Terraform (validated with the real terraform CLI - was never actually
run against this cluster, no state file existed):
- Delete main.tf: it declared a duplicate kubernetes_namespace.core
(also in namespaces.tf) and a duplicate provider "kubernetes" block
(also in providers.tf), both hard errors that would fail
`terraform plan` immediately.
- Fix workloads.tf references to 6 files deleted in the manifest
cleanup (jupiter-sts/svc, atlantis-sts/svc, fiesta-sts/svc) - now
points at the canonical nearle-jupiter/atlantis/fiesta.yaml.
- Fix every kubernetes_manifest resource: they fed multi-document
YAML (multiple '---'-separated docs per file) straight into
yamldecode(), which only parses a single document. Rewrote using a
split-on-'---' + for_each pattern, confirmed safe first by checking
separator counts exactly match document counts for every affected
file (no embedded '---' inside any script/config content).
- Add the doormile namespace; rename kubernetes_namespace to
kubernetes_namespace_v1 (fixes a deprecation warning).
- `terraform validate` now passes clean.
Shell scripts:
- deploy-nearle-stack.sh only applied 4 of the ~13 files in
manifests/nearle/ - missing the ConfigMap/Secrets fiesta/jupiter/
titan/ariane need via envFrom, the fiesta gateway script ConfigMap,
atlantis entirely, and the Gateway/ReferenceGrant/jupiter-cors-proxy
resources. Now applies every file (verified by diffing the
directory listing against the script).
- Added deploy-doormile.sh and deploy-ingress.sh - nothing previously
applied ingress-unified.yaml or traefik-middlewares.yaml at all.
- Rewrote deploy.sh as an orchestrator calling all of the above in
order (previously referenced a manifests/namespace.yaml layout that
hasn't existed since before this repo's initial commit).
- Rewrote check-k8s-status.sh to check the real namespaces
(core/nearle/alaska/doormile/kubernetes-dashboard) instead of a
'nats-backend' namespace that never existed in this repo.
- Fixed a `cd` bug in setup-jetstream.sh that made it change into
shfiles/ and then look for scripts/setup_jetstream.py there (a
child directory that doesn't exist) - it could never have found its
own target file. Now pulls NATS credentials from the live
nats-credentials Secret instead of a third hardcoded copy.
Python scripts:
- sync_manifests.py had hardcoded Windows paths (e:\nats\kubernetes\...)
- replaced with paths relative to the script's own location so it
actually runs here (or anywhere). Verified by running it.
- setup_jetstream.py created durable consumers under different names
than worker.py computes at runtime ({NATS_CONSUMER}_{subject}), so
its max_deliver/ack_wait settings never actually reached the
consumers workers bind to. Naming now derived with the same logic
worker.py uses - verified all 10 derived names match workers.yaml
exactly.
- purge-old-messages.py had hardcoded NATS credentials with no env
var override at all - fixed to match the pattern used everywhere
else.
94 lines
3.5 KiB
HCL
94 lines
3.5 KiB
HCL
# Manage the Nearle Stack (Jupiter, Atlantis, Fiesta) plus the shared core
|
|
# workers, Ingress and Traefik middlewares.
|
|
#
|
|
# NOTE: each of these manifest files contains MULTIPLE '---'-separated YAML
|
|
# documents (e.g. a StatefulSet + Service + HTTPRoute in one file). Terraform's
|
|
# built-in yamldecode() only parses a single document, so each file is split
|
|
# on the '---' separator first and turned into a for_each map, one
|
|
# kubernetes_manifest per document. This has been verified safe for these
|
|
# specific files (the number of '---' lines matches document-count minus one
|
|
# in each case - no embedded '---' inside any script/config content).
|
|
|
|
locals {
|
|
# Splits a multi-document YAML file into a map keyed by
|
|
# "<kind>/<namespace>/<name>" (namespace omitted for cluster-scoped
|
|
# resources), suitable for a kubernetes_manifest for_each.
|
|
jupiter_docs = {
|
|
for doc in [
|
|
for chunk in split("\n---\n", file("${path.module}/../manifests/nearle/nearle-jupiter.yaml")) :
|
|
yamldecode(chunk) if trimspace(chunk) != ""
|
|
] : "${doc.kind}/${lookup(doc.metadata, "namespace", "")}/${doc.metadata.name}" => doc
|
|
}
|
|
|
|
atlantis_docs = {
|
|
for doc in [
|
|
for chunk in split("\n---\n", file("${path.module}/../manifests/nearle/nearle-atlantis.yaml")) :
|
|
yamldecode(chunk) if trimspace(chunk) != ""
|
|
] : "${doc.kind}/${lookup(doc.metadata, "namespace", "")}/${doc.metadata.name}" => doc
|
|
}
|
|
|
|
fiesta_docs = {
|
|
for doc in [
|
|
for chunk in split("\n---\n", file("${path.module}/../manifests/nearle/nearle-fiesta.yaml")) :
|
|
yamldecode(chunk) if trimspace(chunk) != ""
|
|
] : "${doc.kind}/${lookup(doc.metadata, "namespace", "")}/${doc.metadata.name}" => doc
|
|
}
|
|
|
|
core_workers_docs = {
|
|
for doc in [
|
|
for chunk in split("\n---\n", file("${path.module}/../manifests/core/workers.yaml")) :
|
|
yamldecode(chunk) if trimspace(chunk) != ""
|
|
] : "${doc.kind}/${lookup(doc.metadata, "namespace", "")}/${doc.metadata.name}" => doc
|
|
}
|
|
|
|
core_ingress_docs = {
|
|
for doc in [
|
|
for chunk in split("\n---\n", file("${path.module}/../manifests/core/ingress-unified.yaml")) :
|
|
yamldecode(chunk) if trimspace(chunk) != ""
|
|
] : "${doc.kind}/${lookup(doc.metadata, "namespace", "")}/${doc.metadata.name}" => doc
|
|
}
|
|
|
|
traefik_middlewares_docs = {
|
|
for doc in [
|
|
for chunk in split("\n---\n", file("${path.module}/../manifests/core/traefik-middlewares.yaml")) :
|
|
yamldecode(chunk) if trimspace(chunk) != ""
|
|
] : "${doc.kind}/${lookup(doc.metadata, "namespace", "")}/${doc.metadata.name}" => doc
|
|
}
|
|
}
|
|
|
|
# 1. Jupiter (StatefulSet + Service)
|
|
resource "kubernetes_manifest" "nearle_jupiter" {
|
|
for_each = local.jupiter_docs
|
|
manifest = each.value
|
|
}
|
|
|
|
# 2. Atlantis (StatefulSet + Service + HTTPRoute)
|
|
resource "kubernetes_manifest" "nearle_atlantis" {
|
|
for_each = local.atlantis_docs
|
|
manifest = each.value
|
|
}
|
|
|
|
# 3. Fiesta (StatefulSet + Service + HTTPRoute)
|
|
resource "kubernetes_manifest" "nearle_fiesta" {
|
|
for_each = local.fiesta_docs
|
|
manifest = each.value
|
|
}
|
|
|
|
# 4. Workers (CPU-heavy, isolated node pool - 5 StatefulSets)
|
|
resource "kubernetes_manifest" "core_workers" {
|
|
for_each = local.core_workers_docs
|
|
manifest = each.value
|
|
}
|
|
|
|
# 5. Ingress (queue.workolik.com, jupiter/fiesta/atlantis.nearle.app)
|
|
resource "kubernetes_manifest" "core_ingress" {
|
|
for_each = local.core_ingress_docs
|
|
manifest = each.value
|
|
}
|
|
|
|
# 6. Traefik CORS middlewares (alaska + nearle)
|
|
resource "kubernetes_manifest" "traefik_middlewares" {
|
|
for_each = local.traefik_middlewares_docs
|
|
manifest = each.value
|
|
}
|