From 808a05fadf21989f00b444c43e649846c7d80957 Mon Sep 17 00:00:00 2001 From: Sheikah45 Date: Mon, 7 Sep 2026 19:39:59 -0400 Subject: [PATCH 1/5] add ucp config options --- .../mail/account-deletion-confirmation.html | 491 ++++++++++++++++++ .../mail/account-deletion-notification.html | 400 ++++++++++++++ .../templates/config-files.yaml | 4 + apps/faf-user-service/templates/config.yaml | 8 +- .../templates/local-secret.yaml | 1 + apps/rabbitmq/templates/config.yaml | 2 +- apps/rabbitmq/values.yaml | 4 + 7 files changed, 908 insertions(+), 2 deletions(-) create mode 100644 apps/faf-user-service/mail/account-deletion-confirmation.html create mode 100644 apps/faf-user-service/mail/account-deletion-notification.html diff --git a/apps/faf-user-service/mail/account-deletion-confirmation.html b/apps/faf-user-service/mail/account-deletion-confirmation.html new file mode 100644 index 00000000..a514466c --- /dev/null +++ b/apps/faf-user-service/mail/account-deletion-confirmation.html @@ -0,0 +1,491 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Confirm your FAF account deletion
+ +
+ + + + +
+
+ + + + + + +
+ + +
+ + + + + + + + + + + + + + + + + + + + + +
+ +
 
+ +
+ + + + + + + +
+ + FAF Logo + +
+ +
+ +
Forged Alliance Forever
+ +
+ +
 
+ +
+ +
+ + +
+
+
+ + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + + + + + + + + + +
+ +

Confirm your account deletion

+ +

Dear {{`{{username}}`}},

+ +

+ We received a request to permanently delete your FAForever account. + Click the button below to confirm this request. +

+ +

+ Once confirmed, your account will be deleted or anonymized in accordance + with our account deletion process. This action cannot be undone. +

+ +
+ + + + + + + +
+ + Confirm account deletion + +
+ +
+ +

Thanks,

+

-- The FAForever team

+ +
+ +
+ + +
+ +
+ + + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

+ If you did not request this deletion, you can safely ignore this email. + Your account will remain unchanged unless you confirm the request. +

+ +
+ +
+ + +
+ +
+ + + + + + + + + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

+ If the button above does not work, open this URL manually in your browser: + {{`{{confirmationUrl}}`}} +

+ +
+ +
+ + +
+ +
+ + + + + +
+ + + + \ No newline at end of file diff --git a/apps/faf-user-service/mail/account-deletion-notification.html b/apps/faf-user-service/mail/account-deletion-notification.html new file mode 100644 index 00000000..d2a86a13 --- /dev/null +++ b/apps/faf-user-service/mail/account-deletion-notification.html @@ -0,0 +1,400 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Your FAF account has been deleted
+ +
+ + + + +
+
+ + + + + + +
+ + +
+ + + + + + + + + + + + + + + + + + + + + +
+ +
 
+ +
+ + + + + + + +
+ + FAF Logo + +
+ +
+ +
Forged Alliance Forever
+ +
+ +
 
+ +
+ +
+ + +
+
+
+ + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

Your account has been deleted

+ +

Dear {{`{{username}}`}},

+ +

+ Your FAForever account deletion request has now been completed. +

+ +

+ Your personal account data has been deleted or anonymized in accordance + with our account deletion process. +

+ +

Thanks,

+

-- The FAForever team

+ +
+ +
+ + +
+ +
+ + + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

+ If you did not request this account deletion, please contact the FAForever team immediately. +

+ +
+ +
+ + +
+ +
+ + + + + + + + + + + +
+ + + + \ No newline at end of file diff --git a/apps/faf-user-service/templates/config-files.yaml b/apps/faf-user-service/templates/config-files.yaml index 1bf82ef3..e4bc1cb4 100644 --- a/apps/faf-user-service/templates/config-files.yaml +++ b/apps/faf-user-service/templates/config-files.yaml @@ -7,6 +7,10 @@ metadata: data: "account-activation.html": |- {{ tpl (.Files.Get "mail/account-activation.html") . | indent 4 }} + "account-deletion-confirmation.html": |- +{{ tpl (.Files.Get "mail/account-deletion-confirmation.html") . | indent 4 }} + "account-deletion-notification.html": |- +{{ tpl (.Files.Get "mail/account-deletion-notification.html") . | indent 4 }} "password-reset.html": |- {{ tpl (.Files.Get "mail/password-reset.html") . | indent 4 }} "welcome-to-faf.html": |- diff --git a/apps/faf-user-service/templates/config.yaml b/apps/faf-user-service/templates/config.yaml index 914f43da..86d6b3ed 100644 --- a/apps/faf-user-service/templates/config.yaml +++ b/apps/faf-user-service/templates/config.yaml @@ -25,4 +25,10 @@ data: LOBBY_URL: "wss://ws.{{.Values.baseDomain}}" IRC_TOKEN_TTL: "86400" REPLAY_URL: "wss://replay-ws.{{.Values.baseDomain}}" - ALTCHA_ENABLED: "true" \ No newline at end of file + ALTCHA_ENABLED: "true" + RABBITMQ_USER: "faf-user-service" + RABBITMQ_PORT: "5672" + RABBITMQ_HOST: "rabbitmq" + NODEBB_READ_API_URL: https://forum.{{.Values.baseDomain}}/api + NODEBB_WRITE_API_URL: https://forum.{{.Values.baseDomain}}/api/v3 + WIKIJS_GRAPHQL_URL: https://wiki.{{.Values.baseDomain}}/graphql diff --git a/apps/faf-user-service/templates/local-secret.yaml b/apps/faf-user-service/templates/local-secret.yaml index f31836fd..bf615074 100644 --- a/apps/faf-user-service/templates/local-secret.yaml +++ b/apps/faf-user-service/templates/local-secret.yaml @@ -12,4 +12,5 @@ stringData: LOBBY_SECRET: "banana" REPLAY_SECRET: "banana" ALTCHA_HMAC_KEY: "bananabananabananabanana" + RABBITMQ_PASSWORD: "banana" {{- end}} diff --git a/apps/rabbitmq/templates/config.yaml b/apps/rabbitmq/templates/config.yaml index dec705fc..af3e16d9 100644 --- a/apps/rabbitmq/templates/config.yaml +++ b/apps/rabbitmq/templates/config.yaml @@ -6,7 +6,7 @@ metadata: app: rabbitmq data: ADMIN_USER: "faf-admin" - "enabled_plugins": "[rabbitmq_management,rabbitmq_prometheus]." + "enabled_plugins": "[rabbitmq_management,rabbitmq_prometheus,rabbitmq_shovel,rabbitmq_shovel_management]." "rabbitmq_conf": |- default_user = $(ADMIN_USER) default_pass = $(ADMIN_PASSWORD) diff --git a/apps/rabbitmq/values.yaml b/apps/rabbitmq/values.yaml index 82b9d710..5dc17484 100644 --- a/apps/rabbitmq/values.yaml +++ b/apps/rabbitmq/values.yaml @@ -26,3 +26,7 @@ users: secretRef: faf-icebreaker usernameKey: RABBITMQ_USER passwordKey: RABBITMQ_PASSWORD + - configMapRef: faf-user-service + secretRef: faf-user-service + usernameKey: RABBITMQ_USER + passwordKey: RABBITMQ_PASSWORD From cfe48ae2103d2af09e37a08f351e637d8c23de97 Mon Sep 17 00:00:00 2001 From: Sheikah45 Date: Sun, 4 Oct 2026 19:51:22 -0400 Subject: [PATCH 2/5] fix tilt dependencies and use check_runninig for rabbitmq startup probe --- Tiltfile | 4 ++-- apps/rabbitmq/templates/statefulset.yaml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/Tiltfile b/Tiltfile index 25bb1e3a..7c33f156 100644 --- a/Tiltfile +++ b/Tiltfile @@ -316,7 +316,7 @@ k8s_resource(workload="mariadb", objects=["mariadb:configmap", "mariadb:secret", mariadb_setup_resources = [] for object in decode_yaml_stream(mariadb_init_user_yaml): mariadb_setup_resources.append(object["metadata"]["name"]) - k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "mariadb", "faf-api-config", "faf-user-service-config", "faf-lobby-server-config", "faf-replay-server-config", "faf-policy-server-config", "faf-league-service-config", "wordpress-config", "ergochat-config"], labels=["database"]) + k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "mariadb", "faf-api-config", "faf-user-service-config", "faf-lobby-server-config", "faf-replay-server-config", "faf-policy-server-config", "faf-league-service-config", "wordpress-config", "ergochat-config", "faf-icebreaker-config"], labels=["database"]) mongodb_yaml = helm_with_build_cache("infra/mongodb", namespace="faf-infra", values=["config/local.yaml"]) mongodb_init_user_yaml, mongodb_resource_yaml = filter_yaml(mongodb_yaml, {"app": "mongodb-sync-db-user"}) @@ -337,7 +337,7 @@ k8s_resource(workload="rabbitmq", objects=["rabbitmq:configmap", "rabbitmq:secre rabbitmq_setup_resources = [] for object in decode_yaml_stream(rabbitmq_init_user_yaml): rabbitmq_setup_resources.append(object["metadata"]["name"]) - k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "rabbitmq", "faf-api-config", "faf-icebreaker-config", "faf-lobby-server-config", "debezium-config", "faf-league-service-config"], labels=["rabbitmq"]) + k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "rabbitmq", "faf-api-config", "faf-icebreaker-config", "faf-lobby-server-config", "debezium-config", "faf-league-service-config", "faf-user-service-config"], labels=["rabbitmq"]) k8s_yaml(cronjob_to_job(helm_with_build_cache("apps/faf-db-migrations", namespace="faf-apps", values=["config/local.yaml"]))) k8s_resource(workload="faf-db-migrations", objects=["faf-db-migrations:secret"], resource_deps=mariadb_setup_resources, labels=["database"]) diff --git a/apps/rabbitmq/templates/statefulset.yaml b/apps/rabbitmq/templates/statefulset.yaml index 802ec2e3..30a0d00c 100644 --- a/apps/rabbitmq/templates/statefulset.yaml +++ b/apps/rabbitmq/templates/statefulset.yaml @@ -32,7 +32,7 @@ spec: protocol: TCP startupProbe: exec: - command: ["rabbitmq-diagnostics", "-q", "ping"] + command: ["rabbitmq-diagnostics", "-q", "check_running"] initialDelaySeconds: 15 timeoutSeconds: 15 periodSeconds: 5 From f69bb154cc615f77ad9279ae1611020997d8c0cb Mon Sep 17 00:00:00 2001 From: Sheikah45 Date: Sun, 4 Oct 2026 20:24:48 -0400 Subject: [PATCH 3/5] Add resource usage hints --- README.MD | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.MD b/README.MD index 336f2dcf..1a8e6440 100644 --- a/README.MD +++ b/README.MD @@ -73,6 +73,8 @@ This repository aims to provide a ready-to-go [Tilt](https://docs.tilt.dev/) set * [helm](https://helm.sh/docs/intro/install/) must be installed to generate the k8s from the helm charts in the gitops repo * For Windows users: * A bash program. By default git bash is used with an assumed installation directory of C:/Program Files/Git +* System Resource Usage + * For local development containers takee about 4GB with docker desktop on windows full k8s used 11GB ## Startup Services In the root directory of the repository run `tilt up`. This will start all the faf services in the correct order. The status of each service can be viewed in the tilt UI by visiting . This is the control server for tilt where you can restart services or disable them for substitution by services you would like to run from source code as you actively develop them. From 8b3f75b58c40772f0e4557c2b349856b961d30a4 Mon Sep 17 00:00:00 2001 From: Sheikah45 Date: Sun, 4 Oct 2026 21:21:24 -0400 Subject: [PATCH 4/5] fix path issues with kind docker desktop --- Tiltfile | 16 +++------------- 1 file changed, 3 insertions(+), 13 deletions(-) diff --git a/Tiltfile b/Tiltfile index 7c33f156..88f760a8 100644 --- a/Tiltfile +++ b/Tiltfile @@ -28,23 +28,16 @@ if os.name == "nt": if not os.path.exists(windows_bash_path): fail("Windows users need to supply a valid path to a bash executable") + data_absolute_path = "//data/" + data_relative_path if k8s_context() == "docker-desktop": hostname = cfg.get("hostname", "host.docker.internal") - drive, path_without_drive = os.getcwd().split(":") - data_absolute_path = os.path.join("//run/desktop/mnt/host/", drive, path_without_drive, data_relative_path).replace("\\","/").lower() - use_named_volumes = ["mariadb"] elif k8s_context() == "minikube" or k8s_context() == "kind-kind": hostname = cfg.get("hostname", "") - data_absolute_path = "//data/" + data_relative_path - use_named_volumes = [] - else: - fail("Cannot determine how to mount for windows host") else: faf_data_dir = cfg.get("faf-data-dir", "~/.faforever") hostname = cfg.get("hostname", "") data_absolute_path = os.path.join(os.getcwd(), data_relative_path) - use_named_volumes = [] host_details = ["hostIP="+host_ip, "hostname="+hostname] @@ -169,15 +162,12 @@ def helm_with_build_cache(chart, namespace="", values=[], set=[], specifier = "" return encode_yaml_stream(objects) -def to_hostpath_storage(yaml, use_named_volumes): +def to_hostpath_storage(yaml): objects = decode_yaml_stream(yaml) for object in objects: if object["kind"] == "PersistentVolume": object["spec"].pop("nodeAffinity", None) localpath_spec = object["spec"].pop("local", {"path": ""}) - if os.path.basename(localpath_spec["path"]) in use_named_volumes: - volume_name = os.path.basename(localpath_spec["path"]) - localpath_spec["path"] = volume_name object["spec"]["hostPath"] = localpath_spec object["spec"]["hostPath"]["type"] = "DirectoryOrCreate" @@ -267,7 +257,7 @@ if not is_ci: k8s_resource(workload="release-name-reloader", new_name="reloader", objects=["release-name-reloader:serviceaccount", "release-name-reloader-metadata-role:role", "release-name-reloader-role:clusterrole", "release-name-reloader-metadata-role-binding:rolebinding", "release-name-reloader-role-binding:clusterrolebinding"], resource_deps=["namespaces"], labels=["core"]) storage_yaml = helm_with_build_cache("cluster/storage", values=["config/local.yaml"], set=["dataPath="+data_absolute_path]) -storage_yaml = to_hostpath_storage(storage_yaml, use_named_volumes=use_named_volumes) +storage_yaml = to_hostpath_storage(storage_yaml) k8s_yaml(storage_yaml) volume_identifiers = [] From b3df5278287fdd0e6c707451eb4408eb0cc70b13 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 15:15:12 +0000 Subject: [PATCH 5/5] Update Helm release secrets-operator to v0.11.11 --- ops/infisical/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ops/infisical/Chart.yaml b/ops/infisical/Chart.yaml index 555cb02c..7955fccb 100644 --- a/ops/infisical/Chart.yaml +++ b/ops/infisical/Chart.yaml @@ -3,5 +3,5 @@ name: infisical version: 1.0.0 dependencies: - name: secrets-operator - version: 0.10.29 + version: 0.11.11 repository: https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/