DocumentationDeployment

Rust · 0.1.0

Kubernetes

Apply the container's storage and configuration contract to a cluster.

Use the same application contract

Build and publish your own authorized image to a registry your cluster can read. Mount persistent storage at MEMOS_DATA, set MEMOS_PORT explicitly, and route a Service to that port. A /healthz HTTP check can detect a running listener. Keep the first setup process private until the administrator account is established.

Storage and rollout decisions

For SQLite, use one application replica and a volume with suitable single-writer semantics; do not turn a local database into a shared multi-writer deployment. For a network database, validate rollout, migration and concurrent-access behavior in your environment before increasing replicas. A database alone does not carry local attachment files. Ensure mounted /etc/secrets files follow the deployment configuration format, and restart pods after changing them.

Validation checklist

No Helm chart or cluster installation has been validated by this documentation build. Test image pulling, writable volumes, secret mounts, proxy forwarding, graceful termination and a restore into an isolated namespace before production use.

A single-writer SQLite template

Prerequisites: a working kubectl context, a default StorageClass, permission to create these resources, and a private registry image built from your authorized checkout. Replace the image reference below with your own pinned tag or digest; configure imagePullSecrets if your registry needs them. Save as memos.yaml. This intentionally uses one replica, a Recreate update strategy, a persistent volume and a ClusterIP Service. It provides a private starting point, not a tested high-availability deployment.

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: memos-data
  labels: {app: memos}
spec:
  accessModes: [ReadWriteOnce]
  resources:
    requests:
      storage: 2Gi
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: memos
  labels: {app: memos}
spec:
  replicas: 1
  strategy:
    type: Recreate
  selector:
    matchLabels: {app: memos}
  template:
    metadata:
      labels: {app: memos}
    spec:
      containers:
        - name: memos
          image: registry.example.com/your-team/memos:YOUR_COMMIT
          ports:
            - containerPort: 5230
          env:
            - {name: MEMOS_PORT, value: "5230"}
            - {name: MEMOS_DATA, value: /var/opt/memos}
          readinessProbe:
            httpGet: {path: /healthz, port: 5230}
            periodSeconds: 5
          volumeMounts:
            - {name: data, mountPath: /var/opt/memos}
      volumes:
        - name: data
          persistentVolumeClaim: {claimName: memos-data}
---
apiVersion: v1
kind: Service
metadata:
  name: memos
  labels: {app: memos}
spec:
  type: ClusterIP
  selector: {app: memos}
  ports:
    - {port: 5230, targetPort: 5230}

Apply privately and initialize

Use an isolated namespace selected in your context. Inspect the proposed changes, apply the manifest, then forward the service to your own loopback address. Open http://127.0.0.1:5230, complete first-account setup and save a disposable memo. Readiness means the health handler responds; it does not verify sign-in, persistence or authorization. Keep the Service private until those checks pass.

kubectl diff -f memos.yaml
kubectl apply -f memos.yaml
kubectl rollout status deployment/memos --timeout=180s
kubectl get pods,pvc,service -l app=memos
kubectl get pvc memos-data
kubectl port-forward --address 127.0.0.1 service/memos 5230:5230

Understand a stalled rollout

ImagePullBackOff points to the image reference or registry access; a Pending PVC points to storage provisioning; repeated exits require application logs, configuration and volume permissions. The packaged entrypoint normally starts as root to prepare ownership and drops to UID/GID 10001. A cluster policy that requires a non-root container from its first instruction needs an already-writable volume and a reviewed securityContext; do not guess a chmod 777 workaround. ReadWriteOnce is a mount-access mode, not a guarantee that every possible controller action prevents overlapping writers. Do not scale this SQLite template above one replica. Review Kubernetes rollout behavior before adapting it.

kubectl describe pod -l app=memos
kubectl describe pvc memos-data
kubectl logs deployment/memos --tail=100