Skip to content

Slice 2c: render data, with Vault delivery, Assets, sidecars and backups #191

Description

@ExtraToast

Parent

#35

What to build

Slice 2c of the transformation architecture: data renders, so its share of the tree is produced by the core and replaces the hand-written placeholder tree. What 2b resolved now reaches the rendered objects, and backups land with the decisions taken for them (deploy audit rows 22 and 23, SC-41 row 19):

  • Grants. A new vso adapter renders a VaultAuth per Process holding a grant and a VaultStaticSecret per synced grant, in the Application's own directory (vso.yaml), each destination excluded from Flagger's configuration tracking. A new vault-policy adapter renders one policy and one Kubernetes auth role per Process identity, at apps/vso-secrets/policies/<namespace>/<process>.{policy,role}.json, estate-scoped and listed by no kustomization (rendered, not applied).
  • Env and file delivery. A secret reference renders as a secretKeyRef to the grant's synced Secret; a file grant mounts it.
  • Assets. An Asset renders as an immutable ConfigMap under its content-hashed name, mounted at its mountAt.
  • Sidecars. A sidecar renders as a container beside the Process, under the platform's posture.
  • Writable paths. Each renders as an emptyDir at the platform's ephemeral size.
  • Backups.
    • A backed-up volume renders a backup CronJob at its class's schedule, running the engine's method image, which prunes to retain copies. No separate sweep job.
    • Each runs as a derived per-Process backup identity, <process>-backup. Only that identity holds the off-cluster credential, never the serving Process.
    • Each volume derives a <claim>-backup claim of the same size, the on-cluster copy.
    • A claim whose class derives a backup, and its backup claim, are never pruned.
  • retain counts copies kept, as chapter 10 says.

Acceptance criteria

  • data's rendered share equals its committed golden tree byte for byte, every file attributed to one adapter.
  • The vso, vault-policy and backup spellings are stated in chapter 30 and proven at the adapter seam.
  • The kubernetes manifest lint validates every rendered data object.

Blocked by

None: slice 2b (#189) is merged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: deployhomelab-deploy, deploy-v2, manifests, and rollout flow.type: featureNew user-facing or operator-facing capability.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions