Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions argo_apps/platform/charts/00_cilium/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,7 @@ cilium:
labelSelector:
matchLabels:
k8s-app: hubble-relay
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
ui:
enabled: true
Expand All @@ -100,6 +101,7 @@ cilium:
labelSelector:
matchLabels:
k8s-app: hubble-ui
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
tls:
auto:
Expand Down
7 changes: 6 additions & 1 deletion argo_apps/platform/charts/01_argocd/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,16 @@ argo-cd:
logging:
level: warn
# maxSkew 1 + DoNotSchedule over 3 nodes puts the 2-replica components on distinct nodes. The chart fills
# in each component's labelSelector; singletons satisfy it trivially.
# in each component's labelSelector.
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: DoNotSchedule
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
# The spread constraint above already separates replicas. The chart's soft anti-affinity preset cannot take
# matchLabelKeys, so during a rollout it would push every singleton off its node.
affinity:
podAntiAffinity: none
dex:
enabled: false
notifications:
Expand Down
2 changes: 2 additions & 0 deletions argo_apps/platform/charts/01_envoy_gateway/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ envoyProxy:
app.kubernetes.io/name: envoy
app.kubernetes.io/component: proxy
app.kubernetes.io/managed-by: envoy-gateway
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname

# Envoy's default cluster stats already carry envoy_cluster_name="httproute/<ns>/<route>/rule/N", so the
Expand Down Expand Up @@ -59,6 +60,7 @@ gateway-helm:
labelSelector:
matchLabels:
control-plane: envoy-gateway
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
# Injects topology.kubernetes.io/zone for zone-aware routing. Bare Pi nodes have no zone label and we use no
# zoneAware traffic policies, so it is a webhook round-trip plus cert plumbing for nothing.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ victoria-metrics-operator:
vm: true

# Soft + hostname: bare Pi nodes have no zone label, and soft means raising replicaCount never wedges a pod
# Pending on 3 nodes. No-op at the default single replica.
# Pending on 3 nodes.
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
Expand All @@ -47,4 +47,5 @@ victoria-metrics-operator:
labelSelector:
matchLabels:
app.kubernetes.io/name: victoria-metrics-operator
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
5 changes: 4 additions & 1 deletion argo_apps/platform/charts/02_cert_manager/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ cert-manager:
requests: { cpu: 10m, memory: 49Mi }
limits: { memory: 95Mi }
# Soft + hostname on all three: bare Pi nodes carry no zone label, and soft means raising replicaCount
# never wedges a pod Pending on a 3-node cluster. No-op at the default single replica.
# never wedges a pod Pending on a 3-node cluster.
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
Expand All @@ -31,6 +31,7 @@ cert-manager:
matchLabels:
app.kubernetes.io/name: cert-manager
app.kubernetes.io/component: controller
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
webhook:
resources:
Expand All @@ -45,6 +46,7 @@ cert-manager:
matchLabels:
app.kubernetes.io/name: webhook
app.kubernetes.io/component: webhook
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
cainjector:
resources:
Expand All @@ -59,6 +61,7 @@ cert-manager:
matchLabels:
app.kubernetes.io/name: cainjector
app.kubernetes.io/component: cainjector
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname

# HTTP-01 through Gateway API. Not a feature gate, it only exists in this controller config file.
Expand Down
1 change: 1 addition & 0 deletions argo_apps/platform/charts/02_cnpg_operator/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -44,4 +44,5 @@ cloudnative-pg:
labelSelector:
matchLabels:
app.kubernetes.io/name: cloudnative-pg
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
11 changes: 11 additions & 0 deletions argo_apps/platform/charts/02_longhorn/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -75,3 +75,14 @@ longhorn:
limits: {memory: 472Mi} # it bursts well past the request, so a limit close to it just OOMKills
longhornUI:
replicas: 1 # a read-mostly dashboard; the chart's default 2 is wasted footprint here
# The chart's default rule, plus matchLabelKeys.
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 1
podAffinityTerm:
labelSelector:
matchExpressions:
- {key: app, operator: In, values: [longhorn-ui]}
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
3 changes: 2 additions & 1 deletion argo_apps/platform/charts/02_metrics_server/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ metrics-server:
memory: 200Mi

# Soft + hostname: bare Pi nodes have no zone label, and soft means raising replicas never wedges a pod
# Pending on 3 nodes. No-op at the single replica above.
# Pending on 3 nodes.
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
Expand All @@ -27,6 +27,7 @@ metrics-server:
labelSelector:
matchLabels:
app.kubernetes.io/name: metrics-server
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname

metrics:
Expand Down
5 changes: 3 additions & 2 deletions argo_apps/platform/charts/03_redis_operator/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -32,15 +32,16 @@ redis-operator:
memory: 92Mi

# Soft + hostname: bare Pi nodes have no zone label, and soft means raising replicas never wedges a pod
# Pending on 3 nodes. No-op at the chart's default single replica.
# Pending on 3 nodes.
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchLabels:
app.kubernetes.io/name: redis-operator
name: redis-operator # the chart labels its pod only with `name`
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname

# No StorageClasses here. Every redis-instance PVC uses longhorn-r2-ephemeral, owned by 02_longhorn.
1 change: 1 addition & 0 deletions argo_apps/platform/charts/05_grafana/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -128,6 +128,7 @@ grafana:
labelSelector:
matchLabels:
app.kubernetes.io/name: grafana
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname

# Restarts grafana after a sync that changed files/alerts/, which is what removes a rule that was deleted
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -260,6 +260,7 @@ victoria-metrics-k8s-stack:
labelSelector:
matchLabels:
app.kubernetes.io/name: kube-state-metrics
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname

kubelet:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ spec:
labelSelector:
matchLabels:
app: {{ .Values.app.name }}
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
# PodSecurity `restricted` baseline, the same block on every first-party pod here. 65532 matches the
# distroless nonroot uid the sample-app image declares.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ spec:
labelSelector:
matchLabels:
app: {{ .Values.app.name }}
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
# PodSecurity `restricted` baseline, the same block on every first-party pod here. 65532 matches the
# distroless nonroot uid the sample-app image declares.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ spec:
labelSelector:
matchLabels:
app: {{ .Values.app.name }}
matchLabelKeys: [pod-template-hash] # compare within one revision, so a rollout's old pod never repels the new one
topologyKey: kubernetes.io/hostname
# PodSecurity `restricted` baseline, the same block on every first-party pod here. 65532 matches the
# distroless nonroot uid the sample-app image declares.
Expand Down