Files
foxhunt/infra/k8s/services/ib-gateway.yaml
jgrusewski 68b6aa8313 feat(infra): migrate container registry from SCW to internal GitLab
Full migration off Scaleway Container Registry to internal GitLab
registry backed by MinIO S3. All 4 images (ci-builder, ci-builder-cpu,
foxhunt-runtime, foxhunt-training-runtime) rebuilt in internal registry.

Registry & images:
- All image refs → gitlab-registry.foxhunt.svc.cluster.local:5000/root/foxhunt/
- imagePullSecrets: scw-registry → gitlab-registry
- Kaniko build template: two-step DAG (git-clone → kaniko-build) with shared PVC
- Kaniko layer cache enabled at root/foxhunt/cache
- AWS_ACCESS_KEY_ID: $SCW_ACCESS_KEY → $MINIO_ACCESS_KEY in .gitlab-ci.yml

Network policies:
- ci-pipeline: add HTTP/80, registry/5000, webservice/8181 egress rules

DNS & Tailscale proxy cleanup:
- Remove ci, prometheus, monitor DNS records (no longer exposed)
- Rename s3 → minio DNS record
- Remove Argo UI, Prometheus, monitor nginx server blocks
- Remove argo-htpasswd volume mount
- Tailscale proxy nodeSelector: infra → platform

Terraform cleanup:
- Delete infra/modules/registry/ (SCW CR namespace)
- Delete infra/modules/object-storage/ (SCW S3 buckets)
- Delete infra/modules/secrets/ (SCW secrets)
- Delete corresponding live configs
- TF state backend: S3 → GitLab HTTP

Argo workflows:
- Add events/ (GitLab push eventsource + ci-pipeline sensor)
- ci-pipeline + training templates: SCW → internal registry
- Delete obsolete compile-training-template.yaml

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 13:52:24 +01:00

113 lines
2.8 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: ib-gateway
namespace: foxhunt
labels:
app: ib-gateway
app.kubernetes.io/part-of: foxhunt
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app: ib-gateway
template:
metadata:
labels:
app: ib-gateway
app.kubernetes.io/part-of: foxhunt
spec:
securityContext:
seccompProfile:
type: RuntimeDefault
imagePullSecrets:
- name: gitlab-registry
nodeSelector:
k8s.scaleway.com/pool-name: foxhunt
containers:
- name: ib-gateway
image: ghcr.io/gnzsnz/ib-gateway:stable
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
ports:
- name: tws-api
containerPort: 4002
protocol: TCP
- name: tws-api-socat
containerPort: 4004
protocol: TCP
- name: vnc
containerPort: 5900
protocol: TCP
env:
- name: TWS_USERID
valueFrom:
secretKeyRef:
name: ibkr-credentials
key: username
- name: TWS_PASSWORD
valueFrom:
secretKeyRef:
name: ibkr-credentials
key: password
- name: TRADING_MODE
value: "paper"
- name: TWS_ACCEPT_INCOMING
value: "accept"
- name: READ_ONLY_API
value: "no"
- name: TWOFA_TIMEOUT_ACTION
value: "restart"
- name: EXISTING_SESSION_DETECTED_ACTION
value: "primaryoverride"
- name: VNC_SERVER_PASSWORD
valueFrom:
secretKeyRef:
name: ibkr-credentials
key: vnc-password
optional: true
resources:
requests:
memory: "1Gi"
cpu: "500m"
limits:
memory: "2Gi"
cpu: "1000m"
readinessProbe:
tcpSocket:
port: 4002
initialDelaySeconds: 90
periodSeconds: 10
livenessProbe:
tcpSocket:
port: 4002
initialDelaySeconds: 120
periodSeconds: 30
failureThreshold: 5
---
apiVersion: v1
kind: Service
metadata:
name: ib-gateway
namespace: foxhunt
labels:
app: ib-gateway
spec:
selector:
app: ib-gateway
ports:
- name: tws-api
port: 4002
targetPort: 4002
- name: tws-api-socat
port: 4004
targetPort: 4004
- name: vnc
port: 5900
targetPort: 5900
type: ClusterIP