Feature description
A shared, provider agnostic layer that installs the SRDP app and is reused across clouds, so each cloud only supplies its own infra values. Split out from #34.
Use case
The Scaleway blueprint bundled the app install under deploy/scaleway/deploy/srdp/. That ties the app deployment to one cloud and hardcodes infra values (S3 URL, Secret Manager region). We want to write the app install once and reuse it across providers instead of copying it per cloud.
Removed overlay for reference (pinned commit, before the strip): https://github.com/srdp-hub/srdp/tree/6571735939e43fbf8d44b97a9fb4d25283f6234f/deploy/scaleway/deploy/srdp
Proposed solution
Two nested layers:
deploy/
docker/ Compose stack (local), already here
kubernetes/
srdp-chart/ the chart (the contract), already here
clusters/<env>/ Flux delivery overlay: values + HelmRelease, cloud agnostic (new)
scaleway/ Scaleway infra (Terraform), its Flux points at deploy/kubernetes/clusters/<env>
azure/ (future) different infra, same deploy/kubernetes/clusters
Convention: deploy/<runtime> is self-contained (like deploy/docker for Compose). The k8s app deployment lives under deploy/kubernetes next to the chart, not in a separate top-level folder. Cloud folders only provision infra and point Flux at it.
Contract that keeps the app layer cloud agnostic: each provider's Terraform writes its outputs (DB host, S3 URL, project, region, secret refs) into a ConfigMap. Flux injects them into the shared values with postBuild.substituteFrom. No cloud specific values live in the app layer.
Chart as contract: deployment values only set infra knobs (hosts, domains, tiers, buckets). Do not restate core config (db names, ports, ETL env vars) that already lives in the chart. Relates to the DuckLake env contract backlog item.
Tasks:
Alternatives considered
Keep the app install per provider: duplicated config that drifts. Restructure it inside #34: blows up that PR's scope and forces the handoff contract under merge pressure.
Component: Deploy: Kubernetes, Deploy: Other
Feature description
A shared, provider agnostic layer that installs the SRDP app and is reused across clouds, so each cloud only supplies its own infra values. Split out from #34.
Use case
The Scaleway blueprint bundled the app install under
deploy/scaleway/deploy/srdp/. That ties the app deployment to one cloud and hardcodes infra values (S3 URL, Secret Manager region). We want to write the app install once and reuse it across providers instead of copying it per cloud.Removed overlay for reference (pinned commit, before the strip): https://github.com/srdp-hub/srdp/tree/6571735939e43fbf8d44b97a9fb4d25283f6234f/deploy/scaleway/deploy/srdp
Proposed solution
Two nested layers:
Convention:
deploy/<runtime>is self-contained (likedeploy/dockerfor Compose). The k8s app deployment lives underdeploy/kubernetesnext to the chart, not in a separate top-level folder. Cloud folders only provision infra and point Flux at it.Contract that keeps the app layer cloud agnostic: each provider's Terraform writes its outputs (DB host, S3 URL, project, region, secret refs) into a ConfigMap. Flux injects them into the shared values with
postBuild.substituteFrom. No cloud specific values live in the app layer.Chart as contract: deployment values only set infra knobs (hosts, domains, tiers, buckets). Do not restate core config (db names, ports, ETL env vars) that already lives in the chart. Relates to the DuckLake env contract backlog item.
Tasks:
deploy/kubernetes/clusters/<env>shared overlay (base + per env)substituteFromhandoff["-m", "etl.definitions"],LAKEHOUSE_S3_URLvia substitution not hardcoded, immutable image tags for proddeploy/kubernetes/clusters/<env>deploy/README.mdAlternatives considered
Keep the app install per provider: duplicated config that drifts. Restructure it inside #34: blows up that PR's scope and forces the handoff contract under merge pressure.
Component: Deploy: Kubernetes, Deploy: Other