feat: add ArgoCD Application and backend k8s manifests
This commit is contained in:
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: nextgen-be
|
||||
@@ -0,0 +1,14 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: nextgen-be-config
|
||||
namespace: nextgen-be
|
||||
data:
|
||||
RADIUS_SERVER_IP: "freeradius.freeradius.svc.cluster.local"
|
||||
RADIUS_TIMEOUT_SECONDS: "2"
|
||||
JWT_ALGORITHM: "HS256"
|
||||
JWT_AUDIENCE: "nextgen-web"
|
||||
JWT_ISSUER: "nextgen-auth"
|
||||
ACCESS_TOKEN_EXPIRE_MINUTES: "30"
|
||||
VPN_LAUNCH_TOKEN_EXPIRE_SECONDS: "300"
|
||||
VPN_SESSION_EXPIRE_MINUTES: "60"
|
||||
@@ -0,0 +1,60 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: nextgen-be
|
||||
namespace: nextgen-be
|
||||
labels:
|
||||
app: nextgen-be
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: nextgen-be
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: nextgen-be
|
||||
spec:
|
||||
imagePullSecrets:
|
||||
- name: registry-credentials
|
||||
containers:
|
||||
- name: nextgen-be
|
||||
image: gitea.infrastructure.helmholz.cloud/gitea_admin/nextgen-be:latest
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: nextgen-be-config
|
||||
- secretRef:
|
||||
name: nextgen-be-db
|
||||
- secretRef:
|
||||
name: nextgen-be-jwt
|
||||
- secretRef:
|
||||
name: nextgen-be-radius
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 8000
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 3
|
||||
failureThreshold: 3
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /health
|
||||
port: 8000
|
||||
initialDelaySeconds: 15
|
||||
periodSeconds: 20
|
||||
timeoutSeconds: 3
|
||||
failureThreshold: 3
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,13 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: nextgen-be
|
||||
namespace: nextgen-be
|
||||
spec:
|
||||
type: ClusterIP
|
||||
selector:
|
||||
app: nextgen-be
|
||||
ports:
|
||||
- port: 8000
|
||||
targetPort: 8000
|
||||
protocol: TCP
|
||||
@@ -0,0 +1,23 @@
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: nextgen-be-migrate
|
||||
namespace: nextgen-be
|
||||
annotations:
|
||||
# ArgoCD: run this before the Deployment is synced, on every sync where it changed
|
||||
argocd.argoproj.io/hook: PreSync
|
||||
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
|
||||
spec:
|
||||
backoffLimit: 2
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
imagePullSecrets:
|
||||
- name: registry-credentials
|
||||
containers:
|
||||
- name: migrate
|
||||
image: registry.example.com/nextgen/nextgen_be:latest # TODO: keep in sync with 03-deployment.yaml
|
||||
command: ["alembic", "upgrade", "head"]
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: nextgen-be-db
|
||||
@@ -0,0 +1,9 @@
|
||||
apiVersion: v1
|
||||
data:
|
||||
.dockerconfigjson: eyJhdXRocyI6eyJnaXRlYS5pbmZyYXN0cnVjdHVyZS5oZWxtaG9sei5jbG91ZCI6eyJ1c2VybmFtZSI6ImdpdGVhX2FkbWluIiwicGFzc3dvcmQiOiIwMWVlMmUxOTJmYmE4NDA0OGI3YTQ2NDMzNmNhYTAyZmRlZjU3MDJiIiwiYXV0aCI6IloybDBaV0ZmWVdSdGFXNDZNREZsWlRKbE1Ua3labUpoT0RRd05EaGlOMkUwTmpRek16WmpZV0V3TW1aa1pXWTFOekF5WWc9PSJ9fX0=
|
||||
kind: Secret
|
||||
metadata:
|
||||
creationTimestamp: null
|
||||
name: registry-credentials
|
||||
namespace: nextgen-be
|
||||
type: kubernetes.io/dockerconfigjson
|
||||
@@ -0,0 +1,37 @@
|
||||
# ⚠️ TESTING ONLY — DO NOT COMMIT THIS FILE TO GIT ⚠️
|
||||
# This file contains (or will contain) plaintext secret values.
|
||||
# Add "secrets.yaml" to .gitignore before you ever `git add` this directory.
|
||||
# Once everything works, replace this with Sealed Secrets / SOPS per the
|
||||
# earlier discussion — this file is a shortcut for getting unblocked now.
|
||||
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: nextgen-be-db
|
||||
namespace: nextgen-be
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Get this value with:
|
||||
# kubectl get secret postgresql-prod-app -n postgresql -o jsonpath='{.data.uri}' | base64 -d
|
||||
DATABASE_URL: "postgresql://radius:kVwBYXzIfS8ZENgEZ0kdql0O9k75d6nflBcPTB5clj1iOmgxNtisIkKychusIQ7k@postgresql-prod-rw.postgresql:5432/radius"
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: nextgen-be-jwt
|
||||
namespace: nextgen-be
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Generate with: openssl rand -hex 32
|
||||
SECRET_KEY: "f0e2684aab93f96557fc2b63ba55e790222d5c516c4dbb3de75d0a2fcc6d0a9b"
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: nextgen-be-radius
|
||||
namespace: nextgen-be
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Must match the shared secret configured on the FreeRADIUS side
|
||||
# (rotate this value before going anywhere near production)
|
||||
RADIUS_CLIENT_SECRET: "aloulou"
|
||||
Reference in New Issue
Block a user