Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion deploy/kubernetes/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ This directory deploys the control plane — Core and the Web console — to a K

| Object | From | Notes |
| --- | --- | --- |
| Deployment and Service `oac-core` | `prod/core.yaml.tpl` | Core on port 8091. One replica: Core takes a PostgreSQL lease that gives one execution service per database, so a second replica exits at startup. An init container prepares the adapter state volume, then `oac-core-migrate` applies the schema |
| Deployment and Service `oac-core` | `prod/core.yaml.tpl` | Core on port 8091. One replica: Core takes a PostgreSQL lease that gives one execution service per database, so a second replica exits at startup. An init container prepares the adapter state volume and secret files; Core applies the schema during startup before listening |
| ConfigMap `oac-core-env` | `prod/core-env.yaml.tpl` | Core's process environment; no secret |
| PersistentVolumeClaim `oac-core-state` | `prod/core-state.yaml.tpl` | `OAC_PROVIDER_STATE_ROOT`, required for E2B; see [the state volume](#the-state-volume). Back it up with the database and the credential key |
| Deployment and Service `oac-web` | `prod/web.yaml.tpl` | The console on port 8080. One replica: Web holds sign-in sessions in process memory, so a cookie is valid only on the Pod that issued it |
Expand Down
30 changes: 0 additions & 30 deletions deploy/kubernetes/prod/core.yaml.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -93,36 +93,6 @@ spec:
limits:
cpu: 200m
memory: 128Mi
# Core never migrates its own schema. The schema must match the image
# before Core opens the database.
- name: migrate
image: "${OAC_CORE_IMAGE}"
imagePullPolicy: IfNotPresent
command: ["/usr/local/bin/oac-core-migrate"]
envFrom:
- configMapRef:
name: oac-core-env
securityContext:
runAsUser: 65532
runAsGroup: 65532
runAsNonRoot: true
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
volumeMounts:
- name: secrets
mountPath: /run/oac
readOnly: true
- name: tmp
mountPath: /tmp
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: "1"
memory: 512Mi
containers:
- name: core
image: "${OAC_CORE_IMAGE}"
Expand Down
Loading