679 lines
20 KiB
YAML
679 lines
20 KiB
YAML
---
|
||
clusterName: "elasticsearch"
|
||
nodeGroup: "master"
|
||
|
||
# The service that non master groups will try to connect to when joining the cluster
|
||
# This should be set to clusterName + "-" + nodeGroup for your master group
|
||
masterService: ""
|
||
|
||
# Elasticsearch roles that will be applied to this nodeGroup
|
||
# These will be set as environment variables. E.g. node.roles=master
|
||
# https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#node-roles
|
||
roles:
|
||
- master
|
||
- data
|
||
- data_content
|
||
- data_hot
|
||
- data_warm
|
||
- data_cold
|
||
- ingest
|
||
- ml
|
||
- remote_cluster_client
|
||
- transform
|
||
|
||
replicas: 3
|
||
minimumMasterNodes: 2
|
||
|
||
esMajorVersion: ""
|
||
|
||
# Allows you to add any config files in /usr/share/elasticsearch/config/
|
||
# such as elasticsearch.yml and log4j2.properties
|
||
esConfig:
|
||
elasticsearch.yml: |
|
||
xpack.security.enabled: false # Disable Elasticsearch security
|
||
xpack.security.http.ssl.enabled: false # Disable HTTP SSL
|
||
xpack.security.transport.ssl.enabled: false # Disable transport SSL
|
||
|
||
createCert: false
|
||
|
||
esJvmOptions: {}
|
||
# processors.options: |
|
||
# -XX:ActiveProcessorCount=3
|
||
|
||
# Extra environment variables to append to this nodeGroup
|
||
# This will be appended to the current 'env:' key. You can use any of the kubernetes env
|
||
# syntax here
|
||
extraEnvs:
|
||
- name: ES_USERNAME
|
||
valueFrom:
|
||
secretKeyRef:
|
||
name: elasticsearch-master-credentials
|
||
key: username
|
||
- name: ES_PASSWORD
|
||
valueFrom:
|
||
secretKeyRef:
|
||
name: elasticsearch-master-credentials
|
||
key: password
|
||
- name: CA_CERT
|
||
value: "/usr/share/elasticsearch/config/http-certs/ca.crt"
|
||
- name: ES_URL
|
||
value: "http://elasticsearch-master:9200"
|
||
- name: TEMPLATE_PATH_1
|
||
value: "/usr/share/elasticsearch/templates/chat_v1_idx.json"
|
||
- name: TEMPLATE_PATH_2
|
||
value: "/usr/share/elasticsearch/templates/message_v1_idx.json"
|
||
- name: TEMPLATE_PATH_3
|
||
value: "/usr/share/elasticsearch/templates/user_v1_idx.json"
|
||
- name: MAX_RETRIES
|
||
value: "30"
|
||
|
||
# Allows you to load environment variables from kubernetes secret or config map
|
||
envFrom: []
|
||
# - secretRef:
|
||
# name: env-secret
|
||
# - configMapRef:
|
||
# name: config-map
|
||
|
||
# Disable it to use your own elastic-credential Secret.
|
||
secret:
|
||
enabled: false
|
||
password: "" # generated randomly if not defined
|
||
|
||
# A list of secrets and their paths to mount inside the pod
|
||
# This is useful for mounting certificates for security and for mounting
|
||
# the X-Pack license
|
||
secretMounts: []
|
||
# - name: elastic-certificates
|
||
# secretName: elastic-certificates
|
||
# path: /usr/share/elasticsearch/config/certs
|
||
# defaultMode: 0755
|
||
|
||
hostAliases: []
|
||
#- ip: "127.0.0.1"
|
||
# hostnames:
|
||
# - "foo.local"
|
||
# - "bar.local"
|
||
|
||
image: "docker.io/library/elasticsearch"
|
||
imageTag: "8.5.1"
|
||
imagePullPolicy: "IfNotPresent"
|
||
|
||
podAnnotations: {}
|
||
# iam.amazonaws.com/role: es-cluster
|
||
|
||
# additionals labels
|
||
labels: {}
|
||
|
||
esJavaOpts: "" # example: "-Xmx1g -Xms1g"
|
||
|
||
resources:
|
||
requests:
|
||
cpu: "1000m"
|
||
memory: "2Gi"
|
||
limits:
|
||
cpu: "1000m"
|
||
memory: "2Gi"
|
||
|
||
initResources: {}
|
||
# limits:
|
||
# cpu: "25m"
|
||
# # memory: "128Mi"
|
||
# requests:
|
||
# cpu: "25m"
|
||
# memory: "128Mi"
|
||
|
||
networkHost: "0.0.0.0"
|
||
|
||
volumeClaimTemplate:
|
||
accessModes: ["ReadWriteOnce"]
|
||
resources:
|
||
requests:
|
||
storage: 30Gi
|
||
|
||
rbac:
|
||
create: false
|
||
serviceAccountAnnotations: {}
|
||
serviceAccountName: ""
|
||
automountToken: true
|
||
|
||
podSecurityPolicy:
|
||
create: false
|
||
name: ""
|
||
spec:
|
||
privileged: true
|
||
fsGroup:
|
||
rule: RunAsAny
|
||
runAsUser:
|
||
rule: RunAsAny
|
||
seLinux:
|
||
rule: RunAsAny
|
||
supplementalGroups:
|
||
rule: RunAsAny
|
||
volumes:
|
||
- secret
|
||
- configMap
|
||
- persistentVolumeClaim
|
||
- emptyDir
|
||
|
||
persistence:
|
||
enabled: true
|
||
labels:
|
||
# Add default labels for the volumeClaimTemplate of the StatefulSet
|
||
enabled: false
|
||
annotations: {}
|
||
|
||
extraVolumeMounts:
|
||
- name: index-template
|
||
mountPath: /usr/share/elasticsearch/templates
|
||
readOnly: true
|
||
# - name: http-cert
|
||
# mountPath: /usr/share/elasticsearch/config/http-certs
|
||
# readOnly: true
|
||
#
|
||
extraContainers: []
|
||
# - name: do-something
|
||
# image: busybox
|
||
# command: ['do', 'something']
|
||
|
||
|
||
extraInitContainers: []
|
||
# - name: es-index-init
|
||
# image: alpine/curl:latest
|
||
# command: ['/bin/sh', '-c']
|
||
# args:
|
||
# - |
|
||
# ES_HOST="elasticsearch-master" # Match your ES service name
|
||
# ES_PORT="9200"
|
||
# ELASTIC_PASSWORD=$(cat /etc/elasticsearch-password/password)
|
||
# curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/chat_v1_idx?pretty" -H 'Content-Type: application/json' -d'
|
||
# {
|
||
# "settings": {
|
||
# "index": {
|
||
# "number_of_shards": 3,
|
||
# "number_of_replicas": 1,
|
||
# "max_ngram_diff": 2
|
||
# },
|
||
# "analysis": {
|
||
# "analyzer": {
|
||
# "ngram_analyzer": {
|
||
# "type": "custom",
|
||
# "tokenizer": "ngram_tokenizer",
|
||
# "filter": [
|
||
# "lowercase"
|
||
# ]
|
||
# },
|
||
# "standard_search_analyzer_lowercase": {
|
||
# "type": "custom",
|
||
# "tokenizer": "standard",
|
||
# "filter": [
|
||
# "lowercase"
|
||
# ]
|
||
# }
|
||
# },
|
||
# "tokenizer": {
|
||
# "ngram_tokenizer": {
|
||
# "type": "ngram",
|
||
# "min_gram": 3,
|
||
# "max_gram": 5,
|
||
# "token_chars": []
|
||
# }
|
||
# },
|
||
# "normalizer": {
|
||
# "lowercase_normalizer": {
|
||
# "type": "custom",
|
||
# "filter": [
|
||
# "lowercase"
|
||
# ]
|
||
# }
|
||
# }
|
||
# }
|
||
# },
|
||
# "mappings": {
|
||
# "properties": {
|
||
# "id": {
|
||
# "type": "long"
|
||
# },
|
||
# "name": {
|
||
# "type": "keyword",
|
||
# "normalizer": "lowercase_normalizer"
|
||
# },
|
||
# "name_ngram": {
|
||
# "type": "text",
|
||
# "analyzer": "ngram_analyzer",
|
||
# "search_analyzer": "ngram_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "description": {
|
||
# "type": "text",
|
||
# "analyzer": "standard",
|
||
# "search_analyzer": "standard_search_analyzer_lowercase",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "_class": {
|
||
# "type": "text",
|
||
# "fields": {
|
||
# "keyword": {
|
||
# "ignore_above": 256.0,
|
||
# "type": "keyword"
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/message_v1_idx?pretty" -H 'Content-Type: application/json' -d'
|
||
# {
|
||
# "settings": {
|
||
# "index": {
|
||
# "number_of_shards": "3",
|
||
# "number_of_replicas": "1"
|
||
# },
|
||
# "analysis": {
|
||
# "analyzer": {
|
||
# "edge_ngram_index_analyzer": {
|
||
# "tokenizer": "edge_ngram_index_tokenizer",
|
||
# "filter": [
|
||
# "lowercase",
|
||
# "apostrophe",
|
||
# "classic"
|
||
# ]
|
||
# },
|
||
# "message_search_analyzer": {
|
||
# "tokenizer": "standard"
|
||
# }
|
||
# },
|
||
# "tokenizer": {
|
||
# "edge_ngram_index_tokenizer": {
|
||
# "type": "edge_ngram",
|
||
# "min_gram": 1,
|
||
# "max_gram": 20,
|
||
# "token_chars": [
|
||
# "letter",
|
||
# "digit"
|
||
# ]
|
||
# }
|
||
# }
|
||
# }
|
||
# },
|
||
# "mappings": {
|
||
# "properties": {
|
||
# "chatId": {
|
||
# "type": "long"
|
||
# },
|
||
# "messageId": {
|
||
# "type": "long"
|
||
# },
|
||
# "serverTime": {
|
||
# "type": "long"
|
||
# },
|
||
# "_class": {
|
||
# "type": "text",
|
||
# "fields": {
|
||
# "keyword": {
|
||
# "ignore_above": 256.0,
|
||
# "type": "keyword"
|
||
# }
|
||
# }
|
||
# },
|
||
# "id": {
|
||
# "type": "keyword"
|
||
# },
|
||
# "text": {
|
||
# "type": "text",
|
||
# "analyzer": "edge_ngram_index_analyzer",
|
||
# "search_analyzer": "message_search_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/user_v1_idx?pretty" -H 'Content-Type: application/json' -d'
|
||
# {
|
||
# "settings": {
|
||
# "index": {
|
||
# "number_of_shards": 3,
|
||
# "number_of_replicas": 1,
|
||
# "max_ngram_diff": 2
|
||
# },
|
||
# "analysis": {
|
||
# "analyzer": {
|
||
# "ngram_analyzer": {
|
||
# "type": "custom",
|
||
# "tokenizer": "ngram_tokenizer",
|
||
# "filter": [
|
||
# "lowercase"
|
||
# ]
|
||
# },
|
||
# "standard_search_analyzer_lowercase": {
|
||
# "type": "custom",
|
||
# "tokenizer": "standard",
|
||
# "filter": [
|
||
# "lowercase"
|
||
# ]
|
||
# }
|
||
# },
|
||
# "tokenizer": {
|
||
# "ngram_tokenizer": {
|
||
# "type": "ngram",
|
||
# "min_gram": 3,
|
||
# "max_gram": 5,
|
||
# "token_chars": []
|
||
# }
|
||
# },
|
||
# "normalizer": {
|
||
# "lowercase_normalizer": {
|
||
# "type": "custom",
|
||
# "filter": [
|
||
# "lowercase"
|
||
# ]
|
||
# }
|
||
# }
|
||
# }
|
||
# },
|
||
# "mappings": {
|
||
# "properties": {
|
||
# "id": {
|
||
# "type": "long"
|
||
# },
|
||
# "username": {
|
||
# "type": "keyword",
|
||
# "normalizer": "lowercase_normalizer"
|
||
# },
|
||
# "username_ngram": {
|
||
# "type": "text",
|
||
# "analyzer": "ngram_analyzer",
|
||
# "search_analyzer": "ngram_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "nickname": {
|
||
# "type": "keyword",
|
||
# "normalizer": "lowercase_normalizer"
|
||
# },
|
||
# "nickname_ngram": {
|
||
# "type": "text",
|
||
# "analyzer": "ngram_analyzer",
|
||
# "search_analyzer": "ngram_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "phone": {
|
||
# "type": "keyword",
|
||
# "normalizer": "lowercase_normalizer"
|
||
# },
|
||
# "phone_ngram": {
|
||
# "type": "text",
|
||
# "analyzer": "ngram_analyzer",
|
||
# "search_analyzer": "ngram_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "email": {
|
||
# "type": "keyword",
|
||
# "normalizer": "lowercase_normalizer"
|
||
# },
|
||
# "email_ngram": {
|
||
# "type": "text",
|
||
# "analyzer": "ngram_analyzer",
|
||
# "search_analyzer": "ngram_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "job_title": {
|
||
# "type": "keyword",
|
||
# "normalizer": "lowercase_normalizer"
|
||
# },
|
||
# "job_title_ngram": {
|
||
# "type": "text",
|
||
# "analyzer": "ngram_analyzer",
|
||
# "search_analyzer": "ngram_analyzer",
|
||
# "index_options": "offsets",
|
||
# "term_vector": "with_positions_offsets"
|
||
# },
|
||
# "_class": {
|
||
# "type": "text",
|
||
# "fields": {
|
||
# "keyword": {
|
||
# "ignore_above": 256.0,
|
||
# "type": "keyword"
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# }
|
||
# volumeMounts:
|
||
# - name: elasticsearch-password
|
||
# mountPath: /etc/elasticsearch-password
|
||
# readOnly: true
|
||
|
||
extraVolumes:
|
||
# Mount the JSON template
|
||
- name: index-template
|
||
configMap:
|
||
name: index-template-1
|
||
# - name: http-cert
|
||
# secret:
|
||
# secretName: elasticsearch-master-certs
|
||
|
||
# (Secret volume is optional; we’ll inject via envFrom)
|
||
# This is the PriorityClass settings as defined in
|
||
# https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass
|
||
priorityClassName: ""
|
||
|
||
# By default this will make sure two pods don't end up on the same node
|
||
# Changing this to a region would allow you to spread pods across regions
|
||
antiAffinityTopologyKey: "kubernetes.io/hostname"
|
||
|
||
# Hard means that by default pods will only be scheduled if there are enough nodes for them
|
||
# and that they will never end up on the same node. Setting this to soft will do this "best effort"
|
||
antiAffinity: "hard"
|
||
|
||
# This is the node affinity settings as defined in
|
||
# https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#node-affinity-beta-feature
|
||
nodeAffinity: {}
|
||
|
||
# The default is to deploy all pods serially. By setting this to parallel all pods are started at
|
||
# the same time when bootstrapping the cluster
|
||
podManagementPolicy: "Parallel"
|
||
|
||
# The environment variables injected by service links are not used, but can lead to slow Elasticsearch boot times when
|
||
# there are many services in the current namespace.
|
||
# If you experience slow pod startups you probably want to set this to `false`.
|
||
enableServiceLinks: true
|
||
|
||
protocol: http
|
||
httpPort: 9200
|
||
transportPort: 9300
|
||
|
||
service:
|
||
enabled: true
|
||
labels: {}
|
||
labelsHeadless: {}
|
||
type: ClusterIP
|
||
# Consider that all endpoints are considered "ready" even if the Pods themselves are not
|
||
# https://kubernetes.io/docs/reference/kubernetes-api/service-resources/service-v1/#ServiceSpec
|
||
publishNotReadyAddresses: false
|
||
nodePort: ""
|
||
annotations: {}
|
||
httpPortName: http
|
||
transportPortName: transport
|
||
loadBalancerIP: ""
|
||
loadBalancerSourceRanges: []
|
||
externalTrafficPolicy: ""
|
||
|
||
updateStrategy: RollingUpdate
|
||
|
||
# This is the max unavailable setting for the pod disruption budget
|
||
# The default value of 1 will make sure that kubernetes won't allow more than 1
|
||
# of your pods to be unavailable during maintenance
|
||
maxUnavailable: 1
|
||
|
||
podSecurityContext:
|
||
fsGroup: 1000
|
||
runAsUser: 1000
|
||
|
||
securityContext:
|
||
capabilities:
|
||
drop:
|
||
- ALL
|
||
# readOnlyRootFilesystem: true
|
||
runAsNonRoot: true
|
||
runAsUser: 1000
|
||
|
||
# How long to wait for elasticsearch to stop gracefully
|
||
terminationGracePeriod: 120
|
||
|
||
sysctlVmMaxMapCount: 262144
|
||
|
||
readinessProbe:
|
||
failureThreshold: 3
|
||
initialDelaySeconds: 10
|
||
periodSeconds: 10
|
||
successThreshold: 3
|
||
timeoutSeconds: 5
|
||
|
||
# https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html#request-params wait_for_status
|
||
clusterHealthCheckParams: "wait_for_status=green&timeout=1s"
|
||
|
||
## Use an alternate scheduler.
|
||
## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
|
||
##
|
||
schedulerName: ""
|
||
|
||
imagePullSecrets: []
|
||
nodeSelector: {}
|
||
tolerations: []
|
||
|
||
# Enabling this will publicly expose your Elasticsearch instance.
|
||
# Only enable this if you have security enabled on your cluster
|
||
ingress:
|
||
enabled: false
|
||
annotations: {}
|
||
# kubernetes.io/ingress.class: nginx
|
||
# kubernetes.io/tls-acme: "true"
|
||
className: "nginx"
|
||
pathtype: ImplementationSpecific
|
||
hosts:
|
||
- host: chart-example.local
|
||
paths:
|
||
- path: /
|
||
tls: []
|
||
# - secretName: chart-example-tls
|
||
# hosts:
|
||
# - chart-example.local
|
||
|
||
nameOverride: ""
|
||
fullnameOverride: ""
|
||
healthNameOverride: ""
|
||
lifecycle: {}
|
||
postStart:
|
||
exec:
|
||
command:
|
||
- /bin/bash
|
||
- -c
|
||
- |
|
||
set -euo pipefail
|
||
echo "[postStart] Waiting for Elasticsearch to be ready..." >&2
|
||
for ((i=1; i<=MAX_RETRIES; i++)); do
|
||
if /usr/bin/curl --cacert "$CA_CERT" -s -u "$ES_USERNAME:$ELASTIC_PASSWORD" "$ES_URL" >/dev/null; then
|
||
echo "[postStart] Elasticsearch is up after $i attempts!" >&2
|
||
break
|
||
fi
|
||
if [ "$i" -eq "$MAX_RETRIES" ]; then
|
||
echo "[postStart] ERROR: Elasticsearch did not become ready after $MAX_RETRIES attempts." >&2
|
||
exit 1
|
||
fi
|
||
sleep 5
|
||
done
|
||
echo "[postStart] Loading index template from $TEMPLATE_PATH" >&2
|
||
if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/chat" \
|
||
-u "$ES_USERNAME:$ES_PASSWORD" \
|
||
-H 'Content-Type: application/json' \
|
||
--data-binary @"$TEMPLATE_PATH_1"; then
|
||
echo "[postStart] ERROR: Failed to apply index template!" >&2
|
||
exit 1
|
||
fi
|
||
if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/message" \
|
||
-u "$ES_USERNAME:$ELASTIC_PASSWORD" \
|
||
-H 'Content-Type: application/json' \
|
||
--data-binary @"$TEMPLATE_PATH_2"; then
|
||
echo "[postStart] ERROR: Failed to apply index template!" >&2
|
||
exit 1
|
||
fi
|
||
if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/user" \
|
||
-u "$ES_USERNAME:$ELASTIC_PASSWORD" \
|
||
-H 'Content-Type: application/json' \
|
||
--data-binary @"$TEMPLATE_PATH_3"; then
|
||
echo "[postStart] ERROR: Failed to apply index template!" >&2
|
||
exit 1
|
||
fi
|
||
echo "[postStart] Index template 'chat_v1_idx' applied." >&2
|
||
echo "Debug message" >> /poststart.log 2>&1
|
||
|
||
sysctlInitContainer:
|
||
enabled: true
|
||
|
||
keystore: []
|
||
|
||
networkPolicy:
|
||
## Enable creation of NetworkPolicy resources. Only Ingress traffic is filtered for now.
|
||
## In order for a Pod to access Elasticsearch, it needs to have the following label:
|
||
## {{ template "uname" . }}-client: "true"
|
||
## Example for default configuration to access HTTP port:
|
||
## elasticsearch-master-http-client: "true"
|
||
## Example for default configuration to access transport port:
|
||
## elasticsearch-master-transport-client: "true"
|
||
|
||
http:
|
||
enabled: true
|
||
## if explicitNamespacesSelector is not set or set to {}, only client Pods being in the networkPolicy's namespace
|
||
## and matching all criteria can reach the DB.
|
||
## But sometimes, we want the Pods to be accessible to clients from other namespaces, in this case, we can use this
|
||
## parameter to select these namespaces
|
||
##
|
||
# explicitNamespacesSelector:
|
||
# # Accept from namespaces with all those different rules (only from whitelisted Pods)
|
||
# matchLabels:
|
||
# role: frontend
|
||
# matchExpressions:
|
||
# - {key: role, operator: In, values: [frontend]}
|
||
|
||
## Additional NetworkPolicy Ingress "from" rules to set. Note that all rules are OR-ed.
|
||
##
|
||
# additionalRules:
|
||
# - podSelector:
|
||
# matchLabels:
|
||
# role: frontend
|
||
# - podSelector:
|
||
# matchExpressions:
|
||
# - key: role
|
||
# operator: In
|
||
# values:
|
||
# - frontend
|
||
|
||
transport:
|
||
## Note that all Elasticsearch Pods can talk to themselves using transport port even if enabled.
|
||
enabled: false
|
||
# explicitNamespacesSelector:
|
||
# matchLabels:
|
||
# role: frontend
|
||
# matchExpressions:
|
||
# - {key: role, operator: In, values: [frontend]}
|
||
# additionalRules:
|
||
# - podSelector:
|
||
# matchLabels:
|
||
# role: frontend
|
||
# - podSelector:
|
||
# matchExpressions:
|
||
# - key: role
|
||
# operator: In
|
||
# values:
|
||
# - frontend
|
||
|
||
tests:
|
||
enabled: true
|