feat(supabase): add services and statefulset for database management
feat(synapse): update ingress to use traefik ingress class and bump version feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration fix(taiga): update liveness and readiness probes to use tcpSocket for health checks fix(taiga): change PVC access mode to ReadWriteMany for media and static storage feat(traefik): add icon and ignore rules for traefik service docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments feat(ushahidi): implement dedicated Redis deployment for Ushahidi fix(vllm): update deployment strategy and readiness/liveness probes for improved stability fix(writefreely): pin writefreely image version to v0.15.1 for consistency docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
This commit is contained in:
28
ushahidi/notes.md
Normal file
28
ushahidi/notes.md
Normal file
@@ -0,0 +1,28 @@
|
||||
# Ushahidi — Notes
|
||||
|
||||
## Requires a dedicated local Redis (no password support)
|
||||
|
||||
Ushahidi provides no way to configure a Redis password (`REDIS_HOST` and `REDIS_PORT` only).
|
||||
Connecting to Wild Cloud's shared authenticated Redis fails with `ConnectionError`.
|
||||
|
||||
**Fix**: deploy a dedicated Redis sidecar or separate Deployment for Ushahidi with no auth:
|
||||
|
||||
```yaml
|
||||
- name: redis
|
||||
image: redis:7-alpine
|
||||
args: ["--save", ""] # disable persistence
|
||||
```
|
||||
|
||||
Remove `redis` from `requires` in `manifest.yaml` (Ushahidi won't use the shared instance) and
|
||||
point `REDIS_HOST` to the app-local Service name.
|
||||
|
||||
## Laravel startup probe
|
||||
|
||||
Ushahidi's API is Laravel-based. The startup process (autoload optimization, key generation,
|
||||
migrations) commonly takes 2–3 minutes. Set an extended initial delay on the liveness probe:
|
||||
|
||||
```yaml
|
||||
livenessProbe:
|
||||
initialDelaySeconds: 120
|
||||
failureThreshold: 6
|
||||
```
|
||||
@@ -10,6 +10,7 @@ labels:
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- db-init-job.yaml
|
||||
- redis.yaml
|
||||
- deployment-api.yaml
|
||||
- deployment-worker.yaml
|
||||
- deployment-client.yaml
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
version: 5.1.0-2
|
||||
requires:
|
||||
- name: mysql
|
||||
- name: redis
|
||||
defaultConfig:
|
||||
namespace: ushahidi
|
||||
externalDnsDomain: '{{ .cloud.domain }}'
|
||||
@@ -15,8 +14,8 @@ defaultConfig:
|
||||
name: ushahidi
|
||||
user: ushahidi
|
||||
redis:
|
||||
host: '{{ .apps.redis.host }}'
|
||||
port: '{{ .apps.redis.port }}'
|
||||
host: ushahidi-redis
|
||||
port: '6379'
|
||||
defaultSecrets:
|
||||
- key: appKey
|
||||
- key: dbPassword
|
||||
|
||||
51
ushahidi/versions/5/redis.yaml
Normal file
51
ushahidi/versions/5/redis.yaml
Normal file
@@ -0,0 +1,51 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: ushahidi-redis
|
||||
namespace: {{ .namespace }}
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
component: redis
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
component: redis
|
||||
spec:
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 999
|
||||
runAsGroup: 999
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: redis
|
||||
image: redis:7-alpine
|
||||
args: ["--save", ""]
|
||||
ports:
|
||||
- containerPort: 6379
|
||||
resources:
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 128Mi
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop: [ALL]
|
||||
readOnlyRootFilesystem: false
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: ushahidi-redis
|
||||
namespace: {{ .namespace }}
|
||||
spec:
|
||||
selector:
|
||||
component: redis
|
||||
ports:
|
||||
- port: 6379
|
||||
targetPort: 6379
|
||||
Reference in New Issue
Block a user