feat(synapse): update ingress to use traefik ingress class and bump version feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration fix(taiga): update liveness and readiness probes to use tcpSocket for health checks fix(taiga): change PVC access mode to ReadWriteMany for media and static storage feat(traefik): add icon and ignore rules for traefik service docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments feat(ushahidi): implement dedicated Redis deployment for Ushahidi fix(vllm): update deployment strategy and readiness/liveness probes for improved stability fix(writefreely): pin writefreely image version to v0.15.1 for consistency docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
46 lines
1.5 KiB
Markdown
46 lines
1.5 KiB
Markdown
# Post-Deploy Scripts
|
|
|
|
Some apps require a management command after first deploy to create an admin account, register a node, or invite the first user. Package these as shell scripts in `scripts/` alongside the kustomize files.
|
|
|
|
## Registering scripts
|
|
|
|
Register every script in `manifest.yaml` — the web UI shows a button with a parameter form for each one:
|
|
|
|
```yaml
|
|
scripts:
|
|
- name: create-superuser
|
|
path: scripts/create-superuser.sh
|
|
description: "Create the initial admin account."
|
|
params:
|
|
- name: EMAIL
|
|
required: true
|
|
- name: PASSWORD
|
|
description: Leave blank to generate a random one
|
|
```
|
|
|
|
## Script conventions
|
|
|
|
Follow `synapse/versions/v1/scripts/create-user.sh` as the reference implementation:
|
|
|
|
- Require `KUBECONFIG`, `WILD_INSTANCE`, and `WILD_API_DATA_DIR`; exit with a clear error if missing
|
|
- Read `namespace` from `config.yaml` via `yq` — never hardcode it
|
|
- Auto-generate passwords with `openssl rand` if `PASSWORD` is not supplied
|
|
- Find the running pod by label — never hardcode a pod name
|
|
- Print credentials at the end with a "save this — it won't be shown again" warning
|
|
|
|
## Common commands
|
|
|
|
**Django non-interactive superuser**:
|
|
```bash
|
|
kubectl exec -n <ns> <pod> -- \
|
|
env DJANGO_SUPERUSER_PASSWORD="${PASSWORD}" \
|
|
python manage.py createsuperuser --email "${EMAIL}" --noinput
|
|
```
|
|
|
|
**Rails**:
|
|
```bash
|
|
kubectl exec -n <ns> <pod> -- bundle exec rake db:migrate
|
|
```
|
|
|
|
**Affected apps**: Eventyay, Synapse, Headscale.
|