feat(supabase): add services and statefulset for database management
feat(synapse): update ingress to use traefik ingress class and bump version feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration fix(taiga): update liveness and readiness probes to use tcpSocket for health checks fix(taiga): change PVC access mode to ReadWriteMany for media and static storage feat(traefik): add icon and ignore rules for traefik service docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments feat(ushahidi): implement dedicated Redis deployment for Ushahidi fix(vllm): update deployment strategy and readiness/liveness probes for improved stability fix(writefreely): pin writefreely image version to v0.15.1 for consistency docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
This commit is contained in:
45
docs/scripts.md
Normal file
45
docs/scripts.md
Normal file
@@ -0,0 +1,45 @@
|
||||
# Post-Deploy Scripts
|
||||
|
||||
Some apps require a management command after first deploy to create an admin account, register a node, or invite the first user. Package these as shell scripts in `scripts/` alongside the kustomize files.
|
||||
|
||||
## Registering scripts
|
||||
|
||||
Register every script in `manifest.yaml` — the web UI shows a button with a parameter form for each one:
|
||||
|
||||
```yaml
|
||||
scripts:
|
||||
- name: create-superuser
|
||||
path: scripts/create-superuser.sh
|
||||
description: "Create the initial admin account."
|
||||
params:
|
||||
- name: EMAIL
|
||||
required: true
|
||||
- name: PASSWORD
|
||||
description: Leave blank to generate a random one
|
||||
```
|
||||
|
||||
## Script conventions
|
||||
|
||||
Follow `synapse/versions/v1/scripts/create-user.sh` as the reference implementation:
|
||||
|
||||
- Require `KUBECONFIG`, `WILD_INSTANCE`, and `WILD_API_DATA_DIR`; exit with a clear error if missing
|
||||
- Read `namespace` from `config.yaml` via `yq` — never hardcode it
|
||||
- Auto-generate passwords with `openssl rand` if `PASSWORD` is not supplied
|
||||
- Find the running pod by label — never hardcode a pod name
|
||||
- Print credentials at the end with a "save this — it won't be shown again" warning
|
||||
|
||||
## Common commands
|
||||
|
||||
**Django non-interactive superuser**:
|
||||
```bash
|
||||
kubectl exec -n <ns> <pod> -- \
|
||||
env DJANGO_SUPERUSER_PASSWORD="${PASSWORD}" \
|
||||
python manage.py createsuperuser --email "${EMAIL}" --noinput
|
||||
```
|
||||
|
||||
**Rails**:
|
||||
```bash
|
||||
kubectl exec -n <ns> <pod> -- bundle exec rake db:migrate
|
||||
```
|
||||
|
||||
**Affected apps**: Eventyay, Synapse, Headscale.
|
||||
Reference in New Issue
Block a user