Enable auth-service/api-gateway on production, build their images in CI

This commit is contained in:
2026-08-18 14:11:00 +07:00
parent e5afedfa2f
commit b68005be1c
70 changed files with 6781 additions and 263 deletions
@@ -0,0 +1,51 @@
# Tracked copy of the live `medical-chatbot-app` Application (k3s, personal
# ArgoCD instance at argocd.realvuxbaro.me). Verified against the live object
# 2026-08-18 — every field below matches `status.sync.status: Synced`,
# `status.health.status: Healthy`.
#
# This Application serves BOTH realvuxbaro.me and readytochat.realvuxbaro.me
# (same release, same Pods) since the 2026-08-17 cutover.
#
# Deliberately NOT reproduced here: `spec.source.helm.values`. The live
# Application carries two things inline that must never live in Git:
#
# - aiService.image.tag / web.image.tag — rewritten on every push by
# .github/scripts/sync_practice_argocd.py (or by rollback-k3s.yml for a
# rollback). A tag committed here would go stale the moment CI runs again,
# and applying this file naively would silently roll the running image
# back to whatever tag happened to be in Git.
# - secret.grafanaAdminPassword — a real credential. It must never enter
# Git history. It belongs in a proper Kubernetes Secret referenced via
# `secret.existingSecret` (see infra/helm/medical-chatbot/values.yaml),
# not inline on the Application — that migration hasn't been done yet
# (it needs cluster write access this repo's automation doesn't have).
#
# Applying this file (`argocd app create -f` or the ArgoCD UI) recreates the
# Application's STRUCTURE — source, destination, sync policy — for disaster
# recovery. It does NOT restore the current image tag or the Grafana
# password: set the tag afterward via `rollback-k3s.yml` (target_sha = the
# last known-good commit) and re-enter the Grafana password by hand.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: medical-chatbot-app
namespace: argocd
spec:
project: default
source:
repoURL: https://github.com/BaoVu2k4/vsf-duocthu.git
targetRevision: master
path: infra/helm/medical-chatbot
helm:
valueFiles:
- values.yaml
- values-production.yaml
destination:
server: https://kubernetes.default.svc
namespace: medical-chatbot-app
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true
@@ -0,0 +1,39 @@
# Tracked copy of the live `medical-chatbot-data` Application (k3s, personal
# ArgoCD instance at argocd.realvuxbaro.me). Verified against the live object
# 2026-08-18 — every field below matches `status.sync.status: Synced`,
# `status.health.status: Healthy`.
#
# Owns PostgreSQL and Qdrant only (the 15,100-point corpus and query
# history). Deliberately a separate Application from medical-chatbot-app so
# that an app-side sync failure, prune, or rollback can never delete the
# PersistentVolumeClaims — see values-production-data.yaml.
#
# Unlike medical-chatbot-app, the live Application carries no inline
# `spec.source.helm.values` at all: this release has no image tag CI rewrites
# and no secret, so it is already fully represented by this file plus
# values.yaml + values-production-data.yaml. Applying this file for disaster
# recovery needs no follow-up step.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: medical-chatbot-data
namespace: argocd
spec:
project: default
source:
repoURL: https://github.com/BaoVu2k4/vsf-duocthu.git
targetRevision: master
path: infra/helm/medical-chatbot
helm:
valueFiles:
- values.yaml
- values-production-data.yaml
destination:
server: https://kubernetes.default.svc
namespace: medical-chatbot-data
syncPolicy:
automated:
prune: true
selfHeal: true
syncOptions:
- CreateNamespace=true