Files
monky-deployd/config.example.yaml
T
mdella 6336012b74 feat(install): read-only deploy token for the private package registry (v0.1.2)
The GitLab project is private (its parent groups are private, so it cannot be
made public): the v0.1.1 one-liner answered 401 anonymously. install.sh gains
--token / MONKY_DEPLOYD_TOKEN and sends `DEPLOY-TOKEN: <token>` (a GitLab deploy
token, scope read_package_registry only, revocable) on every registry download,
the script itself included; the token goes through a 0600 curl -K file (never the
command line, the log or an xtrace). The grant is taken via --bootstrap-file when
the script is piped (stdin IS the script). Ansible: monky_deployd_download_token
(vaulted) -> DEPLOY-TOKEN header, no_log. Docs explain why, the token's scope and
the --source gitea alternative (split-horizon Gitea, cbs/iac#102).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
2026-09-05 19:03:25 +00:00

47 lines
3.1 KiB
YAML

# /etc/monky-deployd/config.yaml — monky-deployd v0.1.2 (MONKY-ADR-0028 §D)
# Written by packaging/install.sh (or the ansible role monky_deployd). YAML *subset*: maps, scalars,
# simple lists, comments. Keys not listed here are a config error.
env_id: env-qa-02 # env-<tier>-<nn> (or a grandfathered legacy id); MUST match the token's env
site: cbs # cbs | pdx (lowercase DC code)
transport: sdk # sdk (OpenZiti Python SDK, default) | proxy (monky-deployd-proxy.service) | system (tunneler `run` mode / plain DNS)
identity: /opt/openziti/etc/identities/monky-host.env-qa-02.json # the box's host identity (read via ACL)
tenancy:
service: monky.tenancy.deploy # ziti service bound by the tenancy sidecar -> 127.0.0.1:8081 (agent entrypoint)
host: monky.tenancy.deploy # intercept host (sdk/system); defaults to `service`
port: 8081
scheme: http # plain HTTP inside the mesh; the mesh is the transport security
proxy_addr: 127.0.0.1:18443 # transport: proxy
timeout_s: 30
bao:
service: openbao # ziti service (#openbao-client dial), terminates on openbao-active
addr: https://bao.cbs.tikali.net:8200 # intercept name — NOT public DNS; TLS validated against ca_bundle
proxy_addr: 127.0.0.1:18200 # transport: proxy (SNI + cert check still use bao.cbs.tikali.net)
ca_bundle: /etc/monky-deployd/openbao-ca.pem # the openbao-ca certificate (cert-manager CA, not public); `none` = system store
mount: jwt-tenancy # AUTH mount: POST /v1/auth/jwt-tenancy/login {"role": "see-env", "jwt": <deploy grant>}
role: see-env
kv_mount: monky # KV-v2 mount; the agent may read monky/data/<env_id>/see/* only
token_max_ttl_s: 2592000 # 30 d — re-lease `release_before_s` before this age
renew_below_s: 43200 # renew-self when the remaining TTL drops under 12 h
release_before_s: 172800 # re-lease 2 d before max TTL
timeout_s: 30
state_dir: /var/lib/monky-deployd # bao.token (0600), state.json, lock
deploy_dir: /var/lib/monky-deployd/env-qa-02 # releases/<sha>/ + current -> the compose project directory
bootstrap_path: /etc/monky-deployd/bootstrap.jwt # the kit's one-time deploy grant; consumed and deleted on first login
interval_s: 60 # loop-mode sleep (the systemd timer is the normal driver)
healthy_timeout_s: 300 # wait for `compose ps` to be healthy after `up`
disk:
factor: 1.5 # refuse when docker data-root free < need x factor + headroom (the env-dev-09 lesson)
headroom_bytes: 2147483648 # 2 GiB
volumes_on_absent: keep # keep | purge — what `down` does with data volumes (never purge on prod)
laptop_mode: false # true: offline exits 0 quietly; run without the timer (`monky-deployd run`)
# prod: false # override tier detection (env-prod-* / prod-cedar are prod)
# compose_project: monky-env-qa-02 # docker compose project name
# docker_bin: docker
# log_level: INFO