Deployment model¶
dyson-deployment is the GitOps source of truth for running Dyson. Application
code, Dockerfiles, tests, and image publishing stay in dyson; Kubernetes,
platform services, and environment desired state stay in dyson-deployment.
Release flow¶
Dyson commit
-> test and build component images
-> publish signed immutable ECR digests
-> update an environment overlay
-> Argo CD reconciles the selected cluster
Components are promoted independently. An API change does not require changing
the strategy, market-data, or control-panel digest. Environments select exact
digests rather than rebuilding or consuming latest.
Configuration ownership¶
| Path | Owns |
|---|---|
apps/ |
Reusable workload, service, storage, and service-account bases |
environments/ |
Image digests, replicas, deployment IDs, namespaces, and secret references |
clusters/ |
Argo CD child applications, destinations, sync waves, and sync policy |
bootstrap/ |
Argo CD project and root applications |
platform/ |
NATS, observability, alerting, and single-node data services |
Secrets are supplied through Doppler-backed or deliberately created Kubernetes Secrets. Secret values do not belong in Git.
Deployment shapes¶
Single-node staging¶
The staging-only K3s topology defines Argo CD, NATS, a Mongo-compatible store, InfluxDB, Grafana, and Dyson workloads on one host. It is intentionally non-HA, uses local persistent volumes, and is suitable for integration testing only.
The committed staging overlay declares one replica each for market data, the Strategy API, and the control panel. Order-executing strategy workloads remain scaled to zero until explicitly activated.
Cluster environments¶
Dev and staging target the non-production cluster; production targets its own cluster. Shared platform definitions provide NATS and the monitoring stack. Most non-production applications auto-sync, while secrets require deliberate initial synchronization. Production applications require manual sync.
Current workload coverage¶
Reusable manifests exist for market data, the Strategy API, the control panel,
and toxic-taker. Dyson also builds kuru-quoter, but this deployment repository
does not yet contain its workload manifest. No committed environment currently
enables an order-executing strategy.
Activation boundary¶
Before increasing an execution-capable replica count, confirm that the overlay pins a real digest, required secrets and data services are reachable, MongoDB contains the selected deployment/version documents, NATS subjects align with the publishers and strategy, and the strategy remains intentionally stopped until the operator starts it.