sort into folders

This commit is contained in:
2026-06-03 14:09:28 +01:00
parent bf39a87964
commit 0a03987dae
18 changed files with 36 additions and 16 deletions
@@ -0,0 +1,73 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: k8s-registry-api-discovery
rules:
- apiGroups:
- toolhive.stacklok.dev
resources:
- mcpservers
- mcpremoteproxies
- virtualmcpservers
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- services
verbs:
- get
- list
- watch
- apiGroups:
- gateway.networking.k8s.io
resources:
- httproutes
- gateways
verbs:
- get
- list
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: k8s-registry-api-discovery
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: k8s-registry-api-discovery
subjects:
- kind: ServiceAccount
name: k8s-registry-registry-api
namespace: toolhive-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: k8s-registry-api-events
namespace: toolhive-system
rules:
- apiGroups:
- ""
resources:
- events
verbs:
- create
- patch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: k8s-registry-api-events
namespace: toolhive-system
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: k8s-registry-api-events
subjects:
- kind: ServiceAccount
name: k8s-registry-registry-api
namespace: toolhive-system
@@ -0,0 +1,22 @@
apiVersion: toolhive.stacklok.dev/v1beta1
kind: MCPRegistry
metadata:
name: k8s-registry
spec:
pgpassSecretRef:
name: toolhive-reg-pg-app
key: pgpass
configYAML: |
database:
host: toolhive-reg-pg-rw
port: 5432
user: toolhive-registry
database: toolhive-reg-pg
sources:
- name: k8s
kubernetes: {}
registries:
- name: default
sources: ["k8s"]
auth:
mode: anonymous
@@ -0,0 +1,10 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: toolhive-system
resources:
- k8s-registry.yaml
- k8s-registry-rbac.yaml
- toolhive-registry-backup.yaml
- toolhive-registry-postgres.yaml
@@ -0,0 +1,28 @@
apiVersion: barmancloud.cnpg.io/v1
kind: ObjectStore
metadata:
name: minio-store
namespace: toolhive-system
spec:
configuration:
destinationPath: s3://cnpg-backup/backup
endpointURL: http://ventoux.olb42.com:9000
s3Credentials:
accessKeyId:
name: cnpg-backup
key: AWS_ACCESS_KEY_ID
secretAccessKey:
name: cnpg-backup
key: AWS_SECRET_ACCESS_KEY
wal:
compression: gzip
retentionPolicy: "14d"
instanceSidecarConfiguration:
retentionPolicyIntervalSeconds: 1800
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
@@ -0,0 +1,30 @@
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: toolhive-reg-pg
namespace: toolhive-system
spec:
instances: 2
storage:
storageClass: local-postgres
size: 8Gi
affinity:
enablePodAntiAffinity: true
podAntiAffinityType: required
topologyKey: topology.kubernetes.io/zone
plugins:
- name: barman-cloud.cloudnative-pg.io
isWALArchiver: true
enabled: true
parameters:
barmanObjectName: minio-store
bootstrap:
initdb:
database: toolhive-reg-pg
owner: toolhive-registry
postInitSQL:
- CREATE ROLE toolhive_registry_server;
postgresql:
parameters:
max_connections: "200"
shared_buffers: "256MB"