apiVersion: apps/v1 kind: Deployment metadata: name: vncmail-plus labels: app: vncmail-plus spec: replicas: 1 selector: matchLabels: app: vncmail-plus # RWO volumes can only mount to one pod — Recreate avoids a stuck rollout. strategy: type: Recreate template: metadata: labels: app: vncmail-plus spec: # The image runs as uid/gid 1001 (nextjs:nodejs) and the Dockerfile # chowns /app/data to 1001. fsGroup makes the mounted PVCs writable by it. securityContext: fsGroup: 1001 runAsUser: 1001 runAsGroup: 1001 # The GitLab container registry is private by default. Nodes need a # docker-registry secret named `gitlab-registry` in the target namespace. # Create it once per environment during first-time setup # (see deploy/k8s/README.md §3a). imagePullSecrets: - name: gitlab-registry containers: - name: vncmail-plus # Generic placeholder — the real image name + tag are injected by the # image-tag kustomize Component on every deploy (see # overlays/*/image-tag/kustomization.yaml, rewritten by CI). image: vncmail-plus:latest imagePullPolicy: Always ports: - containerPort: 3000 envFrom: - secretRef: name: vncmail-env env: - name: HOSTNAME value: "0.0.0.0" - name: PORT value: "3000" readinessProbe: httpGet: path: /api/health port: 3000 initialDelaySeconds: 10 periodSeconds: 10 livenessProbe: httpGet: path: /api/health port: 3000 initialDelaySeconds: 25 periodSeconds: 30 resources: requests: cpu: 100m memory: 256Mi limits: cpu: "1" memory: 1Gi volumeMounts: - name: settings mountPath: /app/data/settings - name: admin mountPath: /app/data/admin - name: admin-state mountPath: /app/data/admin-state - name: telemetry mountPath: /app/data/telemetry volumes: - name: settings persistentVolumeClaim: claimName: vncmail-settings - name: admin persistentVolumeClaim: claimName: vncmail-admin - name: admin-state persistentVolumeClaim: claimName: vncmail-admin-state - name: telemetry persistentVolumeClaim: claimName: vncmail-telemetry