- S3BlobStore (object_store, path-style) behind the same BlobStore trait, tested against a REAL MinIO container (round trip, overwrite, NotFound on get and delete, nested keys); [storage] backend=local|s3 config with validation + server-side selection (S3 creds via env overlay) - Helm chart: server pod with the secret broker as a SIDECAR sharing a private emptyDir unix socket (no network hop carries credentials), frontend, optional local PVC vs S3, OIDC/oauth values, unbuffered-SSE ingress annotations, NetworkPolicies (frontend->server only), hardened securityContexts; ci/check-helm.sh lints AND asserts the rendered topology properties - deploy/airgapped/install.sh: offline signature+checksum verification via the bundled teamclaw-bundler BEFORE any docker load; --verify-only mode; ci/test-install.sh rehearses clean/tampered/wrong-key paths with the real binary - CI: helm gate + installer rehearsal wired in 149 Rust tests; helm lint + rendered assertions green; installer verify-path rehearsal green. Co-Authored-By: Claude Fable 5 <[email protected]>
38 lines
1.2 KiB
YAML
38 lines
1.2 KiB
YAML
{{- if .Values.ingress.enabled }}
|
|
# SSE streaming (POST /api/gateway) requires unbuffered proxying with long
|
|
# read timeouts; without these annotations approvals and live transcripts
|
|
# stall behind nginx buffering.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: Ingress
|
|
metadata:
|
|
name: teamclaw
|
|
labels: {{- include "teamclaw.labels" . | nindent 4 }}
|
|
annotations:
|
|
nginx.ingress.kubernetes.io/proxy-buffering: "off"
|
|
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
|
|
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
|
|
spec:
|
|
ingressClassName: {{ .Values.ingress.className }}
|
|
{{- if .Values.ingress.tlsSecretName }}
|
|
tls:
|
|
- hosts: [{{ .Values.ingress.host | quote }}]
|
|
secretName: {{ .Values.ingress.tlsSecretName }}
|
|
{{- end }}
|
|
rules:
|
|
- host: {{ .Values.ingress.host | quote }}
|
|
http:
|
|
paths:
|
|
- path: /api
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: teamclaw-server
|
|
port: { name: http }
|
|
- path: /
|
|
pathType: Prefix
|
|
backend:
|
|
service:
|
|
name: teamclaw-frontend
|
|
port: { name: http }
|
|
{{- end }}
|