Skip to content

Add faf-tournaments - #334

Merged
Sheikah45 merged 2 commits into
FAForever:developfrom
TimMasalme:feat/faf-tournaments
Oct 5, 2026
Merged

Sheikah45 merged 2 commits into
FAForever:developfrom
TimMasalme:feat/faf-tournaments

Conversation

@TimMasalme

Copy link
Copy Markdown
Contributor

Adds the tournament site, FAForever/faf-tournaments, which is hosted privately on tournaments.doodlepros.com today. A Node.js service with no runtime dependencies that keeps its data in one db.json plus three image folders, so it gets its own small volume and touches none of the shared databases.

What's in it

  • apps/faf-tournaments: Deployment, Service, IngressRoute (tournaments.$BASE_DOMAIN), ConfigMap, local secret.
    • Release = push to main in faf-tournaments. Its workflow republishes faforever/faf-tournaments:latest (already on Docker Hub, plus a tag per commit), and Keel rolls it out. Polled @every 2m instead of hourly, because tournaments run live and a fix can't wait an hour.
    • strategy: Recreate: one db.json on one volume, so the old pod has to be gone before the new one starts.
    • The image runs as uid 1000; an init container chowns the volume, since a local volume keeps the owner its directory was created with.
    • Liveness/readiness on GET /healthz. On SIGTERM the app writes any pending save before exiting.
  • cluster/storage: a 5Gi faf-tournaments volume in faf-apps.
  • apps/ory-hydra: https://tournaments.$BASE_DOMAIN/auth/faf/callback added as a second redirect URI on the existing "FAF Tournaments" client, so the old and new host both work during the move. The app's FAF_CLIENT_ID is that client's id.
  • Tiltfile: the service, depending only on volumes (and Traefik through its IngressRoute).

Needed before it starts on a cluster

Infisical, path /faf-tournaments:

  • ADMIN_PASSWORD: the bootstrap site-admin password (Nuggets has the current one).
  • FAF_CLIENT_SECRET: the same value as Hydra's FAFTOURNEY_SECRET. Without it the site still runs, with FAF login off and name-only login.

Tested locally

  • helm lint and helm template with config/local.yaml.
  • With Tilt on Docker Desktop: the pod becomes ready, the init container hands over the volume, https://tournaments.faforever.localhost/healthz answers through Traefik, and a tournament created through the API is still on the volume after kubectl rollout restart.
  • The image itself: CI checks in a node:24 container, SIGTERM save on docker stop, data across a container restart.

Not tested

  • A full tilt ci did not complete on my machine (6 GB for Docker isn't enough for the whole stack). faf-tournaments came up in every attempt; the failures were elsewhere in the stack.
  • Keel, Infisical and FAF login only exist on the real clusters, so they get checked on test first.

Data from the current server moves once, at switch-over, from an archive of its Docker volume.

The tournament site (FAForever/faf-tournaments), until now hosted
privately. A Node.js service with no runtime dependencies that keeps
its data in one db.json plus image folders, so it gets its own small
volume and nothing in the shared databases.

- Released by pushing to main in its repository: the image is
  republished as faforever/faf-tournaments:latest and Keel rolls it out,
  polled every two minutes because tournaments run live.
- Recreate strategy: one db.json on one volume, so the old pod must be
  gone before the new one starts.
- The image runs as uid 1000; an init container hands it the volume,
  since a local volume keeps the owner its directory was created with.
- /healthz for liveness and readiness.
- FAF login stays dormant until FAF_CLIENT_ID and FAF_CLIENT_SECRET are
  set in the secret.
Hydra already has a client for the site, registered for its current
host. Add the cluster host as a second redirect URI, so both work while
the site moves, and give the app that client id. The secret is Hydra's
FAFTOURNEY_SECRET; until it is in the app's secret, FAF login stays off
and the site uses name-only login.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: dd0a70b5-0b92-48ec-972f-f8c0ccc73d8f
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread apps/faf-tournaments/templates/local-secret.yaml
@Sheikah45
Sheikah45 merged commit b2e0081 into FAForever:develop Oct 5, 2026
2 checks passed
Sheikah45 pushed a commit that referenced this pull request Oct 5, 2026
* Add faf-tournaments

The tournament site (FAForever/faf-tournaments), until now hosted
privately. A Node.js service with no runtime dependencies that keeps
its data in one db.json plus image folders, so it gets its own small
volume and nothing in the shared databases.

- Released by pushing to main in its repository: the image is
  republished as faforever/faf-tournaments:latest and Keel rolls it out,
  polled every two minutes because tournaments run live.
- Recreate strategy: one db.json on one volume, so the old pod must be
  gone before the new one starts.
- The image runs as uid 1000; an init container hands it the volume,
  since a local volume keeps the owner its directory was created with.
- /healthz for liveness and readiness.
- FAF login stays dormant until FAF_CLIENT_ID and FAF_CLIENT_SECRET are
  set in the secret.

* Reuse the existing FAF Tournaments OAuth client

Hydra already has a client for the site, registered for its current
host. Add the cluster host as a second redirect URI, so both work while
the site moves, and give the app that client id. The secret is Hydra's
FAFTOURNEY_SECRET; until it is in the app's secret, FAF login stays off
and the site uses name-only login.
Sheikah45 pushed a commit that referenced this pull request Oct 5, 2026
* Add faf-tournaments

The tournament site (FAForever/faf-tournaments), until now hosted
privately. A Node.js service with no runtime dependencies that keeps
its data in one db.json plus image folders, so it gets its own small
volume and nothing in the shared databases.

- Released by pushing to main in its repository: the image is
  republished as faforever/faf-tournaments:latest and Keel rolls it out,
  polled every two minutes because tournaments run live.
- Recreate strategy: one db.json on one volume, so the old pod must be
  gone before the new one starts.
- The image runs as uid 1000; an init container hands it the volume,
  since a local volume keeps the owner its directory was created with.
- /healthz for liveness and readiness.
- FAF login stays dormant until FAF_CLIENT_ID and FAF_CLIENT_SECRET are
  set in the secret.

* Reuse the existing FAF Tournaments OAuth client

Hydra already has a client for the site, registered for its current
host. Add the cluster host as a second redirect URI, so both work while
the site moves, and give the app that client id. The secret is Hydra's
FAFTOURNEY_SECRET; until it is in the app's secret, FAF login stays off
and the site uses name-only login.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants