| 1 | amends "../../config/Service.pkl" |
| 2 | |
| 3 | import "../../config/site.pkl" as site |
| 4 | |
| 5 | local isolated = site.preview || site.domain.endsWith(".test") |
| 6 | |
| 7 | meta { name = "ATProto PDS"; launcher = false } |
| 8 | traceServiceName = module.id |
| 9 | metricsPushed = true |
| 10 | rollout = "simple" |
| 11 | stageIsolation = "fresh" |
| 12 | dependsOn { "victoria" } |
| 13 | |
| 14 | secrets = if (isolated) new { |
| 15 | ["jwt_secret"] {} |
| 16 | ["admin_password"] {} |
| 17 | ["plc_rotation_key"] {} |
| 18 | } else new {} |
| 19 | |
| 20 | requiredSecrets = if (isolated) new {} else new { |
| 21 | "jwt_secret" |
| 22 | "admin_password" |
| 23 | "plc_rotation_key" |
| 24 | "mailer_address" |
| 25 | "mailer_username" |
| 26 | "mailer_password" |
| 27 | } |
| 28 | |
| 29 | container { |
| 30 | image = "ghcr.io/bluesky-social/pds@sha256:d155af1c906d7848e7dea9d59a8a7def065a04b77aa98ae56ea05a8d4eadb63a" |
| 31 | entrypoint = "/bin/sh" |
| 32 | args { "/studio/start.sh" } |
| 33 | cpu = 250 |
| 34 | memory = 512 |
| 35 | |
| 36 | http { |
| 37 | containerPort = 3000 |
| 38 | subdomain = "at" |
| 39 | checkPath = "/xrpc/_health" |
| 40 | } |
| 41 | |
| 42 | volumes { |
| 43 | ["/pds"] {} |
| 44 | ["/studio/start.sh"] { config = "start.sh" } |
| 45 | } |
| 46 | |
| 47 | env { |
| 48 | ["HOME_DOMAIN"] = site.domain |
| 49 | ["PDS_HOSTNAME"] = module.container.http.hostname |
| 50 | ["PDS_JWT_SECRET"] = "${secret.own.jwt_secret}" |
| 51 | ["PDS_ADMIN_PASSWORD"] = "${secret.own.admin_password}" |
| 52 | ["PDS_PLC_ROTATION_KEY_K256_PRIVATE_KEY_HEX"] = "${secret.own.plc_rotation_key}" |
| 53 | ["PDS_DATA_DIRECTORY"] = "/pds" |
| 54 | ["PDS_BLOBSTORE_DISK_LOCATION"] = "/pds/blocks" |
| 55 | ["PDS_DID_PLC_URL"] = if (isolated) "http://127.0.0.1:1" else "https://plc.directory" |
| 56 | ["PDS_BSKY_APP_VIEW_URL"] = "https://api.bsky.app" |
| 57 | ["PDS_BSKY_APP_VIEW_DID"] = "did:web:api.bsky.app" |
| 58 | ["PDS_REPORT_SERVICE_URL"] = "https://mod.bsky.app" |
| 59 | ["PDS_REPORT_SERVICE_DID"] = "did:plc:ar7c4by46qjdydhdevvrndac" |
| 60 | ["PDS_CRAWLERS"] = if (isolated) "" else "https://bsky.network" |
| 61 | ["PDS_INVITE_REQUIRED"] = if (isolated) "true" else "false" |
| 62 | ["PDS_RATE_LIMITS_ENABLED"] = "true" |
| 63 | ["PDS_CONTACT_EMAIL_ADDRESS"] = site.ownerEmail |
| 64 | ["LOG_ENABLED"] = "true" |
| 65 | ["NODE_OPTIONS"] = "--import=@atproto/pds/telemetry" |
| 66 | ["OTEL_SERVICE_NAME"] = module.id |
| 67 | ["OTEL_EXPORTER_OTLP_TRACES_PROTOCOL"] = "http/protobuf" |
| 68 | ["OTEL_EXPORTER_OTLP_METRICS_PROTOCOL"] = "http/protobuf" |
| 69 | ["OTEL_METRIC_EXPORT_INTERVAL"] = "15000" |
| 70 | ["OTEL_SEMCONV_STABILITY_OPT_IN"] = "http" |
| 71 | ["OTEL_TRACES_SAMPLER"] = "parentbased_traceidratio" |
| 72 | ["OTEL_TRACES_SAMPLER_ARG"] = "0.25" |
| 73 | ["OTEL_NODE_RESOURCE_DETECTORS"] = "env,host,os,process,serviceinstance,container" |
| 74 | ["MAILER_ADDRESS"] = if (isolated) "" else "${secret.own.mailer_address}" |
| 75 | ["MAILER_USERNAME"] = if (isolated) "" else "${secret.own.mailer_username}" |
| 76 | ["MAILER_PASSWORD"] = if (isolated) "" else "${secret.own.mailer_password}" |
| 77 | } |
| 78 | |
| 79 | envTemplate = """ |
| 80 | {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "victoria-traces" }}OTEL_EXPORTER_OTLP_TRACES_ENDPOINT=http://\(module.nomadHostPort)/insert/opentelemetry/v1/traces{{ end }} |
| 81 | {{ range nomadService 1 (env "NOMAD_ALLOC_ID") "victoria-metrics" }}OTEL_EXPORTER_OTLP_METRICS_ENDPOINT=http://\(module.nomadHostPort)/opentelemetry/v1/metrics{{ end }} |
| 82 | """ |
| 83 | } |