# Push `.env` to Kubernetes Buzz Sheet reads private configuration from the `buzz-sheet-env` Kubernetes Secret in the `buzz-sheet` namespace. Use the local `.env` file as the source. Never commit `.env` or paste its values into a Kubernetes manifest. This repository uses the manifests under `k8s/`, not a Kuber `compose.yml`, so environment-only updates are applied with `kubectl`. ## 1. Check the target cluster Run these commands from the repository root: ```bash kubectl config current-context kubectl get namespace buzz-sheet ``` Stop if the context is not the cluster you intend to update. Confirm that `.env` exists, then inspect only its variable names: ```bash test -f .env awk -F= '/^[A-Za-z_][A-Za-z0-9_]*=/{print $1}' .env ``` ## 2. Create or update the Secret The following command builds the Secret locally and sends it directly to the cluster. It does not create a plaintext YAML file: ```bash kubectl create secret generic buzz-sheet-env \ --namespace buzz-sheet \ --from-env-file=.env \ --dry-run=client \ --output=yaml \ | kubectl apply --filename=- ``` Verify that the Secret exists without displaying its values: ```bash kubectl get secret buzz-sheet-env \ --namespace buzz-sheet \ --output='go-template={{range $key, $value := .data}}{{$key}}{{"\n"}}{{end}}' ``` Add `DEPLOYMENT_WEBHOOK_SECRET` to the Gitea Actions repository secrets with the same value stored in `.env`. CI uses it to announce deployment lifecycle updates to the running site. ## 3. Restart the application Environment variables sourced from a Secret are read when a pod starts. Restart all Buzz Sheet workloads after updating the Secret: ```bash kubectl rollout restart deployment/buzz-sheet \ --namespace buzz-sheet kubectl rollout restart deployment/buzz-sheet-worker \ --namespace buzz-sheet kubectl rollout restart deployment/buzz-sheet-discord-worker \ --namespace buzz-sheet ``` Wait for every rollout to finish: ```bash kubectl rollout status deployment/buzz-sheet \ --namespace buzz-sheet \ --timeout=10m kubectl rollout status deployment/buzz-sheet-worker \ --namespace buzz-sheet \ --timeout=10m kubectl rollout status deployment/buzz-sheet-discord-worker \ --namespace buzz-sheet \ --timeout=10m ``` ## 4. Verify the deployment ```bash curl -fsS 'https://guide.sudloh.com/api/health?ready=1' bun logs ``` The health response should show `"status":"ready"` with both `database` and `redis` set to `"ok"`. ## Troubleshooting - `namespace "buzz-sheet" not found`: apply the base manifests first with `kubectl apply --kustomize k8s/base`. - Pods fail after the restart: inspect them with `kubectl describe pod --namespace buzz-sheet ` and `bun logs`. - A new `DATABASE_URL` points to an empty database: run the database migrations before serving traffic. Updating the Secret does not migrate the database. - `NEXT_DEPLOYMENT_ID` comes from `buzz-sheet-config`, not `.env`. - Rotating `NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` requires a new application build and deployment because Next.js uses it during the build. - `S3_ENDPOINT` must be the private S3-compatible API endpoint. `S3_PUBLIC_URL` must be the public read URL.