Prod Keycloak manifests, graceful-swap checklist, and runbook image swap via apply - #485
Open
chrisdoehring wants to merge 2 commits into
Open
chrisdoehring wants to merge 2 commits into
chrisdoehring wants to merge 2 commits into
Conversation
…ul swap Records the fix for the outage seen on the 2026-09-28 image swap: a BackendConfig with a 5 s health check and 30 s draining, a 5 s readiness probe, a preStop sleep and a 60 s grace period. Also covers moving the Deployment's credentials into a Secret, exporting the live objects with kubectl neat as the manifest of record, and a one-hour theme cache lifetime so theme changes reach browsers without a hard reload. Status as of 2026-09-30: everything is applied except step 5b (probe period and cache lifetime), which is prepared in the manifest and waits for the next restart window. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
keycloak/prod/ holds the live Deployment, Service and BackendConfig for cdip-prod01/cdip-auth, exported with kubectl neat and stripped of cluster-owned fields. Credentials are secretKeyRef entries against the keycloak-credentials Secret, which stays out of git. The README covers the diff-then-apply workflow with server-side apply and when to force conflicts. The runbook's image swap now edits deployment.yaml and applies it instead of kubectl set image, so the files cannot drift from prod, and its health check expects 200 or 400 depending on the client's redirect list. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
keycloak/prod/: the live prod Keycloak 11 Deployment, Service and BackendConfig forcdip-prod01/cdip-auth, exported withkubectl neatand stripped of cluster-owned fields. Credentials aresecretKeyRefentries against thekeycloak-credentialsSecret, which stays out of git. The README covers the diff-then-apply workflow with server-side apply, when to force conflicts, and why each value is set.keycloak/RUNBOOK.md: the image-swap step now editskeycloak/prod/deployment.yamland applies it instead ofkubectl set image, so the files cannot drift from prod. Step 1 checks for an empty diff first. The post-swap health check expects 200 or 400 depending on the client's redirect list (thecdip-devadmin-portal client accepts any redirect, so it returns the login page).docs/superpowers/plans/2026-09-28-keycloak-prod-lb-health-check.md: checklist for the changes that keep the load balancer pointed at a serving pod during a swap (5 s health check, 30 s draining, 5 s readiness probe, preStop sleep, 60 s grace period), the credential move into a Secret, and a one-hour theme cache lifetime (-Dkeycloak.theme.staticMaxAge=3600) so theme changes reach browsers without a hard reload.Status
Everything in the checklist is applied to prod except step 5b (readiness probe period and the theme cache flag). Those two edits are already in
keycloak/prod/deployment.yamland wait for the next restart window, so until thenkubectl diff --server-side -f keycloak/prod/shows exactly those two lines.Notes for review
DB_ADDRin the Deployment is the Cloud SQL private IP. It is internal-only; flag it if we would rather keep it out of the repo.🤖 Generated with Claude Code