2.7 KiB
2.7 KiB
Updating .env in Kubernetes
Buzz Sheet uses the buzz-sheet-env Secret in the buzz-sheet namespace. The
local .env file is ignored by Git and must never be committed.
This repository uses hand-authored Kustomize manifests rather than a
Kuber-managed Compose file, so synchronize .env with kubectl.
Push an updated .env
From the repository root, confirm that kubectl is connected to the intended
cluster:
cd /home/gunshiz/buzz-sheet
kubectl config current-context
kubectl get namespace buzz-sheet
Create or update the Secret without printing its values:
kubectl create secret generic buzz-sheet-env \
--namespace buzz-sheet \
--from-env-file=.env \
--dry-run=client \
--output=yaml | kubectl apply --filename=-
Running pods do not reload Secret values automatically. Restart the web application and both workers, then wait for each rollout:
kubectl rollout restart deployment/buzz-sheet \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-worker \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet
kubectl rollout status deployment/buzz-sheet \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-worker \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet \
--timeout=10m
Verify PostgreSQL and Redis readiness, then inspect the application logs:
curl -fsS 'https://guide.sudloh.com/api/health?ready=1'
bun logs
The health response should report "status":"ready", with both database
and redis set to "ok".
Important exceptions
- Updating the Secret does not apply database migrations or seed data. If
DATABASE_URLnow points to a new database, migrate and seed that database before restarting the application. - Better Auth errors about missing database fields require a schema migration.
Pushing
.envagain will not fix them. NEXT_DEPLOYMENT_IDis controlled bybuzz-sheet-configand the immutable image revision. Do not change it for an environment-only update.NEXT_SERVER_ACTIONS_ENCRYPTION_KEYis embedded duringnext build. Rotating it requires building and deploying a new image; restarting the existing image is not sufficient.- If
BETTER_AUTH_URLor the public hostname changes, update the Kubernetes ingress and Cloudflare/DNS configuration as well. S3_ENDPOINTis the private Garage API used for writes.S3_PUBLIC_URLis the public read-only CDN base (production useshttps://buzz-cdn.astrxl.dev). Browser uploads go through the authenticated application route; do not pointS3_ENDPOINTat the CDN hostname.