a96c46fd6ee0fc4d308aaaa8c9c555b9b8d93f88
The Vector archiver leg wrote gzip NDJSON to S3 with no index or encryption. logarchiver replaces it with a Go service that seals raw logs to S3 as zstd + OpenPGP objects and indexes each object in ClickHouse (logs.archive_index), acking JetStream only after the object is stored and indexed. - Add logarchiver Deployment (image git.unkin.net/unkin/logarchiver:v0.1.0), ConfigMap, and dedicated ServiceAccount. Reuses the archiver's NATS (log-consumer / durable archiver / ARCHIVE_SUBJECTS=logs.k8s.vault.>), S3 (logs-archive-s3 BucketAccess), ClickHouse (clickhouse-credentials) and vault-ca wiring. Encrypts to the logarchive gpg public key, fetched from the gpg engine via k8s auth (role logging_logarchiver, projected vault-audience token). ack_wait > batch max_age so messages are not redelivered mid-batch. - Add logs.archive_index DDL to the clickhouse-schema bootstrap Job (no TTL). - Remove the vector-archiver Helm release, values and pipeline ConfigMap. Cross-repo: apply terraform-vault #106 (gpg key + role/policy) before this syncs, or the pod cannot fetch the public key. Sequencing: apply after argocd-apps #306. Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
argocd-apps docs
Operational notes for the manifests in this repo.
| Doc | What it covers |
|---|---|
| cnpg-backups.md | How CNPG Postgres backups (WAL archiving + nightly base backups) to Ceph RGW are configured. |
| cnpg-restore.md | Restoring a CNPG cluster: full recovery, point-in-time recovery, cutover, and gotchas. |
Description
Languages
Shell
88.8%
Makefile
11.2%