apiVersion: apps/v1 kind: Deployment metadata: name: soma namespace: neuron-prod labels: app: soma env: prod spec: replicas: 1 selector: matchLabels: app: soma template: metadata: labels: app: soma env: prod spec: securityContext: runAsUser: 1000 fsGroup: 1000 seccompProfile: type: RuntimeDefault containers: - name: soma image: registry.neuralplatform.ai/soma:latest imagePullPolicy: Always ports: - name: http containerPort: 8080 env: - name: SOMA_CONFIG_PATH value: /etc/soma/soma.toml envFrom: - secretRef: name: soma-secrets volumeMounts: - name: config mountPath: /etc/soma securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: false capabilities: drop: ["ALL"] resources: requests: cpu: 500m memory: 512Mi limits: cpu: 2000m memory: 1Gi livenessProbe: httpGet: path: /health port: 8080 initialDelaySeconds: 10 periodSeconds: 30 readinessProbe: httpGet: path: /health port: 8080 initialDelaySeconds: 5 periodSeconds: 10 volumes: - name: config configMap: name: soma-config