Files
monky-deployd/config.example.yaml
T
mdella 037782e1ff fix: accept sites fmt|cbs|pdx|roam (tenancy 0.7.x) and keep the identity read grant alive across tunneller rewrites — 0.1.10
deployd#3 (DD-0620): every kit for a backend registered since 2026-09-08 died at `--site`.
env-dev-08 (2026-09-11..13): two days of "identity is not readable" ticks — ziti-edge-tunnel
re-creates the file with mode 0600, the ACL mask goes to ---, group membership stops helping.
identity-acl.sh + monky-deployd-identity-acl.path re-apply the grant on every directory change.

Doc-Drift: DD-0620 fixed
Closes #3

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ASnneBmT7rfaJLE8NGNw7S
2026-09-13 00:17:35 +00:00

51 lines
3.4 KiB
YAML

# /etc/monky-deployd/config.yaml — monky-deployd v0.1.6 (MONKY-ADR-0028 §D)
# Written by packaging/install.sh (or the ansible role monky_deployd). YAML *subset*: maps, scalars,
# simple lists, comments. Keys not listed here are a config error.
env_id: env-qa-02 # env-<tier>-<nn> (or a grandfathered legacy id); MUST match the token's env
site: cbs # fmt | pdx | roam as tenancy issues it (cbs = deprecated alias of fmt, still on rows registered before 2026-09-08)
transport: sdk # sdk (OpenZiti Python SDK, default) | proxy (monky-deployd-proxy.service) | system (tunneler `run` mode / plain DNS)
identity: /opt/openziti/etc/identities/monky-host.env-qa-02.json # the box's host identity (read via ACL)
tenancy:
service: monky.tenancy.deploy # ziti service bound by the tenancy sidecar -> 127.0.0.1:8081 (agent entrypoint)
host: monky.tenancy.deploy # intercept host (sdk/system); defaults to `service`
port: 443 # intercept port of monky.tenancy.deploy (in-pod 8081)
scheme: http # plain HTTP inside the mesh; the mesh is the transport security
proxy_addr: 127.0.0.1:18443 # transport: proxy
timeout_s: 30
bao:
service: openbao # ziti service (#openbao-client dial), terminates on openbao-active
addr: https://bao.cbs.tikali.net:8200 # intercept name — NOT public DNS; TLS validated against ca_bundle
proxy_addr: 127.0.0.1:18200 # transport: proxy (SNI + cert check still use bao.cbs.tikali.net)
ca_bundle: /etc/monky-deployd/openbao-ca.pem # the openbao-ca certificate (cert-manager CA, not public); `none` = system store
mount: jwt-tenancy # AUTH mount: POST /v1/auth/jwt-tenancy/login {"role": "see-env", "jwt": <deploy grant>}
role: see-env
kv_mount: monky # KV-v2 mount; the agent may read monky/data/<env_id>/see/* only
token_max_ttl_s: 2592000 # 30 d — re-lease `release_before_s` before this age
renew_below_s: 43200 # renew-self when the remaining TTL drops under 12 h
release_before_s: 172800 # re-lease 2 d before max TTL
timeout_s: 30
state_dir: /var/lib/monky-deployd # bao.token (0600), state.json, lock
deploy_dir: /var/lib/monky-deployd/env-qa-02 # releases/<sha>/ + current -> the compose project directory
bootstrap_path: /etc/monky-deployd/bootstrap.jwt # the kit's one-time deploy grant; consumed and deleted on first login
interval_s: 60 # loop-mode sleep (the systemd timer is the normal driver)
healthy_timeout_s: 300 # wait for `compose ps` to be healthy after `up`
disk:
factor: 1.5 # refuse when docker data-root free < need x factor + headroom (the env-dev-09 lesson)
headroom_bytes: 2147483648 # 2 GiB
volumes_on_absent: keep # keep | purge — what `down` does with data volumes (never purge on prod)
laptop_mode: false # true: offline exits 0 quietly; run without the timer (`monky-deployd run`)
# prod: false # override tier detection (env-prod-* / prod-cedar are prod)
# compose_project: monky-env-qa-02 # docker compose project name
# docker_bin: docker
# log_level: INFO
# The registry the bundle pulls from. Used only when the seeded pull credential is a bare
# `username:password` (a JSON credential names its own registry). doc 24 §4a.
registry_host: harbor.tikali.net