Add faf-tournaments - #334
Merged
Merged
Conversation
The tournament site (FAForever/faf-tournaments), until now hosted privately. A Node.js service with no runtime dependencies that keeps its data in one db.json plus image folders, so it gets its own small volume and nothing in the shared databases. - Released by pushing to main in its repository: the image is republished as faforever/faf-tournaments:latest and Keel rolls it out, polled every two minutes because tournaments run live. - Recreate strategy: one db.json on one volume, so the old pod must be gone before the new one starts. - The image runs as uid 1000; an init container hands it the volume, since a local volume keeps the owner its directory was created with. - /healthz for liveness and readiness. - FAF login stays dormant until FAF_CLIENT_ID and FAF_CLIENT_SECRET are set in the secret.
Hydra already has a client for the site, registered for its current host. Add the cluster host as a second redirect URI, so both work while the site moves, and give the app that client id. The secret is Hydra's FAFTOURNEY_SECRET; until it is in the app's secret, FAF login stays off and the site uses name-only login.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Sheikah45
reviewed
Oct 5, 2026
Sheikah45
approved these changes
Oct 5, 2026
Sheikah45
pushed a commit
that referenced
this pull request
Oct 5, 2026
* Add faf-tournaments The tournament site (FAForever/faf-tournaments), until now hosted privately. A Node.js service with no runtime dependencies that keeps its data in one db.json plus image folders, so it gets its own small volume and nothing in the shared databases. - Released by pushing to main in its repository: the image is republished as faforever/faf-tournaments:latest and Keel rolls it out, polled every two minutes because tournaments run live. - Recreate strategy: one db.json on one volume, so the old pod must be gone before the new one starts. - The image runs as uid 1000; an init container hands it the volume, since a local volume keeps the owner its directory was created with. - /healthz for liveness and readiness. - FAF login stays dormant until FAF_CLIENT_ID and FAF_CLIENT_SECRET are set in the secret. * Reuse the existing FAF Tournaments OAuth client Hydra already has a client for the site, registered for its current host. Add the cluster host as a second redirect URI, so both work while the site moves, and give the app that client id. The secret is Hydra's FAFTOURNEY_SECRET; until it is in the app's secret, FAF login stays off and the site uses name-only login.
Sheikah45
pushed a commit
that referenced
this pull request
Oct 5, 2026
* Add faf-tournaments The tournament site (FAForever/faf-tournaments), until now hosted privately. A Node.js service with no runtime dependencies that keeps its data in one db.json plus image folders, so it gets its own small volume and nothing in the shared databases. - Released by pushing to main in its repository: the image is republished as faforever/faf-tournaments:latest and Keel rolls it out, polled every two minutes because tournaments run live. - Recreate strategy: one db.json on one volume, so the old pod must be gone before the new one starts. - The image runs as uid 1000; an init container hands it the volume, since a local volume keeps the owner its directory was created with. - /healthz for liveness and readiness. - FAF login stays dormant until FAF_CLIENT_ID and FAF_CLIENT_SECRET are set in the secret. * Reuse the existing FAF Tournaments OAuth client Hydra already has a client for the site, registered for its current host. Add the cluster host as a second redirect URI, so both work while the site moves, and give the app that client id. The secret is Hydra's FAFTOURNEY_SECRET; until it is in the app's secret, FAF login stays off and the site uses name-only login.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the tournament site, FAForever/faf-tournaments, which is hosted privately on
tournaments.doodlepros.comtoday. A Node.js service with no runtime dependencies that keeps its data in onedb.jsonplus three image folders, so it gets its own small volume and touches none of the shared databases.What's in it
apps/faf-tournaments: Deployment, Service, IngressRoute (tournaments.$BASE_DOMAIN), ConfigMap, local secret.mainin faf-tournaments. Its workflow republishesfaforever/faf-tournaments:latest(already on Docker Hub, plus a tag per commit), and Keel rolls it out. Polled@every 2minstead of hourly, because tournaments run live and a fix can't wait an hour.strategy: Recreate: onedb.jsonon one volume, so the old pod has to be gone before the new one starts.GET /healthz. On SIGTERM the app writes any pending save before exiting.cluster/storage: a 5Gifaf-tournamentsvolume infaf-apps.apps/ory-hydra:https://tournaments.$BASE_DOMAIN/auth/faf/callbackadded as a second redirect URI on the existing "FAF Tournaments" client, so the old and new host both work during the move. The app'sFAF_CLIENT_IDis that client's id.volumes(and Traefik through its IngressRoute).Needed before it starts on a cluster
Infisical, path
/faf-tournaments:ADMIN_PASSWORD: the bootstrap site-admin password (Nuggets has the current one).FAF_CLIENT_SECRET: the same value as Hydra'sFAFTOURNEY_SECRET. Without it the site still runs, with FAF login off and name-only login.Tested locally
helm lintandhelm templatewithconfig/local.yaml.https://tournaments.faforever.localhost/healthzanswers through Traefik, and a tournament created through the API is still on the volume afterkubectl rollout restart.node:24container, SIGTERM save ondocker stop, data across a container restart.Not tested
tilt cidid not complete on my machine (6 GB for Docker isn't enough for the whole stack). faf-tournaments came up in every attempt; the failures were elsewhere in the stack.Data from the current server moves once, at switch-over, from an archive of its Docker volume.