3.2 KiB
Push .env to Kubernetes
Buzz Sheet reads private configuration from the buzz-sheet-env Kubernetes
Secret in the buzz-sheet namespace. Use the local .env file as the source.
Never commit .env or paste its values into a Kubernetes manifest.
This repository uses the manifests under k8s/, not a Kuber compose.yml, so
environment-only updates are applied with kubectl.
1. Check the target cluster
Run these commands from the repository root:
kubectl config current-context
kubectl get namespace buzz-sheet
Stop if the context is not the cluster you intend to update.
Confirm that .env exists, then inspect only its variable names:
test -f .env
awk -F= '/^[A-Za-z_][A-Za-z0-9_]*=/{print $1}' .env
2. Create or update the Secret
The following command builds the Secret locally and sends it directly to the cluster. It does not create a plaintext YAML file:
kubectl create secret generic buzz-sheet-env \
--namespace buzz-sheet \
--from-env-file=.env \
--dry-run=client \
--output=yaml \
| kubectl apply --filename=-
Verify that the Secret exists without displaying its values:
kubectl get secret buzz-sheet-env \
--namespace buzz-sheet \
--output='go-template={{range $key, $value := .data}}{{$key}}{{"\n"}}{{end}}'
3. Restart the application
Environment variables sourced from a Secret are read when a pod starts. Restart all Buzz Sheet workloads after updating the Secret:
kubectl rollout restart deployment/buzz-sheet \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-mirror \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-worker \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet
Wait for every rollout to finish:
kubectl rollout status deployment/buzz-sheet \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-mirror \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-worker \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet \
--timeout=10m
4. Verify the deployment
curl -fsS 'https://guide.sudloh.com/api/health?ready=1'
curl -fsS 'https://buzz.sudloh.com/guide/api/health?ready=1'
bun logs
The health response should show "status":"ready" with both database and
redis set to "ok".
Troubleshooting
namespace "buzz-sheet" not found: apply the base manifests first withkubectl apply --kustomize k8s/base.- Pods fail after the restart: inspect them with
kubectl describe pod --namespace buzz-sheet <pod-name>andbun logs. - A new
DATABASE_URLpoints to an empty database: run the database migrations before serving traffic. Updating the Secret does not migrate the database. NEXT_DEPLOYMENT_IDcomes frombuzz-sheet-config, not.env.- Rotating
NEXT_SERVER_ACTIONS_ENCRYPTION_KEYrequires a new application build and deployment because Next.js uses it during the build. S3_ENDPOINTmust be the private S3-compatible API endpoint.S3_PUBLIC_URLmust be the public read URL.