@zephytiju/juntai-platform-constructs
v1.0.0
Published
Reusable Pulumi deployment constructs for Juntai platform and domain-owned IaC packages
Maintainers
Readme
JuntaiPlatformConstructs
@zephytiju/juntai-platform-constructs provides reusable TypeScript Pulumi components for
platform and domain-owned Kubernetes deployment packages. A caller's Pulumi stack owns every
component it instantiates; this library does not select stacks, environments, service releases,
providers, data engines, or platform composition.
The package includes restricted-by-default workload, Service, Job, identity, reference, Gateway API, network-policy, observability, migration, scheduled-operation, optional Casdoor, and Meridian runtime-configuration components. Images are always caller-supplied immutable digests. Secret bytes are never accepted.
npm install @zephytiju/juntai-platform-constructs \
@pulumi/pulumi @pulumi/kubernetes \
@zephytiju/meridian-storage-constructsimport * as k8s from "@pulumi/kubernetes";
import {
JuntaiService,
WorkloadIdentity,
secretValue,
} from "@zephytiju/juntai-platform-constructs";
const provider = new k8s.Provider("cluster", { kubeconfig: "..." });
const identity = new WorkloadIdentity("orders", {
namespace: "orders",
provider,
});
const service = new JuntaiService("orders", {
namespace: "orders",
provider,
identity: identity.reference,
image:
"ghcr.io/example/orders@sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
port: 8080,
resources: {
requests: { cpu: "100m", memory: "128Mi" },
limits: { cpu: "1", memory: "512Mi" },
},
probes: {
startup: { path: "/startup", port: 8080 },
readiness: { path: "/ready", port: 8080 },
liveness: { path: "/health", port: 8080 },
},
environment: [secretValue("DATABASE_URL", { name: "orders-db", key: "url" })],
});
export const endpoint = service.internalEndpoint;See fixtures/consumer/index.ts for representative public-API
composition and docs/adoption-and-aliases.md for resource
adoption, aliases, and import guidance.
Boundary
- No
Pulumi.yaml, stack configuration, provider construction, environment selection, or live stack ownership. - No service image pins, upstream API/CRD copies, Helm charts, generated service contracts, or domain policy.
- No engine selection or copied Meridian implementation.
MeridianRuntimeConfigaccepts an existingMeridianDeploymentfrom@zephytiju/meridian-storage-constructsdirectly. - Casdoor support accepts only the official
casbin/casdoordigest-pinned image and ordinary configuration/secret references; it contains no patch, derivative image, or private API.
Development
npm ci --ignore-scripts
npm run check
npm audit --audit-level=highThe committed api/public-api.v1.json is checked against TypeScript's
resolved module exports. Breaking changes require a new package major and a reviewed snapshot.
