chore: add Kubernetes deployment manifests and Gitea Actions build workflow

Mirror the pr_reviewer deployment pattern: Gitea Actions builds a multi-arch
image in the gitea-runner namespace, pushes to git.aridgwayweb.com, recreates
the steward namespace with regcred + env secret, and applies kube manifests.
Add .omo/ to .gitignore.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
Andrew Ridgway 2026-08-18 21:37:53 +10:00
parent 3c57ea64c1
commit 260720dd10
Signed by: armistace
GPG Key ID: C8D9EAC514B47EF1
4 changed files with 141 additions and 0 deletions

View File

@ -0,0 +1,69 @@
name: Build and Push Image
on:
push:
branches:
- main
jobs:
build:
name: Build and push image
runs-on: ubuntu-latest
container: catthehacker/ubuntu:act-latest
if: gitea.ref == 'refs/heads/main'
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Create Kubeconfig
run: |
mkdir $HOME/.kube
echo "${{ secrets.KUBEC_CONFIG_BUILDX_NEW }}" > $HOME/.kube/config
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
with:
driver: kubernetes
driver-opts: |
namespace=gitea-runner
qemu.install=true
- name: Login to Docker Registry
uses: docker/login-action@v3
with:
registry: git.aridgwayweb.com
username: armistace
password: ${{ secrets.REG_PASSWORD }}
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
push: true
platforms: linux/amd64,linux/arm64
tags: |
git.aridgwayweb.com/armistace/steward:latest
- name: Deploy
run: |
echo "Installing Kubectl"
apt-get update
apt-get install -y apt-transport-https ca-certificates curl gnupg
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.33/deb/Release.key | gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
chmod 644 /etc/apt/keyrings/kubernetes-apt-keyring.gpg
echo 'deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.33/deb/ /' | tee /etc/apt/sources.list.d/kubernetes.list
chmod 644 /etc/apt/sources.list.d/kubernetes.list
apt-get update
apt-get install kubectl
kubectl delete namespace steward --ignore-not-found
kubectl create namespace steward
kubectl create secret docker-registry regcred --docker-server=${{ vars.DOCKER_SERVER }} --docker-username=${{ vars.DOCKER_USERNAME }} --docker-password='${{ secrets.DOCKER_PASSWORD }}' --docker-email=${{ vars.DOCKER_EMAIL }} --namespace=steward
kubectl create secret generic steward-env \
--from-literal=TELEGRAM_BOT_TOKEN=${{ secrets.TELEGRAM_BOT_TOKEN }} \
--from-literal=TELEGRAM_ALLOWED_USER_IDS=${{ vars.TELEGRAM_ALLOWED_USER_IDS }} \
--from-literal=OPENAI_API_KEY=${{ secrets.OPENAI_API_KEY }} \
--from-literal=OPENAI_BASE_URL=${{ vars.OPENAI_BASE_URL }} \
--from-literal=OPENAI_MODEL=${{ vars.OPENAI_MODEL }} \
--from-literal=THREAD_MEMORY_PATH=/data/thread_memory.json \
--namespace=steward
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml

3
.gitignore vendored
View File

@ -38,3 +38,6 @@ htmlcov/
# MCP configuration (contains sensitive tokens) # MCP configuration (contains sensitive tokens)
mcp.json mcp.json
# Local session tooling
.omo/

View File

@ -0,0 +1,55 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: steward-deployment
labels:
app: steward
namespace: steward
spec:
replicas: 1
selector:
matchLabels:
app: steward
template:
metadata:
labels:
app: steward
spec:
containers:
- name: steward
image: git.aridgwayweb.com/armistace/steward:latest
envFrom:
- secretRef:
name: steward-env
env:
- name: THREAD_MEMORY_PATH
value: /data/thread_memory.json
volumeMounts:
- name: steward-data
mountPath: /data
resources:
requests:
memory: "256Mi"
cpu: "100m"
limits:
memory: "1Gi"
cpu: "500m"
volumes:
- name: steward-data
persistentVolumeClaim:
claimName: steward-storage
imagePullSecrets:
- name: regcred
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: steward-storage
namespace: steward
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn
resources:
requests:
storage: 1Gi

14
kube/steward_service.yaml Normal file
View File

@ -0,0 +1,14 @@
apiVersion: v1
kind: Service
metadata:
name: steward-service
namespace: steward
spec:
type: NodePort
selector:
app: steward
ports:
- name: matrix-appservice
port: 8000
targetPort: 8000
nodePort: 30002