Files
buzz-sheet/k8s.md
T
2026-09-06 17:16:38 +07:00

101 lines
2.9 KiB
Markdown

# Push `.env` to Kubernetes
Buzz Sheet reads private configuration from the `buzz-sheet-env` Kubernetes
Secret in the `buzz-sheet` namespace. Use the local `.env` file as the source.
Never commit `.env` or paste its values into a Kubernetes manifest.
This repository uses the manifests under `k8s/`, not a Kuber `compose.yml`, so
environment-only updates are applied with `kubectl`.
## 1. Check the target cluster
Run these commands from the repository root:
```bash
kubectl config current-context
kubectl get namespace buzz-sheet
```
Stop if the context is not the cluster you intend to update.
Confirm that `.env` exists, then inspect only its variable names:
```bash
test -f .env
awk -F= '/^[A-Za-z_][A-Za-z0-9_]*=/{print $1}' .env
```
## 2. Create or update the Secret
The following command builds the Secret locally and sends it directly to the
cluster. It does not create a plaintext YAML file:
```bash
kubectl create secret generic buzz-sheet-env \
--namespace buzz-sheet \
--from-env-file=.env \
--dry-run=client \
--output=yaml \
| kubectl apply --filename=-
```
Verify that the Secret exists without displaying its values:
```bash
kubectl get secret buzz-sheet-env \
--namespace buzz-sheet \
--output='go-template={{range $key, $value := .data}}{{$key}}{{"\n"}}{{end}}'
```
## 3. Restart the application
Environment variables sourced from a Secret are read when a pod starts.
Restart all Buzz Sheet workloads after updating the Secret:
```bash
kubectl rollout restart deployment/buzz-sheet \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-worker \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet
```
Wait for every rollout to finish:
```bash
kubectl rollout status deployment/buzz-sheet \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-worker \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet \
--timeout=10m
```
## 4. Verify the deployment
```bash
curl -fsS 'https://guide.sudloh.com/api/health?ready=1'
bun logs
```
The health response should show `"status":"ready"` with both `database` and
`redis` set to `"ok"`.
## Troubleshooting
- `namespace "buzz-sheet" not found`: apply the base manifests first with
`kubectl apply --kustomize k8s/base`.
- Pods fail after the restart: inspect them with
`kubectl describe pod --namespace buzz-sheet <pod-name>` and `bun logs`.
- A new `DATABASE_URL` points to an empty database: run the database migrations
before serving traffic. Updating the Secret does not migrate the database.
- `NEXT_DEPLOYMENT_ID` comes from `buzz-sheet-config`, not `.env`.
- Rotating `NEXT_SERVER_ACTIONS_ENCRYPTION_KEY` requires a new application
build and deployment because Next.js uses it during the build.
- `S3_ENDPOINT` must be the private S3-compatible API endpoint.
`S3_PUBLIC_URL` must be the public read URL.