Repository navigation
Conversation
Templates agent-service's own deploy/k8s/{app,proxy,networkpolicy}.yaml raw manifests
into a Helm chart (no redesign — same two-plane split, security contexts, resource
limits, health probes, NetworkPolicy rules), wires it into Argo staging/production
via a dedicated agent-service namespace, and adds a public ingress entry for
agent-app only (never agent-proxy, which holds the real model credential).
See the PR description for the open decisions this introduces (first NetworkPolicy
in the repo, first non-experiment namespace, NetworkPolicy-enforcement caveat on
stock EKS, the two Secrets that need to exist before first sync).
Adversarial review caught two real issues: - app.port was a values.yaml/schema knob that moved every K8s-side reference (containerPort, both probes, the Service, the NetworkPolicy) but never reached the container itself — the image's CMD hardcodes --port 8731 with no PORT env var read. An override would have silently broken readiness forever. Now passes an explicit command:, matching proxy's own pattern. - agent-app has no Ingress-direction NetworkPolicy, which is new exposure this PR introduces (the raw manifests never had a public Ingress in front of it). A podSelector rule wouldn't actually restrict ALB traffic anyway (target-type: ip traffic doesn't carry a matchable pod identity) — documented that the real gate is the ALB's own Security Group, not something this chart can enforce, so nobody mistakes an absent policy for an oversight.
…orepo move
image.repository was still ghcr.io/REPLACE_ME/agent-service. agent-service's
release workflow (now living in aipotluck.org's own .github/workflows/,
after the monorepo merge) hardcodes ghcr.io/currentai-org/agent-service
rather than relying on ${{ github.repository }} — this chart needs to
match that exact string.
Also notes in the README that agent-service is now a subdirectory of
currentai-org/aipotluck.org, not its own standalone repo, so the
deploy/README.md and deploy/k8s/*.yaml paths this README points at are
relative to that repo's root.
…e agent-service with external secrets integration
…agent-service/argo-gitops # Conflicts: # charts/agent-service/values.yaml
…st` instead of GitHub registry
…del configurations
…ainer info, and adjust image pull policy
…s, update `command-a-plus` routing
… `access_groups` and routing parameters
…nt and secrets templates
…, Qwen-SEA-LION, and Apertus-v1.5 with `access_groups` and API details
…ups` and API details
…ment, creation, and deletion events in staging apps
…org models with `access_groups` and API details
…mmented configurations for swiss-ai Apertus-v1.5-70b
…pdate staging/default values
…l --dry-run` with `helm template`
…lds configurable in Helm chart
…tartupProbe defaults
…itMigration and update default values
…uration and update configmap template
…nce, and Traefik pollInterval configurability in Helm chart
… secrets in Helm chart
…_API_KEY support in Helm chart
…h check for AWS NLB in staging
…e official dashboard for Kubernetes
…ki compatibility and update Grafana dashboard queries
…re BEDROCK_API_KEY in Helm chart
…configuration in Helm chart
…N-v4.5-27B-IT model configurations with API key support in Helm chart
…ct access for multiple Qwen models, and add Bielik model support with API key configuration in Helm chart
…ation and database name override in Helm chart
…ghcr.io location and version
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.