Files
monky-deployd/config.example.yaml
T
mdella c966450d8e fix(install): fetch from scm.tikali.ai (public project) — Gitea name is split-horizon inside the estate
Inside the estate gitea.cbs.tikali.net resolves to jump1's RED EIP (10.10.0.175),
which has no HTTP ingress, so backend boxes could not download the install
artefacts from the Gitea mirror (cbs/iac#102). scm.tikali.ai is reachable from
those boxes and the project is now public, so the GitLab generic package
registry becomes the PRIMARY source:

- packaging/install.sh: default source = scm.tikali.ai generic package registry
  (projects/69/packages/generic/monky-deployd/<ver>/...); `--source gitea` /
  MONKY_DEPLOYD_SOURCE=gitea keeps the Gitea release as the off-estate
  alternative; --base-url / MONKY_DEPLOYD_BASE_URL still override the base.
- ansible role defaults: monky_deployd_base_url/_deb_url point at the registry,
  Gitea layout kept as a commented alternative.
- README / docs/OPERATIONS.md / CLAUDE.md / CI comments + release description:
  both locations keep being published (release + release:gitea).
- Version 0.1.1 (the tag gate refuses v* tags whose version != __version__);
  tests compare against __version__ instead of a literal. No agent change.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
2026-09-05 17:57:27 +00:00

47 lines
3.1 KiB
YAML

# /etc/monky-deployd/config.yaml — monky-deployd v0.1.1 (MONKY-ADR-0028 §D)
# Written by packaging/install.sh (or the ansible role monky_deployd). YAML *subset*: maps, scalars,
# simple lists, comments. Keys not listed here are a config error.
env_id: env-qa-02 # env-<tier>-<nn> (or a grandfathered legacy id); MUST match the token's env
site: cbs # cbs | pdx (lowercase DC code)
transport: sdk # sdk (OpenZiti Python SDK, default) | proxy (monky-deployd-proxy.service) | system (tunneler `run` mode / plain DNS)
identity: /opt/openziti/etc/identities/monky-host.env-qa-02.json # the box's host identity (read via ACL)
tenancy:
service: monky.tenancy.deploy # ziti service bound by the tenancy sidecar -> 127.0.0.1:8081 (agent entrypoint)
host: monky.tenancy.deploy # intercept host (sdk/system); defaults to `service`
port: 8081
scheme: http # plain HTTP inside the mesh; the mesh is the transport security
proxy_addr: 127.0.0.1:18443 # transport: proxy
timeout_s: 30
bao:
service: openbao # ziti service (#openbao-client dial), terminates on openbao-active
addr: https://bao.cbs.tikali.net:8200 # intercept name — NOT public DNS; TLS validated against ca_bundle
proxy_addr: 127.0.0.1:18200 # transport: proxy (SNI + cert check still use bao.cbs.tikali.net)
ca_bundle: /etc/monky-deployd/openbao-ca.pem # the openbao-ca certificate (cert-manager CA, not public); `none` = system store
mount: jwt-tenancy # AUTH mount: POST /v1/auth/jwt-tenancy/login {"role": "see-env", "jwt": <deploy grant>}
role: see-env
kv_mount: monky # KV-v2 mount; the agent may read monky/data/<env_id>/see/* only
token_max_ttl_s: 2592000 # 30 d — re-lease `release_before_s` before this age
renew_below_s: 43200 # renew-self when the remaining TTL drops under 12 h
release_before_s: 172800 # re-lease 2 d before max TTL
timeout_s: 30
state_dir: /var/lib/monky-deployd # bao.token (0600), state.json, lock
deploy_dir: /var/lib/monky-deployd/env-qa-02 # releases/<sha>/ + current -> the compose project directory
bootstrap_path: /etc/monky-deployd/bootstrap.jwt # the kit's one-time deploy grant; consumed and deleted on first login
interval_s: 60 # loop-mode sleep (the systemd timer is the normal driver)
healthy_timeout_s: 300 # wait for `compose ps` to be healthy after `up`
disk:
factor: 1.5 # refuse when docker data-root free < need x factor + headroom (the env-dev-09 lesson)
headroom_bytes: 2147483648 # 2 GiB
volumes_on_absent: keep # keep | purge — what `down` does with data volumes (never purge on prod)
laptop_mode: false # true: offline exits 0 quietly; run without the timer (`monky-deployd run`)
# prod: false # override tier detection (env-prod-* / prod-cedar are prod)
# compose_project: monky-env-qa-02 # docker compose project name
# docker_bin: docker
# log_level: INFO