Components¶
Reusable kustomize components
live in
kubernetes/components/.
An app's Flux Kustomization opts in with spec.components, and the component
is parameterized through postBuild.substitute:
spec:
components:
- ../../../../components/kopiur/backup
postBuild:
substitute:
APP: *app
KOPIUR_CAPACITY: 10Gi
alerts¶
Included at the namespace level. It adds Flux notification Providers and
Alerts that send reconciliation failures to Alertmanager and post commit
statuses to GitHub.
kopiur/secret¶
Included at the namespace level wherever an app uses kopiur/backup. It
provides the Kopia repository credentials through an ExternalSecret.
kopiur/backup¶
PVC creation, scheduled backup and declarative restore for an app's data volume. See Backups for the full lifecycle.
| Variable | Default | Notes |
|---|---|---|
APP |
(required) | Name of the PVC, policy, schedule and restore |
KOPIUR_CLAIM |
${APP} |
Override the PVC name |
KOPIUR_CAPACITY |
5Gi |
PVC size, also used for the mover cache |
KOPIUR_ACCESSMODES |
ReadWriteOnce |
|
KOPIUR_STORAGECLASS |
ceph-block |
|
KOPIUR_SNAPSHOTCLASS |
csi-ceph-blockpool |
|
KOPIUR_CACHE_STORAGECLASS |
openebs-hostpath |
|
KOPIUR_MOVER_UID / KOPIUR_MOVER_GID |
4000 |
Must match the file ownership in the volume |
postgres¶
A CloudNative-PG cluster per app, with Barman backups to Garage S3 and local dumps to NFS. See PostgreSQL.
dragonfly¶
A Dragonfly (Redis-compatible) instance per app,
with a NetworkPolicy and PodMonitor. authentication/ is an optional
sub-component that enables password auth from ${DRAGONFLY_PASSWORD_SECRET}.
gpu¶
A ResourceClaimTemplate named ${APP}-gpu that requests the node's Intel
iGPU through Dynamic Resource Allocation (deviceClassName: gpu.intel.com),
served by the intel-gpu-resource-driver. Reference it from the app's pod
resourceClaims for hardware transcoding.
zeroscaler/nfs¶
A HorizontalPodAutoscaler (min 0, max 1) driven by the external metric
probe_success{job="nfs_probe"} from blackbox-exporter, through
prometheus-adapter. When the NAS's NFS service stops answering, the app scales
to zero instead of hanging on a stale mount. It comes back when the probe
recovers.
| Variable | Default |
|---|---|
ZEROSCALER_NAME |
${APP} |
CONTROLLER |
Deployment |
ZEROSCALER_METRIC_NAME |
probe_success |