Skip to content

Added some docs to run on Kubernetes - #304

Merged
DuarteSantos8 merged 3 commits into
DuarteSantos8:mainfrom
chriscowley:main
Sep 28, 2026
Merged

DuarteSantos8 merged 3 commits into
DuarteSantos8:mainfrom
chriscowley:main

Conversation

@chriscowley

@chriscowley chriscowley commented Sep 24, 2026 •

Copy link
Copy Markdown

I deployed my instance on Kubernetes (documented here), but decided to feed what I did back to the community.

This is a very basic set of manifests to deploy on a cluster similar to my own:

  • K3s
  • Gateway API
  • Cert-manager for HTTPS

There are other ways to do this that would be more scalable, such as putting the API and frontend in separate deployments, but this will work for most people.

TODO: put this into a Helm chart, but that would be another MR

@kquinsland01

Copy link
Copy Markdown

related: #271

Some of your deployment manifests are similar to what I tweaked. The other things on the list:

  • Quite a few security/hardening related things
    • Coach jobs need root/cron so you can't run rootless, unfortunately
    • With some workarounds (below) you can do read-only file systems.
  • pino or similar for structured logging, please
  • Needs a health and ready probe

I was able to get the web container mounted w/ a read only file system after poking a few holes:

            volumes:
                - name: media
                  persistentVolumeClaim:
                      claimName: opengym-media
                # readOnlyRootFilesystem makes the image read-only, but these emptyDir mounts provide writable paths for temporary files.
                # Their contents are discarded with the Pod; persistent media stays on the PVC above.
                # The media init container clones the dataset into /tmp before copying it to the PVC.
                - name: media-tmp
                  emptyDir: {}
                # nginx copies the upstream template here to enable IPv6 DNS resolution.
                - name: nginx-tmp
                  emptyDir: {}
                # The nginx entrypoint renders its configuration into this writable directory.
                - name: nginx-config
                  emptyDir: {}
                # nginx needs writable request buffers and temporary cache files.
                - name: nginx-cache
                  emptyDir: {}
                # nginx writes its PID and runtime files here.
                - name: nginx-run
                  emptyDir: {}

@DuarteSantos8
DuarteSantos8 merged commit 7e8d148 into DuarteSantos8:main Sep 28, 2026
DuarteSantos8 added a commit that referenced this pull request Sep 28, 2026
…ng guide, the gateway may read the certificate, and the manifests say what to set
DuarteSantos8 added a commit that referenced this pull request Sep 28, 2026
…in the images to a release and the media download to a git version, and the guide says why TRUST_PROXY stays off behind a gateway
DuarteSantos8 added a commit that referenced this pull request Sep 28, 2026
…ith one duplicate swap (#313), an instance default language (#303), Kubernetes manifests (#304) and Coach routine icons (#311)
@DuarteSantos8

Copy link
Copy Markdown
Owner

Thanks @chriscowley, the Kubernetes manifests and guide are in. On top: the manifests create their namespace, pin the images to a release and the media download to a git version, the guide is linked from the self-hosting guide, and it explains why TRUST_PROXY stays off behind a gateway.

@kquinsland01, thanks for the notes. Health/ready probes and the read-only-filesystem tweaks would be welcome as a follow-up PR.

Released in v1.3.9: https://github.com/DuarteSantos8/openGym/releases/tag/v1.3.9

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants