feat: add Kubernetes manifests and A2A protocol support

Phase 2 - A2A Protocol:
- Add A2A models (AgentCard, Task, Message)
- Add A2A service layer
- Add A2A routes with SSE streaming
- Add agent discovery endpoints

Phase 3 - Kubernetes:
- Add deploy/ directory with Kustomize structure
- PostgreSQL StatefulSet with pgvector
- Redis Deployment with persistence
- API and Orchestrator Deployments
- RBAC for orchestrator to manage Jobs
- ArgoCD Application manifest
- Development and production overlays
- K8s Jobs API support in orchestrator

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
Renn F
2025-12-28 05:48:51 +01:00
co-authored by Claude Opus 4.5
parent f9398e4caa
commit b943eb7ac1
31 changed files with 3705 additions and 245 deletions
+110
View File
@@ -0,0 +1,110 @@
# RoboCo Orchestrator Deployment
# Manages agent lifecycle and task dispatching
apiVersion: apps/v1
kind: Deployment
metadata:
name: roboco-orchestrator
namespace: roboco
labels:
app.kubernetes.io/name: roboco-orchestrator
app.kubernetes.io/component: orchestrator
spec:
replicas: 1 # Single instance for now (state coordination needed for HA)
selector:
matchLabels:
app: roboco-orchestrator
template:
metadata:
labels:
app: roboco-orchestrator
app.kubernetes.io/name: roboco-orchestrator
spec:
serviceAccountName: roboco-orchestrator
containers:
- name: orchestrator
image: ghcr.io/renzof/roboco-orchestrator:latest
ports:
- containerPort: 8000
name: http
env:
# Database
- name: ROBOCO_DATABASE_HOST
value: postgres
- name: ROBOCO_DATABASE_PORT
value: "5432"
- name: ROBOCO_DATABASE_USER
valueFrom:
secretKeyRef:
name: roboco-secrets
key: postgres-user
- name: ROBOCO_DATABASE_PASSWORD
valueFrom:
secretKeyRef:
name: roboco-secrets
key: postgres-password
- name: ROBOCO_DATABASE_NAME
value: roboco
# Redis
- name: ROBOCO_REDIS_HOST
value: redis
- name: ROBOCO_REDIS_PORT
value: "6379"
# API
- name: ROBOCO_HOST
value: "0.0.0.0"
- name: ROBOCO_PORT
value: "8000"
- name: ROBOCO_API_URL
value: "http://roboco-api:8000"
- name: ROBOCO_ENVIRONMENT
value: production
# K8s settings
- name: ROBOCO_K8S_ENABLED
value: "true"
- name: ROBOCO_K8S_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: ROBOCO_K8S_AGENT_IMAGE
value: "ghcr.io/renzof/roboco-agent"
# LLM
- name: ROBOCO_ANTHROPIC_API_KEY
valueFrom:
secretKeyRef:
name: roboco-secrets
key: anthropic-api-key
volumeMounts:
- name: blueprints
mountPath: /app/agents/blueprints
readOnly: true
- name: claude-auth
mountPath: /root/.claude
resources:
requests:
memory: "256Mi"
cpu: "100m"
limits:
memory: "1Gi"
cpu: "500m"
livenessProbe:
httpGet:
path: /health
port: 8000
initialDelaySeconds: 15
periodSeconds: 10
timeoutSeconds: 5
readinessProbe:
httpGet:
path: /health
port: 8000
initialDelaySeconds: 5
periodSeconds: 5
timeoutSeconds: 3
volumes:
- name: blueprints
configMap:
name: roboco-blueprints
- name: claude-auth
secret:
secretName: claude-auth
optional: true
+31
View File
@@ -0,0 +1,31 @@
# Orchestrator Role
# Permissions for spawning and managing agent Jobs
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: roboco-orchestrator
namespace: roboco
labels:
app.kubernetes.io/name: roboco-orchestrator
app.kubernetes.io/component: orchestrator
rules:
# Create/manage agent Jobs
- apiGroups: ["batch"]
resources: ["jobs"]
verbs: ["create", "delete", "get", "list", "watch", "patch"]
# Watch pods for job status
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch"]
# Read pod logs for debugging
- apiGroups: [""]
resources: ["pods/log"]
verbs: ["get"]
# Manage ConfigMaps for agent configs (MCP configs, prompts)
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["create", "delete", "get", "list", "update", "patch"]
# Read secrets for agent environment (API keys)
- apiGroups: [""]
resources: ["secrets"]
verbs: ["get"]
+17
View File
@@ -0,0 +1,17 @@
# Orchestrator RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: roboco-orchestrator
namespace: roboco
labels:
app.kubernetes.io/name: roboco-orchestrator
app.kubernetes.io/component: orchestrator
subjects:
- kind: ServiceAccount
name: roboco-orchestrator
namespace: roboco
roleRef:
kind: Role
name: roboco-orchestrator
apiGroup: rbac.authorization.k8s.io
+17
View File
@@ -0,0 +1,17 @@
# Orchestrator Service (internal only)
apiVersion: v1
kind: Service
metadata:
name: roboco-orchestrator
namespace: roboco
labels:
app.kubernetes.io/name: roboco-orchestrator
app.kubernetes.io/component: orchestrator
spec:
type: ClusterIP
ports:
- port: 8000
targetPort: 8000
name: http
selector:
app: roboco-orchestrator
@@ -0,0 +1,10 @@
# Orchestrator ServiceAccount
# Used by the orchestrator to interact with K8s API for spawning agent Jobs
apiVersion: v1
kind: ServiceAccount
metadata:
name: roboco-orchestrator
namespace: roboco
labels:
app.kubernetes.io/name: roboco-orchestrator
app.kubernetes.io/component: orchestrator