Per-PR Kubernetes Pods and Default Queue Path

Per-PR Kubernetes Pods and Default Queue Path An architecture diagram generated by Archify. GitHub PR + Actions · GitHub and public delivery controls GitHub PR + Actions GHCR · GitHub and public delivery controls GHCR Argo CD + Helm · GitHub and public delivery controls Argo CD + Helm Preview Edge · GitHub and public delivery controls Preview Edge Web Pod · One restricted namespace for one OpenReview pull request Web Pod API Pod · One restricted namespace for one OpenReview pull request API Pod Worker Pod · One restricted namespace for one OpenReview pull request Worker Pod Bucket-init Job Pod · One restricted namespace for one OpenReview pull request Bucket-init Job Pod Migration Job Pod · One restricted namespace for one OpenReview pull request Migration Job Pod PostgreSQL Pod · One restricted namespace for one OpenReview pull request PostgreSQL Pod Redis Pod · One restricted namespace for one OpenReview pull request Redis Pod MinIO Pod · One restricted namespace for one OpenReview pull request MinIO Pod push 3 exact-SHA images discover labelled PR Helm release + namespace pull exact-SHA images host + path routing same-origin API calls SQL default BullMQ job claim job read original · write proxy create buckets migrate + seed GitHub and public delivery controls One restricted namespace for one OpenReview pull request Legend Frontend Backend Database Cloud Security Message bus External

What one OpenReview PR declares

  • • 5 baseline pods; worker is 1 by default or KEDA-scaled 0–2 on PR #1
  • • 2 completed Job pods: bucket initialization and database migration
  • • 5 ClusterIP Services · 4 Ingress objects · 3 PVCs · 11 NetworkPolicies

A simpler application PR

  • • 1 Deployment creates 1 application pod in its own namespace
  • • 1 ClusterIP Service + 1 Ingress + quota + limits + restricted Pod Security
  • • Default-deny policy allows only the ingress controller to the application port

Lifecycle and isolation

  • • A second PR creates a second namespace and a separate copy of its declared pods
  • • PR #1 uses Floci SQS and KEDA; this drawing shows the default BullMQ path
  • • Close, merge or label removal prunes the Application, namespace, storage and DNS