- Rebuild manifests/doormile/miletruth.yaml (was corrupted since the initial commit - contained pasted AI/terminal output, truncated env var names/values, duplicate keys). Rebuilt from the confirmed-live config, secrets sourced via a Secret instead of plaintext values. - Lock down the Kubernetes Dashboard: remove --enable-skip-login / --enable-insecure-login / --insecure-port=9090, remove the extra cluster-admin binding on the dashboard's own ServiceAccount, remove the now-dead insecure NodePort Service. Token-based login via the existing admin-user ServiceAccount is unaffected. - Fix the duplicate `backendRefs` key under the same HTTPRoute rule in alaska.yaml (invalid/redundant YAML). - Delete 6 redundant duplicate manifests (fiesta-sts/svc, atlantis-sts/svc, jupiter-sts/svc) that were partial, stale subsets of nearle-fiesta/atlantis/jupiter.yaml - one pair disagreed on the fiesta image tag entirely (v1.3.50 vs v1.3.67, neither of which matched what's actually live). - Reconcile nearle-fiesta.yaml and nearle-jupiter.yaml image tags to the confirmed-live versions (v1.3.78 / v2.7.55). - Add allowPrivilegeEscalation:false + drop-all-capabilities to fiesta/atlantis/jupiter/titan/ariane and the 5 specialized core workers, which previously ran with no securityContext at all. - Add terminationGracePeriodSeconds:45 to the worker StatefulSets so Kubernetes gives the new graceful-shutdown drain (see worker.py changes) enough time before SIGKILL.
573 lines
16 KiB
YAML
573 lines
16 KiB
YAML
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: worker-orders
|
|
namespace: core
|
|
labels:
|
|
app.kubernetes.io/name: worker-orders
|
|
app.kubernetes.io/component: worker
|
|
spec:
|
|
serviceName: "worker-orders"
|
|
replicas: 3
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-orders
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: worker-orders
|
|
app.kubernetes.io/component: worker
|
|
annotations:
|
|
prometheus.io/scrape: "true"
|
|
prometheus.io/port: "9090"
|
|
prometheus.io/path: "/metrics"
|
|
spec:
|
|
terminationGracePeriodSeconds: 45
|
|
tolerations:
|
|
- key: dedicated
|
|
operator: Equal
|
|
value: workers
|
|
effect: NoSchedule
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: node-role.workolik/worker
|
|
operator: In
|
|
values:
|
|
- "true"
|
|
podAntiAffinity:
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 100
|
|
podAffinityTerm:
|
|
labelSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- worker-orders
|
|
topologyKey: kubernetes.io/hostname
|
|
topologySpreadConstraints:
|
|
- maxSkew: 1
|
|
topologyKey: kubernetes.io/hostname
|
|
whenUnsatisfiable: ScheduleAnyway
|
|
labelSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-orders
|
|
containers:
|
|
- name: worker
|
|
image: workolik360/nats-worker:v1.1.0
|
|
imagePullPolicy: IfNotPresent
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
command: ["python3", "-u", "/scripts/worker.py"]
|
|
volumeMounts:
|
|
- name: worker-script-vol
|
|
mountPath: /scripts
|
|
envFrom:
|
|
- configMapRef:
|
|
name: core-config
|
|
env:
|
|
- name: NATS_STREAM
|
|
value: "ORDERS"
|
|
- name: NATS_CONSUMER
|
|
value: "orders-worker"
|
|
- name: FILTER_SUBJECT
|
|
value: "api.v1.mob.orders.createorder"
|
|
- name: WORKER_CONCURRENCY
|
|
value: "20"
|
|
- name: NATS_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: username
|
|
- name: NATS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: password
|
|
- name: EXTERNAL_ENDPOINT_API_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: external-endpoint-secrets
|
|
key: api_key
|
|
optional: true
|
|
- name: EXTERNAL_BASE_URL
|
|
value: "http://10.43.229.168"
|
|
resources:
|
|
requests:
|
|
memory: "128Mi"
|
|
cpu: "100m"
|
|
limits:
|
|
memory: "256Mi"
|
|
cpu: "500m"
|
|
ports:
|
|
- containerPort: 9090
|
|
name: metrics
|
|
volumes:
|
|
- name: worker-script-vol
|
|
configMap:
|
|
name: worker-script
|
|
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: worker-deliveries
|
|
namespace: core
|
|
labels:
|
|
app.kubernetes.io/name: worker-deliveries
|
|
app.kubernetes.io/component: worker
|
|
spec:
|
|
serviceName: "worker-deliveries"
|
|
replicas: 2
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-deliveries
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: worker-deliveries
|
|
app.kubernetes.io/component: worker
|
|
annotations:
|
|
prometheus.io/scrape: "true"
|
|
prometheus.io/port: "9090"
|
|
prometheus.io/path: "/metrics"
|
|
spec:
|
|
terminationGracePeriodSeconds: 45
|
|
tolerations:
|
|
- key: dedicated
|
|
operator: Equal
|
|
value: workers
|
|
effect: NoSchedule
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: node-role.workolik/worker
|
|
operator: In
|
|
values:
|
|
- "true"
|
|
podAntiAffinity:
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 100
|
|
podAffinityTerm:
|
|
labelSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- worker-deliveries
|
|
topologyKey: kubernetes.io/hostname
|
|
topologySpreadConstraints:
|
|
- maxSkew: 1
|
|
topologyKey: kubernetes.io/hostname
|
|
whenUnsatisfiable: ScheduleAnyway
|
|
labelSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-deliveries
|
|
containers:
|
|
- name: worker
|
|
image: workolik360/nats-worker:v1.1.0
|
|
imagePullPolicy: IfNotPresent
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
command: ["python3", "-u", "/scripts/worker.py"]
|
|
volumeMounts:
|
|
- name: worker-script-vol
|
|
mountPath: /scripts
|
|
envFrom:
|
|
- configMapRef:
|
|
name: core-config
|
|
env:
|
|
- name: NATS_STREAM
|
|
value: "DELIVERIES"
|
|
- name: NATS_CONSUMER
|
|
value: "deliveries-worker"
|
|
- name: FILTER_SUBJECT
|
|
value: "api.v1.deliveries.createdeliveries,api.v1.deliveries.updatedelivery,api.v2.deliveries.createdeliverylog"
|
|
- name: WORKER_CONCURRENCY
|
|
value: "10"
|
|
- name: NATS_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: username
|
|
- name: NATS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: password
|
|
- name: EXTERNAL_BASE_URL
|
|
value: "http://10.43.224.63"
|
|
resources:
|
|
requests:
|
|
memory: "128Mi"
|
|
cpu: "80m"
|
|
limits:
|
|
memory: "256Mi"
|
|
cpu: "400m"
|
|
ports:
|
|
- containerPort: 9090
|
|
name: metrics
|
|
volumes:
|
|
- name: worker-script-vol
|
|
configMap:
|
|
name: worker-script
|
|
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: worker-customers
|
|
namespace: core
|
|
labels:
|
|
app.kubernetes.io/name: worker-customers
|
|
app.kubernetes.io/component: worker
|
|
spec:
|
|
serviceName: "worker-customers"
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-customers
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: worker-customers
|
|
app.kubernetes.io/component: worker
|
|
annotations:
|
|
prometheus.io/scrape: "true"
|
|
prometheus.io/port: "9090"
|
|
prometheus.io/path: "/metrics"
|
|
spec:
|
|
terminationGracePeriodSeconds: 45
|
|
tolerations:
|
|
- key: dedicated
|
|
operator: Equal
|
|
value: workers
|
|
effect: NoSchedule
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: node-role.workolik/worker
|
|
operator: In
|
|
values:
|
|
- "true"
|
|
podAntiAffinity:
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 100
|
|
podAffinityTerm:
|
|
labelSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- worker-customers
|
|
topologyKey: kubernetes.io/hostname
|
|
topologySpreadConstraints:
|
|
- maxSkew: 1
|
|
topologyKey: kubernetes.io/hostname
|
|
whenUnsatisfiable: ScheduleAnyway
|
|
labelSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-customers
|
|
containers:
|
|
- name: worker
|
|
image: workolik360/nats-worker:v1.1.0
|
|
imagePullPolicy: IfNotPresent
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
command: ["python3", "-u", "/scripts/worker.py"]
|
|
volumeMounts:
|
|
- name: worker-script-vol
|
|
mountPath: /scripts
|
|
envFrom:
|
|
- configMapRef:
|
|
name: core-config
|
|
env:
|
|
- name: NATS_STREAM
|
|
value: "CUSTOMERS"
|
|
- name: NATS_CONSUMER
|
|
value: "customers-worker"
|
|
- name: FILTER_SUBJECT
|
|
value: "api.v1.mob.customers.login,api.v1.mob.customers.create"
|
|
- name: WORKER_CONCURRENCY
|
|
value: "30"
|
|
- name: NATS_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: username
|
|
- name: NATS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: password
|
|
- name: EXTERNAL_ENDPOINT_API_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: external-endpoint-secrets
|
|
key: api_key
|
|
optional: true
|
|
- name: EXTERNAL_BASE_URL
|
|
value: "http://10.43.229.168"
|
|
resources:
|
|
requests:
|
|
memory: "128Mi"
|
|
cpu: "60m"
|
|
limits:
|
|
memory: "256Mi"
|
|
cpu: "300m"
|
|
ports:
|
|
- containerPort: 9090
|
|
name: metrics
|
|
volumes:
|
|
- name: worker-script-vol
|
|
configMap:
|
|
name: worker-script
|
|
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: worker-rider-logs
|
|
namespace: core
|
|
labels:
|
|
app.kubernetes.io/name: worker-rider-logs
|
|
app.kubernetes.io/component: worker
|
|
spec:
|
|
serviceName: "worker-rider-logs"
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-rider-logs
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: worker-rider-logs
|
|
app.kubernetes.io/component: worker
|
|
annotations:
|
|
prometheus.io/scrape: "true"
|
|
prometheus.io/port: "9090"
|
|
prometheus.io/path: "/metrics"
|
|
spec:
|
|
terminationGracePeriodSeconds: 45
|
|
tolerations:
|
|
- key: dedicated
|
|
operator: Equal
|
|
value: workers
|
|
effect: NoSchedule
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: node-role.workolik/worker
|
|
operator: In
|
|
values:
|
|
- "true"
|
|
podAntiAffinity:
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 100
|
|
podAffinityTerm:
|
|
labelSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- worker-rider-logs
|
|
topologyKey: kubernetes.io/hostname
|
|
topologySpreadConstraints:
|
|
- maxSkew: 1
|
|
topologyKey: kubernetes.io/hostname
|
|
whenUnsatisfiable: ScheduleAnyway
|
|
labelSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-rider-logs
|
|
containers:
|
|
- name: worker
|
|
image: workolik360/nats-worker:v1.1.0
|
|
imagePullPolicy: IfNotPresent
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
command: ["python3", "-u", "/scripts/worker.py"]
|
|
volumeMounts:
|
|
- name: worker-script-vol
|
|
mountPath: /scripts
|
|
envFrom:
|
|
- configMapRef:
|
|
name: core-config
|
|
env:
|
|
- name: NATS_STREAM
|
|
value: "RIDER"
|
|
- name: NATS_CONSUMER
|
|
value: "rider-logs-worker"
|
|
- name: FILTER_SUBJECT
|
|
value: "api.v2.partners.createriderlog,api.v2.partners.createbreaklog,api.v2.partners.updatebreaklog"
|
|
- name: WORKER_CONCURRENCY
|
|
value: "10"
|
|
- name: NATS_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: username
|
|
- name: NATS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: password
|
|
- name: EXTERNAL_ENDPOINT_API_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: external-endpoint-secrets
|
|
key: api_key
|
|
optional: true
|
|
- name: EXTERNAL_BASE_URL
|
|
value: "http://10.43.224.63"
|
|
resources:
|
|
requests:
|
|
memory: "128Mi"
|
|
cpu: "40m"
|
|
limits:
|
|
memory: "128Mi"
|
|
cpu: "200m"
|
|
ports:
|
|
- containerPort: 9090
|
|
name: metrics
|
|
volumes:
|
|
- name: worker-script-vol
|
|
configMap:
|
|
name: worker-script
|
|
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: worker-products
|
|
namespace: core
|
|
labels:
|
|
app.kubernetes.io/name: worker-products
|
|
app.kubernetes.io/component: worker
|
|
spec:
|
|
serviceName: "worker-products"
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-products
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: worker-products
|
|
app.kubernetes.io/component: worker
|
|
annotations:
|
|
prometheus.io/scrape: "true"
|
|
prometheus.io/port: "9090"
|
|
prometheus.io/path: "/metrics"
|
|
spec:
|
|
terminationGracePeriodSeconds: 45
|
|
tolerations:
|
|
- key: dedicated
|
|
operator: Equal
|
|
value: workers
|
|
effect: NoSchedule
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: node-role.workolik/worker
|
|
operator: In
|
|
values:
|
|
- "true"
|
|
podAntiAffinity:
|
|
preferredDuringSchedulingIgnoredDuringExecution:
|
|
- weight: 100
|
|
podAffinityTerm:
|
|
labelSelector:
|
|
matchExpressions:
|
|
- key: app.kubernetes.io/name
|
|
operator: In
|
|
values:
|
|
- worker-products
|
|
topologyKey: kubernetes.io/hostname
|
|
topologySpreadConstraints:
|
|
- maxSkew: 1
|
|
topologyKey: kubernetes.io/hostname
|
|
whenUnsatisfiable: ScheduleAnyway
|
|
labelSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/name: worker-products
|
|
containers:
|
|
- name: worker
|
|
image: workolik360/nats-worker:v1.1.0
|
|
imagePullPolicy: IfNotPresent
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
command: ["python3", "-u", "/scripts/worker.py"]
|
|
volumeMounts:
|
|
- name: worker-script-vol
|
|
mountPath: /scripts
|
|
envFrom:
|
|
- configMapRef:
|
|
name: core-config
|
|
env:
|
|
- name: NATS_STREAM
|
|
value: "PRODUCTS"
|
|
- name: NATS_CONSUMER
|
|
value: "products-worker"
|
|
- name: FILTER_SUBJECT
|
|
value: "api.v1.web.products.create"
|
|
- name: WORKER_CONCURRENCY
|
|
value: "5"
|
|
- name: NATS_USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: username
|
|
- name: NATS_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nats-credentials
|
|
key: password
|
|
- name: EXTERNAL_ENDPOINT_API_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: external-endpoint-secrets
|
|
key: api_key
|
|
optional: true
|
|
- name: EXTERNAL_BASE_URL
|
|
value: "http://10.43.229.168"
|
|
resources:
|
|
requests:
|
|
memory: "128Mi"
|
|
cpu: "40m"
|
|
limits:
|
|
memory: "256Mi"
|
|
cpu: "200m"
|
|
ports:
|
|
- containerPort: 9090
|
|
name: metrics
|
|
volumes:
|
|
- name: worker-script-vol
|
|
configMap:
|
|
name: worker-script
|