update to 2.1.1
This commit is contained in:
parent
c6fe82af17
commit
c8bdb426ca
@ -1,131 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: backend
|
|
||||||
description: Umbrella chart for all backend k8s applications
|
|
||||||
type: application
|
|
||||||
version: "0.1.0"
|
|
||||||
appVersion: "1.0.0"
|
|
||||||
|
|
||||||
dependencies:
|
|
||||||
- name: admin-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/admin-app-k8s
|
|
||||||
- name: android-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/android-app-k8s
|
|
||||||
- name: auth-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/auth-app-k8s
|
|
||||||
- name: auth-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/auth-event-handler-app-k8s
|
|
||||||
- name: bff-admin-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/bff-admin-app-k8s
|
|
||||||
- name: bff-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/bff-app-k8s
|
|
||||||
- name: bff-vcs-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/bff-vcs-app-k8s
|
|
||||||
- name: big-chat-splitter-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/big-chat-splitter-app-k8s
|
|
||||||
- name: call-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/call-app-k8s
|
|
||||||
- name: call-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/call-event-handler-app-k8s
|
|
||||||
- name: call-realtime-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/call-realtime-app-k8s
|
|
||||||
- name: chat-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/chat-app-k8s
|
|
||||||
- name: chat-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/chat-event-handler-app-k8s
|
|
||||||
- name: deeplink-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/deeplink-app-k8s
|
|
||||||
- name: gem-call-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/gem-call-app-k8s
|
|
||||||
- name: gem-call-events-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/gem-call-events-handler-app-k8s
|
|
||||||
- name: huawei-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/huawei-app-k8s
|
|
||||||
- name: ios-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/ios-app-k8s
|
|
||||||
- name: livekit-webhook-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/livekit-webhook-handler-app-k8s
|
|
||||||
- name: message-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/message-app-k8s
|
|
||||||
- name: message-call-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/message-call-event-handler-app-k8s
|
|
||||||
- name: message-chat-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/message-chat-event-handler-app-k8s
|
|
||||||
- name: message-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/message-event-handler-app-k8s
|
|
||||||
- name: message-link-preview-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/message-link-preview-handler-app-k8s
|
|
||||||
- name: message-user-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/message-user-event-handler-app-k8s
|
|
||||||
- name: notification-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/notification-app-k8s
|
|
||||||
- name: notification-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/notification-event-handler-app-k8s
|
|
||||||
- name: realtime-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/realtime-app-k8s
|
|
||||||
- name: regular-chat-splitter-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/regular-chat-splitter-app-k8s
|
|
||||||
- name: search-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/search-app-k8s
|
|
||||||
- name: search-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/search-event-handler-app-k8s
|
|
||||||
- name: sticker-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/sticker-app-k8s
|
|
||||||
- name: unregister-tokens-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/unregister-tokens-app-k8s
|
|
||||||
- name: upload-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/upload-app-k8s
|
|
||||||
- name: user-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/user-app-k8s
|
|
||||||
- name: voip-splitter-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/voip-splitter-app-k8s
|
|
||||||
- name: web-sender-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/web-sender-app-k8s
|
|
||||||
- name: workspace-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/workspace-app-k8s
|
|
||||||
- name: workspace-event-handler-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/workspace-event-handler-app-k8s
|
|
||||||
- name: devices-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/devices-app-k8s
|
|
||||||
- name: license-app
|
|
||||||
version: "0.1.0"
|
|
||||||
repository: file://charts/license-app-k8s
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: admin-app
|
|
||||||
description: Helm chart for Admin app
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
{{/* Common labels */}}
|
|
||||||
{{- define "admin-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Name */}}
|
|
||||||
{{- define "admin-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Fullname */}}
|
|
||||||
{{- define "admin-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "admin-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,62 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "admin-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "admin-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "admin-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
{{- include "admin-app.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: admin-app
|
|
||||||
ports:
|
|
||||||
- containerPort: 9090
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "admin-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "admin-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
selector:
|
|
||||||
{{- include "admin-app.selectorLabels" . | nindent 4 }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.service.targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
@ -1,10 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: admin-ui-app
|
|
||||||
description: Helm chart for Admin ui app
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
{{/* Common labels */}}
|
|
||||||
{{- define "admin-ui-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "admin-ui-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Name */}}
|
|
||||||
{{- define "admin-ui-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Fullname */}}
|
|
||||||
{{- define "admin-ui-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "admin-ui-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "admin-ui-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,22 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "admin-ui-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "admin-ui-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "admin-ui-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
{{- include "admin-ui-app.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: admin-ui-app
|
|
||||||
ports:
|
|
||||||
- containerPort: 9090
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}admin-panel-cowork:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "admin-ui-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "admin-ui-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
selector:
|
|
||||||
{{- include "admin-ui-app.selectorLabels" . | nindent 4 }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.service.targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
@ -1,11 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: preprod
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
service:
|
|
||||||
name: admin-ui-app
|
|
||||||
type: ClusterIP
|
|
||||||
port: 9090
|
|
||||||
targetPort: 80
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: android-app
|
|
||||||
description: Helm chart for Android Sender Application
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
{{/* Common labels */}}
|
|
||||||
{{- define "android-sender-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Name */}}
|
|
||||||
{{- define "android-sender-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Fullname */}}
|
|
||||||
{{- define "android-sender-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "android-sender-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,64 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "android-sender-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "android-sender-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "android-sender-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
{{- include "android-sender-app.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}android-sender-app:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: android-sender
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}android-sender-app:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
- name: ANDROID_FIREBASE_CONFIG
|
|
||||||
value: {{ .Values.env.android_firebase_config }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,9 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
env:
|
|
||||||
android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json"
|
|
||||||
secrets:
|
|
||||||
firebaseSecret: android-firebase-config
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: auth-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,53 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "auth-app-k8s.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "auth-app-k8s.fullname" -}}
|
|
||||||
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "auth-app-k8s.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "auth-app-k8s.labels" -}}
|
|
||||||
helm.sh/chart: {{ include "auth-app-k8s.chart" . }}
|
|
||||||
{{ include "auth-app-k8s.selectorLabels" . }}
|
|
||||||
{{- if .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
{{- end }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Selector labels
|
|
||||||
*/}}
|
|
||||||
{{- define "auth-app-k8s.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "auth-app-k8s.serviceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccount.create }}
|
|
||||||
{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }}
|
|
||||||
{{- else }}
|
|
||||||
{{- default "default" .Values.serviceAccount.name }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,88 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "auth-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
|
||||||
io.kompose.service: auth-app
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "auth-app-k8s.selectorLabels" . | nindent 6 }}
|
|
||||||
io.kompose.service: auth-app
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
|
||||||
labels:
|
|
||||||
{{- include "auth-app-k8s.selectorLabels" . | nindent 8 }}
|
|
||||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
{{- with .Values.imagePullSecrets }}
|
|
||||||
imagePullSecrets:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: {{ include "auth-app-k8s.fullname" . }}-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: auth-app
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: {{ .Values.service.targetPort }}
|
|
||||||
{{- if .Values.service.hostPort }}
|
|
||||||
hostPort: {{ .Values.service.hostPort }}
|
|
||||||
{{- end }}
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
{{- include "global.env.auth" . | nindent 12 }}
|
|
||||||
- name: ADMIN_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.adminPassword.name }}
|
|
||||||
key: {{ .Values.secrets.adminPassword.key }}
|
|
||||||
- name: CLIENT_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.clientSecret.name }}
|
|
||||||
key: {{ .Values.secrets.clientSecret.key }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
resources:
|
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "auth-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.service.targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
selector:
|
|
||||||
{{- include "auth-app-k8s.selectorLabels" . | nindent 4 }}
|
|
||||||
io.kompose.service: auth-app
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Pod
|
|
||||||
metadata:
|
|
||||||
name: "{{ include "auth-app-k8s.fullname" . }}-test-connection"
|
|
||||||
labels:
|
|
||||||
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": test
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: wget
|
|
||||||
image: busybox
|
|
||||||
command: ['wget']
|
|
||||||
args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}']
|
|
||||||
restartPolicy: Never
|
|
||||||
@ -1,40 +0,0 @@
|
|||||||
|
|
||||||
fullnameOverride: "auth-app"
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
hostPort: null
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
adminPassword:
|
|
||||||
name: auth-secrets
|
|
||||||
key: admin-password
|
|
||||||
clientSecret:
|
|
||||||
name: auth-secrets
|
|
||||||
key: client-secret
|
|
||||||
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
memory: 512Mi
|
|
||||||
requests:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 256Mi
|
|
||||||
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: auth-app
|
|
||||||
|
|
||||||
autoscaling:
|
|
||||||
enabled: false
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: auth-event-handler-app
|
|
||||||
description: Authentication Event Handler
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,19 +0,0 @@
|
|||||||
{{/* Common Name Definitions */}}
|
|
||||||
{{- define "auth-event-handler-app-k8s.fullname" -}}
|
|
||||||
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Standard labels */}}
|
|
||||||
{{- define "auth-event-handler-app-k8s.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
|
||||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "auth-event-handler-app-k8s.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,122 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
{{- if not .Values.autoscaling.enabled }}
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
{{- with .Values.podAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
labels:
|
|
||||||
{{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }}
|
|
||||||
{{- with .Values.podLabels }}
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
{{- if .Values.serviceAccount.create }}
|
|
||||||
serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.imagePullSecrets }}
|
|
||||||
imagePullSecrets:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
securityContext:
|
|
||||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
{{- with .Values.volumes }}
|
|
||||||
{{ toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
securityContext:
|
|
||||||
{{- toYaml .Values.securityContext | nindent 12 }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: {{ .Values.service.port }}
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.auth" . | nindent 12 }}
|
|
||||||
- name: ADMIN_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.adminPassword.name }}
|
|
||||||
key: {{ .Values.secrets.adminPassword.key }}
|
|
||||||
- name: CLIENT_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.clientSecret.name }}
|
|
||||||
key: {{ .Values.secrets.clientSecret.key }}
|
|
||||||
livenessProbe:
|
|
||||||
{{- toYaml .Values.livenessProbe | nindent 12 }}
|
|
||||||
readinessProbe:
|
|
||||||
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
|
||||||
resources:
|
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
|
||||||
volumeMounts:
|
|
||||||
{{- with .Values.volumeMounts }}
|
|
||||||
{{- toYaml . | nindent 12 }}
|
|
||||||
{{- end }}
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
{{- with .Values.nodeSelector }}
|
|
||||||
nodeSelector:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.affinity }}
|
|
||||||
affinity:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,12 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.service.targetPort }}
|
|
||||||
selector:
|
|
||||||
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }}
|
|
||||||
@ -1,48 +0,0 @@
|
|||||||
fullnameOverride: "auth-event-handler-app"
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
replicaCount: 1
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
port: 8094
|
|
||||||
targetPort: 9090
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
kafka:
|
|
||||||
name: kafka-password
|
|
||||||
passwordKey: client-passwords
|
|
||||||
username: admin
|
|
||||||
adminPassword:
|
|
||||||
name: auth-secrets
|
|
||||||
key: admin-password
|
|
||||||
clientSecret:
|
|
||||||
name: auth-secrets
|
|
||||||
key: client-secret
|
|
||||||
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
memory: 512Mi
|
|
||||||
requests:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 256Mi
|
|
||||||
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: auth-event-handler-app
|
|
||||||
|
|
||||||
|
|
||||||
podSecurityContext: {}
|
|
||||||
securityContext: {}
|
|
||||||
|
|
||||||
autoscaling:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
serviceAccount:
|
|
||||||
create: false
|
|
||||||
name: ""
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: bff-admin-app
|
|
||||||
description: Helm chart for bff-admin-app
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
{{/* Common labels */}}
|
|
||||||
{{- define "bff-admin-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Name */}}
|
|
||||||
{{- define "bff-admin-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Fullname */}}
|
|
||||||
{{- define "bff-admin-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "bff-admin-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,60 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-admin-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "bff-admin-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
{{- include "bff-admin-app.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: bff-admin-app
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,38 +0,0 @@
|
|||||||
{{- if .Values.ingress.enabled -}}
|
|
||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: Ingress
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.ingress.name }}
|
|
||||||
namespace: {{ .Release.Namespace | default "default" }}
|
|
||||||
{{- with .Values.ingress.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
ingressClassName: {{ .Values.ingress.className }}
|
|
||||||
{{- if .Values.ingress.tls }}
|
|
||||||
tls:
|
|
||||||
{{- range .Values.ingress.tls }}
|
|
||||||
- hosts:
|
|
||||||
{{- range .hosts }}
|
|
||||||
- {{ . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
secretName: {{ .secretName | quote }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
rules:
|
|
||||||
{{- range .Values.ingress.hosts }}
|
|
||||||
- host: {{ .host | quote }}
|
|
||||||
http:
|
|
||||||
paths:
|
|
||||||
{{- range .paths }}
|
|
||||||
- path: {{ .path }}
|
|
||||||
pathType: {{ .pathType }}
|
|
||||||
backend:
|
|
||||||
service:
|
|
||||||
name: {{ $.Values.env.app_name }}
|
|
||||||
port:
|
|
||||||
number: {{ $.Values.service.httpPort }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-admin-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
selector:
|
|
||||||
{{- include "bff-admin-app.selectorLabels" . | nindent 4 }}
|
|
||||||
ports:
|
|
||||||
{{- range .Values.service.ports }}
|
|
||||||
- name: {{ .name }}
|
|
||||||
port: {{ .port }}
|
|
||||||
targetPort: {{ .targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
@ -1,37 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
env:
|
|
||||||
app_name: bff-admin-app
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
httpPort: 8100
|
|
||||||
grpcPort: 8101
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 8100
|
|
||||||
targetPort: 8080
|
|
||||||
- name: grpc
|
|
||||||
port: 8101
|
|
||||||
targetPort: 9090
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
enabled: true
|
|
||||||
className: nginx
|
|
||||||
name: bff-admin-ingress
|
|
||||||
annotations:
|
|
||||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
|
||||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
|
||||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
|
||||||
hosts:
|
|
||||||
- host: adm-p003.cw.ngcloud.ru
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
tls:
|
|
||||||
- hosts:
|
|
||||||
- adm-p003.cw.ngcloud.ru
|
|
||||||
secretName: co-work-secret
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: bff-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,19 +0,0 @@
|
|||||||
{{/* Common Name Definitions */}}
|
|
||||||
{{- define "bff-app-k8s.fullname" -}}
|
|
||||||
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Standard labels */}}
|
|
||||||
{{- define "bff-app-k8s.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
|
||||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "bff-app-k8s.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ .Values.fullnameOverride }}
|
|
||||||
app.kubernetes.io/instance: {{ .Values.fullnameOverride }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,100 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 8 }}
|
|
||||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: bff-app
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: {{ .Values.service.targetPort }}
|
|
||||||
{{- if .Values.service.hostPort }}
|
|
||||||
hostPort: {{ .Values.service.hostPort }}
|
|
||||||
{{- end }}
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: GRPC_CLIENT_AUTH_URL
|
|
||||||
value: {{ .Values.env.services.auth | quote }}
|
|
||||||
- name: GRPC_CLIENT_CHAT_URL
|
|
||||||
value: {{ .Values.env.services.chat | quote }}
|
|
||||||
- name: GRPC_CLIENT_CONFIG_URL
|
|
||||||
value: {{ .Values.env.services.user | quote }}
|
|
||||||
- name: GRPC_CLIENT_DEEPLINK_URL
|
|
||||||
value: {{ .Values.env.services.deeplink | quote }}
|
|
||||||
- name: GRPC_CLIENT_GEM_CALL_URL
|
|
||||||
value: {{ .Values.env.services.gemCall | quote }}
|
|
||||||
- name: GRPC_CLIENT_MESSAGE_URL
|
|
||||||
value: {{ .Values.env.services.message | quote }}
|
|
||||||
- name: GRPC_CLIENT_NOTIFICATIONS_URL
|
|
||||||
value: {{ .Values.env.services.notification | quote }}
|
|
||||||
- name: GRPC_CLIENT_REACTION_URL
|
|
||||||
value: {{ .Values.env.services.message | quote }}
|
|
||||||
- name: GRPC_CLIENT_REALTIME_URL
|
|
||||||
value: {{ .Values.env.services.realtime | quote }}
|
|
||||||
- name: GRPC_CLIENT_SEARCH_URL
|
|
||||||
value: {{ .Values.env.services.search | quote }}
|
|
||||||
- name: GRPC_CLIENT_STICKER_URL
|
|
||||||
value: {{ .Values.env.services.sticker | quote }}
|
|
||||||
- name: GRPC_CLIENT_UPLOAD_URL
|
|
||||||
value: {{ .Values.env.services.upload | quote }}
|
|
||||||
- name: GRPC_CLIENT_USER_URL
|
|
||||||
value: {{ .Values.env.services.user | quote }}
|
|
||||||
- name: GRPC_CLIENT_WORKSPACE_URL
|
|
||||||
value: {{ .Values.env.services.workspace | quote }}
|
|
||||||
- name: GRPC_CLIENT_DEVICE_URL
|
|
||||||
value: {{ .Values.env.services.device | quote }}
|
|
||||||
resources:
|
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,28 +0,0 @@
|
|||||||
{{- if .Values.ingress.enabled -}}
|
|
||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: Ingress
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.ingress.name }}
|
|
||||||
namespace: {{ .Release.Namespace | default "default" }}
|
|
||||||
{{- with .Values.ingress.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
ingressClassName: {{ .Values.ingress.className }}
|
|
||||||
tls:
|
|
||||||
- hosts:
|
|
||||||
- {{ .Values.ingress.host | quote }}
|
|
||||||
secretName: {{ .Values.ingress.tlsSecret | quote }}
|
|
||||||
rules:
|
|
||||||
- host: {{ .Values.ingress.host | quote }}
|
|
||||||
http:
|
|
||||||
paths:
|
|
||||||
- path: {{ .Values.ingress.path }}
|
|
||||||
pathType: {{ .Values.ingress.pathType }}
|
|
||||||
backend:
|
|
||||||
service:
|
|
||||||
name: {{ .Values.service.name }}
|
|
||||||
port:
|
|
||||||
number: {{ .Values.service.port }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,14 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.service.targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
selector:
|
|
||||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
|
|
||||||
@ -1,58 +0,0 @@
|
|||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
port: 8081
|
|
||||||
targetPort: 8080
|
|
||||||
nodePort: 31754
|
|
||||||
name: bff-app # Added service name
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
enabled: true
|
|
||||||
className: nginx
|
|
||||||
name: bff-app-ingress
|
|
||||||
host: api-p003.cw.ngcloud.ru
|
|
||||||
annotations:
|
|
||||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
|
||||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
|
||||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
|
||||||
path: /
|
|
||||||
pathType: Prefix
|
|
||||||
tlsSecret: co-work-secret
|
|
||||||
|
|
||||||
env:
|
|
||||||
services:
|
|
||||||
auth: http://auth-app:9090
|
|
||||||
chat: http://chat-app:9090
|
|
||||||
user: http://user-app:9090
|
|
||||||
deeplink: http://deeplink-app:9090
|
|
||||||
gemCall: http://gem-call-app:9090
|
|
||||||
message: http://message-app:9090
|
|
||||||
notification: http://notification-app:9090
|
|
||||||
realtime: http://realtime-app:9090
|
|
||||||
search: http://search-app:9090
|
|
||||||
sticker: http://sticker-app:9090
|
|
||||||
upload: http://upload-app:9090
|
|
||||||
workspace: http://workspace-app:9090
|
|
||||||
device: http://devices-app:9090
|
|
||||||
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
memory: 1Gi
|
|
||||||
requests:
|
|
||||||
cpu: 200m
|
|
||||||
memory: 512Mi
|
|
||||||
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/bff-app.yml -o k8s/bff-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: bff-app
|
|
||||||
|
|
||||||
fullnameOverride: "bff-app"
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: bff-vcs-app
|
|
||||||
description: Helm chart for bff-vcs-app
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
{{/* Common labels */}}
|
|
||||||
{{- define "bff-vcs-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Name */}}
|
|
||||||
{{- define "bff-vcs-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Fullname */}}
|
|
||||||
{{- define "bff-vcs-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "bff-vcs-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,63 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-vcs-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-vcs-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "bff-vcs-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
{{- include "bff-vcs-app.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: bff-vcs-app
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
- name: GRPC_CLIENT_CALL_URL
|
|
||||||
value: "{{ .Values.env.grpc_client_call_url }}"
|
|
||||||
- name: GRPC_CLIENT_CALL_REALTIME_URL
|
|
||||||
value: "{{ .Values.env.grpc_client_call_realtime_url }}"
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,28 +0,0 @@
|
|||||||
{{- if .Values.ingress.enabled }}
|
|
||||||
apiVersion: networking.k8s.io/v1
|
|
||||||
kind: Ingress
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-vcs-app.fullname" . }}-ingress
|
|
||||||
namespace: {{ .Release.Namespace }}
|
|
||||||
annotations:
|
|
||||||
{{- range $key, $value := .Values.ingress.annotations }}
|
|
||||||
{{ $key }}: {{ $value | quote }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
ingressClassName: {{ .Values.ingress.ingressClassName }}
|
|
||||||
tls:
|
|
||||||
- hosts:
|
|
||||||
- {{ .Values.ingress.host }}
|
|
||||||
secretName: {{ .Values.ingress.tlsSecretName }}
|
|
||||||
rules:
|
|
||||||
- host: {{ .Values.ingress.host }}
|
|
||||||
http:
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
backend:
|
|
||||||
service:
|
|
||||||
name: {{ include "bff-vcs-app.fullname" . }}
|
|
||||||
port:
|
|
||||||
number: {{ .Values.service.port }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,16 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "bff-vcs-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "bff-vcs-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
selector:
|
|
||||||
{{- include "bff-vcs-app.selectorLabels" . | nindent 4 }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.service.targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
env:
|
|
||||||
grpc_client_call_url: http://call-realtime-app:9090
|
|
||||||
grpc_client_call_realtime_url: http://call-realtime-app:9090
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
port: 8079
|
|
||||||
targetPort: 8080
|
|
||||||
|
|
||||||
ingress:
|
|
||||||
enabled: true
|
|
||||||
ingressClassName: nginx
|
|
||||||
host: vcs-p003.cw.ngcloud.ru
|
|
||||||
tlsSecretName: co-work-secret
|
|
||||||
annotations:
|
|
||||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
|
||||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
|
||||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: big-chat-splitter-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,18 +0,0 @@
|
|||||||
{{/* Common Name Definitions */}}
|
|
||||||
{{- define "big-chat-splitter-app-k8s.fullname" -}}
|
|
||||||
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Standard labels */}}
|
|
||||||
{{- define "big-chat-splitter-app-k8s.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
|
||||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "big-chat-splitter-app-k8s.selectorLabels" -}}
|
|
||||||
io.kompose.service: big-chat-splitter-app
|
|
||||||
{{- end }}
|
|
||||||
@ -1,70 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "big-chat-splitter-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "big-chat-splitter-app-k8s.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
|
||||||
labels:
|
|
||||||
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: big-chat-splitter-app
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
- name: CHAT_SERVICE_HOST
|
|
||||||
value: {{ .Values.env.services.chat.host | quote }}
|
|
||||||
- name: CHAT_SERVICE_PORT
|
|
||||||
value: {{ .Values.env.services.chat.port | quote }}
|
|
||||||
- name: USER_SERVICE_HOST
|
|
||||||
value: {{ .Values.env.services.user.host | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,30 +0,0 @@
|
|||||||
fullnameOverride: "big-chat-splitter-app"
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
replicaCount: 1
|
|
||||||
env:
|
|
||||||
services:
|
|
||||||
chat:
|
|
||||||
host: chat-app
|
|
||||||
port: 9090
|
|
||||||
user:
|
|
||||||
host: user-app
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
memory: 1Gi
|
|
||||||
requests:
|
|
||||||
cpu: 500m
|
|
||||||
memory: 512Mi
|
|
||||||
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/big-chat-splitter-app.yml -o k8s/big-chat-splitter-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: big-chat-splitter-app
|
|
||||||
|
|
||||||
fullnameOverride: "big-chat-splitter-app"
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: call-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,18 +0,0 @@
|
|||||||
{{/* Common Name Definitions */}}
|
|
||||||
{{- define "call-app-k8s.fullname" -}}
|
|
||||||
{{- default .Chart.Name .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Standard labels */}}
|
|
||||||
{{- define "call-app-k8s.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
|
||||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Selector labels */}}
|
|
||||||
{{- define "call-app-k8s.selectorLabels" -}}
|
|
||||||
io.kompose.service: call-app
|
|
||||||
{{- end }}
|
|
||||||
@ -1,92 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "call-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-app-k8s.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "call-app-k8s.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-app-k8s.selectorLabels" . | nindent 8 }}
|
|
||||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: call-app
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: 5005
|
|
||||||
protocol: TCP
|
|
||||||
- containerPort: 9090
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
{{- include "global.env.call" . | nindent 12 }}
|
|
||||||
- name: LIVEKIT_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.livekit.name }}
|
|
||||||
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
|
||||||
- name: LIVEKIT_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.livekit.name }}
|
|
||||||
key: {{ .Values.secrets.livekit.secretKey }}
|
|
||||||
- name: RECORDING_ACCESS_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.recording.name }}
|
|
||||||
key: {{ .Values.secrets.recording.accessKeyKey }}
|
|
||||||
- name: RECORDING_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.recording.name }}
|
|
||||||
key: {{ .Values.secrets.recording.secretKeyKey }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "call-app-k8s.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-app-k8s.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
{{- range .Values.service.ports }}
|
|
||||||
- name: {{ .name }}
|
|
||||||
port: {{ .port }}
|
|
||||||
targetPort: {{ .targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
{{- include "call-app-k8s.selectorLabels" . | nindent 4 }}
|
|
||||||
@ -1,35 +0,0 @@
|
|||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
|
||||||
- name: main
|
|
||||||
port: 5005
|
|
||||||
targetPort: 5005
|
|
||||||
- name: metrics
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
livekit:
|
|
||||||
name: livekit-secret
|
|
||||||
apiKeyKey: api-key
|
|
||||||
secretKey: secret
|
|
||||||
recording:
|
|
||||||
name: recording-secret
|
|
||||||
accessKeyKey: access-key
|
|
||||||
secretKeyKey: secret-key
|
|
||||||
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/call-app.yml -o k8s/call-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: call-app
|
|
||||||
|
|
||||||
fullnameOverride: "call-app"
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: call-event-handler-app
|
|
||||||
description: Call Event Handler Application
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.0.0-SNAPSHOT"
|
|
||||||
@ -1,46 +0,0 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "call-event-handler-app.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
*/}}
|
|
||||||
{{- define "call-event-handler-app.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride -}}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
||||||
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "call-event-handler-app.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "call-event-handler-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ include "call-event-handler-app.chart" . }}
|
|
||||||
{{ include "call-event-handler-app.selectorLabels" . }}
|
|
||||||
{{- if .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
{{- end }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Selector labels
|
|
||||||
*/}}
|
|
||||||
{{- define "call-event-handler-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "call-event-handler-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end -}}
|
|
||||||
@ -1,84 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "call-event-handler-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-event-handler-app.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "call-event-handler-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-event-handler-app.selectorLabels" . | nindent 8 }}
|
|
||||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: 5005
|
|
||||||
protocol: TCP
|
|
||||||
- containerPort: 9090
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
{{- include "global.env.callevent" . | nindent 12 }}
|
|
||||||
- name: LIVEKIT_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.livekit.name }}
|
|
||||||
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
|
||||||
- name: LIVEKIT_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.livekit.name }}
|
|
||||||
key: {{ .Values.secrets.livekit.secretKey }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "call-event-handler-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-event-handler-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
{{- range .Values.service.ports }}
|
|
||||||
- name: {{ .name }}
|
|
||||||
port: {{ .port }}
|
|
||||||
targetPort: {{ .targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
{{- include "call-event-handler-app.selectorLabels" . | nindent 4 }}
|
|
||||||
@ -1,35 +0,0 @@
|
|||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
|
||||||
- name: main
|
|
||||||
port: 5005
|
|
||||||
targetPort: 5005
|
|
||||||
- name: metrics
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
|
|
||||||
env:
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
livekit:
|
|
||||||
name: livekit-secret
|
|
||||||
apiKeyKey: api-key
|
|
||||||
secretKey: secret
|
|
||||||
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/call-event-handler-app.yml -o k8s/call-event-handler-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: call-event-handler-app
|
|
||||||
|
|
||||||
|
|
||||||
nameOverride: ""
|
|
||||||
fullnameOverride: ""
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: call-realtime-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,39 +0,0 @@
|
|||||||
{{/* vim: set filetype=mustache: */}}
|
|
||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "call-realtime-app.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
*/}}
|
|
||||||
{{- define "call-realtime-app.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride -}}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
||||||
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "call-realtime-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ include "call-realtime-app.name" . }}
|
|
||||||
{{ include "call-realtime-app.selectorLabels" . }}
|
|
||||||
{{- if .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
{{- end }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Selector labels
|
|
||||||
*/}}
|
|
||||||
{{- define "call-realtime-app.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "call-realtime-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
{{- end -}}
|
|
||||||
@ -1,94 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "call-realtime-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-realtime-app.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "call-realtime-app.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-realtime-app.selectorLabels" . | nindent 8 }}
|
|
||||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: 5005
|
|
||||||
protocol: TCP
|
|
||||||
- containerPort: 9090
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
{{- include "global.env.callevent" . | nindent 12 }}
|
|
||||||
- name: LIVEKIT_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.livekit.name }}
|
|
||||||
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
|
||||||
- name: LIVEKIT_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.livekit.name }}
|
|
||||||
key: {{ .Values.secrets.livekit.secretKey }}
|
|
||||||
- name: RECORDING_ACCESS_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.recording.name }}
|
|
||||||
key: {{ .Values.secrets.recording.accessKeyKey }}
|
|
||||||
- name: RECORDING_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.recording.name }}
|
|
||||||
key: {{ .Values.secrets.recording.secretKey }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "call-realtime-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "call-realtime-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
{{- range .Values.service.ports }}
|
|
||||||
- name: {{ .name }}
|
|
||||||
port: {{ .port }}
|
|
||||||
targetPort: {{ .targetPort }}
|
|
||||||
protocol: TCP
|
|
||||||
{{- end }}
|
|
||||||
selector:
|
|
||||||
{{- include "call-realtime-app.selectorLabels" . | nindent 4 }}
|
|
||||||
@ -1,45 +0,0 @@
|
|||||||
# Image Configuration
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
# Replica Configuration
|
|
||||||
replicaCount: 1
|
|
||||||
|
|
||||||
# Service Configuration
|
|
||||||
service:
|
|
||||||
type: ClusterIP
|
|
||||||
ports:
|
|
||||||
- name: main
|
|
||||||
port: 5096
|
|
||||||
targetPort: 5005
|
|
||||||
- name: metrics
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
|
|
||||||
# Environment Configuration
|
|
||||||
|
|
||||||
|
|
||||||
# Secret References
|
|
||||||
secrets:
|
|
||||||
livekit:
|
|
||||||
name: livekit-secret
|
|
||||||
apiKeyKey: api-key
|
|
||||||
secretKey: secret
|
|
||||||
recording:
|
|
||||||
name: recording-secret
|
|
||||||
accessKeyKey: access-key
|
|
||||||
secretKey: secret-key
|
|
||||||
|
|
||||||
# Kompose Metadata
|
|
||||||
podAnnotations:
|
|
||||||
kompose.cmd: kompose convert -f app/call-realtime-app.yml -o k8s/call-realtime-app-k8s
|
|
||||||
kompose.version: 1.33.0 (HEAD)
|
|
||||||
|
|
||||||
podLabels:
|
|
||||||
io.kompose.network/app-default: "true"
|
|
||||||
io.kompose.service: call-realtime-app
|
|
||||||
|
|
||||||
# Chart Metadata
|
|
||||||
nameOverride: ""
|
|
||||||
fullnameOverride: call-realtime-app
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: chat-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,27 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Return the name of the chart
|
|
||||||
*/}}
|
|
||||||
{{- define "chat-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
*/}}
|
|
||||||
{{- define "chat-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "chat-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "chat-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
{{- define "chat-app.quote" -}}
|
|
||||||
{{- . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,109 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "chat-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "chat-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ include "chat-app.name" . }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: {{ include "chat-app.name" . }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: 9090
|
|
||||||
hostPort: 8085
|
|
||||||
- containerPort: 5005
|
|
||||||
hostPort: 5085
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
- name: DEEPLINK_HOST
|
|
||||||
value: {{ .Values.env.DEEPLINK_HOST }}
|
|
||||||
- name: DEEPLINK_PORT
|
|
||||||
value: {{ include "chat-app.quote" .Values.env.DEEPLINK_PORT }}
|
|
||||||
- name: GEM_CALL_HOST
|
|
||||||
value: {{ .Values.env.GEM_CALL_HOST }}
|
|
||||||
- name: GEM_CALL_PORT
|
|
||||||
value: {{ include "chat-app.quote" .Values.env.GEM_CALL_PORT }}
|
|
||||||
- name: MESSAGE_HOST
|
|
||||||
value: {{ .Values.env.MESSAGE_HOST }}
|
|
||||||
- name: MESSAGE_PORT
|
|
||||||
value: {{ .Values.env.MESSAGE_PORT | quote }}
|
|
||||||
- name: SEARCH_HOST
|
|
||||||
value: {{ .Values.env.SEARCH_HOST }}
|
|
||||||
- name: SEARCH_PORT
|
|
||||||
value: {{ include "chat-app.quote" .Values.env.SEARCH_PORT }}
|
|
||||||
- name: USER_HOST
|
|
||||||
value: {{ .Values.env.USER_HOST }}
|
|
||||||
- name: USER_PORT
|
|
||||||
value: {{ include "chat-app.quote" .Values.env.USER_PORT }}
|
|
||||||
- name: LIVEKIT_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: livekit-secret
|
|
||||||
key: api-key
|
|
||||||
- name: LIVEKIT_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: livekit-secret
|
|
||||||
key: secret
|
|
||||||
- name: RECORDING_ACCESS_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: recording-secret
|
|
||||||
key: access-key
|
|
||||||
- name: RECORDING_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: recording-secret
|
|
||||||
key: secret-key
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
restartPolicy: Always
|
|
||||||
@ -1,16 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "chat-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "chat-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: {{ include "chat-app.name" . }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
- name: debug
|
|
||||||
port: 5085
|
|
||||||
targetPort: 5005
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
env:
|
|
||||||
DEEPLINK_HOST: deeplink-app
|
|
||||||
DEEPLINK_PORT: "9090"
|
|
||||||
GEM_CALL_HOST: gem-call-app
|
|
||||||
GEM_CALL_PORT: "9090"
|
|
||||||
MESSAGE_HOST: message-app
|
|
||||||
MESSAGE_PORT: "9090"
|
|
||||||
SEARCH_HOST: search-app
|
|
||||||
SEARCH_PORT: "9090"
|
|
||||||
USER_HOST: user-app
|
|
||||||
USER_PORT: "9090"
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: chat-event-handler-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,27 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Return the name of the chart
|
|
||||||
*/}}
|
|
||||||
{{- define "chat-event-handler-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
*/}}
|
|
||||||
{{- define "chat-event-handler-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "chat-event-handler-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "chat-event-handler-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
{{- define "chat-event-handler-app.quote" -}}
|
|
||||||
{{- . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,87 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "chat-event-handler-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ include "chat-event-handler-app.name" . }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: {{ include "chat-event-handler-app.name" . }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: 5005
|
|
||||||
hostPort: 5086
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
- name: DEEPLINK_HOST
|
|
||||||
value: {{ .Values.env.DEEPLINK_HOST }}
|
|
||||||
- name: DEEPLINK_PORT
|
|
||||||
value: {{ include "chat-event-handler-app.quote" .Values.env.DEEPLINK_PORT }}
|
|
||||||
- name: GEM_CALL_HOST
|
|
||||||
value: {{ .Values.env.GEM_CALL_HOST }}
|
|
||||||
- name: GEM_CALL_PORT
|
|
||||||
value: {{ include "chat-event-handler-app.quote" .Values.env.GEM_CALL_PORT }}
|
|
||||||
- name: MESSAGE_HOST
|
|
||||||
value: {{ .Values.env.MESSAGE_HOST }}
|
|
||||||
- name: MESSAGE_PORT
|
|
||||||
value: {{ .Values.env.MESSAGE_PORT | quote }}
|
|
||||||
- name: SEARCH_HOST
|
|
||||||
value: {{ .Values.env.SEARCH_HOST }}
|
|
||||||
- name: SEARCH_PORT
|
|
||||||
value: {{ include "chat-event-handler-app.quote" .Values.env.SEARCH_PORT }}
|
|
||||||
- name: USER_HOST
|
|
||||||
value: {{ .Values.env.USER_HOST }}
|
|
||||||
- name: USER_PORT
|
|
||||||
value: {{ include "chat-event-handler-app.quote" .Values.env.USER_PORT }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
restartPolicy: Always
|
|
||||||
@ -1,13 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "chat-event-handler-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: {{ include "chat-event-handler-app.name" . }}
|
|
||||||
ports:
|
|
||||||
- name: debug
|
|
||||||
port: 5086
|
|
||||||
targetPort: 5005
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
env:
|
|
||||||
MESSAGE_HOST: message-app
|
|
||||||
MESSAGE_PORT: "9090"
|
|
||||||
USER_HOST: user-app
|
|
||||||
USER_PORT: "9090"
|
|
||||||
SEARCH_HOST: search-app
|
|
||||||
SEARCH_PORT: "9090"
|
|
||||||
GEM_CALL_HOST: gem-call-app
|
|
||||||
GEM_CALL_PORT: "9090"
|
|
||||||
DEEPLINK_HOST: deeplink-app
|
|
||||||
DEEPLINK_PORT: "9090"
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,6 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: deeplink-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
type: application
|
|
||||||
version: 0.1.0
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,17 +0,0 @@
|
|||||||
{{/* Chart name */}}
|
|
||||||
{{- define "deeplink-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "deeplink-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/* Common labels */}}
|
|
||||||
{{- define "deeplink-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "deeplink-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,101 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "deeplink-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "deeplink-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ include "deeplink-app.name" . }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: {{ include "deeplink-app.name" . }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ include "deeplink-app.name" . }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}{{ .Chart.Name }}:{{ .Values.image.tag }}"
|
|
||||||
ports:
|
|
||||||
- containerPort: {{ .Values.container.port }}
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.cassandra" . | nindent 12 }}
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.redis" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
- name: BRANCHIO_ACCESS
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: branchio-access
|
|
||||||
- name: BRANCHIO_APPID
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: branchio-appid
|
|
||||||
- name: BRANCHIO_DEFAULT_URL
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: branchio-default-url
|
|
||||||
- name: BRANCHIO_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: branchio-key
|
|
||||||
- name: BRANCHIO_SECRET
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: branchio-secret
|
|
||||||
- name: BRANCHIO_URL
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: branchio-url
|
|
||||||
- name: DEEPLINK_WEBDOMAIN
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .Values.secrets.branchio }}
|
|
||||||
key: deeplink-web-domain
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
restartPolicy: Always
|
|
||||||
@ -1,13 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "deeplink-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "deeplink-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: {{ include "deeplink-app.name" . }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: {{ .Values.service.port }}
|
|
||||||
targetPort: {{ .Values.container.port }}
|
|
||||||
@ -1,14 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
service:
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
container:
|
|
||||||
port: 9090
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
branchio: deeplink-secret
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
@ -1,24 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: devices-app
|
|
||||||
description: A Helm chart for Kubernetes
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: 0.1.0
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "1.16.0"
|
|
||||||
@ -1,27 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Return the name of the chart
|
|
||||||
*/}}
|
|
||||||
{{- define "devices-app.name" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
*/}}
|
|
||||||
{{- define "devices-app.fullname" -}}
|
|
||||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "devices-app.labels" -}}
|
|
||||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
|
||||||
app.kubernetes.io/name: {{ include "devices-app.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Chart.Name }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
{{- end }}
|
|
||||||
{{- define "devices-app.quote" -}}
|
|
||||||
{{- . | quote }}
|
|
||||||
{{- end }}
|
|
||||||
@ -1,77 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "devices-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "devices-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: {{ include "devices-app.name" . }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: {{ include "devices-app.name" . }}
|
|
||||||
spec:
|
|
||||||
volumes:
|
|
||||||
- name: ca-cert
|
|
||||||
configMap:
|
|
||||||
name: auth-app-ca-cert
|
|
||||||
items:
|
|
||||||
- key: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
path: RootCA_{{ .Values.global.cert_alias }}.crt
|
|
||||||
- name: cacerts-volume
|
|
||||||
emptyDir: {}
|
|
||||||
initContainers:
|
|
||||||
- name: import-ca
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}device-app:{{ .Values.image.tag }}"
|
|
||||||
env:
|
|
||||||
- name: CERT_ALIAS
|
|
||||||
value: {{ .Values.global.cert_alias | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: ca-cert
|
|
||||||
mountPath: /app/resources
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /tmp/cacerts
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts
|
|
||||||
if keytool -list -keystore /tmp/cacerts/cacerts -storepass changeit -alias gemcert > /dev/null 2>&1; then
|
|
||||||
echo "Certificate with alias gemcert already exists, skipping import"
|
|
||||||
else
|
|
||||||
echo "Importing certificate with alias gemcert"
|
|
||||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
|
||||||
-alias gemcert \
|
|
||||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
|
||||||
-keystore /tmp/cacerts/cacerts
|
|
||||||
fi
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.global.dockerRegistryPrefix }}device-app:{{ .Values.image.tag }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
ports:
|
|
||||||
- containerPort: 9090
|
|
||||||
name: grpc
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
{{- include "global.env.kafka" . | nindent 12 }}
|
|
||||||
{{- include "global.env.postgres" . | nindent 12 }}
|
|
||||||
{{- include "global.env.general" . | nindent 12 }}
|
|
||||||
- name: USER_HOST
|
|
||||||
value: {{ .Values.env.USER_HOST }}
|
|
||||||
- name: USER_PORT
|
|
||||||
value: {{ include "devices-app.quote" .Values.env.USER_PORT }}
|
|
||||||
- name: AUTH_HOST
|
|
||||||
value: {{ .Values.env.AUTH_HOST }}
|
|
||||||
- name: AUTH_PORT
|
|
||||||
value: {{ include "devices-app.quote" .Values.env.AUTH_PORT }}
|
|
||||||
- name: POSTGRES_URL
|
|
||||||
value: {{ .Values.global.infrastructure.postgres.device_url | quote }}
|
|
||||||
volumeMounts:
|
|
||||||
- name: cacerts-volume
|
|
||||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
|
||||||
subPath: cacerts
|
|
||||||
restartPolicy: Always
|
|
||||||
@ -1,13 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "devices-app.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "devices-app.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
selector:
|
|
||||||
app: {{ include "devices-app.name" . }}
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
@ -1,11 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
|
|
||||||
image:
|
|
||||||
tag: 1.0.0-SNAPSHOT
|
|
||||||
pullPolicy: Always
|
|
||||||
|
|
||||||
env:
|
|
||||||
USER_HOST: user-app
|
|
||||||
USER_PORT: 9090
|
|
||||||
AUTH_HOST: auth-app
|
|
||||||
AUTH_PORT: 9090
|
|
||||||
@ -1,23 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user