chore: promote node GitOps source 1c448bc

This commit is contained in:
HWLAB node GitOps Bot
2026-06-29 05:53:00 +00:00
parent 62c2ee2ca0
commit dfd888583a
12 changed files with 4579 additions and 0 deletions
@@ -0,0 +1,53 @@
{
"apiVersion": "v1",
"kind": "List",
"items": [
{
"apiVersion": "v1",
"kind": "ConfigMap",
"metadata": {
"name": "hwlab-v03-hwpod-preinstalled-specs",
"namespace": "hwlab-v03",
"labels": {
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/config-kind": "hwpod-preinstalled-specs"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"hwlab.pikastech.local/source-ref": "config/hwlab-hwpod-preinstalls/constart-71freq-c.yaml#hwpodPreinstall",
"hwlab.pikastech.local/verification-issue": "pikasTech/HWLAB#2183"
}
},
"data": {
"constart-71freq-c.yaml": "apiVersion: hwlab.dev/v0alpha1\nkind: Hwpod\nmetadata:\n uid: CONSTART-71FREQ-C\n name: constart-71freq-c\nspec:\n targetDevice:\n board: ConStart 71-FREQ Controller\n mcu: STM32H723ZGTx\n flashBase: \"0x08000000\"\n workspace:\n path: \"F:\\\\Work\\\\ConStart\"\n toolchain: keil-mdk\n projectRoot: projects/71-00075-11\n keilProject: projects/71-00075-11/FirmWare/MDK-ARM/FREQ_Controller_FW.uvprojx\n keilTarget: FREQ_Controller_FW\n hexPath: projects/71-00075-11/FirmWare/MDK-ARM/FREQ_Controller_FW/FREQ_Controller_FW.hex\n mapPath: projects/71-00075-11/FirmWare/MDK-ARM/FREQ_Controller_FW/FREQ_Controller_FW.map\n keilCliPath: \"C:\\\\Users\\\\liang\\\\.agents\\\\skills\\\\keil\\\\keil-cli.py\"\n debugProbe:\n type: cmsis-dap\n adapter: keil\n probeUid: 3FD750C63E342E24\n probeName: MicroLink CMSIS-DAP\n programBackend: keil-headless\n autoBindUvoptx: true\n ioProbe:\n uart:\n id: uart/1\n port: COM4\n baudrate: 921600\n nodeBinding:\n nodeId: node-d601-f103-v2\n nodeType: pc-host",
"constart-71freq-c.meta.json": "{\n \"contractVersion\": \"hwpod-spec-registry-v1\",\n \"source\": {\n \"kind\": \"preinstalled-yaml-first-spec\",\n \"workspaceRoot\": \"F:\\\\Work\\\\ConStart\",\n \"projectRoot\": \"projects/71-00075-11\",\n \"verificationIssue\": \"pikasTech/HWLAB#2183\",\n \"verifiedAt\": \"2026-06-26\"\n }\n}"
}
},
{
"apiVersion": "v1",
"kind": "ConfigMap",
"metadata": {
"name": "hwlab-v03-project-management-bootstrap",
"namespace": "hwlab-v03",
"labels": {
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/config-kind": "project-management-bootstrap-sources"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"hwlab.pikastech.local/source-ref": "config/hwlab-project-management/constart-71freq-mdtodo.yaml#projectManagement.sources[0]",
"hwlab.pikastech.local/verification-issue": "pikasTech/HWLAB#2183"
}
},
"data": {
"sources.json": "[\n {\n \"sourceId\": \"constart-71freq-mdtodo\",\n \"sourceKind\": \"hwpod-workspace\",\n \"displayName\": \"71-FREQ MDTODO\",\n \"projectId\": \"project_constart_71freq\",\n \"hwpodId\": \"constart-71freq-c\",\n \"nodeId\": \"node-d601-f103-v2\",\n \"workspaceRootRef\": \"F:\\\\Work\\\\ConStart\",\n \"mdtodoRootRef\": \"docs/MDTODO\",\n \"maxFiles\": 300,\n \"capabilities\": [\"probe\", \"list\", \"read\", \"write\", \"reindex\"]\n }\n]"
}
}
]
}
@@ -0,0 +1,327 @@
apiVersion: v1
kind: List
items:
- apiVersion: v1
kind: ConfigMap
metadata:
name: hwlab-deepseek-proxy-config
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-deepseek-proxy
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/service-id: hwlab-deepseek-proxy
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/monitoring: disabled
data:
render-config.sh: >
#!/bin/sh
if [ -z "${DEEPSEEK_API_KEY:-}" ] && [ -z "${OPENCODE_API_KEY:-}" ];
then
echo "at least one of DEEPSEEK_API_KEY or OPENCODE_API_KEY is required" >&2
exit 1
fi
cat > /config/config.yml <<EOF
mode: "Transform"
log:
level: "info"
format: "text"
server:
addr: "0.0.0.0:4001"
persistence:
active_provider: db_sqlite
extensions:
db_sqlite:
enabled: true
config:
path: /data/moonbridge.db
wal: true
busy_timeout_ms: 5000
max_open_conns: 1
metrics:
enabled: true
config:
default_limit: 100
max_limit: 1000
deepseek_v4:
config:
reinforce_instructions: true
reinforce_prompt: "[System Reminder]: Please pay close attention to the system instructions, AGENTS.md files, and any other context provided. Follow them carefully and completely in your response.\n[User]:"
cache:
mode: "explicit"
ttl: "5m"
prompt_caching: true
automatic_prompt_cache: false
explicit_cache_breakpoints: true
allow_retention_downgrade: false
max_breakpoints: 4
min_cache_tokens: 1024
expected_reuse: 2
minimum_value_score: 2048
min_breakpoint_tokens: 1024
defaults:
model: "deepseek-chat"
max_tokens: 8192
trace:
enabled: false
models:
deepseek-chat:
context_window: 128000
max_output_tokens: 8192
display_name: "deepseek-chat"
description: "DeepSeek via Moon Bridge"
default_reasoning_level: null
supported_reasoning_levels: []
extensions:
deepseek_v4:
enabled: true
deepseek-v4-flash:
context_window: 1000000
max_output_tokens: 384000
display_name: "DeepSeek V4 Flash via OpenCode Zen Go"
description: "DeepSeek V4 Flash through OpenCode Zen Go Chat Completions via Moon Bridge"
default_reasoning_level: "xhigh"
supported_reasoning_levels:
- effort: "high"
description: "High reasoning effort"
- effort: "xhigh"
description: "Maximum reasoning effort"
supports_reasoning_summaries: true
default_reasoning_summary: "auto"
extensions:
deepseek_v4:
enabled: true
providers:
deepseek:
base_url: "https://api.deepseek.com/anthropic"
api_key: "${DEEPSEEK_API_KEY}"
version: "2023-06-01"
user_agent: "moonbridge/1.0"
offers:
- model: deepseek-chat
opencode:
base_url: "https://opencode.ai/zen/go/v1"
api_key: "${OPENCODE_API_KEY:-}"
protocol: "openai-chat"
user_agent: "moonbridge-dsflash-go/1.0"
web_search:
support: "disabled"
offers:
- model: deepseek-v4-flash
routes:
deepseek-chat:
model: deepseek-chat
provider: deepseek
deepseek-v4-flash:
model: deepseek-v4-flash
provider: opencode
EOF
- apiVersion: apps/v1
kind: Deployment
metadata:
name: hwlab-deepseek-proxy
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-deepseek-proxy
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/service-id: hwlab-deepseek-proxy
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/moonbridge-source-ref: 1b99888d3dae889b79ee602cb875c7907f7e76f2
hwlab.pikastech.local/bridge-service-id: hwlab-cloud-api
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-image-tag: env-5ff41b539190
hwlab.pikastech.local/bridge-image: 127.0.0.1:5000/hwlab/hwlab-cloud-api-env@sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
hwlab.pikastech.local/bridge-runtime-mode: env-reuse-git-mirror-checkout
hwlab.pikastech.local/bridge-boot-repo: git@github.com:pikasTech/HWLAB.git
hwlab.pikastech.local/bridge-boot-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-boot-sh: deploy/runtime/boot/hwlab-deepseek-responses-bridge.sh
hwlab.pikastech.local/bridge-environment-digest: sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: hwlab-deepseek-proxy
template:
metadata:
labels:
app.kubernetes.io/name: hwlab-deepseek-proxy
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/service-id: hwlab-deepseek-proxy
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/monitoring: disabled
hwlab.pikastech.local/bridge-source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-runtime-mode: env-reuse-git-mirror-checkout
hwlab.pikastech.local/bridge-boot-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
annotations:
hwlab.pikastech.local/bridge-service-id: hwlab-cloud-api
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-image-tag: env-5ff41b539190
hwlab.pikastech.local/bridge-image: 127.0.0.1:5000/hwlab/hwlab-cloud-api-env@sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
hwlab.pikastech.local/bridge-runtime-mode: env-reuse-git-mirror-checkout
hwlab.pikastech.local/bridge-boot-repo: git@github.com:pikasTech/HWLAB.git
hwlab.pikastech.local/bridge-boot-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/bridge-boot-sh: deploy/runtime/boot/hwlab-deepseek-responses-bridge.sh
hwlab.pikastech.local/bridge-environment-digest: sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
spec:
initContainers:
- name: moonbridge-config
image: 127.0.0.1:5000/hwlab/hwlab-cloud-api-env@sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
imagePullPolicy: IfNotPresent
command:
- /bin/sh
- -eu
- /scripts/render-config.sh
env:
- name: DEEPSEEK_API_KEY
valueFrom:
secretKeyRef:
name: hwlab-v03-code-agent-provider
key: openai-api-key
optional: true
- name: OPENCODE_API_KEY
valueFrom:
secretKeyRef:
name: hwlab-v03-code-agent-provider
key: opencode-api-key
optional: true
volumeMounts:
- name: moonbridge-scripts
mountPath: /scripts
readOnly: true
- name: moonbridge-config
mountPath: /config
containers:
- name: responses-bridge
image: 127.0.0.1:5000/hwlab/hwlab-cloud-api-env@sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
imagePullPolicy: IfNotPresent
env:
- name: PORT
value: "4000"
- name: HWLAB_COMMIT_ID
value: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
- name: HWLAB_IMAGE
value: 127.0.0.1:5000/hwlab/hwlab-cloud-api-env@sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
- name: HWLAB_IMAGE_TAG
value: env-5ff41b539190
- name: HWLAB_DEEPSEEK_BRIDGE_UPSTREAM
value: http://127.0.0.1:4001
- name: HWLAB_DEEPSEEK_BRIDGE_MODEL
value: deepseek-chat
- name: HWLAB_RUNTIME_MODE
value: env-reuse-git-mirror-checkout
- name: HWLAB_BOOT_REPO
value: git@github.com:pikasTech/HWLAB.git
- name: HWLAB_BOOT_COMMIT
value: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
- name: HWLAB_BOOT_REF
value: v0.3
- name: HWLAB_BOOT_SH
value: deploy/runtime/boot/hwlab-deepseek-responses-bridge.sh
- name: HWLAB_BOOT_READ_URL
value: http://git-mirror-http.devops-infra.svc.cluster.local:8080/pikasTech/HWLAB.git
- name: HWLAB_ENVIRONMENT_IMAGE
value: 127.0.0.1:5000/hwlab/hwlab-cloud-api-env:env-5ff41b539190
- name: HWLAB_ENVIRONMENT_DIGEST
value: sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
- name: HWLAB_ENVIRONMENT_INPUT_HASH
value: 5ff41b539190849e76511ed722a4539f5921622e98eea1444b606475f8ef55aa
- name: HWLAB_CODE_INPUT_HASH
value: e692ec9a4feee2d0ee983f1f9dc2eeebdfa1e4dd68dd9bcfdef19129d9bbb57a
- name: HWLAB_IMAGE_DIGEST
value: sha256:c317276bb0d002bc82cb8d3cde6d5e596db18325585436d9f3592ebd173eb01d
ports:
- name: http
containerPort: 4000
readinessProbe:
httpGet:
path: /health/readiness
port: http
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /health/liveliness
port: http
initialDelaySeconds: 20
periodSeconds: 20
startupProbe:
httpGet:
path: /health/readiness
port: http
initialDelaySeconds: 10
periodSeconds: 10
timeoutSeconds: 2
failureThreshold: 30
successThreshold: 1
- name: moonbridge
image: 127.0.0.1:5000/hwlab/moonbridge:1b99888d3dae
imagePullPolicy: IfNotPresent
args:
- -config
- /config/config.yml
ports:
- name: moonbridge-http
containerPort: 4001
readinessProbe:
httpGet:
path: /v1/models
port: moonbridge-http
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /v1/models
port: moonbridge-http
initialDelaySeconds: 20
periodSeconds: 20
volumeMounts:
- name: moonbridge-config
mountPath: /config
readOnly: true
- name: moonbridge-data
mountPath: /data
volumes:
- name: moonbridge-scripts
configMap:
name: hwlab-deepseek-proxy-config
- name: moonbridge-config
emptyDir: {}
- name: moonbridge-data
emptyDir: {}
- apiVersion: v1
kind: Service
metadata:
name: hwlab-deepseek-proxy
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-deepseek-proxy
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/service-id: hwlab-deepseek-proxy
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/monitoring: disabled
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-deepseek-proxy
ports:
- name: http
port: 4000
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
@@ -0,0 +1,27 @@
{
"apiVersion": "v1",
"kind": "ConfigMap",
"metadata": {
"name": "hwlab-v03-health-contract",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-v03-health-contract",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13",
"hwlab.pikastech.local/environment": "v03"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs"
}
},
"data": {
"endpoint": "https://hwlab.pikapython.com",
"cloud-api": "GET /health/live through https://hwlab.pikapython.com",
"cloud-api-db": "DEV DB config gate requires HWLAB_CLOUD_DB_URL from Secret hwlab-cloud-api-dev-db/database-url and HWLAB_CLOUD_DB_SSL_MODE=disable. Runtime readiness dials the redacted host parsed from the Secret URL and reports endpointSource=secret-url-host. cloud-api-db is an optional desired alias only until this repo owns Service plus Endpoint or EndpointSlice manifests and rollout/apply contract; health reports env presence, env injection, redacted connection attempt/result, and liveConnected without exposing secret values",
"cloud-web": "GET /health/live on https://hwlab.pikapython.com; consumes cloud-api only",
"agent": "hwlab-cloud-api authorizes Code Agent sessions and dispatches execution to AgentRun v0.1; no HWLAB-owned agent manager/worker service is deployed",
"edge-proxy": "hwlab-edge-proxy:6667 exposes /health/live and proxies DEV endpoint traffic to hwlab-cloud-api",
"runtime-substitute-policy": "Do not replace HWLAB runtime with UniDesk backend, provider-gateway, or microservice proxy"
}
}
@@ -0,0 +1,14 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: hwlab-v03
resources:
- namespace.yaml
- services.yaml
- health-contract.yaml
- configmaps.yaml
- workloads.yaml
- deepseek-proxy.yaml
- postgres.yaml
- workbench-redis.yaml
- openfga.yaml
- node-frpc.yaml
@@ -0,0 +1,17 @@
{
"apiVersion": "v1",
"kind": "Namespace",
"metadata": {
"name": "hwlab-v03",
"labels": {
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13",
"hwlab.pikastech.local/environment": "v03"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs"
}
}
}
@@ -0,0 +1,89 @@
apiVersion: v1
kind: List
items:
- apiVersion: v1
kind: ConfigMap
metadata:
name: hwlab-v03-frpc-config
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-v03-frpc
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
data:
frpc.toml: |
serverAddr = "82.156.23.220"
serverPort = 22000
loginFailExit = true
auth.token = "{{ .Envs.HWLAB_FRP_TOKEN }}"
[[proxies]]
name = "hwlab-jd01-v03-cloud-web"
type = "tcp"
localIP = "hwlab-cloud-web.hwlab-v03.svc.cluster.local"
localPort = 8080
remotePort = 22090
[[proxies]]
name = "hwlab-jd01-v03-edge-proxy"
type = "tcp"
localIP = "hwlab-edge-proxy.hwlab-v03.svc.cluster.local"
localPort = 6667
remotePort = 22089
- apiVersion: apps/v1
kind: Deployment
metadata:
name: hwlab-v03-frpc
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-v03-frpc
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: hwlab-v03-frpc
template:
metadata:
labels:
app.kubernetes.io/name: hwlab-v03-frpc
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/config-sha256: ce6c82e15b128572
annotations:
hwlab.pikastech.local/config-sha256: ce6c82e15b12857248f574b624109aae09b0489b990a252c4955d57567dd2ac2
spec:
hostNetwork: true
dnsPolicy: ClusterFirstWithHostNet
containers:
- name: frpc
image: 127.0.0.1:5000/hwlab/frpc:v0.68.1
imagePullPolicy: IfNotPresent
args:
- -c
- /etc/frp/frpc.toml
volumeMounts:
- name: config
mountPath: /etc/frp
readOnly: true
env:
- name: HWLAB_FRP_TOKEN
valueFrom:
secretKeyRef:
name: hwlab-v03-frpc-secrets
key: token
volumes:
- name: config
configMap:
name: hwlab-v03-frpc-config
strategy:
type: Recreate
@@ -0,0 +1,278 @@
{
"apiVersion": "v1",
"kind": "List",
"items": [
{
"apiVersion": "batch/v1",
"kind": "Job",
"metadata": {
"name": "hwlab-openfga-migrate",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-openfga",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/component": "authorization",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-openfga",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/hook": "Sync",
"argocd.argoproj.io/sync-wave": "1",
"argocd.argoproj.io/hook-delete-policy": "BeforeHookCreation,HookSucceeded"
}
},
"spec": {
"backoffLimit": 3,
"template": {
"metadata": {
"labels": {
"app.kubernetes.io/name": "hwlab-openfga",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/component": "authorization",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-openfga",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs"
}
},
"spec": {
"restartPolicy": "OnFailure",
"containers": [
{
"name": "openfga-migrate",
"image": "127.0.0.1:5000/hwlab/openfga:v1.17.0",
"imagePullPolicy": "IfNotPresent",
"args": [
"migrate"
],
"env": [
{
"name": "OPENFGA_DATASTORE_ENGINE",
"value": "postgres"
},
{
"name": "OPENFGA_DATASTORE_URI",
"valueFrom": {
"secretKeyRef": {
"name": "hwlab-v03-openfga",
"key": "datastore-uri"
}
}
},
{
"name": "OPENFGA_AUTHN_METHOD",
"value": "preshared"
},
{
"name": "OPENFGA_AUTHN_PRESHARED_KEYS",
"valueFrom": {
"secretKeyRef": {
"name": "hwlab-v03-openfga",
"key": "authn-preshared-key"
}
}
},
{
"name": "OPENFGA_PLAYGROUND_ENABLED",
"value": "false"
},
{
"name": "OPENFGA_HTTP_ADDR",
"value": "0.0.0.0:8080"
},
{
"name": "OPENFGA_GRPC_ADDR",
"value": "0.0.0.0:8081"
}
]
}
]
}
}
}
},
{
"apiVersion": "apps/v1",
"kind": "Deployment",
"metadata": {
"name": "hwlab-openfga",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-openfga",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/component": "authorization",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-openfga",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"spec": {
"replicas": 1,
"selector": {
"matchLabels": {
"app.kubernetes.io/name": "hwlab-openfga"
}
},
"template": {
"metadata": {
"labels": {
"app.kubernetes.io/name": "hwlab-openfga",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/component": "authorization",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-openfga",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs"
}
},
"spec": {
"containers": [
{
"name": "openfga",
"image": "127.0.0.1:5000/hwlab/openfga:v1.17.0",
"imagePullPolicy": "IfNotPresent",
"args": [
"run"
],
"env": [
{
"name": "OPENFGA_DATASTORE_ENGINE",
"value": "postgres"
},
{
"name": "OPENFGA_DATASTORE_URI",
"valueFrom": {
"secretKeyRef": {
"name": "hwlab-v03-openfga",
"key": "datastore-uri"
}
}
},
{
"name": "OPENFGA_AUTHN_METHOD",
"value": "preshared"
},
{
"name": "OPENFGA_AUTHN_PRESHARED_KEYS",
"valueFrom": {
"secretKeyRef": {
"name": "hwlab-v03-openfga",
"key": "authn-preshared-key"
}
}
},
{
"name": "OPENFGA_PLAYGROUND_ENABLED",
"value": "false"
},
{
"name": "OPENFGA_HTTP_ADDR",
"value": "0.0.0.0:8080"
},
{
"name": "OPENFGA_GRPC_ADDR",
"value": "0.0.0.0:8081"
}
],
"ports": [
{
"name": "http",
"containerPort": 8080
},
{
"name": "grpc",
"containerPort": 8081
}
],
"readinessProbe": {
"httpGet": {
"path": "/healthz",
"port": "http"
},
"initialDelaySeconds": 3,
"periodSeconds": 10
},
"livenessProbe": {
"httpGet": {
"path": "/healthz",
"port": "http"
},
"initialDelaySeconds": 15,
"periodSeconds": 20
},
"resources": {
"requests": {
"cpu": "50m",
"memory": "128Mi"
},
"limits": {
"cpu": "500m",
"memory": "512Mi"
}
}
}
]
}
}
}
},
{
"apiVersion": "v1",
"kind": "Service",
"metadata": {
"name": "hwlab-openfga",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-openfga",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/component": "authorization",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-openfga",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"spec": {
"type": "ClusterIP",
"selector": {
"app.kubernetes.io/name": "hwlab-openfga"
},
"ports": [
{
"name": "http",
"port": 8080,
"targetPort": "http"
},
{
"name": "grpc",
"port": 8081,
"targetPort": "grpc"
}
]
}
}
]
}
@@ -0,0 +1,942 @@
apiVersion: v1
kind: List
items:
- apiVersion: v1
kind: ConfigMap
metadata:
name: hwlab-v03-postgres-init
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-v03-postgres
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
data:
0001_cloud_core_skeleton.sql: >
-- SPEC: PJ2026-0104010803 Workbench唯一投影
draft-2026-06-24-p0-aggregate-event-stream.
-- HWLAB L1 Cloud Core schema skeleton.
-- This file is source schema only; applying it to DEV/PROD is a
separate
-- operator action and is not performed by source tests or smokes.
CREATE TABLE IF NOT EXISTS projects (
id TEXT PRIMARY KEY,
name TEXT NOT NULL DEFAULT '',
status TEXT NOT NULL DEFAULT 'pending',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS users (
id TEXT PRIMARY KEY,
username TEXT NOT NULL UNIQUE,
display_name TEXT NOT NULL DEFAULT '',
role TEXT NOT NULL CHECK (role IN ('admin', 'user')),
status TEXT NOT NULL DEFAULT 'active' CHECK (status IN ('active', 'disabled')),
password_hash TEXT,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS user_sessions (
id TEXT PRIMARY KEY,
user_id TEXT NOT NULL REFERENCES users(id),
session_token_hash TEXT NOT NULL UNIQUE,
created_at TEXT NOT NULL,
last_seen_at TEXT NOT NULL,
expires_at TEXT NOT NULL,
revoked_at TEXT
);
CREATE TABLE IF NOT EXISTS gateway_sessions (
id TEXT PRIMARY KEY,
project_id TEXT,
gateway_service_id TEXT NOT NULL,
status TEXT NOT NULL DEFAULT 'pending',
started_at TEXT,
ended_at TEXT,
gateway_session_json TEXT NOT NULL DEFAULT '{}'
);
CREATE TABLE IF NOT EXISTS box_resources (
id TEXT PRIMARY KEY,
project_id TEXT,
gateway_session_id TEXT,
resource_state TEXT NOT NULL DEFAULT 'available',
labels_json TEXT NOT NULL DEFAULT '{}',
resource_json TEXT NOT NULL DEFAULT '{}',
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS box_capabilities (
id TEXT PRIMARY KEY,
box_resource_id TEXT NOT NULL,
capability_type TEXT NOT NULL,
capability_json TEXT NOT NULL DEFAULT '{}',
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS wiring_configs (
id TEXT PRIMARY KEY,
project_id TEXT,
wiring_json TEXT NOT NULL DEFAULT '{}',
status TEXT NOT NULL DEFAULT 'pending',
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS patch_panel_status (
id TEXT PRIMARY KEY,
gateway_session_id TEXT,
wiring_config_id TEXT,
status_json TEXT NOT NULL DEFAULT '{}',
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS hardware_operations (
id TEXT PRIMARY KEY,
project_id TEXT,
requested_by TEXT,
operation_type TEXT NOT NULL,
operation_json TEXT NOT NULL DEFAULT '{}',
status TEXT NOT NULL DEFAULT 'requested',
requested_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS audit_events (
id TEXT PRIMARY KEY,
request_id TEXT NOT NULL,
actor TEXT NOT NULL,
source TEXT NOT NULL,
operation TEXT NOT NULL,
target TEXT NOT NULL,
result TEXT NOT NULL,
timestamp TEXT NOT NULL,
event_json TEXT NOT NULL DEFAULT '{}'
);
CREATE TABLE IF NOT EXISTS agent_sessions (
id TEXT PRIMARY KEY,
project_id TEXT,
agent_id TEXT NOT NULL,
status TEXT NOT NULL DEFAULT 'pending',
started_at TEXT,
ended_at TEXT,
owner_user_id TEXT REFERENCES users(id),
conversation_id TEXT,
thread_id TEXT,
last_trace_id TEXT,
session_json TEXT NOT NULL DEFAULT '{}',
updated_at TEXT
);
ALTER TABLE agent_sessions ADD COLUMN IF NOT EXISTS owner_user_id TEXT
REFERENCES users(id);
ALTER TABLE agent_sessions ADD COLUMN IF NOT EXISTS conversation_id
TEXT;
ALTER TABLE agent_sessions ADD COLUMN IF NOT EXISTS thread_id TEXT;
ALTER TABLE agent_sessions ADD COLUMN IF NOT EXISTS last_trace_id TEXT;
ALTER TABLE agent_sessions ADD COLUMN IF NOT EXISTS session_json TEXT
NOT NULL DEFAULT '{}';
ALTER TABLE agent_sessions ADD COLUMN IF NOT EXISTS updated_at TEXT;
CREATE INDEX IF NOT EXISTS idx_agent_sessions_owner ON
agent_sessions(owner_user_id);
CREATE INDEX IF NOT EXISTS idx_agent_sessions_conversation ON
agent_sessions(conversation_id);
CREATE INDEX IF NOT EXISTS idx_agent_sessions_active_updated ON
agent_sessions(updated_at DESC, id DESC) WHERE status <> 'archived';
CREATE INDEX IF NOT EXISTS idx_agent_sessions_owner_active_updated ON
agent_sessions(owner_user_id, updated_at DESC, id DESC) WHERE status <>
'archived';
CREATE TABLE IF NOT EXISTS account_workspaces (
id TEXT PRIMARY KEY,
owner_user_id TEXT NOT NULL REFERENCES users(id),
project_id TEXT NOT NULL,
name TEXT NOT NULL DEFAULT 'Default Workbench',
status TEXT NOT NULL DEFAULT 'active' CHECK (status IN ('active', 'archived')),
is_default BOOLEAN NOT NULL DEFAULT true,
selected_conversation_id TEXT,
selected_agent_session_id TEXT,
active_trace_id TEXT,
provider_profile TEXT,
workspace_json TEXT NOT NULL DEFAULT '{}',
revision INTEGER NOT NULL DEFAULT 1,
updated_by_session_id TEXT,
updated_by_client TEXT,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE UNIQUE INDEX IF NOT EXISTS idx_account_workspaces_default ON
account_workspaces(owner_user_id, project_id) WHERE is_default = TRUE
AND status = 'active';
CREATE INDEX IF NOT EXISTS idx_account_workspaces_owner ON
account_workspaces(owner_user_id, project_id, updated_at DESC);
CREATE TABLE IF NOT EXISTS worker_sessions (
id TEXT PRIMARY KEY,
agent_session_id TEXT,
worker_id TEXT NOT NULL,
status TEXT NOT NULL DEFAULT 'pending',
started_at TEXT,
ended_at TEXT
);
CREATE TABLE IF NOT EXISTS agent_trace_events (
id TEXT PRIMARY KEY,
trace_id TEXT NOT NULL,
agent_session_id TEXT,
worker_session_id TEXT,
level TEXT NOT NULL DEFAULT 'info',
message TEXT NOT NULL DEFAULT '',
event_json TEXT NOT NULL DEFAULT '{}',
occurred_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_agent_trace_events_trace_order ON
agent_trace_events(trace_id, occurred_at, id);
CREATE INDEX IF NOT EXISTS idx_agent_trace_events_session_order ON
agent_trace_events(agent_session_id, occurred_at, id);
CREATE INDEX IF NOT EXISTS idx_agent_trace_events_worker_order ON
agent_trace_events(worker_session_id, occurred_at, id);
CREATE TABLE IF NOT EXISTS workbench_projection_state (
trace_id TEXT PRIMARY KEY,
session_id TEXT,
conversation_id TEXT,
thread_id TEXT,
run_id TEXT NOT NULL,
command_id TEXT NOT NULL,
last_agentrun_seq INTEGER NOT NULL DEFAULT 0,
last_projected_seq INTEGER NOT NULL DEFAULT 0,
upstream_latest_seq INTEGER,
projection_status TEXT NOT NULL DEFAULT 'projecting',
projection_health TEXT NOT NULL DEFAULT 'healthy',
result_sync_state TEXT NOT NULL DEFAULT 'not_started',
last_projected_at TEXT,
last_result_sync_at TEXT,
last_error_code TEXT,
last_error_message TEXT,
failure_count INTEGER NOT NULL DEFAULT 0,
next_retry_at TEXT,
projection_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS
idx_workbench_projection_state_status_retry_updated ON
workbench_projection_state(projection_status, next_retry_at,
updated_at);
CREATE INDEX IF NOT EXISTS idx_workbench_projection_state_run_command ON
workbench_projection_state(run_id, command_id);
CREATE INDEX IF NOT EXISTS
idx_workbench_projection_state_session_updated ON
workbench_projection_state(session_id, updated_at DESC);
CREATE TABLE IF NOT EXISTS workbench_sessions (
session_id TEXT PRIMARY KEY,
owner_user_id TEXT REFERENCES users(id),
project_id TEXT,
conversation_id TEXT,
thread_id TEXT,
status TEXT NOT NULL DEFAULT 'unknown',
last_trace_id TEXT,
projected_seq INTEGER NOT NULL DEFAULT 0,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
session_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_sessions_owner_updated ON
workbench_sessions(owner_user_id, updated_at DESC, session_id);
CREATE INDEX IF NOT EXISTS idx_workbench_sessions_status_updated ON
workbench_sessions(status, updated_at DESC, session_id);
CREATE TABLE IF NOT EXISTS workbench_messages (
message_id TEXT PRIMARY KEY,
session_id TEXT NOT NULL,
turn_id TEXT,
trace_id TEXT,
role TEXT NOT NULL,
status TEXT NOT NULL DEFAULT 'unknown',
projected_seq INTEGER NOT NULL DEFAULT 0,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
message_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_messages_session_updated ON
workbench_messages(session_id, updated_at ASC, message_id);
CREATE INDEX IF NOT EXISTS idx_workbench_messages_trace ON
workbench_messages(trace_id, message_id);
CREATE INDEX IF NOT EXISTS idx_workbench_messages_turn ON
workbench_messages(turn_id, message_id);
CREATE TABLE IF NOT EXISTS workbench_parts (
part_id TEXT PRIMARY KEY,
message_id TEXT NOT NULL,
session_id TEXT NOT NULL,
turn_id TEXT,
trace_id TEXT,
part_index INTEGER NOT NULL DEFAULT 0,
part_type TEXT NOT NULL DEFAULT 'text',
status TEXT NOT NULL DEFAULT 'unknown',
projected_seq INTEGER NOT NULL DEFAULT 0,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
part_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_parts_message_index ON
workbench_parts(message_id, part_index, part_id);
CREATE INDEX IF NOT EXISTS idx_workbench_parts_session_trace ON
workbench_parts(session_id, trace_id, part_index);
CREATE TABLE IF NOT EXISTS workbench_turns (
turn_id TEXT PRIMARY KEY,
session_id TEXT NOT NULL,
trace_id TEXT,
message_id TEXT,
status TEXT NOT NULL DEFAULT 'unknown',
projected_seq INTEGER NOT NULL DEFAULT 0,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
final_response_json TEXT NOT NULL DEFAULT 'null',
diagnostic_json TEXT NOT NULL DEFAULT '{}',
turn_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_turns_session_updated ON
workbench_turns(session_id, updated_at DESC, turn_id);
CREATE INDEX IF NOT EXISTS idx_workbench_turns_trace ON
workbench_turns(trace_id, turn_id);
CREATE TABLE IF NOT EXISTS workbench_trace_events (
id TEXT PRIMARY KEY,
trace_id TEXT NOT NULL,
session_id TEXT,
turn_id TEXT,
message_id TEXT,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
projected_seq INTEGER NOT NULL DEFAULT 0,
event_type TEXT NOT NULL DEFAULT 'event',
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
event_json TEXT NOT NULL DEFAULT '{}',
occurred_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_trace_events_trace_seq ON
workbench_trace_events(trace_id, source_seq, projected_seq, id);
CREATE INDEX IF NOT EXISTS idx_workbench_trace_events_session_seq ON
workbench_trace_events(session_id, source_seq, projected_seq, id);
WITH duplicate_trace_source_events AS (
SELECT
id,
ROW_NUMBER() OVER (
PARTITION BY trace_id, source_event_id
ORDER BY occurred_at, id
) AS duplicate_rank
FROM workbench_trace_events
WHERE trace_id IS NOT NULL AND source_event_id IS NOT NULL
), trace_source_event_rewrites AS (
SELECT
id,
'workbench_trace_events:' || id AS stable_source_event_id
FROM duplicate_trace_source_events
WHERE duplicate_rank > 1
)
UPDATE workbench_trace_events AS target
SET
source_event_id = trace_source_event_rewrites.stable_source_event_id,
updated_at = COALESCE(NULLIF(target.updated_at, ''), target.occurred_at, CURRENT_TIMESTAMP::text)
FROM trace_source_event_rewrites
WHERE target.id = trace_source_event_rewrites.id
AND target.source_event_id IS DISTINCT FROM trace_source_event_rewrites.stable_source_event_id;
WITH trace_event_projected_seq_conflicts AS (
SELECT trace_id
FROM workbench_trace_events
WHERE trace_id IS NOT NULL
GROUP BY trace_id
HAVING COUNT(*) <> COUNT(DISTINCT projected_seq)
), trace_event_resequence AS (
SELECT
workbench_trace_events.id,
(ROW_NUMBER() OVER (
PARTITION BY workbench_trace_events.trace_id
ORDER BY
CASE WHEN workbench_trace_events.projected_seq > 0 THEN 0 ELSE 1 END,
workbench_trace_events.projected_seq,
workbench_trace_events.occurred_at,
workbench_trace_events.id
))::integer AS durable_projected_seq
FROM workbench_trace_events
INNER JOIN trace_event_projected_seq_conflicts
ON trace_event_projected_seq_conflicts.trace_id = workbench_trace_events.trace_id
)
UPDATE workbench_trace_events AS target
SET
projected_seq = trace_event_resequence.durable_projected_seq,
source_seq = CASE
WHEN target.source_seq > 0 THEN target.source_seq
ELSE trace_event_resequence.durable_projected_seq
END,
updated_at = COALESCE(NULLIF(target.updated_at, ''), target.occurred_at, CURRENT_TIMESTAMP::text)
FROM trace_event_resequence
WHERE target.id = trace_event_resequence.id
AND (
target.projected_seq IS DISTINCT FROM trace_event_resequence.durable_projected_seq
OR target.source_seq <= 0
);
DROP INDEX IF EXISTS idx_workbench_trace_events_trace_source_event;
CREATE UNIQUE INDEX idx_workbench_trace_events_trace_source_event ON
workbench_trace_events(trace_id, source_event_id) WHERE source_event_id
IS NOT NULL;
DROP INDEX IF EXISTS idx_workbench_trace_events_trace_projected_seq;
CREATE UNIQUE INDEX idx_workbench_trace_events_trace_projected_seq ON
workbench_trace_events(trace_id, projected_seq);
CREATE TABLE IF NOT EXISTS workbench_event_sequences (
aggregate_id TEXT PRIMARY KEY,
aggregate_type TEXT NOT NULL DEFAULT 'trace',
session_id TEXT,
turn_id TEXT,
trace_id TEXT,
last_seq INTEGER NOT NULL DEFAULT 0,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_event_sequences_session ON
workbench_event_sequences(session_id, updated_at DESC, aggregate_id);
CREATE INDEX IF NOT EXISTS idx_workbench_event_sequences_trace ON
workbench_event_sequences(trace_id, updated_at DESC, aggregate_id);
CREATE TABLE IF NOT EXISTS workbench_events (
event_seq BIGSERIAL PRIMARY KEY,
event_id TEXT NOT NULL UNIQUE,
aggregate_id TEXT NOT NULL,
aggregate_type TEXT NOT NULL DEFAULT 'trace',
aggregate_seq INTEGER NOT NULL,
session_id TEXT,
turn_id TEXT,
trace_id TEXT,
message_id TEXT,
source_run_id TEXT,
source_command_id TEXT,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
event_type TEXT NOT NULL DEFAULT 'event',
projection_revision INTEGER NOT NULL DEFAULT 0,
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
payload_json TEXT NOT NULL DEFAULT '{}',
occurred_at TEXT NOT NULL,
committed_at TEXT NOT NULL
);
CREATE UNIQUE INDEX IF NOT EXISTS idx_workbench_events_aggregate_seq ON
workbench_events(aggregate_id, aggregate_seq);
CREATE UNIQUE INDEX IF NOT EXISTS
idx_workbench_events_aggregate_source_event ON
workbench_events(aggregate_id, source_event_id) WHERE source_event_id IS
NOT NULL;
CREATE INDEX IF NOT EXISTS idx_workbench_events_trace_seq ON
workbench_events(trace_id, event_seq);
CREATE INDEX IF NOT EXISTS idx_workbench_events_session_seq ON
workbench_events(session_id, event_seq);
CREATE INDEX IF NOT EXISTS idx_workbench_events_type_seq ON
workbench_events(event_type, event_seq);
CREATE TABLE IF NOT EXISTS workbench_session_inputs (
input_id TEXT PRIMARY KEY,
session_id TEXT NOT NULL,
turn_id TEXT,
trace_id TEXT,
message_id TEXT,
command_id TEXT,
delivery TEXT NOT NULL DEFAULT 'queue',
admitted_seq INTEGER NOT NULL DEFAULT 0,
promoted_seq INTEGER,
status TEXT NOT NULL DEFAULT 'admitted',
error_code TEXT,
source_event_id TEXT,
input_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS idx_workbench_session_inputs_session_seq ON
workbench_session_inputs(session_id, admitted_seq, input_id);
CREATE INDEX IF NOT EXISTS idx_workbench_session_inputs_trace ON
workbench_session_inputs(trace_id, input_id);
CREATE INDEX IF NOT EXISTS idx_workbench_session_inputs_command ON
workbench_session_inputs(command_id, input_id) WHERE command_id IS NOT
NULL;
CREATE UNIQUE INDEX IF NOT EXISTS
idx_workbench_session_inputs_source_event ON
workbench_session_inputs(session_id, source_event_id) WHERE
source_event_id IS NOT NULL;
CREATE TABLE IF NOT EXISTS workbench_projection_checkpoints (
trace_id TEXT PRIMARY KEY,
session_id TEXT,
turn_id TEXT,
run_id TEXT,
command_id TEXT,
projected_seq INTEGER NOT NULL DEFAULT 0,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
projection_status TEXT NOT NULL DEFAULT 'projecting',
projection_health TEXT NOT NULL DEFAULT 'healthy',
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
diagnostic_json TEXT NOT NULL DEFAULT '{}',
checkpoint_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX IF NOT EXISTS
idx_workbench_projection_checkpoints_status_updated ON
workbench_projection_checkpoints(projection_status, updated_at DESC,
trace_id);
CREATE INDEX IF NOT EXISTS
idx_workbench_projection_checkpoints_session_updated ON
workbench_projection_checkpoints(session_id, updated_at DESC, trace_id);
CREATE TABLE IF NOT EXISTS workbench_projection_outbox (
outbox_seq BIGSERIAL PRIMARY KEY,
event_seq BIGINT,
aggregate_id TEXT,
aggregate_seq INTEGER NOT NULL DEFAULT 0,
projection_revision INTEGER NOT NULL DEFAULT 0,
trace_id TEXT NOT NULL,
session_id TEXT,
turn_id TEXT,
message_id TEXT,
projected_seq INTEGER NOT NULL DEFAULT 0,
source_seq INTEGER NOT NULL DEFAULT 0,
source_event_id TEXT,
commit_type TEXT NOT NULL DEFAULT 'event',
terminal BOOLEAN NOT NULL DEFAULT false,
sealed BOOLEAN NOT NULL DEFAULT false,
payload_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL
);
ALTER TABLE workbench_projection_outbox ADD COLUMN IF NOT EXISTS
event_seq BIGINT;
ALTER TABLE workbench_projection_outbox ADD COLUMN IF NOT EXISTS
aggregate_id TEXT;
ALTER TABLE workbench_projection_outbox ADD COLUMN IF NOT EXISTS
aggregate_seq INTEGER NOT NULL DEFAULT 0;
ALTER TABLE workbench_projection_outbox ADD COLUMN IF NOT EXISTS
projection_revision INTEGER NOT NULL DEFAULT 0;
CREATE INDEX IF NOT EXISTS idx_workbench_projection_outbox_trace_seq ON
workbench_projection_outbox(trace_id, outbox_seq);
CREATE INDEX IF NOT EXISTS idx_workbench_projection_outbox_session_seq
ON workbench_projection_outbox(session_id, outbox_seq);
CREATE INDEX IF NOT EXISTS idx_workbench_projection_outbox_after_seq ON
workbench_projection_outbox(outbox_seq);
CREATE INDEX IF NOT EXISTS idx_workbench_projection_outbox_event_seq ON
workbench_projection_outbox(event_seq) WHERE event_seq IS NOT NULL;
INSERT INTO workbench_sessions (
session_id,
owner_user_id,
project_id,
conversation_id,
thread_id,
status,
last_trace_id,
projected_seq,
source_seq,
source_event_id,
terminal,
sealed,
session_json,
created_at,
updated_at
)
SELECT
id,
owner_user_id,
project_id,
conversation_id,
thread_id,
status,
last_trace_id,
0,
0,
id,
status IN ('completed', 'failed', 'canceled', 'cancelled', 'archived'),
status IN ('completed', 'failed', 'canceled', 'cancelled', 'archived') AND ended_at IS NOT NULL,
COALESCE(NULLIF(session_json, ''), '{}'),
COALESCE(started_at, updated_at, CURRENT_TIMESTAMP::text),
COALESCE(updated_at, ended_at, started_at, CURRENT_TIMESTAMP::text)
FROM agent_sessions
WHERE id IS NOT NULL
ON CONFLICT (session_id) DO NOTHING;
INSERT INTO workbench_trace_events (
id,
trace_id,
session_id,
turn_id,
message_id,
source_seq,
source_event_id,
projected_seq,
event_type,
terminal,
sealed,
event_json,
occurred_at,
updated_at
)
SELECT
source_trace_events.id,
source_trace_events.trace_id,
source_trace_events.agent_session_id,
source_trace_events.trace_id,
NULL,
source_trace_events.durable_projection_seq,
source_trace_events.id,
source_trace_events.durable_projection_seq,
'agent_trace_event',
false,
false,
COALESCE(NULLIF(source_trace_events.event_json, ''), '{}'),
source_trace_events.occurred_at,
source_trace_events.occurred_at
FROM (
SELECT
agent_trace_events.*,
(ROW_NUMBER() OVER (PARTITION BY trace_id ORDER BY occurred_at, id))::integer AS durable_projection_seq
FROM agent_trace_events
WHERE id IS NOT NULL AND trace_id IS NOT NULL
) AS source_trace_events
ON CONFLICT DO NOTHING;
INSERT INTO workbench_turns (
turn_id,
session_id,
trace_id,
message_id,
status,
projected_seq,
source_seq,
source_event_id,
terminal,
sealed,
final_response_json,
diagnostic_json,
turn_json,
created_at,
updated_at
)
SELECT
trace_id,
COALESCE(session_id, trace_id),
trace_id,
NULL,
projection_status,
last_projected_seq,
last_agentrun_seq,
trace_id || ':' || last_agentrun_seq::text,
projection_status IN ('caught_up', 'terminal'),
projection_status = 'terminal',
'null',
COALESCE(NULLIF(projection_json, ''), '{}'),
COALESCE(NULLIF(projection_json, ''), '{}'),
COALESCE(created_at, updated_at, CURRENT_TIMESTAMP::text),
COALESCE(updated_at, created_at, CURRENT_TIMESTAMP::text)
FROM workbench_projection_state
WHERE trace_id IS NOT NULL
ON CONFLICT (turn_id) DO NOTHING;
INSERT INTO workbench_projection_checkpoints (
trace_id,
session_id,
turn_id,
run_id,
command_id,
projected_seq,
source_seq,
source_event_id,
projection_status,
projection_health,
terminal,
sealed,
diagnostic_json,
checkpoint_json,
created_at,
updated_at
)
SELECT
trace_id,
session_id,
trace_id,
run_id,
command_id,
last_projected_seq,
last_agentrun_seq,
trace_id || ':' || last_agentrun_seq::text,
projection_status,
projection_health,
projection_status IN ('caught_up', 'terminal'),
projection_status = 'terminal',
COALESCE(NULLIF(projection_json, ''), '{}'),
COALESCE(NULLIF(projection_json, ''), '{}'),
COALESCE(created_at, updated_at, CURRENT_TIMESTAMP::text),
COALESCE(updated_at, created_at, CURRENT_TIMESTAMP::text)
FROM workbench_projection_state
WHERE trace_id IS NOT NULL
ON CONFLICT (trace_id) DO NOTHING;
CREATE TABLE IF NOT EXISTS evidence_records (
id TEXT PRIMARY KEY,
project_id TEXT,
operation_id TEXT,
evidence_type TEXT NOT NULL,
uri TEXT NOT NULL DEFAULT '',
metadata_json TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS hwlab_schema_migrations (
id TEXT PRIMARY KEY,
schema_version TEXT NOT NULL,
applied_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
migration_json TEXT NOT NULL DEFAULT '{}'
);
INSERT INTO hwlab_schema_migrations (id, schema_version, applied_at,
migration_json)
VALUES (
'0001_cloud_core_skeleton',
'runtime-durable-postgres-v7',
CURRENT_TIMESTAMP,
'{"path":"internal/db/migrations/0001_cloud_core_skeleton.sql","runtime":"cloud-api"}'
)
ON CONFLICT (id) DO UPDATE SET
schema_version = EXCLUDED.schema_version,
migration_json = EXCLUDED.migration_json;
- apiVersion: v1
kind: Service
metadata:
name: hwlab-v03-postgres
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-v03-postgres
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-v03-postgres
ports:
- name: postgres
port: 5432
targetPort: postgres
- apiVersion: apps/v1
kind: StatefulSet
metadata:
name: hwlab-v03-postgres
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-v03-postgres
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
spec:
serviceName: hwlab-v03-postgres
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: hwlab-v03-postgres
template:
metadata:
labels:
app.kubernetes.io/name: hwlab-v03-postgres
app.kubernetes.io/part-of: hwlab
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/migration-sha256: 880f77326c6dd41a
annotations:
hwlab.pikastech.local/migration-sha256: 880f77326c6dd41a994931567da1d0372af0b3c3f8aef1e2f69e3d5ed4343274
spec:
containers:
- name: postgres
image: 127.0.0.1:5000/hwlab/postgres:16-alpine
imagePullPolicy: IfNotPresent
env:
- name: POSTGRES_DB
value: hwlab_v03
- name: POSTGRES_USER
value: hwlab_v03
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
name: hwlab-v03-postgres
key: POSTGRES_PASSWORD
ports:
- name: postgres
containerPort: 5432
readinessProbe:
tcpSocket:
port: postgres
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
tcpSocket:
port: postgres
initialDelaySeconds: 30
periodSeconds: 20
volumeMounts:
- name: data
mountPath: /var/lib/postgresql/data
- name: init
mountPath: /docker-entrypoint-initdb.d
readOnly: true
volumes:
- name: init
configMap:
name: hwlab-v03-postgres-init
volumeClaimTemplates:
- metadata:
name: data
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 8Gi
@@ -0,0 +1,208 @@
apiVersion: v1
kind: List
items:
- apiVersion: v1
kind: Service
metadata:
name: hwlab-cloud-api
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-cloud-api
hwlab.pikastech.local/service-id: hwlab-cloud-api
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-cloud-api
ports:
- name: http
port: 6667
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
- apiVersion: v1
kind: Service
metadata:
name: hwlab-project-management
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-project-management
hwlab.pikastech.local/service-id: hwlab-project-management
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-project-management
ports:
- name: http
port: 6672
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
- apiVersion: v1
kind: Service
metadata:
name: hwlab-workbench-runtime
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-workbench-runtime
hwlab.pikastech.local/service-id: hwlab-workbench-runtime
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-workbench-runtime
ports:
- name: http
port: 6671
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
- apiVersion: v1
kind: Service
metadata:
name: hwlab-user-billing
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-user-billing
hwlab.pikastech.local/service-id: hwlab-user-billing
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-user-billing
ports:
- name: http
port: 6670
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
- apiVersion: v1
kind: Service
metadata:
name: hwlab-cloud-web
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-cloud-web
hwlab.pikastech.local/service-id: hwlab-cloud-web
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-cloud-web
ports:
- name: http
port: 8080
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
- apiVersion: v1
kind: Service
metadata:
name: hwlab-gateway
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-gateway
hwlab.pikastech.local/service-id: hwlab-gateway
hwlab.pikastech.local/activation: manual
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-gateway
ports:
- name: http
port: 7001
targetPort: http
- apiVersion: v1
kind: Service
metadata:
name: hwlab-agent-skills
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-agent-skills
hwlab.pikastech.local/service-id: hwlab-agent-skills
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-agent-skills
ports:
- name: http
port: 7430
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
- apiVersion: v1
kind: Service
metadata:
name: hwlab-edge-proxy
namespace: hwlab-v03
labels:
app.kubernetes.io/name: hwlab-edge-proxy
hwlab.pikastech.local/service-id: hwlab-edge-proxy
hwlab.pikastech.local/gitops-target: v03
hwlab.pikastech.local/source-commit: 1c448bc4b9fac145059b6ceffcb6c52e542aba13
hwlab.pikastech.local/environment: v03
hwlab.pikastech.local/profile: v03
hwlab.pikastech.local/monitoring: disabled
annotations:
hwlab.pikastech.local/rendered-by: scripts/gitops-render.mjs
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: hwlab-edge-proxy
ports:
- name: http
port: 6667
targetPort: http
- name: metrics
port: 9100
targetPort: metrics
@@ -0,0 +1,243 @@
{
"apiVersion": "v1",
"kind": "List",
"items": [
{
"apiVersion": "v1",
"kind": "ConfigMap",
"metadata": {
"name": "hwlab-workbench-redis-config",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-workbench-redis",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/cache-role": "workbench-derived-read",
"hwlab.pikastech.local/component": "workbench-runtime-cache",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-workbench-redis",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"data": {
"redis.conf": "save \"\"\nappendonly no\nmaxmemory 192mb\nmaxmemory-policy allkeys-lru\n"
}
},
{
"apiVersion": "apps/v1",
"kind": "Deployment",
"metadata": {
"name": "hwlab-workbench-redis",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-workbench-redis",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/cache-role": "workbench-derived-read",
"hwlab.pikastech.local/component": "workbench-runtime-cache",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-workbench-redis",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"spec": {
"replicas": 1,
"selector": {
"matchLabels": {
"app.kubernetes.io/name": "hwlab-workbench-redis"
}
},
"template": {
"metadata": {
"labels": {
"app.kubernetes.io/name": "hwlab-workbench-redis",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/cache-role": "workbench-derived-read",
"hwlab.pikastech.local/component": "workbench-runtime-cache",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-workbench-redis",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"spec": {
"containers": [
{
"name": "redis",
"image": "127.0.0.1:5000/hwlab/redis:8.2.3-alpine",
"imagePullPolicy": "IfNotPresent",
"args": [
"redis-server",
"/usr/local/etc/redis/redis.conf"
],
"ports": [
{
"name": "redis",
"containerPort": 6379
}
],
"readinessProbe": {
"exec": {
"command": [
"redis-cli",
"-p",
"6379",
"ping"
]
},
"initialDelaySeconds": 3,
"periodSeconds": 10,
"timeoutSeconds": 2,
"failureThreshold": 3
},
"livenessProbe": {
"exec": {
"command": [
"redis-cli",
"-p",
"6379",
"ping"
]
},
"initialDelaySeconds": 15,
"periodSeconds": 20,
"timeoutSeconds": 3,
"failureThreshold": 3
},
"resources": {
"requests": {
"cpu": "50m",
"memory": "64Mi"
},
"limits": {
"cpu": "250m",
"memory": "256Mi"
}
},
"volumeMounts": [
{
"name": "config",
"mountPath": "/usr/local/etc/redis",
"readOnly": true
}
]
}
],
"volumes": [
{
"name": "config",
"configMap": {
"name": "hwlab-workbench-redis-config"
}
}
]
}
}
}
},
{
"apiVersion": "v1",
"kind": "Service",
"metadata": {
"name": "hwlab-workbench-redis",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-workbench-redis",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/cache-role": "workbench-derived-read",
"hwlab.pikastech.local/component": "workbench-runtime-cache",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-workbench-redis",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"spec": {
"type": "ClusterIP",
"selector": {
"app.kubernetes.io/name": "hwlab-workbench-redis"
},
"ports": [
{
"name": "redis",
"port": 6379,
"targetPort": "redis",
"protocol": "TCP"
}
]
}
},
{
"apiVersion": "networking.k8s.io/v1",
"kind": "NetworkPolicy",
"metadata": {
"name": "hwlab-workbench-redis-ingress",
"namespace": "hwlab-v03",
"labels": {
"app.kubernetes.io/name": "hwlab-workbench-redis",
"app.kubernetes.io/part-of": "hwlab",
"hwlab.pikastech.local/cache-role": "workbench-derived-read",
"hwlab.pikastech.local/component": "workbench-runtime-cache",
"hwlab.pikastech.local/environment": "v03",
"hwlab.pikastech.local/gitops-target": "v03",
"hwlab.pikastech.local/profile": "v03",
"hwlab.pikastech.local/service-id": "hwlab-workbench-redis",
"hwlab.pikastech.local/source-commit": "1c448bc4b9fac145059b6ceffcb6c52e542aba13"
},
"annotations": {
"hwlab.pikastech.local/rendered-by": "scripts/gitops-render.mjs",
"argocd.argoproj.io/sync-wave": "2"
}
},
"spec": {
"podSelector": {
"matchLabels": {
"app.kubernetes.io/name": "hwlab-workbench-redis"
}
},
"policyTypes": [
"Ingress"
],
"ingress": [
{
"from": [
{
"podSelector": {
"matchLabels": {
"app.kubernetes.io/name": "hwlab-workbench-runtime"
}
}
}
],
"ports": [
{
"protocol": "TCP",
"port": 6379
}
]
}
]
}
}
]
}
File diff suppressed because it is too large Load Diff