Jacques ROUSSEL and aleb_the_flash
4f4b4d3231
♻️ (tilt) remove bitnami dependencies from dev stack
...
Remove dependencies on bitnami Helm charts since recent changes in
bitnami organization led to charts no longer being maintained or
published.
Enhanced the Tilt dependencies to avoid any bootstrap or refresh
errors while developping using the Tilt stack.
Making components dependant from each others increase slightly
the time required to spin up the stack the first time.
2025-08-25 17:23:58 +02:00
Jacques ROUSSEL and aleb_the_flash
8518f83211
✨ (helm) add the ability to configure tls secretName
...
Yesterday during a deployment, we were unable to configure the tls
secretName for ingress.
2025-08-01 16:53:36 +02:00
Jacques ROUSSEL and aleb_the_flash
483a219ac4
♻️ (documentation) remove unused environment variables
...
Yesterday during a deployment, we discovered that these variables are
unused:
POSTGRES_DB
POSTGRES_USER
POSTGRES_PASSWORD
2025-08-01 16:14:55 +02:00
Jacques ROUSSEL and aleb_the_flash
9d516bf638
🚸 (helm) improve helm chart
...
Our Helm chart wasn't suitable for use with Helm alone because jobs
remained after deployment. We chose to configure ttlSecondsAfterFinished
to clean up jobs after a period of time.
2025-06-06 16:52:30 +02:00
Jacques ROUSSEL and aleb_the_flash
1e3e7de753
🔒 ️(front) improve docker image security
...
Cyberwatch reported security issues with the frontend Docker image.
2025-05-23 14:25:06 +02:00
Jacques ROUSSEL and aleb_the_flash
d70dc41643
⚡ ️(tilt) fix cp for linux users
...
Fix the cp permission issue for linux users
2025-05-15 17:17:07 +02:00
Jacques ROUSSEL and rouja
93ca4f2bf4
🐛 (ci) use github action for argocd webhook notification
...
In order to refactor this notification between alls projetcs, we
chooseto use a custom github action
2025-03-28 16:24:17 +01:00
Jacques ROUSSEL and rouja
ccca2b9472
🔧 (ci) fix argocd notification
...
Argocd deployment use numerique-gouv/lasuite-deploiement as source so
the webhook need to tell argocd to refresh apps that use this repos
2025-02-21 11:21:01 +01:00
Jacques ROUSSEL
48937bb7a3
♻️ (helm) fix helm chart for keycloak stack
...
Ingress stop working, so this commit fix it
2025-02-14 11:51:31 +01:00
Jacques ROUSSEL and aleb_the_flash
2cd4a6efa8
✨ (helm) add pdbs to deployments
...
In order to avoid a service interruption during a Kubernetes (k8s)
upgrade, we add a Pod Disruption Budget (PDB) to deployments.
2025-02-12 11:54:08 +01:00
Jacques ROUSSEL
723b8718f9
🔐 (helm) bump chart version
...
Bump chart version to publish a new one with evolution
2025-02-05 22:20:49 +01:00
Jacques ROUSSEL
1b7523bbf1
💚 (github) fix argocd notification
...
Use the right variable for webhook url
2025-02-05 11:53:56 +01:00
Jacques ROUSSEL
4326df4b6a
💚 (github) fix argocd notification
...
Fix double simple quote issue on argocd notification job
2025-02-05 11:48:38 +01:00
Jacques ROUSSEL and NathanVss
564d31ab49
💚 (github) remove secret fetch
...
The secrets are not managed in the folder anymore.
2025-02-05 11:41:37 +01:00
Jacques ROUSSEL and aleb_the_flash
dc0e2eefb3
📝 (doc) upgrade README.md
...
Upgrade the README.md of the helm chart meet
2025-01-14 10:15:27 +01:00
Jacques ROUSSEL and aleb_the_flash
7ad9015a6b
👷 (helm) fix typo in the ci
...
Fix the following issue :
```
The workflow is not valid. .github/workflows/release-helmchart.yml
(Line: 25, Col: 12): Job 'release' depends on unknown job
'helmfile-lint'.
```
2025-01-09 18:14:41 +01:00
Jacques ROUSSEL and rouja
25a4e2dfc6
👷 (helm) improve local stack
...
Use the common create_cluster.sh in order to improve cooperation
between teams.
Also, mount extra volume, to avoid setting ssl_verify to false,
while using request module in Python.
2025-01-06 10:19:09 +01:00
Jacques ROUSSEL and rouja
14e83ecaff
📝 (doc) add a self-host tutorial
...
Add a documentation to deploy a self-hosted visio instance in a
standalone way (without AI features)
2025-01-06 10:19:09 +01:00
Jacques ROUSSEL and rouja
8bd90bd2ff
👷 (helm) add a github workflow to publish a chart
...
We have a dedicated deployment repository, also containing
the Helm chart. To avoid duplicating and maintaining twice
a chart, we decided to publish our Helm chart.
At first we tried the official chart releaser action, however,
this ended in creating a new release on Github for each chart
update, which wasn't acceptable.
2025-01-06 10:19:09 +01:00
Jacques ROUSSEL and rouja
b51f127872
🔧 (helm) offer a standalone dev environment
...
Offer a standalone dev environment or a dinum specific dev
environment with ProConnect authentication.
Needed to refactor the way secrets are managed in the project,
and also re-organize the Helm chart to make it totally standalone.
Particulary useful for external wanting to run the project.
Work done by @rouja.
2025-01-06 10:19:09 +01:00
Jacques ROUSSEL and aleb_the_flash
f5a87cc210
🔐 (helm) bump secret in staging
...
We add a typo in secret so we bump secrets to fix it.
2024-12-17 10:19:40 +01:00
Jacques ROUSSEL and aleb_the_flash
0ad37ee6de
🔨 (tilt) improve local stack
...
Improve the local tilt file in order to be abble to start all thing
without any dependencies to DINUM environment
2024-12-16 23:41:09 +01:00
Jacques ROUSSEL and aleb_the_flash
ed4f7dcf6c
🔐 (helm) add production secrets for recording and transcription
...
Added all missing secrets for the recording feature
and transcription microservice.
2024-12-16 23:08:04 +01:00
Jacques ROUSSEL and aleb_the_flash
94d18cffe4
🔐 (secrets) bump secretBump secret
...
In order to use our openai api we need new secret
2024-12-04 10:49:17 +01:00
Jacques ROUSSEL and aleb_the_flash
0f70b544ed
🔐 (secrets) bump secret
...
Bump secret in order to enable recording on staging
2024-11-29 17:05:29 +01:00
Jacques ROUSSEL and aleb_the_flash
0627510f10
♻️ (tilt) simplify the local stack
...
This commit solves few issues:
- sharing the relevant certificates with minio so when triggering the webhook
notification, the minio pod can verify our backend domain certificates.
- making sure everything spawn in the right namespace (LiveKit and the Egress)
without relying on a dirty fix in the make start-tilt.
all these fixes were made by @rouja, I don't fully understand them yet.
He simplified the stack, removing two Kind nodes to make it lightweight.
thx @rouja.
2024-11-29 15:54:24 +01:00
Jacques ROUSSEL and aleb_the_flash
682b69fc11
🔒 ️(backend) migrate backend image to alpine
...
Enhancement made by @rouja while working on the vulnerabilities
found by Trivy scan.
2024-10-09 14:58:39 +02:00
Jacques ROUSSEL and aleb_the_flash
7a73bf8fc2
💚 (frontend) fix frontend image vulnerabilities
...
Fixed vulnerabilities found by the Trivy Scan.
2024-10-09 14:58:39 +02:00
Jacques ROUSSEL and aleb_the_flash
1e934957f5
💚 (backend) fix backend image vulnerabilities
...
Fixed vulnerabilities with setup tools found by the Trivy Scan.
2024-10-09 14:58:39 +02:00
Jacques ROUSSEL and aleb_the_flash
5a7584a3ad
👷 (ci) scan for vulnerabilities on Docker images
...
Configure Trivy Scan in the CI to detect vulnerabilities on our
Docker image. Enhance stack security.
2024-10-09 14:58:39 +02:00
Jacques ROUSSEL and aleb_the_flash
fb9bf6b08e
🔐 (tilt) add Samuel's key
...
Add Samuel's key to handle secret.
2024-10-09 11:14:11 +02:00
Jacques ROUSSEL and aleb_the_flash
11b8541005
🔧 (backend) fix configuration to avoid different ssl warning
...
Fix following warning messages :
- You have not set a value for the SECURE_HSTS_SECONDS setting.
- Your SECURE_SSL_REDIRECT setting is not set to True.
2024-09-27 18:46:26 +02:00
Jacques ROUSSEL and aleb_the_flash
eeb4dae12d
💚 (ci) fix argocd job which handles sync
...
Fixed by @rouja. ArgoCD should be more robust than ever, while
syncing with our code.
2024-09-25 11:40:44 +02:00
Jacques ROUSSEL and aleb_the_flash
fe6eefa1f0
👷 (ci) lint helmfile
...
Introduced by @rouja. Added a new linter to ensure helm and yaml
files can be properly parsed into templates.
ArgoCD can not break anymore.
2024-09-25 11:40:44 +02:00
Jacques ROUSSEL and aleb_the_flash
90c88a8bd3
🔒 ️(helm) change domainon production
...
Add ingress in order to migrate from meet.numerique.gouv.fr to
visio.numerique.gouv.fr
2024-09-23 20:20:56 +02:00
Jacques ROUSSEL and aleb_the_flash
3391165e4b
🔒 ️(helm) change domain
...
Change the domain to visio-staging.beta.numerique.gouv.fr
2024-09-23 12:07:13 +02:00
Jacques ROUSSEL and aleb_the_flash
0be94aa572
🔒 ️(helm) setup temporary redirect
...
Add a specific certificate to prepare redirect
2024-09-23 12:07:13 +02:00
rouja and GitHub
64bb1b3bb5
Merge pull request #161 from numerique-gouv/fix-secret-mep-issue
...
🔒 ️(helm) fix secret sync precedence
2024-09-20 15:04:29 +02:00
Jacques ROUSSEL
a1a56402d1
🔒 ️(helm) fix secret sync precedence
...
When new secret is added to backend secret, it's not sync at the
beginning of argocd synchronisation and jobs are blocked. Theses new
annotations fix this issue.
2024-09-20 14:55:15 +02:00
Jacques ROUSSEL and aleb_the_flash
f6bc57ba91
🔒 ️(helm) configure staging to use livekit-staging
...
Reconfigure staging environment to use
livekit-staging.beta.numerique.gouv.fr
2024-08-21 10:54:49 +02:00
Jacques ROUSSEL and aleb_the_flash
7510d0fc2b
🔧 (helm) configuration
...
Change configuration to use livekit-preprod.beta.numerique.gouv.fr
instead of the docker test vm
2024-07-19 15:35:55 +02:00
Jacques ROUSSEL and aleb_the_flash
f50426b11a
🔧 (helm) fix helm chart
...
Fix helm secret to be abble to use titl on dev
2024-07-18 16:11:56 +02:00
Jacques ROUSSEL and aleb_the_flash
c390499394
🔧 (helm) fix helm chart
...
Add md5sum on secret in order to automatically deploy new pods when
secret change
2024-07-17 15:50:18 +02:00
Jacques ROUSSEL and aleb_the_flash
980d3c19d8
🔧 (helm) upgrade sops secrets
...
Upgrade submodule reference
2024-07-17 15:50:18 +02:00
Jacques ROUSSEL and aleb_the_flash
d9ef64c4c4
🔧 (helm) upgrade sops secrets
...
Fix djangoSecretKey on production
2024-07-16 15:15:20 +02:00
Jacques ROUSSEL
6e3bf3b5f4
🔧 (helm) upgrade sops secrets
...
Add manuu key
2024-07-12 10:49:30 +02:00
Jacques ROUSSEL and aleb_the_flash
d93e262069
🔐 (helm) update secrets
...
Made by @rouja. Structure is inspired from Impress, values are adapted
to Meet.
2024-07-10 23:33:05 +02:00
Jacques ROUSSEL and aleb_the_flash
cf11cc3e60
🔥 (CI) add ci secrets
2024-07-02 19:37:59 +02:00