Resolve ai-service directly from the RAG routes, never the gateway

This commit is contained in:
2026-08-19 10:16:44 +07:00
parent f50ccfc5f7
commit 24c55d1627
13 changed files with 470 additions and 22 deletions
@@ -25,6 +25,37 @@
# recovery. It does NOT restore the current image tag or the Grafana
# password: set the tag afterward via `rollback-k3s.yml` (target_sha = the
# last known-good commit) and re-enter the Grafana password by hand.
#
# ---------------------------------------------------------------------------
# EDITING THE INLINE VALUES BY HAND — read this first (2026-08-18 outage)
# ---------------------------------------------------------------------------
# Editing `spec.source.helm.values` through the ArgoCD UI broke this
# Application for ~16 hours. The UI saved the block as a FOLDED scalar
# (`values: >`), and a folded scalar joins consecutive same-indent lines into
# one. Three comment lines sat directly above `aiService:` at the same indent,
# so all four became a single line and `aiService:` ended up *inside* the
# comment — leaving YAML that cannot parse at all.
#
# It failed silently and misleadingly. ArgoCD kept reporting `Synced` (its
# last successful render was hours stale), the UI's PARAMETERS tab still
# showed sensible values, and the site stayed up — Kubernetes will not retire
# working pods until a replacement goes Ready, and the replacement never
# could. Meanwhile every override in the block was being ignored: the GHCR
# image repositories (so Deployments fell back to the chart-default
# `duocthu-*:local`, which exists in no registry) and `authService`/
# `apiGateway` `enabled: true` (so neither was ever created).
#
# Therefore:
# - Do NOT put comments in the inline values. Explain things here instead;
# this file is version-controlled and no text box can mangle it.
# - Prefer the API over the UI for edits — see
# .github/scripts/repair_argocd_inline_values.py, which reads the live
# object, edits the string, and PUTs it back with the structure intact.
# - After ANY inline edit, verify with
# `.github/workflows/inspect-argocd-app.yml`: it dumps the raw string one
# escaped line at a time, which is the only view that reveals where the
# newlines actually are. The pretty-printed view looked almost correct
# throughout the outage.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata: