docs(deploy): add Kubernetes operations helpers
This commit is contained in:
@@ -0,0 +1,72 @@
|
|||||||
|
# Updating `.env` in Kubernetes
|
||||||
|
|
||||||
|
Buzz Sheet uses the `buzz-sheet-env` Secret in the `buzz-sheet` namespace. The
|
||||||
|
local `.env` file is ignored by Git and must never be committed.
|
||||||
|
|
||||||
|
This repository uses hand-authored Kustomize manifests rather than a
|
||||||
|
Kuber-managed Compose file, so synchronize `.env` with `kubectl`.
|
||||||
|
|
||||||
|
## Push an updated `.env`
|
||||||
|
|
||||||
|
From the repository root, confirm that `kubectl` is connected to the intended
|
||||||
|
cluster:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd /home/gunshiz/buzz-sheet
|
||||||
|
kubectl config current-context
|
||||||
|
kubectl get namespace buzz-sheet
|
||||||
|
```
|
||||||
|
|
||||||
|
Create or update the Secret without printing its values:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl create secret generic buzz-sheet-env \
|
||||||
|
--namespace buzz-sheet \
|
||||||
|
--from-env-file=.env \
|
||||||
|
--dry-run=client \
|
||||||
|
--output=yaml | kubectl apply --filename=-
|
||||||
|
```
|
||||||
|
|
||||||
|
Running pods do not reload Secret values automatically. Restart both the web
|
||||||
|
application and the outbox worker, then wait for each rollout:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
kubectl rollout restart deployment/buzz-sheet \
|
||||||
|
--namespace buzz-sheet
|
||||||
|
|
||||||
|
kubectl rollout restart deployment/buzz-sheet-worker \
|
||||||
|
--namespace buzz-sheet
|
||||||
|
|
||||||
|
kubectl rollout status deployment/buzz-sheet \
|
||||||
|
--namespace buzz-sheet \
|
||||||
|
--timeout=10m
|
||||||
|
|
||||||
|
kubectl rollout status deployment/buzz-sheet-worker \
|
||||||
|
--namespace buzz-sheet \
|
||||||
|
--timeout=10m
|
||||||
|
```
|
||||||
|
|
||||||
|
Verify PostgreSQL and Redis readiness, then inspect the application logs:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsS 'https://sheet.sudloh.com/api/health?ready=1'
|
||||||
|
bun logs
|
||||||
|
```
|
||||||
|
|
||||||
|
The health response should report `"status":"ready"`, with both `database`
|
||||||
|
and `redis` set to `"ok"`.
|
||||||
|
|
||||||
|
## Important exceptions
|
||||||
|
|
||||||
|
- Updating the Secret does not apply database migrations or seed data. If
|
||||||
|
`DATABASE_URL` now points to a new database, migrate and seed that database
|
||||||
|
before restarting the application.
|
||||||
|
- Better Auth errors about missing database fields require a schema migration.
|
||||||
|
Pushing `.env` again will not fix them.
|
||||||
|
- `NEXT_DEPLOYMENT_ID` is controlled by `buzz-sheet-config` and the immutable
|
||||||
|
image revision. Do not change it for an environment-only update.
|
||||||
|
- `NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` is embedded during `next build`. Rotating
|
||||||
|
it requires building and deploying a new image; restarting the existing image
|
||||||
|
is not sufficient.
|
||||||
|
- If `BETTER_AUTH_URL` or the public hostname changes, update the Kubernetes
|
||||||
|
ingress, Cloudflare/DNS, and the Google OAuth callback URL as well.
|
||||||
@@ -11,6 +11,7 @@
|
|||||||
"test": "vitest run",
|
"test": "vitest run",
|
||||||
"test:watch": "vitest",
|
"test:watch": "vitest",
|
||||||
"test:coverage": "vitest run --coverage",
|
"test:coverage": "vitest run --coverage",
|
||||||
|
"logs": "kubectl logs --namespace buzz-sheet --selector 'app.kubernetes.io/name=buzz-sheet,app.kubernetes.io/component in (web,worker)' --all-containers=true --prefix=true --tail=100 --follow --max-log-requests=10",
|
||||||
"db:generate": "drizzle-kit generate",
|
"db:generate": "drizzle-kit generate",
|
||||||
"db:migrate": "bun scripts/migrate.ts",
|
"db:migrate": "bun scripts/migrate.ts",
|
||||||
"db:studio": "drizzle-kit studio",
|
"db:studio": "drizzle-kit studio",
|
||||||
|
|||||||
Reference in New Issue
Block a user