Reusable repo template for homelab services on git.aridgwayweb.com. Bakes in (all verified live on armistace/wedding-photos): - Hard commit guard: shared pre-commit hook (git config core.hooksPath ~/dev/git-hooks) + master branch protection (push whitelist [armistace], merge whitelist [hermes, armistace]). - Gitea Actions CI (.gitea/workflows/build_push.yml): test + build-deploy, persistent remote buildkit cache, registry push, idempotent deploy that preserves hand-provisioned Secrets, cluster injection from repo secrets/vars via scripts/reconcile-cluster-inject.sh. - Persistent buildkit cache (ci/buildkit/): single-replica Longhorn backing. - scripts/reconcile-cluster-inject.sh: reconcile live Secret/ConfigMap from Gitea secrets/vars without clobbering hand-provisioned values. - RUNBOOK.md: handoff-complete ops doc. Placeholders (<APP> <OWNER> <NS> <KEY_*>) are filled per-service on repo creation.
28 lines
1.2 KiB
YAML
28 lines
1.2 KiB
YAML
# StorageClass for the persistent buildkit cache.
|
|
# - numberOfReplicas: 1 -> the cache is written ONCE across the cluster (1x disk,
|
|
# NOT the 3x triple-replication of the default 'longhorn' SC). This is deliberate:
|
|
# a buildkit cache is throwable/recreatable, so replicating it 3x wastes disk that
|
|
# node 2 (already 76%) can't afford. 1 replica survives single-node loss via
|
|
# dataLocality: best-effort (re-replicates only when a node actually dies).
|
|
# - dataLocality: best-effort -> keep the single replica on the same node as the
|
|
# pod (fast local reads), replicate only if that node fails.
|
|
# Auto-revert safety net: the buildkit-cache-monitor cron reverts buildkit to the
|
|
# ephemeral (no-PVC) driver if any node crosses the critical disk threshold.
|
|
# See monitoring/buildkit-cache-monitor.sh.
|
|
apiVersion: storage.k8s.io/v1
|
|
kind: StorageClass
|
|
metadata:
|
|
name: buildkit-single-1r
|
|
annotations:
|
|
description: "Single-replica Longhorn (buildkit cache) - 1x disk, durable across node loss"
|
|
provisioner: driver.longhorn.io
|
|
allowVolumeExpansion: true
|
|
reclaimPolicy: Delete
|
|
volumeBindingMode: Immediate
|
|
parameters:
|
|
numberOfReplicas: "1"
|
|
staleReplicaTimeout: "30"
|
|
fsType: "ext4"
|
|
dataLocality: "best-effort"
|
|
dataEngine: "v1"
|