# sowai-fiscal-svc — dev deploy (cluster sow-dev, namespace autopecas-dev). # Internal ClusterIP only: the consumer (auto's HttpEmitter, F3) reaches it via # cluster DNS `fiscal-svc.autopecas-dev.svc.cluster.local:8140`. No Ingress — # the service is never exposed to the internet (fiscal data + A1 certs). # # DB: dedicated database `fiscal_svc` on the SHARED auto-postgres instance # (spec decision #2, amended: dedicated DATABASE, not a schema). Create it once: # kubectl -n autopecas-dev exec deploy/auto-postgres -- \ # createdb -U postgres fiscal_svc # # Secret `fiscal-svc-secrets` carries the Fernet key for A1 cert ciphertext at # rest (FISCAL_CERT_ENCRYPTION_KEY, read from os.environ by certificates.crypto). # It is NOT in this manifest — created imperatively at deploy so the key never # lands in git: # python3 -c "from cryptography.fernet import Fernet; \ # print('FISCAL_CERT_ENCRYPTION_KEY='+Fernet.generate_key().decode())" \ # | kubectl -n autopecas-dev create secret generic fiscal-svc-secrets \ # --from-env-file=/dev/stdin # (Losing/rotating it makes existing cert ciphertext undecryptable — in dev, # re-upload the cert. Same "secrets don't live in Settings/git" convention as # the auto's auto-fiscal-cert Secret.) apiVersion: apps/v1 kind: Deployment metadata: name: fiscal-svc namespace: autopecas-dev labels: app: fiscal-svc spec: replicas: 1 # Recreate (not RollingUpdate): the node runs near 100% CPU, and a surge pod # would sit Pending and stall the rollout (same reason the auto uses # maxSurge:0 / Recreate). Kill old before new. strategy: type: Recreate selector: matchLabels: app: fiscal-svc template: metadata: labels: app: fiscal-svc spec: imagePullSecrets: - name: registry-credentials initContainers: # Migrations against the dedicated fiscal_svc DB before serving. - name: migrate image: registry.sowai.com.br/autopecas/fiscal-svc:dev # :dev is a mutable tag — always re-pull so a rebuild is picked up # (default IfNotPresent would run stale migrations). imagePullPolicy: Always command: ["uv", "run", "alembic", "upgrade", "head"] env: - name: DATABASE_URL value: postgresql+asyncpg://postgres:postgres@auto-postgres:5432/fiscal_svc containers: - name: fiscal-svc image: registry.sowai.com.br/autopecas/fiscal-svc:dev imagePullPolicy: Always ports: - containerPort: 8140 env: - name: DATABASE_URL value: postgresql+asyncpg://postgres:postgres@auto-postgres:5432/fiscal_svc envFrom: # Fernet key for A1 certificate ciphertext (see header). Without it # the first certificate upload fails loudly at deploy — not silent. - secretRef: name: fiscal-svc-secrets resources: requests: cpu: 50m memory: 192Mi limits: cpu: "1" memory: 768Mi readinessProbe: httpGet: path: /v1/health port: 8140 initialDelaySeconds: 8 periodSeconds: 10 livenessProbe: httpGet: path: /v1/health port: 8140 initialDelaySeconds: 25 periodSeconds: 20 --- apiVersion: v1 kind: Service metadata: name: fiscal-svc namespace: autopecas-dev labels: app: fiscal-svc spec: selector: app: fiscal-svc ports: - port: 8140 targetPort: 8140