# Sandbox deployment values - Gitea registry. # # NOT CLUSTER-VERIFIED. These values are written against images that exist and a # registry whose auth behaviour was checked, but they have not been applied to a # Simpl cluster. Confirm and amend after the first deployment. # # VERSION SKEW, unresolved. These images carry dagster 1.13.19 (requirements.txt # pins no upper bound, so the build took whatever was current). The sandbox # control plane is 1.12.8. A code server is a gRPC server the webserver and # daemon call into, so the two versions have to be compatible; a minor-version # gap is not a supported configuration. Pin dagster to the control plane version # and rebuild before reading a failure here as a bug in this service. # # Use these instead of the code.europa.eu references in # yaml/values-dagster-distributed-execution.yaml and # yaml/loosely-coupled/values-pipes-payload.yaml when deploying to the # dataprovider01 sandbox. Both images were built and published by a Gitea Actions # workflow held in the sandbox Gitea mirror of this repository, not here. # # The tag below is a short commit SHA and is the same for both images. That is # the version lock: the code location and the payload it dispatches must come # from one commit. Bump both together or not at all. # # The sandbox Gitea registry requires authentication - an anonymous manifest GET # returns 401 - so a pull secret is required in every namespace that pulls either # image. Create it with a Gitea access token that has read:package scope: # # kubectl -n create secret docker-registry gitea-registry \ # --docker-server=gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu \ # --docker-username= \ # --docker-password= # # The payload namespace needs it too: PipesK8sClient creates that Job, and a # missing pull secret there leaves the op waiting on a pod that never starts, # which surfaces as pod_wait_timeout rather than as an image error. # # PULL SECRET PLACEMENT. Checked against the chart templates in dagster 1.12.8, # which is what the sandbox runs. There is no per-deployment imagePullSecrets # field - deployment-user.yaml reads the SUBCHART value and the run launcher # helper reads the PARENT value - so a pull secret nested under a deployments[] # entry is silently discarded, and the pod fails with ImagePullBackOff against a # values file that looks correct. # # Both keys below therefore apply to every code location in the release, not # just this one. Extra pull secrets are ignored for registries they do not match, # so the existing code locations are unaffected. dagster: # Run pods, webserver and daemon. imagePullSecrets: - name: gitea-registry dagster-user-deployments: # Code server pods. imagePullSecrets: - name: gitea-registry deployments: - name: distributed-execution image: repository: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution tag: 5122da4691f9 pullPolicy: IfNotPresent env: - name: PIPES_PAYLOAD_IMAGE value: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution-payload:5122da4691f9 - name: PIPES_PAYLOAD_NAMESPACE value: dagster runLauncher: config: k8sRunLauncher: runK8sConfig: containerConfig: env: - name: PIPES_PAYLOAD_IMAGE value: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution-payload:5122da4691f9 - name: PIPES_PAYLOAD_NAMESPACE value: dagster