Files
parking_solution/komodo/resources.toml
T
julian 5443b910c6
Build desktop / desktop (push) Successful in 4m15s
Build & push images / images (push) Successful in 2m52s
CI / check (push) Successful in 43s
feat(fleet): add park-lab stack (lab bench, dev tier)
Second [[stack]] block: server park-test (the lab box's Periphery
connect_as), compose files from the dev branch, MOVING TAG=dev (a lab
may float; real booths pin), its own park_lab_* secret refs (per-box
blast radius — never shared with a real booth). park-buzi is untouched
on stage + pinned.

Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
2026-07-07 10:04:08 +02:00

96 lines
4.0 KiB
TOML

# Komodo resources — parking appliance fleet (control plane as code)
#
# Synced into Komodo Core via a ResourceSync pointing at this file. Drives the SAME
# compose files the booth runs locally (docker-compose.yml + docker-compose.prod.yml);
# Komodo Periphery on each booth executes them. See:
# wiki/decisions/fleet-deployment-komodo.md (rationale + threat model)
# wiki/decisions/container-deployment.md (image build/tag/registry — unchanged)
#
# This file mirrors the WORKING park-buzi Stack (built by hand in the Core UI, then
# exported to TOML). Field names match the running Komodo version (v2.2).
#
# NO [[server]] block: servers are created by the AGENT onboarding outbound (a one-time
# onboarding key → Periphery self-registers with auto-rotating key pairs). The sync owns
# only the Stack; it references the server by the name it onboarded as (`connect_as`).
#
# Secrets ([[park_buzi_jwt_secret]] etc.) are REFERENCES to Komodo Core's secret store —
# per-booth + unique, never inlined here (this file is in git). JWT_SECRET gates login;
# EVENT_SIGNING_KEY signs the append-only anti-fraud ledger; BACKUP_KEY encrypts on-site DB
# backups (separate from the signing key; escrow it offsite — recovery needs both).
#
# Deploys are MANUAL + PINNED: park-buzi is the STAGING booth (real-world test of the app),
# so it tracks the `stage` branch + the `:stage` image, but is still deployed by hand with a
# PINNED immutable TAG=stage-<sha> (no webhook). Promotion: merge dev → stage when confident,
# CI builds :stage / :stage-<sha>, then bump TAG below to that sha and deploy from Komodo Core.
# A PRODUCTION booth tracks `main` + manual+pinned `:main-<sha>`. See
# wiki/decisions/fleet-deployment-komodo.md (dev → stage → main tiers).
##############################################################################
# Stack — the deployable unit for booth "park-buzi". One Stack per booth; add a
# new [[stack]] block per site (unique name, its own per-booth secret refs).
##############################################################################
##############################################################################
# park-lab — the LAB bench box (hardware/dev testing, no real traffic). Chases
# the dev tier: compose files from `dev`, MOVING image tag `dev` (labs may
# float; real booths pin). Secrets are its own park_lab_* refs — per-box blast
# radius, never shared with a real booth even in the lab.
##############################################################################
[[stack]]
name = "park-lab"
[stack.config]
server = "park-test"
git_provider = "git.infra.msai.al"
git_account = "komodo"
repo = "mca/parking_solution"
branch = "dev"
file_paths = [
"docker-compose.yml",
"docker-compose.prod.yml"
]
registry_provider = "git.infra.msai.al"
registry_account = "komodo"
environment = """
REGISTRY=git.infra.msai.al/mca/parking_solution
# Lab tier: the MOVING dev tag — redeploy pulls the latest dev build. Pin to a
# dev-<sha> only when reproducing a specific state.
TAG=dev
COOKIE_SECURE=0
VISION_ENABLED=1
WS_ALLOWED_ORIGINS=
JWT_SECRET=[[park_lab_jwt_secret]]
EVENT_SIGNING_KEY=[[park_lab_event_signing_key]]
BACKUP_KEY=[[park_lab_backup_key]]
"""
##############################################################################
[[stack]]
name = "park-buzi"
[stack.config]
server = "park-buzi"
git_provider = "git.infra.msai.al"
git_account = "komodo"
repo = "mca/parking_solution"
branch = "stage"
file_paths = [
"docker-compose.yml",
"docker-compose.prod.yml"
]
registry_provider = "git.infra.msai.al"
registry_account = "komodo"
environment = """
REGISTRY=git.infra.msai.al/mca/parking_solution
# Staging booth: pinned immutable stage-<sha>. After each promotion (merge dev → stage, CI builds
# :stage-<sha>), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag
# exists as the pointer; we deploy the sha, not the mover.
TAG=stage-f9887c2
COOKIE_SECURE=0
VISION_ENABLED=1
WS_ALLOWED_ORIGINS=
JWT_SECRET=[[park_buzi_jwt_secret]]
EVENT_SIGNING_KEY=[[park_buzi_event_signing_key]]
BACKUP_KEY=[[park_buzi_backup_key]]
"""