simplify production database configuration
This commit is contained in:
1 parent
8cb8b5e463
commit
b26f9679ab
17 files changed
+199
-234
No files matched your search
@@ -13,7 +13,9 @@ for (const file of files) {
|
||||
const migrationJob = read("migration-job.yaml");
|
||||
assert(migrationJob.includes("name: ZHINIAN_DATA_BACKEND\n value: postgres"), "migration Job must select postgres");
|
||||
assert(migrationJob.includes("name: DATABASE_APP_ROLE"), "migration Job must provision the Web role");
|
||||
assert(migrationJob.includes("secretName: zhinian-rds-ca"), "migration Job must mount the RDS CA");
|
||||
assert(migrationJob.includes("secretName: zhinian-rds-ca"), "migration Job must mount the optional RDS CA used by DATABASE_URL");
|
||||
assert(!migrationJob.includes("DATABASE_SSL_MODE"), "migration Job must keep database TLS inside DATABASE_URL");
|
||||
assert(!migrationJob.includes("DATABASE_CA_CERT_PATH"), "migration Job must keep database TLS inside DATABASE_URL");
|
||||
|
||||
const web = read("web.yaml");
|
||||
assert(/^\s*replicas: 1\s*$/m.test(web), "Web must default to one replica until object storage is shared");
|
||||
@@ -27,10 +29,15 @@ assert(goApi.includes("path: /api/ready"), "Go API must use database-aware readi
|
||||
assert(goApi.includes("runAsNonRoot: true"), "Go API must run as a non-root user");
|
||||
assert(goApi.includes("name: zhinian-go-runtime"), "Go API must consume the Go runtime ConfigMap");
|
||||
assert(goApi.includes("name: zhinian-go-bootstrap"), "Go API must receive bootstrap administrator credentials");
|
||||
assert(goApi.includes("secretName: zhinian-rds-ca"), "Go API must mount the RDS CA");
|
||||
assert(goApi.includes("secretName: zhinian-rds-ca"), "Go API must mount the optional RDS CA used by DATABASE_URL");
|
||||
assert(!goApi.includes("DATABASE_SSL_MODE"), "Go API must keep database TLS inside DATABASE_URL");
|
||||
assert(!goApi.includes("DATABASE_CA_CERT_PATH"), "Go API must keep database TLS inside DATABASE_URL");
|
||||
|
||||
const configMap = read("configmap.yaml");
|
||||
assert(configMap.includes("ZHINIAN_GO_EMBEDDED_WORKER: \"true\""), "Go runtime ConfigMap must embed the WorkerLoop");
|
||||
assert(configMap.includes("GO_BACKEND_HOST: 0.0.0.0"), "Go runtime ConfigMap must listen on the Pod interface");
|
||||
assert(!configMap.includes("DATABASE_SSL_MODE"), "ConfigMaps must not carry database TLS settings");
|
||||
assert(!configMap.includes("DATABASE_CA_CERT_PATH"), "ConfigMaps must not carry database CA paths");
|
||||
|
||||
const ingress = read("ingress.yaml");
|
||||
assert(ingress.includes("path: /api/internal/worker"), "Ingress must intercept the internal worker prefix");
|
||||
|
||||
Reference in new issue
Block a user