# The site is served from a git branch, not from an image we built. # # git-sync clones the `site` branch of loom/docs into a shared emptyDir and # polls it; nginx serves whatever is there. Both images are public, which is # what lets this deploy while the cluster's container-registry gap is open. # # Anonymous clone: loom/docs is a public repository. Nothing here holds a # credential, and a private repository would need one — which is the same # unanswered question the registry gap names. apiVersion: apps/v1 kind: Deployment metadata: name: docs namespace: loom spec: replicas: 1 selector: matchLabels: { app: docs } template: metadata: labels: { app: docs } spec: securityContext: fsGroup: 65533 volumes: - name: site emptyDir: {} - name: nginx-conf configMap: { name: docs-nginx } initContainers: # --one-time, so the pod is not Ready until the site is actually on # disk. Without this nginx serves 404s for the first few seconds after # every reschedule. - name: git-sync-init image: registry.k8s.io/git-sync/git-sync:v4.4.0 args: - --repo=https://git.hypertheory-labs.dev/loom/docs.git - --ref=site - --root=/site - --link=current - --one-time volumeMounts: - { name: site, mountPath: /site } containers: - name: git-sync image: registry.k8s.io/git-sync/git-sync:v4.4.0 args: - --repo=https://git.hypertheory-labs.dev/loom/docs.git - --ref=site - --root=/site - --link=current - --period=60s volumeMounts: - { name: site, mountPath: /site } - name: nginx image: nginx:1.29-alpine ports: - { containerPort: 8080, name: http } volumeMounts: - { name: site, mountPath: /site, readOnly: true } - { name: nginx-conf, mountPath: /etc/nginx/conf.d } readinessProbe: httpGet: { path: /, port: http } initialDelaySeconds: 2 resources: requests: { cpu: 10m, memory: 32Mi } limits: { memory: 128Mi }