dfc5a07c10
That host is becoming a Traefik edge, and parking's prod override brings its own Caddy on `network_mode: host` holding :80 — the two cannot share the port. The lab tier moves to a dedicated bench PC rather than contorting either side. This also names what has been holding :80 on that box: the edge stack deployed there on 2026-09-01 failed with "address already in use" and the owner was recorded as unidentified. It was almost certainly this Caddy. REMOVING THIS BLOCK DOES NOT STOP ANYTHING. The containers keep running and keep the port. Destroy park-lab from Komodo Core BEFORE syncing this removal: DestroyStack names a stack and Core resolves where from its own synced copy of the definitions, so a sync that drops the block first takes the teardown handle with it. If that has already happened, remove the containers by hand on the host — there is no compose project context on a Komodo-managed box. Three Core secrets are now unreferenced: art_docker_station_jwt_secret, art_docker_station_event_signing_key, art_docker_station_backup_key. Lab keys with no real ledger behind them, so they are safe to delete once the stack is gone. Claude-Session: https://claude.ai/code/session_01SARfPK19vLBstMWBxubezN
60 lines
2.8 KiB
TOML
60 lines
2.8 KiB
TOML
# Komodo resources — parking appliance fleet (control plane as code)
|
|
#
|
|
# Synced into Komodo Core via a ResourceSync pointing at this file. Drives the SAME
|
|
# compose files the booth runs locally (docker-compose.yml + docker-compose.prod.yml);
|
|
# Komodo Periphery on each booth executes them. See:
|
|
# wiki/decisions/fleet-deployment-komodo.md (rationale + threat model)
|
|
# wiki/decisions/container-deployment.md (image build/tag/registry — unchanged)
|
|
#
|
|
# This file mirrors the WORKING park-buzi Stack (built by hand in the Core UI, then
|
|
# exported to TOML). Field names match the running Komodo version (v2.2).
|
|
#
|
|
# NO [[server]] block: servers are created by the AGENT onboarding outbound (a one-time
|
|
# onboarding key → Periphery self-registers with auto-rotating key pairs). The sync owns
|
|
# only the Stack; it references the server by the name it onboarded as (`connect_as`).
|
|
#
|
|
# Secrets ([[park_buzi_jwt_secret]] etc.) are REFERENCES to Komodo Core's secret store —
|
|
# per-booth + unique, never inlined here (this file is in git). JWT_SECRET gates login;
|
|
# EVENT_SIGNING_KEY signs the append-only anti-fraud ledger; BACKUP_KEY encrypts on-site DB
|
|
# backups (separate from the signing key; escrow it offsite — recovery needs both).
|
|
#
|
|
# Deploys are MANUAL + PINNED: park-buzi is the STAGING booth (real-world test of the app),
|
|
# so it tracks the `stage` branch + the `:stage` image, but is still deployed by hand with a
|
|
# PINNED immutable TAG=stage-<sha> (no webhook). Promotion: merge dev → stage when confident,
|
|
# CI builds :stage / :stage-<sha>, then bump TAG below to that sha and deploy from Komodo Core.
|
|
# A PRODUCTION booth tracks `main` + manual+pinned `:main-<sha>`. See
|
|
# wiki/decisions/fleet-deployment-komodo.md (dev → stage → main tiers).
|
|
|
|
##############################################################################
|
|
# Stack — the deployable unit for booth "park-buzi". One Stack per booth; add a
|
|
# new [[stack]] block per site (unique name, its own per-booth secret refs).
|
|
##############################################################################
|
|
|
|
[[stack]]
|
|
name = "park-buzi"
|
|
[stack.config]
|
|
server = "park-buzi"
|
|
git_provider = "git.infra.msai.al"
|
|
git_account = "komodo"
|
|
repo = "mca/parking_solution"
|
|
branch = "stage"
|
|
file_paths = [
|
|
"docker-compose.yml",
|
|
"docker-compose.prod.yml"
|
|
]
|
|
registry_provider = "git.infra.msai.al"
|
|
registry_account = "komodo"
|
|
environment = """
|
|
REGISTRY=git.infra.msai.al/mca/parking_solution
|
|
# Staging booth: pinned immutable stage-<sha>. After each promotion (merge dev → stage, CI builds
|
|
# :stage-<sha>), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag
|
|
# exists as the pointer; we deploy the sha, not the mover.
|
|
TAG=stage-28bd838
|
|
COOKIE_SECURE=0
|
|
VISION_ENABLED=1
|
|
WS_ALLOWED_ORIGINS=
|
|
JWT_SECRET=[[park_buzi_jwt_secret]]
|
|
EVENT_SIGNING_KEY=[[park_buzi_event_signing_key]]
|
|
BACKUP_KEY=[[park_buzi_backup_key]]
|
|
"""
|