mirror of
https://git.meshkee.com/cssd/cssd-back.git
synced 2026-10-10 19:21:27 +03:30
1010 lines
30 KiB
YAML
1010 lines
30 KiB
YAML
# -- Same as nameOverride but for the namespace.
|
|
namespaceOverride: "cssd"
|
|
|
|
# -- Same as nameOverride but for the component.
|
|
componentOverride: ""
|
|
|
|
# -- Same as nameOverride but for the partOf.
|
|
partOfOverride: ""
|
|
|
|
##########################################################
|
|
# Name of the application.
|
|
##########################################################
|
|
applicationName: "cssd-production-back"
|
|
|
|
##########################################################
|
|
# Global labels
|
|
# These labels will be added on all resources,
|
|
# and you can add additional labels from below
|
|
# on individual resource
|
|
##########################################################
|
|
|
|
cronJob:
|
|
enabled: false
|
|
jobs:
|
|
# db-migration:
|
|
# schedule: "* * * 8 *"
|
|
# env:
|
|
# KEY:
|
|
# value: VALUE
|
|
# image:
|
|
# repository: docker.io/nginx
|
|
# tag: v1.0.0
|
|
# digest: '' # if set to a non empty value, digest takes precedence on the tag
|
|
# imagePullPolicy: IfNotPresent
|
|
# command: ["/bin/bash"]
|
|
# args: ["-c","sleep 5000"]
|
|
# resources:
|
|
# requests:
|
|
# memory: 5Gi
|
|
# cpu: 1
|
|
|
|
|
|
##########################################################
|
|
# Deployment
|
|
##########################################################
|
|
deployment:
|
|
|
|
enabled: true
|
|
# By default deploymentStrategy is set to rollingUpdate with maxSurge of 25% and maxUnavailable of 25%
|
|
# You can change type to `Recreate` or can uncomment `rollingUpdate` specification and adjust them to your usage.
|
|
strategy:
|
|
type: RollingUpdate
|
|
# rollingUpdate:
|
|
# maxSurge: 25%
|
|
# maxUnavailable: 25%
|
|
|
|
# Reload deployment if configMap/secret updates
|
|
reloadOnChange: true
|
|
|
|
# Select nodes to deploy which matches the following labels
|
|
nodeSelector:
|
|
# cloud.google.com/gke-nodepool: default-pool
|
|
|
|
# Init containers which runs before the app container
|
|
hostAliases:
|
|
# - ip: "127.0.0.1"
|
|
# hostnames:
|
|
# - "foo.local"
|
|
# - "bar.local"
|
|
# - ip: "10.1.2.3"
|
|
# hostnames:
|
|
# - "foo.remote"
|
|
# - "bar.remote"
|
|
|
|
# Init containers which runs before the app container
|
|
initContainers:
|
|
init-artisan:
|
|
args:
|
|
- /bin/bash
|
|
- -c
|
|
- (php artisan migrate --force || true) && (php artisan config:cache || true)
|
|
envFrom:
|
|
- configMapRef:
|
|
name: cssd-production-back-configmap
|
|
- secretRef:
|
|
name: cssd-production-back-secret
|
|
image: docker.meshkee.com/repository/docker-hosted/external-projects/cssd-back:latest
|
|
imagePullPolicy: IfNotPresent
|
|
|
|
# Additional labels for Deployment
|
|
additionalLabels:
|
|
# key: value
|
|
|
|
# Additional label added on pod which is used in Service's Label Selector
|
|
podLabels:
|
|
# env: prod
|
|
|
|
# Annotations on deployments
|
|
annotations:
|
|
|
|
# Additional Pod Annotations added on pod created by this Deployment
|
|
additionalPodAnnotations:
|
|
# key: value
|
|
|
|
# Annotations for fluentd Configurations
|
|
fluentdConfigAnnotations:
|
|
# fluentd:
|
|
# regex: hello
|
|
# timeFormat: world
|
|
|
|
# Replicas to be created
|
|
replicas:
|
|
|
|
# Secrets used to pull image
|
|
imagePullSecrets: "regcred"
|
|
|
|
# If want to mount Envs from configmap or secret
|
|
envFrom:
|
|
application-config-env:
|
|
type: configmap
|
|
nameSuffix: configmap
|
|
application-secret-env:
|
|
type: secret
|
|
nameSuffix: secret
|
|
|
|
# Environment variables to be passed to the app container
|
|
env:
|
|
# FREQUENCY:
|
|
# valueFrom:
|
|
# configMapKeyRef:
|
|
# name: config
|
|
# key: frequency
|
|
|
|
# Volumes to be added to the pod
|
|
volumes:
|
|
nginx-volume:
|
|
configMap:
|
|
name: '{{ template "application.name" . }}-nginx'
|
|
# secret-volume:
|
|
# secret:
|
|
# secretName: secret-name
|
|
# persistent-volume-name:
|
|
# persistentVolumeClaim:
|
|
# claimName: claim-name
|
|
|
|
# Mount path for Volumes
|
|
volumeMounts:
|
|
nginx-volume:
|
|
mountPath: /etc/nginx/nginx.conf
|
|
subPath: nginx.conf
|
|
|
|
# volume-name-2:
|
|
# mountPath: path-2
|
|
|
|
# Taint tolerations for nodes
|
|
tolerations:
|
|
# - key: "dedicated"
|
|
# operator: "Equal"
|
|
# value: "app"
|
|
# effect: "NoSchedule"
|
|
|
|
# Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods.
|
|
affinity:
|
|
# nodeAffinity:
|
|
# requiredDuringSchedulingIgnoredDuringExecution:
|
|
# nodeSelectorTerms:
|
|
# - matchExpressions:
|
|
# - key: disktype
|
|
# operator: In
|
|
# values:
|
|
# - ssd
|
|
|
|
# Topology spread constraints
|
|
topologySpreadConstraints:
|
|
# - maxSkew: 1
|
|
# topologyKey: kubernetes.io/hostname
|
|
# whenUnsatisfiable: ScheduleAnyway
|
|
# labelSelector:
|
|
# matchExpressions:
|
|
# - key: disktype
|
|
# operator: In
|
|
# values:
|
|
# - ssd
|
|
# - maxSkew: 1
|
|
# topologyKey: topology.kubernetes.io/zone
|
|
# whenUnsatisfiable: ScheduleAnyway
|
|
# labelSelector:
|
|
# matchExpressions:
|
|
# - key: disktype
|
|
# operator: In
|
|
# values:
|
|
# - ssd
|
|
|
|
# Image of the app container
|
|
image:
|
|
repository: docker.meshkee.com/repository/docker-hosted/external-projects/cssd-back
|
|
tag: nginx-latest
|
|
digest: '' # if set to a non empty value, digest takes precedence on the tag
|
|
pullPolicy: IfNotPresent
|
|
dnsConfig:
|
|
# options:
|
|
# - name: ndots
|
|
# value: '1'
|
|
# Startup, Readiness and Liveness probes
|
|
startupProbe:
|
|
enabled: false
|
|
failureThreshold: 30
|
|
periodSeconds: 10
|
|
# Must specify either one of the following field when enabled
|
|
httpGet: {}
|
|
exec: {}
|
|
tcpSocket: {}
|
|
|
|
readinessProbe:
|
|
enabled: false
|
|
failureThreshold: 3
|
|
periodSeconds: 10
|
|
successThreshold: 1
|
|
timeoutSeconds: 1
|
|
initialDelaySeconds: 10
|
|
# Must specify either one of the following field when enabled
|
|
httpGet: {}
|
|
exec: {}
|
|
tcpSocket: {}
|
|
|
|
livenessProbe:
|
|
enabled: false
|
|
failureThreshold: 3
|
|
periodSeconds: 10
|
|
successThreshold: 1
|
|
timeoutSeconds: 1
|
|
initialDelaySeconds: 10
|
|
# Must specify either one of the following field when enabled
|
|
httpGet: {}
|
|
exec: {}
|
|
tcpSocket: {}
|
|
|
|
# Resources to be defined for pod
|
|
resources:
|
|
limits:
|
|
memory: 4Gi
|
|
cpu: 2
|
|
requests:
|
|
memory: 2Gi
|
|
cpu: 1
|
|
|
|
# Security Context at Container Level
|
|
containerSecurityContext:
|
|
readOnlyRootFilesystem: false
|
|
runAsNonRoot: false
|
|
|
|
openshiftOAuthProxy:
|
|
enabled: false
|
|
port: 8080 # Port on which application is running inside container
|
|
secretName: "openshift-oauth-proxy-tls"
|
|
image: openshift/oauth-proxy:latest # If you have a custom container for oauth-proxy that can be updated here
|
|
disableTLSArg: false # If disabled --http-address=:8081 will be used instead of --https-address=:8443 , to be used when an ingress is used for application
|
|
# Add additional containers besides init and app containers
|
|
additionalContainers:
|
|
- name: php-fpm
|
|
image: docker.meshkee.com/repository/docker-hosted/external-projects/cssd-back:latest
|
|
imagePullPolicy: IfNotPresent
|
|
envFrom:
|
|
- configMapRef:
|
|
name: cssd-production-back-configmap
|
|
- secretRef:
|
|
name: cssd-production-back-secret
|
|
|
|
|
|
# Security Context for the pod
|
|
|
|
securityContext:
|
|
# fsGroup: 2000
|
|
|
|
# Command for primary container
|
|
command: []
|
|
|
|
# Args for primary contaner
|
|
args: []
|
|
|
|
# List of ports for the primary container
|
|
ports:
|
|
- containerPort: 80
|
|
name: http
|
|
protocol: TCP
|
|
#- containerPort: 8778
|
|
# name: jolokia
|
|
# protocol: TCP
|
|
#- containerPort: 8443
|
|
# name: https
|
|
# protocol: TCP
|
|
|
|
worker:
|
|
enabled: false
|
|
|
|
# Additional labels for Deployment worker
|
|
additionalLabels:
|
|
# key: value
|
|
|
|
# Annotations on deployments worker
|
|
annotations:
|
|
|
|
# Replicas to be created worker
|
|
replicas: 1
|
|
|
|
# By default deploymentStrategy is set to rollingUpdate with maxSurge of 25% and maxUnavailable of 25%
|
|
# You can change type to `Recreate` or can uncomment `rollingUpdate` specification and adjust them to your usage.
|
|
strategy:
|
|
type: RollingUpdate
|
|
# rollingUpdate:
|
|
# maxSurge: 25%
|
|
# maxUnavailable: 25%
|
|
|
|
# Additional label added on pod which is used in Service's Label Selector
|
|
podLabels:
|
|
# env: prod
|
|
|
|
image: docker.meshkee.com/repository/docker-hosted/external-projects/cssd-back:latest
|
|
command:
|
|
- /usr/bin/supervisord
|
|
- -n
|
|
- -c
|
|
- /var/www/html/worker.conf
|
|
args:
|
|
envFrom:
|
|
- configMapRef:
|
|
name: balout-production-back-configmap
|
|
- secretRef:
|
|
name: balout-production-back-secret
|
|
|
|
resources:
|
|
limits:
|
|
memory: 1Gi
|
|
cpu: 1
|
|
requests:
|
|
memory: 1Gi
|
|
cpu: 1
|
|
|
|
|
|
##########################################################
|
|
# Add Storage volumes to the pods
|
|
##########################################################
|
|
persistence:
|
|
enabled: false
|
|
mountPVC: false
|
|
mountPath: "/"
|
|
name: ""
|
|
accessMode: ReadWriteOnce
|
|
## If defined, storageClass: <storageClass>
|
|
## If set to "-", storageClass: "", which disables dynamic provisioning
|
|
## If undefined (the default) or set to null, no storageClass spec is
|
|
## set, choosing the default provisioner. (gp2 on AWS, standard on
|
|
## GKE, AWS & OpenStack)
|
|
##
|
|
storageClass: "-"
|
|
additionalLabels:
|
|
# key: "value"
|
|
annotations:
|
|
# "helm.sh/resource-policy": keep
|
|
storageSize: 8Gi
|
|
volumeMode: ""
|
|
volumeName: ""
|
|
|
|
|
|
##########################################################
|
|
# Service object for servicing pods
|
|
##########################################################
|
|
service:
|
|
enabled: true
|
|
additionalLabels:
|
|
# expose: "true"
|
|
|
|
annotations:
|
|
# config.xposer.stakater.com/Domain: stakater.com
|
|
# config.xposer.stakater.com/IngressNameTemplate: '{{ "{{.Service}}-{{.Namespace}}" }}'
|
|
# config.xposer.stakater.com/IngressURLPath: /
|
|
# config.xposer.stakater.com/IngressURLTemplate: '{{ "{{.Service}}.{{.Namespace}}.{{.Domain}}" }}'
|
|
# service.alpha.openshift.io/serving-cert-secret-name: |
|
|
# '{{ template "application.name" . }}-tls'
|
|
# xposer.stakater.com/annotations: |-
|
|
# kubernetes.io/ingress.class: external-ingress
|
|
# ingress.kubernetes.io/rewrite-target: /
|
|
# ingress.kubernetes.io/force-ssl-redirect: true
|
|
|
|
ports:
|
|
- port: 80
|
|
name: http
|
|
protocol: TCP
|
|
targetPort: 80
|
|
type: NodePort
|
|
|
|
##########################################################
|
|
# Ingress object for exposing services
|
|
##########################################################
|
|
ingress:
|
|
enabled: true
|
|
|
|
# Name of the ingress class
|
|
ingressClassName: 'nginx'
|
|
|
|
# List of host addresses to be exposed by this Ingress
|
|
hosts:
|
|
- host: www.cssd-doc.ir
|
|
- host: www.cssd-doc.com
|
|
# Additional labels for this Ingress
|
|
additionalLabels:
|
|
|
|
# Add annotations to this Ingress
|
|
annotations:
|
|
ingress.kubernetes.io/force-ssl-redirect: "true"
|
|
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
|
|
# kubernetes.io/ingress.class: external-ingress
|
|
# ingress.kubernetes.io/rewrite-target: /
|
|
# ingress.kubernetes.io/force-ssl-redirect: true
|
|
|
|
# TLS details for this Ingress
|
|
tls:
|
|
# Secrets must be manually created in the namespace.
|
|
- secretName: cssd-doc-ir-certificate
|
|
hosts:
|
|
- www.cssd-doc.ir
|
|
- secretName: cssd-doc-com-certificate
|
|
hosts:
|
|
- www.cssd-doc.com
|
|
|
|
##########################################################
|
|
# Route object for exposing services (OpenShift)
|
|
##########################################################
|
|
route:
|
|
enabled: false
|
|
|
|
# Add annotations to this Route
|
|
annotations:
|
|
# kubernetes.io/ingress.class: external-ingress
|
|
# ingress.kubernetes.io/rewrite-target: /
|
|
# ingress.kubernetes.io/force-ssl-redirect: true
|
|
|
|
# Additional labels for this Route
|
|
additionalLabels:
|
|
|
|
# If no host is added then openshift inserts the default hostname. To Add host explicitly, use host attribute
|
|
host:
|
|
|
|
path:
|
|
# Port of the service that serves pods
|
|
port:
|
|
targetPort: http
|
|
|
|
to:
|
|
weight: 100
|
|
|
|
wildcardPolicy: None
|
|
|
|
tls:
|
|
# TLS Termination strategy
|
|
termination: edge
|
|
insecureEdgeTerminationPolicy: Redirect
|
|
|
|
alternateBackends:
|
|
# kind: Service
|
|
# name: alternate-application
|
|
# weight: 20
|
|
|
|
##########################################################
|
|
# SecretProviderClass
|
|
##########################################################
|
|
secretProviderClass:
|
|
enabled: false
|
|
name: ""
|
|
# name: example
|
|
provider: ""
|
|
# provider: vault
|
|
vaultAddress: ""
|
|
# vaultAddress: http://vault:8200
|
|
roleName: ""
|
|
# roleName: example-role
|
|
objects:
|
|
#- objectName: MONGO_HOST
|
|
# secretPath: testing/data/mongoDb
|
|
# secretKey: MONGO_HOST
|
|
secretObjects:
|
|
#- data:
|
|
# - key: MONGO_HOST
|
|
# objectName: host
|
|
# secretName: secret-mongo-host
|
|
# type: Opaque
|
|
|
|
##########################################################
|
|
# Expose Application on Forecastle Dashboard
|
|
# https://github.com/stakater/Forecastle
|
|
##########################################################
|
|
forecastle:
|
|
enabled: false
|
|
|
|
# Add additional labels on Forecastle Custom Resource
|
|
additionalLabels:
|
|
|
|
# URL of the icon for the custom app
|
|
icon: https://raw.githubusercontent.com/stakater/ForecastleIcons/master/stakater-big.png
|
|
|
|
# Name of the application to be displayed on the Forecastle Dashboard
|
|
displayName: "application"
|
|
|
|
# Group for the custom app (default: .Release.Namespace)
|
|
group: ""
|
|
|
|
# Add properties to Custom Resource
|
|
properties:
|
|
|
|
# Whether app is network restricted or not
|
|
networkRestricted: false
|
|
|
|
##########################################################
|
|
# Role Based Access Control (RBAC)
|
|
##########################################################
|
|
rbac:
|
|
enabled: true
|
|
|
|
# Service Account to use by pods
|
|
serviceAccount:
|
|
enabled: true
|
|
name: "cssd-production-back"
|
|
|
|
# Additional Labels on service account
|
|
additionalLabels:
|
|
# key: value
|
|
|
|
# Annotations on service account
|
|
annotations:
|
|
# key: value
|
|
|
|
# Create Roles (Namespaced)
|
|
roles:
|
|
# - name: configmaps
|
|
# rules:
|
|
# - apiGroups:
|
|
# - ""
|
|
# resources:
|
|
# - configmaps
|
|
# verbs:
|
|
# - get
|
|
# - name: secrets
|
|
# rules:
|
|
# - apiGroups:
|
|
# - ""
|
|
# resources:
|
|
# - secrets
|
|
# verbs:
|
|
# - get
|
|
|
|
##########################################################
|
|
# Additional ConfigMaps
|
|
##########################################################
|
|
configMap:
|
|
enabled: true
|
|
files:
|
|
nginx:
|
|
nginx.conf: |
|
|
user nginx;
|
|
worker_processes auto;
|
|
|
|
error_log /var/log/nginx/error.log warn;
|
|
pid /var/run/nginx.pid;
|
|
|
|
events {
|
|
worker_connections 1024;
|
|
}
|
|
|
|
http {
|
|
include /etc/nginx/mime.types;
|
|
default_type application/octet-stream;
|
|
server_tokens off;
|
|
|
|
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
|
|
'$status $body_bytes_sent "$http_referer" '
|
|
'"$http_user_agent" "$http_x_forwarded_for" "$http_x_real_ip" "$http_x_client_ip"';
|
|
|
|
access_log /var/log/nginx/access.log main;
|
|
|
|
sendfile on;
|
|
keepalive_timeout 65;
|
|
|
|
server {
|
|
listen 80;
|
|
server_name cssd-doc.ir www.cssd-doc.ir;
|
|
|
|
return 301 https://www.cssd-doc.com$request_uri;
|
|
}
|
|
|
|
server {
|
|
listen 80;
|
|
server_name cssd-doc.com;
|
|
|
|
return 301 https://www.cssd-doc.com$request_uri;
|
|
}
|
|
|
|
server {
|
|
listen 80;
|
|
server_name www.cssd-doc.com;
|
|
|
|
access_log /var/log/nginx/access.log main;
|
|
error_log /var/log/nginx/error.log;
|
|
|
|
charset utf-8;
|
|
client_max_body_size 500m;
|
|
|
|
error_page 404 /index.php;
|
|
|
|
index index.html index.htm index.php;
|
|
location / {
|
|
try_files $uri $uri/ /index.php?$query_string;
|
|
proxy_set_header X-Real-IP $http_x_real_ip;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
}
|
|
|
|
location ~* ^/.+\.(jpg|jpeg|png|gif|ico|css|js|otf|ttf|eot|woff|svg)$ {
|
|
root /var/www/html/public;
|
|
expires 365d;
|
|
}
|
|
|
|
location ~ \.php {
|
|
if ($request_method = 'OPTIONS' ) {
|
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
|
add_header 'Access-Control-Allow-Credentials' 'true';
|
|
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE';
|
|
add_header 'Access-Control-Allow-Headers'
|
|
'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type';
|
|
add_header 'Access-Control-Max-Age' 10;
|
|
add_header 'Content-Type' 'text/plain charset=UTF-8';
|
|
add_header 'Content-Length' 0;
|
|
return 204;
|
|
}
|
|
|
|
if ($request_method = 'POST' ) {
|
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
|
add_header 'Access-Control-Allow-Credentials' 'true';
|
|
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE';
|
|
add_header 'Access-Control-Allow-Headers'
|
|
'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type';
|
|
}
|
|
|
|
if ($request_method = 'GET' ) {
|
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
|
add_header 'Access-Control-Allow-Credentials' 'true';
|
|
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE';
|
|
add_header 'Access-Control-Allow-Headers'
|
|
'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type';
|
|
}
|
|
|
|
if ($request_method = 'PUT' ) {
|
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
|
add_header 'Access-Control-Allow-Credentials' 'true';
|
|
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE';
|
|
add_header 'Access-Control-Allow-Headers'
|
|
'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type';
|
|
}
|
|
|
|
if ($request_method = 'DELETE' ) {
|
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
|
add_header 'Access-Control-Allow-Credentials' 'true';
|
|
add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE';
|
|
add_header 'Access-Control-Allow-Headers'
|
|
'DNT,Authorization,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type';
|
|
}
|
|
fastcgi_pass localhost:9000;
|
|
fastcgi_split_path_info ^(.+\.php)(.*)$;
|
|
include /etc/nginx/fastcgi_params;
|
|
fastcgi_param SCRIPT_FILENAME /var/www/html/public/index.php;
|
|
fastcgi_param X-Real-IP $http_x_real_ip;
|
|
fastcgi_param X-Forwarded-For $http_x_forwarded_for;
|
|
}
|
|
}
|
|
}
|
|
|
|
##########################################################
|
|
# SealedSecrets
|
|
##########################################################
|
|
sealedSecret:
|
|
enabled: false
|
|
additionalLabels:
|
|
#key: value
|
|
annotations:
|
|
#key: value
|
|
files:
|
|
# #nameSuffix of sealedSecret
|
|
# example:
|
|
# encryptedData:
|
|
# name: AgBghrdepGMKmp/rdtJrkBv/CWpJbtmoMsbKQ7QiZZ2kUoLeeTbrDnhmJY03kWKkNW4kN/sQRf6r1vvBEaR4nkHt5f/ayAeaH3NveI3bdb0xv/svvWjyjehwqwr/kNEAVWxRoUij0Y7MyIEAr4hnV2UnrhgvcjPJLNA8bK6spA+kuT328Vpyceyvnm6yArNn1aYlEckaFHrnculHWRpG73iRYxS5GWAY7EdkLXx7OLLWoopHtLcupklYyPfraJzPvBNZ5/PsyjlUBvoQbGV3cZlrdEj1WHj2S1RQ13ddf2WGtMHmY83t9B3LFZAZuA7BBt4rjludbwQm3/tJ5Kas1dDsSIRIIF7MTeum9YfRB8XUz8IxVKQ/JDskeynrWe3VzN/3HFVnv9GGFy+BCVXZKVU/roIRancz+nXkyoOHS722ZpBi53dfLItoS5dG+0EzArMTQzK/KXHz3b1rxp5oWWDNt3WggTiSg2zwy5ZR8VV2ToTDof6UrFmbCZv/kKriyxbVSxIo3KFnvuRiUZ5MwC0TNut4mW3LKyJfHqkUuLa1mYV6tKF58qBnoj/+JaibAIBEudT9hms5U52p7/jKmgHuop7XPEsz4OVwER//Vbv7X6ctoXtyPu6mZyOfOyJHM8Qj/H7/gwMBYhZHQ96DWrVmZOsWSRpZGJni4Xm7rgt2cFj6UtWv6lvl8aOi/HSZVC3TwWZ9mQrk
|
|
# annotations:
|
|
# key: value
|
|
# labels:
|
|
# key: value
|
|
# clusterWide: true
|
|
# example2:
|
|
# encryptedData:
|
|
# name: AgBghrdepGMKmp/rdtJrkBv/CWpJbtmoMsbKQ7QiZZ2kUoLeeTbrDnhmJY03kWKkNW4kN/sQRf6r1vvBEaR4nkHt5f/ayAeaH3NveI3bdb0xv/svvWjyjehwqwr/kNEAVWxRoUij0Y7MyIEAr4hnV2UnrhgvcjPJLNA8bK6spA+kuT328Vpyceyvnm6yArNn1aYlEckaFHrnculHWRpG73iRYxS5GWAY7EdkLXx7OLLWoopHtLcupklYyPfraJzPvBNZ5/PsyjlUBvoQbGV3cZlrdEj1WHj2S1RQ13ddf2WGtMHmY83t9B3LFZAZuA7BBt4rjludbwQm3/tJ5Kas1dDsSIRIIF7MTeum9YfRB8XUz8IxVKQ/JDskeynrWe3VzN/3HFVnv9GGFy+BCVXZKVU/roIRancz+nXkyoOHS722ZpBi53dfLItoS5dG+0EzArMTQzK/KXHz3b1rxp5oWWDNt3WggTiSg2zwy5ZR8VV2ToTDof6UrFmbCZv/kKriyxbVSxIo3KFnvuRiUZ5MwC0TNut4mW3LKyJfHqkUuLa1mYV6tKF58qBnoj/+JaibAIBEudT9hms5U52p7/jKmgHuop7XPEsz4OVwER//Vbv7X6ctoXtyPu6mZyOfOyJHM8Qj/H7/gwMBYhZHQ96DWrVmZOsWSRpZGJni4Xm7rgt2cFj6UtWv6lvl8aOi/HSZVC3TwWZ9mQrk
|
|
|
|
##########################################################
|
|
# Additional Secrets
|
|
##########################################################
|
|
secret:
|
|
enabled: false
|
|
additionalLabels:
|
|
# key: value
|
|
annotations:
|
|
# key: value
|
|
files:
|
|
# nameSuffix of Secret
|
|
# credentials:
|
|
# data:
|
|
# secretKey1: secretValue1
|
|
# secretKey2: secretValue2
|
|
# password:
|
|
# data:
|
|
# secretKey1: secretValue1
|
|
# secretKey2: secretValue2
|
|
|
|
##########################################################
|
|
# Service Monitor to collect Prometheus metrices
|
|
##########################################################
|
|
serviceMonitor:
|
|
enabled: false
|
|
|
|
# Additional labels
|
|
additionalLabels:
|
|
# key: value
|
|
|
|
# Additional annotations
|
|
annotations:
|
|
# key: value
|
|
|
|
# List of the endpoints of service from which prometheus will scrape data
|
|
endpoints:
|
|
- interval: 5s
|
|
path: /actuator/prometheus
|
|
port: http
|
|
|
|
##########################################################
|
|
# HPA - Horizontal Pod Autoscaling
|
|
##########################################################
|
|
autoscaling:
|
|
# enabled is a boolean flag for enabling or disabling autoscaling
|
|
enabled: false
|
|
# additionalLabels defines additional labels
|
|
additionalLabels:
|
|
# key: value
|
|
# annotations defines annotations in key value pair
|
|
annotations:
|
|
# key: value
|
|
# minReplicas sets the minimum number of replicas
|
|
minReplicas: 1
|
|
# maxReplicas sets the maximum number of replicas
|
|
maxReplicas: 10
|
|
# metrics is the list of metrics used for hpa
|
|
metrics:
|
|
- type: Resource
|
|
resource:
|
|
name: cpu
|
|
target:
|
|
type: Utilization
|
|
averageUtilization: 60
|
|
- type: Resource
|
|
resource:
|
|
name: memory
|
|
target:
|
|
type: Utilization
|
|
averageUtilization: 60
|
|
|
|
##########################################################
|
|
# EndpointMonitor for IMC
|
|
# https://github.com/stakater/IngressMonitorController
|
|
##########################################################
|
|
endpointMonitor:
|
|
enabled: false
|
|
|
|
# Additional labels
|
|
additionalLabels:
|
|
# key: value
|
|
|
|
# Additional annotations
|
|
annotations:
|
|
# key: value
|
|
|
|
##########################################################
|
|
# Certficate CRD to generate the certificate
|
|
##########################################################
|
|
certificate:
|
|
enabled: false
|
|
|
|
# Additional labels
|
|
additionalLabels:
|
|
# key: value
|
|
|
|
# Additional annotations
|
|
annotations:
|
|
# key: value
|
|
|
|
secretName: tls-cert
|
|
duration: 8760h0m0s # 1 year
|
|
renewBefore: 720h0m0s # 30d
|
|
subject:
|
|
# organizations:
|
|
# - stakater
|
|
# countries:
|
|
# - SE
|
|
# organizationalUnits:
|
|
# - '{{ template "application.namespace" . }}'
|
|
# localities:
|
|
# - Stockholm
|
|
# provinces:
|
|
# - Stockholm
|
|
commonName: admin-app
|
|
keyAlgorithm: rsa
|
|
keyEncoding: pkcs1
|
|
keySize: 2048
|
|
isCA: false
|
|
usages:
|
|
# - digital signature
|
|
# - client auth
|
|
dnsNames:
|
|
# - admin-app
|
|
ipAddresses:
|
|
# - 192.168.0.5
|
|
uriSANs:
|
|
# - spiffe://cluster.local/ns/sandbox/sa/example
|
|
emailSANs:
|
|
# - emailSubjectAltNames
|
|
privateKey:
|
|
enabled: false
|
|
rotationPolicy: Always
|
|
issuerRef:
|
|
name: ca-issuer
|
|
# We can reference ClusterIssuers by changing the kind here.
|
|
kind: ClusterIssuer
|
|
group: #cert-manager.io
|
|
keystores:
|
|
enabled: false
|
|
pkcs12:
|
|
create: true
|
|
key: test_key
|
|
name: test-creds
|
|
jks:
|
|
create: false
|
|
key: test_key
|
|
name: test-creds
|
|
|
|
##########################################################
|
|
# AlertmanagerConfig object for defining application
|
|
# specific alertmanager configurations
|
|
##########################################################
|
|
alertmanagerConfig:
|
|
enabled: false
|
|
|
|
# AlertmanagerConfig selectionLabels to specify label to be picked up by Alertmanager to add it to base config. Read more about it at [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/alertmanager-monitoring-coreos-com-v1.html] under .spec.alertmanagerConfigSelector
|
|
selectionLabels:
|
|
alertmanagerConfig: "workload"
|
|
|
|
# AlertmanagerConfig spec, read details here [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/alertmanagerconfig-monitoring-coreos-com-v1alpha1.html]
|
|
spec:
|
|
route:
|
|
# receiver: "null"
|
|
# groupBy:
|
|
# - job
|
|
# routes:
|
|
# - receiver: "null"
|
|
# groupBy:
|
|
# - alertname
|
|
# - severity
|
|
# continue: true
|
|
# groupWait: 30s
|
|
# groupInterval: 5m
|
|
# repeatInterval: 12h
|
|
receivers: []
|
|
# - name: "null"
|
|
inhibitRules: []
|
|
# - sourceMatch:
|
|
# severity: 'critical'
|
|
# targetMatch:
|
|
# severity: 'warning'
|
|
# equal: ['cluster', 'service']
|
|
|
|
##########################################################
|
|
# PrometheusRule object for defining application
|
|
# alerting rules
|
|
##########################################################
|
|
prometheusRule:
|
|
enabled: false
|
|
|
|
# PrometheusRule labels
|
|
additionalLabels:
|
|
# prometheus: stakater-workload-monitoring
|
|
# role: alert-rules
|
|
|
|
# Groups with alerting rules. Read more here [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/prometheusrule-monitoring-coreos-com-v1.html]
|
|
|
|
groups: []
|
|
# - name: example-app-uptime
|
|
# rules:
|
|
# - alert: ExampleAppDown
|
|
# annotations:
|
|
# message: >-
|
|
# The Example App is Down (Test Alert)
|
|
# expr: up{namespace="test-app"} == 0
|
|
# for: 1m
|
|
# labels:
|
|
# severity: critical
|
|
##########################################################
|
|
# External Secrets
|
|
##########################################################
|
|
externalSecret:
|
|
enabled: false
|
|
|
|
# Default SecretStore for all externalsecrets defines which SecretStore to use when fetching the secret data
|
|
secretStore:
|
|
name: tenant-vault-secret-store
|
|
#kind: ClusterSecretStore # Defaults to SecretStore if not specified
|
|
|
|
# RefreshInterval is the amount of time before the values reading again from the SecretStore provider
|
|
refreshInterval: "1m"
|
|
files:
|
|
# mongodb:
|
|
# # Data defines the connection between the Kubernetes Secret keys and the Provider data
|
|
# data:
|
|
# mongo-password:
|
|
# remoteRef:
|
|
# key: monodb
|
|
# property: passowrd
|
|
# secretStore:
|
|
# name: secret-store-name-2 # specify if value is other than default secretstore
|
|
# labels:
|
|
# stakater.com/app: mongodb
|
|
# #
|
|
# postgres:
|
|
## Used to fetch all properties from the Provider key
|
|
# dataFrom:
|
|
# key: postgres
|
|
|
|
|
|
##########################################################
|
|
# Network Policy
|
|
##########################################################
|
|
networkPolicy:
|
|
enabled: false
|
|
additionalLabels:
|
|
# key: value
|
|
annotations:
|
|
# key: value
|
|
ingress:
|
|
# - from:
|
|
# - ipBlock:
|
|
# cidr: 172.17.0.0/16
|
|
# except:
|
|
# - 172.17.1.0/24
|
|
# - namespaceSelector:
|
|
# matchLabels:
|
|
# project: myproject
|
|
# - podSelector:
|
|
# matchLabels:
|
|
# role: frontend
|
|
# ports:
|
|
# - protocol: TCP
|
|
# port: 6379
|
|
egress:
|
|
# - to:
|
|
# - ipBlock:
|
|
# cidr: 10.0.0.0/24
|
|
# ports:
|
|
# - protocol: TCP
|
|
# port: 5978
|
|
|
|
##########################################################
|
|
# Pod disruption budget - PDB
|
|
##########################################################
|
|
pdb:
|
|
enabled: false
|
|
minAvailable: 1
|
|
# maxUnavailable: 1
|
|
|
|
##########################################################
|
|
# grafanaDashboard object for defining application
|
|
# Grafana Dashboard
|
|
##########################################################
|
|
grafanaDashboard:
|
|
enabled: false
|
|
|
|
# GrafanaDashboard additonal labels
|
|
additionalLabels:
|
|
# grafanaDashboard: grafana-operator
|
|
|
|
# GrafanaDashboard annotations
|
|
annotations:
|
|
# key: value
|
|
|
|
# GrafanaDashboard contents
|
|
# this includes pairs of dashboard name and associated json content
|
|
# Accoroding to GrafanaDashboard behavior, if both url and json are specified then the GrafanaDashboard content will be updated with fetched content from url
|
|
contents:
|
|
# dashboard-name-1:
|
|
# json: |-
|
|
# {
|
|
# "data"
|
|
# }
|
|
# url: http://hostname/path/to/file.json
|
|
# dashboard-name-2:
|
|
# json: |-
|
|
# {
|
|
# "data"
|
|
# }
|
|
# url: http://hostname/path/to/file.json
|