bolletjestrui: deploy main-10268f1 (routes, voting, push, ride uploads)

Adds the VAPID keypair for web push and raises the ingress body limit to 25m to
match the app's BODY_SIZE_LIMIT, since a bulk route import posts every GPX in one
request.

The VAPID env refs are optional:true on purpose — a missing key in a secretKeyRef
puts the pod in CreateContainerConfigError, and the app already handles absent
keys by sending no notifications.
This commit is contained in:
Ruben Hensen
2026-08-15 17:55:37 +02:00
parent b50f8dc5b6
commit ec5405fc29
3 changed files with 32 additions and 2 deletions
+19 -1
View File
@@ -17,7 +17,7 @@ spec:
app: bolletjestrui
spec:
containers:
- image: ghcr.io/rubenhensen/bolletjestrui:main-8f17b5d
- image: ghcr.io/rubenhensen/bolletjestrui:main-10268f1
name: bolletjestrui
ports:
- containerPort: 3000
@@ -51,6 +51,24 @@ spec:
secretKeyRef:
name: bolletjestrui-secrets
key: key_secret
# Push notifications. optional:true is load-bearing: without it a missing
# key leaves the pod in CreateContainerConfigError and the site is down,
# which would make deploying this depend on the Vault entries landing
# first. The app already treats absent VAPID keys as "send nothing".
- name: VAPID_PUBLIC_KEY
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: vapid_public_key
optional: true
- name: VAPID_PRIVATE_KEY
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: vapid_private_key
optional: true
- name: VAPID_SUBJECT
value: mailto:ruben.hensen@protonmail.com
resources:
requests:
memory: "128Mi"
+11
View File
@@ -23,3 +23,14 @@ spec:
remoteRef:
key: kv/bolletjestrui
property: key_secret
# web-push keypair for the "de route is gekozen" notification.
# Generate once with `npx web-push generate-vapid-keys` and never rotate it:
# a new key invalidates every subscription on everyone's phone.
- secretKey: vapid_public_key
remoteRef:
key: kv/bolletjestrui
property: vapid_public_key
- secretKey: vapid_private_key
remoteRef:
key: kv/bolletjestrui
property: vapid_private_key
+2 -1
View File
@@ -6,7 +6,8 @@ metadata:
cert-manager.io/cluster-issuer: prod-cluster-issuer
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/ssl-passthrough: "false"
nginx.ingress.kubernetes.io/proxy-body-size: "10m"
# matches the app's BODY_SIZE_LIMIT: a bulk route import posts every GPX at once
nginx.ingress.kubernetes.io/proxy-body-size: "25m"
spec:
ingressClassName: nginx
rules: