atlas-iac/services/hermes/suite-planner-deployment.yaml

174 lines
6.4 KiB
YAML

# services/hermes/suite-planner-deployment.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: hermes-suite-planner
namespace: hermes
automountServiceAccountToken: false
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: hermes-suite-metadata
namespace: hermes
spec:
accessModes: [ReadWriteOnce]
storageClassName: local-path
resources:
requests:
storage: 1Gi
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hermes-suite-planner
namespace: hermes
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app: hermes-suite-planner
template:
metadata:
labels:
app: hermes-suite-planner
annotations:
fluentbit.io/exclude: "true"
ai.bstein.dev/config-rev: suite-v3-20260929
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-run-as-user: "10000"
vault.hashicorp.com/agent-run-as-group: "10000"
vault.hashicorp.com/agent-service-account-token-volume-name: vault-auth
vault.hashicorp.com/role: hermes-suite-planner
vault.hashicorp.com/agent-inject-containers: planner
vault.hashicorp.com/agent-inject-secret-token: kv/data/atlas/hermes/suite-planning-api
vault.hashicorp.com/agent-inject-template-token: |
{{- with secret "kv/data/atlas/hermes/suite-planning-api" -}}
{{ .Data.data.token }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-synthetic-token: kv/data/atlas/hermes/suite-planning-api
vault.hashicorp.com/agent-inject-template-synthetic-token: |
{{- with secret "kv/data/atlas/hermes/suite-planning-api" -}}
{{ .Data.data.synthetic_token }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-local-token: kv/data/atlas/hermes/model-gate-lan-api
vault.hashicorp.com/agent-inject-template-local-token: |
{{- with secret "kv/data/atlas/hermes/model-gate-lan-api" -}}
{{ .Data.data.token }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-claude-token: kv/data/atlas/hermes/agent-tokens
vault.hashicorp.com/agent-inject-template-claude-token: |
{{- with secret "kv/data/atlas/hermes/agent-tokens" -}}
{{ .Data.data.claude_oauth_token }}
{{- end -}}
vault.hashicorp.com/agent-inject-perms-token: "0400"
vault.hashicorp.com/agent-inject-perms-synthetic-token: "0400"
vault.hashicorp.com/agent-inject-perms-local-token: "0400"
vault.hashicorp.com/agent-inject-perms-claude-token: "0400"
spec:
serviceAccountName: hermes-suite-planner
automountServiceAccountToken: false
enableServiceLinks: false
terminationGracePeriodSeconds: 15
# The installed amd64 CLI is copied from the existing RWO tools volume.
nodeSelector:
kubernetes.io/hostname: titan-22
securityContext:
runAsNonRoot: true
runAsUser: 10000
runAsGroup: 10000
fsGroup: 10000
fsGroupChangePolicy: OnRootMismatch
seccompProfile:
type: RuntimeDefault
initContainers:
- name: stage-cli
image: python:3.13-slim@sha256:9662417aace5ae7b8e2609cce472b72a8958e134ba372808abe9cc1a0c0125e6
command: [python, -c]
args:
- |
import hashlib,pathlib,shutil
source=pathlib.Path('/installed/lib/node_modules/@anthropic-ai/claude-code/bin/claude.exe')
assert hashlib.sha256(source.read_bytes()).hexdigest() == '4e9bec1177ce9690e8bd988b710ac24105e70da428dd094c5adcbbe786a55555'
shutil.copyfile(source, '/opt/cli/claude')
pathlib.Path('/opt/cli/claude').chmod(0o555)
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: [ALL]
volumeMounts:
- {name: installed, mountPath: /installed, subPath: tools, readOnly: true}
- {name: cli, mountPath: /opt/cli}
resources:
requests: {cpu: 25m, memory: 256Mi}
limits: {cpu: "1", memory: 1Gi}
containers:
- name: planner
image: python:3.13-slim@sha256:9662417aace5ae7b8e2609cce472b72a8958e134ba372808abe9cc1a0c0125e6
command: [python, /opt/planner/suite_api.py]
env:
- {name: PYTHONDONTWRITEBYTECODE, value: "1"}
- {name: PYTHONUNBUFFERED, value: "1"}
- {name: PLANNING_CLAUDE_SHA256, value: 4e9bec1177ce9690e8bd988b710ac24105e70da428dd094c5adcbbe786a55555}
ports:
- {name: http, containerPort: 9000}
- {name: decision, containerPort: 9001}
readinessProbe:
httpGet: {path: /healthz, port: decision}
livenessProbe:
httpGet: {path: /healthz, port: decision}
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: [ALL]
volumeMounts:
- {name: scripts, mountPath: /opt/planner, readOnly: true}
- {name: cli, mountPath: /opt/cli, readOnly: true}
- {name: jobs, mountPath: /jobs}
- {name: tmp, mountPath: /tmp}
- {name: state, mountPath: /state}
resources:
requests: {cpu: 100m, memory: 512Mi}
limits: {cpu: "2", memory: 2Gi}
volumes:
- name: scripts
configMap:
name: hermes-suite-planner
- name: installed
persistentVolumeClaim:
claimName: hermes-agent-home
readOnly: true
- name: cli
emptyDir: {medium: Memory, sizeLimit: 512Mi}
- name: jobs
emptyDir: {medium: Memory, sizeLimit: 512Mi}
- name: tmp
emptyDir: {medium: Memory, sizeLimit: 64Mi}
- name: state
persistentVolumeClaim:
claimName: hermes-suite-metadata
- name: vault-auth
projected:
sources:
- serviceAccountToken:
path: token
expirationSeconds: 600
---
apiVersion: v1
kind: Service
metadata:
name: hermes-suite-planner
namespace: hermes
spec:
selector:
app: hermes-suite-planner
ports:
- {name: http, port: 9000, targetPort: http}
- {name: decision, port: 9001, targetPort: decision}