Add shared arrstack Valkey and wire arr apps' Redis features
Activate the arr forks' #14 Redis features (SignalR backplane, cross-replica cache-invalidation bus, distributed rate limiter), which ship deployed but inert because no Valkey exists and nothing is wired. - Add a single shared ValkeyCluster (arrstack-valkey) under apps/base/arrstack/valkey, modeled on jellyfin-valkey: shards:1/replicas:2 HA, image via artifactapi, passwordless default user, node spread + cluster PDB, ephemeral storage. - Register the valkey component in the arrstack base kustomization. - Wire <App>__Redis__Host/Port into the sonarr/radarr/prowlarr env ConfigMaps, all pointing at the shared service valkey-arrstack-valkey:6379. Host is the activation switch (RedisOptions.IsConfigured gates on Host; no Enabled flag). Passwordless (jellyfin parity) so no Password/Ssl. Per-app key/channel prefixes keep the three apps isolated on one cluster.
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- valkeycluster.yaml
|
||||
@@ -0,0 +1,47 @@
|
||||
---
|
||||
# Single shared HA Valkey for the arr apps (sonarr/radarr/prowlarr), managed by
|
||||
# valkey-operator. It activates the fork's #14 Redis features: the SignalR
|
||||
# backplane, the cross-replica cache-invalidation bus, and the distributed rate
|
||||
# limiter. One cluster is safe for all three because each fork namespaces its
|
||||
# keys and pub/sub channels by a per-app prefix (sonarr:ratelimit: /
|
||||
# radarr:ratelimit: / prowlarr:ratelimit:), so their state never collides.
|
||||
#
|
||||
# Modeled on jellyfin-valkey: shards:1 + replicas:2 is one primary with two
|
||||
# replicas in a single shard group (three ValkeyNodes total); losing the primary
|
||||
# triggers an automatic failover so a node/pod loss no longer drops the shared
|
||||
# state the app replicas coordinate through. The operator runs Valkey
|
||||
# cluster-mode-enabled with protected-mode off and leaves the built-in `default`
|
||||
# user passwordless, so clients connect with no auth/TLS; StackExchange.Redis
|
||||
# seeds off the single service and auto-discovers topology plus failovers.
|
||||
# scheduling.node.spread.shard:Required keeps the three nodes on distinct hosts,
|
||||
# so one host loss removes at most one node; podDisruptionBudget.mode:Cluster
|
||||
# lets the operator manage a quorum-aware PDB. Persistence is omitted (/data is an
|
||||
# emptyDir): the coordination state is ephemeral (short TTLs / transient pub/sub),
|
||||
# replication+failover already provide redundancy, and an operator-managed PVC
|
||||
# cannot carry the k8up.io/backup:"false" annotation the namespace k8up Schedule
|
||||
# needs to skip in-use RWO volumes.
|
||||
apiVersion: valkey.io/v1alpha1
|
||||
kind: ValkeyCluster
|
||||
metadata:
|
||||
name: arrstack-valkey
|
||||
namespace: arrstack
|
||||
spec:
|
||||
shards: 1
|
||||
replicas: 2
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/valkey/valkey:9.0.0
|
||||
exporter:
|
||||
enabled: false
|
||||
scheduling:
|
||||
node:
|
||||
spread:
|
||||
shard:
|
||||
mode: Required
|
||||
podDisruptionBudget:
|
||||
mode: Cluster
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
Reference in New Issue
Block a user