- CI/CD: stop deleting the steward namespace on every deploy; use kubectl apply (dry-run -> apply) so the PVC and conversation memory survive deployments. - core: bound _histories with an LRU eviction (max 1000 active threads) to prevent unbounded memory growth. - core: wrap knowledge-base context in KB START/END delimiters and instruct the LLM to treat it as data, mitigating indirect prompt injection. - matrix: wrap message processing in try/except so failures are logged instead of silently dropped. - telegram: remove now-dead flush/tags prompt constants (centralized in core). Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
80 lines
3.7 KiB
YAML
80 lines
3.7 KiB
YAML
name: Build and Push Image
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
jobs:
|
|
build:
|
|
name: Build and push image
|
|
runs-on: ubuntu-latest
|
|
container: catthehacker/ubuntu:act-latest
|
|
if: gitea.ref == 'refs/heads/main'
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Create Kubeconfig
|
|
run: |
|
|
mkdir $HOME/.kube
|
|
echo "${{ secrets.KUBEC_CONFIG_BUILDX_NEW }}" > $HOME/.kube/config
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
with:
|
|
driver: kubernetes
|
|
driver-opts: |
|
|
namespace=gitea-runner
|
|
qemu.install=true
|
|
|
|
- name: Login to Docker Registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: git.aridgwayweb.com
|
|
username: armistace
|
|
password: ${{ secrets.REG_PASSWORD }}
|
|
|
|
- name: Build and push
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: .
|
|
push: true
|
|
platforms: linux/amd64,linux/arm64
|
|
tags: |
|
|
git.aridgwayweb.com/armistace/steward:latest
|
|
git.aridgwayweb.com/armistace/steward:${{ gitea.sha }}
|
|
|
|
- name: Deploy
|
|
run: |
|
|
echo "Installing Kubectl"
|
|
apt-get update
|
|
apt-get install -y apt-transport-https ca-certificates curl gnupg
|
|
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.33/deb/Release.key | gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
|
|
chmod 644 /etc/apt/keyrings/kubernetes-apt-keyring.gpg
|
|
echo 'deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.33/deb/ /' | tee /etc/apt/sources.list.d/kubernetes.list
|
|
chmod 644 /etc/apt/sources.list.d/kubernetes.list
|
|
apt-get update
|
|
apt-get install kubectl
|
|
kubectl create namespace steward --dry-run=client -o yaml | kubectl apply -f -
|
|
kubectl create secret docker-registry regcred --dry-run=client -o yaml \
|
|
--docker-server=${{ vars.DOCKER_SERVER }} --docker-username=${{ vars.DOCKER_USERNAME }} --docker-password='${{ secrets.DOCKER_PASSWORD }}' --docker-email=${{ vars.DOCKER_EMAIL }} --namespace=steward | kubectl apply -f -
|
|
kubectl create secret generic steward-env --dry-run=client -o yaml \
|
|
--from-literal=TELEGRAM_BOT_TOKEN=${{ secrets.TELEGRAM_BOT_TOKEN }} \
|
|
--from-literal=TELEGRAM_ALLOWED_USER_IDS=${{ vars.TELEGRAM_ALLOWED_USER_IDS }} \
|
|
--from-literal=OPENAI_API_KEY=${{ secrets.OPENAI_API_KEY }} \
|
|
--from-literal=OPENAI_BASE_URL=${{ vars.OPENAI_BASE_URL }} \
|
|
--from-literal=OPENAI_MODEL=${{ vars.OPENAI_MODEL }} \
|
|
--from-literal=THREAD_MEMORY_PATH=/data/thread_memory.json \
|
|
--from-literal=STEWARD__MATRIX__HOMESERVER_URL=${{ vars.MATRIX_HOMESERVER_URL }} \
|
|
--from-literal=STEWARD__MATRIX__HOMESERVER_DOMAIN=${{ vars.MATRIX_HOMESERVER_DOMAIN }} \
|
|
--from-literal=STEWARD__MATRIX__AS_TOKEN=${{ secrets.MATRIX_AS_TOKEN }} \
|
|
--from-literal=STEWARD__MATRIX__HS_TOKEN=${{ secrets.MATRIX_HS_TOKEN }} \
|
|
--from-literal=STEWARD__MATRIX__BOT_LOCALPART=${{ vars.MATRIX_BOT_LOCALPART }} \
|
|
--from-literal=STEWARD__MATRIX__LISTEN_PORT=8000 \
|
|
--from-literal=STEWARD__MATRIX__ALLOWED_ROOM_IDS=${{ vars.MATRIX_ALLOWED_ROOM_IDS }} \
|
|
--from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \
|
|
--namespace=steward | kubectl apply -f -
|
|
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml
|
|
kubectl set image deployment/steward-deployment steward=git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} --namespace=steward
|