Fix Kubernetes manifest bugs, dedupe drifted files, harden security
- Rebuild manifests/doormile/miletruth.yaml (was corrupted since the initial commit - contained pasted AI/terminal output, truncated env var names/values, duplicate keys). Rebuilt from the confirmed-live config, secrets sourced via a Secret instead of plaintext values. - Lock down the Kubernetes Dashboard: remove --enable-skip-login / --enable-insecure-login / --insecure-port=9090, remove the extra cluster-admin binding on the dashboard's own ServiceAccount, remove the now-dead insecure NodePort Service. Token-based login via the existing admin-user ServiceAccount is unaffected. - Fix the duplicate `backendRefs` key under the same HTTPRoute rule in alaska.yaml (invalid/redundant YAML). - Delete 6 redundant duplicate manifests (fiesta-sts/svc, atlantis-sts/svc, jupiter-sts/svc) that were partial, stale subsets of nearle-fiesta/atlantis/jupiter.yaml - one pair disagreed on the fiesta image tag entirely (v1.3.50 vs v1.3.67, neither of which matched what's actually live). - Reconcile nearle-fiesta.yaml and nearle-jupiter.yaml image tags to the confirmed-live versions (v1.3.78 / v2.7.55). - Add allowPrivilegeEscalation:false + drop-all-capabilities to fiesta/atlantis/jupiter/titan/ariane and the 5 specialized core workers, which previously ran with no securityContext at all. - Add terminationGracePeriodSeconds:45 to the worker StatefulSets so Kubernetes gives the new graceful-shutdown drain (see worker.py changes) enough time before SIGKILL.
This commit is contained in:
@@ -330,10 +330,6 @@ spec:
|
|||||||
- name: deliveries-service
|
- name: deliveries-service
|
||||||
port: 8000
|
port: 8000
|
||||||
weight: 100
|
weight: 100
|
||||||
backendRefs:
|
|
||||||
- name: deliveries-service
|
|
||||||
port: 8000
|
|
||||||
weight: 100
|
|
||||||
- matches:
|
- matches:
|
||||||
- path:
|
- path:
|
||||||
type: PathPrefix
|
type: PathPrefix
|
||||||
|
|||||||
@@ -34,19 +34,6 @@ metadata:
|
|||||||
kubernetes.io/service-account.name: "admin-user"
|
kubernetes.io/service-account.name: "admin-user"
|
||||||
type: kubernetes.io/service-account-token
|
type: kubernetes.io/service-account-token
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: ClusterRoleBinding
|
|
||||||
metadata:
|
|
||||||
name: kubernetes-dashboard-admin
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: ClusterRole
|
|
||||||
name: cluster-admin
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: kubernetes-dashboard
|
|
||||||
namespace: kubernetes-dashboard
|
|
||||||
---
|
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
@@ -75,9 +62,6 @@ spec:
|
|||||||
args:
|
args:
|
||||||
- --auto-generate-certificates
|
- --auto-generate-certificates
|
||||||
- --namespace=kubernetes-dashboard
|
- --namespace=kubernetes-dashboard
|
||||||
- --enable-skip-login
|
|
||||||
- --enable-insecure-login
|
|
||||||
- --insecure-port=9090
|
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: kubernetes-dashboard-certs
|
- name: kubernetes-dashboard-certs
|
||||||
mountPath: /certs
|
mountPath: /certs
|
||||||
@@ -135,10 +119,6 @@ spec:
|
|||||||
targetPort: 8443
|
targetPort: 8443
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
name: https
|
name: https
|
||||||
- port: 9090
|
|
||||||
targetPort: 9090
|
|
||||||
protocol: TCP
|
|
||||||
name: http
|
|
||||||
selector:
|
selector:
|
||||||
k8s-app: kubernetes-dashboard
|
k8s-app: kubernetes-dashboard
|
||||||
---
|
---
|
||||||
@@ -307,22 +287,3 @@ spec:
|
|||||||
targetPort: 8083
|
targetPort: 8083
|
||||||
nodePort: 30826
|
nodePort: 30826
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: dashboard-loadbalancer
|
|
||||||
namespace: kubernetes-dashboard
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: kubernetes-dashboard
|
|
||||||
app.kubernetes.io/component: loadbalancer
|
|
||||||
spec:
|
|
||||||
type: NodePort
|
|
||||||
selector:
|
|
||||||
k8s-app: kubernetes-dashboard
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 9090
|
|
||||||
targetPort: 9090 # Dashboard HTTP port
|
|
||||||
nodePort: 30827 # Fixed NodePort for nginx proxy
|
|
||||||
protocol: TCP
|
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ spec:
|
|||||||
prometheus.io/port: "9090"
|
prometheus.io/port: "9090"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
spec:
|
spec:
|
||||||
|
terminationGracePeriodSeconds: 45
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsUser: 1000
|
runAsUser: 1000
|
||||||
runAsGroup: 1000
|
runAsGroup: 1000
|
||||||
|
|||||||
@@ -22,6 +22,7 @@ spec:
|
|||||||
prometheus.io/port: "9090"
|
prometheus.io/port: "9090"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
spec:
|
spec:
|
||||||
|
terminationGracePeriodSeconds: 45
|
||||||
tolerations:
|
tolerations:
|
||||||
- key: dedicated
|
- key: dedicated
|
||||||
operator: Equal
|
operator: Equal
|
||||||
@@ -58,6 +59,11 @@ spec:
|
|||||||
- name: worker
|
- name: worker
|
||||||
image: workolik360/nats-worker:v1.1.0
|
image: workolik360/nats-worker:v1.1.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
command: ["python3", "-u", "/scripts/worker.py"]
|
command: ["python3", "-u", "/scripts/worker.py"]
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: worker-script-vol
|
- name: worker-script-vol
|
||||||
@@ -132,6 +138,7 @@ spec:
|
|||||||
prometheus.io/port: "9090"
|
prometheus.io/port: "9090"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
spec:
|
spec:
|
||||||
|
terminationGracePeriodSeconds: 45
|
||||||
tolerations:
|
tolerations:
|
||||||
- key: dedicated
|
- key: dedicated
|
||||||
operator: Equal
|
operator: Equal
|
||||||
@@ -168,6 +175,11 @@ spec:
|
|||||||
- name: worker
|
- name: worker
|
||||||
image: workolik360/nats-worker:v1.1.0
|
image: workolik360/nats-worker:v1.1.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
command: ["python3", "-u", "/scripts/worker.py"]
|
command: ["python3", "-u", "/scripts/worker.py"]
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: worker-script-vol
|
- name: worker-script-vol
|
||||||
@@ -236,6 +248,7 @@ spec:
|
|||||||
prometheus.io/port: "9090"
|
prometheus.io/port: "9090"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
spec:
|
spec:
|
||||||
|
terminationGracePeriodSeconds: 45
|
||||||
tolerations:
|
tolerations:
|
||||||
- key: dedicated
|
- key: dedicated
|
||||||
operator: Equal
|
operator: Equal
|
||||||
@@ -272,6 +285,11 @@ spec:
|
|||||||
- name: worker
|
- name: worker
|
||||||
image: workolik360/nats-worker:v1.1.0
|
image: workolik360/nats-worker:v1.1.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
command: ["python3", "-u", "/scripts/worker.py"]
|
command: ["python3", "-u", "/scripts/worker.py"]
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: worker-script-vol
|
- name: worker-script-vol
|
||||||
@@ -346,6 +364,7 @@ spec:
|
|||||||
prometheus.io/port: "9090"
|
prometheus.io/port: "9090"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
spec:
|
spec:
|
||||||
|
terminationGracePeriodSeconds: 45
|
||||||
tolerations:
|
tolerations:
|
||||||
- key: dedicated
|
- key: dedicated
|
||||||
operator: Equal
|
operator: Equal
|
||||||
@@ -382,6 +401,11 @@ spec:
|
|||||||
- name: worker
|
- name: worker
|
||||||
image: workolik360/nats-worker:v1.1.0
|
image: workolik360/nats-worker:v1.1.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
command: ["python3", "-u", "/scripts/worker.py"]
|
command: ["python3", "-u", "/scripts/worker.py"]
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: worker-script-vol
|
- name: worker-script-vol
|
||||||
@@ -456,6 +480,7 @@ spec:
|
|||||||
prometheus.io/port: "9090"
|
prometheus.io/port: "9090"
|
||||||
prometheus.io/path: "/metrics"
|
prometheus.io/path: "/metrics"
|
||||||
spec:
|
spec:
|
||||||
|
terminationGracePeriodSeconds: 45
|
||||||
tolerations:
|
tolerations:
|
||||||
- key: dedicated
|
- key: dedicated
|
||||||
operator: Equal
|
operator: Equal
|
||||||
@@ -492,6 +517,11 @@ spec:
|
|||||||
- name: worker
|
- name: worker
|
||||||
image: workolik360/nats-worker:v1.1.0
|
image: workolik360/nats-worker:v1.1.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
command: ["python3", "-u", "/scripts/worker.py"]
|
command: ["python3", "-u", "/scripts/worker.py"]
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: worker-script-vol
|
- name: worker-script-vol
|
||||||
|
|||||||
@@ -2,26 +2,31 @@ apiVersion: v1
|
|||||||
kind: Namespace
|
kind: Namespace
|
||||||
metadata:
|
metadata:
|
||||||
name: doormile
|
name: doormile
|
||||||
|
labels:
|
||||||
Read 1 file
|
|
||||||
|
|
||||||
Found the critical issue — INTERNAL_API_KEY not set in the manifest means
|
|
||||||
all /internal/* endpoode explicitly rejects empty keys). That plus the NATS_URL duplicate.
|
|
||||||
|
|
||||||
Here's the corrected miletruth.yaml with all missing env vars added. Run
|
|
||||||
this on the server:
|
|
||||||
|
|
||||||
cat > /root/kuberneteh.yaml << 'EOF'
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: doormile
|
name: doormile
|
||||||
---
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: doormile-secrets
|
||||||
|
namespace: doormile
|
||||||
|
labels:
|
||||||
|
app: doormile
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
DB_PASSWORD: "Package@321#"
|
||||||
|
REDIS_PASSWORD: "Package@321#"
|
||||||
|
NATS_USER: "doormile"
|
||||||
|
NATS_PASSWORD: "Package@321#"
|
||||||
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: StatefulSet
|
kind: StatefulSet
|
||||||
metadata:
|
metadata:
|
||||||
name: doormile
|
name: doormile
|
||||||
namespace: doormile
|
namespace: doormile
|
||||||
|
labels:
|
||||||
|
app: doormile
|
||||||
|
app-group: doormile-api
|
||||||
spec:
|
spec:
|
||||||
serviceName: "doormile-service"
|
serviceName: "doormile-service"
|
||||||
replicas: 3
|
replicas: 3
|
||||||
@@ -33,57 +38,68 @@ spec:
|
|||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
app: doormile
|
app: doormile
|
||||||
app-group: do
|
app-group: doormile-api
|
||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: doormile
|
- name: doormile
|
||||||
image: doormi
|
image: doormile/doormile-backend:latest
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
ports:
|
||||||
|
- containerPort: 8081
|
||||||
env:
|
env:
|
||||||
- name: ENV
|
- name: DB_HOST
|
||||||
value: "production"
|
|
||||||
- name: APP_PORT
|
|
||||||
value: "8081"
|
|
||||||
- name: DB_HO
|
|
||||||
value: "31.97.228.132"
|
value: "31.97.228.132"
|
||||||
- name: DB_PO
|
- name: DB_PORT
|
||||||
value: "5433"
|
value: "5433"
|
||||||
- name: DB_NA
|
- name: DB_NAME
|
||||||
value: "logistics"
|
value: "logistics"
|
||||||
- name: DB_US
|
- name: DB_USER
|
||||||
value: "admin"
|
value: "admin"
|
||||||
- name: DB_PASSWORD
|
- name: DB_PASSWORD
|
||||||
value: "Pac
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: doormile-secrets
|
||||||
|
key: DB_PASSWORD
|
||||||
- name: REDIS_HOST
|
- name: REDIS_HOST
|
||||||
value: "31.97.228.132"
|
value: "31.97.228.132"
|
||||||
- name: REDIS
|
- name: REDIS_PORT
|
||||||
value: "6379"
|
value: "6379"
|
||||||
- name: REDIS_USER
|
|
||||||
value: "adm
|
|
||||||
- name: REDIS_PASSWORD
|
- name: REDIS_PASSWORD
|
||||||
value: "Package@321#"
|
valueFrom:
|
||||||
- name: JWT_S
|
secretKeyRef:
|
||||||
value: "DoormileSuperSecretJWTKey2026!"
|
name: doormile-secrets
|
||||||
- name: NATS_
|
key: REDIS_PASSWORD
|
||||||
|
- name: NATS_URL
|
||||||
value: "nats://66.116.226.161:4223"
|
value: "nats://66.116.226.161:4223"
|
||||||
- name: NATS_
|
- name: NATS_USER
|
||||||
value: "doormile"
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: doormile-secrets
|
||||||
|
key: NATS_USER
|
||||||
- name: NATS_PASSWORD
|
- name: NATS_PASSWORD
|
||||||
value: "Pac
|
valueFrom:
|
||||||
- name: INTERNAL_API_KEY
|
secretKeyRef:
|
||||||
value: "doormile-internal-2024"
|
name: doormile-secrets
|
||||||
|
key: NATS_PASSWORD
|
||||||
---
|
---
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: doormile-service
|
name: doormile-service
|
||||||
namespace: doormile
|
namespace: doormile
|
||||||
|
labels:
|
||||||
|
app: doormile
|
||||||
spec:
|
spec:
|
||||||
type: NodePort
|
type: NodePort
|
||||||
selector:
|
selector:
|
||||||
app-group: doormile-api
|
app-group: doormile-api
|
||||||
ports:
|
ports:
|
||||||
- protocol: TCP
|
- protocol: TCP
|
||||||
port: 8081
|
port: 8081 # Expose port 8081 internally
|
||||||
targetPort: 808
|
targetPort: 8081 # The port the backend application actually listens on
|
||||||
nodePort: 30830
|
nodePort: 30830 # This must match what NGINX is looking for
|
||||||
|
|||||||
@@ -1,61 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: atlantis
|
|
||||||
namespace: nearle
|
|
||||||
labels:
|
|
||||||
app: atlantis
|
|
||||||
spec:
|
|
||||||
serviceName: "atlantis"
|
|
||||||
replicas: 2
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: atlantis
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: atlantis
|
|
||||||
spec:
|
|
||||||
tolerations:
|
|
||||||
- key: dedicated
|
|
||||||
operator: Equal
|
|
||||||
value: apps
|
|
||||||
effect: NoSchedule
|
|
||||||
affinity:
|
|
||||||
nodeAffinity:
|
|
||||||
requiredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
nodeSelectorTerms:
|
|
||||||
- matchExpressions:
|
|
||||||
- key: node-role.workolik/app
|
|
||||||
operator: In
|
|
||||||
values:
|
|
||||||
- "true"
|
|
||||||
podAntiAffinity:
|
|
||||||
preferredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
- weight: 100
|
|
||||||
podAffinityTerm:
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: atlantis
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
topologySpreadConstraints:
|
|
||||||
- maxSkew: 1
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
whenUnsatisfiable: ScheduleAnyway
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: atlantis
|
|
||||||
containers:
|
|
||||||
- name: backend
|
|
||||||
image: nearlecommerce/atlantis:v0.0.41
|
|
||||||
imagePullPolicy: Always
|
|
||||||
ports:
|
|
||||||
- containerPort: 3000
|
|
||||||
env:
|
|
||||||
- name: PORT
|
|
||||||
value: "3000"
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: nearle-config
|
|
||||||
- secretRef:
|
|
||||||
name: app-secrets
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: atlantis
|
|
||||||
namespace: nearle
|
|
||||||
labels:
|
|
||||||
app: atlantis
|
|
||||||
spec:
|
|
||||||
type: NodePort
|
|
||||||
ports:
|
|
||||||
- port: 80
|
|
||||||
targetPort: 3000
|
|
||||||
nodePort: 30825
|
|
||||||
protocol: TCP
|
|
||||||
selector:
|
|
||||||
app: atlantis
|
|
||||||
@@ -1,99 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: fiesta
|
|
||||||
namespace: nearle
|
|
||||||
labels:
|
|
||||||
app: fiesta
|
|
||||||
spec:
|
|
||||||
serviceName: "fiesta"
|
|
||||||
replicas: 3
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: fiesta
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: fiesta
|
|
||||||
spec:
|
|
||||||
tolerations:
|
|
||||||
- key: dedicated
|
|
||||||
operator: Equal
|
|
||||||
value: apps
|
|
||||||
effect: NoSchedule
|
|
||||||
affinity:
|
|
||||||
nodeAffinity:
|
|
||||||
requiredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
nodeSelectorTerms:
|
|
||||||
- matchExpressions:
|
|
||||||
- key: node-role.workolik/app
|
|
||||||
operator: In
|
|
||||||
values:
|
|
||||||
- "true"
|
|
||||||
podAntiAffinity:
|
|
||||||
preferredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
- weight: 100
|
|
||||||
podAffinityTerm:
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: fiesta
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
topologySpreadConstraints:
|
|
||||||
- maxSkew: 1
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
whenUnsatisfiable: ScheduleAnyway
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: fiesta
|
|
||||||
containers:
|
|
||||||
- name: backend
|
|
||||||
image: nearlecommerce/fiesta:v1.3.67
|
|
||||||
imagePullPolicy: Always
|
|
||||||
ports:
|
|
||||||
- containerPort: 1122
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: nearle-config
|
|
||||||
- secretRef:
|
|
||||||
name: app-secrets
|
|
||||||
env:
|
|
||||||
- name: PORT
|
|
||||||
value: "1122"
|
|
||||||
- name: NATS_USER
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: nats-credentials
|
|
||||||
key: username
|
|
||||||
- name: NATS_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: nats-credentials
|
|
||||||
key: password
|
|
||||||
- name: gateway
|
|
||||||
image: workolik360/alaska:v1.2.0
|
|
||||||
imagePullPolicy: Always
|
|
||||||
ports:
|
|
||||||
- containerPort: 8000
|
|
||||||
name: http
|
|
||||||
volumeMounts:
|
|
||||||
- name: gateway-script
|
|
||||||
mountPath: /app/app.py
|
|
||||||
subPath: app.py
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: nearle-config
|
|
||||||
env:
|
|
||||||
- name: NATS_USER
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: nats-credentials
|
|
||||||
key: username
|
|
||||||
- name: NATS_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: nats-credentials
|
|
||||||
key: password
|
|
||||||
volumes:
|
|
||||||
- name: gateway-script
|
|
||||||
configMap:
|
|
||||||
name: fiesta-gateway-script
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: fiesta
|
|
||||||
namespace: nearle
|
|
||||||
labels:
|
|
||||||
app: fiesta
|
|
||||||
spec:
|
|
||||||
type: NodePort
|
|
||||||
ports:
|
|
||||||
- port: 80
|
|
||||||
targetPort: 1122
|
|
||||||
nodePort: 30823
|
|
||||||
protocol: TCP
|
|
||||||
name: main
|
|
||||||
- port: 8000
|
|
||||||
targetPort: 8000
|
|
||||||
name: gateway
|
|
||||||
protocol: TCP
|
|
||||||
selector:
|
|
||||||
app: fiesta
|
|
||||||
@@ -1,77 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: jupiter
|
|
||||||
namespace: nearle
|
|
||||||
labels:
|
|
||||||
app: jupiter
|
|
||||||
spec:
|
|
||||||
serviceName: "jupiter"
|
|
||||||
replicas: 3
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: jupiter
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: jupiter
|
|
||||||
spec:
|
|
||||||
tolerations:
|
|
||||||
- key: dedicated
|
|
||||||
operator: Equal
|
|
||||||
value: apps
|
|
||||||
effect: NoSchedule
|
|
||||||
affinity:
|
|
||||||
nodeAffinity:
|
|
||||||
requiredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
nodeSelectorTerms:
|
|
||||||
- matchExpressions:
|
|
||||||
- key: node-role.workolik/app
|
|
||||||
operator: In
|
|
||||||
values:
|
|
||||||
- "true"
|
|
||||||
podAntiAffinity:
|
|
||||||
preferredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
- weight: 100
|
|
||||||
podAffinityTerm:
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: jupiter
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
topologySpreadConstraints:
|
|
||||||
- maxSkew: 1
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
whenUnsatisfiable: ScheduleAnyway
|
|
||||||
labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: jupiter
|
|
||||||
containers:
|
|
||||||
- name: jupiter
|
|
||||||
image: nearlecommerce/jupiter:v2.7.53
|
|
||||||
imagePullPolicy: Always
|
|
||||||
ports:
|
|
||||||
- containerPort: 1009
|
|
||||||
env:
|
|
||||||
- name: PORT
|
|
||||||
value: "1009"
|
|
||||||
- name: TZ
|
|
||||||
value: "Asia/Kolkata"
|
|
||||||
volumeMounts:
|
|
||||||
- name: tz-config
|
|
||||||
mountPath: /etc/localtime
|
|
||||||
readOnly: true
|
|
||||||
- name: tz-data
|
|
||||||
mountPath: /usr/share/zoneinfo
|
|
||||||
readOnly: true
|
|
||||||
envFrom:
|
|
||||||
- configMapRef:
|
|
||||||
name: nearle-config
|
|
||||||
- secretRef:
|
|
||||||
name: app-secrets
|
|
||||||
volumes:
|
|
||||||
- name: tz-config
|
|
||||||
hostPath:
|
|
||||||
path: /usr/share/zoneinfo/Asia/Kolkata
|
|
||||||
- name: tz-data
|
|
||||||
hostPath:
|
|
||||||
path: /usr/share/zoneinfo
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: jupiter
|
|
||||||
namespace: nearle
|
|
||||||
labels:
|
|
||||||
app: jupiter
|
|
||||||
spec:
|
|
||||||
type: NodePort
|
|
||||||
ports:
|
|
||||||
- port: 80
|
|
||||||
targetPort: 1009
|
|
||||||
nodePort: 30822
|
|
||||||
protocol: TCP
|
|
||||||
selector:
|
|
||||||
app: jupiter
|
|
||||||
@@ -49,6 +49,11 @@ spec:
|
|||||||
- name: backend
|
- name: backend
|
||||||
image: nearlecommerce/ariane:v1.0.22
|
image: nearlecommerce/ariane:v1.0.22
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 1000
|
- containerPort: 1000
|
||||||
env:
|
env:
|
||||||
|
|||||||
@@ -49,6 +49,11 @@ spec:
|
|||||||
- name: backend
|
- name: backend
|
||||||
image: nearlecommerce/atlantis:v0.0.41
|
image: nearlecommerce/atlantis:v0.0.41
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 3000
|
- containerPort: 3000
|
||||||
env:
|
env:
|
||||||
|
|||||||
@@ -47,8 +47,13 @@ spec:
|
|||||||
app: fiesta
|
app: fiesta
|
||||||
containers:
|
containers:
|
||||||
- name: backend
|
- name: backend
|
||||||
image: nearlecommerce/fiesta:v1.3.50
|
image: nearlecommerce/fiesta:v1.3.78
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 1122
|
- containerPort: 1122
|
||||||
envFrom:
|
envFrom:
|
||||||
@@ -72,6 +77,11 @@ spec:
|
|||||||
- name: gateway
|
- name: gateway
|
||||||
image: workolik360/alaska:v1.2.0
|
image: workolik360/alaska:v1.2.0
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8000
|
- containerPort: 8000
|
||||||
name: http
|
name: http
|
||||||
|
|||||||
@@ -47,8 +47,13 @@ spec:
|
|||||||
app: jupiter
|
app: jupiter
|
||||||
containers:
|
containers:
|
||||||
- name: jupiter
|
- name: jupiter
|
||||||
image: nearlecommerce/jupiter:v2.7.31
|
image: nearlecommerce/jupiter:v2.7.55
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 1009
|
- containerPort: 1009
|
||||||
env:
|
env:
|
||||||
|
|||||||
@@ -49,6 +49,11 @@ spec:
|
|||||||
- name: backend
|
- name: backend
|
||||||
image: groomgear/groomgear:v1.0.41
|
image: groomgear/groomgear:v1.0.41
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 1006
|
- containerPort: 1006
|
||||||
---
|
---
|
||||||
|
|||||||
Reference in New Issue
Block a user