3.1 KiB
Push .env to Kubernetes
Buzz Guide reads private configuration from the buzz-sheet-env Kubernetes
Secret in the buzz-sheet namespace. Use the local .env file as the source.
Never commit .env or paste its values into a Kubernetes manifest.
This repository uses the manifests under k8s/, not a Kuber compose.yml, so
environment-only updates are applied with kubectl.
1. Check the target cluster
Run these commands from the repository root:
kubectl config current-context
kubectl get namespace buzz-sheet
Stop if the context is not the cluster you intend to update.
Confirm that .env exists, then inspect only its variable names:
test -f .env
awk -F= '/^[A-Za-z_][A-Za-z0-9_]*=/{print $1}' .env
2. Create or update the Secret
The following command builds the Secret locally and sends it directly to the cluster. It does not create a plaintext YAML file:
kubectl create secret generic buzz-sheet-env \
--namespace buzz-sheet \
--from-env-file=.env \
--dry-run=client \
--output=yaml \
| kubectl apply --filename=-
Verify that the Secret exists without displaying its values:
kubectl get secret buzz-sheet-env \
--namespace buzz-sheet \
--output='go-template={{range $key, $value := .data}}{{$key}}{{"\n"}}{{end}}'
Add DEPLOYMENT_WEBHOOK_SECRET to the Gitea Actions repository secrets with
the same value stored in .env. CI uses it to announce deployment lifecycle
updates to the running site.
3. Restart the application
Environment variables sourced from a Secret are read when a pod starts. Restart all Buzz Guide workloads after updating the Secret:
kubectl rollout restart deployment/buzz-sheet \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-worker \
--namespace buzz-sheet
kubectl rollout restart deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet
Wait for every rollout to finish:
kubectl rollout status deployment/buzz-sheet \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-worker \
--namespace buzz-sheet \
--timeout=10m
kubectl rollout status deployment/buzz-sheet-discord-worker \
--namespace buzz-sheet \
--timeout=10m
4. Verify the deployment
curl -fsS 'https://guide.sudloh.com/api/healthz'
bun logs
The health response should show "status":"ready" with both database and
redis set to "ok".
Troubleshooting
namespace "buzz-sheet" not found: apply the base manifests first withkubectl apply --kustomize k8s/base.- Pods fail after the restart: inspect them with
kubectl describe pod --namespace buzz-sheet <pod-name>andbun logs. - A new
DATABASE_URLpoints to an empty database: run the database migrations before serving traffic. Updating the Secret does not migrate the database. NEXT_DEPLOYMENT_IDcomes frombuzz-sheet-config, not.env.- Rotating
NEXT_SERVER_ACTIONS_ENCRYPTION_KEYrequires a new application build and deployment because Next.js uses it during the build. S3_ENDPOINTmust be the private S3-compatible API endpoint.S3_PUBLIC_URLmust be the public read URL.