deploy/helm/sentry/templates/api.yaml and the new enterprise-api.yaml
are mutually exclusive, gated on opposite sides of the same
enterprise.enabled flag -- exactly one renders, both as a Deployment+
Service named {{ .Release.Name }}-api on port 8080, so every consumer
(alerting's API_QUERY_URL, web's build args) needs zero conditional
logic of its own. This is the concrete fix for what the threat model
named as the single largest remaining gap once both storage engines'
isolation mechanisms were built: previously nothing forced or flagged
whether a deployment ran the tenant-isolated binary. Now the same flag
that turns on RBAC/audit/SSO also chooses the query binary.
Verified by parsing (not eyeballing) helm template's rendered output
under both value sets: exactly one sentry-api Deployment/Service either
way, with the right image, and kubeconform -strict clean against the
real Kubernetes 1.31 schema. Not applied to a live cluster (still no
cluster in this environment) -- docker-compose.yml also still runs
plain api unconditionally, so this enforcement is Helm-only for now.
Updated the threat model, architecture doc, CLAUDE.md, and deploy/
READMEs to reflect this and to name what's left: ingest has no tenant
concept for either storage engine (undesigned), and the Tenant CRD
(deploy/operator) and enterprise-api -provision-tenant are still two
separate, unreconciled provisioning mechanisms.
87 lines
3.3 KiB
YAML
87 lines
3.3 KiB
YAML
{{/*
|
|
Mutually exclusive with enterprise-api.yaml's Deployment+Service, gated
|
|
the opposite way -- see that file's doc comment for why: "does a
|
|
deployment run the tenant-isolated binary or not" should be a single
|
|
values.yaml decision (enterprise.enabled), not two independently
|
|
driftable ones. Both render a Service named {{ .Release.Name }}-api on
|
|
port 8080, so every consumer (alerting's API_QUERY_URL, web's build
|
|
args) needs zero conditional logic of its own.
|
|
*/}}
|
|
{{- if not .Values.enterprise.enabled }}
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: {{ .Release.Name }}-api
|
|
labels:
|
|
{{- include "sentry.labels" . | nindent 4 }}
|
|
{{- include "sentry.selectorLabels" (list $ "api") | nindent 4 }}
|
|
spec:
|
|
replicas: {{ .Values.api.replicas }}
|
|
selector:
|
|
matchLabels:
|
|
{{- include "sentry.selectorLabels" (list $ "api") | nindent 6 }}
|
|
template:
|
|
metadata:
|
|
labels:
|
|
{{- include "sentry.selectorLabels" (list $ "api") | nindent 8 }}
|
|
spec:
|
|
initContainers:
|
|
{{- include "sentry.waitForTCP" (list "clickhouse" (printf "%s-clickhouse" .Release.Name) "9000") | nindent 8 }}
|
|
{{- include "sentry.waitForTCP" (list "postgres" (printf "%s-postgres" .Release.Name) "5432") | nindent 8 }}
|
|
{{- include "sentry.waitForTCP" (list "search" (printf "%s-search" .Release.Name) "50052") | nindent 8 }}
|
|
containers:
|
|
- name: api
|
|
image: "{{ .Values.api.image.repository }}:{{ .Values.api.image.tag }}"
|
|
imagePullPolicy: {{ .Values.global.imagePullPolicy }}
|
|
env:
|
|
- name: CLICKHOUSE_ADDR
|
|
value: "{{ .Release.Name }}-clickhouse:9000"
|
|
- name: CLICKHOUSE_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: {{ .Release.Name }}-clickhouse
|
|
key: password
|
|
- name: SEARCH_GRPC_ADDR
|
|
value: "{{ .Release.Name }}-search:50052"
|
|
- name: POSTGRES_ADDR
|
|
value: "{{ .Release.Name }}-postgres:5432"
|
|
- name: POSTGRES_DATABASE
|
|
value: sentry_metadata
|
|
- name: POSTGRES_USERNAME
|
|
value: sentry
|
|
- name: POSTGRES_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: {{ .Release.Name }}-postgres
|
|
key: password
|
|
# No ENTERPRISE_AUTH_URL here -- this file only renders when
|
|
# enterprise.enabled is false (see the top of this file), so
|
|
# authz.RequireRole*/RequireRoleOrService stay a permanent
|
|
# no-op for this Deployment. enterprise-api.yaml is where
|
|
# that enforcement actually turns on.
|
|
ports:
|
|
- name: http
|
|
containerPort: 8080
|
|
readinessProbe:
|
|
exec:
|
|
command: ["/api", "-healthcheck"]
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
resources:
|
|
{{- toYaml .Values.api.resources | nindent 12 }}
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: {{ .Release.Name }}-api
|
|
labels:
|
|
{{- include "sentry.labels" . | nindent 4 }}
|
|
{{- include "sentry.selectorLabels" (list $ "api") | nindent 4 }}
|
|
spec:
|
|
selector:
|
|
{{- include "sentry.selectorLabels" (list $ "api") | nindent 4 }}
|
|
ports:
|
|
- name: http
|
|
port: 8080
|
|
{{- end }}
|