Commit Graph

384 Commits

Author SHA1 Message Date
Will Anderson 90bde78d7a feat(marketing): add NEURON_LICENSE_ADMIN_TOKEN to ExternalSecret 2026-04-24 15:19:15 -05:00
Will Anderson fe17d020ef fix(k8s): use Recreate strategy for neuron-mcp deployments
Single-node k3s cluster cannot schedule a second pod during rolling update
(512Mi request × 2 exceeds available memory). Recreate terminates the old
pod before starting the new one, trading brief downtime for schedulability.
2026-04-24 15:19:10 -05:00
Will Anderson 95b4669839 feat(neuron-prod): add IngressRoute for license API at /api/v1/* paths 2026-04-24 15:12:37 -05:00
Will Anderson c238fbb198 fix(marketing): point license API URL to neuron-license service on correct port 8082 2026-04-24 15:10:08 -05:00
Will Anderson d9257ab1b7 feat(marketing): expose Team and Enterprise Stripe price IDs via ExternalSecret 2026-04-24 14:34:59 -05:00
Will Anderson 02db9c3d43 feat(observability): wire OpenTelemetry into MCP backend and marketing site
- Add OTEL_EXPORTER_OTLP_ENDPOINT env var to prod and stage MCP deployments pointing at Alloy in-cluster
- Add Neuron Platform Overview Grafana dashboard (request rate, latency percentiles, error rate, memory nodes, HTTP status distribution)
- Allow grafana/dashboards/*.json through .gitignore (was blocked by secrets rule)
2026-04-24 14:21:34 -05:00
Will Anderson 2d98df75ad Deploy Plane project management to k8s with Cloudflare Access gate
Adds all k8s manifests (namespace, postgres, redis, api, worker, beat,
web, ingress, externalsecret, configmap, kustomization), Argo CD Application,
and Cloudflare Zero Trust access policy for plane.neuralplatform.ai.
2026-04-24 14:21:02 -05:00
Will Anderson e901b9a541 Add staging marketing site and Cloudflare Access gate
- Deploy marketing site to neuron-stage namespace (replaces bare REST catch-all)
- Staging uses test-mode Stripe keys from Vault
- Updated stage ingress to match prod routing pattern (MCP paths + marketing at /)
- Cloudflare Access: stage.neurontechnologies.ai requires Google auth
  - @neurontechnologies.ai domain allowed
  - 1timlingo@gmail.com explicitly allowed
2026-04-24 13:43:12 -05:00
Neuron CI 477af9b673 ci(neuron-prod): deploy neuron@v0.7.0 2026-04-24 18:32:40 +00:00
Neuron CI b187805e63 ci(neuron-stage): deploy neuron@stage-6d08a241 2026-04-24 18:23:50 +00:00
Will Anderson 0bb18cedac Route /connect to neuron-mcp for OAuth dynamic client registration 2026-04-24 13:16:36 -05:00
Will Anderson 0f9448e8ea deploy neuron marketing site to neurontechnologies.ai
Add marketing/ manifests (Deployment, Service, ExternalSecret) for the
Next.js marketing site in neuron-prod namespace, an Argo CD app pointing
to the new path, and update the prod ingress to serve / from neuron-marketing
instead of neuron-rest.
2026-04-24 13:09:29 -05:00
Will Anderson ebe4789935 Route /.well-known, /oauth2, /login, /sse, /message to neuron-mcp
OAuth discovery endpoints (/.well-known/oauth-protected-resource and
/.well-known/oauth-authorization-server) and the authorization server
paths (/oauth2/*, /login) were routing to neuron-rest, which has none
of those endpoints. MCP also uses /sse and /message directly.

All five path prefixes now route to neuron-mcp on port 8080.
2026-04-24 13:00:56 -05:00
Will Anderson 336a9333a2 prepare neuron-tim namespace for Tim's future Neuron instance
Adds the neuron-tim namespace (via Terraform) and a full Argo CD
app + k8s manifests mirroring neuron-prod. All deployments set to
replicas=0 — nothing runs until Tim's imprint is ready and Vault
secrets are populated at secret/neuron-technologies/tim.
2026-04-24 12:52:36 -05:00
Will Anderson 92743b1efc add redpanda to legion cluster
Deploy single-broker Redpanda in dedicated namespace with 20Gi storage,
1 CPU / 2Gi memory limits, and a one-shot topic init job for neuron.swarm,
neuron.ci, neuron.vcs, and neuron.webhooks with appropriate retention.
2026-04-24 12:39:02 -05:00
Neuron CI befbc006be ci(neuron-prod): deploy neuron@v0.6.1 2026-04-24 17:35:59 +00:00
Neuron CI 91e7607c28 ci(neuron-stage): deploy neuron@stage-fa185003 2026-04-24 17:31:16 +00:00
Neuron CI 5eb18b6e7c ci(neuron-prod): deploy neuron@v0.6.0 2026-04-24 17:20:57 +00:00
Neuron CI 88d8b34724 ci(neuron-stage): deploy neuron@stage-fcc34199 2026-04-24 17:16:51 +00:00
Will Anderson 0858844c25 neuron-prod: add NEURON_API_KEY to ExternalSecret from Vault 2026-04-24 12:07:08 -05:00
Neuron CI 48e349559d ci(neuron-stage): deploy neuron@stage-0879a862 2026-04-24 15:48:03 +00:00
Neuron CI fb17a37bea ci(neuron-prod): deploy neuron@v0.5.0 2026-04-24 15:42:48 +00:00
Neuron CI 058f52ec21 ci(neuron-stage): deploy neuron@stage-5d3537e1 2026-04-24 15:34:21 +00:00
Neuron CI e68836de8d ci(neuron-stage): deploy neuron@stage-473abea9 2026-04-24 15:25:09 +00:00
Neuron CI f729ef9812 ci(neuron-stage): deploy neuron@stage-94b7a876 2026-04-24 13:02:44 +00:00
Neuron CI 6f349a21b9 ci(neuron-prod): deploy neuron@v0.4.4 2026-04-24 12:44:46 +00:00
Neuron CI 8e27d7e069 ci(neuron-prod): deploy neuron@v0.4.3 2026-04-24 12:05:43 +00:00
Neuron CI 5f99d10839 ci(neuron-prod): deploy neuron@v0.4.2 2026-04-24 11:47:42 +00:00
Neuron CI ec2ee48ae5 ci(neuron-prod): deploy neuron@v0.4.1 2026-04-24 11:42:27 +00:00
Will Anderson 3b2b1d037c fix(neuron-stage): set NEURON_DATA_DIR=/data for persistent Kotlin DB
The Kotlin NeuronModule reads NEURON_DATA_DIR to locate the SQLite file.
The stage configmap only had NEURON_DB_PATH/NEURON_STORAGE_PATH which
the Kotlin code doesn't read, causing it to fall back to a temp file
that was wiped on every pod restart.

Adding NEURON_DATA_DIR=/data ensures the server reads from the persistent
PVC-backed /data/neuron.db going forward.
2026-04-24 06:36:13 -05:00
Neuron CI 0f77faea81 ci(neuron-prod): deploy neuron@v0.4.0 2026-04-24 10:22:56 +00:00
Will Anderson add9d92fd0 chore(neuron-prod): restart pods to pick up NEURON_DATA_DIR configmap change 2026-04-24 04:57:11 -05:00
Will Anderson b5e8ea9111 fix(neuron-prod): set NEURON_DATA_DIR to point app to PVC database
NeuronModule reads NEURON_DATA_DIR to construct the DB path as
$NEURON_DATA_DIR/neuron.db. Without this env var the app falls
back to a temp file, losing all data on pod restart. Also renamed
the PVC file from neuron-prod.db to neuron.db to match.
2026-04-24 04:56:29 -05:00
Will Anderson 883c4afd50 ci(neuron-prod): restart mcp and rest pods to reload DB state 2026-04-24 04:47:33 -05:00
Neuron CI bd2a6ccddb ci(neuron-stage): deploy neuron@stage-e743beed 2026-04-24 09:25:54 +00:00
Neuron CI 87d11aa87c ci(neuron-prod): deploy neuron@v0.3.2 2026-04-24 09:21:57 +00:00
Will Anderson 9d824aaf1f feat(neuron-stage): scale stage MCP and REST to 1 replica for cultivation loop 2026-04-24 04:03:01 -05:00
Neuron CI 129dd0d606 ci(neuron-prod): deploy neuron@v0.3.1 2026-04-24 08:58:38 +00:00
Will Anderson 9bf99bdd8e fix(neuron-prod): add PVC and volume mount for neuron-license SQLite data
The license server writes its database to /data/neuron-license.db.
The deployment had no volume, causing CrashLoopBackOff on first start.
2026-04-24 03:13:56 -05:00
Neuron CI d66062b4cc ci(neuron-prod): deploy neuron@v0.3.0 2026-04-24 08:12:04 +00:00
Neuron CI 7a47e0cbf9 ci(neuron-prod): deploy neuron@v0.2.0 2026-04-24 08:04:37 +00:00
Will Anderson 59aa0f0dfb deploy neuron-license service to prod
Adds license deployment, service, ingress route (/license), and
Unkey + admin token secrets via ExternalSecret. Image built and
pushed by CI on merge of neuron PR #30.
2026-04-24 01:42:07 -05:00
Will Anderson b1867a542d add nightly Vault raft snapshot backup to R2
Snapshot via vault operator raft snapshot save using a least-privilege
periodic token. Stored in legion-vault-backup R2 bucket via restic.
Retains 30 daily / 12 weekly / 6 monthly snapshots. Runs at 3am,
offset from the Gitea backup at 2am.
2026-04-24 01:36:30 -05:00
Will Anderson 816d79760d add alpha/beta/gamma subdomains on neurontechnologies.ai
- Tunnel ingress rules for alpha/beta/gamma.neurontechnologies.ai
- DNS CNAME records pointing to legion tunnel
- k8s ingress rules routing to neuron-alpha/beta/gamma services (port 8001)
- TLS certs via cert-manager for new hostnames
2026-04-24 01:13:03 -05:00
Neuron CI 3e28dd88eb ci(neuron-prod): deploy neuron@v0.0.15 2026-04-24 05:45:09 +00:00
Neuron CI 97973ba6be ci(neuron-prod): deploy neuron@v0.0.14 2026-04-24 05:35:02 +00:00
Neuron CI c3f2ecc9a9 ci(neuron-prod): deploy neuron@v0.0.13 2026-04-24 05:16:25 +00:00
Neuron CI b9e1c94b36 ci(neuron-prod): deploy neuron@v0.0.11 2026-04-24 04:53:51 +00:00
Neuron CI 69c2f1d2f9 ci(neuron-prod): deploy neuron@v0.0.8 2026-04-24 04:23:02 +00:00
Neuron CI 0b23a5e964 ci(neuron-prod): deploy neuron@v0.0.7 2026-04-24 04:14:10 +00:00