diff --git a/.terraform.lock.hcl b/.terraform.lock.hcl index fbdf18e..e7f784a 100644 --- a/.terraform.lock.hcl +++ b/.terraform.lock.hcl @@ -1,21 +1,43 @@ # This file is maintained automatically by "terraform init". # Manual edits may be lost in future updates. -provider "registry.terraform.io/hashicorp/google" { - version = "7.14.1" +provider "registry.terraform.io/fluxcd/flux" { + version = "1.7.6" + constraints = ">= 1.2.0" hashes = [ - "h1:PWld5LsERFpdHnINaCgXebs2oQtm2T09Ls/0OUASk0A=", - "zh:0006182db112098af8514fc38d9cd4e816da4145a2a0b9fb62cc9e281eb2b2a1", - "zh:60311d9770ca26c549af9a964ee6cb60ce7541b52fedfaf5f112b0931e6bcce1", - "zh:65b400c0718f6b7c5cd0fba1b2e3696d5f4f69868229627b11b0b2b94b613ade", - "zh:9ec00812dc750687610140f9a97c374492ef320eddcb669b154e1d2e8714f7f3", - "zh:adaf0486d68da121886992a3762cedffa86b611fa43294359b2a569044c462a7", - "zh:ba95c0d8279dd8e7b9294e521e461d4adaa7c171b00502be197b6c7ff4f07d65", - "zh:c216ca4b350a90c4e74e3f502ef3f35617cdd5c278e2b04ecba2bca980fb5e96", - "zh:dd7991a71477dee46c7c57f60775341524271c425ab04e66d8f2762f9b4763eb", - "zh:dd7b63b40e67b073d2acb32ee60099d884ce75bf1152a307422c47358054d170", - "zh:e5d601ca4ab813c51d897e4c2e80bf3e3565c0dd4f37f85bb91964e90ca92dfe", - "zh:f12d8f91ed783ffac9ed8d6c331e0cbe5189455fe352ba633b171b366f52e2cd", + "h1:Zciva4ZlK4Oqg6cAnFoKUOVpEkJvZx/xbCvE4xbFSWY=", + "zh:08f1d43cc4d0d73beb26e433126ef68434ae1b88a945f3c7403e93ef8ce40b16", + "zh:0a27c7876f2399a66049deae0a2f0ba2233a8eddd3a45560eff6e20dac279317", + "zh:199ba361e9cbbb0289094480be7d1cdaae1796dcdbddb40bf5d3ee9c5aeb4483", + "zh:44ea3043649059b6884031b9e31016fad62dcb1e724dae29e5012a8ad4007039", + "zh:467f67a39b60ff247ead85d689cbdbaff2baac7693804a2a24857cb4824e2cc6", + "zh:4b910e6a1e4b65e838d4f2bb5965ff4b54ea315b35ae60ee5b17ceed1a75d11a", + "zh:5418c8ca39db1bb5e65edc4a976d3cb0140b30cbe63814287a3b7f36f14978ec", + "zh:6a2dad787674fd2219cb6a6d72d2e77500aba1c5b527db7c3e4d6fedb10d40db", + "zh:7cf60dc7fa3a7f9323aa8d036e931348482fb69340e6238caff21ec49e941bef", + "zh:8802c20134830ea46ef9214498c0539d3b63d7b0d0af82cfa6731ca7d41390c4", + "zh:9f20bcf0fda0ac6a3a162566537d8319bec377617cbec58d4c0805c9088d107c", + "zh:ace15c081c466984beecee05b9b072bfdf563020eccab6ed6ae7004238602f82", + "zh:d39a431d592629c23a4fb04ebc44c24b2bc68f03c5b85d5830fb21da0f025d9b", + "zh:fce784eb774155ccd9a87663d2dc9aa3e82e4fd495d8adb304301adf756a8f63", + ] +} + +provider "registry.terraform.io/hashicorp/helm" { + version = "3.1.1" + hashes = [ + "h1:5b2ojWKT0noujHiweCds37ZreRFRQLNaErdJLusJN88=", + "zh:1a6d5ce931708aec29d1f3d9e360c2a0c35ba5a54d03eeaff0ce3ca597cd0275", + "zh:3411919ba2a5941801e677f0fea08bdd0ae22ba3c9ce3309f55554699e06524a", + "zh:81b36138b8f2320dc7f877b50f9e38f4bc614affe68de885d322629dd0d16a29", + "zh:95a2a0a497a6082ee06f95b38bd0f0d6924a65722892a856cfd914c0d117f104", + "zh:9d3e78c2d1bb46508b972210ad706dd8c8b106f8b206ecf096cd211c54f46990", + "zh:a79139abf687387a6efdbbb04289a0a8e7eaca2bd91cdc0ce68ea4f3286c2c34", + "zh:aaa8784be125fbd50c48d84d6e171d3fb6ef84a221dbc5165c067ce05faab4c8", + "zh:afecd301f469975c9d8f350cc482fe656e082b6ab0f677d1a816c3c615837cc1", + "zh:c54c22b18d48ff9053d899d178d9ffef7d9d19785d9bf310a07d648b7aac075b", + "zh:db2eefd55aea48e73384a555c72bac3f7d428e24147bedb64e1a039398e5b903", + "zh:ee61666a233533fd2be971091cecc01650561f1585783c381b6f6e8a390198a4", "zh:f569b65999264a9416862bca5cd2a6177d94ccb0424f3a4ef424428912b9cb3c", ] } diff --git a/apps/base/customer1/news_bot/analyst-cronjob.yaml b/apps/base/customer1/news_bot/analyst-cronjob.yaml index 4d2626c..0b66e72 100644 --- a/apps/base/customer1/news_bot/analyst-cronjob.yaml +++ b/apps/base/customer1/news_bot/analyst-cronjob.yaml @@ -1,14 +1,14 @@ apiVersion: batch/v1 -kind: CronJob +kind: CronJob metadata: - name: news-analyst - namespace: customer1 + name: analyst-gemma + namespace: customer1 spec: - schedule: "15 * * * *" + schedule: "15 * * * *" jobTemplate: spec: template: - spec: + spec: volumes: - name: ollama-storage emptyDir: {} @@ -17,32 +17,38 @@ spec: - name: model-puller image: ollama/ollama:latest volumeMounts: - - name: ollama-storage + - name: ollama-storage mountPath: /root/.ollama command: ["/bin/sh", "-c"] args: ["ollama serve & sleep 5 && ollama pull gemma2"] + + - name: ollama-sidecar + image: ollama/ollama:latest + restartPolicy: Always # This is the magic + ports: + - containerPort: 11434 + volumeMounts: + - name: ollama-storage + mountPath: /root/.ollama + resources: + limits: + nvidia.com/gpu: 1 + + containers: - - name: analyst - image: siriussec/summarizer:latest - - envFrom: - - configMapRef: - name: news-app-config - - - - secretRef: - name: news-user-password - - - - name: ollama-sidecar - image: ollama/ollama:latest - ports: - - containerPort: 11434 - volumeMounts: - - name: ollama-storage - mountPath: /root/.ollama - resources: - limits: - nvidia.com/gpu: 1 - restartPolicy: OnFailure + - name: analyst + image: siriussec/summarizer:latest + env: + - name: DB_PASSWORD + valueFrom: + secretKeyRef: + name: news-user-password + key: password + envFrom: + - configMapRef: + name: news-app-config + # Make sure your summarizer script talks to http://localhost:11434 + # (or http://127.0.0.1:11434) + + restartPolicy: OnFailure diff --git a/apps/base/customer1/news_bot/configmap.yaml b/apps/base/customer1/news_bot/configmap.yaml index 0b45f9e..10c1d23 100644 --- a/apps/base/customer1/news_bot/configmap.yaml +++ b/apps/base/customer1/news_bot/configmap.yaml @@ -11,8 +11,23 @@ data: LLM_URL: "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.0-flash:generateContent" MODEL_NAME: "gemini-2.0-flash" SUMMARY_PROMPT: | - You are an expert news analyst working for DARPA . Analyze these news articles - ARTICLES - {data} - report back a 4-5 sentence summary for each of the most impactful events. Also a few paragraphs on the lesser important articles. + You are an expert news analyst working for DARPA. Your task is to deliver thorough, insightful analysis of the provided news articles. + ARTICLES: + {data} + + Instructions: + - Identify the 3–6 most impactful events or developments (prioritize geopolitical, technological, military, economic, or security implications). + - For each impactful event: Write a detailed 4–6 sentence summary, including key facts, context, potential consequences, and why it matters strategically. + - For all remaining/lesser articles: Write 2–4 cohesive paragraphs synthesizing them into broader themes or trends (do NOT list them individually unless critical). + - Aim for a total output length of 400–800 words. Be comprehensive but concise. + - Always produce substantial content — even if articles seem minor, extract value, implications, or connections. + - Use neutral, professional, analytical tone with precise language. + - Structure your response clearly with headings like: + ## Most Impactful Events + ### Event 1: [Brief Title] + [4–6 sentences...] + ... + ## Synthesis of Lesser Developments + [Paragraphs...] + - Output ONLY the structured report — no introductions, apologies, or meta-comments like "no major events found". diff --git a/immediate-backup.yaml b/immediate-backup.yaml new file mode 100644 index 0000000..1e8f44e --- /dev/null +++ b/immediate-backup.yaml @@ -0,0 +1,12 @@ +apiVersion: postgresql.cnpg.io/v1 +kind: ScheduledBackup +metadata: + name: immediate-full-backup # Can be any name; will be deleted later if one-off + namespace: customer1 +spec: + schedule: "0 0 1 1 *" + immediate: true # ← This triggers the backup RIGHT NOW + suspend: false + backupOwnerReference: self # Or 'cluster' — 'self' is fine for one-off + cluster: + name: customer1-pgdb # Your Cluster name diff --git a/mise.toml b/mise.toml index dd6d9e6..fc6a963 100644 --- a/mise.toml +++ b/mise.toml @@ -1,5 +1,6 @@ [tools] gcloud = "latest" +k9s = "latest" kubectl = "latest" sops = "latest" terraform = "latest" diff --git a/modules/nodepool-gpu.tf b/modules/nodepool-gpu.tf index f7ca663..881973a 100644 --- a/modules/nodepool-gpu.tf +++ b/modules/nodepool-gpu.tf @@ -7,7 +7,7 @@ resource "google_container_node_pool" "gpu_pool" { autoscaling { min_node_count = 0 - max_node_count = 5 + max_node_count = 1 } node_config {