feat: add ArgoCD Application and backend k8s manifests

This commit is contained in:
2026-09-23 16:02:11 +02:00
parent c08fddbdba
commit 477157478f
9 changed files with 191 additions and 91 deletions
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: nextgen-be
+14
View File
@@ -0,0 +1,14 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: nextgen-be-config
namespace: nextgen-be
data:
RADIUS_SERVER_IP: "freeradius.freeradius.svc.cluster.local"
RADIUS_TIMEOUT_SECONDS: "2"
JWT_ALGORITHM: "HS256"
JWT_AUDIENCE: "nextgen-web"
JWT_ISSUER: "nextgen-auth"
ACCESS_TOKEN_EXPIRE_MINUTES: "30"
VPN_LAUNCH_TOKEN_EXPIRE_SECONDS: "300"
VPN_SESSION_EXPIRE_MINUTES: "60"
+60
View File
@@ -0,0 +1,60 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: nextgen-be
namespace: nextgen-be
labels:
app: nextgen-be
spec:
replicas: 1
selector:
matchLabels:
app: nextgen-be
template:
metadata:
labels:
app: nextgen-be
spec:
imagePullSecrets:
- name: registry-credentials
containers:
- name: nextgen-be
image: gitea.infrastructure.helmholz.cloud/gitea_admin/nextgen-be:latest
ports:
- containerPort: 8000
envFrom:
- configMapRef:
name: nextgen-be-config
- secretRef:
name: nextgen-be-db
- secretRef:
name: nextgen-be-jwt
- secretRef:
name: nextgen-be-radius
readinessProbe:
httpGet:
path: /health
port: 8000
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 3
failureThreshold: 3
livenessProbe:
httpGet:
path: /health
port: 8000
initialDelaySeconds: 15
periodSeconds: 20
timeoutSeconds: 3
failureThreshold: 3
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
securityContext:
runAsNonRoot: true
runAsUser: 1000
allowPrivilegeEscalation: false
+13
View File
@@ -0,0 +1,13 @@
apiVersion: v1
kind: Service
metadata:
name: nextgen-be
namespace: nextgen-be
spec:
type: ClusterIP
selector:
app: nextgen-be
ports:
- port: 8000
targetPort: 8000
protocol: TCP
+23
View File
@@ -0,0 +1,23 @@
apiVersion: batch/v1
kind: Job
metadata:
name: nextgen-be-migrate
namespace: nextgen-be
annotations:
# ArgoCD: run this before the Deployment is synced, on every sync where it changed
argocd.argoproj.io/hook: PreSync
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
spec:
backoffLimit: 2
template:
spec:
restartPolicy: Never
imagePullSecrets:
- name: registry-credentials
containers:
- name: migrate
image: gitea.infrastructure.helmholz.cloud/gitea_admin/nextgen-be:latest
command: ["alembic", "upgrade", "head"]
envFrom:
- secretRef:
name: nextgen-be-db
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
data:
.dockerconfigjson: eyJhdXRocyI6eyJnaXRlYS5pbmZyYXN0cnVjdHVyZS5oZWxtaG9sei5jbG91ZCI6eyJ1c2VybmFtZSI6ImdpdGVhX2FkbWluIiwicGFzc3dvcmQiOiIwMWVlMmUxOTJmYmE4NDA0OGI3YTQ2NDMzNmNhYTAyZmRlZjU3MDJiIiwiYXV0aCI6IloybDBaV0ZmWVdSdGFXNDZNREZsWlRKbE1Ua3labUpoT0RRd05EaGlOMkUwTmpRek16WmpZV0V3TW1aa1pXWTFOekF5WWc9PSJ9fX0=
kind: Secret
metadata:
creationTimestamp: null
name: registry-credentials
namespace: nextgen-be
type: kubernetes.io/dockerconfigjson
+37
View File
@@ -0,0 +1,37 @@
# ⚠️ TESTING ONLY — DO NOT COMMIT THIS FILE TO GIT ⚠️
# This file contains (or will contain) plaintext secret values.
# Add "secrets.yaml" to .gitignore before you ever `git add` this directory.
# Once everything works, replace this with Sealed Secrets / SOPS per the
# earlier discussion — this file is a shortcut for getting unblocked now.
apiVersion: v1
kind: Secret
metadata:
name: nextgen-be-db
namespace: nextgen-be
type: Opaque
stringData:
# Get this value with:
# kubectl get secret postgresql-prod-app -n postgresql -o jsonpath='{.data.uri}' | base64 -d
DATABASE_URL: "postgresql://radius:kVwBYXzIfS8ZENgEZ0kdql0O9k75d6nflBcPTB5clj1iOmgxNtisIkKychusIQ7k@postgresql-prod-rw.postgresql:5432/radius"
---
apiVersion: v1
kind: Secret
metadata:
name: nextgen-be-jwt
namespace: nextgen-be
type: Opaque
stringData:
# Generate with: openssl rand -hex 32
SECRET_KEY: "f0e2684aab93f96557fc2b63ba55e790222d5c516c4dbb3de75d0a2fcc6d0a9b"
---
apiVersion: v1
kind: Secret
metadata:
name: nextgen-be-radius
namespace: nextgen-be
type: Opaque
stringData:
# Must match the shared secret configured on the FreeRADIUS side
# (rotate this value before going anywhere near production)
RADIUS_CLIENT_SECRET: "aloulou"