Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a690ca37b8 |
No files matched your search
@@ -89,27 +89,10 @@ stage_validate() {
|
|||||||
cd "$REPO"
|
cd "$REPO"
|
||||||
select_manifests
|
select_manifests
|
||||||
local m k cf
|
local m k cf
|
||||||
# Compose .env files and secret files are gitignored by design, so the
|
|
||||||
# workstation never has real values for them. Validate structure only:
|
|
||||||
# skip interpolation, env-file resolution, and path resolution so that
|
|
||||||
# required-variable guards (:?) and missing local files don't fail CI.
|
|
||||||
# Normalization and consistency checks stay enabled.
|
|
||||||
local compose_validate_flags=()
|
|
||||||
local compose_config_help
|
|
||||||
compose_config_help="$(docker compose config --help 2>/dev/null || true)"
|
|
||||||
if printf '%s' "$compose_config_help" | grep -q -- '--no-interpolate'; then
|
|
||||||
compose_validate_flags+=(--no-interpolate)
|
|
||||||
fi
|
|
||||||
if printf '%s' "$compose_config_help" | grep -q -- '--no-env-resolution'; then
|
|
||||||
compose_validate_flags+=(--no-env-resolution)
|
|
||||||
fi
|
|
||||||
if printf '%s' "$compose_config_help" | grep -q -- '--no-path-resolution'; then
|
|
||||||
compose_validate_flags+=(--no-path-resolution)
|
|
||||||
fi
|
|
||||||
log "Validate compose stacks"
|
log "Validate compose stacks"
|
||||||
for cf in ${COMPOSE_STACKS[@]+"${COMPOSE_STACKS[@]}"}; do
|
for cf in ${COMPOSE_STACKS[@]+"${COMPOSE_STACKS[@]}"}; do
|
||||||
echo " config: $cf"
|
echo " config: $cf"
|
||||||
docker compose -f "$cf" config --quiet "${compose_validate_flags[@]}"
|
docker compose -f "$cf" config --quiet
|
||||||
done
|
done
|
||||||
log "Validate k8s manifests (kubectl dry-run=client)"
|
log "Validate k8s manifests (kubectl dry-run=client)"
|
||||||
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ on:
|
|||||||
|
|
||||||
concurrency:
|
concurrency:
|
||||||
group: deploy-main
|
group: deploy-main
|
||||||
cancel-in-progress: true
|
cancel-in-progress: false
|
||||||
|
|
||||||
env:
|
env:
|
||||||
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
DEPLOY_HOST: ${{ secrets.DEPLOY_HOST }}
|
||||||
|
|||||||
@@ -11,14 +11,9 @@ spec:
|
|||||||
rules:
|
rules:
|
||||||
# No successful webinar check for 5m (~2-3 missed 2-min checks).
|
# No successful webinar check for 5m (~2-3 missed 2-min checks).
|
||||||
# Catches: playwright hangs/timeouts, version skew, site changes, hung job.
|
# Catches: playwright hangs/timeouts, version skew, site changes, hung job.
|
||||||
# The last_success > 0 guard is mandatory: checker.py initialises
|
|
||||||
# last_success to 0, so without it `time() - 0` equals the current epoch
|
|
||||||
# and humanizeDuration renders ~20722d on every pod restart. Keep the
|
|
||||||
# duration expression on the left so $value stays the real gap.
|
|
||||||
- alert: WebinarCheckerNoSuccessfulCheck
|
- alert: WebinarCheckerNoSuccessfulCheck
|
||||||
expr: |
|
expr: |
|
||||||
((time() - webinar_check_last_success_timestamp_seconds) > 300)
|
(time() - webinar_check_last_success_timestamp_seconds > 300)
|
||||||
and (webinar_check_last_success_timestamp_seconds > 0)
|
|
||||||
and (webinar_check_last_run_timestamp_seconds > 0)
|
and (webinar_check_last_run_timestamp_seconds > 0)
|
||||||
for: 2m
|
for: 2m
|
||||||
labels:
|
labels:
|
||||||
@@ -27,20 +22,6 @@ spec:
|
|||||||
summary: "Webinar checker has no successful check for 5m"
|
summary: "Webinar checker has no successful check for 5m"
|
||||||
description: "edu-master/webinar-checker: last successful webinar check was {{ $value | humanizeDuration }} ago. Checks are failing or hanging (see consecutive failures alert). Notifications about new webinars are NOT being sent."
|
description: "edu-master/webinar-checker: last successful webinar check was {{ $value | humanizeDuration }} ago. Checks are failing or hanging (see consecutive failures alert). Notifications about new webinars are NOT being sent."
|
||||||
|
|
||||||
# Checks are running but none has ever succeeded since pod start.
|
|
||||||
# Split out from the rule above so a zeroed gauge never feeds
|
|
||||||
# humanizeDuration.
|
|
||||||
- alert: WebinarCheckerNeverSucceeded
|
|
||||||
expr: |
|
|
||||||
(webinar_check_last_success_timestamp_seconds == 0)
|
|
||||||
and (webinar_check_last_run_timestamp_seconds > 0)
|
|
||||||
for: 10m
|
|
||||||
labels:
|
|
||||||
severity: critical
|
|
||||||
annotations:
|
|
||||||
summary: "Webinar checker has never completed a successful check"
|
|
||||||
description: 'edu-master/webinar-checker: checks have been running for 10m but not one has ever succeeded since the pod started, so every check is failing. Check pod logs (Loki: {namespace="edu-master", container="webinar-checker"}).'
|
|
||||||
|
|
||||||
# Fast path: 3 consecutive failures (~6+ min at 2-min interval).
|
# Fast path: 3 consecutive failures (~6+ min at 2-min interval).
|
||||||
- alert: WebinarCheckerConsecutiveFailures
|
- alert: WebinarCheckerConsecutiveFailures
|
||||||
expr: |
|
expr: |
|
||||||
|
|||||||
File renamed without changes.
File renamed without changes.
@@ -69,18 +69,3 @@ alertmanager:
|
|||||||
defaultRules:
|
defaultRules:
|
||||||
disabled:
|
disabled:
|
||||||
CPUThrottlingHigh: true
|
CPUThrottlingHigh: true
|
||||||
KubeControllerManagerDown: true
|
|
||||||
KubeSchedulerDown: true
|
|
||||||
KubeEtcdDown: true
|
|
||||||
KubeEtcdHighCommitDurations: true
|
|
||||||
|
|
||||||
# k0s runs controller-manager/scheduler/etcd internally, not as pods with
|
|
||||||
# component=kube-controller-manager/kube-scheduler/k8s-app=kube-etcd labels.
|
|
||||||
# Their Services get no endpoints, so the targets are permanently down.
|
|
||||||
# kube-proxy and kubelet have endpoints on k0s, keep them enabled.
|
|
||||||
kubeControllerManager:
|
|
||||||
enabled: false
|
|
||||||
kubeScheduler:
|
|
||||||
enabled: false
|
|
||||||
kubeEtcd:
|
|
||||||
enabled: false
|
|
||||||
@@ -3,7 +3,7 @@
|
|||||||
services:
|
services:
|
||||||
core:
|
core:
|
||||||
container_name: searxng-core
|
container_name: searxng-core
|
||||||
image: docker.io/searxng/searxng:${SEARXNG_VERSION:-2026.9.25-12f8b6515}
|
image: docker.io/searxng/searxng:${SEARXNG_VERSION:-2026.09.13-d4ce87c23}
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
# ports:
|
||||||
# - ${SEARXNG_PORT:-8080}
|
# - ${SEARXNG_PORT:-8080}
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: searxng
|
- name: searxng
|
||||||
image: docker.io/searxng/searxng:2026.9.25-12f8b6515
|
image: docker.io/searxng/searxng:2026.09.13-d4ce87c23
|
||||||
envFrom:
|
envFrom:
|
||||||
- configMapRef:
|
- configMapRef:
|
||||||
name: searxng-config
|
name: searxng-config
|
||||||
|
|||||||
Reference in new issue
Block a user