Files
buzz-sheet/k8s.md
T
gunshiz 6e62ed6649
CI / Verify (push) Successful in 54s
CI / Build immutable images and deploy (push) Successful in 1m31s
k8s : asd
2026-08-30 07:26:09 +00:00

2.5 KiB

Updating .env in Kubernetes

Buzz Sheet uses the buzz-sheet-env Secret in the buzz-sheet namespace. The local .env file is ignored by Git and must never be committed.

This repository uses hand-authored Kustomize manifests rather than a Kuber-managed Compose file, so synchronize .env with kubectl.

Push an updated .env

From the repository root, confirm that kubectl is connected to the intended cluster:

cd /home/gunshiz/buzz-sheet
kubectl config current-context
kubectl get namespace buzz-sheet

Create or update the Secret without printing its values:

kubectl create secret generic buzz-sheet-env \
  --namespace buzz-sheet \
  --from-env-file=.env \
  --dry-run=client \
  --output=yaml | kubectl apply --filename=-

Running pods do not reload Secret values automatically. Restart both the web application and the outbox worker, then wait for each rollout:

kubectl rollout restart deployment/buzz-sheet \
  --namespace buzz-sheet

kubectl rollout restart deployment/buzz-sheet-worker \
  --namespace buzz-sheet

kubectl rollout status deployment/buzz-sheet \
  --namespace buzz-sheet \
  --timeout=10m

kubectl rollout status deployment/buzz-sheet-worker \
  --namespace buzz-sheet \
  --timeout=10m

Verify PostgreSQL and Redis readiness, then inspect the application logs:

curl -fsS 'https://guide.sudloh.com/api/health?ready=1'
bun logs

The health response should report "status":"ready", with both database and redis set to "ok".

Important exceptions

  • Updating the Secret does not apply database migrations or seed data. If DATABASE_URL now points to a new database, migrate and seed that database before restarting the application.
  • Better Auth errors about missing database fields require a schema migration. Pushing .env again will not fix them.
  • NEXT_DEPLOYMENT_ID is controlled by buzz-sheet-config and the immutable image revision. Do not change it for an environment-only update.
  • NEXT_SERVER_ACTIONS_ENCRYPTION_KEY is embedded during next build. Rotating it requires building and deploying a new image; restarting the existing image is not sufficient.
  • If BETTER_AUTH_URL or the public hostname changes, update the Kubernetes ingress and Cloudflare/DNS configuration as well.
  • S3_ENDPOINT is the private Garage API used for writes. S3_PUBLIC_URL is the public read-only CDN base (production uses https://buzz-cdn.astrxl.dev). Browser uploads go through the authenticated application route; do not point S3_ENDPOINT at the CDN hostname.