Stop mislabeling the Compose box as production in read-only audits
This commit is contained in:
@@ -1,61 +0,0 @@
|
||||
# Production values for the eventual ArgoCD cutover of realvuxbaro.me.
|
||||
#
|
||||
# Not live yet: production still runs Docker Compose on its own EC2, which is
|
||||
# the DNS-level rollback for the migration. This file is what the production
|
||||
# ArgoCD Application will render from once the rehearsal gates pass.
|
||||
#
|
||||
# The behavioural settings mirror the production runtime contract audited on
|
||||
# 2026-08-17 — see coordination/ARGOCD_PRODUCTION_MIGRATION_STATE_2026-08-17.md.
|
||||
|
||||
global:
|
||||
environment: production
|
||||
# The GHCR packages are private, same as on the practice cluster. The Secret
|
||||
# must exist in the target namespace before the first sync.
|
||||
imagePullSecrets:
|
||||
- name: ghcr-pull-secret
|
||||
|
||||
aiService:
|
||||
replicaCount: 2
|
||||
image:
|
||||
repository: ghcr.io/baovu2k4/vsf-duocthu-ai-service
|
||||
# Deliberately empty. Production must run an immutable, verifiable image,
|
||||
# so the tag is supplied per deploy as a commit SHA — through the ArgoCD
|
||||
# Application's inline values, exactly as the practice cluster does. A
|
||||
# `latest` here would make "which code is production running?" unanswerable
|
||||
# and would break rollback, since the same tag would point at new content.
|
||||
#
|
||||
# `medical-chatbot.image` turns this empty value into a hard render error
|
||||
# rather than a silent fallback to the chart's `local` development tag.
|
||||
tag: ""
|
||||
pullPolicy: Always
|
||||
config:
|
||||
embeddingProvider: cohere-v4
|
||||
embeddingDimensions: 1024
|
||||
evidenceMinimumScore: 0.12
|
||||
awsRegion: us-east-1
|
||||
answerProvider: bedrock-converse
|
||||
answerModelId: qwen.qwen3-next-80b-a3b
|
||||
rerankEnabled: true
|
||||
otelSampleRatio: 0.25
|
||||
|
||||
web:
|
||||
replicaCount: 2
|
||||
image:
|
||||
repository: ghcr.io/baovu2k4/vsf-duocthu-web
|
||||
tag: ""
|
||||
pullPolicy: Always
|
||||
|
||||
ingress:
|
||||
enabled: true
|
||||
host: realvuxbaro.me
|
||||
|
||||
secret:
|
||||
create: false
|
||||
existingSecret: medical-chatbot-prod
|
||||
|
||||
observability:
|
||||
prometheus:
|
||||
retention: 15d
|
||||
|
||||
serviceMonitor:
|
||||
enabled: false
|
||||
+3
-3
@@ -1,6 +1,6 @@
|
||||
# k3s practice cluster — the `medical-chatbot-data` release.
|
||||
# Production — the `medical-chatbot-data` release (PostgreSQL + Qdrant).
|
||||
#
|
||||
# Companion to values-practice.yaml. The practice cluster deliberately splits
|
||||
# Companion to values-production.yaml. The practice cluster deliberately splits
|
||||
# the chart into two ArgoCD Applications so that PostgreSQL and Qdrant survive
|
||||
# every app rollout, prune and self-heal: only this release owns the
|
||||
# PersistentVolumeClaims, so an app-side sync failure can never delete the
|
||||
@@ -13,7 +13,7 @@
|
||||
# image tag that CI rewrites and no secret, so it is fully tracked in Git.
|
||||
|
||||
global:
|
||||
environment: k3s-practice
|
||||
environment: production
|
||||
|
||||
aiService:
|
||||
enabled: false
|
||||
+3
-3
@@ -1,7 +1,7 @@
|
||||
# k3s practice cluster — the `medical-chatbot-app` release.
|
||||
# Production — the `medical-chatbot-app` release serving realvuxbaro.me.
|
||||
#
|
||||
# This file is the Git source of truth for every stable, non-secret setting of
|
||||
# the practice rehearsal environment. It exists because the same values used to
|
||||
# this cluster. It exists because the same values used to
|
||||
# live only inside the ArgoCD Application's inline `spec.source.helm.values`,
|
||||
# where they were invisible to review, diff and rollback: the cluster could
|
||||
# drift from the repository without a single commit recording it. That is how
|
||||
@@ -25,7 +25,7 @@
|
||||
# Practice is only useful as a migration rehearsal while they stay in sync.
|
||||
|
||||
global:
|
||||
environment: k3s-practice
|
||||
environment: production
|
||||
# The GHCR packages are private; without this the Pods fail ImagePullBackOff.
|
||||
imagePullSecrets:
|
||||
- name: ghcr-pull-secret
|
||||
Reference in New Issue
Block a user