74 lines
2.3 KiB
YAML

# clusters/atlas/flux-system/applications/hermes/kustomization.yaml
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: hermes
namespace: flux-system
annotations:
kustomize.toolkit.fluxcd.io/ssa: Merge
spec:
interval: 10m
path: ./services/hermes
targetNamespace: hermes
prune: true
sourceRef:
kind: GitRepository
name: flux-system
namespace: flux-system
wait: false
timeout: 10m
healthChecks:
- apiVersion: apps/v1
kind: Deployment
name: hermes-model-gate
namespace: hermes
- apiVersion: apps/v1
kind: Deployment
name: hermes-switchyard
namespace: hermes
- apiVersion: apps/v1
kind: Deployment
name: hermes-suite-planner
namespace: hermes
- apiVersion: apps/v1
kind: Deployment
name: hermes-agent
namespace: hermes
# hermes-execution-worker and its mediators are deliberately absent. They run
# at scavenger priority on a best-effort pool whose first start installs the
# provider CLIs, so gating this Kustomization's 10m health window on them
# would stall hermes-chat and hermes-observer-bindings, which dependsOn
# hermes. The pool reports its own health through the worker readiness probe,
# the per-ordinal mediator /ready endpoint, and the coordinator on :9007.
# The node SSH hardener is deliberately absent. It reconciles every node,
# including offline and maintenance hosts, so its availability must not
# turn a node-local account issue into a blocked owner-service rollout.
- apiVersion: apps/v1
kind: Deployment
name: hermes
namespace: hermes
- apiVersion: apps/v1
kind: StatefulSet
name: hermes-chat-tenant
namespace: hermes
- apiVersion: apps/v1
kind: Deployment
name: hermes-chat-router
namespace: hermes
- apiVersion: apps/v1
kind: Deployment
name: oauth2-proxy-hermes-chat
namespace: hermes
- apiVersion: apps/v1
kind: Deployment
name: oauth2-proxy-hermes-triage
namespace: hermes
dependsOn:
- name: cert-manager
- name: core
- name: keycloak
- name: longhorn
- name: vault
# CI availability must not block recovery of the inference services.
- name: hermes-observer-rbac