# Komodo resources — parking appliance fleet (control plane as code) # # Synced into Komodo Core via a ResourceSync pointing at this file. Drives the SAME # compose files the booth runs locally (docker-compose.yml + docker-compose.prod.yml); # Komodo Periphery on each booth executes them. See: # wiki/decisions/fleet-deployment-komodo.md (rationale + threat model) # wiki/decisions/container-deployment.md (image build/tag/registry — unchanged) # # This file mirrors the WORKING park-buzi Stack (built by hand in the Core UI, then # exported to TOML). Field names match the running Komodo version (v2.2). # # NO [[server]] block: servers are created by the AGENT onboarding outbound (a one-time # onboarding key → Periphery self-registers with auto-rotating key pairs). The sync owns # only the Stack; it references the server by the name it onboarded as (`connect_as`). # # Secrets ([[park_buzi_jwt_secret]] etc.) are REFERENCES to Komodo Core's secret store — # per-booth + unique, never inlined here (this file is in git). JWT_SECRET gates login; # EVENT_SIGNING_KEY signs the append-only anti-fraud ledger; BACKUP_KEY encrypts on-site DB # backups (separate from the signing key; escrow it offsite — recovery needs both). # # Deploys are MANUAL + PINNED: park-buzi is the STAGING booth (real-world test of the app), # so it tracks the `stage` branch + the `:stage` image, but is still deployed by hand with a # PINNED immutable TAG=stage- (no webhook). Promotion: merge dev → stage when confident, # CI builds :stage / :stage-, then bump TAG below to that sha and deploy from Komodo Core. # A PRODUCTION booth tracks `main` + manual+pinned `:main-`. See # wiki/decisions/fleet-deployment-komodo.md (dev → stage → main tiers). ############################################################################## # Stack — the deployable unit for booth "park-buzi". One Stack per booth; add a # new [[stack]] block per site (unique name, its own per-booth secret refs). ############################################################################## [[stack]] name = "park-buzi" [stack.config] server = "park-buzi" git_provider = "git.infra.msai.al" git_account = "komodo" repo = "mca/parking_solution" branch = "stage" file_paths = [ "docker-compose.yml", "docker-compose.prod.yml" ] registry_provider = "git.infra.msai.al" registry_account = "komodo" environment = """ REGISTRY=git.infra.msai.al/mca/parking_solution # Staging booth: pinned immutable stage-. After each promotion (merge dev → stage, CI builds # :stage-), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag # exists as the pointer; we deploy the sha, not the mover. TAG=stage-28bd838 COOKIE_SECURE=0 VISION_ENABLED=1 # Desktop app WS handshake: Origin is tauri://localhost (set explicitly by # platform-ws.ts, since the native WS plugin has no page context to auto-attach # one). Linux may also send http://tauri.localhost. See routes/ws.ts anti-CSWSH check. WS_ALLOWED_ORIGINS=tauri://localhost,http://tauri.localhost JWT_SECRET=[[park_buzi_jwt_secret]] EVENT_SIGNING_KEY=[[park_buzi_event_signing_key]] BACKUP_KEY=[[park_buzi_backup_key]] """ ############################################################################## [[stack]] name = "park-2" [stack.config] server = "park-2" git_provider = "git.infra.msai.al" git_account = "komodo" repo = "mca/parking_solution" branch = "stage" file_paths = [ "docker-compose.yml", "docker-compose.prod.yml" ] registry_provider = "git.infra.msai.al" registry_account = "komodo" environment = """ REGISTRY=git.infra.msai.al/mca/parking_solution # Staging booth: pinned immutable stage-. After each promotion (merge dev → stage, CI builds # :stage-), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag # exists as the pointer; we deploy the sha, not the mover. TAG=stage-28bd838 COOKIE_SECURE=0 VISION_ENABLED=1 # Desktop app WS handshake: Origin is tauri://localhost (set explicitly by # platform-ws.ts, since the native WS plugin has no page context to auto-attach # one). Linux may also send http://tauri.localhost. See routes/ws.ts anti-CSWSH check. WS_ALLOWED_ORIGINS=tauri://localhost,http://tauri.localhost JWT_SECRET=[[park_2_jwt_secret]] EVENT_SIGNING_KEY=[[park_2_event_signing_key]] BACKUP_KEY=[[park_2_backup_key]] """