fix(k8s): Recreate singletons and trim requests for scheduler headroom
ci / lint-compose (push) Successful in 3s
ci / lint-actionlint (push) Successful in 1s
ci / lint-shellcheck (push) Successful in 2s
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 2s
ci / scan-deps (push) Successful in 18s
ci / test-backend (push) Successful in 8s
ci / test-frontend (push) Successful in 11s
ci / validate (push) Successful in 3s
renovate-ci / validate-renovate (push) Successful in 13s
ci / build (push) Successful in 1m30s

RollingUpdate with default maxSurge needs a spare pod the single node does not have (99% CPU requested), so multi-workload restarts end Pending and verify times out. Recreate on all replicas:1 Deployments (immich-server and bentopdf keep RollingUpdate at replicas 2). Also trims CPU/memory requests toward measured use (adguard, authentik, gitea, netbox, uptime-kuma, netbird-server) and gives traefik requests/limits so it is no longer BestEffort.
This commit is contained in:
forust committed 2026-09-28 22:36:46 +02:00
1 parent 76f39da90c
commit a6af69dca0
29 files changed
+79 -7

No files matched your search

+6 -2
View File
@@ -34,6 +34,8 @@ spec:
selector:
matchLabels:
app: authentik-server
strategy:
type: Recreate
template:
metadata:
labels:
@@ -53,7 +55,7 @@ spec:
resources:
requests:
memory: "768Mi"
cpu: "300m"
cpu: "100m"
limits:
memory: "1.5Gi"
cpu: "1000m"
@@ -68,6 +70,8 @@ spec:
selector:
matchLabels:
app: authentik-worker
strategy:
type: Recreate
template:
metadata:
labels:
@@ -87,7 +91,7 @@ spec:
resources:
requests:
memory: "320Mi"
cpu: "300m"
cpu: "100m"
limits:
memory: "768Mi"
cpu: "700m"