added files from backend
This commit is contained in:
parent
4205bf2e7b
commit
fba2ed5fe4
18
argo-infra-apps/backend-apps.yaml
Executable file
18
argo-infra-apps/backend-apps.yaml
Executable file
@ -0,0 +1,18 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: backend-apps
|
||||||
|
namespace: argocd
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
source:
|
||||||
|
repoURL: https://gitlab.ii-p001.local/cw-devops/cw-infra-apps-nubes.git
|
||||||
|
targetRevision: main
|
||||||
|
path: charts/backend
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
namespace: backend
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
67
charts/backend/Chart.yaml
Executable file
67
charts/backend/Chart.yaml
Executable file
@ -0,0 +1,67 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: umbrella-chart
|
||||||
|
description: A Helm umbrella chart to deploy multiple microservices with shared config
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: 1.0.0
|
||||||
|
dependencies:
|
||||||
|
- name: auth-event-handler-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/auth-event-handler-app-k8s
|
||||||
|
- name: chat-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/chat-app-k8s
|
||||||
|
- name: auth-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/auth-app-k8s
|
||||||
|
- name: message-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/message-app-k8s
|
||||||
|
- name: user-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/user-app-k8s
|
||||||
|
- name: notification-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/notification-app-k8s
|
||||||
|
- name: search-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/search-app-k8s
|
||||||
|
- name: call-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/call-app-k8s
|
||||||
|
- name: workspace-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/workspace-app-k8s
|
||||||
|
- name: realtime-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/realtime-app-k8s
|
||||||
|
- name: web-sender-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/web-sender-app-k8s
|
||||||
|
- name: bff-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/bff-app-k8s
|
||||||
|
- name: upload-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/upload-app-k8s
|
||||||
|
- name: deeplink-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/deeplink-app-k8s
|
||||||
|
- name: livekit-webhook-handler-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/livekit-webhook-handler-app-k8s
|
||||||
|
- name: ios-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/ios-app-k8s
|
||||||
|
- name: android-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/android-app-k8s
|
||||||
|
- name: desktop-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/desktop-app-k8s
|
||||||
|
- name: huawei-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/huawei-app-k8s
|
||||||
|
- name: safari-app-k8s
|
||||||
|
version: 0.1.0
|
||||||
|
repository: file://charts/safari-app-k8s
|
||||||
23
charts/backend/charts/admin-app-k8s/.helmignore
Executable file
23
charts/backend/charts/admin-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/admin-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/admin-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: admin-app
|
||||||
|
description: Helm chart for Admin app
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/admin-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/admin-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "admin-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "admin-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "admin-app.fullname" -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "admin-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
65
charts/backend/charts/admin-app-k8s/templates/deployment.yaml
Executable file
65
charts/backend/charts/admin-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,65 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "admin-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "admin-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: admin-app
|
||||||
|
ports:
|
||||||
|
- containerPort: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: WORKSPACE_HOST
|
||||||
|
value: "{{ .Values.env.workspace_host }}"
|
||||||
|
- name: WORKSPACE_PORT
|
||||||
|
value: "{{ .Values.env.workspace_port }}"
|
||||||
|
- name: USER_HOST
|
||||||
|
value: "{{ .Values.env.user_host }}"
|
||||||
|
- name: USER_PORT
|
||||||
|
value: "{{ .Values.env.user_port }}"
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
15
charts/backend/charts/admin-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/admin-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "admin-app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
16
charts/backend/charts/admin-app-k8s/values.yaml
Executable file
16
charts/backend/charts/admin-app-k8s/values.yaml
Executable file
@ -0,0 +1,16 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/admin-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
env:
|
||||||
|
workspace_host: workspace-app
|
||||||
|
workspace_port: 9090
|
||||||
|
user_host: user-app
|
||||||
|
user_port: 9090
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
23
charts/backend/charts/android-app-k8s/.helmignore
Executable file
23
charts/backend/charts/android-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/android-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/android-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: android-sender-app
|
||||||
|
description: Helm chart for Android Sender Application
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/android-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/android-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "android-sender-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "android-sender-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "android-sender-app.fullname" -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "android-sender-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "android-sender-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
72
charts/backend/charts/android-app-k8s/templates/deployment.yaml
Executable file
72
charts/backend/charts/android-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,72 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "android-sender-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "android-sender-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "android-sender-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "android-sender-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: android-sender
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: KAFKA_SERVER
|
||||||
|
value: {{ .Values.env.kafkaServers }}
|
||||||
|
- name: KAFKA_USER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafkaSecret }}
|
||||||
|
key: username
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafkaSecret }}
|
||||||
|
key: client-passwords
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.redisHost }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.env.redisPort | quote }}
|
||||||
|
- name: ANDROID_FIREBASE_CONFIG
|
||||||
|
value: {{ .Values.env.android_firebase_config }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
16
charts/backend/charts/android-app-k8s/values.yaml
Executable file
16
charts/backend/charts/android-app-k8s/values.yaml
Executable file
@ -0,0 +1,16 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/android-sender-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
env:
|
||||||
|
kafkaServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
redisHost: redis-master.redis.svc.cluster.local
|
||||||
|
redisPort: 6379
|
||||||
|
android_firebase_config: "cowork-prod-firebase-adminsdk-l136z-648992e82d.json"
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
kafkaSecret: kafka-password
|
||||||
|
firebaseSecret: android-firebase-config
|
||||||
23
charts/backend/charts/auth-app-k8s/.helmignore
Executable file
23
charts/backend/charts/auth-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/auth-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/auth-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: auth-app-k8s
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
62
charts/backend/charts/auth-app-k8s/templates/_helpers.tpl
Executable file
62
charts/backend/charts/auth-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,62 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "auth-app-k8s.chart" . }}
|
||||||
|
{{ include "auth-app-k8s.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "auth-app-k8s.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "auth-app-k8s.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "auth-app-k8s.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
103
charts/backend/charts/auth-app-k8s/templates/deployment.yaml
Executable file
103
charts/backend/charts/auth-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,103 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||||
|
io.kompose.service: auth-app
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "auth-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
io.kompose.service: auth-app
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: {{ include "auth-app-k8s.fullname" . }}-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: auth-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: {{ .Values.service.targetPort }}
|
||||||
|
{{- if .Values.service.hostPort }}
|
||||||
|
hostPort: {{ .Values.service.hostPort }}
|
||||||
|
{{- end }}
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: ADMIN_CLIENT_ID
|
||||||
|
value: {{ .Values.env.adminClientId | quote }}
|
||||||
|
- name: ADMIN_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.adminPassword.name }}
|
||||||
|
key: {{ .Values.secrets.adminPassword.key }}
|
||||||
|
- name: ADMIN_REALM
|
||||||
|
value: {{ .Values.env.adminRealm | quote }}
|
||||||
|
- name: ADMIN_URL
|
||||||
|
value: {{ .Values.env.adminUrl | quote }}
|
||||||
|
- name: ADMIN_USERNAME
|
||||||
|
value: {{ .Values.env.adminUsername | quote }}
|
||||||
|
- name: CLIENT_ID
|
||||||
|
value: {{ .Values.env.clientId | quote }}
|
||||||
|
- name: CLIENT_ISSUER_IRI
|
||||||
|
value: {{ .Values.env.clientIssuerIri | quote }}
|
||||||
|
- name: CLIENT_REALM
|
||||||
|
value: {{ .Values.env.clientRealm | quote }}
|
||||||
|
- name: CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.clientSecret.name }}
|
||||||
|
key: {{ .Values.secrets.clientSecret.key }}
|
||||||
|
- name: REALM
|
||||||
|
value: {{ .Values.env.realm | quote }}
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
- name: SECURITY_ADMIN_REALM
|
||||||
|
value: {{ .Values.env.securityAdminRealm | quote }}
|
||||||
|
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
|
||||||
|
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
15
charts/backend/charts/auth-app-k8s/templates/service.yaml
Executable file
15
charts/backend/charts/auth-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
{{- include "auth-app-k8s.selectorLabels" . | nindent 4 }}
|
||||||
|
io.kompose.service: auth-app
|
||||||
15
charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml
Executable file
15
charts/backend/charts/auth-app-k8s/templates/tests/test-connection.yaml
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "auth-app-k8s.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "auth-app-k8s.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "auth-app-k8s.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
||||||
58
charts/backend/charts/auth-app-k8s/values.yaml
Executable file
58
charts/backend/charts/auth-app-k8s/values.yaml
Executable file
@ -0,0 +1,58 @@
|
|||||||
|
|
||||||
|
fullnameOverride: "auth-app"
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/auth-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
hostPort: null
|
||||||
|
|
||||||
|
env:
|
||||||
|
cert_alias: co-work
|
||||||
|
adminClientId: "admin-cli"
|
||||||
|
adminRealm: "master"
|
||||||
|
adminUrl: "https://iam.nubes.ru/admin/realms/cowork"
|
||||||
|
adminUsername: "admin"
|
||||||
|
clientId: "gem-auth-client"
|
||||||
|
clientIssuerIri: "https://iam.nubes.ru/realms/cowork"
|
||||||
|
clientRealm: "cowork"
|
||||||
|
realm: "cowork"
|
||||||
|
securityAdminRealm: "master"
|
||||||
|
securityOauth2ClientIssuerUri: "https://iam.nubes.ru/realms"
|
||||||
|
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
adminPassword:
|
||||||
|
name: auth-secrets
|
||||||
|
key: admin-password
|
||||||
|
clientSecret:
|
||||||
|
name: auth-secrets
|
||||||
|
key: client-secret
|
||||||
|
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 512Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 256Mi
|
||||||
|
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/auth-app.yml -o k8s/auth-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: auth-app
|
||||||
|
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
23
charts/backend/charts/auth-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/auth-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/auth-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: auth-event-handler-app-k8s
|
||||||
|
description: Authentication Event Handler
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
23
charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl
Executable file
23
charts/backend/charts/auth-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
{{/* Common Name Definitions */}}
|
||||||
|
{{- define "auth-event-handler-app-k8s.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Standard labels */}}
|
||||||
|
{{- define "auth-event-handler-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "auth-event-handler-app-k8s.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
141
charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml
Executable file
141
charts/backend/charts/auth-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,141 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.labels" . | nindent 8 }}
|
||||||
|
{{- with .Values.podLabels }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
serviceAccountName: {{ .Values.serviceAccount.name | default (include "auth-event-handler-app-k8s.serviceAccountName" .) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
{{- with .Values.volumes }}
|
||||||
|
{{ toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: ADMIN_CLIENT_ID
|
||||||
|
value: {{ .Values.env.adminClientId | quote }}
|
||||||
|
- name: ADMIN_REALM
|
||||||
|
value: {{ .Values.env.adminRealm | quote }}
|
||||||
|
- name: ADMIN_URL
|
||||||
|
value: {{ .Values.env.adminUrl | quote }}
|
||||||
|
- name: ADMIN_USERNAME
|
||||||
|
value: {{ .Values.env.adminUsername | quote }}
|
||||||
|
- name: CLIENT_ID
|
||||||
|
value: {{ .Values.env.clientId | quote }}
|
||||||
|
- name: CLIENT_ISSUER_IRI
|
||||||
|
value: {{ .Values.env.clientIssuerIri | quote }}
|
||||||
|
- name: CLIENT_REALM
|
||||||
|
value: {{ .Values.env.clientRealm | quote }}
|
||||||
|
- name: REALM
|
||||||
|
value: {{ .Values.env.realm | quote }}
|
||||||
|
- name: SECURITY_ADMIN_REALM
|
||||||
|
value: {{ .Values.env.securityAdminRealm | quote }}
|
||||||
|
- name: SECURITY_OAUTH2_CLIENT_ISSUER_URI
|
||||||
|
value: {{ .Values.env.securityOauth2ClientIssuerUri | quote }}
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.kafkaBrokers | quote }}
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
value: {{ .Values.secrets.kafka.username | quote }}
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||||
|
- name: ADMIN_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.adminPassword.name }}
|
||||||
|
key: {{ .Values.secrets.adminPassword.key }}
|
||||||
|
- name: CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.clientSecret.name }}
|
||||||
|
key: {{ .Values.secrets.clientSecret.key }}
|
||||||
|
livenessProbe:
|
||||||
|
{{- toYaml .Values.livenessProbe | nindent 12 }}
|
||||||
|
readinessProbe:
|
||||||
|
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
{{- with .Values.volumeMounts }}
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
12
charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml
Executable file
12
charts/backend/charts/auth-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,12 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "auth-event-handler-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "auth-event-handler-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
selector:
|
||||||
|
{{- include "auth-event-handler-app-k8s.selectorLabels" . | nindent 4 }}
|
||||||
60
charts/backend/charts/auth-event-handler-app-k8s/values.yaml
Executable file
60
charts/backend/charts/auth-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,60 @@
|
|||||||
|
fullnameOverride: "auth-event-handler-app"
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/auth-event-handler-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 8094
|
||||||
|
targetPort: 9090
|
||||||
|
env:
|
||||||
|
adminClientId: "admin-cli"
|
||||||
|
adminRealm: "master"
|
||||||
|
adminUrl: "https://iam.nubes.ru/admin/realms/cowork"
|
||||||
|
adminUsername: "admin"
|
||||||
|
clientId: "gem-auth-client"
|
||||||
|
clientIssuerIri: "https://iam.nubes.ru/realms/cowork"
|
||||||
|
clientRealm: "cowork"
|
||||||
|
realm: "cowork"
|
||||||
|
securityAdminRealm: "master"
|
||||||
|
securityOauth2ClientIssuerUri: "https://iam.nubes.ru/realms"
|
||||||
|
kafkaBrokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
secrets:
|
||||||
|
kafka:
|
||||||
|
name: kafka-password
|
||||||
|
passwordKey: client-passwords
|
||||||
|
username: admin
|
||||||
|
adminPassword:
|
||||||
|
name: auth-secrets
|
||||||
|
key: admin-password
|
||||||
|
clientSecret:
|
||||||
|
name: auth-secrets
|
||||||
|
key: client-secret
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 512Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 256Mi
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/auth-event-handler-app.yml -o k8s/auth-event-handler-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: auth-event-handler-app
|
||||||
|
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
securityContext: {}
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
create: false
|
||||||
|
name: ""
|
||||||
23
charts/backend/charts/bff-admin-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-admin-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/bff-admin-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/bff-admin-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: bff-admin-app
|
||||||
|
description: Helm chart for bff-admin-app
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/bff-admin-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "bff-admin-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "bff-admin-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "bff-admin-app.fullname" -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "bff-admin-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "bff-admin-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
39
charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml
Executable file
39
charts/backend/charts/bff-admin-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,39 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "bff-admin-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "bff-admin-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: bff-admin-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: SWAGGER_HOST
|
||||||
|
value: "{{ .Values.env.swagger_host }}"
|
||||||
|
- name: SWAGGER_PORT
|
||||||
|
value: "{{ .Values.env.swagger_port }}"
|
||||||
|
- name: WORKSPACE_HOST
|
||||||
|
value: "{{ .Values.env.workspace_host }}"
|
||||||
|
- name: WORKSPACE_PORT
|
||||||
|
value: "{{ .Values.env.workspace_port }}"
|
||||||
|
- name: USER_HOST
|
||||||
|
value: "{{ .Values.env.user_host }}"
|
||||||
|
- name: USER_PORT
|
||||||
|
value: "{{ .Values.env.user_port }}"
|
||||||
|
- name: ADMIN_HOST
|
||||||
|
value: "{{ .Values.env.admin_host }}"
|
||||||
|
- name: ADMIN_PORT
|
||||||
|
value: "{{ .Values.env.admin_port }}"
|
||||||
|
- name: APP_NAME
|
||||||
|
value: "{{ .Values.env.app_name }}"
|
||||||
38
charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml
Executable file
38
charts/backend/charts/bff-admin-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,38 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ .Values.ingress.name }}
|
||||||
|
namespace: {{ .Release.Namespace | default "default" }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
{{- range .paths }}
|
||||||
|
- path: {{ .path }}
|
||||||
|
pathType: {{ .pathType }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $.Values.env.app_name }}
|
||||||
|
port:
|
||||||
|
number: {{ $.Values.service.httpPort }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
17
charts/backend/charts/bff-admin-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/bff-admin-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-admin-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-admin-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "bff-admin-app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
{{- range .Values.service.ports }}
|
||||||
|
- name: {{ .name }}
|
||||||
|
port: {{ .port }}
|
||||||
|
targetPort: {{ .targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
46
charts/backend/charts/bff-admin-app-k8s/values.yaml
Executable file
46
charts/backend/charts/bff-admin-app-k8s/values.yaml
Executable file
@ -0,0 +1,46 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/bff-admin-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
env:
|
||||||
|
swagger_host: "localhost"
|
||||||
|
swagger_port: 8080
|
||||||
|
workspace_host: "workspace-app"
|
||||||
|
workspace_port: 9090
|
||||||
|
user_host: "user-app"
|
||||||
|
user_port: 9090
|
||||||
|
admin_host: "admin-app"
|
||||||
|
admin_port: 9090
|
||||||
|
app_name: bff-admin-app
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
httpPort: 8100
|
||||||
|
grpcPort: 8101
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 8100 # Changed from templated value to static
|
||||||
|
targetPort: 8080
|
||||||
|
- name: grpc
|
||||||
|
port: 8101 # Changed from templated value to static
|
||||||
|
targetPort: 9090
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: nginx
|
||||||
|
name: bff-admin-ingress
|
||||||
|
annotations:
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||||
|
hosts:
|
||||||
|
- host: api-adm-p001.cw.ngcloud.ru
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- api-adm-p001.cw.ngcloud.ru
|
||||||
|
secretName: co-work-secret
|
||||||
23
charts/backend/charts/bff-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/bff-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/bff-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: bff-app-k8s
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
23
charts/backend/charts/bff-app-k8s/templates/_helpers.tpl
Executable file
23
charts/backend/charts/bff-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
{{/* Common Name Definitions */}}
|
||||||
|
{{- define "bff-app-k8s.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Standard labels */}}
|
||||||
|
{{- define "bff-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "bff-app-k8s.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
93
charts/backend/charts/bff-app-k8s/templates/deployment.yaml
Executable file
93
charts/backend/charts/bff-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,93 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "bff-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-app-k8s.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
# initContainers:
|
||||||
|
# - name: import-ca
|
||||||
|
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
# env:
|
||||||
|
# - name: CERT_ALIAS
|
||||||
|
# value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
# volumeMounts:
|
||||||
|
# - name: ca-cert
|
||||||
|
# mountPath: /app/resources
|
||||||
|
# - name: cacerts-volume
|
||||||
|
# mountPath: /tmp/cacerts
|
||||||
|
# command:
|
||||||
|
# - sh
|
||||||
|
# - -c
|
||||||
|
# - |
|
||||||
|
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
# keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
# -alias gemcert \
|
||||||
|
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
# -keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: bff-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: {{ .Values.service.targetPort }}
|
||||||
|
{{- if .Values.service.hostPort }}
|
||||||
|
hostPort: {{ .Values.service.hostPort }}
|
||||||
|
{{- end }}
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: GRPC_CLIENT_AUTH_URL
|
||||||
|
value: {{ .Values.env.services.auth | quote }}
|
||||||
|
- name: GRPC_CLIENT_CHAT_URL
|
||||||
|
value: {{ .Values.env.services.chat | quote }}
|
||||||
|
- name: GRPC_CLIENT_CONFIG_URL
|
||||||
|
value: {{ .Values.env.services.user | quote }}
|
||||||
|
- name: GRPC_CLIENT_DEEPLINK_URL
|
||||||
|
value: {{ .Values.env.services.deeplink | quote }}
|
||||||
|
- name: GRPC_CLIENT_GEM_CALL_URL
|
||||||
|
value: {{ .Values.env.services.gemCall | quote }}
|
||||||
|
- name: GRPC_CLIENT_MESSAGE_URL
|
||||||
|
value: {{ .Values.env.services.message | quote }}
|
||||||
|
- name: GRPC_CLIENT_NOTIFICATIONS_URL
|
||||||
|
value: {{ .Values.env.services.notification | quote }}
|
||||||
|
- name: GRPC_CLIENT_REACTION_URL
|
||||||
|
value: {{ .Values.env.services.message | quote }}
|
||||||
|
- name: GRPC_CLIENT_REALTIME_URL
|
||||||
|
value: {{ .Values.env.services.realtime | quote }}
|
||||||
|
- name: GRPC_CLIENT_SEARCH_URL
|
||||||
|
value: {{ .Values.env.services.search | quote }}
|
||||||
|
- name: GRPC_CLIENT_STICKER_URL
|
||||||
|
value: {{ .Values.env.services.sticker | quote }}
|
||||||
|
- name: GRPC_CLIENT_UPLOAD_URL
|
||||||
|
value: {{ .Values.env.services.upload | quote }}
|
||||||
|
- name: GRPC_CLIENT_USER_URL
|
||||||
|
value: {{ .Values.env.services.user | quote }}
|
||||||
|
- name: GRPC_CLIENT_WORKSPACE_URL
|
||||||
|
value: {{ .Values.env.services.workspace | quote }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
28
charts/backend/charts/bff-app-k8s/templates/ingress.yaml
Executable file
28
charts/backend/charts/bff-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ .Values.ingress.name }}
|
||||||
|
namespace: {{ .Release.Namespace | default "default" }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- {{ .Values.ingress.host | quote }}
|
||||||
|
secretName: {{ .Values.ingress.tlsSecret | quote }}
|
||||||
|
rules:
|
||||||
|
- host: {{ .Values.ingress.host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: {{ .Values.ingress.path }}
|
||||||
|
pathType: {{ .Values.ingress.pathType }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ .Values.service.name }}
|
||||||
|
port:
|
||||||
|
number: {{ .Values.service.port }}
|
||||||
|
{{- end }}
|
||||||
14
charts/backend/charts/bff-app-k8s/templates/service.yaml
Executable file
14
charts/backend/charts/bff-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
{{- include "bff-app-k8s.selectorLabels" . | nindent 4 }}
|
||||||
58
charts/backend/charts/bff-app-k8s/values.yaml
Executable file
58
charts/backend/charts/bff-app-k8s/values.yaml
Executable file
@ -0,0 +1,58 @@
|
|||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/bff-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 8081
|
||||||
|
targetPort: 8080
|
||||||
|
nodePort: 31754
|
||||||
|
name: bff-app # Added service name
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: nginx
|
||||||
|
name: bff-app-ingress
|
||||||
|
host: api-p001.cw.ngcloud.ru
|
||||||
|
annotations:
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tlsSecret: co-work-secret
|
||||||
|
|
||||||
|
env:
|
||||||
|
services:
|
||||||
|
auth: http://auth-app:9090
|
||||||
|
chat: http://chat-app:9090
|
||||||
|
user: http://user-app:9090
|
||||||
|
deeplink: http://deeplink-app:9090
|
||||||
|
gemCall: http://gem-call-app:9090
|
||||||
|
message: http://message-app:9090
|
||||||
|
notification: http://notification-app:9090
|
||||||
|
realtime: http://realtime-app:9090
|
||||||
|
search: http://search-app:9090
|
||||||
|
sticker: http://sticker-app:9090
|
||||||
|
upload: http://upload-app:9090
|
||||||
|
workspace: http://workspace-app:9090
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 1Gi
|
||||||
|
requests:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 512Mi
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/bff-app.yml -o k8s/bff-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: bff-app
|
||||||
|
|
||||||
|
fullnameOverride: "bff-app"
|
||||||
23
charts/backend/charts/bff-vcs-app-k8s/.helmignore
Executable file
23
charts/backend/charts/bff-vcs-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/bff-vcs-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/bff-vcs-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: bff-vcs-app
|
||||||
|
description: Helm chart for bff-vcs-app
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
24
charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl
Executable file
24
charts/backend/charts/bff-vcs-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "bff-vcs-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Name */}}
|
||||||
|
{{- define "bff-vcs-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Fullname */}}
|
||||||
|
{{- define "bff-vcs-app.fullname" -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "bff-vcs-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "bff-vcs-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
58
charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml
Executable file
58
charts/backend/charts/bff-vcs-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,58 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-vcs-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-vcs-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "bff-vcs-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "bff-vcs-app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
# initContainers:
|
||||||
|
# - name: import-ca
|
||||||
|
# image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
# env:
|
||||||
|
# - name: CERT_ALIAS
|
||||||
|
# value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
# volumeMounts:
|
||||||
|
# - name: ca-cert
|
||||||
|
# mountPath: /app/resources
|
||||||
|
# - name: cacerts-volume
|
||||||
|
# mountPath: /tmp/cacerts
|
||||||
|
# command:
|
||||||
|
# - sh
|
||||||
|
# - -c
|
||||||
|
# - |
|
||||||
|
# cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
# keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
# -alias gemcert \
|
||||||
|
# -file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
# -keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: bff-vcs-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: GRPC_CLIENT_CALL_URL
|
||||||
|
value: "{{ .Values.env.grpc_client_call_url }}"
|
||||||
|
- name: GRPC_CLIENT_CALL_REALTIME_URL
|
||||||
|
value: "{{ .Values.env.grpc_client_call_realtime_url }}"
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
28
charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml
Executable file
28
charts/backend/charts/bff-vcs-app-k8s/templates/ingress.yaml
Executable file
@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.ingress.enabled }}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-vcs-app.fullname" . }}-ingress
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
annotations:
|
||||||
|
{{- range $key, $value := .Values.ingress.annotations }}
|
||||||
|
{{ $key }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
ingressClassName: {{ .Values.ingress.ingressClassName }}
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- {{ .Values.ingress.host }}
|
||||||
|
secretName: {{ .Values.ingress.tlsSecretName }}
|
||||||
|
rules:
|
||||||
|
- host: {{ .Values.ingress.host }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ include "bff-vcs-app.fullname" . }}
|
||||||
|
port:
|
||||||
|
number: {{ .Values.service.port }}
|
||||||
|
{{- end }}
|
||||||
16
charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml
Executable file
16
charts/backend/charts/bff-vcs-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "bff-vcs-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "bff-vcs-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "bff-vcs-app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.service.targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
|
||||||
25
charts/backend/charts/bff-vcs-app-k8s/values.yaml
Executable file
25
charts/backend/charts/bff-vcs-app-k8s/values.yaml
Executable file
@ -0,0 +1,25 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: pibff-vcs-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
env:
|
||||||
|
grpc_client_call_url: http://call-realtime-app:9090
|
||||||
|
grpc_client_call_realtime_url: http://call-realtime-app:9090
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 8079
|
||||||
|
targetPort: 8080
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
ingressClassName: nginx
|
||||||
|
host: api-vcs-p001.cw.ngcloud.ru
|
||||||
|
tlsSecretName: co-work-secret
|
||||||
|
annotations:
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
|
||||||
23
charts/backend/charts/big-chat-splitter-app-k8s/.helmignore
Executable file
23
charts/backend/charts/big-chat-splitter-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/big-chat-splitter-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: big-chat-splitter-app-k8s
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
22
charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl
Executable file
22
charts/backend/charts/big-chat-splitter-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,22 @@
|
|||||||
|
{{/* Common Name Definitions */}}
|
||||||
|
{{- define "big-chat-splitter-app-k8s.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Standard labels */}}
|
||||||
|
{{- define "big-chat-splitter-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "big-chat-splitter-app-k8s.selectorLabels" -}}
|
||||||
|
io.kompose.service: big-chat-splitter-app
|
||||||
|
{{- end }}
|
||||||
86
charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml
Executable file
86
charts/backend/charts/big-chat-splitter-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,86 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "big-chat-splitter-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "big-chat-splitter-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "big-chat-splitter-app-k8s.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: big-chat-splitter-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: CASSANDRA_DC
|
||||||
|
value: {{ .Values.env.cassandra.dc | quote }}
|
||||||
|
- name: CASSANDRA_HOST
|
||||||
|
value: {{ .Values.env.cassandra.host | quote }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
value: {{ .Values.secrets.cassandra.username | quote }}
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||||
|
- name: CHAT_SERVICE_HOST
|
||||||
|
value: {{ .Values.env.services.chat.host | quote }}
|
||||||
|
- name: CHAT_SERVICE_PORT
|
||||||
|
value: {{ .Values.env.services.chat.port | quote }}
|
||||||
|
- name: KAFKA_USER
|
||||||
|
value: {{ .Values.secrets.kafka.username | quote }}
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||||
|
- name: KAFKA_SERVER
|
||||||
|
value: {{ .Values.env.kafka.servers | quote }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.redis.host | quote }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.env.redis.port | quote }}
|
||||||
|
- name: USER_SERVICE_HOST
|
||||||
|
value: {{ .Values.env.services.user.host | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
54
charts/backend/charts/big-chat-splitter-app-k8s/values.yaml
Executable file
54
charts/backend/charts/big-chat-splitter-app-k8s/values.yaml
Executable file
@ -0,0 +1,54 @@
|
|||||||
|
|
||||||
|
fullnameOverride: "big-chat-splitter-app"
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/big-chat-splitter-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
replicaCount: 1
|
||||||
|
env:
|
||||||
|
cassandra:
|
||||||
|
dc: datacenter1
|
||||||
|
host: "cassandra.cassandra.svc.cluster.local"
|
||||||
|
services:
|
||||||
|
chat:
|
||||||
|
host: chat-app
|
||||||
|
port: 9090
|
||||||
|
user:
|
||||||
|
host: user-app
|
||||||
|
port: 9090
|
||||||
|
redis:
|
||||||
|
host: redis-master.redis.svc.cluster.local
|
||||||
|
port: 6379
|
||||||
|
kafka:
|
||||||
|
servers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
cassandra:
|
||||||
|
name: cassandra
|
||||||
|
passwordKey: cassandra-password
|
||||||
|
username: cassandra
|
||||||
|
|
||||||
|
kafka:
|
||||||
|
name: kafka-password
|
||||||
|
passwordKey: client-passwords
|
||||||
|
username: admin
|
||||||
|
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 1Gi
|
||||||
|
requests:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 512Mi
|
||||||
|
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/big-chat-splitter-app.yml -o k8s/big-chat-splitter-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: big-chat-splitter-app
|
||||||
|
|
||||||
|
|
||||||
|
fullnameOverride: "big-chat-splitter-app"
|
||||||
23
charts/backend/charts/call-app-k8s/.helmignore
Executable file
23
charts/backend/charts/call-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/call-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/call-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: call-app-k8s
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
22
charts/backend/charts/call-app-k8s/templates/_helpers.tpl
Executable file
22
charts/backend/charts/call-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,22 @@
|
|||||||
|
{{/* Common Name Definitions */}}
|
||||||
|
{{- define "call-app-k8s.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Standard labels */}}
|
||||||
|
{{- define "call-app-k8s.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Selector labels */}}
|
||||||
|
{{- define "call-app-k8s.selectorLabels" -}}
|
||||||
|
io.kompose.service: call-app
|
||||||
|
{{- end }}
|
||||||
131
charts/backend/charts/call-app-k8s/templates/deployment.yaml
Executable file
131
charts/backend/charts/call-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,131 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "call-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "call-app-k8s.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-app-k8s.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: call-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: 5005
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 5005
|
||||||
|
- containerPort: 9090
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 9090
|
||||||
|
env:
|
||||||
|
- name: TENANT_ID
|
||||||
|
value: {{ .Values.env.TENANT_ID | quote }}
|
||||||
|
- name: CASSANDRA_CONTACTPOINT
|
||||||
|
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.usernameKey }}
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.kafka.brokers | quote }}
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.usernameKey }}
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||||
|
- name: KEYCLOAK_URL
|
||||||
|
value: {{ .Values.env.keycloak.url | quote }}
|
||||||
|
- name: LIVEKIT_API_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.livekit.name }}
|
||||||
|
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
||||||
|
- name: LIVEKIT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.livekit.name }}
|
||||||
|
key: {{ .Values.secrets.livekit.secretKey }}
|
||||||
|
- name: RECORDING_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.recording.name }}
|
||||||
|
key: {{ .Values.secrets.recording.accessKeyKey }}
|
||||||
|
- name: RECORDING_API_HOST
|
||||||
|
value: {{ .Values.env.livekit.apiHost | quote }}
|
||||||
|
- name: RECORDING_BUCKET
|
||||||
|
value: {{ .Values.env.recording.bucket | quote }}
|
||||||
|
- name: RECORDING_ENDPOINT
|
||||||
|
value: {{ .Values.env.recording.endpoint | quote }}
|
||||||
|
- name: RECORDING_REGION
|
||||||
|
value: {{ .Values.env.recording.region | quote }}
|
||||||
|
- name: RECORDING_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.recording.name }}
|
||||||
|
key: {{ .Values.secrets.recording.secretKeyKey }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.redis.host | quote }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.env.redis.port | quote }}
|
||||||
|
- name: REDIS_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.redis.name }}
|
||||||
|
key: {{ .Values.secrets.redis.passwordKey }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
17
charts/backend/charts/call-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/call-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "call-app-k8s.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-app-k8s.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
{{- range .Values.service.ports }}
|
||||||
|
- name: {{ .name }}
|
||||||
|
port: {{ .port }}
|
||||||
|
targetPort: {{ .targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
{{- include "call-app-k8s.selectorLabels" . | nindent 4 }}
|
||||||
66
charts/backend/charts/call-app-k8s/values.yaml
Executable file
66
charts/backend/charts/call-app-k8s/values.yaml
Executable file
@ -0,0 +1,66 @@
|
|||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/call-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- name: main
|
||||||
|
port: 5005
|
||||||
|
targetPort: 5005
|
||||||
|
- name: metrics
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
env:
|
||||||
|
cassandra:
|
||||||
|
contactPoint: cassandra.cassandra.svc.cluster.local
|
||||||
|
datacenter: datacenter1
|
||||||
|
kafka:
|
||||||
|
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
redis:
|
||||||
|
host: redis-master.redis.svc.cluster.local
|
||||||
|
port: 6379
|
||||||
|
keycloak:
|
||||||
|
url: https://iam.nubes.ru/realms/cowork
|
||||||
|
livekit:
|
||||||
|
apiHost: https://av-p001.cw.ngcloud.ru
|
||||||
|
recording:
|
||||||
|
endpoint: https://store-p001.cw.ngcloud.ru:9000
|
||||||
|
region: us-east-2
|
||||||
|
bucket: livekit
|
||||||
|
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
cassandra:
|
||||||
|
name: cassandra
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: cassandra-password
|
||||||
|
kafka:
|
||||||
|
name: kafka-password
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: client-passwords
|
||||||
|
redis:
|
||||||
|
name: redis-kafka-user-passwords
|
||||||
|
passwordKey: client-passwords
|
||||||
|
livekit:
|
||||||
|
name: livekit-secret
|
||||||
|
apiKeyKey: api-key
|
||||||
|
secretKey: secret
|
||||||
|
recording:
|
||||||
|
name: recording-secret
|
||||||
|
accessKeyKey: access-key
|
||||||
|
secretKeyKey: secret
|
||||||
|
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/call-app.yml -o k8s/call-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: call-app
|
||||||
|
|
||||||
|
fullnameOverride: "call-app"
|
||||||
23
charts/backend/charts/call-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/call-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/call-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/call-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: call-event-handler-app
|
||||||
|
description: Call Event Handler Application
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0-SNAPSHOT"
|
||||||
46
charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl
Executable file
46
charts/backend/charts/call-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,46 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "call-event-handler-app.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
*/}}
|
||||||
|
{{- define "call-event-handler-app.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "call-event-handler-app.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "call-event-handler-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "call-event-handler-app.chart" . }}
|
||||||
|
{{ include "call-event-handler-app.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "call-event-handler-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "call-event-handler-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end -}}
|
||||||
111
charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml
Executable file
111
charts/backend/charts/call-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,111 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "call-event-handler-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-event-handler-app.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "call-event-handler-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-event-handler-app.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: 5005
|
||||||
|
protocol: TCP
|
||||||
|
- containerPort: 9090
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: CASSANDRA_CONTACTPOINT
|
||||||
|
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.usernameKey }}
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.kafka.brokers | quote }}
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.usernameKey }}
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||||
|
- name: LIVEKIT_API_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.livekit.name }}
|
||||||
|
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
||||||
|
- name: LIVEKIT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.livekit.name }}
|
||||||
|
key: {{ .Values.secrets.livekit.secretKey }}
|
||||||
|
- name: RECORDING_API_HOST
|
||||||
|
value: {{ .Values.env.recording.apiHost | quote }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.redis.host | quote }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.env.redis.port | quote }}
|
||||||
|
- name: REDIS_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.redis.name }}
|
||||||
|
key: {{ .Values.secrets.redis.passwordKey }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
17
charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/call-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "call-event-handler-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-event-handler-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
{{- range .Values.service.ports }}
|
||||||
|
- name: {{ .name }}
|
||||||
|
port: {{ .port }}
|
||||||
|
targetPort: {{ .targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
{{- include "call-event-handler-app.selectorLabels" . | nindent 4 }}
|
||||||
57
charts/backend/charts/call-event-handler-app-k8s/values.yaml
Executable file
57
charts/backend/charts/call-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,57 @@
|
|||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/call-event-handler-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- name: main
|
||||||
|
port: 5005
|
||||||
|
targetPort: 5005
|
||||||
|
- name: metrics
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
|
||||||
|
env:
|
||||||
|
cassandra:
|
||||||
|
contactPoint: cassandra.cassandra.svc.cluster.local
|
||||||
|
datacenter: datacenter1
|
||||||
|
kafka:
|
||||||
|
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
redis:
|
||||||
|
host: redis-master.redis.svc.cluster.local
|
||||||
|
port: "6379"
|
||||||
|
recording:
|
||||||
|
apiHost: https://store-p001.cw.ngcloud.ru:9000
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
cassandra:
|
||||||
|
name: cassandra
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: cassandra-password
|
||||||
|
kafka:
|
||||||
|
name: kafka-password
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: client-passwords
|
||||||
|
redis:
|
||||||
|
name: redis-kafka-user-passwords
|
||||||
|
passwordKey: client-passwords
|
||||||
|
livekit:
|
||||||
|
name: livekit-secret
|
||||||
|
apiKeyKey: api-key
|
||||||
|
secretKey: secret
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/call-event-handler-app.yml -o k8s/call-event-handler-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: call-event-handler-app
|
||||||
|
|
||||||
|
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
23
charts/backend/charts/call-realtime-app-k8s/.helmignore
Executable file
23
charts/backend/charts/call-realtime-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/call-realtime-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/call-realtime-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: call-realtime-app-k8s
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
39
charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl
Executable file
39
charts/backend/charts/call-realtime-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,39 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "call-realtime-app.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
*/}}
|
||||||
|
{{- define "call-realtime-app.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- printf "%s" $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "call-realtime-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "call-realtime-app.name" . }}
|
||||||
|
{{ include "call-realtime-app.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "call-realtime-app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "call-realtime-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end -}}
|
||||||
120
charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml
Executable file
120
charts/backend/charts/call-realtime-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,120 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "call-realtime-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-realtime-app.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "call-realtime-app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.podAnnotations | nindent 8 }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-realtime-app.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- toYaml .Values.podLabels | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: 5005
|
||||||
|
protocol: TCP
|
||||||
|
- containerPort: 9090
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: TENANT_ID
|
||||||
|
value: {{ .Values.env.TENANT_ID | quote }}
|
||||||
|
- name: CASSANDRA_CONTACTPOINT
|
||||||
|
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.usernameKey }}
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra.name }}
|
||||||
|
key: {{ .Values.secrets.cassandra.passwordKey }}
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.kafka.brokers | quote }}
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.usernameKey }}
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka.name }}
|
||||||
|
key: {{ .Values.secrets.kafka.passwordKey }}
|
||||||
|
- name: LIVEKIT_API_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.livekit.name }}
|
||||||
|
key: {{ .Values.secrets.livekit.apiKeyKey }}
|
||||||
|
- name: LIVEKIT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.livekit.name }}
|
||||||
|
key: {{ .Values.secrets.livekit.secretKey }}
|
||||||
|
- name: RECORDING_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.recording.name }}
|
||||||
|
key: {{ .Values.secrets.recording.accessKeyKey }}
|
||||||
|
- name: RECORDING_API_HOST
|
||||||
|
value: {{ .Values.env.recording.apiHost | quote }}
|
||||||
|
- name: RECORDING_BUCKET
|
||||||
|
value: {{ .Values.env.recording.bucket | quote }}
|
||||||
|
- name: RECORDING_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.recording.name }}
|
||||||
|
key: {{ .Values.secrets.recording.secretKey }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.redis.host | quote }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.env.redis.port | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
17
charts/backend/charts/call-realtime-app-k8s/templates/service.yaml
Executable file
17
charts/backend/charts/call-realtime-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "call-realtime-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "call-realtime-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
{{- range .Values.service.ports }}
|
||||||
|
- name: {{ .name }}
|
||||||
|
port: {{ .port }}
|
||||||
|
targetPort: {{ .targetPort }}
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
{{- include "call-realtime-app.selectorLabels" . | nindent 4 }}
|
||||||
66
charts/backend/charts/call-realtime-app-k8s/values.yaml
Executable file
66
charts/backend/charts/call-realtime-app-k8s/values.yaml
Executable file
@ -0,0 +1,66 @@
|
|||||||
|
# Image Configuration
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/call-realtime-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
# Replica Configuration
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
# Service Configuration
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- name: main
|
||||||
|
port: 5096
|
||||||
|
targetPort: 5005
|
||||||
|
- name: metrics
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
|
||||||
|
# Environment Configuration
|
||||||
|
env:
|
||||||
|
cassandra:
|
||||||
|
contactPoint: cassandra.cassandra.svc.cluster.local
|
||||||
|
datacenter: datacenter1
|
||||||
|
kafka:
|
||||||
|
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
redis:
|
||||||
|
host: redis-master.redis.svc.cluster.local
|
||||||
|
port: "6379"
|
||||||
|
recording:
|
||||||
|
apiHost: https://store-p001.cw.ngcloud.ru:9000
|
||||||
|
bucket: livekit
|
||||||
|
TENANT_ID: "412eb2e1-9660-4b74-a56a-6198f3b5338a"
|
||||||
|
|
||||||
|
# Secret References
|
||||||
|
secrets:
|
||||||
|
cassandra:
|
||||||
|
name: cassandra
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: cassandra-password
|
||||||
|
kafka:
|
||||||
|
name: kafka-password
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: client-passwords
|
||||||
|
livekit:
|
||||||
|
name: livekit-secret
|
||||||
|
apiKeyKey: api-key
|
||||||
|
secretKey: secret
|
||||||
|
recording:
|
||||||
|
name: recording-secret
|
||||||
|
accessKeyKey: access-key
|
||||||
|
secretKey: secret
|
||||||
|
|
||||||
|
# Kompose Metadata
|
||||||
|
podAnnotations:
|
||||||
|
kompose.cmd: kompose convert -f app/call-realtime-app.yml -o k8s/call-realtime-app-k8s
|
||||||
|
kompose.version: 1.33.0 (HEAD)
|
||||||
|
|
||||||
|
podLabels:
|
||||||
|
io.kompose.network/app-default: "true"
|
||||||
|
io.kompose.service: call-realtime-app
|
||||||
|
|
||||||
|
# Chart Metadata
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: call-realtime-app
|
||||||
23
charts/backend/charts/chat-app-k8s/.helmignore
Executable file
23
charts/backend/charts/chat-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
24
charts/backend/charts/chat-app-k8s/Chart.yaml
Executable file
24
charts/backend/charts/chat-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: chat-app
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
27
charts/backend/charts/chat-app-k8s/templates/_helpers.tpl
Executable file
27
charts/backend/charts/chat-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,27 @@
|
|||||||
|
{{/*
|
||||||
|
Return the name of the chart
|
||||||
|
*/}}
|
||||||
|
{{- define "chat-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
*/}}
|
||||||
|
{{- define "chat-app.fullname" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "chat-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "chat-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
{{- define "chat-app.quote" -}}
|
||||||
|
{{- . | quote }}
|
||||||
|
{{- end }}
|
||||||
131
charts/backend/charts/chat-app-k8s/templates/deployment.yaml
Executable file
131
charts/backend/charts/chat-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,131 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "chat-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "chat-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ include "chat-app.name" . }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ include "chat-app.name" . }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
ports:
|
||||||
|
- containerPort: 9090
|
||||||
|
hostPort: 8085
|
||||||
|
- containerPort: 5005
|
||||||
|
hostPort: 5085
|
||||||
|
env:
|
||||||
|
- name: CASSANDRA_CONTACTPOINT
|
||||||
|
value: {{ .Values.env.CASSANDRA_CONTACTPOINT }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.env.CASSANDRA_DATACENTER }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: cassandra
|
||||||
|
key: username
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: cassandra
|
||||||
|
key: cassandra-password
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: kafka-password
|
||||||
|
key: username
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: kafka-password
|
||||||
|
key: client-passwords
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.KAFKA | quote }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.REDIS_HOST }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ include "chat-app.quote" .Values.env.REDIS_PORT }}
|
||||||
|
- name: DEEPLINK_HOST
|
||||||
|
value: {{ .Values.env.DEEPLINK_HOST }}
|
||||||
|
- name: DEEPLINK_PORT
|
||||||
|
value: {{ include "chat-app.quote" .Values.env.DEEPLINK_PORT }}
|
||||||
|
- name: GEM_CALL_HOST
|
||||||
|
value: {{ .Values.env.GEM_CALL_HOST }}
|
||||||
|
- name: GEM_CALL_PORT
|
||||||
|
value: {{ include "chat-app.quote" .Values.env.GEM_CALL_PORT }}
|
||||||
|
- name: MESSAGE_HOST
|
||||||
|
value: {{ .Values.env.MESSAGE_HOST }}
|
||||||
|
- name: MESSAGE_PORT
|
||||||
|
value: {{ .Values.env.MESSAGE_PORT | quote }}
|
||||||
|
- name: SEARCH_HOST
|
||||||
|
value: {{ .Values.env.SEARCH_HOST }}
|
||||||
|
- name: SEARCH_PORT
|
||||||
|
value: {{ include "chat-app.quote" .Values.env.SEARCH_PORT }}
|
||||||
|
- name: USER_HOST
|
||||||
|
value: {{ .Values.env.USER_HOST }}
|
||||||
|
- name: USER_PORT
|
||||||
|
value: {{ include "chat-app.quote" .Values.env.USER_PORT }}
|
||||||
|
- name: KEYCLOAK_URL
|
||||||
|
value: {{ .Values.env.KEYCLOAK_URL }}
|
||||||
|
- name: LIVEKIT_API_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: livekit-secret
|
||||||
|
key: api-key
|
||||||
|
- name: LIVEKIT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: livekit-secret
|
||||||
|
key: secret
|
||||||
|
- name: RECORDING_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: recording-secret
|
||||||
|
key: access-key
|
||||||
|
- name: RECORDING_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: recording-secret
|
||||||
|
key: secret
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
restartPolicy: Always
|
||||||
16
charts/backend/charts/chat-app-k8s/templates/service.yaml
Executable file
16
charts/backend/charts/chat-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "chat-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "chat-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: {{ include "chat-app.name" . }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
- name: debug
|
||||||
|
port: 5085
|
||||||
|
targetPort: 5005
|
||||||
23
charts/backend/charts/chat-app-k8s/values.yaml
Executable file
23
charts/backend/charts/chat-app-k8s/values.yaml
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/chat-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
|
||||||
|
env:
|
||||||
|
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
|
||||||
|
CASSANDRA_DATACENTER: datacenter1
|
||||||
|
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
REDIS_HOST: redis-master.redis.svc.cluster.local
|
||||||
|
REDIS_PORT: "6379"
|
||||||
|
DEEPLINK_HOST: deeplink-app
|
||||||
|
DEEPLINK_PORT: "9090"
|
||||||
|
GEM_CALL_HOST: gem-call-app
|
||||||
|
GEM_CALL_PORT: "9090"
|
||||||
|
MESSAGE_HOST: message-app
|
||||||
|
MESSAGE_PORT: "9090"
|
||||||
|
SEARCH_HOST: search-app
|
||||||
|
SEARCH_PORT: "9090"
|
||||||
|
USER_HOST: user-app
|
||||||
|
USER_PORT: "9090"
|
||||||
|
KEYCLOAK_URL: https://iam.nubes.ru/realms/cowork
|
||||||
23
charts/backend/charts/chat-event-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/chat-event-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/chat-event-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: chat-event-handler-app
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.16.0"
|
||||||
27
charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl
Executable file
27
charts/backend/charts/chat-event-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,27 @@
|
|||||||
|
{{/*
|
||||||
|
Return the name of the chart
|
||||||
|
*/}}
|
||||||
|
{{- define "chat-event-handler-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
*/}}
|
||||||
|
{{- define "chat-event-handler-app.fullname" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "chat-event-handler-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "chat-event-handler-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
{{- define "chat-event-handler-app.quote" -}}
|
||||||
|
{{- . | quote }}
|
||||||
|
{{- end }}
|
||||||
109
charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml
Executable file
109
charts/backend/charts/chat-event-handler-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,109 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "chat-event-handler-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ include "chat-event-handler-app.name" . }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ include "chat-event-handler-app.name" . }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
ports:
|
||||||
|
- containerPort: 5005
|
||||||
|
hostPort: 5086
|
||||||
|
env:
|
||||||
|
- name: CASSANDRA_CONTACTPOINT
|
||||||
|
value: {{ .Values.env.CASSANDRA_CONTACTPOINT }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.env.CASSANDRA_DATACENTER }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: cassandra
|
||||||
|
key: username
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: cassandra
|
||||||
|
key: cassandra-password
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: kafka-password
|
||||||
|
key: username
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: kafka-password
|
||||||
|
key: client-passwords
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.KAFKA | quote }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.env.REDIS_HOST }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ include "chat-event-handler-app.quote" .Values.env.REDIS_PORT }}
|
||||||
|
- name: DEEPLINK_HOST
|
||||||
|
value: {{ .Values.env.DEEPLINK_HOST }}
|
||||||
|
- name: DEEPLINK_PORT
|
||||||
|
value: {{ include "chat-event-handler-app.quote" .Values.env.DEEPLINK_PORT }}
|
||||||
|
- name: GEM_CALL_HOST
|
||||||
|
value: {{ .Values.env.GEM_CALL_HOST }}
|
||||||
|
- name: GEM_CALL_PORT
|
||||||
|
value: {{ include "chat-event-handler-app.quote" .Values.env.GEM_CALL_PORT }}
|
||||||
|
- name: MESSAGE_HOST
|
||||||
|
value: {{ .Values.env.MESSAGE_HOST }}
|
||||||
|
- name: MESSAGE_PORT
|
||||||
|
value: {{ .Values.env.MESSAGE_PORT | quote }}
|
||||||
|
- name: SEARCH_HOST
|
||||||
|
value: {{ .Values.env.SEARCH_HOST }}
|
||||||
|
- name: SEARCH_PORT
|
||||||
|
value: {{ include "chat-event-handler-app.quote" .Values.env.SEARCH_PORT }}
|
||||||
|
- name: USER_HOST
|
||||||
|
value: {{ .Values.env.USER_HOST }}
|
||||||
|
- name: USER_PORT
|
||||||
|
value: {{ include "chat-event-handler-app.quote" .Values.env.USER_PORT }}
|
||||||
|
- name: KEYCLOAK_URL
|
||||||
|
value: {{ .Values.env.KEYCLOAK_URL }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
restartPolicy: Always
|
||||||
13
charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml
Executable file
13
charts/backend/charts/chat-event-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "chat-event-handler-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "chat-event-handler-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: {{ include "chat-event-handler-app.name" . }}
|
||||||
|
ports:
|
||||||
|
- name: debug
|
||||||
|
port: 5086
|
||||||
|
targetPort: 5005
|
||||||
22
charts/backend/charts/chat-event-handler-app-k8s/values.yaml
Executable file
22
charts/backend/charts/chat-event-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,22 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/chat-event-handler-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
|
||||||
|
env:
|
||||||
|
CASSANDRA_CONTACTPOINT: cassandra.cassandra.svc.cluster.local
|
||||||
|
CASSANDRA_DATACENTER: datacenter1
|
||||||
|
MESSAGE_HOST: message-app
|
||||||
|
MESSAGE_PORT: "9090"
|
||||||
|
USER_HOST: user-app
|
||||||
|
USER_PORT: "9090"
|
||||||
|
SEARCH_HOST: search-app
|
||||||
|
SEARCH_PORT: "9090"
|
||||||
|
GEM_CALL_HOST: gem-call-app
|
||||||
|
GEM_CALL_PORT: "9090"
|
||||||
|
DEEPLINK_HOST: deeplink-app
|
||||||
|
DEEPLINK_PORT: "9090"
|
||||||
|
REDIS_HOST: redis-master.redis.svc.cluster.local
|
||||||
|
REDIS_PORT: "6379"
|
||||||
|
KAFKA: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
23
charts/backend/charts/deeplink-app-k8s/.helmignore
Executable file
23
charts/backend/charts/deeplink-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
charts/backend/charts/deeplink-app-k8s/Chart.yaml
Executable file
6
charts/backend/charts/deeplink-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: deeplink-app-k8s
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.16.0"
|
||||||
17
charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl
Executable file
17
charts/backend/charts/deeplink-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,17 @@
|
|||||||
|
{{/* Chart name */}}
|
||||||
|
{{- define "deeplink-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "deeplink-app.fullname" -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* Common labels */}}
|
||||||
|
{{- define "deeplink-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "deeplink-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
70
charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml
Executable file
70
charts/backend/charts/deeplink-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,70 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "deeplink-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "deeplink-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ include "deeplink-app.name" . }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ include "deeplink-app.name" . }}
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: {{ include "deeplink-app.name" . }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
ports:
|
||||||
|
- containerPort: {{ .Values.container.port }}
|
||||||
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: CASSANDRA_PORT
|
||||||
|
value: {{ .Values.env.CASSANDRA_PORT | quote }}
|
||||||
|
- name: BRANCHIO_ACCESS
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: branchio-access
|
||||||
|
- name: BRANCHIO_APPID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: branchio-appid
|
||||||
|
- name: BRANCHIO_DEFAULT_URL
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: branchio-default-url
|
||||||
|
- name: BRANCHIO_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: branchio-key
|
||||||
|
- name: BRANCHIO_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: branchio-secret
|
||||||
|
- name: BRANCHIO_URL
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: branchio-url
|
||||||
|
- name: DEEPLINK_DOMAIN
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: deeplink-domain
|
||||||
|
- name: DEEPLINK_WEBDOMAIN
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.branchio }}
|
||||||
|
key: deeplink-webdomain
|
||||||
|
- name: DEEPLINK_TENANT
|
||||||
|
value: nubes.ru
|
||||||
|
- name: KEYCLOAK_URL
|
||||||
|
value: {{ .Values.keycloak.url | quote }}
|
||||||
|
restartPolicy: Always
|
||||||
13
charts/backend/charts/deeplink-app-k8s/templates/service.yaml
Executable file
13
charts/backend/charts/deeplink-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,13 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "deeplink-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "deeplink-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: {{ include "deeplink-app.name" . }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.container.port }}
|
||||||
20
charts/backend/charts/deeplink-app-k8s/values.yaml
Executable file
20
charts/backend/charts/deeplink-app-k8s/values.yaml
Executable file
@ -0,0 +1,20 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/deeplink-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
|
||||||
|
service:
|
||||||
|
port: 9090
|
||||||
|
|
||||||
|
container:
|
||||||
|
port: 9090
|
||||||
|
|
||||||
|
keycloak:
|
||||||
|
url: https://iam.nubes.ru/realms/cowork
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
branchio: deeplink-secret
|
||||||
|
|
||||||
|
env:
|
||||||
|
CASSANDRA_PORT: "9042"
|
||||||
23
charts/backend/charts/gem-call-app-k8s/.helmignore
Executable file
23
charts/backend/charts/gem-call-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
8
charts/backend/charts/gem-call-app-k8s/Chart.yaml
Executable file
8
charts/backend/charts/gem-call-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: gem-call-app
|
||||||
|
description: A Helm chart for gem-call-app
|
||||||
|
|
||||||
|
type: application
|
||||||
|
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0"
|
||||||
15
charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl
Executable file
15
charts/backend/charts/gem-call-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
{{- define "gem-call-app.name" -}}
|
||||||
|
{{- .Chart.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "gem-call-app.fullname" -}}
|
||||||
|
{{ .Chart.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "gem-call-app.labels" -}}
|
||||||
|
helm.sh/chart: {{ .Chart.Name }}-{{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/name: {{ include "gem-call-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
68
charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml
Executable file
68
charts/backend/charts/gem-call-app-k8s/templates/deployment.yaml
Executable file
@ -0,0 +1,68 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "gem-call-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "gem-call-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ include "gem-call-app.name" . }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ include "gem-call-app.name" . }}
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: {{ include "gem-call-app.name" . }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
ports:
|
||||||
|
- containerPort: 9090
|
||||||
|
- containerPort: 5005
|
||||||
|
env:
|
||||||
|
- name: CALL_HOST
|
||||||
|
value: {{ .Values.call.host | quote }}
|
||||||
|
- name: CALL_PORT
|
||||||
|
value: {{ .Values.call.port | quote }}
|
||||||
|
- name: CALL_REALTIME_HOST
|
||||||
|
value: {{ .Values.callRealtime.host | quote }}
|
||||||
|
- name: CALL_REALTIME_PORT
|
||||||
|
value: {{ .Values.callRealtime.port | quote }}
|
||||||
|
- name: CHAT_HOST
|
||||||
|
value: {{ .Values.chat.host | quote }}
|
||||||
|
- name: CHAT_PORT
|
||||||
|
value: {{ .Values.chat.port | quote }}
|
||||||
|
- name: DEEPLINK_HOST
|
||||||
|
value: {{ .Values.deeplink.host | quote }}
|
||||||
|
- name: DEEPLINK_PORT
|
||||||
|
value: {{ .Values.deeplink.port | quote }}
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.kafka.bootstrapServers | quote }}
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka }}
|
||||||
|
key: username
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka }}
|
||||||
|
key: client-passwords
|
||||||
|
- name: KEYCLOAK_URL
|
||||||
|
value: {{ .Values.keycloak.url | quote }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.redis.host | quote }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.redis.port | quote }}
|
||||||
|
- name: REDIS_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.redis }}
|
||||||
|
key: client-passwords
|
||||||
|
- name: USER_HOST
|
||||||
|
value: {{ .Values.user.host | quote }}
|
||||||
|
- name: USER_PORT
|
||||||
|
value: {{ .Values.user.port | quote }}
|
||||||
|
|
||||||
|
restartPolicy: Always
|
||||||
19
charts/backend/charts/gem-call-app-k8s/templates/service.yaml
Executable file
19
charts/backend/charts/gem-call-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "gem-call-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ .Release.Name }}
|
||||||
|
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: "9090"
|
||||||
|
port: 9090
|
||||||
|
targetPort: 9090
|
||||||
|
- name: "5089"
|
||||||
|
port: 5089
|
||||||
|
targetPort: 5005
|
||||||
|
selector:
|
||||||
|
app: gem-call-app
|
||||||
40
charts/backend/charts/gem-call-app-k8s/values.yaml
Executable file
40
charts/backend/charts/gem-call-app-k8s/values.yaml
Executable file
@ -0,0 +1,40 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.co-work.ru/gem-call-app
|
||||||
|
tag: 1.0.0-SNAPSHOT
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
kafka: kafka-password
|
||||||
|
redis: redis-kafka-user-passwords
|
||||||
|
|
||||||
|
kafka:
|
||||||
|
bootstrapServers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
redis:
|
||||||
|
host: redis-master.redis.svc.cluster.local
|
||||||
|
port: "6379"
|
||||||
|
|
||||||
|
keycloak:
|
||||||
|
url: https://iam.nubes.ru/realms/cowork
|
||||||
|
env:
|
||||||
|
cert_alias: nubes
|
||||||
|
|
||||||
|
call:
|
||||||
|
host: call-app
|
||||||
|
port: "9090"
|
||||||
|
|
||||||
|
callRealtime:
|
||||||
|
host: call-realtime-app
|
||||||
|
port: "9090"
|
||||||
|
|
||||||
|
chat:
|
||||||
|
host: chat-app
|
||||||
|
port: "9090"
|
||||||
|
|
||||||
|
deeplink:
|
||||||
|
host: deeplink-app
|
||||||
|
port: "9090"
|
||||||
|
|
||||||
|
user:
|
||||||
|
host: user-app
|
||||||
|
port: "9090"
|
||||||
23
charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore
Executable file
23
charts/backend/charts/gem-call-events-handler-app-k8s/.helmignore
Executable file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
8
charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml
Executable file
8
charts/backend/charts/gem-call-events-handler-app-k8s/Chart.yaml
Executable file
@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: gem-call-events-handler-app
|
||||||
|
description: A Helm chart for gem-call-events-handler-app
|
||||||
|
|
||||||
|
type: application
|
||||||
|
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: "1.0.0"
|
||||||
15
charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl
Executable file
15
charts/backend/charts/gem-call-events-handler-app-k8s/templates/_helpers.tpl
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
{{- define "gem-call-events-handler-app.name" -}}
|
||||||
|
gem-call-events-handler-app
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "gem-call-events-handler-app.fullname" -}}
|
||||||
|
{{- .Release.Name }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "gem-call-events-handler-app.labels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.Version }}
|
||||||
|
app.kubernetes.io/component: gem-call-events-handler-app
|
||||||
|
app.kubernetes.io/part-of: gem-call-events-handler-app
|
||||||
|
{{- end -}}
|
||||||
@ -0,0 +1,92 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "gem-call-events-handler-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "gem-call-events-handler-app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: {{ include "gem-call-events-handler-app.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: ca-cert
|
||||||
|
configMap:
|
||||||
|
name: auth-app-ca-cert
|
||||||
|
items:
|
||||||
|
- key: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
path: RootCA_{{ .Values.env.cert_alias }}.crt
|
||||||
|
- name: cacerts-volume
|
||||||
|
emptyDir: {}
|
||||||
|
initContainers:
|
||||||
|
- name: import-ca
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CERT_ALIAS
|
||||||
|
value: {{ .Values.env.cert_alias | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: ca-cert
|
||||||
|
mountPath: /app/resources
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /tmp/cacerts
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
cp /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts /tmp/cacerts/cacerts &&
|
||||||
|
keytool -import -trustcacerts -storepass changeit -noprompt \
|
||||||
|
-alias gemcert \
|
||||||
|
-file /app/resources/RootCA_${CERT_ALIAS}.crt \
|
||||||
|
-keystore /tmp/cacerts/cacerts
|
||||||
|
containers:
|
||||||
|
- name: gem-call-events-handler-app
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
env:
|
||||||
|
- name: CASSANDRA_CONTACTPOINT
|
||||||
|
value: {{ .Values.env.cassandra.contactPoint | quote }}
|
||||||
|
- name: CASSANDRA_DATACENTER
|
||||||
|
value: {{ .Values.env.cassandra.datacenter | quote }}
|
||||||
|
- name: CASSANDRA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra }}
|
||||||
|
key: username
|
||||||
|
- name: CASSANDRA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.cassandra }}
|
||||||
|
key: cassandra-password
|
||||||
|
- name: KAFKA
|
||||||
|
value: {{ .Values.env.kafka.brokers | quote }}
|
||||||
|
- name: KAFKA_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka }}
|
||||||
|
key: username
|
||||||
|
- name: KAFKA_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.secrets.kafka }}
|
||||||
|
key: client-passwords
|
||||||
|
- name: KEYCLOAK_URL
|
||||||
|
value: {{ .Values.keycloak.url | quote }}
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value: {{ .Values.redis.host | quote }}
|
||||||
|
- name: REDIS_PORT
|
||||||
|
value: {{ .Values.redis.port | quote }}
|
||||||
|
- name: CHAT_HOST
|
||||||
|
value: {{ .Values.chat.host | quote }}
|
||||||
|
- name: CHAT_PORT
|
||||||
|
value: {{ .Values.chat.port | quote }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: cacerts-volume
|
||||||
|
mountPath: /usr/lib/jvm/java-21-amazon-corretto/lib/security/cacerts
|
||||||
|
subPath: cacerts
|
||||||
|
restartPolicy: Always
|
||||||
19
charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml
Executable file
19
charts/backend/charts/gem-call-events-handler-app-k8s/templates/service.yaml
Executable file
@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "gem-call-events-handler-app.fullname" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ .Release.Name }}
|
||||||
|
chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: "8089"
|
||||||
|
port: 8089
|
||||||
|
targetPort: 9090
|
||||||
|
- name: "5089"
|
||||||
|
port: 5089
|
||||||
|
targetPort: 5005
|
||||||
|
selector:
|
||||||
|
io.kompose.service: gem-call-events-handler-app
|
||||||
32
charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml
Executable file
32
charts/backend/charts/gem-call-events-handler-app-k8s/values.yaml
Executable file
@ -0,0 +1,32 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: "registry.co-work.ru/gem-call-events-handler-app"
|
||||||
|
tag: "1.0.0-SNAPSHOT"
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
env:
|
||||||
|
cassandra:
|
||||||
|
contactPoint: "cassandra.cassandra.svc.cluster.local"
|
||||||
|
datacenter: "datacenter1"
|
||||||
|
kafka:
|
||||||
|
brokers: "kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092,kafka.kafka.svc.cluster.local:9092"
|
||||||
|
|
||||||
|
keycloak:
|
||||||
|
url: "https://iam.nubes.ru/realms/cowork"
|
||||||
|
|
||||||
|
redis:
|
||||||
|
host: "redis-master.redis.svc.cluster.local"
|
||||||
|
port: "6379"
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
cassandra: cassandra
|
||||||
|
kafka: kafka-password
|
||||||
|
chat:
|
||||||
|
host: "chat-app"
|
||||||
|
port: "9090"
|
||||||
|
|
||||||
|
additionalEnv: []
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
podLabels: {}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user