k8s/argo optimizations

This commit is contained in:
Graham McInitre 2026-07-21 12:14:01 -05:00
parent 5c6cef2227
commit c193f35a0c
5 changed files with 124 additions and 2 deletions

View file

@ -22,6 +22,7 @@ spec:
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
minReadySeconds: 5
selector:
matchLabels:
app: hrrr-point-rs

View file

@ -9,8 +9,8 @@
# for scheduler bin-packing without accidentally changing when HPA
# decides to add a replica.
#
# The corresponding Deployments have their `spec.replicas` removed so
# Flux's periodic reconcile doesn't fight HPA's live scaling.
# The corresponding Deployments omit their spec.replicas so ArgoCD's
# periodic reconcile doesn't fight HPA's live scaling.
---
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler

View file

@ -13,3 +13,5 @@ resources:
- service.yaml
- metrics-service.yaml
- hpa.yaml
- pdb.yaml
- network-policy.yaml

108
k8s/network-policy.yaml Normal file
View file

@ -0,0 +1,108 @@
# Minimal ingress policy for a home cluster. Default-deny within the
# namespace, then allow:
# - Web traffic to hot pods on :5000 (cloudflared ingress)
# - Prometheus scrape traffic on :5000 (prop metrics) and :9100 (Rust workers)
# - Erlang distribution (EPMD + ephemeral ports) between prop + backfill pods
#
# Egress is unrestricted — pods need to reach Postgres, NFS (10.0.19.103),
# HRRR (skippy + NOAA S3), and IEM.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: prop-allow-web
namespace: prop
spec:
podSelector:
matchLabels:
app: prop
tier: hot
policyTypes:
- Ingress
ingress:
# Web traffic from cloudflared (any source, port :5000).
- from: []
ports:
- port: 5000
protocol: TCP
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: prop-allow-metrics
namespace: prop
spec:
podSelector:
matchLabels:
app: prop
tier: hot
policyTypes:
- Ingress
ingress:
# Prometheus scrape via apiserver proxy or NodePort.
- from:
- namespaceSelector: {} # any namespace
ports:
- port: 5000
protocol: TCP
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: grid-rs-allow-metrics
namespace: prop
spec:
podSelector:
matchLabels:
app: prop-grid-rs
policyTypes:
- Ingress
ingress:
- from:
- namespaceSelector: {}
ports:
- port: 9100
protocol: TCP
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: hrrr-point-allow-metrics
namespace: prop
spec:
podSelector:
matchLabels:
app: hrrr-point-rs
policyTypes:
- Ingress
ingress:
- from:
- namespaceSelector: {}
ports:
- port: 9100
protocol: TCP
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: prop-allow-epmd
namespace: prop
spec:
podSelector:
matchLabels:
app: prop
policyTypes:
- Ingress
ingress:
# Erlang distribution within the cluster (libcluster). EPMD listens on
# 4369; actual distribution uses ephemeral ports negotiated via EPMD.
- from:
- podSelector:
matchLabels:
app: prop
ports:
- port: 4369
protocol: TCP
- from:
- podSelector:
matchLabels:
app: prop

11
k8s/pdb.yaml Normal file
View file

@ -0,0 +1,11 @@
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: prop
namespace: prop
spec:
minAvailable: 1
selector:
matchLabels:
app: prop
tier: hot