apiVersion: apps/v1 kind: Deployment metadata: name: {{ include "agent-monitor.fullname" . }} labels: {{- include "agent-monitor.labels" . | nindent 4 }} spec: {{- if not .Values.autoscaling.enabled }} replicas: {{ .Values.replicaCount }} {{- end }} revisionHistoryLimit: {{ .Values.deployment.revisionHistoryLimit | default 5 }} {{- with .Values.deployment.strategy }} strategy: {{- toYaml . | nindent 4 }} {{- end }} selector: matchLabels: {{- include "agent-monitor.selectorLabels" . | nindent 6 }} template: metadata: annotations: checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} {{- with .Values.podAnnotations }} {{- toYaml . | nindent 8 }} {{- end }} labels: {{- include "agent-monitor.labels" . | nindent 8 }} {{- with .Values.podLabels }} {{- toYaml . | nindent 8 }} {{- end }} spec: {{- with .Values.imagePullSecrets }} imagePullSecrets: {{- toYaml . | nindent 8 }} {{- end }} serviceAccountName: {{ include "agent-monitor.serviceAccountName" . }} automountServiceAccountToken: false {{- with .Values.podSecurityContext }} securityContext: {{- toYaml . | nindent 8 }} {{- end }} containers: # ── Main application container ──────────────────────────────────── - name: {{ .Chart.Name }} {{- with .Values.securityContext }} securityContext: {{- toYaml . | nindent 12 }} {{- end }} image: {{ include "agent-monitor.image" . }} imagePullPolicy: {{ .Values.image.pullPolicy }} ports: - name: http containerPort: {{ .Values.service.targetPort }} protocol: TCP {{- with .Values.livenessProbe }} livenessProbe: {{- toYaml . | nindent 12 }} {{- end }} {{- with .Values.readinessProbe }} readinessProbe: {{- toYaml . | nindent 12 }} {{- end }} {{- with .Values.startupProbe }} startupProbe: {{- toYaml . | nindent 12 }} {{- end }} envFrom: - configMapRef: name: {{ include "agent-monitor.fullname" . }}-config {{- with .Values.extraEnvFrom }} {{- toYaml . | nindent 12 }} {{- end }} {{- with .Values.resources }} resources: {{- toYaml . | nindent 12 }} {{- end }} lifecycle: preStop: exec: # Allow in-flight requests (including WebSockets) to drain before SIGTERM command: ["sh", "-c", "sleep 5"] volumeMounts: - name: data mountPath: /app/data - name: tmp mountPath: /tmp {{- if .Values.mcp.enabled }} # ── MCP sidecar container ───────────────────────────────────────── - name: mcp {{- with .Values.mcp.securityContext }} securityContext: {{- toYaml . | nindent 12 }} {{- end }} image: {{ include "agent-monitor.mcpImage" . }} imagePullPolicy: {{ .Values.mcp.image.pullPolicy }} ports: - name: mcp containerPort: {{ .Values.mcp.port }} protocol: TCP env: {{- range $key, $value := .Values.mcp.env }} - name: {{ $key }} value: {{ $value | quote }} {{- end }} startupProbe: tcpSocket: port: mcp failureThreshold: 30 periodSeconds: 2 livenessProbe: tcpSocket: port: mcp initialDelaySeconds: 15 periodSeconds: 20 timeoutSeconds: 3 failureThreshold: 3 readinessProbe: tcpSocket: port: mcp initialDelaySeconds: 5 periodSeconds: 10 timeoutSeconds: 3 failureThreshold: 3 {{- with .Values.mcp.resources }} resources: {{- toYaml . | nindent 12 }} {{- end }} volumeMounts: - name: tmp mountPath: /tmp {{- end }} volumes: - name: data {{- if .Values.persistence.enabled }} persistentVolumeClaim: claimName: {{ .Values.persistence.existingClaim | default (printf "%s-data" (include "agent-monitor.fullname" .)) }} {{- else }} emptyDir: {} {{- end }} - name: tmp emptyDir: sizeLimit: 100Mi terminationGracePeriodSeconds: 30 {{- with .Values.nodeSelector }} nodeSelector: {{- toYaml . | nindent 8 }} {{- end }} {{- with .Values.affinity }} affinity: {{- toYaml . | nindent 8 }} {{- end }} {{- with .Values.tolerations }} tolerations: {{- toYaml . | nindent 8 }} {{- end }} {{- with .Values.topologySpreadConstraints }} topologySpreadConstraints: {{- toYaml . | nindent 8 }} {{- end }}