
|
|
- GCP config loaded from conf/prod/gcp.cfg on every screen entry;
|
|
keys normalised to lowercase so project_id lookup is always consistent
|
|
|
|
## Config / Namespace persistence
|
|
- knoe_conf.py activate_environment: symlink creation removed; sets
|
|
CLUSTER_ENV env-var so all subsequent calls resolve correct env directory
|
|
- knoe/ui/screens/__init__.py: startup config load uses entrypoint_path()
|
|
instead of hardcoded conf/knoe.cfg; seeds SERVICE_NAMESPACE=knoe-system
|
|
for managed envs so Common Services never defaults to 'default'
|
|
- cfg.py _save_knoe_cfg: saves to env-specific path via entrypoint_path()
|
|
- etc/knoe_cfg.sh: removed all ln -snf symlink creation
|
|
|
|
Co-authored-by: Junie <junie@jetbrains.com>
|