Merge branch 'refactor-with-backend' into 'nubes'

added files from backend

See merge request devops/cw-infra-apps!4
This commit is contained in:
leonid.sokurov 2025-06-26 18:58:51 +00:00
commit 471de0b051
1570 changed files with 127399 additions and 0 deletions

View File

@ -0,0 +1,18 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: backend-apps
namespace: argocd
spec:
project: default
source:
repoURL: https://gitlab.ii-p001.local/cw-devops/cw-infra-apps-nubes.git
targetRevision: main
path: charts/backend
destination:
server: https://kubernetes.default.svc
namespace: backend
syncPolicy:
automated:
prune: true
selfHeal: true

67
charts/backend/Chart.yaml Executable file
View File

@ -0,0 +1,67 @@
apiVersion: v2
name: umbrella-chart
description: A Helm umbrella chart to deploy multiple microservices with shared config
type: application
version: 0.1.0
appVersion: 1.0.0
dependencies:
- name: auth-event-handler-app-k8s
version: 0.1.0
repository: file://charts/auth-event-handler-app-k8s
- name: chat-app-k8s
version: 0.1.0
repository: file://charts/chat-app-k8s
- name: auth-app-k8s
version: 0.1.0
repository: file://charts/auth-app-k8s
- name: message-app-k8s
version: 0.1.0
repository: file://charts/message-app-k8s
- name: user-app-k8s
version: 0.1.0
repository: file://charts/user-app-k8s
- name: notification-app-k8s
version: 0.1.0
repository: file://charts/notification-app-k8s
- name: search-app-k8s
version: 0.1.0
repository: file://charts/search-app-k8s
- name: call-app-k8s
version: 0.1.0
repository: file://charts/call-app-k8s
- name: workspace-app-k8s
version: 0.1.0
repository: file://charts/workspace-app-k8s
- name: realtime-app-k8s
version: 0.1.0
repository: file://charts/realtime-app-k8s
- name: web-sender-app-k8s
version: 0.1.0
repository: file://charts/web-sender-app-k8s
- name: bff-app-k8s
version: 0.1.0
repository: file://charts/bff-app-k8s
- name: upload-app-k8s
version: 0.1.0
repository: file://charts/upload-app-k8s
- name: deeplink-app-k8s
version: 0.1.0
repository: file://charts/deeplink-app-k8s
- name: livekit-webhook-handler-app-k8s
version: 0.1.0
repository: file://charts/livekit-webhook-handler-app-k8s
- name: ios-app-k8s
version: 0.1.0
repository: file://charts/ios-app-k8s
- name: android-app-k8s
version: 0.1.0
repository: file://charts/android-app-k8s
- name: desktop-app-k8s
version: 0.1.0
repository: file://charts/desktop-app-k8s
- name: huawei-app-k8s
version: 0.1.0
repository: file://charts/huawei-app-k8s
- name: safari-app-k8s
version: 0.1.0
repository: file://charts/safari-app-k8s

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: admin-app
description: Helm chart for Admin app
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "admin-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "admin-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "admin-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "admin-app.fullname" -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "admin-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "admin-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

View File

@ -0,0 +1,65 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "admin-app.fullname" . }}
labels:
{{- include "admin-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "admin-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "admin-app.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: admin-app
ports:
- containerPort: 9090
targetPort: 9090
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: WORKSPACE_HOST
value: "{{ .Values.env.workspace_host }}"
- name: WORKSPACE_PORT
value: "{{ .Values.env.workspace_port }}"
- name: USER_HOST
value: "{{ .Values.env.user_host }}"
- name: USER_PORT
value: "{{ .Values.env.user_port }}"
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "admin-app.fullname" . }}
labels:
{{- include "admin-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
selector:
{{- include "admin-app.selectorLabels" . | nindent 4 }}
ports:
- name: http
port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP

View File

@ -0,0 +1,16 @@
replicaCount: 1
image:
repository: registry.co-work.ru/admin-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
env:
workspace_host: workspace-app
workspace_port: 9090
user_host: user-app
user_port: 9090
service:
type: ClusterIP
port: 9090
targetPort: 9090

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: android-sender-app
description: Helm chart for Android Sender Application
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "android-sender-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "android-sender-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "android-sender-app.fullname" -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "android-sender-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

View File

@ -0,0 +1,72 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "android-sender-app.fullname" . }}
labels:
{{- include "android-sender-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "android-sender-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "android-sender-app.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: android-sender
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: KAFKA_SERVER
value: {{ .Values.env.kafkaServers }}
- name: KAFKA_USER
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafkaSecret }}
key: username
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafkaSecret }}
key: client-passwords
- name: REDIS_HOST
value: {{ .Values.env.redisHost }}
- name: REDIS_PORT
value: {{ .Values.env.redisPort | quote }}
- name: ANDROID_FIREBASE_CONFIG
value: {{ .Values.env.android_firebase_config }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,16 @@
replicaCount: 1
image:
repository: registry.co-work.ru/android-sender-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
env:
kafkaServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redisHost: redis-master.redis.svc.cluster.local
redisPort: 6379
android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json"
secrets:
kafkaSecret: kafka-password
firebaseSecret: android-firebase-config

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: auth-app-k8s
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,62 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "auth-app-k8s.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "auth-app-k8s.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "auth-app-k8s.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "auth-app-k8s.labels" -}}
helm.sh/chart: {{ include "auth-app-k8s.chart" . }}
{{ include "auth-app-k8s.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "auth-app-k8s.selectorLabels" -}}
app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "auth-app-k8s.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}

View File

@ -0,0 +1,103 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "auth-app-k8s.fullname" . }}
labels:
{{- include "auth-app-k8s.labels" . | nindent 4 }}
io.kompose.service: auth-app
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "auth-app-k8s.selectorLabels" . | nindent 6 }}
io.kompose.service: auth-app
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "auth-app-k8s.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
volumes:
- name: ca-cert
configMap:
name: {{ include "auth-app-k8s.fullname" . }}-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: auth-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: {{ .Values.service.targetPort }}
{{- if .Values.service.hostPort }}
hostPort: {{ .Values.service.hostPort }}
{{- end }}
protocol: TCP
env:
- name: ADMIN_CLIENT_ID
value: {{ .Values.env.adminClientId | quote }}
- name: ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.adminPassword.name }}
key: {{ .Values.secrets.adminPassword.key }}
- name: ADMIN_REALM
value: {{ .Values.env.adminRealm | quote }}
- name: ADMIN_URL
value: {{ .Values.env.adminUrl | quote }}
- name: ADMIN_USERNAME
value: {{ .Values.env.adminUsername | quote }}
- name: CLIENT_ID
value: {{ .Values.env.clientId | quote }}
- name: CLIENT_ISSUER_IRI
value: {{ .Values.env.clientIssuerIri | quote }}
- name: CLIENT_REALM
value: {{ .Values.env.clientRealm | quote }}
- name: CLIENT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.clientSecret.name }}
key: {{ .Values.secrets.clientSecret.key }}
- name: REALM
value: {{ .Values.env.realm | quote }}
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
- name: SECURITY_ADMIN_REALM
value: {{ .Values.env.securityAdminRealm | quote }}
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
resources:
{{- toYaml .Values.resources | nindent 12 }}

View File

@ -0,0 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "auth-app-k8s.fullname" . }}
labels:
{{- include "auth-app-k8s.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
- port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP
selector:
{{- include "auth-app-k8s.selectorLabels" . | nindent 4 }}
io.kompose.service: auth-app

View File

@ -0,0 +1,15 @@
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "auth-app-k8s.fullname" . }}-test-connection"
labels:
{{- include "auth-app-k8s.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never

View File

@ -0,0 +1,58 @@
fullnameOverride: "auth-app"
image:
repository: registry.co-work.ru/auth-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
port: 9090
targetPort: 9090
hostPort: null
env:
cert_alias: co-work
adminClientId: "admin-cli"
adminRealm: "master"
adminUrl: "https://iam.nubes.ru/admin/realms/cowork"
adminUsername: "admin"
clientId: "gem-auth-client"
clientIssuerIri: "https://iam.nubes.ru/realms/cowork"
clientRealm: "cowork"
realm: "cowork"
securityAdminRealm: "master"
securityOauth2ClientIssuerUri: "https://iam.nubes.ru/realms"
secrets:
adminPassword:
name: auth-secrets
key: admin-password
clientSecret:
name: auth-secrets
key: client-secret
resources:
limits:
memory: 512Mi
requests:
cpu: 100m
memory: 256Mi
podAnnotations:
kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: auth-app
autoscaling:
enabled: false

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: auth-event-handler-app-k8s
description: Authentication Event Handler
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,23 @@
{{/* Common Name Definitions */}}
{{- define "auth-event-handler-app-k8s.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{/* Standard labels */}}
{{- define "auth-event-handler-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "auth-event-handler-app-k8s.selectorLabels" -}}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

View File

@ -0,0 +1,141 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
labels:
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- if .Values.serviceAccount.create }}
serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
{{- with .Values.volumes }}
{{ toYaml . | nindent 8 }}
{{- end }}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
protocol: TCP
env:
- name: ADMIN_CLIENT_ID
value: {{ .Values.env.adminClientId | quote }}
- name: ADMIN_REALM
value: {{ .Values.env.adminRealm | quote }}
- name: ADMIN_URL
value: {{ .Values.env.adminUrl | quote }}
- name: ADMIN_USERNAME
value: {{ .Values.env.adminUsername | quote }}
- name: CLIENT_ID
value: {{ .Values.env.clientId | quote }}
- name: CLIENT_ISSUER_IRI
value: {{ .Values.env.clientIssuerIri | quote }}
- name: CLIENT_REALM
value: {{ .Values.env.clientRealm | quote }}
- name: REALM
value: {{ .Values.env.realm | quote }}
- name: SECURITY_ADMIN_REALM
value: {{ .Values.env.securityAdminRealm | quote }}
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
- name: KAFKA
value: {{ .Values.env.kafkaBrokers | quote }}
- name: KAFKA_USERNAME
value: {{ .Values.secrets.kafka.username | quote }}
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.passwordKey }}
- name: ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.adminPassword.name }}
key: {{ .Values.secrets.adminPassword.key }}
- name: CLIENT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.clientSecret.name }}
key: {{ .Values.secrets.clientSecret.key }}
livenessProbe:
{{- toYaml .Values.livenessProbe | nindent 12 }}
readinessProbe:
{{- toYaml .Values.readinessProbe | nindent 12 }}
resources:
{{- toYaml .Values.resources | nindent 12 }}
volumeMounts:
{{- with .Values.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}

View File

@ -0,0 +1,12 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
labels:
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
spec:
ports:
- port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
selector:
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,60 @@
fullnameOverride: "auth-event-handler-app"
image:
repository: registry.co-work.ru/auth-event-handler-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
port: 8094
targetPort: 9090
env:
adminClientId: "admin-cli"
adminRealm: "master"
adminUrl: "https://iam.nubes.ru/admin/realms/cowork"
adminUsername: "admin"
clientId: "gem-auth-client"
clientIssuerIri: "https://iam.nubes.ru/realms/cowork"
clientRealm: "cowork"
realm: "cowork"
securityAdminRealm: "master"
securityOauth2ClientIssuerUri: "https://iam.nubes.ru/realms"
kafkaBrokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
secrets:
kafka:
name: kafka-password
passwordKey: client-passwords
username: admin
adminPassword:
name: auth-secrets
key: admin-password
clientSecret:
name: auth-secrets
key: client-secret
resources:
limits:
memory: 512Mi
requests:
cpu: 100m
memory: 256Mi
podAnnotations:
kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: auth-event-handler-app
podSecurityContext: {}
securityContext: {}
autoscaling:
enabled: false
serviceAccount:
create: false
name: ""

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: bff-admin-app
description: Helm chart for bff-admin-app
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "bff-admin-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "bff-admin-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "bff-admin-app.fullname" -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "bff-admin-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

View File

@ -0,0 +1,39 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "bff-admin-app.fullname" . }}
labels:
{{- include "bff-admin-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "bff-admin-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "bff-admin-app.selectorLabels" . | nindent 8 }}
spec:
containers:
- name: bff-admin-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: SWAGGER_HOST
value: "{{ .Values.env.swagger_host }}"
- name: SWAGGER_PORT
value: "{{ .Values.env.swagger_port }}"
- name: WORKSPACE_HOST
value: "{{ .Values.env.workspace_host }}"
- name: WORKSPACE_PORT
value: "{{ .Values.env.workspace_port }}"
- name: USER_HOST
value: "{{ .Values.env.user_host }}"
- name: USER_PORT
value: "{{ .Values.env.user_port }}"
- name: ADMIN_HOST
value: "{{ .Values.env.admin_host }}"
- name: ADMIN_PORT
value: "{{ .Values.env.admin_port }}"
- name: APP_NAME
value: "{{ .Values.env.app_name }}"

View File

@ -0,0 +1,38 @@
{{- if .Values.ingress.enabled -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ .Values.ingress.name }}
namespace: {{ .Release.Namespace | default "default" }}
{{- with .Values.ingress.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
ingressClassName: {{ .Values.ingress.className }}
{{- if .Values.ingress.tls }}
tls:
{{- range .Values.ingress.tls }}
- hosts:
{{- range .hosts }}
- {{ . | quote }}
{{- end }}
secretName: {{ .secretName | quote }}
{{- end }}
{{- end }}
rules:
{{- range .Values.ingress.hosts }}
- host: {{ .host | quote }}
http:
paths:
{{- range .paths }}
- path: {{ .path }}
pathType: {{ .pathType }}
backend:
service:
name: {{ $.Values.env.app_name }}
port:
number: {{ $.Values.service.httpPort }}
{{- end }}
{{- end }}
{{- end }}

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "bff-admin-app.fullname" . }}
labels:
{{- include "bff-admin-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
selector:
{{- include "bff-admin-app.selectorLabels" . | nindent 4 }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}

View File

@ -0,0 +1,46 @@
replicaCount: 1
image:
repository: registry.co-work.ru/bff-admin-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
env:
swagger_host: "localhost"
swagger_port: 8080
workspace_host: "workspace-app"
workspace_port: 9090
user_host: "user-app"
user_port: 9090
admin_host: "admin-app"
admin_port: 9090
app_name: bff-admin-app
service:
type: ClusterIP
httpPort: 8100
grpcPort: 8101
ports:
- name: http
port: 8100 # Changed from templated value to static
targetPort: 8080
- name: grpc
port: 8101 # Changed from templated value to static
targetPort: 9090
ingress:
enabled: true
className: nginx
name: bff-admin-ingress
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
hosts:
- host: api-adm-p001.cw.ngcloud.ru
paths:
- path: /
pathType: Prefix
tls:
- hosts:
- api-adm-p001.cw.ngcloud.ru
secretName: co-work-secret

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: bff-app-k8s
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,23 @@
{{/* Common Name Definitions */}}
{{- define "bff-app-k8s.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{/* Standard labels */}}
{{- define "bff-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "bff-app-k8s.selectorLabels" -}}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

View File

@ -0,0 +1,93 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "bff-app-k8s.fullname" . }}
labels:
{{- include "bff-app-k8s.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "bff-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "bff-app-k8s.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
# initContainers:
# - name: import-ca
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
# env:
# - name: CERT_ALIAS
# value: {{ .Values.env.cert_alias | quote }}
# volumeMounts:
# - name: ca-cert
# mountPath: /app/resources
# - name: cacerts-volume
# mountPath: /tmp/cacerts
# command:
# - sh
# - -c
# - |
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
# keytool -import -trustcacerts -storepass changeit -noprompt \
# -alias gemcert \
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
# -keystore /tmp/cacerts/cacerts
containers:
- name: bff-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: {{ .Values.service.targetPort }}
{{- if .Values.service.hostPort }}
hostPort: {{ .Values.service.hostPort }}
{{- end }}
protocol: TCP
env:
- name: GRPC_CLIENT_AUTH_URL
value: {{ .Values.env.services.auth | quote }}
- name: GRPC_CLIENT_CHAT_URL
value: {{ .Values.env.services.chat | quote }}
- name: GRPC_CLIENT_CONFIG_URL
value: {{ .Values.env.services.user | quote }}
- name: GRPC_CLIENT_DEEPLINK_URL
value: {{ .Values.env.services.deeplink | quote }}
- name: GRPC_CLIENT_GEM_CALL_URL
value: {{ .Values.env.services.gemCall | quote }}
- name: GRPC_CLIENT_MESSAGE_URL
value: {{ .Values.env.services.message | quote }}
- name: GRPC_CLIENT_NOTIFICATIONS_URL
value: {{ .Values.env.services.notification | quote }}
- name: GRPC_CLIENT_REACTION_URL
value: {{ .Values.env.services.message | quote }}
- name: GRPC_CLIENT_REALTIME_URL
value: {{ .Values.env.services.realtime | quote }}
- name: GRPC_CLIENT_SEARCH_URL
value: {{ .Values.env.services.search | quote }}
- name: GRPC_CLIENT_STICKER_URL
value: {{ .Values.env.services.sticker | quote }}
- name: GRPC_CLIENT_UPLOAD_URL
value: {{ .Values.env.services.upload | quote }}
- name: GRPC_CLIENT_USER_URL
value: {{ .Values.env.services.user | quote }}
- name: GRPC_CLIENT_WORKSPACE_URL
value: {{ .Values.env.services.workspace | quote }}
resources:
{{- toYaml .Values.resources | nindent 12 }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,28 @@
{{- if .Values.ingress.enabled -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ .Values.ingress.name }}
namespace: {{ .Release.Namespace | default "default" }}
{{- with .Values.ingress.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
ingressClassName: {{ .Values.ingress.className }}
tls:
- hosts:
- {{ .Values.ingress.host | quote }}
secretName: {{ .Values.ingress.tlsSecret | quote }}
rules:
- host: {{ .Values.ingress.host | quote }}
http:
paths:
- path: {{ .Values.ingress.path }}
pathType: {{ .Values.ingress.pathType }}
backend:
service:
name: {{ .Values.service.name }}
port:
number: {{ .Values.service.port }}
{{- end }}

View File

@ -0,0 +1,14 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "bff-app-k8s.fullname" . }}
labels:
{{- include "bff-app-k8s.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
- port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP
selector:
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,58 @@
image:
repository: registry.co-work.ru/bff-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
replicaCount: 1
service:
type: ClusterIP
port: 8081
targetPort: 8080
nodePort: 31754
name: bff-app # Added service name
ingress:
enabled: true
className: nginx
name: bff-app-ingress
host: api-p001.cw.ngcloud.ru
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
path: /
pathType: Prefix
tlsSecret: co-work-secret
env:
services:
auth: http://auth-app:9090
chat: http://chat-app:9090
user: http://user-app:9090
deeplink: http://deeplink-app:9090
gemCall: http://gem-call-app:9090
message: http://message-app:9090
notification: http://notification-app:9090
realtime: http://realtime-app:9090
search: http://search-app:9090
sticker: http://sticker-app:9090
upload: http://upload-app:9090
workspace: http://workspace-app:9090
resources:
limits:
memory: 1Gi
requests:
cpu: 200m
memory: 512Mi
podAnnotations:
kompose.cmd: kompose convert -f app/bff-app.yml -o k8s/bff-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: bff-app
fullnameOverride: "bff-app"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: bff-vcs-app
description: Helm chart for bff-vcs-app
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "bff-vcs-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "bff-vcs-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "bff-vcs-app.fullname" -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "bff-vcs-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

View File

@ -0,0 +1,58 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "bff-vcs-app.fullname" . }}
labels:
{{- include "bff-vcs-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "bff-vcs-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "bff-vcs-app.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
# initContainers:
# - name: import-ca
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
# env:
# - name: CERT_ALIAS
# value: {{ .Values.env.cert_alias | quote }}
# volumeMounts:
# - name: ca-cert
# mountPath: /app/resources
# - name: cacerts-volume
# mountPath: /tmp/cacerts
# command:
# - sh
# - -c
# - |
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
# keytool -import -trustcacerts -storepass changeit -noprompt \
# -alias gemcert \
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
# -keystore /tmp/cacerts/cacerts
containers:
- name: bff-vcs-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: GRPC_CLIENT_CALL_URL
value: "{{ .Values.env.grpc_client_call_url }}"
- name: GRPC_CLIENT_CALL_REALTIME_URL
value: "{{ .Values.env.grpc_client_call_realtime_url }}"
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,28 @@
{{- if .Values.ingress.enabled }}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ include "bff-vcs-app.fullname" . }}-ingress
namespace: {{ .Release.Namespace }}
annotations:
{{- range $key, $value := .Values.ingress.annotations }}
{{ $key }}: {{ $value | quote }}
{{- end }}
spec:
ingressClassName: {{ .Values.ingress.ingressClassName }}
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecretName }}
rules:
- host: {{ .Values.ingress.host }}
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: {{ include "bff-vcs-app.fullname" . }}
port:
number: {{ .Values.service.port }}
{{- end }}

View File

@ -0,0 +1,16 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "bff-vcs-app.fullname" . }}
labels:
{{- include "bff-vcs-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
selector:
{{- include "bff-vcs-app.selectorLabels" . | nindent 4 }}
ports:
- name: http
port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP

View File

@ -0,0 +1,25 @@
replicaCount: 1
image:
repository: pibff-vcs-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
env:
grpc_client_call_url: http://call-realtime-app:9090
grpc_client_call_realtime_url: http://call-realtime-app:9090
service:
type: ClusterIP
port: 8079
targetPort: 8080
ingress:
enabled: true
ingressClassName: nginx
host: api-vcs-p001.cw.ngcloud.ru
tlsSecretName: co-work-secret
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: big-chat-splitter-app-k8s
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,22 @@
{{/* Common Name Definitions */}}
{{- define "big-chat-splitter-app-k8s.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{/* Standard labels */}}
{{- define "big-chat-splitter-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "big-chat-splitter-app-k8s.selectorLabels" -}}
io.kompose.service: big-chat-splitter-app
{{- end }}

View File

@ -0,0 +1,86 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "big-chat-splitter-app-k8s.fullname" . }}
labels:
{{- include "big-chat-splitter-app-k8s.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: big-chat-splitter-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: CASSANDRA_DC
value: {{ .Values.env.cassandra.dc | quote }}
- name: CASSANDRA_HOST
value: {{ .Values.env.cassandra.host | quote }}
- name: CASSANDRA_USERNAME
value: {{ .Values.secrets.cassandra.username | quote }}
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.passwordKey }}
- name: CHAT_SERVICE_HOST
value: {{ .Values.env.services.chat.host | quote }}
- name: CHAT_SERVICE_PORT
value: {{ .Values.env.services.chat.port | quote }}
- name: KAFKA_USER
value: {{ .Values.secrets.kafka.username | quote }}
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.passwordKey }}
- name: KAFKA_SERVER
value: {{ .Values.env.kafka.servers | quote }}
- name: REDIS_HOST
value: {{ .Values.env.redis.host | quote }}
- name: REDIS_PORT
value: {{ .Values.env.redis.port | quote }}
- name: USER_SERVICE_HOST
value: {{ .Values.env.services.user.host | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,54 @@
fullnameOverride: "big-chat-splitter-app"
image:
repository: registry.co-work.ru/big-chat-splitter-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
env:
cassandra:
dc: datacenter1
host: "cassandra.cassandra.svc.cluster.local"
services:
chat:
host: chat-app
port: 9090
user:
host: user-app
port: 9090
redis:
host: redis-master.redis.svc.cluster.local
port: 6379
kafka:
servers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
secrets:
cassandra:
name: cassandra
passwordKey: cassandra-password
username: cassandra
kafka:
name: kafka-password
passwordKey: client-passwords
username: admin
resources:
limits:
memory: 1Gi
requests:
cpu: 500m
memory: 512Mi
podAnnotations:
kompose.cmd: kompose convert -f app/big-chat-splitter-app.yml -o k8s/big-chat-splitter-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: big-chat-splitter-app
fullnameOverride: "big-chat-splitter-app"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: call-app-k8s
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,22 @@
{{/* Common Name Definitions */}}
{{- define "call-app-k8s.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{/* Standard labels */}}
{{- define "call-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "call-app-k8s.selectorLabels" -}}
io.kompose.service: call-app
{{- end }}

View File

@ -0,0 +1,131 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "call-app-k8s.fullname" . }}
labels:
{{- include "call-app-k8s.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "call-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "call-app-k8s.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: call-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
protocol: TCP
targetPort: 5005
- containerPort: 9090
protocol: TCP
targetPort: 9090
env:
- name: TENANT_ID
value: {{ .Values.env.TENANT_ID | quote }}
- name: CASSANDRA_CONTACTPOINT
value: {{ .Values.env.cassandra.contactPoint | quote }}
- name: CASSANDRA_DATACENTER
value: {{ .Values.env.cassandra.datacenter | quote }}
- name: CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.usernameKey }}
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.passwordKey }}
- name: KAFKA
value: {{ .Values.env.kafka.brokers | quote }}
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.usernameKey }}
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.passwordKey }}
- name: KEYCLOAK_URL
value: {{ .Values.env.keycloak.url | quote }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.apiKeyKey }}
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.secretKey }}
- name: RECORDING_ACCESS_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.accessKeyKey }}
- name: RECORDING_API_HOST
value: {{ .Values.env.livekit.apiHost | quote }}
- name: RECORDING_BUCKET
value: {{ .Values.env.recording.bucket | quote }}
- name: RECORDING_ENDPOINT
value: {{ .Values.env.recording.endpoint | quote }}
- name: RECORDING_REGION
value: {{ .Values.env.recording.region | quote }}
- name: RECORDING_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.secretKeyKey }}
- name: REDIS_HOST
value: {{ .Values.env.redis.host | quote }}
- name: REDIS_PORT
value: {{ .Values.env.redis.port | quote }}
- name: REDIS_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.redis.name }}
key: {{ .Values.secrets.redis.passwordKey }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "call-app-k8s.fullname" . }}
labels:
{{- include "call-app-k8s.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}
selector:
{{- include "call-app-k8s.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,66 @@
image:
repository: registry.co-work.ru/call-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
ports:
- name: main
port: 5005
targetPort: 5005
- name: metrics
port: 9090
targetPort: 9090
env:
cassandra:
contactPoint: cassandra.cassandra.svc.cluster.local
datacenter: datacenter1
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: 6379
keycloak:
url: https://iam.nubes.ru/realms/cowork
livekit:
apiHost: https://av-p001.cw.ngcloud.ru
recording:
endpoint: https://store-p001.cw.ngcloud.ru:9000
region: us-east-2
bucket: livekit
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
secrets:
cassandra:
name: cassandra
usernameKey: username
passwordKey: cassandra-password
kafka:
name: kafka-password
usernameKey: username
passwordKey: client-passwords
redis:
name: redis-kafka-user-passwords
passwordKey: client-passwords
livekit:
name: livekit-secret
apiKeyKey: api-key
secretKey: secret
recording:
name: recording-secret
accessKeyKey: access-key
secretKeyKey: secret
podAnnotations:
kompose.cmd: kompose convert -f app/call-app.yml -o k8s/call-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: call-app
fullnameOverride: "call-app"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: call-event-handler-app
description: Call Event Handler Application
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,46 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "call-event-handler-app.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "call-event-handler-app.fullname" -}}
{{- if .Values.fullnameOverride -}}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "call-event-handler-app.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Common labels
*/}}
{{- define "call-event-handler-app.labels" -}}
helm.sh/chart: {{ include "call-event-handler-app.chart" . }}
{{ include "call-event-handler-app.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end -}}
{{/*
Selector labels
*/}}
{{- define "call-event-handler-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "call-event-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end -}}

View File

@ -0,0 +1,111 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "call-event-handler-app.fullname" . }}
labels:
{{- include "call-event-handler-app.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.podAnnotations | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "call-event-handler-app.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "call-event-handler-app.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
protocol: TCP
- containerPort: 9090
protocol: TCP
env:
- name: CASSANDRA_CONTACTPOINT
value: {{ .Values.env.cassandra.contactPoint | quote }}
- name: CASSANDRA_DATACENTER
value: {{ .Values.env.cassandra.datacenter | quote }}
- name: CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.usernameKey }}
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.passwordKey }}
- name: KAFKA
value: {{ .Values.env.kafka.brokers | quote }}
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.usernameKey }}
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.passwordKey }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.apiKeyKey }}
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.secretKey }}
- name: RECORDING_API_HOST
value: {{ .Values.env.recording.apiHost | quote }}
- name: REDIS_HOST
value: {{ .Values.env.redis.host | quote }}
- name: REDIS_PORT
value: {{ .Values.env.redis.port | quote }}
- name: REDIS_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.redis.name }}
key: {{ .Values.secrets.redis.passwordKey }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "call-event-handler-app.fullname" . }}
labels:
{{- include "call-event-handler-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}
selector:
{{- include "call-event-handler-app.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,57 @@
image:
repository: registry.co-work.ru/call-event-handler-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
replicaCount: 1
service:
type: ClusterIP
ports:
- name: main
port: 5005
targetPort: 5005
- name: metrics
port: 9090
targetPort: 9090
env:
cassandra:
contactPoint: cassandra.cassandra.svc.cluster.local
datacenter: datacenter1
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: "6379"
recording:
apiHost: https://store-p001.cw.ngcloud.ru:9000
secrets:
cassandra:
name: cassandra
usernameKey: username
passwordKey: cassandra-password
kafka:
name: kafka-password
usernameKey: username
passwordKey: client-passwords
redis:
name: redis-kafka-user-passwords
passwordKey: client-passwords
livekit:
name: livekit-secret
apiKeyKey: api-key
secretKey: secret
podAnnotations:
kompose.cmd: kompose convert -f app/call-event-handler-app.yml -o k8s/call-event-handler-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: call-event-handler-app
nameOverride: ""
fullnameOverride: ""

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: call-realtime-app-k8s
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,39 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "call-realtime-app.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "call-realtime-app.fullname" -}}
{{- if .Values.fullnameOverride -}}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{/*
Common labels
*/}}
{{- define "call-realtime-app.labels" -}}
helm.sh/chart: {{ include "call-realtime-app.name" . }}
{{ include "call-realtime-app.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end -}}
{{/*
Selector labels
*/}}
{{- define "call-realtime-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "call-realtime-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end -}}

View File

@ -0,0 +1,120 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "call-realtime-app.fullname" . }}
labels:
{{- include "call-realtime-app.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.podAnnotations | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "call-realtime-app.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "call-realtime-app.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
protocol: TCP
- containerPort: 9090
protocol: TCP
env:
- name: TENANT_ID
value: {{ .Values.env.TENANT_ID | quote }}
- name: CASSANDRA_CONTACTPOINT
value: {{ .Values.env.cassandra.contactPoint | quote }}
- name: CASSANDRA_DATACENTER
value: {{ .Values.env.cassandra.datacenter | quote }}
- name: CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.usernameKey }}
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra.name }}
key: {{ .Values.secrets.cassandra.passwordKey }}
- name: KAFKA
value: {{ .Values.env.kafka.brokers | quote }}
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.usernameKey }}
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka.name }}
key: {{ .Values.secrets.kafka.passwordKey }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.apiKeyKey }}
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.secretKey }}
- name: RECORDING_ACCESS_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.accessKeyKey }}
- name: RECORDING_API_HOST
value: {{ .Values.env.recording.apiHost | quote }}
- name: RECORDING_BUCKET
value: {{ .Values.env.recording.bucket | quote }}
- name: RECORDING_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.secretKey }}
- name: REDIS_HOST
value: {{ .Values.env.redis.host | quote }}
- name: REDIS_PORT
value: {{ .Values.env.redis.port | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "call-realtime-app.fullname" . }}
labels:
{{- include "call-realtime-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}
selector:
{{- include "call-realtime-app.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,66 @@
# Image Configuration
image:
repository: registry.co-work.ru/call-realtime-app
tag: 1.0.0-SNAPSHOT
pullPolicy: IfNotPresent
# Replica Configuration
replicaCount: 1
# Service Configuration
service:
type: ClusterIP
ports:
- name: main
port: 5096
targetPort: 5005
- name: metrics
port: 9090
targetPort: 9090
# Environment Configuration
env:
cassandra:
contactPoint: cassandra.cassandra.svc.cluster.local
datacenter: datacenter1
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: "6379"
recording:
apiHost: https://store-p001.cw.ngcloud.ru:9000
bucket: livekit
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
# Secret References
secrets:
cassandra:
name: cassandra
usernameKey: username
passwordKey: cassandra-password
kafka:
name: kafka-password
usernameKey: username
passwordKey: client-passwords
livekit:
name: livekit-secret
apiKeyKey: api-key
secretKey: secret
recording:
name: recording-secret
accessKeyKey: access-key
secretKey: secret
# Kompose Metadata
podAnnotations:
kompose.cmd: kompose convert -f app/call-realtime-app.yml -o k8s/call-realtime-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: call-realtime-app
# Chart Metadata
nameOverride: ""
fullnameOverride: call-realtime-app

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: chat-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,27 @@
{{/*
Return the name of the chart
*/}}
{{- define "chat-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "chat-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Common labels
*/}}
{{- define "chat-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "chat-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{- define "chat-app.quote" -}}
{{- . | quote }}
{{- end }}

View File

@ -0,0 +1,131 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "chat-app.fullname" . }}
labels:
{{- include "chat-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "chat-app.name" . }}
template:
metadata:
labels:
app: {{ include "chat-app.name" . }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
ports:
- containerPort: 9090
hostPort: 8085
- containerPort: 5005
hostPort: 5085
env:
- name: CASSANDRA_CONTACTPOINT
value: {{ .Values.env.CASSANDRA_CONTACTPOINT }}
- name: CASSANDRA_DATACENTER
value: {{ .Values.env.CASSANDRA_DATACENTER }}
- name: CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: cassandra
key: username
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: cassandra
key: cassandra-password
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: kafka-password
key: username
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: kafka-password
key: client-passwords
- name: KAFKA
value: {{ .Values.env.KAFKA | quote }}
- name: REDIS_HOST
value: {{ .Values.env.REDIS_HOST }}
- name: REDIS_PORT
value: {{ include "chat-app.quote" .Values.env.REDIS_PORT }}
- name: DEEPLINK_HOST
value: {{ .Values.env.DEEPLINK_HOST }}
- name: DEEPLINK_PORT
value: {{ include "chat-app.quote" .Values.env.DEEPLINK_PORT }}
- name: GEM_CALL_HOST
value: {{ .Values.env.GEM_CALL_HOST }}
- name: GEM_CALL_PORT
value: {{ include "chat-app.quote" .Values.env.GEM_CALL_PORT }}
- name: MESSAGE_HOST
value: {{ .Values.env.MESSAGE_HOST }}
- name: MESSAGE_PORT
value: {{ .Values.env.MESSAGE_PORT | quote }}
- name: SEARCH_HOST
value: {{ .Values.env.SEARCH_HOST }}
- name: SEARCH_PORT
value: {{ include "chat-app.quote" .Values.env.SEARCH_PORT }}
- name: USER_HOST
value: {{ .Values.env.USER_HOST }}
- name: USER_PORT
value: {{ include "chat-app.quote" .Values.env.USER_PORT }}
- name: KEYCLOAK_URL
value: {{ .Values.env.KEYCLOAK_URL }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: livekit-secret
key: api-key
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: livekit-secret
key: secret
- name: RECORDING_ACCESS_KEY
valueFrom:
secretKeyRef:
name: recording-secret
key: access-key
- name: RECORDING_SECRET
valueFrom:
secretKeyRef:
name: recording-secret
key: secret
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
restartPolicy: Always

View File

@ -0,0 +1,16 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "chat-app.fullname" . }}
labels:
{{- include "chat-app.labels" . | nindent 4 }}
spec:
selector:
app: {{ include "chat-app.name" . }}
ports:
- name: http
port: 9090
targetPort: 9090
- name: debug
port: 5085
targetPort: 5005

View File

@ -0,0 +1,23 @@
replicaCount: 1
image:
repository: registry.co-work.ru/chat-app
tag: 1.0.0-SNAPSHOT
env:
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
CASSANDRA_DATACENTER: datacenter1
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
REDIS_HOST: redis-master.redis.svc.cluster.local
REDIS_PORT: "6379"
DEEPLINK_HOST: deeplink-app
DEEPLINK_PORT: "9090"
GEM_CALL_HOST: gem-call-app
GEM_CALL_PORT: "9090"
MESSAGE_HOST: message-app
MESSAGE_PORT: "9090"
SEARCH_HOST: search-app
SEARCH_PORT: "9090"
USER_HOST: user-app
USER_PORT: "9090"
KEYCLOAK_URL: https://iam.nubes.ru/realms/cowork

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: chat-event-handler-app
description: A Helm chart for Kubernetes
type: application
version: 0.1.0
appVersion: "1.16.0"

View File

@ -0,0 +1,27 @@
{{/*
Return the name of the chart
*/}}
{{- define "chat-event-handler-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "chat-event-handler-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Common labels
*/}}
{{- define "chat-event-handler-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "chat-event-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{- define "chat-event-handler-app.quote" -}}
{{- . | quote }}
{{- end }}

View File

@ -0,0 +1,109 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "chat-event-handler-app.fullname" . }}
labels:
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "chat-event-handler-app.name" . }}
template:
metadata:
labels:
app: {{ include "chat-event-handler-app.name" . }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
ports:
- containerPort: 5005
hostPort: 5086
env:
- name: CASSANDRA_CONTACTPOINT
value: {{ .Values.env.CASSANDRA_CONTACTPOINT }}
- name: CASSANDRA_DATACENTER
value: {{ .Values.env.CASSANDRA_DATACENTER }}
- name: CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: cassandra
key: username
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: cassandra
key: cassandra-password
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: kafka-password
key: username
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: kafka-password
key: client-passwords
- name: KAFKA
value: {{ .Values.env.KAFKA | quote }}
- name: REDIS_HOST
value: {{ .Values.env.REDIS_HOST }}
- name: REDIS_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.REDIS_PORT }}
- name: DEEPLINK_HOST
value: {{ .Values.env.DEEPLINK_HOST }}
- name: DEEPLINK_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.DEEPLINK_PORT }}
- name: GEM_CALL_HOST
value: {{ .Values.env.GEM_CALL_HOST }}
- name: GEM_CALL_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.GEM_CALL_PORT }}
- name: MESSAGE_HOST
value: {{ .Values.env.MESSAGE_HOST }}
- name: MESSAGE_PORT
value: {{ .Values.env.MESSAGE_PORT | quote }}
- name: SEARCH_HOST
value: {{ .Values.env.SEARCH_HOST }}
- name: SEARCH_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.SEARCH_PORT }}
- name: USER_HOST
value: {{ .Values.env.USER_HOST }}
- name: USER_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.USER_PORT }}
- name: KEYCLOAK_URL
value: {{ .Values.env.KEYCLOAK_URL }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
restartPolicy: Always

View File

@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "chat-event-handler-app.fullname" . }}
labels:
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
spec:
selector:
app: {{ include "chat-event-handler-app.name" . }}
ports:
- name: debug
port: 5086
targetPort: 5005

View File

@ -0,0 +1,22 @@
replicaCount: 1
image:
repository: registry.co-work.ru/chat-event-handler-app
tag: 1.0.0-SNAPSHOT
env:
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
CASSANDRA_DATACENTER: datacenter1
MESSAGE_HOST: message-app
MESSAGE_PORT: "9090"
USER_HOST: user-app
USER_PORT: "9090"
SEARCH_HOST: search-app
SEARCH_PORT: "9090"
GEM_CALL_HOST: gem-call-app
GEM_CALL_PORT: "9090"
DEEPLINK_HOST: deeplink-app
DEEPLINK_PORT: "9090"
REDIS_HOST: redis-master.redis.svc.cluster.local
REDIS_PORT: "6379"
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: deeplink-app-k8s
description: A Helm chart for Kubernetes
type: application
version: 0.1.0
appVersion: "1.16.0"

View File

@ -0,0 +1,17 @@
{{/* Chart name */}}
{{- define "deeplink-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{- define "deeplink-app.fullname" -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Common labels */}}
{{- define "deeplink-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "deeplink-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}

View File

@ -0,0 +1,70 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "deeplink-app.fullname" . }}
labels:
{{- include "deeplink-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "deeplink-app.name" . }}
template:
metadata:
labels:
app: {{ include "deeplink-app.name" . }}
spec:
containers:
- name: {{ include "deeplink-app.name" . }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
ports:
- containerPort: {{ .Values.container.port }}
protocol: TCP
env:
- name: CASSANDRA_PORT
value: {{ .Values.env.CASSANDRA_PORT | quote }}
- name: BRANCHIO_ACCESS
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-access
- name: BRANCHIO_APPID
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-appid
- name: BRANCHIO_DEFAULT_URL
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-default-url
- name: BRANCHIO_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-key
- name: BRANCHIO_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-secret
- name: BRANCHIO_URL
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-url
- name: DEEPLINK_DOMAIN
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: deeplink-domain
- name: DEEPLINK_WEBDOMAIN
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: deeplink-webdomain
- name: DEEPLINK_TENANT
value: nubes.ru
- name: KEYCLOAK_URL
value: {{ .Values.keycloak.url | quote }}
restartPolicy: Always

View File

@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "deeplink-app.fullname" . }}
labels:
{{- include "deeplink-app.labels" . | nindent 4 }}
spec:
selector:
app: {{ include "deeplink-app.name" . }}
ports:
- name: http
port: {{ .Values.service.port }}
targetPort: {{ .Values.container.port }}

View File

@ -0,0 +1,20 @@
replicaCount: 1
image:
repository: registry.co-work.ru/deeplink-app
tag: 1.0.0-SNAPSHOT
service:
port: 9090
container:
port: 9090
keycloak:
url: https://iam.nubes.ru/realms/cowork
secrets:
branchio: deeplink-secret
env:
CASSANDRA_PORT: "9042"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,8 @@
apiVersion: v2
name: gem-call-app
description: A Helm chart for gem-call-app
type: application
version: 0.1.0
appVersion: "1.0.0"

View File

@ -0,0 +1,15 @@
{{- define "gem-call-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{- define "gem-call-app.fullname" -}}
{{ .Chart.Name }}
{{- end }}
{{- define "gem-call-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "gem-call-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}

View File

@ -0,0 +1,68 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "gem-call-app.fullname" . }}
labels:
{{- include "gem-call-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "gem-call-app.name" . }}
template:
metadata:
labels:
app: {{ include "gem-call-app.name" . }}
spec:
containers:
- name: {{ include "gem-call-app.name" . }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
ports:
- containerPort: 9090
- containerPort: 5005
env:
- name: CALL_HOST
value: {{ .Values.call.host | quote }}
- name: CALL_PORT
value: {{ .Values.call.port | quote }}
- name: CALL_REALTIME_HOST
value: {{ .Values.callRealtime.host | quote }}
- name: CALL_REALTIME_PORT
value: {{ .Values.callRealtime.port | quote }}
- name: CHAT_HOST
value: {{ .Values.chat.host | quote }}
- name: CHAT_PORT
value: {{ .Values.chat.port | quote }}
- name: DEEPLINK_HOST
value: {{ .Values.deeplink.host | quote }}
- name: DEEPLINK_PORT
value: {{ .Values.deeplink.port | quote }}
- name: KAFKA
value: {{ .Values.kafka.bootstrapServers | quote }}
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka }}
key: username
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka }}
key: client-passwords
- name: KEYCLOAK_URL
value: {{ .Values.keycloak.url | quote }}
- name: REDIS_HOST
value: {{ .Values.redis.host | quote }}
- name: REDIS_PORT
value: {{ .Values.redis.port | quote }}
- name: REDIS_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.redis }}
key: client-passwords
- name: USER_HOST
value: {{ .Values.user.host | quote }}
- name: USER_PORT
value: {{ .Values.user.port | quote }}
restartPolicy: Always

View File

@ -0,0 +1,19 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "gem-call-app.fullname" . }}
labels:
app: {{ .Release.Name }}
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
ports:
- name: "9090"
port: 9090
targetPort: 9090
- name: "5089"
port: 5089
targetPort: 5005
selector:
app: gem-call-app

View File

@ -0,0 +1,40 @@
replicaCount: 1
image:
repository: registry.co-work.ru/gem-call-app
tag: 1.0.0-SNAPSHOT
secrets:
kafka: kafka-password
redis: redis-kafka-user-passwords
kafka:
bootstrapServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: "6379"
keycloak:
url: https://iam.nubes.ru/realms/cowork
env:
cert_alias: nubes
call:
host: call-app
port: "9090"
callRealtime:
host: call-realtime-app
port: "9090"
chat:
host: chat-app
port: "9090"
deeplink:
host: deeplink-app
port: "9090"
user:
host: user-app
port: "9090"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,8 @@
apiVersion: v2
name: gem-call-events-handler-app
description: A Helm chart for gem-call-events-handler-app
type: application
version: 0.1.0
appVersion: "1.0.0"

View File

@ -0,0 +1,15 @@
{{- define "gem-call-events-handler-app.name" -}}
gem-call-events-handler-app
{{- end -}}
{{- define "gem-call-events-handler-app.fullname" -}}
{{- .Release.Name }}
{{- end -}}
{{- define "gem-call-events-handler-app.labels" -}}
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/version: {{ .Chart.Version }}
app.kubernetes.io/component: gem-call-events-handler-app
app.kubernetes.io/part-of: gem-call-events-handler-app
{{- end -}}

View File

@ -0,0 +1,92 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "gem-call-events-handler-app.fullname" . }}
labels:
{{- include "gem-call-events-handler-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
template:
metadata:
labels:
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.env.cert_alias }}.crt
path: RootCA_{{ .Values.env.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.env.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: gem-call-events-handler-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CASSANDRA_CONTACTPOINT
value: {{ .Values.env.cassandra.contactPoint | quote }}
- name: CASSANDRA_DATACENTER
value: {{ .Values.env.cassandra.datacenter | quote }}
- name: CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra }}
key: username
- name: CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.cassandra }}
key: cassandra-password
- name: KAFKA
value: {{ .Values.env.kafka.brokers | quote }}
- name: KAFKA_USERNAME
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka }}
key: username
- name: KAFKA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.kafka }}
key: client-passwords
- name: KEYCLOAK_URL
value: {{ .Values.keycloak.url | quote }}
- name: REDIS_HOST
value: {{ .Values.redis.host | quote }}
- name: REDIS_PORT
value: {{ .Values.redis.port | quote }}
- name: CHAT_HOST
value: {{ .Values.chat.host | quote }}
- name: CHAT_PORT
value: {{ .Values.chat.port | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
restartPolicy: Always

View File

@ -0,0 +1,19 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "gem-call-events-handler-app.fullname" . }}
labels:
app: {{ .Release.Name }}
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
release: {{ .Release.Name }}
heritage: {{ .Release.Service }}
spec:
ports:
- name: "8089"
port: 8089
targetPort: 9090
- name: "5089"
port: 5089
targetPort: 5005
selector:
io.kompose.service: gem-call-events-handler-app

View File

@ -0,0 +1,32 @@
replicaCount: 1
image:
repository: "registry.co-work.ru/gem-call-events-handler-app"
tag: "1.0.0-SNAPSHOT"
pullPolicy: IfNotPresent
env:
cassandra:
contactPoint: "cassandra.cassandra.svc.cluster.local"
datacenter: "datacenter1"
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
keycloak:
url: "https://iam.nubes.ru/realms/cowork"
redis:
host: "redis-master.redis.svc.cluster.local"
port: "6379"
secrets:
cassandra: cassandra
kafka: kafka-password
chat:
host: "chat-app"
port: "9090"
additionalEnv: []
podAnnotations: {}
podLabels: {}

Some files were not shown because too many files have changed in this diff Show More