added files from backend
This commit is contained in:
parent
4205bf2e7b
commit
fba2ed5fe4
18
argo-infra-apps/backend-apps.yaml
Executable file
18
argo-infra-apps/backend-apps.yaml
Executable file
@ -0,0 +1,18 @@
|
||||
apiVersion: argoproj.io/v1alpha1
|
||||
kind: Application
|
||||
metadata:
|
||||
name: backend-apps
|
||||
namespace: argocd
|
||||
spec:
|
||||
project: default
|
||||
source:
|
||||
repoURL: https://gitlab.ii-p001.local/cw-devops/cw-infra-apps-nubes.git
|
||||
targetRevision: main
|
||||
path: charts/backend
|
||||
destination:
|
||||
server: https://kubernetes.default.svc
|
||||
namespace: backend
|
||||
syncPolicy:
|
||||
automated:
|
||||
prune: true
|
||||
selfHeal: true
|
||||
67
charts/backend/Chart.yaml
Executable file
67
charts/backend/Chart.yaml
Executable file
@ -0,0 +1,67 @@
|
||||
apiVersion: v2
|
||||
name: umbrella-chart
|
||||
description: A Helm umbrella chart to deploy multiple microservices with shared config
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: 1.0.0
|
||||
dependencies:
|
||||
- name: auth-event-handler-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/auth-event-handler-app-k8s
|
||||
- name: chat-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/chat-app-k8s
|
||||
- name: auth-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/auth-app-k8s
|
||||
- name: message-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/message-app-k8s
|
||||
- name: user-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/user-app-k8s
|
||||
- name: notification-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/notification-app-k8s
|
||||
- name: search-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/search-app-k8s
|
||||
- name: call-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/call-app-k8s
|
||||
- name: workspace-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/workspace-app-k8s
|
||||
- name: realtime-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/realtime-app-k8s
|
||||
- name: web-sender-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/web-sender-app-k8s
|
||||
- name: bff-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/bff-app-k8s
|
||||
- name: upload-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/upload-app-k8s
|
||||
- name: deeplink-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/deeplink-app-k8s
|
||||
- name: livekit-webhook-handler-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/livekit-webhook-handler-app-k8s
|
||||
- name: ios-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/ios-app-k8s
|
||||
- name: android-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/android-app-k8s
|
||||
- name: desktop-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/desktop-app-k8s
|
||||
- name: huawei-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/huawei-app-k8s
|
||||
- name: safari-app-k8s
|
||||
version: 0.1.0
|
||||
repository: file://charts/safari-app-k8s
|
||||
23
charts/backend/charts/admin-app-k8s/.helmignore
Executable file
23
charts/backend/charts/admin-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/admin-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/admin-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: admin-app
|
||||
description: Helm chart for Admin app
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0-SNAPSHOT"
|
||||
24
charts/backend/charts/admin-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/admin-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
||||
{{/* Common labels */}}
|
||||
{{- define "admin-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Name */}}
|
||||
{{- define "admin-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Fullname */}}
|
||||
{{- define "admin-app.fullname" -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "admin-app.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
65
charts/backend/charts/admin-app-k8s/templates/deployment.yaml
Executable file
65
charts/backend/charts/admin-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,65 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "admin-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "admin-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "admin-app.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "admin-app.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: admin-app
|
||||
ports:
|
||||
- containerPort: 9090
|
||||
targetPort: 9090
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
env:
|
||||
- name: WORKSPACE_HOST
|
||||
value: "{{ .Values.env.workspace_host }}"
|
||||
- name: WORKSPACE_PORT
|
||||
value: "{{ .Values.env.workspace_port }}"
|
||||
- name: USER_HOST
|
||||
value: "{{ .Values.env.user_host }}"
|
||||
- name: USER_PORT
|
||||
value: "{{ .Values.env.user_port }}"
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
15
charts/backend/charts/admin-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/admin-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "admin-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "admin-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
selector:
|
||||
{{- include "admin-app.selectorLabels" . | nindent 4 }}
|
||||
ports:
|
||||
- name: http
|
||||
port: {{ .Values.service.port }}
|
||||
targetPort: {{ .Values.service.targetPort }}
|
||||
protocol: TCP
|
||||
16
charts/backend/charts/admin-app-k8s/values.yaml
Executable file
16
charts/backend/charts/admin-app-k8s/values.yaml
Executable file
@ -0,0 +1,16 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/admin-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
env:
|
||||
workspace_host: workspace-app
|
||||
workspace_port: 9090
|
||||
user_host: user-app
|
||||
user_port: 9090
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
23
charts/backend/charts/android-app-k8s/.helmignore
Executable file
23
charts/backend/charts/android-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/android-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/android-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: android-sender-app
|
||||
description: Helm chart for Android Sender Application
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0-SNAPSHOT"
|
||||
24
charts/backend/charts/android-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/android-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
||||
{{/* Common labels */}}
|
||||
{{- define "android-sender-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Name */}}
|
||||
{{- define "android-sender-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Fullname */}}
|
||||
{{- define "android-sender-app.fullname" -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "android-sender-app.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
72
charts/backend/charts/android-app-k8s/templates/deployment.yaml
Executable file
72
charts/backend/charts/android-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,72 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "android-sender-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "android-sender-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "android-sender-app.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "android-sender-app.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: android-sender
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
env:
|
||||
- name: KAFKA_SERVER
|
||||
value: {{ .Values.env.kafkaServers }}
|
||||
- name: KAFKA_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafkaSecret }}
|
||||
key: username
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafkaSecret }}
|
||||
key: client-passwords
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.redisHost }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.env.redisPort | quote }}
|
||||
- name: ANDROID_FIREBASE_CONFIG
|
||||
value: {{ .Values.env.android_firebase_config }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
16
charts/backend/charts/android-app-k8s/values.yaml
Executable file
16
charts/backend/charts/android-app-k8s/values.yaml
Executable file
@ -0,0 +1,16 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/android-sender-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
env:
|
||||
kafkaServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
redisHost: redis-master.redis.svc.cluster.local
|
||||
redisPort: 6379
|
||||
android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json"
|
||||
|
||||
secrets:
|
||||
kafkaSecret: kafka-password
|
||||
firebaseSecret: android-firebase-config
|
||||
23
charts/backend/charts/auth-app-k8s/.helmignore
Executable file
23
charts/backend/charts/auth-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
24
charts/backend/charts/auth-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/auth-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
||||
apiVersion: v2
|
||||
name: auth-app-k8s
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.16.0"
|
||||
62
charts/backend/charts/auth-app-k8s/templates/_helpers.tpl
Executable file
62
charts/backend/charts/auth-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,62 @@
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "auth-app-k8s.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
If release name contains chart name it will be used as a full name.
|
||||
*/}}
|
||||
{{- define "auth-app-k8s.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||
{{- if contains $name .Release.Name }}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "auth-app-k8s.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "auth-app-k8s.labels" -}}
|
||||
helm.sh/chart: {{ include "auth-app-k8s.chart" . }}
|
||||
{{ include "auth-app-k8s.selectorLabels" . }}
|
||||
{{- if .Chart.AppVersion }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
{{- end }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "auth-app-k8s.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create the name of the service account to use
|
||||
*/}}
|
||||
{{- define "auth-app-k8s.serviceAccountName" -}}
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }}
|
||||
{{- else }}
|
||||
{{- default "default" .Values.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
103
charts/backend/charts/auth-app-k8s/templates/deployment.yaml
Executable file
103
charts/backend/charts/auth-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,103 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "auth-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||
io.kompose.service: auth-app
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "auth-app-k8s.selectorLabels" . | nindent 6 }}
|
||||
io.kompose.service: auth-app
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||
labels:
|
||||
{{- include "auth-app-k8s.selectorLabels" . | nindent 8 }}
|
||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||
spec:
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: {{ include "auth-app-k8s.fullname" . }}-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: auth-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: {{ .Values.service.targetPort }}
|
||||
{{- if .Values.service.hostPort }}
|
||||
hostPort: {{ .Values.service.hostPort }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: ADMIN_CLIENT_ID
|
||||
value: {{ .Values.env.adminClientId | quote }}
|
||||
- name: ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.adminPassword.name }}
|
||||
key: {{ .Values.secrets.adminPassword.key }}
|
||||
- name: ADMIN_REALM
|
||||
value: {{ .Values.env.adminRealm | quote }}
|
||||
- name: ADMIN_URL
|
||||
value: {{ .Values.env.adminUrl | quote }}
|
||||
- name: ADMIN_USERNAME
|
||||
value: {{ .Values.env.adminUsername | quote }}
|
||||
- name: CLIENT_ID
|
||||
value: {{ .Values.env.clientId | quote }}
|
||||
- name: CLIENT_ISSUER_IRI
|
||||
value: {{ .Values.env.clientIssuerIri | quote }}
|
||||
- name: CLIENT_REALM
|
||||
value: {{ .Values.env.clientRealm | quote }}
|
||||
- name: CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.clientSecret.name }}
|
||||
key: {{ .Values.secrets.clientSecret.key }}
|
||||
- name: REALM
|
||||
value: {{ .Values.env.realm | quote }}
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
- name: SECURITY_ADMIN_REALM
|
||||
value: {{ .Values.env.securityAdminRealm | quote }}
|
||||
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
|
||||
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
15
charts/backend/charts/auth-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/auth-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "auth-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
- port: {{ .Values.service.port }}
|
||||
targetPort: {{ .Values.service.targetPort }}
|
||||
protocol: TCP
|
||||
selector:
|
||||
{{- include "auth-app-k8s.selectorLabels" . | nindent 4 }}
|
||||
io.kompose.service: auth-app
|
||||
15
charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml
Executable file
15
charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml
Executable file
@ -0,0 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: "{{ include "auth-app-k8s.fullname" . }}-test-connection"
|
||||
labels:
|
||||
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
"helm.sh/hook": test
|
||||
spec:
|
||||
containers:
|
||||
- name: wget
|
||||
image: busybox
|
||||
command: ['wget']
|
||||
args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}']
|
||||
restartPolicy: Never
|
||||
58
charts/backend/charts/auth-app-k8s/values.yaml
Executable file
58
charts/backend/charts/auth-app-k8s/values.yaml
Executable file
@ -0,0 +1,58 @@
|
||||
|
||||
fullnameOverride: "auth-app"
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/auth-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: Always
|
||||
|
||||
replicaCount: 1
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
hostPort: null
|
||||
|
||||
env:
|
||||
cert_alias: co-work
|
||||
adminClientId: "admin-cli"
|
||||
adminRealm: "master"
|
||||
adminUrl: "https://iam.nubes.ru/admin/realms/cowork"
|
||||
adminUsername: "admin"
|
||||
clientId: "gem-auth-client"
|
||||
clientIssuerIri: "https://iam.nubes.ru/realms/cowork"
|
||||
clientRealm: "cowork"
|
||||
realm: "cowork"
|
||||
securityAdminRealm: "master"
|
||||
securityOauth2ClientIssuerUri: "https://iam.nubes.ru/realms"
|
||||
|
||||
|
||||
secrets:
|
||||
adminPassword:
|
||||
name: auth-secrets
|
||||
key: admin-password
|
||||
clientSecret:
|
||||
name: auth-secrets
|
||||
key: client-secret
|
||||
|
||||
|
||||
resources:
|
||||
limits:
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
|
||||
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: auth-app
|
||||
|
||||
|
||||
autoscaling:
|
||||
enabled: false
|
||||
23
charts/backend/charts/auth-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/auth-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: auth-event-handler-app-k8s
|
||||
description: Authentication Event Handler
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0-SNAPSHOT"
|
||||
23
charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl
Executable file
23
charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,23 @@
|
||||
{{/* Common Name Definitions */}}
|
||||
{{- define "auth-event-handler-app-k8s.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Standard labels */}}
|
||||
{{- define "auth-event-handler-app-k8s.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "auth-event-handler-app-k8s.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
141
charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml
Executable file
141
charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,141 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
{{- if not .Values.autoscaling.enabled }}
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
{{- end }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
{{- with .Values.podAnnotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }}
|
||||
{{- with .Values.podLabels }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
{{- with .Values.volumes }}
|
||||
{{ toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: {{ .Values.service.port }}
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: ADMIN_CLIENT_ID
|
||||
value: {{ .Values.env.adminClientId | quote }}
|
||||
- name: ADMIN_REALM
|
||||
value: {{ .Values.env.adminRealm | quote }}
|
||||
- name: ADMIN_URL
|
||||
value: {{ .Values.env.adminUrl | quote }}
|
||||
- name: ADMIN_USERNAME
|
||||
value: {{ .Values.env.adminUsername | quote }}
|
||||
- name: CLIENT_ID
|
||||
value: {{ .Values.env.clientId | quote }}
|
||||
- name: CLIENT_ISSUER_IRI
|
||||
value: {{ .Values.env.clientIssuerIri | quote }}
|
||||
- name: CLIENT_REALM
|
||||
value: {{ .Values.env.clientRealm | quote }}
|
||||
- name: REALM
|
||||
value: {{ .Values.env.realm | quote }}
|
||||
- name: SECURITY_ADMIN_REALM
|
||||
value: {{ .Values.env.securityAdminRealm | quote }}
|
||||
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
|
||||
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.kafkaBrokers | quote }}
|
||||
- name: KAFKA_USERNAME
|
||||
value: {{ .Values.secrets.kafka.username | quote }}
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||
- name: ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.adminPassword.name }}
|
||||
key: {{ .Values.secrets.adminPassword.key }}
|
||||
- name: CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.clientSecret.name }}
|
||||
key: {{ .Values.secrets.clientSecret.key }}
|
||||
livenessProbe:
|
||||
{{- toYaml .Values.livenessProbe | nindent 12 }}
|
||||
readinessProbe:
|
||||
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
volumeMounts:
|
||||
{{- with .Values.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
12
charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml
Executable file
12
charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,12 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
ports:
|
||||
- port: {{ .Values.service.port }}
|
||||
targetPort: {{ .Values.service.targetPort }}
|
||||
selector:
|
||||
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }}
|
||||
60
charts/backend/charts/auth-event-handler-app-k8s/values.yaml
Executable file
60
charts/backend/charts/auth-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,60 @@
|
||||
fullnameOverride: "auth-event-handler-app"
|
||||
image:
|
||||
repository: registry.co-work.ru/auth-event-handler-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: Always
|
||||
|
||||
replicaCount: 1
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 8094
|
||||
targetPort: 9090
|
||||
env:
|
||||
adminClientId: "admin-cli"
|
||||
adminRealm: "master"
|
||||
adminUrl: "https://iam.nubes.ru/admin/realms/cowork"
|
||||
adminUsername: "admin"
|
||||
clientId: "gem-auth-client"
|
||||
clientIssuerIri: "https://iam.nubes.ru/realms/cowork"
|
||||
clientRealm: "cowork"
|
||||
realm: "cowork"
|
||||
securityAdminRealm: "master"
|
||||
securityOauth2ClientIssuerUri: "https://iam.nubes.ru/realms"
|
||||
kafkaBrokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
secrets:
|
||||
kafka:
|
||||
name: kafka-password
|
||||
passwordKey: client-passwords
|
||||
username: admin
|
||||
adminPassword:
|
||||
name: auth-secrets
|
||||
key: admin-password
|
||||
clientSecret:
|
||||
name: auth-secrets
|
||||
key: client-secret
|
||||
|
||||
resources:
|
||||
limits:
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: auth-event-handler-app
|
||||
|
||||
|
||||
podSecurityContext: {}
|
||||
securityContext: {}
|
||||
|
||||
autoscaling:
|
||||
enabled: false
|
||||
|
||||
serviceAccount:
|
||||
create: false
|
||||
name: ""
|
||||
23
charts/backend/charts/bff-admin-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-admin-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/bff-admin-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/bff-admin-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: bff-admin-app
|
||||
description: Helm chart for bff-admin-app
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0-SNAPSHOT"
|
||||
24
charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
||||
{{/* Common labels */}}
|
||||
{{- define "bff-admin-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Name */}}
|
||||
{{- define "bff-admin-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Fullname */}}
|
||||
{{- define "bff-admin-app.fullname" -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "bff-admin-app.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
39
charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml
Executable file
39
charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,39 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "bff-admin-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "bff-admin-app.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "bff-admin-app.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
containers:
|
||||
- name: bff-admin-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
env:
|
||||
- name: SWAGGER_HOST
|
||||
value: "{{ .Values.env.swagger_host }}"
|
||||
- name: SWAGGER_PORT
|
||||
value: "{{ .Values.env.swagger_port }}"
|
||||
- name: WORKSPACE_HOST
|
||||
value: "{{ .Values.env.workspace_host }}"
|
||||
- name: WORKSPACE_PORT
|
||||
value: "{{ .Values.env.workspace_port }}"
|
||||
- name: USER_HOST
|
||||
value: "{{ .Values.env.user_host }}"
|
||||
- name: USER_PORT
|
||||
value: "{{ .Values.env.user_port }}"
|
||||
- name: ADMIN_HOST
|
||||
value: "{{ .Values.env.admin_host }}"
|
||||
- name: ADMIN_PORT
|
||||
value: "{{ .Values.env.admin_port }}"
|
||||
- name: APP_NAME
|
||||
value: "{{ .Values.env.app_name }}"
|
||||
38
charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml
Executable file
38
charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,38 @@
|
||||
{{- if .Values.ingress.enabled -}}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ .Values.ingress.name }}
|
||||
namespace: {{ .Release.Namespace | default "default" }}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
ingressClassName: {{ .Values.ingress.className }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .Values.ingress.hosts }}
|
||||
- host: {{ .host | quote }}
|
||||
http:
|
||||
paths:
|
||||
{{- range .paths }}
|
||||
- path: {{ .path }}
|
||||
pathType: {{ .pathType }}
|
||||
backend:
|
||||
service:
|
||||
name: {{ $.Values.env.app_name }}
|
||||
port:
|
||||
number: {{ $.Values.service.httpPort }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
17
charts/backend/charts/bff-admin-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/bff-admin-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "bff-admin-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
selector:
|
||||
{{- include "bff-admin-app.selectorLabels" . | nindent 4 }}
|
||||
ports:
|
||||
{{- range .Values.service.ports }}
|
||||
- name: {{ .name }}
|
||||
port: {{ .port }}
|
||||
targetPort: {{ .targetPort }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
46
charts/backend/charts/bff-admin-app-k8s/values.yaml
Executable file
46
charts/backend/charts/bff-admin-app-k8s/values.yaml
Executable file
@ -0,0 +1,46 @@
|
||||
replicaCount: 1
|
||||
image:
|
||||
repository: registry.co-work.ru/bff-admin-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
env:
|
||||
swagger_host: "localhost"
|
||||
swagger_port: 8080
|
||||
workspace_host: "workspace-app"
|
||||
workspace_port: 9090
|
||||
user_host: "user-app"
|
||||
user_port: 9090
|
||||
admin_host: "admin-app"
|
||||
admin_port: 9090
|
||||
app_name: bff-admin-app
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
httpPort: 8100
|
||||
grpcPort: 8101
|
||||
ports:
|
||||
- name: http
|
||||
port: 8100 # Changed from templated value to static
|
||||
targetPort: 8080
|
||||
- name: grpc
|
||||
port: 8101 # Changed from templated value to static
|
||||
targetPort: 9090
|
||||
|
||||
ingress:
|
||||
enabled: true
|
||||
className: nginx
|
||||
name: bff-admin-ingress
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||
hosts:
|
||||
- host: api-adm-p001.cw.ngcloud.ru
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls:
|
||||
- hosts:
|
||||
- api-adm-p001.cw.ngcloud.ru
|
||||
secretName: co-work-secret
|
||||
23
charts/backend/charts/bff-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
24
charts/backend/charts/bff-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/bff-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
||||
apiVersion: v2
|
||||
name: bff-app-k8s
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.16.0"
|
||||
23
charts/backend/charts/bff-app-k8s/templates/_helpers.tpl
Executable file
23
charts/backend/charts/bff-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,23 @@
|
||||
{{/* Common Name Definitions */}}
|
||||
{{- define "bff-app-k8s.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Standard labels */}}
|
||||
{{- define "bff-app-k8s.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "bff-app-k8s.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
93
charts/backend/charts/bff-app-k8s/templates/deployment.yaml
Executable file
93
charts/backend/charts/bff-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,93 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "bff-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "bff-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||
labels:
|
||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 8 }}
|
||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
# initContainers:
|
||||
# - name: import-ca
|
||||
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
# env:
|
||||
# - name: CERT_ALIAS
|
||||
# value: {{ .Values.env.cert_alias | quote }}
|
||||
# volumeMounts:
|
||||
# - name: ca-cert
|
||||
# mountPath: /app/resources
|
||||
# - name: cacerts-volume
|
||||
# mountPath: /tmp/cacerts
|
||||
# command:
|
||||
# - sh
|
||||
# - -c
|
||||
# - |
|
||||
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
# keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
# -alias gemcert \
|
||||
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
# -keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: bff-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: {{ .Values.service.targetPort }}
|
||||
{{- if .Values.service.hostPort }}
|
||||
hostPort: {{ .Values.service.hostPort }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: GRPC_CLIENT_AUTH_URL
|
||||
value: {{ .Values.env.services.auth | quote }}
|
||||
- name: GRPC_CLIENT_CHAT_URL
|
||||
value: {{ .Values.env.services.chat | quote }}
|
||||
- name: GRPC_CLIENT_CONFIG_URL
|
||||
value: {{ .Values.env.services.user | quote }}
|
||||
- name: GRPC_CLIENT_DEEPLINK_URL
|
||||
value: {{ .Values.env.services.deeplink | quote }}
|
||||
- name: GRPC_CLIENT_GEM_CALL_URL
|
||||
value: {{ .Values.env.services.gemCall | quote }}
|
||||
- name: GRPC_CLIENT_MESSAGE_URL
|
||||
value: {{ .Values.env.services.message | quote }}
|
||||
- name: GRPC_CLIENT_NOTIFICATIONS_URL
|
||||
value: {{ .Values.env.services.notification | quote }}
|
||||
- name: GRPC_CLIENT_REACTION_URL
|
||||
value: {{ .Values.env.services.message | quote }}
|
||||
- name: GRPC_CLIENT_REALTIME_URL
|
||||
value: {{ .Values.env.services.realtime | quote }}
|
||||
- name: GRPC_CLIENT_SEARCH_URL
|
||||
value: {{ .Values.env.services.search | quote }}
|
||||
- name: GRPC_CLIENT_STICKER_URL
|
||||
value: {{ .Values.env.services.sticker | quote }}
|
||||
- name: GRPC_CLIENT_UPLOAD_URL
|
||||
value: {{ .Values.env.services.upload | quote }}
|
||||
- name: GRPC_CLIENT_USER_URL
|
||||
value: {{ .Values.env.services.user | quote }}
|
||||
- name: GRPC_CLIENT_WORKSPACE_URL
|
||||
value: {{ .Values.env.services.workspace | quote }}
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
28
charts/backend/charts/bff-app-k8s/templates/ingress.yaml
Executable file
28
charts/backend/charts/bff-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,28 @@
|
||||
{{- if .Values.ingress.enabled -}}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ .Values.ingress.name }}
|
||||
namespace: {{ .Release.Namespace | default "default" }}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
ingressClassName: {{ .Values.ingress.className }}
|
||||
tls:
|
||||
- hosts:
|
||||
- {{ .Values.ingress.host | quote }}
|
||||
secretName: {{ .Values.ingress.tlsSecret | quote }}
|
||||
rules:
|
||||
- host: {{ .Values.ingress.host | quote }}
|
||||
http:
|
||||
paths:
|
||||
- path: {{ .Values.ingress.path }}
|
||||
pathType: {{ .Values.ingress.pathType }}
|
||||
backend:
|
||||
service:
|
||||
name: {{ .Values.service.name }}
|
||||
port:
|
||||
number: {{ .Values.service.port }}
|
||||
{{- end }}
|
||||
14
charts/backend/charts/bff-app-k8s/templates/service.yaml
Executable file
14
charts/backend/charts/bff-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,14 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "bff-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "bff-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
- port: {{ .Values.service.port }}
|
||||
targetPort: {{ .Values.service.targetPort }}
|
||||
protocol: TCP
|
||||
selector:
|
||||
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
|
||||
58
charts/backend/charts/bff-app-k8s/values.yaml
Executable file
58
charts/backend/charts/bff-app-k8s/values.yaml
Executable file
@ -0,0 +1,58 @@
|
||||
image:
|
||||
repository: registry.co-work.ru/bff-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
replicaCount: 1
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 8081
|
||||
targetPort: 8080
|
||||
nodePort: 31754
|
||||
name: bff-app # Added service name
|
||||
|
||||
ingress:
|
||||
enabled: true
|
||||
className: nginx
|
||||
name: bff-app-ingress
|
||||
host: api-p001.cw.ngcloud.ru
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||
path: /
|
||||
pathType: Prefix
|
||||
tlsSecret: co-work-secret
|
||||
|
||||
env:
|
||||
services:
|
||||
auth: http://auth-app:9090
|
||||
chat: http://chat-app:9090
|
||||
user: http://user-app:9090
|
||||
deeplink: http://deeplink-app:9090
|
||||
gemCall: http://gem-call-app:9090
|
||||
message: http://message-app:9090
|
||||
notification: http://notification-app:9090
|
||||
realtime: http://realtime-app:9090
|
||||
search: http://search-app:9090
|
||||
sticker: http://sticker-app:9090
|
||||
upload: http://upload-app:9090
|
||||
workspace: http://workspace-app:9090
|
||||
|
||||
resources:
|
||||
limits:
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 200m
|
||||
memory: 512Mi
|
||||
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/bff-app.yml -o k8s/bff-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: bff-app
|
||||
|
||||
fullnameOverride: "bff-app"
|
||||
23
charts/backend/charts/bff-vcs-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-vcs-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/bff-vcs-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/bff-vcs-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: bff-vcs-app
|
||||
description: Helm chart for bff-vcs-app
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0-SNAPSHOT"
|
||||
24
charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
||||
{{/* Common labels */}}
|
||||
{{- define "bff-vcs-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Name */}}
|
||||
{{- define "bff-vcs-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Fullname */}}
|
||||
{{- define "bff-vcs-app.fullname" -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "bff-vcs-app.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
58
charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml
Executable file
58
charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,58 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "bff-vcs-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "bff-vcs-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "bff-vcs-app.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "bff-vcs-app.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
# initContainers:
|
||||
# - name: import-ca
|
||||
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
# env:
|
||||
# - name: CERT_ALIAS
|
||||
# value: {{ .Values.env.cert_alias | quote }}
|
||||
# volumeMounts:
|
||||
# - name: ca-cert
|
||||
# mountPath: /app/resources
|
||||
# - name: cacerts-volume
|
||||
# mountPath: /tmp/cacerts
|
||||
# command:
|
||||
# - sh
|
||||
# - -c
|
||||
# - |
|
||||
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
# keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
# -alias gemcert \
|
||||
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
# -keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: bff-vcs-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
env:
|
||||
- name: GRPC_CLIENT_CALL_URL
|
||||
value: "{{ .Values.env.grpc_client_call_url }}"
|
||||
- name: GRPC_CLIENT_CALL_REALTIME_URL
|
||||
value: "{{ .Values.env.grpc_client_call_realtime_url }}"
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
28
charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml
Executable file
28
charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,28 @@
|
||||
{{- if .Values.ingress.enabled }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ include "bff-vcs-app.fullname" . }}-ingress
|
||||
namespace: {{ .Release.Namespace }}
|
||||
annotations:
|
||||
{{- range $key, $value := .Values.ingress.annotations }}
|
||||
{{ $key }}: {{ $value | quote }}
|
||||
{{- end }}
|
||||
spec:
|
||||
ingressClassName: {{ .Values.ingress.ingressClassName }}
|
||||
tls:
|
||||
- hosts:
|
||||
- {{ .Values.ingress.host }}
|
||||
secretName: {{ .Values.ingress.tlsSecretName }}
|
||||
rules:
|
||||
- host: {{ .Values.ingress.host }}
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: {{ include "bff-vcs-app.fullname" . }}
|
||||
port:
|
||||
number: {{ .Values.service.port }}
|
||||
{{- end }}
|
||||
16
charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml
Executable file
16
charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,16 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "bff-vcs-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "bff-vcs-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
selector:
|
||||
{{- include "bff-vcs-app.selectorLabels" . | nindent 4 }}
|
||||
ports:
|
||||
- name: http
|
||||
port: {{ .Values.service.port }}
|
||||
targetPort: {{ .Values.service.targetPort }}
|
||||
protocol: TCP
|
||||
|
||||
25
charts/backend/charts/bff-vcs-app-k8s/values.yaml
Executable file
25
charts/backend/charts/bff-vcs-app-k8s/values.yaml
Executable file
@ -0,0 +1,25 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: pibff-vcs-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
env:
|
||||
grpc_client_call_url: http://call-realtime-app:9090
|
||||
grpc_client_call_realtime_url: http://call-realtime-app:9090
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 8079
|
||||
targetPort: 8080
|
||||
|
||||
ingress:
|
||||
enabled: true
|
||||
ingressClassName: nginx
|
||||
host: api-vcs-p001.cw.ngcloud.ru
|
||||
tlsSecretName: co-work-secret
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||
23
charts/backend/charts/big-chat-splitter-app-k8s/.helmignore
Executable file
23
charts/backend/charts/big-chat-splitter-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
24
charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
||||
apiVersion: v2
|
||||
name: big-chat-splitter-app-k8s
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.16.0"
|
||||
22
charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl
Executable file
22
charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,22 @@
|
||||
{{/* Common Name Definitions */}}
|
||||
{{- define "big-chat-splitter-app-k8s.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Standard labels */}}
|
||||
{{- define "big-chat-splitter-app-k8s.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "big-chat-splitter-app-k8s.selectorLabels" -}}
|
||||
io.kompose.service: big-chat-splitter-app
|
||||
{{- end }}
|
||||
86
charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml
Executable file
86
charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,86 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "big-chat-splitter-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "big-chat-splitter-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||
labels:
|
||||
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: big-chat-splitter-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
env:
|
||||
- name: CASSANDRA_DC
|
||||
value: {{ .Values.env.cassandra.dc | quote }}
|
||||
- name: CASSANDRA_HOST
|
||||
value: {{ .Values.env.cassandra.host | quote }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
value: {{ .Values.secrets.cassandra.username | quote }}
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||
- name: CHAT_SERVICE_HOST
|
||||
value: {{ .Values.env.services.chat.host | quote }}
|
||||
- name: CHAT_SERVICE_PORT
|
||||
value: {{ .Values.env.services.chat.port | quote }}
|
||||
- name: KAFKA_USER
|
||||
value: {{ .Values.secrets.kafka.username | quote }}
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||
- name: KAFKA_SERVER
|
||||
value: {{ .Values.env.kafka.servers | quote }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.redis.host | quote }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.env.redis.port | quote }}
|
||||
- name: USER_SERVICE_HOST
|
||||
value: {{ .Values.env.services.user.host | quote }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
54
charts/backend/charts/big-chat-splitter-app-k8s/values.yaml
Executable file
54
charts/backend/charts/big-chat-splitter-app-k8s/values.yaml
Executable file
@ -0,0 +1,54 @@
|
||||
|
||||
fullnameOverride: "big-chat-splitter-app"
|
||||
image:
|
||||
repository: registry.co-work.ru/big-chat-splitter-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: Always
|
||||
replicaCount: 1
|
||||
env:
|
||||
cassandra:
|
||||
dc: datacenter1
|
||||
host: "cassandra.cassandra.svc.cluster.local"
|
||||
services:
|
||||
chat:
|
||||
host: chat-app
|
||||
port: 9090
|
||||
user:
|
||||
host: user-app
|
||||
port: 9090
|
||||
redis:
|
||||
host: redis-master.redis.svc.cluster.local
|
||||
port: 6379
|
||||
kafka:
|
||||
servers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
|
||||
secrets:
|
||||
cassandra:
|
||||
name: cassandra
|
||||
passwordKey: cassandra-password
|
||||
username: cassandra
|
||||
|
||||
kafka:
|
||||
name: kafka-password
|
||||
passwordKey: client-passwords
|
||||
username: admin
|
||||
|
||||
|
||||
resources:
|
||||
limits:
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
|
||||
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/big-chat-splitter-app.yml -o k8s/big-chat-splitter-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: big-chat-splitter-app
|
||||
|
||||
|
||||
fullnameOverride: "big-chat-splitter-app"
|
||||
23
charts/backend/charts/call-app-k8s/.helmignore
Executable file
23
charts/backend/charts/call-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
24
charts/backend/charts/call-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/call-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
||||
apiVersion: v2
|
||||
name: call-app-k8s
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.16.0"
|
||||
22
charts/backend/charts/call-app-k8s/templates/_helpers.tpl
Executable file
22
charts/backend/charts/call-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,22 @@
|
||||
{{/* Common Name Definitions */}}
|
||||
{{- define "call-app-k8s.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Standard labels */}}
|
||||
{{- define "call-app-k8s.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/* Selector labels */}}
|
||||
{{- define "call-app-k8s.selectorLabels" -}}
|
||||
io.kompose.service: call-app
|
||||
{{- end }}
|
||||
131
charts/backend/charts/call-app-k8s/templates/deployment.yaml
Executable file
131
charts/backend/charts/call-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,131 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "call-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "call-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "call-app-k8s.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||
labels:
|
||||
{{- include "call-app-k8s.selectorLabels" . | nindent 8 }}
|
||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: call-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: 5005
|
||||
protocol: TCP
|
||||
targetPort: 5005
|
||||
- containerPort: 9090
|
||||
protocol: TCP
|
||||
targetPort: 9090
|
||||
env:
|
||||
- name: TENANT_ID
|
||||
value: {{ .Values.env.TENANT_ID | quote }}
|
||||
- name: CASSANDRA_CONTACTPOINT
|
||||
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||
- name: CASSANDRA_DATACENTER
|
||||
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.usernameKey }}
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.kafka.brokers | quote }}
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.usernameKey }}
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||
- name: KEYCLOAK_URL
|
||||
value: {{ .Values.env.keycloak.url | quote }}
|
||||
- name: LIVEKIT_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.livekit.name }}
|
||||
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
||||
- name: LIVEKIT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.livekit.name }}
|
||||
key: {{ .Values.secrets.livekit.secretKey }}
|
||||
- name: RECORDING_ACCESS_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.recording.name }}
|
||||
key: {{ .Values.secrets.recording.accessKeyKey }}
|
||||
- name: RECORDING_API_HOST
|
||||
value: {{ .Values.env.livekit.apiHost | quote }}
|
||||
- name: RECORDING_BUCKET
|
||||
value: {{ .Values.env.recording.bucket | quote }}
|
||||
- name: RECORDING_ENDPOINT
|
||||
value: {{ .Values.env.recording.endpoint | quote }}
|
||||
- name: RECORDING_REGION
|
||||
value: {{ .Values.env.recording.region | quote }}
|
||||
- name: RECORDING_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.recording.name }}
|
||||
key: {{ .Values.secrets.recording.secretKeyKey }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.redis.host | quote }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.env.redis.port | quote }}
|
||||
- name: REDIS_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.redis.name }}
|
||||
key: {{ .Values.secrets.redis.passwordKey }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
17
charts/backend/charts/call-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/call-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "call-app-k8s.fullname" . }}
|
||||
labels:
|
||||
{{- include "call-app-k8s.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
{{- range .Values.service.ports }}
|
||||
- name: {{ .name }}
|
||||
port: {{ .port }}
|
||||
targetPort: {{ .targetPort }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
selector:
|
||||
{{- include "call-app-k8s.selectorLabels" . | nindent 4 }}
|
||||
66
charts/backend/charts/call-app-k8s/values.yaml
Executable file
66
charts/backend/charts/call-app-k8s/values.yaml
Executable file
@ -0,0 +1,66 @@
|
||||
image:
|
||||
repository: registry.co-work.ru/call-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: Always
|
||||
|
||||
replicaCount: 1
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- name: main
|
||||
port: 5005
|
||||
targetPort: 5005
|
||||
- name: metrics
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
env:
|
||||
cassandra:
|
||||
contactPoint: cassandra.cassandra.svc.cluster.local
|
||||
datacenter: datacenter1
|
||||
kafka:
|
||||
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
redis:
|
||||
host: redis-master.redis.svc.cluster.local
|
||||
port: 6379
|
||||
keycloak:
|
||||
url: https://iam.nubes.ru/realms/cowork
|
||||
livekit:
|
||||
apiHost: https://av-p001.cw.ngcloud.ru
|
||||
recording:
|
||||
endpoint: https://store-p001.cw.ngcloud.ru:9000
|
||||
region: us-east-2
|
||||
bucket: livekit
|
||||
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
|
||||
|
||||
secrets:
|
||||
cassandra:
|
||||
name: cassandra
|
||||
usernameKey: username
|
||||
passwordKey: cassandra-password
|
||||
kafka:
|
||||
name: kafka-password
|
||||
usernameKey: username
|
||||
passwordKey: client-passwords
|
||||
redis:
|
||||
name: redis-kafka-user-passwords
|
||||
passwordKey: client-passwords
|
||||
livekit:
|
||||
name: livekit-secret
|
||||
apiKeyKey: api-key
|
||||
secretKey: secret
|
||||
recording:
|
||||
name: recording-secret
|
||||
accessKeyKey: access-key
|
||||
secretKeyKey: secret
|
||||
|
||||
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/call-app.yml -o k8s/call-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: call-app
|
||||
|
||||
fullnameOverride: "call-app"
|
||||
23
charts/backend/charts/call-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/call-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/call-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/call-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: call-event-handler-app
|
||||
description: Call Event Handler Application
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0-SNAPSHOT"
|
||||
46
charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl
Executable file
46
charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,46 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "call-event-handler-app.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
*/}}
|
||||
{{- define "call-event-handler-app.fullname" -}}
|
||||
{{- if .Values.fullnameOverride -}}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "call-event-handler-app.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "call-event-handler-app.labels" -}}
|
||||
helm.sh/chart: {{ include "call-event-handler-app.chart" . }}
|
||||
{{ include "call-event-handler-app.selectorLabels" . }}
|
||||
{{- if .Chart.AppVersion }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
{{- end }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "call-event-handler-app.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "call-event-handler-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end -}}
|
||||
111
charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml
Executable file
111
charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,111 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "call-event-handler-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "call-event-handler-app.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "call-event-handler-app.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||
labels:
|
||||
{{- include "call-event-handler-app.selectorLabels" . | nindent 8 }}
|
||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: 5005
|
||||
protocol: TCP
|
||||
- containerPort: 9090
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: CASSANDRA_CONTACTPOINT
|
||||
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||
- name: CASSANDRA_DATACENTER
|
||||
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.usernameKey }}
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.kafka.brokers | quote }}
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.usernameKey }}
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||
- name: LIVEKIT_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.livekit.name }}
|
||||
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
||||
- name: LIVEKIT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.livekit.name }}
|
||||
key: {{ .Values.secrets.livekit.secretKey }}
|
||||
- name: RECORDING_API_HOST
|
||||
value: {{ .Values.env.recording.apiHost | quote }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.redis.host | quote }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.env.redis.port | quote }}
|
||||
- name: REDIS_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.redis.name }}
|
||||
key: {{ .Values.secrets.redis.passwordKey }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
17
charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "call-event-handler-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "call-event-handler-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
{{- range .Values.service.ports }}
|
||||
- name: {{ .name }}
|
||||
port: {{ .port }}
|
||||
targetPort: {{ .targetPort }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
selector:
|
||||
{{- include "call-event-handler-app.selectorLabels" . | nindent 4 }}
|
||||
57
charts/backend/charts/call-event-handler-app-k8s/values.yaml
Executable file
57
charts/backend/charts/call-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,57 @@
|
||||
image:
|
||||
repository: registry.co-work.ru/call-event-handler-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
replicaCount: 1
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- name: main
|
||||
port: 5005
|
||||
targetPort: 5005
|
||||
- name: metrics
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
|
||||
env:
|
||||
cassandra:
|
||||
contactPoint: cassandra.cassandra.svc.cluster.local
|
||||
datacenter: datacenter1
|
||||
kafka:
|
||||
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
redis:
|
||||
host: redis-master.redis.svc.cluster.local
|
||||
port: "6379"
|
||||
recording:
|
||||
apiHost: https://store-p001.cw.ngcloud.ru:9000
|
||||
|
||||
secrets:
|
||||
cassandra:
|
||||
name: cassandra
|
||||
usernameKey: username
|
||||
passwordKey: cassandra-password
|
||||
kafka:
|
||||
name: kafka-password
|
||||
usernameKey: username
|
||||
passwordKey: client-passwords
|
||||
redis:
|
||||
name: redis-kafka-user-passwords
|
||||
passwordKey: client-passwords
|
||||
livekit:
|
||||
name: livekit-secret
|
||||
apiKeyKey: api-key
|
||||
secretKey: secret
|
||||
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/call-event-handler-app.yml -o k8s/call-event-handler-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: call-event-handler-app
|
||||
|
||||
|
||||
nameOverride: ""
|
||||
fullnameOverride: ""
|
||||
23
charts/backend/charts/call-realtime-app-k8s/.helmignore
Executable file
23
charts/backend/charts/call-realtime-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
24
charts/backend/charts/call-realtime-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/call-realtime-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
||||
apiVersion: v2
|
||||
name: call-realtime-app-k8s
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.16.0"
|
||||
39
charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl
Executable file
39
charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,39 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "call-realtime-app.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
*/}}
|
||||
{{- define "call-realtime-app.fullname" -}}
|
||||
{{- if .Values.fullnameOverride -}}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "call-realtime-app.labels" -}}
|
||||
helm.sh/chart: {{ include "call-realtime-app.name" . }}
|
||||
{{ include "call-realtime-app.selectorLabels" . }}
|
||||
{{- if .Chart.AppVersion }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
{{- end }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "call-realtime-app.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "call-realtime-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end -}}
|
||||
120
charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml
Executable file
120
charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,120 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "call-realtime-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "call-realtime-app.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "call-realtime-app.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||
labels:
|
||||
{{- include "call-realtime-app.selectorLabels" . | nindent 8 }}
|
||||
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: 5005
|
||||
protocol: TCP
|
||||
- containerPort: 9090
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: TENANT_ID
|
||||
value: {{ .Values.env.TENANT_ID | quote }}
|
||||
- name: CASSANDRA_CONTACTPOINT
|
||||
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||
- name: CASSANDRA_DATACENTER
|
||||
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.usernameKey }}
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra.name }}
|
||||
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.kafka.brokers | quote }}
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.usernameKey }}
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka.name }}
|
||||
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||
- name: LIVEKIT_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.livekit.name }}
|
||||
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
||||
- name: LIVEKIT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.livekit.name }}
|
||||
key: {{ .Values.secrets.livekit.secretKey }}
|
||||
- name: RECORDING_ACCESS_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.recording.name }}
|
||||
key: {{ .Values.secrets.recording.accessKeyKey }}
|
||||
- name: RECORDING_API_HOST
|
||||
value: {{ .Values.env.recording.apiHost | quote }}
|
||||
- name: RECORDING_BUCKET
|
||||
value: {{ .Values.env.recording.bucket | quote }}
|
||||
- name: RECORDING_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.recording.name }}
|
||||
key: {{ .Values.secrets.recording.secretKey }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.redis.host | quote }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.env.redis.port | quote }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
17
charts/backend/charts/call-realtime-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/call-realtime-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "call-realtime-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "call-realtime-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
{{- range .Values.service.ports }}
|
||||
- name: {{ .name }}
|
||||
port: {{ .port }}
|
||||
targetPort: {{ .targetPort }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
selector:
|
||||
{{- include "call-realtime-app.selectorLabels" . | nindent 4 }}
|
||||
66
charts/backend/charts/call-realtime-app-k8s/values.yaml
Executable file
66
charts/backend/charts/call-realtime-app-k8s/values.yaml
Executable file
@ -0,0 +1,66 @@
|
||||
# Image Configuration
|
||||
image:
|
||||
repository: registry.co-work.ru/call-realtime-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
# Replica Configuration
|
||||
replicaCount: 1
|
||||
|
||||
# Service Configuration
|
||||
service:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- name: main
|
||||
port: 5096
|
||||
targetPort: 5005
|
||||
- name: metrics
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
|
||||
# Environment Configuration
|
||||
env:
|
||||
cassandra:
|
||||
contactPoint: cassandra.cassandra.svc.cluster.local
|
||||
datacenter: datacenter1
|
||||
kafka:
|
||||
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
redis:
|
||||
host: redis-master.redis.svc.cluster.local
|
||||
port: "6379"
|
||||
recording:
|
||||
apiHost: https://store-p001.cw.ngcloud.ru:9000
|
||||
bucket: livekit
|
||||
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
|
||||
|
||||
# Secret References
|
||||
secrets:
|
||||
cassandra:
|
||||
name: cassandra
|
||||
usernameKey: username
|
||||
passwordKey: cassandra-password
|
||||
kafka:
|
||||
name: kafka-password
|
||||
usernameKey: username
|
||||
passwordKey: client-passwords
|
||||
livekit:
|
||||
name: livekit-secret
|
||||
apiKeyKey: api-key
|
||||
secretKey: secret
|
||||
recording:
|
||||
name: recording-secret
|
||||
accessKeyKey: access-key
|
||||
secretKey: secret
|
||||
|
||||
# Kompose Metadata
|
||||
podAnnotations:
|
||||
kompose.cmd: kompose convert -f app/call-realtime-app.yml -o k8s/call-realtime-app-k8s
|
||||
kompose.version: 1.33.0 (HEAD)
|
||||
|
||||
podLabels:
|
||||
io.kompose.network/app-default: "true"
|
||||
io.kompose.service: call-realtime-app
|
||||
|
||||
# Chart Metadata
|
||||
nameOverride: ""
|
||||
fullnameOverride: call-realtime-app
|
||||
23
charts/backend/charts/chat-app-k8s/.helmignore
Executable file
23
charts/backend/charts/chat-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
24
charts/backend/charts/chat-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/chat-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
||||
apiVersion: v2
|
||||
name: chat-app
|
||||
description: A Helm chart for Kubernetes
|
||||
|
||||
# A chart can be either an 'application' or a 'library' chart.
|
||||
#
|
||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||
# to be deployed.
|
||||
#
|
||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||
type: application
|
||||
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.1.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.16.0"
|
||||
27
charts/backend/charts/chat-app-k8s/templates/_helpers.tpl
Executable file
27
charts/backend/charts/chat-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,27 @@
|
||||
{{/*
|
||||
Return the name of the chart
|
||||
*/}}
|
||||
{{- define "chat-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
*/}}
|
||||
{{- define "chat-app.fullname" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "chat-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "chat-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
{{- define "chat-app.quote" -}}
|
||||
{{- . | quote }}
|
||||
{{- end }}
|
||||
131
charts/backend/charts/chat-app-k8s/templates/deployment.yaml
Executable file
131
charts/backend/charts/chat-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,131 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "chat-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "chat-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ include "chat-app.name" . }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ include "chat-app.name" . }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
ports:
|
||||
- containerPort: 9090
|
||||
hostPort: 8085
|
||||
- containerPort: 5005
|
||||
hostPort: 5085
|
||||
env:
|
||||
- name: CASSANDRA_CONTACTPOINT
|
||||
value: {{ .Values.env.CASSANDRA_CONTACTPOINT }}
|
||||
- name: CASSANDRA_DATACENTER
|
||||
value: {{ .Values.env.CASSANDRA_DATACENTER }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: cassandra
|
||||
key: username
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: cassandra
|
||||
key: cassandra-password
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: kafka-password
|
||||
key: username
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: kafka-password
|
||||
key: client-passwords
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.KAFKA | quote }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.REDIS_HOST }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ include "chat-app.quote" .Values.env.REDIS_PORT }}
|
||||
- name: DEEPLINK_HOST
|
||||
value: {{ .Values.env.DEEPLINK_HOST }}
|
||||
- name: DEEPLINK_PORT
|
||||
value: {{ include "chat-app.quote" .Values.env.DEEPLINK_PORT }}
|
||||
- name: GEM_CALL_HOST
|
||||
value: {{ .Values.env.GEM_CALL_HOST }}
|
||||
- name: GEM_CALL_PORT
|
||||
value: {{ include "chat-app.quote" .Values.env.GEM_CALL_PORT }}
|
||||
- name: MESSAGE_HOST
|
||||
value: {{ .Values.env.MESSAGE_HOST }}
|
||||
- name: MESSAGE_PORT
|
||||
value: {{ .Values.env.MESSAGE_PORT | quote }}
|
||||
- name: SEARCH_HOST
|
||||
value: {{ .Values.env.SEARCH_HOST }}
|
||||
- name: SEARCH_PORT
|
||||
value: {{ include "chat-app.quote" .Values.env.SEARCH_PORT }}
|
||||
- name: USER_HOST
|
||||
value: {{ .Values.env.USER_HOST }}
|
||||
- name: USER_PORT
|
||||
value: {{ include "chat-app.quote" .Values.env.USER_PORT }}
|
||||
- name: KEYCLOAK_URL
|
||||
value: {{ .Values.env.KEYCLOAK_URL }}
|
||||
- name: LIVEKIT_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: livekit-secret
|
||||
key: api-key
|
||||
- name: LIVEKIT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: livekit-secret
|
||||
key: secret
|
||||
- name: RECORDING_ACCESS_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: recording-secret
|
||||
key: access-key
|
||||
- name: RECORDING_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: recording-secret
|
||||
key: secret
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
restartPolicy: Always
|
||||
16
charts/backend/charts/chat-app-k8s/templates/service.yaml
Executable file
16
charts/backend/charts/chat-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,16 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "chat-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "chat-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
selector:
|
||||
app: {{ include "chat-app.name" . }}
|
||||
ports:
|
||||
- name: http
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
- name: debug
|
||||
port: 5085
|
||||
targetPort: 5005
|
||||
23
charts/backend/charts/chat-app-k8s/values.yaml
Executable file
23
charts/backend/charts/chat-app-k8s/values.yaml
Executable file
@ -0,0 +1,23 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/chat-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
|
||||
env:
|
||||
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
|
||||
CASSANDRA_DATACENTER: datacenter1
|
||||
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
REDIS_HOST: redis-master.redis.svc.cluster.local
|
||||
REDIS_PORT: "6379"
|
||||
DEEPLINK_HOST: deeplink-app
|
||||
DEEPLINK_PORT: "9090"
|
||||
GEM_CALL_HOST: gem-call-app
|
||||
GEM_CALL_PORT: "9090"
|
||||
MESSAGE_HOST: message-app
|
||||
MESSAGE_PORT: "9090"
|
||||
SEARCH_HOST: search-app
|
||||
SEARCH_PORT: "9090"
|
||||
USER_HOST: user-app
|
||||
USER_PORT: "9090"
|
||||
KEYCLOAK_URL: https://iam.nubes.ru/realms/cowork
|
||||
23
charts/backend/charts/chat-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/chat-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: chat-event-handler-app
|
||||
description: A Helm chart for Kubernetes
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.16.0"
|
||||
27
charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl
Executable file
27
charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,27 @@
|
||||
{{/*
|
||||
Return the name of the chart
|
||||
*/}}
|
||||
{{- define "chat-event-handler-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
*/}}
|
||||
{{- define "chat-event-handler-app.fullname" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "chat-event-handler-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "chat-event-handler-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
{{- define "chat-event-handler-app.quote" -}}
|
||||
{{- . | quote }}
|
||||
{{- end }}
|
||||
109
charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml
Executable file
109
charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,109 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "chat-event-handler-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ include "chat-event-handler-app.name" . }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ include "chat-event-handler-app.name" . }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
ports:
|
||||
- containerPort: 5005
|
||||
hostPort: 5086
|
||||
env:
|
||||
- name: CASSANDRA_CONTACTPOINT
|
||||
value: {{ .Values.env.CASSANDRA_CONTACTPOINT }}
|
||||
- name: CASSANDRA_DATACENTER
|
||||
value: {{ .Values.env.CASSANDRA_DATACENTER }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: cassandra
|
||||
key: username
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: cassandra
|
||||
key: cassandra-password
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: kafka-password
|
||||
key: username
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: kafka-password
|
||||
key: client-passwords
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.KAFKA | quote }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.env.REDIS_HOST }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ include "chat-event-handler-app.quote" .Values.env.REDIS_PORT }}
|
||||
- name: DEEPLINK_HOST
|
||||
value: {{ .Values.env.DEEPLINK_HOST }}
|
||||
- name: DEEPLINK_PORT
|
||||
value: {{ include "chat-event-handler-app.quote" .Values.env.DEEPLINK_PORT }}
|
||||
- name: GEM_CALL_HOST
|
||||
value: {{ .Values.env.GEM_CALL_HOST }}
|
||||
- name: GEM_CALL_PORT
|
||||
value: {{ include "chat-event-handler-app.quote" .Values.env.GEM_CALL_PORT }}
|
||||
- name: MESSAGE_HOST
|
||||
value: {{ .Values.env.MESSAGE_HOST }}
|
||||
- name: MESSAGE_PORT
|
||||
value: {{ .Values.env.MESSAGE_PORT | quote }}
|
||||
- name: SEARCH_HOST
|
||||
value: {{ .Values.env.SEARCH_HOST }}
|
||||
- name: SEARCH_PORT
|
||||
value: {{ include "chat-event-handler-app.quote" .Values.env.SEARCH_PORT }}
|
||||
- name: USER_HOST
|
||||
value: {{ .Values.env.USER_HOST }}
|
||||
- name: USER_PORT
|
||||
value: {{ include "chat-event-handler-app.quote" .Values.env.USER_PORT }}
|
||||
- name: KEYCLOAK_URL
|
||||
value: {{ .Values.env.KEYCLOAK_URL }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
restartPolicy: Always
|
||||
13
charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml
Executable file
13
charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,13 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "chat-event-handler-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
selector:
|
||||
app: {{ include "chat-event-handler-app.name" . }}
|
||||
ports:
|
||||
- name: debug
|
||||
port: 5086
|
||||
targetPort: 5005
|
||||
22
charts/backend/charts/chat-event-handler-app-k8s/values.yaml
Executable file
22
charts/backend/charts/chat-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,22 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/chat-event-handler-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
|
||||
env:
|
||||
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
|
||||
CASSANDRA_DATACENTER: datacenter1
|
||||
MESSAGE_HOST: message-app
|
||||
MESSAGE_PORT: "9090"
|
||||
USER_HOST: user-app
|
||||
USER_PORT: "9090"
|
||||
SEARCH_HOST: search-app
|
||||
SEARCH_PORT: "9090"
|
||||
GEM_CALL_HOST: gem-call-app
|
||||
GEM_CALL_PORT: "9090"
|
||||
DEEPLINK_HOST: deeplink-app
|
||||
DEEPLINK_PORT: "9090"
|
||||
REDIS_HOST: redis-master.redis.svc.cluster.local
|
||||
REDIS_PORT: "6379"
|
||||
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
23
charts/backend/charts/deeplink-app-k8s/.helmignore
Executable file
23
charts/backend/charts/deeplink-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
6
charts/backend/charts/deeplink-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/deeplink-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
||||
apiVersion: v2
|
||||
name: deeplink-app-k8s
|
||||
description: A Helm chart for Kubernetes
|
||||
type: application
|
||||
version: 0.1.0
|
||||
appVersion: "1.16.0"
|
||||
17
charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl
Executable file
17
charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,17 @@
|
||||
{{/* Chart name */}}
|
||||
{{- define "deeplink-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "deeplink-app.fullname" -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* Common labels */}}
|
||||
{{- define "deeplink-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "deeplink-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
70
charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml
Executable file
70
charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,70 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "deeplink-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "deeplink-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ include "deeplink-app.name" . }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ include "deeplink-app.name" . }}
|
||||
spec:
|
||||
containers:
|
||||
- name: {{ include "deeplink-app.name" . }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
ports:
|
||||
- containerPort: {{ .Values.container.port }}
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: CASSANDRA_PORT
|
||||
value: {{ .Values.env.CASSANDRA_PORT | quote }}
|
||||
- name: BRANCHIO_ACCESS
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: branchio-access
|
||||
- name: BRANCHIO_APPID
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: branchio-appid
|
||||
- name: BRANCHIO_DEFAULT_URL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: branchio-default-url
|
||||
- name: BRANCHIO_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: branchio-key
|
||||
- name: BRANCHIO_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: branchio-secret
|
||||
- name: BRANCHIO_URL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: branchio-url
|
||||
- name: DEEPLINK_DOMAIN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: deeplink-domain
|
||||
- name: DEEPLINK_WEBDOMAIN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.branchio }}
|
||||
key: deeplink-webdomain
|
||||
- name: DEEPLINK_TENANT
|
||||
value: nubes.ru
|
||||
- name: KEYCLOAK_URL
|
||||
value: {{ .Values.keycloak.url | quote }}
|
||||
restartPolicy: Always
|
||||
13
charts/backend/charts/deeplink-app-k8s/templates/service.yaml
Executable file
13
charts/backend/charts/deeplink-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,13 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "deeplink-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "deeplink-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
selector:
|
||||
app: {{ include "deeplink-app.name" . }}
|
||||
ports:
|
||||
- name: http
|
||||
port: {{ .Values.service.port }}
|
||||
targetPort: {{ .Values.container.port }}
|
||||
20
charts/backend/charts/deeplink-app-k8s/values.yaml
Executable file
20
charts/backend/charts/deeplink-app-k8s/values.yaml
Executable file
@ -0,0 +1,20 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/deeplink-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
|
||||
service:
|
||||
port: 9090
|
||||
|
||||
container:
|
||||
port: 9090
|
||||
|
||||
keycloak:
|
||||
url: https://iam.nubes.ru/realms/cowork
|
||||
|
||||
secrets:
|
||||
branchio: deeplink-secret
|
||||
|
||||
env:
|
||||
CASSANDRA_PORT: "9042"
|
||||
23
charts/backend/charts/gem-call-app-k8s/.helmignore
Executable file
23
charts/backend/charts/gem-call-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
8
charts/backend/charts/gem-call-app-k8s/Chart.yaml
Executable file
8
charts/backend/charts/gem-call-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,8 @@
|
||||
apiVersion: v2
|
||||
name: gem-call-app
|
||||
description: A Helm chart for gem-call-app
|
||||
|
||||
type: application
|
||||
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0"
|
||||
15
charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl
Executable file
15
charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,15 @@
|
||||
{{- define "gem-call-app.name" -}}
|
||||
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gem-call-app.fullname" -}}
|
||||
{{ .Chart.Name }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gem-call-app.labels" -}}
|
||||
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||
app.kubernetes.io/name: {{ include "gem-call-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
68
charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml
Executable file
68
charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,68 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "gem-call-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "gem-call-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: {{ include "gem-call-app.name" . }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: {{ include "gem-call-app.name" . }}
|
||||
spec:
|
||||
containers:
|
||||
- name: {{ include "gem-call-app.name" . }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
ports:
|
||||
- containerPort: 9090
|
||||
- containerPort: 5005
|
||||
env:
|
||||
- name: CALL_HOST
|
||||
value: {{ .Values.call.host | quote }}
|
||||
- name: CALL_PORT
|
||||
value: {{ .Values.call.port | quote }}
|
||||
- name: CALL_REALTIME_HOST
|
||||
value: {{ .Values.callRealtime.host | quote }}
|
||||
- name: CALL_REALTIME_PORT
|
||||
value: {{ .Values.callRealtime.port | quote }}
|
||||
- name: CHAT_HOST
|
||||
value: {{ .Values.chat.host | quote }}
|
||||
- name: CHAT_PORT
|
||||
value: {{ .Values.chat.port | quote }}
|
||||
- name: DEEPLINK_HOST
|
||||
value: {{ .Values.deeplink.host | quote }}
|
||||
- name: DEEPLINK_PORT
|
||||
value: {{ .Values.deeplink.port | quote }}
|
||||
- name: KAFKA
|
||||
value: {{ .Values.kafka.bootstrapServers | quote }}
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka }}
|
||||
key: username
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka }}
|
||||
key: client-passwords
|
||||
- name: KEYCLOAK_URL
|
||||
value: {{ .Values.keycloak.url | quote }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.redis.host | quote }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.redis.port | quote }}
|
||||
- name: REDIS_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.redis }}
|
||||
key: client-passwords
|
||||
- name: USER_HOST
|
||||
value: {{ .Values.user.host | quote }}
|
||||
- name: USER_PORT
|
||||
value: {{ .Values.user.port | quote }}
|
||||
|
||||
restartPolicy: Always
|
||||
19
charts/backend/charts/gem-call-app-k8s/templates/service.yaml
Executable file
19
charts/backend/charts/gem-call-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,19 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "gem-call-app.fullname" . }}
|
||||
labels:
|
||||
app: {{ .Release.Name }}
|
||||
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||
release: {{ .Release.Name }}
|
||||
heritage: {{ .Release.Service }}
|
||||
spec:
|
||||
ports:
|
||||
- name: "9090"
|
||||
port: 9090
|
||||
targetPort: 9090
|
||||
- name: "5089"
|
||||
port: 5089
|
||||
targetPort: 5005
|
||||
selector:
|
||||
app: gem-call-app
|
||||
40
charts/backend/charts/gem-call-app-k8s/values.yaml
Executable file
40
charts/backend/charts/gem-call-app-k8s/values.yaml
Executable file
@ -0,0 +1,40 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: registry.co-work.ru/gem-call-app
|
||||
tag: 1.0.0-SNAPSHOT
|
||||
|
||||
secrets:
|
||||
kafka: kafka-password
|
||||
redis: redis-kafka-user-passwords
|
||||
|
||||
kafka:
|
||||
bootstrapServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
redis:
|
||||
host: redis-master.redis.svc.cluster.local
|
||||
port: "6379"
|
||||
|
||||
keycloak:
|
||||
url: https://iam.nubes.ru/realms/cowork
|
||||
env:
|
||||
cert_alias: nubes
|
||||
|
||||
call:
|
||||
host: call-app
|
||||
port: "9090"
|
||||
|
||||
callRealtime:
|
||||
host: call-realtime-app
|
||||
port: "9090"
|
||||
|
||||
chat:
|
||||
host: chat-app
|
||||
port: "9090"
|
||||
|
||||
deeplink:
|
||||
host: deeplink-app
|
||||
port: "9090"
|
||||
|
||||
user:
|
||||
host: user-app
|
||||
port: "9090"
|
||||
23
charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
||||
# Patterns to ignore when building packages.
|
||||
# This supports shell glob matching, relative path matching, and
|
||||
# negation (prefixed with !). Only one pattern per line.
|
||||
.DS_Store
|
||||
# Common VCS dirs
|
||||
.git/
|
||||
.gitignore
|
||||
.bzr/
|
||||
.bzrignore
|
||||
.hg/
|
||||
.hgignore
|
||||
.svn/
|
||||
# Common backup files
|
||||
*.swp
|
||||
*.bak
|
||||
*.tmp
|
||||
*.orig
|
||||
*~
|
||||
# Various IDEs
|
||||
.project
|
||||
.idea/
|
||||
*.tmproj
|
||||
.vscode/
|
||||
8
charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml
Executable file
8
charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,8 @@
|
||||
apiVersion: v2
|
||||
name: gem-call-events-handler-app
|
||||
description: A Helm chart for gem-call-events-handler-app
|
||||
|
||||
type: application
|
||||
|
||||
version: 0.1.0
|
||||
appVersion: "1.0.0"
|
||||
15
charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl
Executable file
15
charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,15 @@
|
||||
{{- define "gem-call-events-handler-app.name" -}}
|
||||
gem-call-events-handler-app
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gem-call-events-handler-app.fullname" -}}
|
||||
{{- .Release.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gem-call-events-handler-app.labels" -}}
|
||||
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
app.kubernetes.io/version: {{ .Chart.Version }}
|
||||
app.kubernetes.io/component: gem-call-events-handler-app
|
||||
app.kubernetes.io/part-of: gem-call-events-handler-app
|
||||
{{- end -}}
|
||||
@ -0,0 +1,92 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "gem-call-events-handler-app.fullname" . }}
|
||||
labels:
|
||||
{{- include "gem-call-events-handler-app.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
spec:
|
||||
volumes:
|
||||
- name: ca-cert
|
||||
configMap:
|
||||
name: auth-app-ca-cert
|
||||
items:
|
||||
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||
- name: cacerts-volume
|
||||
emptyDir: {}
|
||||
initContainers:
|
||||
- name: import-ca
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CERT_ALIAS
|
||||
value: {{ .Values.env.cert_alias | quote }}
|
||||
volumeMounts:
|
||||
- name: ca-cert
|
||||
mountPath: /app/resources
|
||||
- name: cacerts-volume
|
||||
mountPath: /tmp/cacerts
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||
-alias gemcert \
|
||||
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||
-keystore /tmp/cacerts/cacerts
|
||||
containers:
|
||||
- name: gem-call-events-handler-app
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
env:
|
||||
- name: CASSANDRA_CONTACTPOINT
|
||||
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||
- name: CASSANDRA_DATACENTER
|
||||
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||
- name: CASSANDRA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra }}
|
||||
key: username
|
||||
- name: CASSANDRA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.cassandra }}
|
||||
key: cassandra-password
|
||||
- name: KAFKA
|
||||
value: {{ .Values.env.kafka.brokers | quote }}
|
||||
- name: KAFKA_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka }}
|
||||
key: username
|
||||
- name: KAFKA_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.secrets.kafka }}
|
||||
key: client-passwords
|
||||
- name: KEYCLOAK_URL
|
||||
value: {{ .Values.keycloak.url | quote }}
|
||||
- name: REDIS_HOST
|
||||
value: {{ .Values.redis.host | quote }}
|
||||
- name: REDIS_PORT
|
||||
value: {{ .Values.redis.port | quote }}
|
||||
- name: CHAT_HOST
|
||||
value: {{ .Values.chat.host | quote }}
|
||||
- name: CHAT_PORT
|
||||
value: {{ .Values.chat.port | quote }}
|
||||
volumeMounts:
|
||||
- name: cacerts-volume
|
||||
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||
subPath: cacerts
|
||||
restartPolicy: Always
|
||||
19
charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml
Executable file
19
charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,19 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "gem-call-events-handler-app.fullname" . }}
|
||||
labels:
|
||||
app: {{ .Release.Name }}
|
||||
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||
release: {{ .Release.Name }}
|
||||
heritage: {{ .Release.Service }}
|
||||
spec:
|
||||
ports:
|
||||
- name: "8089"
|
||||
port: 8089
|
||||
targetPort: 9090
|
||||
- name: "5089"
|
||||
port: 5089
|
||||
targetPort: 5005
|
||||
selector:
|
||||
io.kompose.service: gem-call-events-handler-app
|
||||
32
charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml
Executable file
32
charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,32 @@
|
||||
replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: "registry.co-work.ru/gem-call-events-handler-app"
|
||||
tag: "1.0.0-SNAPSHOT"
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
env:
|
||||
cassandra:
|
||||
contactPoint: "cassandra.cassandra.svc.cluster.local"
|
||||
datacenter: "datacenter1"
|
||||
kafka:
|
||||
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||
|
||||
keycloak:
|
||||
url: "https://iam.nubes.ru/realms/cowork"
|
||||
|
||||
redis:
|
||||
host: "redis-master.redis.svc.cluster.local"
|
||||
port: "6379"
|
||||
|
||||
secrets:
|
||||
cassandra: cassandra
|
||||
kafka: kafka-password
|
||||
chat:
|
||||
host: "chat-app"
|
||||
port: "9090"
|
||||
|
||||
additionalEnv: []
|
||||
|
||||
podAnnotations: {}
|
||||
podLabels: {}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user