Files
buzz-sheet/k8s.md
T
gunshiz 659a57fb4a
CI / Verify (push) Successful in 1m6s
CI / Build immutable images and deploy (push) Has been skipped
feat(auth): replace Google login with credentials
2026-08-29 07:54:15 +00:00

73 lines
2.3 KiB
Markdown

# Updating `.env` in Kubernetes
Buzz Sheet uses the `buzz-sheet-env` Secret in the `buzz-sheet` namespace. The
local `.env` file is ignored by Git and must never be committed.
This repository uses hand-authored Kustomize manifests rather than a
Kuber-managed Compose file, so synchronize `.env` with `kubectl`.
## Push an updated `.env`
From the repository root, confirm that `kubectl` is connected to the intended
cluster:
```bash
cd /home/gunshiz/buzz-sheet
kubectl config current-context
kubectl get namespace buzz-sheet
```
Create or update the Secret without printing its values:
```bash
kubectl create secret generic buzz-sheet-env \
--namespace buzz-sheet \
--from-env-file=.env \
--dry-run=client \
--output=yaml | kubectl apply --filename=-
```
Running pods do not reload Secret values automatically. Restart both the web
application and the outbox worker, then wait for each rollout:
```bash
kubectl rollout restart deployment/buzz-sheet \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-worker \
--namespace buzz-sheet
kubectl rollout status deployment/buzz-sheet \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-worker \
--namespace buzz-sheet \
--timeout=10m
```
Verify PostgreSQL and Redis readiness, then inspect the application logs:
```bash
curl -fsS 'https://sheet.sudloh.com/api/health?ready=1'
bun logs
```
The health response should report `"status":"ready"`, with both `database`
and `redis` set to `"ok"`.
## Important exceptions
- Updating the Secret does not apply database migrations or seed data. If
`DATABASE_URL` now points to a new database, migrate and seed that database
before restarting the application.
- Better Auth errors about missing database fields require a schema migration.
Pushing `.env` again will not fix them.
- `NEXT_DEPLOYMENT_ID` is controlled by `buzz-sheet-config` and the immutable
image revision. Do not change it for an environment-only update.
- `NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` is embedded during `next build`. Rotating
it requires building and deploying a new image; restarting the existing image
is not sufficient.
- If `BETTER_AUTH_URL` or the public hostname changes, update the Kubernetes
ingress and Cloudflare/DNS configuration as well.