Files
wild-directory/docs/scripts.md
Paul Payne 4d983819c9 feat(supabase): add services and statefulset for database management
feat(synapse): update ingress to use traefik ingress class and bump version

feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress

feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration

fix(taiga): update liveness and readiness probes to use tcpSocket for health checks

fix(taiga): change PVC access mode to ReadWriteMany for media and static storage

feat(traefik): add icon and ignore rules for traefik service

docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments

feat(ushahidi): implement dedicated Redis deployment for Ushahidi

fix(vllm): update deployment strategy and readiness/liveness probes for improved stability

fix(writefreely): pin writefreely image version to v0.15.1 for consistency

docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
2026-07-02 21:34:27 +00:00

1.5 KiB

Post-Deploy Scripts

Some apps require a management command after first deploy to create an admin account, register a node, or invite the first user. Package these as shell scripts in scripts/ alongside the kustomize files.

Registering scripts

Register every script in manifest.yaml — the web UI shows a button with a parameter form for each one:

scripts:
  - name: create-superuser
    path: scripts/create-superuser.sh
    description: "Create the initial admin account."
    params:
      - name: EMAIL
        required: true
      - name: PASSWORD
        description: Leave blank to generate a random one

Script conventions

Follow synapse/versions/v1/scripts/create-user.sh as the reference implementation:

  • Require KUBECONFIG, WILD_INSTANCE, and WILD_API_DATA_DIR; exit with a clear error if missing
  • Read namespace from config.yaml via yq — never hardcode it
  • Auto-generate passwords with openssl rand if PASSWORD is not supplied
  • Find the running pod by label — never hardcode a pod name
  • Print credentials at the end with a "save this — it won't be shown again" warning

Common commands

Django non-interactive superuser:

kubectl exec -n <ns> <pod> -- \
    env DJANGO_SUPERUSER_PASSWORD="${PASSWORD}" \
    python manage.py createsuperuser --email "${EMAIL}" --noinput

Rails:

kubectl exec -n <ns> <pod> -- bundle exec rake db:migrate

Affected apps: Eventyay, Synapse, Headscale.