Full migration off Scaleway Container Registry to internal GitLab registry backed by MinIO S3. All 4 images (ci-builder, ci-builder-cpu, foxhunt-runtime, foxhunt-training-runtime) rebuilt in internal registry. Registry & images: - All image refs → gitlab-registry.foxhunt.svc.cluster.local:5000/root/foxhunt/ - imagePullSecrets: scw-registry → gitlab-registry - Kaniko build template: two-step DAG (git-clone → kaniko-build) with shared PVC - Kaniko layer cache enabled at root/foxhunt/cache - AWS_ACCESS_KEY_ID: $SCW_ACCESS_KEY → $MINIO_ACCESS_KEY in .gitlab-ci.yml Network policies: - ci-pipeline: add HTTP/80, registry/5000, webservice/8181 egress rules DNS & Tailscale proxy cleanup: - Remove ci, prometheus, monitor DNS records (no longer exposed) - Rename s3 → minio DNS record - Remove Argo UI, Prometheus, monitor nginx server blocks - Remove argo-htpasswd volume mount - Tailscale proxy nodeSelector: infra → platform Terraform cleanup: - Delete infra/modules/registry/ (SCW CR namespace) - Delete infra/modules/object-storage/ (SCW S3 buckets) - Delete infra/modules/secrets/ (SCW secrets) - Delete corresponding live configs - TF state backend: S3 → GitLab HTTP Argo workflows: - Add events/ (GitLab push eventsource + ci-pipeline sensor) - ci-pipeline + training templates: SCW → internal registry - Delete obsolete compile-training-template.yaml Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
113 lines
2.8 KiB
YAML
113 lines
2.8 KiB
YAML
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: ib-gateway
|
|
namespace: foxhunt
|
|
labels:
|
|
app: ib-gateway
|
|
app.kubernetes.io/part-of: foxhunt
|
|
spec:
|
|
replicas: 1
|
|
strategy:
|
|
type: Recreate
|
|
selector:
|
|
matchLabels:
|
|
app: ib-gateway
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: ib-gateway
|
|
app.kubernetes.io/part-of: foxhunt
|
|
spec:
|
|
securityContext:
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
imagePullSecrets:
|
|
- name: gitlab-registry
|
|
nodeSelector:
|
|
k8s.scaleway.com/pool-name: foxhunt
|
|
containers:
|
|
- name: ib-gateway
|
|
image: ghcr.io/gnzsnz/ib-gateway:stable
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop: ["ALL"]
|
|
ports:
|
|
- name: tws-api
|
|
containerPort: 4002
|
|
protocol: TCP
|
|
- name: tws-api-socat
|
|
containerPort: 4004
|
|
protocol: TCP
|
|
- name: vnc
|
|
containerPort: 5900
|
|
protocol: TCP
|
|
env:
|
|
- name: TWS_USERID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ibkr-credentials
|
|
key: username
|
|
- name: TWS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ibkr-credentials
|
|
key: password
|
|
- name: TRADING_MODE
|
|
value: "paper"
|
|
- name: TWS_ACCEPT_INCOMING
|
|
value: "accept"
|
|
- name: READ_ONLY_API
|
|
value: "no"
|
|
- name: TWOFA_TIMEOUT_ACTION
|
|
value: "restart"
|
|
- name: EXISTING_SESSION_DETECTED_ACTION
|
|
value: "primaryoverride"
|
|
- name: VNC_SERVER_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: ibkr-credentials
|
|
key: vnc-password
|
|
optional: true
|
|
resources:
|
|
requests:
|
|
memory: "1Gi"
|
|
cpu: "500m"
|
|
limits:
|
|
memory: "2Gi"
|
|
cpu: "1000m"
|
|
readinessProbe:
|
|
tcpSocket:
|
|
port: 4002
|
|
initialDelaySeconds: 90
|
|
periodSeconds: 10
|
|
livenessProbe:
|
|
tcpSocket:
|
|
port: 4002
|
|
initialDelaySeconds: 120
|
|
periodSeconds: 30
|
|
failureThreshold: 5
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: ib-gateway
|
|
namespace: foxhunt
|
|
labels:
|
|
app: ib-gateway
|
|
spec:
|
|
selector:
|
|
app: ib-gateway
|
|
ports:
|
|
- name: tws-api
|
|
port: 4002
|
|
targetPort: 4002
|
|
- name: tws-api-socat
|
|
port: 4004
|
|
targetPort: 4004
|
|
- name: vnc
|
|
port: 5900
|
|
targetPort: 5900
|
|
type: ClusterIP
|