--- apiVersion: apps/v1 kind: Deployment metadata: name: haproxy namespace: haproxy annotations: reloader.stakater.com/auto: "true" spec: replicas: 3 selector: matchLabels: app: haproxy strategy: type: RollingUpdate rollingUpdate: maxUnavailable: 1 template: metadata: labels: app: haproxy spec: automountServiceAccountToken: false terminationGracePeriodSeconds: 150 affinity: podAntiAffinity: requiredDuringSchedulingIgnoredDuringExecution: - labelSelector: matchLabels: app: haproxy topologyKey: kubernetes.io/hostname securityContext: runAsNonRoot: true runAsUser: 99 runAsGroup: 99 seccompProfile: type: RuntimeDefault containers: - name: haproxy image: haproxy:3.2.24-alpine imagePullPolicy: IfNotPresent command: - haproxy - -W - -db - -f - /usr/local/etc/haproxy/haproxy.cfg securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: [ALL] # Frontends bind 25/80/143/443/587; the dst_port ACLs need the real ports. add: [NET_BIND_SERVICE] ports: - name: http containerPort: 80 protocol: TCP - name: https containerPort: 443 protocol: TCP - name: smtp containerPort: 25 protocol: TCP - name: imap containerPort: 143 protocol: TCP - name: submission containerPort: 587 protocol: TCP - name: imaps containerPort: 993 protocol: TCP - name: health containerPort: 8404 protocol: TCP - name: metrics containerPort: 8405 protocol: TCP - name: stats containerPort: 9090 protocol: TCP lifecycle: preStop: exec: # SIGUSR1 to the master soft-stops the workers; hard-stop-after # caps the drain. Wait so kubelet holds SIGTERM until it is done. command: - /bin/sh - -c - kill -s USR1 1; while kill -0 1 2>/dev/null; do sleep 1; done livenessProbe: httpGet: path: /healthz port: health initialDelaySeconds: 15 periodSeconds: 30 timeoutSeconds: 5 failureThreshold: 3 readinessProbe: httpGet: path: /healthz port: health initialDelaySeconds: 5 periodSeconds: 5 timeoutSeconds: 5 failureThreshold: 3 resources: requests: cpu: 200m memory: 256Mi limits: cpu: 2 memory: 1Gi volumeMounts: - name: config mountPath: /usr/local/etc/haproxy readOnly: true - name: cert-unkin-net mountPath: /etc/haproxy/certs/unkin-net readOnly: true - name: cert-main-unkin-net mountPath: /etc/haproxy/certs/main-unkin-net readOnly: true - name: cert-ceph-unkin-net mountPath: /etc/haproxy/certs/ceph-unkin-net readOnly: true - name: run mountPath: /var/lib/haproxy volumes: - name: config configMap: name: haproxy-config # ssl-load-extra-files loads .key by default, so the key is # projected next to the cert as tls.crt.key. - name: cert-unkin-net secret: secretName: wildcard-unkin-net-tls items: - key: tls.crt path: tls.crt - key: tls.key path: tls.crt.key - name: cert-main-unkin-net secret: secretName: wildcard-main-unkin-net-tls items: - key: tls.crt path: tls.crt - key: tls.key path: tls.crt.key - name: cert-ceph-unkin-net secret: secretName: wildcard-ceph-unkin-net-tls items: - key: tls.crt path: tls.crt - key: tls.key path: tls.crt.key - name: run emptyDir: {} restartPolicy: Always