Adding an App¶
The canonical, step-by-step version lives in the
add-app
skill, which coding agents also follow. This page is the short version.
Good reference apps¶
| App | Shows |
|---|---|
network/echo-server |
Minimal stateless app with a route |
security/authentik |
Secrets, and a config file via configMapGenerator |
default/paperless |
Custom probes, Dragonfly dependency, Kopiur-backed persistence |
Steps¶
- Decide the basics: namespace, image and tag, port, internal
(
envoy-internal) or public (envoy-external), whether it has state, which secrets it needs, and what it depends on. - Create the directory
kubernetes/apps/<namespace>/<app>/withks.yamlandapp/{kustomization,ocirepository,helmrelease}.yaml. Copy the closest reference app rather than starting from nothing. - State? Add the
kopiur/backupcomponent and mount the${APP}PVC. SetKOPIUR_MOVER_UID/GIDto the app's UID/GID if it isn't4000. - Database? Add the
postgrescomponent and follow New Database. - Secrets? Add an
externalsecret.yamlthat reads from theonepasswordClusterSecretStore. Use the exact 1Password item and field names. - Enable it by adding
./<app>/ks.yamlto the namespacekustomization.yaml. -
Validate:
-
Open a PR. konflate posts the rendered diff. Merging deploys the app.
Common mistakes¶
- Adding
timeoutorcommonMetadatatoks.yaml.cluster-appsinjectstimeout, and the chart already sets the labelscommonMetadatawould add. - Adding
wait: trueby reflex. Leave it unset, unless another Kustomization depends on this app and it has no health checks. Thenwait: trueis what gives the dependent a readiness gate. readOnlyRootFilesystem: truewithout a writabletmpfsfor/tmp.- Forgetting the
kopiur/secretcomponent at the namespace level when the app's namespace has no other backed-up apps.