Multiple developers now work on this repo, and the only working deploy
trigger required pushing to GitHub - which contradicts the standing
GitLab-canonical policy for this repo - while every actual deploy was a
manual kubectl run against one environment (no prod exists at all).
Restructures deploy/k8s/ into base/ + overlays/{dev,prod}: overlays/dev
is a verified byte-for-byte no-op for the live sandbox (kubectl kustomize
diff against the old flat layout is empty), overlays/prod is scaffolded
but inert (placeholder hostname + JMAP_SERVER_URL, since neither a prod
hostname decision nor a prod Stalwart exist yet). deploy/k8s/ca/ (the
EJBCA internal CA) is untouched and never referenced by either overlay.
Adds .gitlab-ci.yml: verify (MR gate, no push/deploy) -> build+deploy-dev
(automatic on push to dev, one image name/tag-only environments, fixing
the old -dev/-beta naming split) -> promote (manual, protected
`production` environment, retags the exact dev digest via
`docker buildx imagetools create` - never rebuilds - and is left as a
documented TODO for the actual `kubectl apply` until prod is real).
Updates VNCMAIL-SETUP.md and deploy/k8s/README.md to describe the new
flow and correct the aspirational promotion description that assumed a
"production image" CI never actually built.
Also fixes a pre-existing lint error (no-control-regex false positive on
an intentional DN-sanitizing character class in lib/smime-ca/ejbca.ts)
that was blocking this commit's pre-commit hook - unrelated to this
change otherwise, confirmed already present on dev before this branch.
Runner/RBAC/registry setup is an infra prerequisite this commit cannot
provide - documented in the pipeline plan, not part of this diff.
22 lines
750 B
YAML
22 lines
750 B
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
namespace: vncmail-prod
|
|
resources:
|
|
- ../../base
|
|
- namespace.yaml
|
|
# - secret.yaml # create from secret.example.yaml; not committed
|
|
|
|
patches:
|
|
- path: patch-ingress.yaml
|
|
- path: patch-deployment.yaml
|
|
|
|
# NOT MEANT TO BE APPLIED AS COMMITTED. Scaffolding only (see the pipeline
|
|
# plan's Phase C/D) — the tag below is an obviously-invalid placeholder;
|
|
# the real promote job (.gitlab-ci.yml) resolves and pins an actual digest at
|
|
# deploy time via `kubectl set image`, it never trusts whatever is checked
|
|
# in here.
|
|
images:
|
|
- name: ghcr.io/brvncde-dotcom/vncmail-plus-dev
|
|
newName: registry.gitlab.vnc.biz/gitlab-instance-b9b5cf2f/vncmail-plus
|
|
newTag: not-yet-promoted
|