k8s(pilot): dashboard deploy manifest + README; pin NodePort 31540

This commit is contained in:
Claude
2026-08-22 17:01:34 +00:00
parent 218a8dc271
commit 5fe83b0b2a
2 changed files with 9 additions and 8 deletions
+6 -6
View File
@@ -13,7 +13,7 @@ and the dashboard is just `python3 -m pilot.dashboard`.
Browser (tailnet)
NodePort :30082 on 100.74.17.70 (kubernets)
NodePort :31540 on 100.74.17.70 (kubernets)
Service pragent-dashboard.pragent.svc.cluster.local (NodePort, ns pragent)
@@ -160,7 +160,7 @@ K8s manifest at `~/k8s/pragent-dashboard.yaml`. Key fields:
- `resources.requests: {cpu: 100m, memory: 256Mi}` /
`limits: {cpu: 500m, memory: 512Mi}` — read-heavy + tiny writes, no
opencode subprocess fan-out, much smaller than the webhook.
- `Service.type: NodePort`, `nodePort: 30082` — between pages-proxy
- `Service.type: NodePort`, `nodePort: 31540` — between pages-proxy
(30081) and browserless (30100), outside the 30096..30969 media range.
## Smoke test
@@ -178,17 +178,17 @@ kill %1
# 2. NodePort (host-side, Tailscale IP — only reachable on 100.74.17.70
# or 192.168.1.80; no public DNS yet)
curl -s -o /tmp/dash-nodeport.html -w "HTTP %{http_code}\n" \
http://100.74.17.70:30082/
http://100.74.17.70:31540/
grep -o "<title>[^<]*</title>" /tmp/dash-nodeport.html
# 3. auth: POST the login cookie value, capture into a jar
curl -sS -c /tmp/dash.jar -X POST \
-d "token=$(cat ~/.config/pragent/dashboard-token)" \
http://100.74.17.70:30082/login
http://100.74.17.70:31540/login
# 4. authenticated overview
curl -sS -b /tmp/dash.jar -o /tmp/dash-auth.html -w "HTTP %{http_code}\n" \
http://100.74.17.70:30082/
http://100.74.17.70:31540/
grep -o "<title>[^<]*</title>" /tmp/dash-auth.html
# 5. pod logs
@@ -202,7 +202,7 @@ to `/login` on the unauthenticated GETs is expected when
## Threat model / security notes
- **Tailnet-only by default.** NodePort 30082 is exposed on the
- **Tailnet-only by default.** NodePort 31540 is exposed on the
Tailscale / LAN interfaces of kubernets (100.74.17.70, 192.168.1.80).
No public DNS, no Caddy route yet — keep it that way until the auth
story is solid. When you do add a public route, terminate TLS at