Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 1d9b7ec924 | |||
| fc7d69644c | |||
| 045c7ff009 | |||
| 69f2a2a6ec | |||
| f89927b1f4 | |||
| 7960ee03f9 | |||
| 393100430b |
@@ -36,7 +36,7 @@ spec:
|
|||||||
mountPath: /combined-certs
|
mountPath: /combined-certs
|
||||||
containers:
|
containers:
|
||||||
- name: api
|
- name: api
|
||||||
image: git.unkin.net/unkin/artifactapi:v3.12.0
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi:v3.13.1
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8000
|
- containerPort: 8000
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
name: image-keeper
|
||||||
|
namespace: artifactapi
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: image-keeper
|
||||||
|
updateStrategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 25%
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: image-keeper
|
||||||
|
spec:
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
priorityClassName: low
|
||||||
|
tolerations:
|
||||||
|
- operator: Exists
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65532
|
||||||
|
runAsGroup: 65532
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
initContainers:
|
||||||
|
# artifactapi is distroless with no exit-0 flag, so run a static busybox as `true`
|
||||||
|
- name: copy-true
|
||||||
|
image: busybox:1.37.0-musl
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command: ["cp", "/bin/busybox", "/keeper/true"]
|
||||||
|
volumeMounts:
|
||||||
|
- name: keeper
|
||||||
|
mountPath: /keeper
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 16Mi
|
||||||
|
requests:
|
||||||
|
cpu: 1m
|
||||||
|
memory: 4Mi
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop: ["ALL"]
|
||||||
|
- name: api
|
||||||
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi:v3.13.1
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command: ["/keeper/true"]
|
||||||
|
volumeMounts:
|
||||||
|
- name: keeper
|
||||||
|
mountPath: /keeper
|
||||||
|
readOnly: true
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 16Mi
|
||||||
|
requests:
|
||||||
|
cpu: 1m
|
||||||
|
memory: 4Mi
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop: ["ALL"]
|
||||||
|
- name: ui
|
||||||
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi-ui:v3.13.1
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command: ["true"]
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 16Mi
|
||||||
|
requests:
|
||||||
|
cpu: 1m
|
||||||
|
memory: 4Mi
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop: ["ALL"]
|
||||||
|
containers:
|
||||||
|
- name: pause
|
||||||
|
image: rancher/mirrored-pause:3.6
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 16Mi
|
||||||
|
requests:
|
||||||
|
cpu: 1m
|
||||||
|
memory: 4Mi
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
capabilities:
|
||||||
|
drop: ["ALL"]
|
||||||
|
volumes:
|
||||||
|
- name: keeper
|
||||||
|
emptyDir: {}
|
||||||
@@ -11,6 +11,7 @@ resources:
|
|||||||
- cnpg_pooler.yaml
|
- cnpg_pooler.yaml
|
||||||
- gateway.yaml
|
- gateway.yaml
|
||||||
- httproute.yaml
|
- httproute.yaml
|
||||||
|
- image-keeper.yaml
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- oauth2-proxy-configmap.yaml
|
- oauth2-proxy-configmap.yaml
|
||||||
- oauth2-proxy-deployment.yaml
|
- oauth2-proxy-deployment.yaml
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ spec:
|
|||||||
automountServiceAccountToken: true
|
automountServiceAccountToken: true
|
||||||
containers:
|
containers:
|
||||||
- name: ui
|
- name: ui
|
||||||
image: git.unkin.net/unkin/artifactapi-ui:v3.12.0
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi-ui:v3.13.1
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 80
|
- containerPort: 80
|
||||||
|
|||||||
@@ -1,12 +1,7 @@
|
|||||||
# consul (k8s)
|
# consul (k8s)
|
||||||
|
|
||||||
Consul servers (plain StatefulSet, overlay `apps/overlays/au-syd1/consul`) that
|
Consul server cluster (DC `au-syd1`), deployed via the HashiCorp helm chart with
|
||||||
join the VM datacenter `au-syd1` as extra raft voters. Pod `consul-server-N`
|
ACLs enabled (`default_policy: deny`, parity with the VM cluster).
|
||||||
advertises its own purelb LB IP `198.18.200.(11+N)`; `consul-dns` serves DNS on
|
|
||||||
`198.18.200.5:53`. VSO renders the agent/default ACL tokens from
|
|
||||||
`kv/kubernetes/namespace/consul/default/server-acl` into `consul-server-acl`
|
|
||||||
(`acl-tokens.json`, hot-reloaded via `auto_reload_config`). Port 8501 serves
|
|
||||||
the `consul-server-tls` certificate.
|
|
||||||
|
|
||||||
## API access (ACL auth)
|
## API access (ACL auth)
|
||||||
|
|
||||||
@@ -15,7 +10,9 @@ The HTTP API and UI are served on port 8500 behind the gateway at
|
|||||||
With ACLs enabled, requests beyond the anonymous policy require a token:
|
With ACLs enabled, requests beyond the anonymous policy require a token:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# management token (the VM cluster's initial_management token):
|
# management (bootstrap) token — seeded from Vault, synced by VSO into the
|
||||||
|
# consul-bootstrap-acl-token secret; same value as the VM cluster's
|
||||||
|
# initial_management token:
|
||||||
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
|
CONSUL_HTTP_TOKEN=$(vault kv get -field=token kv/kubernetes/namespace/consul/default/bootstrap-acl-token)
|
||||||
|
|
||||||
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
|
curl -H "X-Consul-Token: $CONSUL_HTTP_TOKEN" https://consul.k8s.syd1.au.unkin.net/v1/status/leader
|
||||||
|
|||||||
@@ -1,6 +1,9 @@
|
|||||||
---
|
---
|
||||||
# ClusterIP service targeting the consul server pods' HTTP API and UI (8500),
|
# ClusterIP service targeting the consul server pods' HTTP API (8500).
|
||||||
# the Gateway's backend.
|
# The HashiCorp chart only ships consul-ui (also 8500 via the server pods)
|
||||||
|
# and the headless consul-server; this named service gives the Gateway a
|
||||||
|
# stable API backend. Consul serves both the HTTP API and the UI (at /ui/)
|
||||||
|
# on this same port, so routing the API hostname here preserves the UI too.
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
|
|||||||
@@ -2,24 +2,16 @@
|
|||||||
apiVersion: secrets.hashicorp.com/v1beta1
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
kind: VaultStaticSecret
|
kind: VaultStaticSecret
|
||||||
metadata:
|
metadata:
|
||||||
name: server-acl
|
name: bootstrap-acl-token
|
||||||
namespace: consul
|
namespace: consul
|
||||||
spec:
|
spec:
|
||||||
destination:
|
destination:
|
||||||
create: true
|
create: true
|
||||||
name: consul-server-acl
|
name: consul-bootstrap-acl-token
|
||||||
overwrite: true
|
overwrite: true
|
||||||
transformation:
|
|
||||||
excludeRaw: true
|
|
||||||
excludes:
|
|
||||||
- .*
|
|
||||||
templates:
|
|
||||||
acl-tokens.json:
|
|
||||||
text: >-
|
|
||||||
{"acl":{"tokens":{"agent":{{ get .Secrets "agent_token" | toJson }},"default":{{ get .Secrets "default_token" | toJson }}}}}
|
|
||||||
hmacSecretData: true
|
hmacSecretData: true
|
||||||
mount: kv
|
mount: kv
|
||||||
path: kubernetes/namespace/consul/default/server-acl
|
path: kubernetes/namespace/consul/default/bootstrap-acl-token
|
||||||
refreshAfter: 5m
|
refreshAfter: 5m
|
||||||
type: kv-v2
|
type: kv-v2
|
||||||
vaultAuthRef: default
|
vaultAuthRef: default
|
||||||
|
|||||||
@@ -0,0 +1,40 @@
|
|||||||
|
---
|
||||||
|
apiVersion: ceph.unkin.net/v1alpha1
|
||||||
|
kind: ObjectStoreUser
|
||||||
|
metadata:
|
||||||
|
name: cnpg-mail-backup
|
||||||
|
namespace: mail
|
||||||
|
spec:
|
||||||
|
displayName: "CNPG backup owner (mail)"
|
||||||
|
uid: cnpg-mail-backup
|
||||||
|
maxBuckets: 5
|
||||||
|
secretName: cnpg-mail-backup-s3
|
||||||
|
retainOnDelete: true
|
||||||
|
---
|
||||||
|
apiVersion: ceph.unkin.net/v1alpha1
|
||||||
|
kind: Bucket
|
||||||
|
metadata:
|
||||||
|
name: cnpg-mail
|
||||||
|
namespace: mail
|
||||||
|
spec:
|
||||||
|
placementTarget: ec
|
||||||
|
bucketName: cnpg-mail
|
||||||
|
ownerRef: cnpg-mail-backup
|
||||||
|
versioning: false
|
||||||
|
tags:
|
||||||
|
app: mail
|
||||||
|
purpose: cnpg-backup
|
||||||
|
retainOnDelete: true
|
||||||
|
---
|
||||||
|
apiVersion: postgresql.cnpg.io/v1
|
||||||
|
kind: ScheduledBackup
|
||||||
|
metadata:
|
||||||
|
name: cnpg-mail-nightly
|
||||||
|
namespace: mail
|
||||||
|
spec:
|
||||||
|
schedule: "0 20 4 * * *"
|
||||||
|
immediate: false
|
||||||
|
backupOwnerReference: self
|
||||||
|
method: barmanObjectStore
|
||||||
|
cluster:
|
||||||
|
name: stalwart-db
|
||||||
@@ -0,0 +1,118 @@
|
|||||||
|
---
|
||||||
|
# Stalwart metadata store. No bootstrap secret: CNPG mints stalwart-db-app
|
||||||
|
# (username/password/dbname/uri) for Stalwart to consume.
|
||||||
|
apiVersion: postgresql.cnpg.io/v1
|
||||||
|
kind: Cluster
|
||||||
|
metadata:
|
||||||
|
name: stalwart-db
|
||||||
|
namespace: mail
|
||||||
|
spec:
|
||||||
|
affinity:
|
||||||
|
podAntiAffinityType: preferred
|
||||||
|
backup:
|
||||||
|
retentionPolicy: 30d
|
||||||
|
barmanObjectStore:
|
||||||
|
destinationPath: s3://cnpg-mail
|
||||||
|
endpointURL: https://s3.ceph.unkin.net
|
||||||
|
endpointCA:
|
||||||
|
name: vault-ca-cert
|
||||||
|
key: ca.crt
|
||||||
|
s3Credentials:
|
||||||
|
accessKeyId:
|
||||||
|
name: cnpg-mail-backup-s3
|
||||||
|
key: AWS_ACCESS_KEY_ID
|
||||||
|
secretAccessKey:
|
||||||
|
name: cnpg-mail-backup-s3
|
||||||
|
key: AWS_SECRET_ACCESS_KEY
|
||||||
|
serverName: stalwart-db
|
||||||
|
data:
|
||||||
|
compression: bzip2
|
||||||
|
jobs: 2
|
||||||
|
wal:
|
||||||
|
compression: zstd
|
||||||
|
maxParallel: 2
|
||||||
|
bootstrap:
|
||||||
|
initdb:
|
||||||
|
database: stalwart
|
||||||
|
encoding: UTF8
|
||||||
|
localeCType: C
|
||||||
|
localeCollate: C
|
||||||
|
owner: stalwart
|
||||||
|
enablePDB: true
|
||||||
|
enableSuperuserAccess: false
|
||||||
|
failoverDelay: 0
|
||||||
|
imageName: ghcr.io/cloudnative-pg/postgresql:18.1-system-trixie
|
||||||
|
instances: 3
|
||||||
|
logLevel: info
|
||||||
|
maxSyncReplicas: 0
|
||||||
|
minSyncReplicas: 0
|
||||||
|
monitoring:
|
||||||
|
customQueriesConfigMap:
|
||||||
|
- key: queries
|
||||||
|
name: cnpg-default-monitoring
|
||||||
|
disableDefaultQueries: false
|
||||||
|
enablePodMonitor: false
|
||||||
|
postgresql:
|
||||||
|
parameters:
|
||||||
|
archive_mode: "on"
|
||||||
|
archive_timeout: 5min
|
||||||
|
dynamic_shared_memory_type: posix
|
||||||
|
effective_cache_size: 256MB
|
||||||
|
full_page_writes: "on"
|
||||||
|
hot_standby_feedback: "on"
|
||||||
|
log_destination: csvlog
|
||||||
|
log_directory: /controller/log
|
||||||
|
log_filename: postgres
|
||||||
|
log_rotation_age: "0"
|
||||||
|
log_rotation_size: "0"
|
||||||
|
log_truncate_on_rotation: "false"
|
||||||
|
logging_collector: "on"
|
||||||
|
max_connections: "200"
|
||||||
|
max_parallel_workers: "16"
|
||||||
|
max_replication_slots: "16"
|
||||||
|
max_worker_processes: "16"
|
||||||
|
pg_stat_statements.max: "10000"
|
||||||
|
pg_stat_statements.track: top
|
||||||
|
shared_buffers: 128MB
|
||||||
|
shared_memory_type: mmap
|
||||||
|
ssl_max_protocol_version: TLSv1.3
|
||||||
|
ssl_min_protocol_version: TLSv1.3
|
||||||
|
wal_keep_size: 256MB
|
||||||
|
wal_level: logical
|
||||||
|
wal_log_hints: "on"
|
||||||
|
wal_receiver_timeout: 5s
|
||||||
|
wal_sender_timeout: 5s
|
||||||
|
shared_preload_libraries:
|
||||||
|
- pg_stat_statements
|
||||||
|
syncReplicaElectionConstraint:
|
||||||
|
enabled: false
|
||||||
|
primaryUpdateMethod: restart
|
||||||
|
primaryUpdateStrategy: unsupervised
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
isolationCheck:
|
||||||
|
connectionTimeout: 1000
|
||||||
|
enabled: true
|
||||||
|
requestTimeout: 1000
|
||||||
|
replicationSlots:
|
||||||
|
highAvailability:
|
||||||
|
enabled: true
|
||||||
|
slotPrefix: _cnpg_
|
||||||
|
synchronizeReplicas:
|
||||||
|
enabled: true
|
||||||
|
updateInterval: 30
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: "1"
|
||||||
|
memory: 1Gi
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 512Mi
|
||||||
|
smartShutdownTimeout: 180
|
||||||
|
startDelay: 3600
|
||||||
|
stopDelay: 1800
|
||||||
|
storage:
|
||||||
|
resizeInUseVolumes: true
|
||||||
|
size: 10Gi
|
||||||
|
storageClass: cephrbd-fast-delete
|
||||||
|
switchoverDelay: 3600
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- cnpg_backup.yaml
|
||||||
|
- cnpg_cluster.yaml
|
||||||
|
- namespace.yaml
|
||||||
|
- stalwart-blobs-bucket.yaml
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: mail
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
# Stalwart S3 blob store. The owner user has read-write on its own bucket; the
|
||||||
|
# operator mints AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / S3_ENDPOINT into
|
||||||
|
# stalwart-blobs-s3.
|
||||||
|
apiVersion: ceph.unkin.net/v1alpha1
|
||||||
|
kind: ObjectStoreUser
|
||||||
|
metadata:
|
||||||
|
name: stalwart-blobs
|
||||||
|
namespace: mail
|
||||||
|
spec:
|
||||||
|
displayName: "Stalwart blob store owner"
|
||||||
|
uid: mail-stalwart-blobs
|
||||||
|
maxBuckets: 5
|
||||||
|
secretName: stalwart-blobs-s3
|
||||||
|
retainOnDelete: true
|
||||||
|
---
|
||||||
|
apiVersion: ceph.unkin.net/v1alpha1
|
||||||
|
kind: Bucket
|
||||||
|
metadata:
|
||||||
|
name: stalwart-blobs
|
||||||
|
namespace: mail
|
||||||
|
spec:
|
||||||
|
placementTarget: ec
|
||||||
|
bucketName: stalwart-blobs
|
||||||
|
ownerRef: stalwart-blobs
|
||||||
|
versioning: false
|
||||||
|
tags:
|
||||||
|
app: stalwart
|
||||||
|
purpose: blob-store
|
||||||
|
retainOnDelete: true
|
||||||
@@ -25,7 +25,7 @@ spec:
|
|||||||
- name: pdbmux
|
- name: pdbmux
|
||||||
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on
|
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on
|
||||||
# a v* tag. It only exists after that tag is cut (see PR merge gates).
|
# a v* tag. It only exists after that tag is cut (see PR merge gates).
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.4.0
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.5.0
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
|
|||||||
@@ -20,6 +20,7 @@ resources:
|
|||||||
- serviceaccount_repospawner_ci.yaml
|
- serviceaccount_repospawner_ci.yaml
|
||||||
- serviceaccount_terraform_artifactapi.yaml
|
- serviceaccount_terraform_artifactapi.yaml
|
||||||
- serviceaccount_terraform_authentik.yaml
|
- serviceaccount_terraform_authentik.yaml
|
||||||
|
- serviceaccount_terraform_binarylane.yaml
|
||||||
- serviceaccount_terraform_enc.yaml
|
- serviceaccount_terraform_enc.yaml
|
||||||
- serviceaccount_terraform_git.yaml
|
- serviceaccount_terraform_git.yaml
|
||||||
- serviceaccount_terraform_netbox.yaml
|
- serviceaccount_terraform_netbox.yaml
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: terraform-binarylane
|
||||||
|
namespace: woodpecker
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: cert-manager.io/v1
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: consul-server-tls
|
|
||||||
namespace: consul
|
|
||||||
spec:
|
|
||||||
secretName: consul-server-tls
|
|
||||||
issuerRef:
|
|
||||||
kind: ClusterIssuer
|
|
||||||
name: vault-issuer
|
|
||||||
commonName: consul.k8s.syd1.au.unkin.net
|
|
||||||
dnsNames:
|
|
||||||
- consul.service.consul
|
|
||||||
- consul.service.au-syd1.consul
|
|
||||||
- consul
|
|
||||||
- consul.k8s.syd1.au.unkin.net
|
|
||||||
- server.au-syd1.consul
|
|
||||||
privateKey:
|
|
||||||
algorithm: RSA
|
|
||||||
size: 4096
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
|
|
||||||
namespace: consul
|
|
||||||
|
|
||||||
resources:
|
|
||||||
- ../../../base/consul
|
|
||||||
- statefulset.yaml
|
|
||||||
- services.yaml
|
|
||||||
- certificate.yaml
|
|
||||||
|
|
||||||
configMapGenerator:
|
|
||||||
- name: consul-server-config
|
|
||||||
files:
|
|
||||||
- server.json
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
{
|
|
||||||
"acl": {
|
|
||||||
"default_policy": "deny",
|
|
||||||
"down_policy": "extend-cache",
|
|
||||||
"enable_token_persistence": true,
|
|
||||||
"enabled": true
|
|
||||||
},
|
|
||||||
"auto_reload_config": true,
|
|
||||||
"bind_addr": "0.0.0.0",
|
|
||||||
"client_addr": "0.0.0.0",
|
|
||||||
"connect": {
|
|
||||||
"enabled": true
|
|
||||||
},
|
|
||||||
"datacenter": "au-syd1",
|
|
||||||
"disable_remote_exec": true,
|
|
||||||
"disable_update_check": true,
|
|
||||||
"leave_on_terminate": false,
|
|
||||||
"performance": {
|
|
||||||
"raft_multiplier": 10
|
|
||||||
},
|
|
||||||
"ports": {
|
|
||||||
"dns": 8600,
|
|
||||||
"grpc": 8502,
|
|
||||||
"http": 8500,
|
|
||||||
"https": 8501
|
|
||||||
},
|
|
||||||
"primary_datacenter": "au-syd1",
|
|
||||||
"retry_join": [
|
|
||||||
"198.18.200.11",
|
|
||||||
"198.18.200.12",
|
|
||||||
"198.18.200.13",
|
|
||||||
"198.18.200.14",
|
|
||||||
"198.18.200.15",
|
|
||||||
"ausyd1nxvm2005.main.unkin.net",
|
|
||||||
"ausyd1nxvm2006.main.unkin.net",
|
|
||||||
"ausyd1nxvm2007.main.unkin.net",
|
|
||||||
"ausyd1nxvm2008.main.unkin.net",
|
|
||||||
"ausyd1nxvm2009.main.unkin.net"
|
|
||||||
],
|
|
||||||
"server": true,
|
|
||||||
"tls": {
|
|
||||||
"https": {
|
|
||||||
"cert_file": "/consul/tls/tls.crt",
|
|
||||||
"key_file": "/consul/tls/tls.key",
|
|
||||||
"verify_incoming": false
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"ui_config": {
|
|
||||||
"enabled": true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,151 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-server
|
|
||||||
namespace: consul
|
|
||||||
spec:
|
|
||||||
clusterIP: None
|
|
||||||
publishNotReadyAddresses: true
|
|
||||||
selector:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
release: consul
|
|
||||||
ports:
|
|
||||||
- {name: server, port: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, port: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, port: 8301, protocol: UDP}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-dns
|
|
||||||
namespace: consul
|
|
||||||
annotations:
|
|
||||||
purelb.io/service-group: common
|
|
||||||
purelb.io/addresses: 198.18.200.5
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
selector:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
release: consul
|
|
||||||
ports:
|
|
||||||
- {name: dns-udp, port: 53, protocol: UDP, targetPort: 8600}
|
|
||||||
- {name: dns-tcp, port: 53, protocol: TCP, targetPort: 8600}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-server-0-lb
|
|
||||||
namespace: consul
|
|
||||||
annotations:
|
|
||||||
purelb.io/service-group: common
|
|
||||||
purelb.io/addresses: 198.18.200.11
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
publishNotReadyAddresses: true
|
|
||||||
selector:
|
|
||||||
statefulset.kubernetes.io/pod-name: consul-server-0
|
|
||||||
ports:
|
|
||||||
- {name: server, port: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, port: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, port: 8301, protocol: UDP}
|
|
||||||
- {name: serfwan-tcp, port: 8302, protocol: TCP}
|
|
||||||
- {name: serfwan-udp, port: 8302, protocol: UDP}
|
|
||||||
- {name: http, port: 8500, protocol: TCP}
|
|
||||||
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-server-1-lb
|
|
||||||
namespace: consul
|
|
||||||
annotations:
|
|
||||||
purelb.io/service-group: common
|
|
||||||
purelb.io/addresses: 198.18.200.12
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
publishNotReadyAddresses: true
|
|
||||||
selector:
|
|
||||||
statefulset.kubernetes.io/pod-name: consul-server-1
|
|
||||||
ports:
|
|
||||||
- {name: server, port: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, port: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, port: 8301, protocol: UDP}
|
|
||||||
- {name: serfwan-tcp, port: 8302, protocol: TCP}
|
|
||||||
- {name: serfwan-udp, port: 8302, protocol: UDP}
|
|
||||||
- {name: http, port: 8500, protocol: TCP}
|
|
||||||
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-server-2-lb
|
|
||||||
namespace: consul
|
|
||||||
annotations:
|
|
||||||
purelb.io/service-group: common
|
|
||||||
purelb.io/addresses: 198.18.200.13
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
publishNotReadyAddresses: true
|
|
||||||
selector:
|
|
||||||
statefulset.kubernetes.io/pod-name: consul-server-2
|
|
||||||
ports:
|
|
||||||
- {name: server, port: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, port: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, port: 8301, protocol: UDP}
|
|
||||||
- {name: serfwan-tcp, port: 8302, protocol: TCP}
|
|
||||||
- {name: serfwan-udp, port: 8302, protocol: UDP}
|
|
||||||
- {name: http, port: 8500, protocol: TCP}
|
|
||||||
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-server-3-lb
|
|
||||||
namespace: consul
|
|
||||||
annotations:
|
|
||||||
purelb.io/service-group: common
|
|
||||||
purelb.io/addresses: 198.18.200.14
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
publishNotReadyAddresses: true
|
|
||||||
selector:
|
|
||||||
statefulset.kubernetes.io/pod-name: consul-server-3
|
|
||||||
ports:
|
|
||||||
- {name: server, port: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, port: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, port: 8301, protocol: UDP}
|
|
||||||
- {name: serfwan-tcp, port: 8302, protocol: TCP}
|
|
||||||
- {name: serfwan-udp, port: 8302, protocol: UDP}
|
|
||||||
- {name: http, port: 8500, protocol: TCP}
|
|
||||||
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
|
|
||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: consul-server-4-lb
|
|
||||||
namespace: consul
|
|
||||||
annotations:
|
|
||||||
purelb.io/service-group: common
|
|
||||||
purelb.io/addresses: 198.18.200.15
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
externalTrafficPolicy: Local
|
|
||||||
publishNotReadyAddresses: true
|
|
||||||
selector:
|
|
||||||
statefulset.kubernetes.io/pod-name: consul-server-4
|
|
||||||
ports:
|
|
||||||
- {name: server, port: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, port: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, port: 8301, protocol: UDP}
|
|
||||||
- {name: serfwan-tcp, port: 8302, protocol: TCP}
|
|
||||||
- {name: serfwan-udp, port: 8302, protocol: UDP}
|
|
||||||
- {name: http, port: 8500, protocol: TCP}
|
|
||||||
- {name: https, port: 443, protocol: TCP, targetPort: 8501}
|
|
||||||
@@ -1,131 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: StatefulSet
|
|
||||||
metadata:
|
|
||||||
name: consul-server
|
|
||||||
namespace: consul
|
|
||||||
labels:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
release: consul
|
|
||||||
spec:
|
|
||||||
serviceName: consul-server
|
|
||||||
replicas: 1
|
|
||||||
minReadySeconds: 30
|
|
||||||
podManagementPolicy: OrderedReady
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
release: consul
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
release: consul
|
|
||||||
spec:
|
|
||||||
terminationGracePeriodSeconds: 30
|
|
||||||
securityContext:
|
|
||||||
runAsUser: 100
|
|
||||||
runAsGroup: 1000
|
|
||||||
runAsNonRoot: true
|
|
||||||
fsGroup: 1000
|
|
||||||
affinity:
|
|
||||||
podAntiAffinity:
|
|
||||||
requiredDuringSchedulingIgnoredDuringExecution:
|
|
||||||
- labelSelector:
|
|
||||||
matchLabels:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
topologyKey: kubernetes.io/hostname
|
|
||||||
containers:
|
|
||||||
- name: consul
|
|
||||||
image: hashicorp/consul:1.22.7
|
|
||||||
securityContext:
|
|
||||||
allowPrivilegeEscalation: false
|
|
||||||
capabilities:
|
|
||||||
drop: [ALL]
|
|
||||||
command:
|
|
||||||
- /bin/sh
|
|
||||||
- -ec
|
|
||||||
# ponytail: contiguous .11-.15 block
|
|
||||||
- >-
|
|
||||||
exec consul agent
|
|
||||||
-config-dir=/consul/config
|
|
||||||
-config-dir=/consul/acl
|
|
||||||
-data-dir=/consul/data
|
|
||||||
-node="${HOSTNAME}"
|
|
||||||
-advertise="198.18.200.$((11 + ${HOSTNAME##*-}))"
|
|
||||||
ports:
|
|
||||||
- {name: server, containerPort: 8300, protocol: TCP}
|
|
||||||
- {name: serflan-tcp, containerPort: 8301, protocol: TCP}
|
|
||||||
- {name: serflan-udp, containerPort: 8301, protocol: UDP}
|
|
||||||
- {name: serfwan-tcp, containerPort: 8302, protocol: TCP}
|
|
||||||
- {name: serfwan-udp, containerPort: 8302, protocol: UDP}
|
|
||||||
- {name: http, containerPort: 8500, protocol: TCP}
|
|
||||||
- {name: https, containerPort: 8501, protocol: TCP}
|
|
||||||
- {name: grpc, containerPort: 8502, protocol: TCP}
|
|
||||||
- {name: dns-tcp, containerPort: 8600, protocol: TCP}
|
|
||||||
- {name: dns-udp, containerPort: 8600, protocol: UDP}
|
|
||||||
readinessProbe:
|
|
||||||
exec:
|
|
||||||
command:
|
|
||||||
- /bin/sh
|
|
||||||
- -c
|
|
||||||
- wget -qO- http://127.0.0.1:8500/v1/status/leader | grep -q ':8300'
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 10
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 100m
|
|
||||||
memory: 256Mi
|
|
||||||
limits:
|
|
||||||
cpu: "1"
|
|
||||||
memory: 2Gi
|
|
||||||
volumeMounts:
|
|
||||||
- name: data
|
|
||||||
mountPath: /consul/data
|
|
||||||
- name: config
|
|
||||||
mountPath: /consul/config
|
|
||||||
readOnly: true
|
|
||||||
- name: acl
|
|
||||||
mountPath: /consul/acl
|
|
||||||
readOnly: true
|
|
||||||
- name: tls
|
|
||||||
mountPath: /consul/tls
|
|
||||||
readOnly: true
|
|
||||||
volumes:
|
|
||||||
- name: config
|
|
||||||
configMap:
|
|
||||||
name: consul-server-config
|
|
||||||
- name: acl
|
|
||||||
secret:
|
|
||||||
secretName: consul-server-acl
|
|
||||||
defaultMode: 0440
|
|
||||||
- name: tls
|
|
||||||
secret:
|
|
||||||
secretName: consul-server-tls
|
|
||||||
volumeClaimTemplates:
|
|
||||||
- metadata:
|
|
||||||
name: data
|
|
||||||
spec:
|
|
||||||
accessModes:
|
|
||||||
- ReadWriteOnce
|
|
||||||
storageClassName: cephrbd-fast-retain
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
storage: 10Gi
|
|
||||||
---
|
|
||||||
apiVersion: policy/v1
|
|
||||||
kind: PodDisruptionBudget
|
|
||||||
metadata:
|
|
||||||
name: consul-server
|
|
||||||
namespace: consul
|
|
||||||
spec:
|
|
||||||
maxUnavailable: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: consul
|
|
||||||
component: server
|
|
||||||
release: consul
|
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/mail
|
||||||
@@ -34,6 +34,7 @@ spec:
|
|||||||
- path: apps/overlays/*/jfrog
|
- path: apps/overlays/*/jfrog
|
||||||
- path: apps/overlays/*/k8up-system
|
- path: apps/overlays/*/k8up-system
|
||||||
- path: apps/overlays/*/kanidm
|
- path: apps/overlays/*/kanidm
|
||||||
|
- path: apps/overlays/*/mail
|
||||||
- path: apps/overlays/*/netbox
|
- path: apps/overlays/*/netbox
|
||||||
- path: apps/overlays/*/node-feature-discovery
|
- path: apps/overlays/*/node-feature-discovery
|
||||||
- path: apps/overlays/*/pdbmux
|
- path: apps/overlays/*/pdbmux
|
||||||
|
|||||||
@@ -49,6 +49,8 @@ spec:
|
|||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'kanidm'
|
- namespace: 'kanidm'
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
|
- namespace: 'mail'
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'netbox'
|
- namespace: 'netbox'
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: 'node-feature-discovery'
|
- namespace: 'node-feature-discovery'
|
||||||
|
|||||||
Reference in New Issue
Block a user