apiVersion: apps/v1 kind: Deployment metadata: name: api namespace: foxhunt labels: app.kubernetes.io/name: api app.kubernetes.io/part-of: foxhunt spec: replicas: 1 strategy: type: RollingUpdate rollingUpdate: maxSurge: 0 maxUnavailable: 1 selector: matchLabels: app.kubernetes.io/name: api template: metadata: annotations: prometheus.io/scrape: "true" prometheus.io/port: "9091" prometheus.io/path: "/metrics" labels: app.kubernetes.io/name: api app.kubernetes.io/part-of: foxhunt spec: serviceAccountName: api securityContext: runAsNonRoot: true runAsUser: 1000 runAsGroup: 1000 fsGroup: 1000 seccompProfile: type: RuntimeDefault imagePullSecrets: - name: gitlab-registry nodeSelector: k8s.scaleway.com/pool-name: platform initContainers: - name: fetch-binary image: gitlab-registry.foxhunt.svc.cluster.local:5000/root/foxhunt/foxhunt-runtime:latest command: ["/bin/sh", "-c"] args: - | set -e BINARY="api" curl -fSL -o "/binaries/${BINARY}" \ --header "DEPLOY-TOKEN: ${GITLAB_DEPLOY_TOKEN}" \ "${GITLAB_API}/projects/1/packages/generic/foxhunt-services/${FOXHUNT_RELEASE}/${BINARY}" chmod +x "/binaries/${BINARY}" echo "Fetched ${BINARY} ${FOXHUNT_RELEASE} ($(stat -c%s /binaries/${BINARY}) bytes)" env: - name: GITLAB_DEPLOY_TOKEN valueFrom: secretKeyRef: name: gitlab-deploy-token key: token - name: GITLAB_API value: "http://gitlab-webservice-default.foxhunt.svc.cluster.local:8181/api/v4" - name: FOXHUNT_RELEASE value: "latest" volumeMounts: - name: binaries mountPath: /binaries resources: requests: cpu: 100m memory: 64Mi limits: cpu: 500m memory: 128Mi containers: - name: api image: gitlab-registry.foxhunt.svc.cluster.local:5000/root/foxhunt/foxhunt-runtime:latest securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: ["ALL"] command: ["/binaries/api"] ports: - containerPort: 50051 name: grpc - containerPort: 9091 name: metrics env: - name: DATABASE_PASSWORD valueFrom: secretKeyRef: name: db-credentials key: password - name: DATABASE_URL value: "postgresql://foxhunt:$(DATABASE_PASSWORD)@postgres:5432/foxhunt" - name: REDIS_URL value: "redis://redis:6379" - name: JWT_SECRET valueFrom: secretKeyRef: name: jwt-secret key: secret - name: JWT_ISSUER value: foxhunt-api - name: JWT_AUDIENCE value: foxhunt-services - name: TRADING_SERVICE_URL value: "http://trading-service:50051" - name: BACKTESTING_SERVICE_URL value: "http://backtesting-service:50053" - name: ML_TRAINING_SERVICE_URL value: "http://ml-training-service:50053" - name: TRADING_AGENT_SERVICE_URL value: "http://trading-agent-service:50055" - name: BROKER_GATEWAY_SERVICE_URL value: "http://broker-gateway:50056" - name: DATA_ACQUISITION_SERVICE_URL value: "http://data-acquisition-service:50057" - name: ML_SERVICE_URL value: "http://trading-service:50051" - name: PROMETHEUS_URL value: "http://prometheus-stack-kube-prom-prometheus:9090" - name: RUST_LOG value: "info,opentelemetry=warn,h2=warn,tonic=warn,hyper=warn" - name: OTEL_EXPORTER_OTLP_ENDPOINT value: "http://tempo.foxhunt.svc.cluster.local:4317" - name: CORS_ORIGINS value: "https://dashboard.fxhnt.ai,http://localhost:5173" volumeMounts: - name: binaries mountPath: /binaries readOnly: true - name: tmp mountPath: /tmp readinessProbe: exec: command: - grpc_health_probe - -addr=localhost:50051 initialDelaySeconds: 10 periodSeconds: 10 livenessProbe: exec: command: - grpc_health_probe - -addr=localhost:50051 initialDelaySeconds: 30 periodSeconds: 15 failureThreshold: 5 resources: requests: cpu: 200m memory: 256Mi limits: cpu: 500m memory: 512Mi volumes: - name: binaries emptyDir: sizeLimit: 200Mi - name: tmp emptyDir: sizeLimit: 50Mi --- apiVersion: v1 kind: Service metadata: name: api namespace: foxhunt labels: app.kubernetes.io/name: api app.kubernetes.io/part-of: foxhunt spec: selector: app.kubernetes.io/name: api ports: - port: 50051 targetPort: 50051 name: grpc - port: 9091 targetPort: 9091 name: metrics --- apiVersion: v1 kind: ServiceAccount metadata: name: api namespace: foxhunt labels: app.kubernetes.io/name: api app.kubernetes.io/part-of: foxhunt --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: api-pod-reader namespace: foxhunt rules: - apiGroups: [""] resources: [pods] verbs: [get, list, watch] - apiGroups: [metrics.k8s.io] resources: [pods] verbs: [get, list] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: api-pod-reader namespace: foxhunt roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: api-pod-reader subjects: - kind: ServiceAccount name: api namespace: foxhunt