initial commit of new tenant client2

This commit is contained in:
Leo Sok 2025-07-18 11:38:43 +03:00
parent e07a63e1cc
commit b3bfc73310
515 changed files with 13847 additions and 10376 deletions

3
.gitignore vendored Normal file
View File

@ -0,0 +1,3 @@
# macOS
.DS_Store
**/.DS_Store

View File

@ -0,0 +1,18 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: backend-app
namespace: argocd
spec:
project: default
source:
repoURL: https://gitlab.ii-p001.local/cw-devops/cw-infra-apps.git
targetRevision: main
path: charts/backend
destination:
server: https://kubernetes.default.svc
namespace: client1
syncPolicy:
automated:
prune: true
selfHeal: true

View File

@ -14,7 +14,7 @@ metadata:
uid: dcda9843-8c6e-4465-9f41-43be4d47e794
spec:
destination:
namespace: cassandra
namespace: client1
server: https://kubernetes.default.svc
project: default
source:

View File

@ -9,7 +9,7 @@ metadata:
uid: 928fb09c-938a-4ed5-9f05-5f8702d14a5e
spec:
destination:
namespace: elasticsearch
namespace: client1
server: https://kubernetes.default.svc
project: default
source:

View File

@ -9,7 +9,7 @@ metadata:
uid: 5f1ac9c2-48c5-4778-afc3-6a9a2c525a4f
spec:
destination:
namespace: grafana
namespace: client1
server: https://kubernetes.default.svc
project: default
source:

View File

@ -14,7 +14,7 @@ metadata:
uid: 742ebfdd-6dd9-4eea-bc4f-075e1f970bf4
spec:
destination:
namespace: kafka
namespace: client1
server: https://kubernetes.default.svc
project: default
source:
@ -349,7 +349,7 @@ status:
sync:
comparedTo:
destination:
namespace: kafka
namespace: client1
server: https://kubernetes.default.svc
source:
path: kafka

View File

@ -9,7 +9,7 @@ metadata:
uid: e20642c8-3378-4c0c-8f8f-9c54440413ac
spec:
destination:
namespace: livekit
namespace: client1
server: https://kubernetes.default.svc
project: default
source:
@ -24,7 +24,7 @@ spec:
- group: apps
kind: Deployment
name: livekit-egress
namespace: livekit
namespace: client1
jsonPointers:
- /spec/replicas
status:
@ -61,7 +61,7 @@ status:
- group: ""
hookPhase: Running
kind: Namespace
message: namespace/livekit created
message: namespace/client1 created
name: livekit
namespace: ""
status: Synced
@ -72,7 +72,7 @@ status:
kind: ConfigMap
message: configmap/livekit-egress created
name: livekit-egress
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -81,7 +81,7 @@ status:
kind: Deployment
message: deployment.apps/livekit-egress created
name: livekit-egress
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -94,7 +94,7 @@ status:
resources:
- kind: ConfigMap
name: livekit-egress
namespace: livekit
namespace: client1
status: Synced
version: v1
- group: apps
@ -102,7 +102,7 @@ status:
status: Healthy
kind: Deployment
name: livekit-egress
namespace: livekit
namespace: client1
status: Synced
version: v1
sourceType: Helm
@ -112,7 +112,7 @@ status:
sync:
comparedTo:
destination:
namespace: livekit
namespace: client1
server: https://kubernetes.default.svc
source:
path: livekit/livekit-egress

View File

@ -9,7 +9,7 @@ metadata:
uid: 6fd2964a-59c7-442f-8029-d3c7095ee329
spec:
destination:
namespace: livekit
namespace: client1
server: https://kubernetes.default.svc
project: default
source:
@ -24,7 +24,7 @@ spec:
- group: apps
kind: Deployment
name: livekit-server
namespace: livekit
namespace: client1
jsonPointers:
- /spec/replicas
@ -69,7 +69,7 @@ status:
configmap "livekit-server" deleted
configmap/livekit-server replaced
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -80,7 +80,7 @@ status:
service "livekit-server" deleted
service/livekit-server replaced
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -91,7 +91,7 @@ status:
service "livekit-server-turn" deleted
service/livekit-server-turn replaced
name: livekit-server-turn
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -111,7 +111,7 @@ status:
kind: Ingress
message: ingress.networking.k8s.io/livekit-server-turn created
name: livekit-server-turn
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -120,7 +120,7 @@ status:
kind: Ingress
message: ingress.networking.k8s.io/livekit-server created
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -133,14 +133,14 @@ status:
resources:
- kind: ConfigMap
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
version: v1
- health:
status: Healthy
kind: Service
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
version: v1
- health:
@ -155,7 +155,7 @@ status:
status: Healthy
kind: Deployment
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
version: v1
- group: networking.k8s.io
@ -163,7 +163,7 @@ status:
status: Healthy
kind: Ingress
name: livekit-server
namespace: livekit
namespace: client1
status: Synced
version: v1
- group: networking.k8s.io
@ -171,7 +171,7 @@ status:
status: Progressing
kind: Ingress
name: livekit-server-turn
namespace: livekit
namespace: client1
status: Synced
version: v1
sourceType: Helm
@ -184,7 +184,7 @@ status:
sync:
comparedTo:
destination:
namespace: livekit
namespace: client1
server: https://kubernetes.default.svc
source:
path: livekit/livekit-server

View File

@ -14,7 +14,7 @@ metadata:
uid: 46da0f9d-0b3b-4b16-ab5d-ef5d65b15792
spec:
destination:
namespace: nfs-subdir-external-provisioner
namespace: client1
server: https://kubernetes.default.svc
project: default
source:

View File

@ -11,7 +11,7 @@ spec:
path: postgresql-ha
destination:
server: https://kubernetes.default.svc
namespace: postgresql-ha
namespace: client1
syncPolicy:
automated:
prune: true

View File

@ -9,7 +9,7 @@ metadata:
uid: e79154a8-6a82-4993-8479-4260dd93deea
spec:
destination:
namespace: redis
namespace: client1
server: https://kubernetes.default.svc
project: default
source:

View File

@ -9,7 +9,7 @@ metadata:
uid: 0acb50cc-b736-4760-aa60-b1dffc497fdd
spec:
destination:
namespace: vault-secrets-operator
namespace: client1
server: https://kubernetes.default.svc
project: default
source:

View File

@ -14,7 +14,7 @@ metadata:
uid: 495b57f6-384a-4a4e-b976-514011af6c45
spec:
destination:
namespace: vault
namespace: client1
server: https://kubernetes.default.svc
ignoreDifferences:
- group: admissionregistration.k8s.io
@ -120,7 +120,7 @@ status:
poddisruptionbudget.policy "vault" deleted
poddisruptionbudget.policy/vault replaced
name: vault
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -131,7 +131,7 @@ status:
serviceaccount "vault-agent-injector" deleted
serviceaccount/vault-agent-injector replaced
name: vault-agent-injector
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -142,7 +142,7 @@ status:
serviceaccount "vault" deleted
serviceaccount/vault replaced
name: vault
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -153,7 +153,7 @@ status:
configmap "vault-config" deleted
configmap/vault-config replaced
name: vault-config
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -164,7 +164,7 @@ status:
clusterrole.rbac.authorization.k8s.io/vault-agent-injector-clusterrole reconciled. clusterrole.rbac.authorization.k8s.io "vault-agent-injector-clusterrole" deleted
clusterrole.rbac.authorization.k8s.io/vault-agent-injector-clusterrole replaced
name: vault-agent-injector-clusterrole
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -175,7 +175,7 @@ status:
clusterrolebinding.rbac.authorization.k8s.io/vault-server-binding reconciled. clusterrolebinding.rbac.authorization.k8s.io "vault-server-binding" deleted
clusterrolebinding.rbac.authorization.k8s.io/vault-server-binding replaced
name: vault-server-binding
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -186,7 +186,7 @@ status:
clusterrolebinding.rbac.authorization.k8s.io/vault-agent-injector-binding reconciled. clusterrolebinding.rbac.authorization.k8s.io "vault-agent-injector-binding" deleted
clusterrolebinding.rbac.authorization.k8s.io/vault-agent-injector-binding replaced
name: vault-agent-injector-binding
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -197,7 +197,7 @@ status:
role.rbac.authorization.k8s.io/vault-discovery-role reconciled. role.rbac.authorization.k8s.io "vault-discovery-role" deleted
role.rbac.authorization.k8s.io/vault-discovery-role replaced
name: vault-discovery-role
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -208,7 +208,7 @@ status:
rolebinding.rbac.authorization.k8s.io/vault-discovery-rolebinding reconciled. rolebinding.rbac.authorization.k8s.io "vault-discovery-rolebinding" deleted
rolebinding.rbac.authorization.k8s.io/vault-discovery-rolebinding replaced
name: vault-discovery-rolebinding
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -219,7 +219,7 @@ status:
service "vault-internal" deleted
service/vault-internal replaced
name: vault-internal
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -230,7 +230,7 @@ status:
service "vault-agent-injector-svc" deleted
service/vault-agent-injector-svc replaced
name: vault-agent-injector-svc
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -241,7 +241,7 @@ status:
service "vault-standby" deleted
service/vault-standby replaced
name: vault-standby
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -252,7 +252,7 @@ status:
service "vault" deleted
service/vault replaced
name: vault
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -263,7 +263,7 @@ status:
service "vault-active" deleted
service/vault-active replaced
name: vault-active
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -274,7 +274,7 @@ status:
deployment.apps "vault-agent-injector" deleted
deployment.apps/vault-agent-injector replaced
name: vault-agent-injector
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -285,7 +285,7 @@ status:
statefulset.apps "vault" deleted
statefulset.apps/vault replaced
name: vault
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -296,7 +296,7 @@ status:
mutatingwebhookconfiguration.admissionregistration.k8s.io "vault-agent-injector-cfg" deleted
mutatingwebhookconfiguration.admissionregistration.k8s.io/vault-agent-injector-cfg replaced
name: vault-agent-injector-cfg
namespace: vault
namespace: client1
status: Synced
syncPhase: Sync
version: v1
@ -312,52 +312,52 @@ status:
resources:
- kind: ConfigMap
name: vault-config
namespace: vault
namespace: client1
status: Synced
version: v1
- health:
status: Healthy
kind: Service
name: vault
namespace: vault
namespace: client1
status: Synced
version: v1
- health:
status: Healthy
kind: Service
name: vault-active
namespace: vault
namespace: client1
status: Synced
version: v1
- health:
status: Healthy
kind: Service
name: vault-agent-injector-svc
namespace: vault
namespace: client1
status: Synced
version: v1
- health:
status: Healthy
kind: Service
name: vault-internal
namespace: vault
namespace: client1
status: Synced
version: v1
- health:
status: Healthy
kind: Service
name: vault-standby
namespace: vault
namespace: client1
status: Synced
version: v1
- kind: ServiceAccount
name: vault
namespace: vault
namespace: client1
status: Synced
version: v1
- kind: ServiceAccount
name: vault-agent-injector
namespace: vault
namespace: client1
status: Synced
version: v1
- group: admissionregistration.k8s.io
@ -370,7 +370,7 @@ status:
status: Healthy
kind: Deployment
name: vault-agent-injector
namespace: vault
namespace: client1
status: Synced
version: v1
- group: apps
@ -379,13 +379,13 @@ status:
status: Healthy
kind: StatefulSet
name: vault
namespace: vault
namespace: client1
status: Synced
version: v1
- group: policy
kind: PodDisruptionBudget
name: vault
namespace: vault
namespace: client1
status: Synced
version: v1
- group: rbac.authorization.k8s.io
@ -406,13 +406,13 @@ status:
- group: rbac.authorization.k8s.io
kind: Role
name: vault-discovery-role
namespace: vault
namespace: client1
status: Synced
version: v1
- group: rbac.authorization.k8s.io
kind: RoleBinding
name: vault-discovery-rolebinding
namespace: vault
namespace: client1
status: Synced
version: v1
sourceType: Helm
@ -423,7 +423,7 @@ status:
sync:
comparedTo:
destination:
namespace: vault
namespace: client1
server: https://kubernetes.default.svc
ignoreDifferences:
- group: admissionregistration.k8s.io

View File

@ -4,4 +4,4 @@ binaryData:
kind: ConfigMap
metadata:
name: cassandra-init-script
namespace: cassandra
namespace: {{ .Release.Namespace }}

View File

@ -641,7 +641,7 @@ persistence:
## set, choosing the default provisioner. (gp2 on AWS, standard on
## GKE, AWS & OpenStack)
##
storageClass: ""
storageClass: "client1"
## @param persistence.commitStorageClass PVC Storage Class for Cassandra Commit Log volume
## Storage class to use with CASSANDRA_COMMITLOG_DIR to reduce the concurrence for writing data and commit logs
## ref: https://github.com/bitnami/containers/tree/main/bitnami/cassandra

125
charts/backend/Chart.yaml Executable file
View File

@ -0,0 +1,125 @@
apiVersion: v2
name: backend
description: Umbrella chart for all backend k8s applications
type: application
version: "0.1.0"
appVersion: "1.0.0"
dependencies:
- name: admin-app
version: "0.1.0"
repository: file://charts/admin-app-k8s
- name: android-app
version: "0.1.0"
repository: file://charts/android-app-k8s
- name: auth-app
version: "0.1.0"
repository: file://charts/auth-app-k8s
- name: auth-event-handler-app
version: "0.1.0"
repository: file://charts/auth-event-handler-app-k8s
- name: bff-admin-app
version: "0.1.0"
repository: file://charts/bff-admin-app-k8s
- name: bff-app
version: "0.1.0"
repository: file://charts/bff-app-k8s
- name: bff-vcs-app
version: "0.1.0"
repository: file://charts/bff-vcs-app-k8s
- name: big-chat-splitter-app
version: "0.1.0"
repository: file://charts/big-chat-splitter-app-k8s
- name: call-app
version: "0.1.0"
repository: file://charts/call-app-k8s
- name: call-event-handler-app
version: "0.1.0"
repository: file://charts/call-event-handler-app-k8s
- name: call-realtime-app
version: "0.1.0"
repository: file://charts/call-realtime-app-k8s
- name: chat-app
version: "0.1.0"
repository: file://charts/chat-app-k8s
- name: chat-event-handler-app
version: "0.1.0"
repository: file://charts/chat-event-handler-app-k8s
- name: deeplink-app
version: "0.1.0"
repository: file://charts/deeplink-app-k8s
- name: gem-call-app
version: "0.1.0"
repository: file://charts/gem-call-app-k8s
- name: gem-call-events-handler-app
version: "0.1.0"
repository: file://charts/gem-call-events-handler-app-k8s
- name: huawei-app
version: "0.1.0"
repository: file://charts/huawei-app-k8s
- name: ios-app
version: "0.1.0"
repository: file://charts/ios-app-k8s
- name: livekit-webhook-handler-app
version: "0.1.0"
repository: file://charts/livekit-webhook-handler-app-k8s
- name: message-app
version: "0.1.0"
repository: file://charts/message-app-k8s
- name: message-call-event-handler-app
version: "0.1.0"
repository: file://charts/message-call-event-handler-app-k8s
- name: message-chat-event-handler-app
version: "0.1.0"
repository: file://charts/message-chat-event-handler-app-k8s
- name: message-event-handler-app
version: "0.1.0"
repository: file://charts/message-event-handler-app-k8s
- name: message-link-preview-handler-app
version: "0.1.0"
repository: file://charts/message-link-preview-handler-app-k8s
- name: message-user-event-handler-app
version: "0.1.0"
repository: file://charts/message-user-event-handler-app-k8s
- name: notification-app
version: "0.1.0"
repository: file://charts/notification-app-k8s
- name: notification-event-handler-app
version: "0.1.0"
repository: file://charts/notification-event-handler-app-k8s
- name: realtime-app
version: "0.1.0"
repository: file://charts/realtime-app-k8s
- name: regular-chat-splitter-app
version: "0.1.0"
repository: file://charts/regular-chat-splitter-app-k8s
- name: search-app
version: "0.1.0"
repository: file://charts/search-app-k8s
- name: search-event-handler-app
version: "0.1.0"
repository: file://charts/search-event-handler-app-k8s
- name: sticker-app
version: "0.1.0"
repository: file://charts/sticker-app-k8s
- name: unregister-tokens-app
version: "0.1.0"
repository: file://charts/unregister-tokens-app-k8s
- name: upload-app
version: "0.1.0"
repository: file://charts/upload-app-k8s
- name: user-app
version: "0.1.0"
repository: file://charts/user-app-k8s
- name: voip-splitter-app
version: "0.1.0"
repository: file://charts/voip-splitter-app-k8s
- name: web-sender-app
version: "0.1.0"
repository: file://charts/web-sender-app-k8s
- name: workspace-app
version: "0.1.0"
repository: file://charts/workspace-app-k8s
- name: workspace-event-handler-app
version: "0.1.0"
repository: file://charts/workspace-event-handler-app-k8s

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: admin-app
description: Helm chart for Admin app
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "admin-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "admin-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "admin-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "admin-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "admin-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "admin-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end }}

View File

@ -0,0 +1,64 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "admin-app.fullname" . }}
labels:
{{- include "admin-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "admin-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "admin-app.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: admin-app
ports:
- containerPort: 9090
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: WORKSPACE_HOST
value: "{{ .Values.env.workspace_host }}"
- name: WORKSPACE_PORT
value: "{{ .Values.env.workspace_port }}"
- name: USER_HOST
value: "{{ .Values.env.user_host }}"
- name: USER_PORT
value: "{{ .Values.env.user_port }}"
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "admin-app.fullname" . }}
labels:
{{- include "admin-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
selector:
{{- include "admin-app.selectorLabels" . | nindent 4 }}
ports:
- name: http
port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP

View File

@ -0,0 +1,16 @@
replicaCount: 1
image:
repository: docker.ii-p001.local/admin-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
env:
workspace_host: workspace-app
workspace_port: 9090
user_host: user-app
user_port: 9090
service:
type: ClusterIP
port: 9090
targetPort: 9090

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: android-app
description: Helm chart for Android Sender Application
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "android-sender-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "android-sender-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "android-sender-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "android-sender-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end }}

View File

@ -0,0 +1,64 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "android-sender-app.fullname" . }}
labels:
{{- include "android-sender-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "android-sender-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "android-sender-app.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
echo "Certificate with alias gemcert already exists, skipping import"
else
echo "Importing certificate with alias gemcert"
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
fi
containers:
- name: android-sender
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: ANDROID_FIREBASE_CONFIG
value: {{ .Values.env.android_firebase_config }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,16 @@
replicaCount: 1
image:
repository: docker.ii-p001.local/android-sender-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
env:
kafkaServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redisHost: redis-master.redis.svc.cluster.local
redisPort: 6379
android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json"
secrets:
kafkaSecret: kafka-password
firebaseSecret: android-firebase-config

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: auth-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,53 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "auth-app-k8s.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "auth-app-k8s.fullname" -}}
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "auth-app-k8s.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "auth-app-k8s.labels" -}}
helm.sh/chart: {{ include "auth-app-k8s.chart" . }}
{{ include "auth-app-k8s.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "auth-app-k8s.selectorLabels" -}}
app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "auth-app-k8s.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}

View File

@ -0,0 +1,103 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "auth-app-k8s.fullname" . }}
labels:
{{- include "auth-app-k8s.labels" . | nindent 4 }}
io.kompose.service: auth-app
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "auth-app-k8s.selectorLabels" . | nindent 6 }}
io.kompose.service: auth-app
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "auth-app-k8s.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
volumes:
- name: ca-cert
configMap:
name: {{ include "auth-app-k8s.fullname" . }}-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: auth-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: {{ .Values.service.targetPort }}
{{- if .Values.service.hostPort }}
hostPort: {{ .Values.service.hostPort }}
{{- end }}
protocol: TCP
env:
- name: ADMIN_CLIENT_ID
value: {{ .Values.env.adminClientId | quote }}
- name: ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.adminPassword.name }}
key: {{ .Values.secrets.adminPassword.key }}
- name: ADMIN_REALM
value: {{ .Values.env.adminRealm | quote }}
- name: ADMIN_URL
value: {{ .Values.env.adminUrl | quote }}
- name: ADMIN_USERNAME
value: {{ .Values.env.adminUsername | quote }}
- name: CLIENT_ID
value: {{ .Values.env.clientId | quote }}
- name: CLIENT_ISSUER_IRI
value: {{ .Values.env.clientIssuerIri | quote }}
- name: CLIENT_REALM
value: {{ .Values.env.clientRealm | quote }}
- name: CLIENT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.clientSecret.name }}
key: {{ .Values.secrets.clientSecret.key }}
- name: REALM
value: {{ .Values.env.realm | quote }}
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
- name: SECURITY_ADMIN_REALM
value: {{ .Values.env.securityAdminRealm | quote }}
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
resources:
{{- toYaml .Values.resources | nindent 12 }}

View File

@ -0,0 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "auth-app-k8s.fullname" . }}
labels:
{{- include "auth-app-k8s.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
- port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP
selector:
{{- include "auth-app-k8s.selectorLabels" . | nindent 4 }}
io.kompose.service: auth-app

View File

@ -0,0 +1,15 @@
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "auth-app-k8s.fullname" . }}-test-connection"
labels:
{{- include "auth-app-k8s.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never

View File

@ -0,0 +1,58 @@
fullnameOverride: "auth-app"
image:
repository: docker.ii-p001.local/auth-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
port: 9090
targetPort: 9090
hostPort: null
env:
cert_alias: co-work
adminClientId: "admin-cli"
adminRealm: "master"
adminUrl: "https://iam.stage.co-work.local/admin/realms/co-work"
adminUsername: "admin"
clientId: "gem-auth-client"
clientIssuerIri: "https://iam.stage.co-work.local/realms/co-work"
clientRealm: "co-work"
realm: "co-work"
securityAdminRealm: "master"
securityOauth2ClientIssuerUri: "https://iam.stage.co-work.local/realms"
secrets:
adminPassword:
name: auth-secrets
key: admin-password
clientSecret:
name: auth-secrets
key: client-secret
resources:
limits:
memory: 512Mi
requests:
cpu: 100m
memory: 256Mi
podAnnotations:
kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: auth-app
autoscaling:
enabled: false

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: auth-event-handler-app
description: Authentication Event Handler
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,19 @@
{{/* Common Name Definitions */}}
{{- define "auth-event-handler-app-k8s.fullname" -}}
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Standard labels */}}
{{- define "auth-event-handler-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "auth-event-handler-app-k8s.selectorLabels" -}}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end }}

View File

@ -0,0 +1,135 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
labels:
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }}
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- if .Values.serviceAccount.create }}
serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
{{- with .Values.volumes }}
{{ toYaml . | nindent 8 }}
{{- end }}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
protocol: TCP
env:
- name: ADMIN_CLIENT_ID
value: {{ .Values.env.adminClientId | quote }}
- name: ADMIN_REALM
value: {{ .Values.env.adminRealm | quote }}
- name: ADMIN_URL
value: {{ .Values.env.adminUrl | quote }}
- name: ADMIN_USERNAME
value: {{ .Values.env.adminUsername | quote }}
- name: CLIENT_ID
value: {{ .Values.env.clientId | quote }}
- name: CLIENT_ISSUER_IRI
value: {{ .Values.env.clientIssuerIri | quote }}
- name: CLIENT_REALM
value: {{ .Values.env.clientRealm | quote }}
- name: REALM
value: {{ .Values.env.realm | quote }}
- name: SECURITY_ADMIN_REALM
value: {{ .Values.env.securityAdminRealm | quote }}
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.adminPassword.name }}
key: {{ .Values.secrets.adminPassword.key }}
- name: CLIENT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.clientSecret.name }}
key: {{ .Values.secrets.clientSecret.key }}
livenessProbe:
{{- toYaml .Values.livenessProbe | nindent 12 }}
readinessProbe:
{{- toYaml .Values.readinessProbe | nindent 12 }}
resources:
{{- toYaml .Values.resources | nindent 12 }}
volumeMounts:
{{- with .Values.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}

View File

@ -0,0 +1,12 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
labels:
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
spec:
ports:
- port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
selector:
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,60 @@
fullnameOverride: "auth-event-handler-app"
image:
repository: docker.ii-p001.local/auth-event-handler-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
port: 8094
targetPort: 9090
env:
adminClientId: "admin-cli"
adminRealm: "master"
adminUrl: "https://iam.stage.co-work.local/admin/realms/co-work"
adminUsername: "admin"
clientId: "gem-auth-client"
clientIssuerIri: "https://iam.stage.co-work.local/realms/co-work"
clientRealm: "co-work"
realm: "co-work"
securityAdminRealm: "master"
securityOauth2ClientIssuerUri: "https://iam.stage.co-work.local/realms"
kafkaBrokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
secrets:
kafka:
name: kafka-password
passwordKey: client-passwords
username: admin
adminPassword:
name: auth-secrets
key: admin-password
clientSecret:
name: auth-secrets
key: client-secret
resources:
limits:
memory: 512Mi
requests:
cpu: 100m
memory: 256Mi
podAnnotations:
kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: auth-event-handler-app
podSecurityContext: {}
securityContext: {}
autoscaling:
enabled: false
serviceAccount:
create: false
name: ""

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: bff-admin-app
description: Helm chart for bff-admin-app
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "bff-admin-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "bff-admin-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "bff-admin-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "bff-admin-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end }}

View File

@ -0,0 +1,39 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "bff-admin-app.fullname" . }}
labels:
{{- include "bff-admin-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "bff-admin-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "bff-admin-app.selectorLabels" . | nindent 8 }}
spec:
containers:
- name: bff-admin-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: SWAGGER_HOST
value: "{{ .Values.env.swagger_host }}"
- name: SWAGGER_PORT
value: "{{ .Values.env.swagger_port }}"
- name: WORKSPACE_HOST
value: "{{ .Values.env.workspace_host }}"
- name: WORKSPACE_PORT
value: "{{ .Values.env.workspace_port }}"
- name: USER_HOST
value: "{{ .Values.env.user_host }}"
- name: USER_PORT
value: "{{ .Values.env.user_port }}"
- name: ADMIN_HOST
value: "{{ .Values.env.admin_host }}"
- name: ADMIN_PORT
value: "{{ .Values.env.admin_port }}"
- name: APP_NAME
value: "{{ .Values.env.app_name }}"

View File

@ -0,0 +1,38 @@
{{- if .Values.ingress.enabled -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ .Values.ingress.name }}
namespace: {{ .Release.Namespace | default "default" }}
{{- with .Values.ingress.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
ingressClassName: {{ .Values.ingress.className }}
{{- if .Values.ingress.tls }}
tls:
{{- range .Values.ingress.tls }}
- hosts:
{{- range .hosts }}
- {{ . | quote }}
{{- end }}
secretName: {{ .secretName | quote }}
{{- end }}
{{- end }}
rules:
{{- range .Values.ingress.hosts }}
- host: {{ .host | quote }}
http:
paths:
{{- range .paths }}
- path: {{ .path }}
pathType: {{ .pathType }}
backend:
service:
name: {{ $.Values.env.app_name }}
port:
number: {{ $.Values.service.httpPort }}
{{- end }}
{{- end }}
{{- end }}

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "bff-admin-app.fullname" . }}
labels:
{{- include "bff-admin-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
selector:
{{- include "bff-admin-app.selectorLabels" . | nindent 4 }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}

View File

@ -0,0 +1,46 @@
replicaCount: 1
image:
repository: docker.ii-p001.local/bff-admin-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
env:
swagger_host: "localhost"
swagger_port: 8080
workspace_host: "workspace-app"
workspace_port: 9090
user_host: "user-app"
user_port: 9090
admin_host: "admin-app"
admin_port: 9090
app_name: bff-admin-app
service:
type: ClusterIP
httpPort: 8100
grpcPort: 8101
ports:
- name: http
port: 8100
targetPort: 8080
- name: grpc
port: 8101
targetPort: 9090
ingress:
enabled: true
className: nginx
name: bff-admin-ingress
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
hosts:
- host: adm-s001.co-work.ru
paths:
- path: /
pathType: Prefix
tls:
- hosts:
- adm-s001.co-work.ru
secretName: co-work-secret

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: bff-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,19 @@
{{/* Common Name Definitions */}}
{{- define "bff-app-k8s.fullname" -}}
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Standard labels */}}
{{- define "bff-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "bff-app-k8s.selectorLabels" -}}
app.kubernetes.io/name: {{ .Values.fullnameOverride }}
app.kubernetes.io/instance: {{ .Values.fullnameOverride }}
{{- end }}

View File

@ -0,0 +1,93 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "bff-app-k8s.fullname" . }}
labels:
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "bff-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "bff-app-k8s.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
# initContainers:
# - name: import-ca
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
# env:
# - name: CERT_ALIAS
# value: {{ .Values.global.cert_alias | quote }}
# volumeMounts:
# - name: ca-cert
# mountPath: /app/resources
# - name: cacerts-volume
# mountPath: /tmp/cacerts
# command:
# - sh
# - -c
# - |
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
# keytool -import -trustcacerts -storepass changeit -noprompt \
# -alias gemcert \
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
# -keystore /tmp/cacerts/cacerts
containers:
- name: bff-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: {{ .Values.service.targetPort }}
{{- if .Values.service.hostPort }}
hostPort: {{ .Values.service.hostPort }}
{{- end }}
protocol: TCP
env:
- name: GRPC_CLIENT_AUTH_URL
value: {{ .Values.env.services.auth | quote }}
- name: GRPC_CLIENT_CHAT_URL
value: {{ .Values.env.services.chat | quote }}
- name: GRPC_CLIENT_CONFIG_URL
value: {{ .Values.env.services.user | quote }}
- name: GRPC_CLIENT_DEEPLINK_URL
value: {{ .Values.env.services.deeplink | quote }}
- name: GRPC_CLIENT_GEM_CALL_URL
value: {{ .Values.env.services.gemCall | quote }}
- name: GRPC_CLIENT_MESSAGE_URL
value: {{ .Values.env.services.message | quote }}
- name: GRPC_CLIENT_NOTIFICATIONS_URL
value: {{ .Values.env.services.notification | quote }}
- name: GRPC_CLIENT_REACTION_URL
value: {{ .Values.env.services.message | quote }}
- name: GRPC_CLIENT_REALTIME_URL
value: {{ .Values.env.services.realtime | quote }}
- name: GRPC_CLIENT_SEARCH_URL
value: {{ .Values.env.services.search | quote }}
- name: GRPC_CLIENT_STICKER_URL
value: {{ .Values.env.services.sticker | quote }}
- name: GRPC_CLIENT_UPLOAD_URL
value: {{ .Values.env.services.upload | quote }}
- name: GRPC_CLIENT_USER_URL
value: {{ .Values.env.services.user | quote }}
- name: GRPC_CLIENT_WORKSPACE_URL
value: {{ .Values.env.services.workspace | quote }}
resources:
{{- toYaml .Values.resources | nindent 12 }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,28 @@
{{- if .Values.ingress.enabled -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ .Values.ingress.name }}
namespace: {{ .Release.Namespace | default "default" }}
{{- with .Values.ingress.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
ingressClassName: {{ .Values.ingress.className }}
tls:
- hosts:
- {{ .Values.ingress.host | quote }}
secretName: {{ .Values.ingress.tlsSecret | quote }}
rules:
- host: {{ .Values.ingress.host | quote }}
http:
paths:
- path: {{ .Values.ingress.path }}
pathType: {{ .Values.ingress.pathType }}
backend:
service:
name: {{ .Values.service.name }}
port:
number: {{ .Values.service.port }}
{{- end }}

View File

@ -0,0 +1,14 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "bff-app-k8s.fullname" . }}
labels:
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
- port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP
selector:
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,58 @@
image:
repository: docker.ii-p001.local/bff-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
port: 8081
targetPort: 8080
nodePort: 31754
name: bff-app # Added service name
ingress:
enabled: true
className: nginx
name: bff-app-ingress
host: api-s001.co-work.ru
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
path: /
pathType: Prefix
tlsSecret: co-work-secret
env:
services:
auth: http://auth-app:9090
chat: http://chat-app:9090
user: http://user-app:9090
deeplink: http://deeplink-app:9090
gemCall: http://gem-call-app:9090
message: http://message-app:9090
notification: http://notification-app:9090
realtime: http://realtime-app:9090
search: http://search-app:9090
sticker: http://sticker-app:9090
upload: http://upload-app:9090
workspace: http://workspace-app:9090
resources:
limits:
memory: 1Gi
requests:
cpu: 200m
memory: 512Mi
podAnnotations:
kompose.cmd: kompose convert -f app/bff-app.yml -o k8s/bff-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: bff-app
fullnameOverride: "bff-app"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: bff-vcs-app
description: Helm chart for bff-vcs-app
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,24 @@
{{/* Common labels */}}
{{- define "bff-vcs-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Name */}}
{{- define "bff-vcs-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Fullname */}}
{{- define "bff-vcs-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Selector labels */}}
{{- define "bff-vcs-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end }}

View File

@ -0,0 +1,58 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "bff-vcs-app.fullname" . }}
labels:
{{- include "bff-vcs-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "bff-vcs-app.selectorLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "bff-vcs-app.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
# initContainers:
# - name: import-ca
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
# env:
# - name: CERT_ALIAS
# value: {{ .Values.global.cert_alias | quote }}
# volumeMounts:
# - name: ca-cert
# mountPath: /app/resources
# - name: cacerts-volume
# mountPath: /tmp/cacerts
# command:
# - sh
# - -c
# - |
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
# keytool -import -trustcacerts -storepass changeit -noprompt \
# -alias gemcert \
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
# -keystore /tmp/cacerts/cacerts
containers:
- name: bff-vcs-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
- name: GRPC_CLIENT_CALL_URL
value: "{{ .Values.env.grpc_client_call_url }}"
- name: GRPC_CLIENT_CALL_REALTIME_URL
value: "{{ .Values.env.grpc_client_call_realtime_url }}"
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,28 @@
{{- if .Values.ingress.enabled }}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ include "bff-vcs-app.fullname" . }}-ingress
namespace: {{ .Release.Namespace }}
annotations:
{{- range $key, $value := .Values.ingress.annotations }}
{{ $key }}: {{ $value | quote }}
{{- end }}
spec:
ingressClassName: {{ .Values.ingress.ingressClassName }}
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecretName }}
rules:
- host: {{ .Values.ingress.host }}
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: {{ include "bff-vcs-app.fullname" . }}
port:
number: {{ .Values.service.port }}
{{- end }}

View File

@ -0,0 +1,16 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "bff-vcs-app.fullname" . }}
labels:
{{- include "bff-vcs-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
selector:
{{- include "bff-vcs-app.selectorLabels" . | nindent 4 }}
ports:
- name: http
port: {{ .Values.service.port }}
targetPort: {{ .Values.service.targetPort }}
protocol: TCP

View File

@ -0,0 +1,25 @@
replicaCount: 1
image:
repository: docker.ii-p001.local/bff-vcs-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
env:
grpc_client_call_url: http://call-realtime-app:9090
grpc_client_call_realtime_url: http://call-realtime-app:9090
service:
type: ClusterIP
port: 8079
targetPort: 8080
ingress:
enabled: true
ingressClassName: nginx
host: vcs-s001.co-work.ru
tlsSecretName: co-work-secret
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: big-chat-splitter-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,18 @@
{{/* Common Name Definitions */}}
{{- define "big-chat-splitter-app-k8s.fullname" -}}
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Standard labels */}}
{{- define "big-chat-splitter-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "big-chat-splitter-app-k8s.selectorLabels" -}}
io.kompose.service: big-chat-splitter-app
{{- end }}

View File

@ -0,0 +1,65 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "big-chat-splitter-app-k8s.fullname" . }}
labels:
{{- include "big-chat-splitter-app-k8s.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: big-chat-splitter-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
env:
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: CHAT_SERVICE_HOST
value: {{ .Values.env.services.chat.host | quote }}
- name: CHAT_SERVICE_PORT
value: {{ .Values.env.services.chat.port | quote }}
- name: USER_SERVICE_HOST
value: {{ .Values.env.services.user.host | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,54 @@
fullnameOverride: "big-chat-splitter-app"
image:
repository: docker.ii-p001.local/big-chat-splitter-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
env:
cassandra:
dc: datacenter1
host: "cassandra.cassandra.svc.cluster.local"
services:
chat:
host: chat-app
port: 9090
user:
host: user-app
port: 9090
redis:
host: redis-master.redis.svc.cluster.local
port: 6379
kafka:
servers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
secrets:
cassandra:
name: cassandra
passwordKey: cassandra-password
username: cassandra
kafka:
name: kafka-password
passwordKey: client-passwords
username: admin
resources:
limits:
memory: 1Gi
requests:
cpu: 500m
memory: 512Mi
podAnnotations:
kompose.cmd: kompose convert -f app/big-chat-splitter-app.yml -o k8s/big-chat-splitter-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: big-chat-splitter-app
fullnameOverride: "big-chat-splitter-app"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: call-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,18 @@
{{/* Common Name Definitions */}}
{{- define "call-app-k8s.fullname" -}}
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Standard labels */}}
{{- define "call-app-k8s.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
app.kubernetes.io/name: {{ .Chart.Name }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/* Selector labels */}}
{{- define "call-app-k8s.selectorLabels" -}}
io.kompose.service: call-app
{{- end }}

View File

@ -0,0 +1,97 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "call-app-k8s.fullname" . }}
labels:
{{- include "call-app-k8s.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "call-app-k8s.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "call-app-k8s.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: call-app
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
protocol: TCP
- containerPort: 9090
protocol: TCP
env:
- name: TENANT_ID
value: {{ .Values.env.TENANT_ID | quote }}
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: KEYCLOAK_URL
value: {{ .Values.env.keycloak.url | quote }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.apiKeyKey }}
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.secretKey }}
- name: RECORDING_ACCESS_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.accessKeyKey }}
- name: RECORDING_API_HOST
value: {{ .Values.env.livekit.apiHost | quote }}
- name: RECORDING_BUCKET
value: {{ .Values.env.recording.bucket | quote }}
- name: RECORDING_ENDPOINT
value: {{ .Values.env.recording.endpoint | quote }}
- name: RECORDING_REGION
value: {{ .Values.env.recording.region | quote }}
- name: RECORDING_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.secretKeyKey }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "call-app-k8s.fullname" . }}
labels:
{{- include "call-app-k8s.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}
selector:
{{- include "call-app-k8s.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,66 @@
image:
repository: docker.ii-p001.local/call-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
ports:
- name: main
port: 5005
targetPort: 5005
- name: metrics
port: 9090
targetPort: 9090
env:
cassandra:
contactPoint: cassandra.cassandra.svc.cluster.local
datacenter: datacenter1
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: 6379
keycloak:
url: https://iam.stage.co-work.local/realms/co-work
livekit:
apiHost: https://av-s001.co-work.ru/
recording:
endpoint: https://store.stage.co-work.local:9000
region: us-east-2
bucket: livekit
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
secrets:
cassandra:
name: cassandra
usernameKey: username
passwordKey: cassandra-password
kafka:
name: kafka-password
usernameKey: username
passwordKey: client-passwords
redis:
name: redis-kafka-user-passwords
passwordKey: client-passwords
livekit:
name: livekit-secret
apiKeyKey: api-key
secretKey: secret
recording:
name: recording-secret
accessKeyKey: access-key
secretKeyKey: secret
podAnnotations:
kompose.cmd: kompose convert -f app/call-app.yml -o k8s/call-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: call-app
fullnameOverride: "call-app"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: call-event-handler-app
description: Call Event Handler Application
type: application
version: 0.1.0
appVersion: "1.0.0-SNAPSHOT"

View File

@ -0,0 +1,46 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "call-event-handler-app.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "call-event-handler-app.fullname" -}}
{{- if .Values.fullnameOverride -}}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "call-event-handler-app.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Common labels
*/}}
{{- define "call-event-handler-app.labels" -}}
helm.sh/chart: {{ include "call-event-handler-app.chart" . }}
{{ include "call-event-handler-app.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end -}}
{{/*
Selector labels
*/}}
{{- define "call-event-handler-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "call-event-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end -}}

View File

@ -0,0 +1,79 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "call-event-handler-app.fullname" . }}
labels:
{{- include "call-event-handler-app.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.podAnnotations | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "call-event-handler-app.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "call-event-handler-app.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
protocol: TCP
- containerPort: 9090
protocol: TCP
env:
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.apiKeyKey }}
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.secretKey }}
- name: RECORDING_API_HOST
value: {{ .Values.env.recording.apiHost | quote }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "call-event-handler-app.fullname" . }}
labels:
{{- include "call-event-handler-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}
selector:
{{- include "call-event-handler-app.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,57 @@
image:
repository: docker.ii-p001.local/call-event-handler-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
replicaCount: 1
service:
type: ClusterIP
ports:
- name: main
port: 5005
targetPort: 5005
- name: metrics
port: 9090
targetPort: 9090
env:
cassandra:
contactPoint: cassandra.cassandra.svc.cluster.local
datacenter: datacenter1
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: "6379"
recording:
apiHost: https://store.stage.co-work.local:9000
secrets:
cassandra:
name: cassandra
usernameKey: username
passwordKey: cassandra-password
kafka:
name: kafka-password
usernameKey: username
passwordKey: client-passwords
redis:
name: redis-kafka-user-passwords
passwordKey: client-passwords
livekit:
name: livekit-secret
apiKeyKey: api-key
secretKey: secret
podAnnotations:
kompose.cmd: kompose convert -f app/call-event-handler-app.yml -o k8s/call-event-handler-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: call-event-handler-app
nameOverride: ""
fullnameOverride: ""

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: call-realtime-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,39 @@
{{/* vim: set filetype=mustache: */}}
{{/*
Expand the name of the chart.
*/}}
{{- define "call-realtime-app.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "call-realtime-app.fullname" -}}
{{- if .Values.fullnameOverride -}}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{/*
Common labels
*/}}
{{- define "call-realtime-app.labels" -}}
helm.sh/chart: {{ include "call-realtime-app.name" . }}
{{ include "call-realtime-app.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end -}}
{{/*
Selector labels
*/}}
{{- define "call-realtime-app.selectorLabels" -}}
app.kubernetes.io/name: {{ include "call-realtime-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
{{- end -}}

View File

@ -0,0 +1,93 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "call-realtime-app.fullname" . }}
labels:
{{- include "call-realtime-app.labels" . | nindent 4 }}
annotations:
{{- toYaml .Values.podAnnotations | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "call-realtime-app.selectorLabels" . | nindent 6 }}
template:
metadata:
annotations:
{{- toYaml .Values.podAnnotations | nindent 8 }}
labels:
{{- include "call-realtime-app.selectorLabels" . | nindent 8 }}
{{- toYaml .Values.podLabels | nindent 8 }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
protocol: TCP
- containerPort: 9090
protocol: TCP
env:
- name: TENANT_ID
value: {{ .Values.env.TENANT_ID | quote }}
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.apiKeyKey }}
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.livekit.name }}
key: {{ .Values.secrets.livekit.secretKey }}
- name: RECORDING_ACCESS_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.accessKeyKey }}
- name: RECORDING_API_HOST
value: {{ .Values.env.recording.apiHost | quote }}
- name: RECORDING_BUCKET
value: {{ .Values.env.recording.bucket | quote }}
- name: RECORDING_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.recording.name }}
key: {{ .Values.secrets.recording.secretKey }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts

View File

@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "call-realtime-app.fullname" . }}
labels:
{{- include "call-realtime-app.labels" . | nindent 4 }}
spec:
type: {{ .Values.service.type }}
ports:
{{- range .Values.service.ports }}
- name: {{ .name }}
port: {{ .port }}
targetPort: {{ .targetPort }}
protocol: TCP
{{- end }}
selector:
{{- include "call-realtime-app.selectorLabels" . | nindent 4 }}

View File

@ -0,0 +1,66 @@
# Image Configuration
image:
repository: docker.ii-p001.local/call-realtime-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
# Replica Configuration
replicaCount: 1
# Service Configuration
service:
type: ClusterIP
ports:
- name: main
port: 5096
targetPort: 5005
- name: metrics
port: 9090
targetPort: 9090
# Environment Configuration
env:
cassandra:
contactPoint: cassandra.cassandra.svc.cluster.local
datacenter: datacenter1
kafka:
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
redis:
host: redis-master.redis.svc.cluster.local
port: "6379"
recording:
apiHost: https://store.stage.co-work.local:9000
bucket: livekit
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
# Secret References
secrets:
cassandra:
name: cassandra
usernameKey: username
passwordKey: cassandra-password
kafka:
name: kafka-password
usernameKey: username
passwordKey: client-passwords
livekit:
name: livekit-secret
apiKeyKey: api-key
secretKey: secret
recording:
name: recording-secret
accessKeyKey: access-key
secretKey: secret
# Kompose Metadata
podAnnotations:
kompose.cmd: kompose convert -f app/call-realtime-app.yml -o k8s/call-realtime-app-k8s
kompose.version: 1.33.0 (HEAD)
podLabels:
io.kompose.network/app-default: "true"
io.kompose.service: call-realtime-app
# Chart Metadata
nameOverride: ""
fullnameOverride: call-realtime-app

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,24 @@
apiVersion: v2
name: chat-app
description: A Helm chart for Kubernetes
# A chart can be either an 'application' or a 'library' chart.
#
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
#
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.1.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.16.0"

View File

@ -0,0 +1,27 @@
{{/*
Return the name of the chart
*/}}
{{- define "chat-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "chat-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Common labels
*/}}
{{- define "chat-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "chat-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{- define "chat-app.quote" -}}
{{- . | quote }}
{{- end }}

View File

@ -0,0 +1,105 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "chat-app.fullname" . }}
labels:
{{- include "chat-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "chat-app.name" . }}
template:
metadata:
labels:
app: {{ include "chat-app.name" . }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 9090
hostPort: 8085
- containerPort: 5005
hostPort: 5085
env:
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: DEEPLINK_HOST
value: {{ .Values.env.DEEPLINK_HOST }}
- name: DEEPLINK_PORT
value: {{ include "chat-app.quote" .Values.env.DEEPLINK_PORT }}
- name: GEM_CALL_HOST
value: {{ .Values.env.GEM_CALL_HOST }}
- name: GEM_CALL_PORT
value: {{ include "chat-app.quote" .Values.env.GEM_CALL_PORT }}
- name: MESSAGE_HOST
value: {{ .Values.env.MESSAGE_HOST }}
- name: MESSAGE_PORT
value: {{ .Values.env.MESSAGE_PORT | quote }}
- name: SEARCH_HOST
value: {{ .Values.env.SEARCH_HOST }}
- name: SEARCH_PORT
value: {{ include "chat-app.quote" .Values.env.SEARCH_PORT }}
- name: USER_HOST
value: {{ .Values.env.USER_HOST }}
- name: USER_PORT
value: {{ include "chat-app.quote" .Values.env.USER_PORT }}
- name: KEYCLOAK_URL
value: {{ .Values.env.KEYCLOAK_URL }}
- name: LIVEKIT_API_KEY
valueFrom:
secretKeyRef:
name: livekit-secret
key: api-key
- name: LIVEKIT_SECRET
valueFrom:
secretKeyRef:
name: livekit-secret
key: secret
- name: RECORDING_ACCESS_KEY
valueFrom:
secretKeyRef:
name: recording-secret
key: access-key
- name: RECORDING_SECRET
valueFrom:
secretKeyRef:
name: recording-secret
key: secret
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
restartPolicy: Always

View File

@ -0,0 +1,16 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "chat-app.fullname" . }}
labels:
{{- include "chat-app.labels" . | nindent 4 }}
spec:
selector:
app: {{ include "chat-app.name" . }}
ports:
- name: http
port: 9090
targetPort: 9090
- name: debug
port: 5085
targetPort: 5005

View File

@ -0,0 +1,24 @@
replicaCount: 1
image:
repository: docker.ii-p001.local/chat-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
env:
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
CASSANDRA_DATACENTER: datacenter1
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
REDIS_HOST: redis-master.redis.svc.cluster.local
REDIS_PORT: "6379"
DEEPLINK_HOST: deeplink-app
DEEPLINK_PORT: "9090"
GEM_CALL_HOST: gem-call-app
GEM_CALL_PORT: "9090"
MESSAGE_HOST: message-app
MESSAGE_PORT: "9090"
SEARCH_HOST: search-app
SEARCH_PORT: "9090"
USER_HOST: user-app
USER_PORT: "9090"
KEYCLOAK_URL: https://iam.stage.co-work.local/realms/co-work

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: chat-event-handler-app
description: A Helm chart for Kubernetes
type: application
version: 0.1.0
appVersion: "1.16.0"

View File

@ -0,0 +1,27 @@
{{/*
Return the name of the chart
*/}}
{{- define "chat-event-handler-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Create a default fully qualified app name.
*/}}
{{- define "chat-event-handler-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/*
Common labels
*/}}
{{- define "chat-event-handler-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "chat-event-handler-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{- define "chat-event-handler-app.quote" -}}
{{- . | quote }}
{{- end }}

View File

@ -0,0 +1,83 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "chat-event-handler-app.fullname" . }}
labels:
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "chat-event-handler-app.name" . }}
template:
metadata:
labels:
app: {{ include "chat-event-handler-app.name" . }}
spec:
volumes:
- name: ca-cert
configMap:
name: auth-app-ca-cert
items:
- key: RootCA_{{ .Values.global.cert_alias }}.crt
path: RootCA_{{ .Values.global.cert_alias }}.crt
- name: cacerts-volume
emptyDir: {}
initContainers:
- name: import-ca
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
env:
- name: CERT_ALIAS
value: {{ .Values.global.cert_alias | quote }}
volumeMounts:
- name: ca-cert
mountPath: /app/resources
- name: cacerts-volume
mountPath: /tmp/cacerts
command:
- sh
- -c
- |
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
keytool -import -trustcacerts -storepass changeit -noprompt \
-alias gemcert \
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
-keystore /tmp/cacerts/cacerts
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- containerPort: 5005
hostPort: 5086
env:
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: DEEPLINK_HOST
value: {{ .Values.env.DEEPLINK_HOST }}
- name: DEEPLINK_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.DEEPLINK_PORT }}
- name: GEM_CALL_HOST
value: {{ .Values.env.GEM_CALL_HOST }}
- name: GEM_CALL_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.GEM_CALL_PORT }}
- name: MESSAGE_HOST
value: {{ .Values.env.MESSAGE_HOST }}
- name: MESSAGE_PORT
value: {{ .Values.env.MESSAGE_PORT | quote }}
- name: SEARCH_HOST
value: {{ .Values.env.SEARCH_HOST }}
- name: SEARCH_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.SEARCH_PORT }}
- name: USER_HOST
value: {{ .Values.env.USER_HOST }}
- name: USER_PORT
value: {{ include "chat-event-handler-app.quote" .Values.env.USER_PORT }}
- name: KEYCLOAK_URL
value: {{ .Values.env.KEYCLOAK_URL }}
volumeMounts:
- name: cacerts-volume
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
subPath: cacerts
restartPolicy: Always

View File

@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "chat-event-handler-app.fullname" . }}
labels:
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
spec:
selector:
app: {{ include "chat-event-handler-app.name" . }}
ports:
- name: debug
port: 5086
targetPort: 5005

View File

@ -0,0 +1,23 @@
replicaCount: 1
image:
repository: docker.ii-p001.local/chat-event-handler-app
tag: 1.0.0-SNAPSHOT
pullPolicy: Always
env:
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
CASSANDRA_DATACENTER: datacenter1
MESSAGE_HOST: message-app
MESSAGE_PORT: "9090"
USER_HOST: user-app
USER_PORT: "9090"
SEARCH_HOST: search-app
SEARCH_PORT: "9090"
GEM_CALL_HOST: gem-call-app
GEM_CALL_PORT: "9090"
DEEPLINK_HOST: deeplink-app
DEEPLINK_PORT: "9090"
REDIS_HOST: redis-master.redis.svc.cluster.local
REDIS_PORT: "6379"
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"

View File

@ -0,0 +1,23 @@
# Patterns to ignore when building packages.
# This supports shell glob matching, relative path matching, and
# negation (prefixed with !). Only one pattern per line.
.DS_Store
# Common VCS dirs
.git/
.gitignore
.bzr/
.bzrignore
.hg/
.hgignore
.svn/
# Common backup files
*.swp
*.bak
*.tmp
*.orig
*~
# Various IDEs
.project
.idea/
*.tmproj
.vscode/

View File

@ -0,0 +1,6 @@
apiVersion: v2
name: deeplink-app
description: A Helm chart for Kubernetes
type: application
version: 0.1.0
appVersion: "1.16.0"

View File

@ -0,0 +1,17 @@
{{/* Chart name */}}
{{- define "deeplink-app.name" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{- define "deeplink-app.fullname" -}}
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
{{- end }}
{{/* Common labels */}}
{{- define "deeplink-app.labels" -}}
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
app.kubernetes.io/name: {{ include "deeplink-app.name" . }}
app.kubernetes.io/instance: {{ .Chart.Name }}
app.kubernetes.io/version: {{ .Chart.AppVersion }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}

View File

@ -0,0 +1,72 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "deeplink-app.fullname" . }}
labels:
{{- include "deeplink-app.labels" . | nindent 4 }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
app: {{ include "deeplink-app.name" . }}
template:
metadata:
labels:
app: {{ include "deeplink-app.name" . }}
spec:
containers:
- name: {{ include "deeplink-app.name" . }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
ports:
- containerPort: {{ .Values.container.port }}
protocol: TCP
env:
{{- include "global.env.cassandra" . | nindent 12 }}
{{- include "global.env.kafka" . | nindent 12 }}
{{- include "global.env.redis" . | nindent 12 }}
- name: BRANCHIO_ACCESS
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-access
- name: BRANCHIO_APPID
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-appid
- name: BRANCHIO_DEFAULT_URL
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-default-url
- name: BRANCHIO_KEY
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-key
- name: BRANCHIO_SECRET
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-secret
- name: BRANCHIO_URL
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: branchio-url
- name: DEEPLINK_DOMAIN
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: deeplink-domain
- name: DEEPLINK_WEBDOMAIN
valueFrom:
secretKeyRef:
name: {{ .Values.secrets.branchio }}
key: deeplink-webdomain
- name: DEEPLINK_TENANT
value: {{ .Values.deeplink.tenant | quote }}
- name: KEYCLOAK_URL
value: {{ .Values.keycloak.url | quote }}
restartPolicy: Always

Some files were not shown because too many files have changed in this diff Show More