- S3BlobStore (object_store, path-style) behind the same BlobStore trait, tested against a REAL MinIO container (round trip, overwrite, NotFound on get and delete, nested keys); [storage] backend=local|s3 config with validation + server-side selection (S3 creds via env overlay) - Helm chart: server pod with the secret broker as a SIDECAR sharing a private emptyDir unix socket (no network hop carries credentials), frontend, optional local PVC vs S3, OIDC/oauth values, unbuffered-SSE ingress annotations, NetworkPolicies (frontend->server only), hardened securityContexts; ci/check-helm.sh lints AND asserts the rendered topology properties - deploy/airgapped/install.sh: offline signature+checksum verification via the bundled teamclaw-bundler BEFORE any docker load; --verify-only mode; ci/test-install.sh rehearses clean/tampered/wrong-key paths with the real binary - CI: helm gate + installer rehearsal wired in 149 Rust tests; helm lint + rendered assertions green; installer verify-path rehearsal green. Co-Authored-By: Claude Fable 5 <[email protected]>
21 lines
548 B
Smarty
21 lines
548 B
Smarty
{{- define "teamclaw.labels" -}}
|
|
app.kubernetes.io/name: teamclaw
|
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
{{- end }}
|
|
|
|
{{- define "teamclaw.serverSelector" -}}
|
|
app.kubernetes.io/name: teamclaw
|
|
app.kubernetes.io/component: server
|
|
{{- end }}
|
|
|
|
{{- define "teamclaw.brokerSelector" -}}
|
|
app.kubernetes.io/name: teamclaw
|
|
app.kubernetes.io/component: broker
|
|
{{- end }}
|
|
|
|
{{- define "teamclaw.frontendSelector" -}}
|
|
app.kubernetes.io/name: teamclaw
|
|
app.kubernetes.io/component: frontend
|
|
{{- end }}
|