This commit is contained in:
parent
6bd916a32e
commit
d30bc8cf7a
|
|
@ -0,0 +1,22 @@
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIDljCCAn6gAwIBAgIUagOvFaYyS/yDsKIDiEFndbL94HUwDQYJKoZIhvcNAQEL
|
||||||
|
BQAwPzELMAkGA1UEBhMCS1IxDjAMBgNVBAgMBVNlb3VsMQ0wCwYDVQQKDARnb29k
|
||||||
|
MREwDwYDVQQDDAhnb29kLmNvbTAeFw0yNTA2MjMwOTQ2MjlaFw0yNzA2MjMwOTQ2
|
||||||
|
MjlaME4xCzAJBgNVBAYTAktSMQ4wDAYDVQQIDAVTZW91bDEOMAwGA1UECgwFaWpp
|
||||||
|
bmMxHzAdBgNVBAMMFiouZ3B1bGl2ZS5uaG5jbG91ZC5jb20wggEiMA0GCSqGSIb3
|
||||||
|
DQEBAQUAA4IBDwAwggEKAoIBAQCefQoIn0JWkKchP4U8DV4dafhJfyy6LExm2sMv
|
||||||
|
hT8dTa3PuNXve1thXS5l/9UEVGdC7EP1k+biI382ouMfhZeLK5vg29H1BXzUvTx3
|
||||||
|
h6aPypUi8FPm1SuM6zL1V9ZVh5z6QiwkzyMxVYGM1YsiWLO0SH24eLVDi3/EFYVx
|
||||||
|
JrXsbe82jJ0MmZ+ZqWwI8MJSXCef4YE7+BxGrBTo9jaPm+Nb163ZW6ZokWB4WZNt
|
||||||
|
SVYXcSFULYMPB085LZeuJUtE9APLq7VG8GbEqe+ApENwLpF/HvtHnuFLgftNu9zS
|
||||||
|
L+gX9s2ekjg8q7IT9f20N59/P3mEMk9VHA9ABnNaLEJ2KQ9RAgMBAAGjezB5MDcG
|
||||||
|
A1UdEQQwMC6CFGdwdWxpdmUubmhuY2xvdWQuY29tghYqLmdwdWxpdmUubmhuY2xv
|
||||||
|
dWQuY29tMB0GA1UdDgQWBBR2c6jASvY/IiMw9tEjKXRKUXyUAzAfBgNVHSMEGDAW
|
||||||
|
gBRGafRI9OGcRnoBgsE1Qhqf5rLl5TANBgkqhkiG9w0BAQsFAAOCAQEATZqNGWj3
|
||||||
|
e7c2KDH4h4eCnTeuZinONpd1XUvk/LT8GkrndjjfX74hc2G4Es8v1ojWFOEtCFkI
|
||||||
|
v0FRQkHwI07RW9hojldUPC2SksZWxYztOivI4y5rW/Q9K5Fl02YTtgcTZIQx1BAj
|
||||||
|
7qehEp+Fs3bdjLjornPuyG9rqwsWpmwoYNASECcGr5ON5CJ0BljuD7rxbLrT/rR/
|
||||||
|
fG8/NzA0EBYbfUNQzc4xR6vsTmJOEaty2H1HsVL+LQSD7Bj6+zNAfORLS2+OHBz7
|
||||||
|
qZJzyH4IawJvvRzoh9KKiYTZORCv5lkcpjIVFVqWwh+AIHTyieHo5j8EiAHT4//r
|
||||||
|
CcX/mCaHlIVa9g==
|
||||||
|
-----END CERTIFICATE-----
|
||||||
|
|
@ -0,0 +1,28 @@
|
||||||
|
-----BEGIN PRIVATE KEY-----
|
||||||
|
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCefQoIn0JWkKch
|
||||||
|
P4U8DV4dafhJfyy6LExm2sMvhT8dTa3PuNXve1thXS5l/9UEVGdC7EP1k+biI382
|
||||||
|
ouMfhZeLK5vg29H1BXzUvTx3h6aPypUi8FPm1SuM6zL1V9ZVh5z6QiwkzyMxVYGM
|
||||||
|
1YsiWLO0SH24eLVDi3/EFYVxJrXsbe82jJ0MmZ+ZqWwI8MJSXCef4YE7+BxGrBTo
|
||||||
|
9jaPm+Nb163ZW6ZokWB4WZNtSVYXcSFULYMPB085LZeuJUtE9APLq7VG8GbEqe+A
|
||||||
|
pENwLpF/HvtHnuFLgftNu9zSL+gX9s2ekjg8q7IT9f20N59/P3mEMk9VHA9ABnNa
|
||||||
|
LEJ2KQ9RAgMBAAECggEABbYIk1PDcDS5aqYY7WRBH/SeaqEw9QR9PFEykP1pAmu2
|
||||||
|
97IRaeMBrmCAa4Yfuig23SwZk5/gxTiPCcj7P9RW9NmwpEmt8/mR2TJFTryOPZNv
|
||||||
|
P4ypeVTB9phphBQsnqhkX7ncUJDZejQHY98BRIH6kWSLVm2ctCWZIde+SnWHclDC
|
||||||
|
FGIGXHeXUz+mueqK4d6G7cYpj53NQkboEG6Nq/wenQFVuJ7oS84WlEjza+nXK8TY
|
||||||
|
iz5bJcDprZTWwe6sP50As1bDeWohUBhGYCRTYxYqsWWI4Y+whpyCyPl1J/P/M1GR
|
||||||
|
Hq2qcK+4/GhA6WZ2Rd+iYxLCOooBqLVGiLIzUyG2AQKBgQDXfKtTiD7gr/ufJdiQ
|
||||||
|
hWZcMzC3GecdqLzyoAurVtwFyuKefzQvRtLD4mRFOfk2BClULKqlSWCwMuR0ZJo4
|
||||||
|
yyRw8Cj/0zGUXrWGsol+8WI0FrBu/7i05p8NP5QAU5bTY/+yqNr2/b2dCi/UPa0V
|
||||||
|
aROeFOq/SE2PfiAKdEjOC9xAhQKBgQC8SQt7obbz2gG0m9iKpRbV4plycFuQ/kNY
|
||||||
|
pNEUfF76D+wXo4nhgSOkp1p0LV2qkUi4rbNuUumhnbAJ7K7/lUCfp7Wn54RsWMZE
|
||||||
|
KejH2ro4gx3/XueufHLomrQ0czMD9A42Vkf1HC4/bjxkmdFWzFarRXFOyC9YQ+xj
|
||||||
|
kVe+w5jTXQKBgQDGFw8QLRFQT7bJ6GqbAGbGnzBLQf6Z30JC8CmKCsEcehO1jE4W
|
||||||
|
n86kz/tJQC/+Hfk4Lg94/mlp0H7/GHRFfUk0oTGvayAKur2442tOTOvv4mOyxlWv
|
||||||
|
xsmzzhxp6G2gSi8Gt/8CSuQB9xlczI3OPtgP3D6oNPlHzbP6qEc9Ut3YWQKBgCn/
|
||||||
|
9ULHyQLOP5ElLoGG3/goCuifLZ3DSgyM/2Kdd6Y6RQTk4w3de7Dv79p4gCtbKyie
|
||||||
|
/qZ+ckUt4qXkGQlEJt02UOw6VazBhMCRxK5IGUAf52IernmaoxtF3yrQA7I/D6iJ
|
||||||
|
SJXhimN12JzsPukovbCI1gSn3P/IbwOq2TLheMa1AoGBAMgIkmtSpk3DG1XeM8Cj
|
||||||
|
auR/HAh0tumCe6qmjnKGXhJyhMnsWtJ/TGF5Y/7Cfj45bHA851TiBkTdNRuI+CHJ
|
||||||
|
tXm2iwnyHyi32lCqyjVc746QJv43DEXeWk/bx1fmCgDUAO4OrTP/IeHLAeXZvih4
|
||||||
|
bwNJTWjdNQPSytvcKv1KMiZj
|
||||||
|
-----END PRIVATE KEY-----
|
||||||
|
|
@ -0,0 +1,22 @@
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIDljCCAn6gAwIBAgIUagOvFaYyS/yDsKIDiEFndbL94HUwDQYJKoZIhvcNAQEL
|
||||||
|
BQAwPzELMAkGA1UEBhMCS1IxDjAMBgNVBAgMBVNlb3VsMQ0wCwYDVQQKDARnb29k
|
||||||
|
MREwDwYDVQQDDAhnb29kLmNvbTAeFw0yNTA2MjMwOTQ2MjlaFw0yNzA2MjMwOTQ2
|
||||||
|
MjlaME4xCzAJBgNVBAYTAktSMQ4wDAYDVQQIDAVTZW91bDEOMAwGA1UECgwFaWpp
|
||||||
|
bmMxHzAdBgNVBAMMFiouZ3B1bGl2ZS5uaG5jbG91ZC5jb20wggEiMA0GCSqGSIb3
|
||||||
|
DQEBAQUAA4IBDwAwggEKAoIBAQCefQoIn0JWkKchP4U8DV4dafhJfyy6LExm2sMv
|
||||||
|
hT8dTa3PuNXve1thXS5l/9UEVGdC7EP1k+biI382ouMfhZeLK5vg29H1BXzUvTx3
|
||||||
|
h6aPypUi8FPm1SuM6zL1V9ZVh5z6QiwkzyMxVYGM1YsiWLO0SH24eLVDi3/EFYVx
|
||||||
|
JrXsbe82jJ0MmZ+ZqWwI8MJSXCef4YE7+BxGrBTo9jaPm+Nb163ZW6ZokWB4WZNt
|
||||||
|
SVYXcSFULYMPB085LZeuJUtE9APLq7VG8GbEqe+ApENwLpF/HvtHnuFLgftNu9zS
|
||||||
|
L+gX9s2ekjg8q7IT9f20N59/P3mEMk9VHA9ABnNaLEJ2KQ9RAgMBAAGjezB5MDcG
|
||||||
|
A1UdEQQwMC6CFGdwdWxpdmUubmhuY2xvdWQuY29tghYqLmdwdWxpdmUubmhuY2xv
|
||||||
|
dWQuY29tMB0GA1UdDgQWBBR2c6jASvY/IiMw9tEjKXRKUXyUAzAfBgNVHSMEGDAW
|
||||||
|
gBRGafRI9OGcRnoBgsE1Qhqf5rLl5TANBgkqhkiG9w0BAQsFAAOCAQEATZqNGWj3
|
||||||
|
e7c2KDH4h4eCnTeuZinONpd1XUvk/LT8GkrndjjfX74hc2G4Es8v1ojWFOEtCFkI
|
||||||
|
v0FRQkHwI07RW9hojldUPC2SksZWxYztOivI4y5rW/Q9K5Fl02YTtgcTZIQx1BAj
|
||||||
|
7qehEp+Fs3bdjLjornPuyG9rqwsWpmwoYNASECcGr5ON5CJ0BljuD7rxbLrT/rR/
|
||||||
|
fG8/NzA0EBYbfUNQzc4xR6vsTmJOEaty2H1HsVL+LQSD7Bj6+zNAfORLS2+OHBz7
|
||||||
|
qZJzyH4IawJvvRzoh9KKiYTZORCv5lkcpjIVFVqWwh+AIHTyieHo5j8EiAHT4//r
|
||||||
|
CcX/mCaHlIVa9g==
|
||||||
|
-----END CERTIFICATE-----
|
||||||
|
|
@ -0,0 +1,28 @@
|
||||||
|
-----BEGIN PRIVATE KEY-----
|
||||||
|
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCefQoIn0JWkKch
|
||||||
|
P4U8DV4dafhJfyy6LExm2sMvhT8dTa3PuNXve1thXS5l/9UEVGdC7EP1k+biI382
|
||||||
|
ouMfhZeLK5vg29H1BXzUvTx3h6aPypUi8FPm1SuM6zL1V9ZVh5z6QiwkzyMxVYGM
|
||||||
|
1YsiWLO0SH24eLVDi3/EFYVxJrXsbe82jJ0MmZ+ZqWwI8MJSXCef4YE7+BxGrBTo
|
||||||
|
9jaPm+Nb163ZW6ZokWB4WZNtSVYXcSFULYMPB085LZeuJUtE9APLq7VG8GbEqe+A
|
||||||
|
pENwLpF/HvtHnuFLgftNu9zSL+gX9s2ekjg8q7IT9f20N59/P3mEMk9VHA9ABnNa
|
||||||
|
LEJ2KQ9RAgMBAAECggEABbYIk1PDcDS5aqYY7WRBH/SeaqEw9QR9PFEykP1pAmu2
|
||||||
|
97IRaeMBrmCAa4Yfuig23SwZk5/gxTiPCcj7P9RW9NmwpEmt8/mR2TJFTryOPZNv
|
||||||
|
P4ypeVTB9phphBQsnqhkX7ncUJDZejQHY98BRIH6kWSLVm2ctCWZIde+SnWHclDC
|
||||||
|
FGIGXHeXUz+mueqK4d6G7cYpj53NQkboEG6Nq/wenQFVuJ7oS84WlEjza+nXK8TY
|
||||||
|
iz5bJcDprZTWwe6sP50As1bDeWohUBhGYCRTYxYqsWWI4Y+whpyCyPl1J/P/M1GR
|
||||||
|
Hq2qcK+4/GhA6WZ2Rd+iYxLCOooBqLVGiLIzUyG2AQKBgQDXfKtTiD7gr/ufJdiQ
|
||||||
|
hWZcMzC3GecdqLzyoAurVtwFyuKefzQvRtLD4mRFOfk2BClULKqlSWCwMuR0ZJo4
|
||||||
|
yyRw8Cj/0zGUXrWGsol+8WI0FrBu/7i05p8NP5QAU5bTY/+yqNr2/b2dCi/UPa0V
|
||||||
|
aROeFOq/SE2PfiAKdEjOC9xAhQKBgQC8SQt7obbz2gG0m9iKpRbV4plycFuQ/kNY
|
||||||
|
pNEUfF76D+wXo4nhgSOkp1p0LV2qkUi4rbNuUumhnbAJ7K7/lUCfp7Wn54RsWMZE
|
||||||
|
KejH2ro4gx3/XueufHLomrQ0czMD9A42Vkf1HC4/bjxkmdFWzFarRXFOyC9YQ+xj
|
||||||
|
kVe+w5jTXQKBgQDGFw8QLRFQT7bJ6GqbAGbGnzBLQf6Z30JC8CmKCsEcehO1jE4W
|
||||||
|
n86kz/tJQC/+Hfk4Lg94/mlp0H7/GHRFfUk0oTGvayAKur2442tOTOvv4mOyxlWv
|
||||||
|
xsmzzhxp6G2gSi8Gt/8CSuQB9xlczI3OPtgP3D6oNPlHzbP6qEc9Ut3YWQKBgCn/
|
||||||
|
9ULHyQLOP5ElLoGG3/goCuifLZ3DSgyM/2Kdd6Y6RQTk4w3de7Dv79p4gCtbKyie
|
||||||
|
/qZ+ckUt4qXkGQlEJt02UOw6VazBhMCRxK5IGUAf52IernmaoxtF3yrQA7I/D6iJ
|
||||||
|
SJXhimN12JzsPukovbCI1gSn3P/IbwOq2TLheMa1AoGBAMgIkmtSpk3DG1XeM8Cj
|
||||||
|
auR/HAh0tumCe6qmjnKGXhJyhMnsWtJ/TGF5Y/7Cfj45bHA851TiBkTdNRuI+CHJ
|
||||||
|
tXm2iwnyHyi32lCqyjVc746QJv43DEXeWk/bx1fmCgDUAO4OrTP/IeHLAeXZvih4
|
||||||
|
bwNJTWjdNQPSytvcKv1KMiZj
|
||||||
|
-----END PRIVATE KEY-----
|
||||||
|
|
@ -0,0 +1,28 @@
|
||||||
|
-----BEGIN PRIVATE KEY-----
|
||||||
|
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDOd8XzD5yvrtT4
|
||||||
|
Q4yRnyFl/LKaeTsrbK9qcYgbwb/A4iTzak5b5XCf/g72GMwuNokmmOlk2ppEmdJJ
|
||||||
|
qCMEdXHCR7YCuf81bxdd9xvsxShQ1JTdAdlOBA6OlsqGsk5ls/gTxLWyj+EgvkPf
|
||||||
|
l/WnIH0s2J+tDwr/QNMHMPE0pCLXef3F2TeeTyrbHv2Vbf4KcAOfA+wDjrWK49rr
|
||||||
|
1In5U0Q9Vhk5/4tbUU9SrnBwCrF5B7c10fajJ2iIZj6gSjZd1/C7L+LntC3KtJF5
|
||||||
|
bhASjvixG92CsysBxnoZsQnhRa2CFVi1jVfWLwxsNRcT2bVGnoEzaS7P2pkavjT3
|
||||||
|
A+SxS4QJAgMBAAECggEAGODz2FMERWMixHuXP6DWLGzjtJtxFs104bWmefnBumNF
|
||||||
|
opMnuAkQpia99MeOKu9lXWJFlWKF/kguv7Nj7NCeEZQEiZWR/AVT4n25PrGPJxZG
|
||||||
|
jc8AOVdhzaq74rkvmy+xb+hfIJIXxZNHqHSuJCJVEwdTTk4mvBU6mH48QmSY0i/o
|
||||||
|
aETuMrfB86pZYgf/mND2IlIcfbTDFyn1bUevI+hxh2kU71BDrLyH34ib09OxhYnO
|
||||||
|
8uS1SOwsPF/atLOmS5efxYLtFwS1yF1hQvYt8rUS+5Y/CsGO3ZO2X6WiJB1+KA5x
|
||||||
|
adeU2CckeNQVkljJm6C9ZwFpXU/v237gob5cKXOqpQKBgQDV3AIiRCG6b4gU/ZGK
|
||||||
|
UhAMFIKllVILSF1RyIansu5baM+1jysRDvkqpUoYoc0pljGaYHoWXyDLJ5WnHPMN
|
||||||
|
8E7SQRkZ2s0h8NsR7TukTqm4LeuGzDH64rjAb6VOun3uKMDmHTjoo5rU/7Tdsxjh
|
||||||
|
ggY9WkltvniHg0EkdlMHCRhk2wKBgQD3JudPMj2gSXoF6ylTX6mviGwc2FSxZOLn
|
||||||
|
83PdCV2iQyVJwMUlCl5IZjATERFuj4NV1TE6j2GjOl1pCnoanDgg7603Aw3bOPT3
|
||||||
|
xcnQIhE4UmSsIfLjUfZrM9oTE1d6L1R2/ptXYSF4nbmOuAqknp9tpHOrtrv9L+xy
|
||||||
|
SSkB+Hh96wKBgAHlWmt9WSMy++zbtp+YTKYexG29XiXVdWZVNcRk1LIgwr6kT0hu
|
||||||
|
bo0PPBHt1UjKGRR6SHrMSxkh97SskAcOm1RH2XYeN3VWkkqdZMr3G5ATcCQYyVSl
|
||||||
|
D+g81SVWh+lFmTgxCCEf2i6LOcpBXTYalf2TQFVlu+HPqxMsrV3BmeLDAoGBAO1R
|
||||||
|
FNCN7HDJvPqL6P2eoN/k/fLgospHlj2lHf8DbD5PfTGJgYPkpc2dGdJlFDj2YuT7
|
||||||
|
Ni8F2HoUo/cl0UNV9+tgWRG2xApZcZes+vD4lVJggzxpyMEQRa6AdojUjK3NXqx4
|
||||||
|
JA9OPAaGZNOu0sFpcqqkO1GJwI8IAmFm8JJs1L4LAoGAS61hq8fUegnvv1HQtfHP
|
||||||
|
CnHKUXHazQoTyycbrZPnN0jmYNmnBW8jyF+WHg2+Qa6/Bo5Tq2H9242VCktID6M9
|
||||||
|
TEAhBkFifbUzFBLvl//C86xUBslDqND4Qa+8HFE4FbSO0RcmTyLatZ0V/ai2cVtj
|
||||||
|
jAD3OaTPNdv3NJbd8+zetTY=
|
||||||
|
-----END PRIVATE KEY-----
|
||||||
|
|
@ -0,0 +1,21 @@
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIDXzCCAkegAwIBAgIUPHDvz3298b47cmBPGk9aukCPmTwwDQYJKoZIhvcNAQEL
|
||||||
|
BQAwPzELMAkGA1UEBhMCS1IxDjAMBgNVBAgMBVNlb3VsMQ0wCwYDVQQKDARnb29k
|
||||||
|
MREwDwYDVQQDDAhnb29kLmNvbTAeFw0yNTA2MjMwOTQxMjdaFw0yNzA2MjMwOTQx
|
||||||
|
MjdaMD8xCzAJBgNVBAYTAktSMQ4wDAYDVQQIDAVTZW91bDENMAsGA1UECgwEZ29v
|
||||||
|
ZDERMA8GA1UEAwwIZ29vZC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
|
||||||
|
AoIBAQDOd8XzD5yvrtT4Q4yRnyFl/LKaeTsrbK9qcYgbwb/A4iTzak5b5XCf/g72
|
||||||
|
GMwuNokmmOlk2ppEmdJJqCMEdXHCR7YCuf81bxdd9xvsxShQ1JTdAdlOBA6OlsqG
|
||||||
|
sk5ls/gTxLWyj+EgvkPfl/WnIH0s2J+tDwr/QNMHMPE0pCLXef3F2TeeTyrbHv2V
|
||||||
|
bf4KcAOfA+wDjrWK49rr1In5U0Q9Vhk5/4tbUU9SrnBwCrF5B7c10fajJ2iIZj6g
|
||||||
|
SjZd1/C7L+LntC3KtJF5bhASjvixG92CsysBxnoZsQnhRa2CFVi1jVfWLwxsNRcT
|
||||||
|
2bVGnoEzaS7P2pkavjT3A+SxS4QJAgMBAAGjUzBRMB0GA1UdDgQWBBRGafRI9OGc
|
||||||
|
RnoBgsE1Qhqf5rLl5TAfBgNVHSMEGDAWgBRGafRI9OGcRnoBgsE1Qhqf5rLl5TAP
|
||||||
|
BgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAD2qU2QxK43/0tmDTc
|
||||||
|
mpXjXA58bIdbFXJAgK7xXVoDixG6RxAx6SS5puZtRtlh4n1phcdKbez4bMV6aOOY
|
||||||
|
2DUsQBwEU7Lj0o3wX3hhJ//RG6IzibwpnlxgE/En44KZ6i1plaNLw5FqZRRuMKeZ
|
||||||
|
I6iyuDi9Dk2W27NIJHuO2ryNXOCBwVj5hDeQmoVAtZJntlmILG3/fqK2ma1m3xIg
|
||||||
|
rMNbJ/NuQZa/bHqgJvBQkTiNPtzuA/DJzFovQ6CXQQ4Jv7GPh3prlkHJE3rAAzAg
|
||||||
|
PZ4RtUZX+LhquM4lwSveYG4fESKHiFJgB+oclBzS/nf8KzkX22sdBwdW0YNtOllS
|
||||||
|
6BRS
|
||||||
|
-----END CERTIFICATE-----
|
||||||
|
|
@ -0,0 +1,16 @@
|
||||||
|
-----BEGIN CERTIFICATE REQUEST-----
|
||||||
|
MIICkzCCAXsCAQAwTjELMAkGA1UEBhMCS1IxDjAMBgNVBAgMBVNlb3VsMQ4wDAYD
|
||||||
|
VQQKDAVpamluYzEfMB0GA1UEAwwWKi5ncHVsaXZlLm5obmNsb3VkLmNvbTCCASIw
|
||||||
|
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJ59CgifQlaQpyE/hTwNXh1p+El/
|
||||||
|
LLosTGbawy+FPx1Nrc+41e97W2FdLmX/1QRUZ0LsQ/WT5uIjfzai4x+Fl4srm+Db
|
||||||
|
0fUFfNS9PHeHpo/KlSLwU+bVK4zrMvVX1lWHnPpCLCTPIzFVgYzViyJYs7RIfbh4
|
||||||
|
tUOLf8QVhXEmtext7zaMnQyZn5mpbAjwwlJcJ5/hgTv4HEasFOj2No+b41vXrdlb
|
||||||
|
pmiRYHhZk21JVhdxIVQtgw8HTzktl64lS0T0A8urtUbwZsSp74CkQ3AukX8e+0ee
|
||||||
|
4UuB+0273NIv6Bf2zZ6SODyrshP1/bQ3n38/eYQyT1UcD0AGc1osQnYpD1ECAwEA
|
||||||
|
AaAAMA0GCSqGSIb3DQEBCwUAA4IBAQA3zXoZY3NQyRX+e5NmiLKsOTeQOkuJ3z5L
|
||||||
|
0vXy0UXNaaLPuNMemU3f4PqW2ye2qp3618tXvIeR0dJ/kFNjvHanAz3Iuix0Kgfp
|
||||||
|
3eXrsZHKrmFbUkzEl2WtcemoQxeZJnqwGyYaIm0kWZio05fErobYPz69xl49gqnT
|
||||||
|
P5QgVKW6l+WoqawJ35O/IPscRlWV1KCLc/z08KQ0cZQJWNcL91DgSrEJq265CSTT
|
||||||
|
CMLRF4JI3bOTZ47e9oSD4mdHRgeIPz0rUAMQjnEOMhCvl2bLAENzDRobwC1YNUVY
|
||||||
|
Fz/4cnLsWPHPoTRd4EmaWyUu32UITxDKcBoZ9muoMpQsu9yEMDiY
|
||||||
|
-----END CERTIFICATE REQUEST-----
|
||||||
|
|
@ -0,0 +1,6 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: gitea
|
||||||
|
labels:
|
||||||
|
kubernetes.io/metadata.name: gitea
|
||||||
|
|
@ -0,0 +1,79 @@
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/pgpool/networkpolicy.yaml
|
||||||
|
kind: NetworkPolicy
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-pgpool
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
role: data
|
||||||
|
spec:
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
policyTypes:
|
||||||
|
- Ingress
|
||||||
|
- Egress
|
||||||
|
egress:
|
||||||
|
- {}
|
||||||
|
ingress:
|
||||||
|
- ports:
|
||||||
|
- port: 5432
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/networkpolicy.yaml
|
||||||
|
kind: NetworkPolicy
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: data
|
||||||
|
spec:
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
policyTypes:
|
||||||
|
- Ingress
|
||||||
|
- Egress
|
||||||
|
egress:
|
||||||
|
- {}
|
||||||
|
ingress:
|
||||||
|
- ports:
|
||||||
|
- port: 5432
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/redis-cluster/templates/networkpolicy.yaml
|
||||||
|
kind: NetworkPolicy
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
metadata:
|
||||||
|
name: release-name-redis-cluster
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
spec:
|
||||||
|
podSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
policyTypes:
|
||||||
|
- Ingress
|
||||||
|
- Egress
|
||||||
|
egress:
|
||||||
|
- {}
|
||||||
|
ingress:
|
||||||
|
# Allow inbound connections
|
||||||
|
- ports:
|
||||||
|
- port: 6379
|
||||||
|
- port: 16379
|
||||||
|
|
@ -0,0 +1,77 @@
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/pgpool/pdb.yaml
|
||||||
|
apiVersion: policy/v1
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-pgpool
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 4.5.2
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
spec:
|
||||||
|
maxUnavailable: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/pdb.yaml
|
||||||
|
apiVersion: policy/v1
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
spec:
|
||||||
|
maxUnavailable: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/witness-pdb.yaml
|
||||||
|
apiVersion: policy/v1
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql-witness
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: witness
|
||||||
|
spec:
|
||||||
|
maxUnavailable: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: witness
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/redis-cluster/templates/poddisruptionbudget.yaml
|
||||||
|
apiVersion: policy/v1
|
||||||
|
kind: PodDisruptionBudget
|
||||||
|
metadata:
|
||||||
|
name: release-name-redis-cluster
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
spec:
|
||||||
|
maxUnavailable: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
matchExpressions:
|
||||||
|
- {key: job-name, operator: NotIn, values: [release-name-redis-cluster-cluster-update]}
|
||||||
|
|
@ -0,0 +1,23 @@
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/redis-cluster/templates/redis-serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: release-name-redis-cluster
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
|
@ -0,0 +1,384 @@
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/pgpool/secrets.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-pgpool
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 4.5.2
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
admin-password: "aWppbmMxMjMh"
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/secrets.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
namespace: "gitea"
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
postgres-password: "aWppbmMxMjMh"
|
||||||
|
password: "Z2l0ZWE="
|
||||||
|
repmgr-password: "aWppbmMxMjMh"
|
||||||
|
---
|
||||||
|
# Source: gitea/templates/gitea/config.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: release-name-gitea-inline-config
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
_generals_: ""
|
||||||
|
cache: |-
|
||||||
|
ADAPTER=redis
|
||||||
|
HOST=redis+cluster://:@release-name-redis-cluster-headless.gitea.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||||
|
database: |-
|
||||||
|
DB_TYPE=postgres
|
||||||
|
HOST=release-name-postgresql-ha-pgpool.gitea.svc.cluster.local:5432
|
||||||
|
NAME=gitea
|
||||||
|
PASSWD=gitea
|
||||||
|
USER=gitea
|
||||||
|
indexer: ISSUE_INDEXER_TYPE=db
|
||||||
|
metrics: ENABLED=false
|
||||||
|
queue: |-
|
||||||
|
CONN_STR=redis+cluster://:@release-name-redis-cluster-headless.gitea.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||||
|
TYPE=redis
|
||||||
|
repository: ROOT=/data/git/gitea-repositories
|
||||||
|
security: INSTALL_LOCK=true
|
||||||
|
server: |-
|
||||||
|
APP_DATA_PATH=/data
|
||||||
|
DOMAIN=gitea.nhngpuaas.com
|
||||||
|
ENABLE_PPROF=false
|
||||||
|
HTTP_PORT=3000
|
||||||
|
PROTOCOL=http
|
||||||
|
ROOT_URL=https://gitea.nhngpuaas.com
|
||||||
|
SSH_DOMAIN=gitea.nhngpuaas.com
|
||||||
|
SSH_LISTEN_PORT=2222
|
||||||
|
SSH_PORT=22
|
||||||
|
START_SSH_SERVER=true
|
||||||
|
session: |-
|
||||||
|
PROVIDER=redis
|
||||||
|
PROVIDER_CONFIG=redis+cluster://:@release-name-redis-cluster-headless.gitea.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||||
|
---
|
||||||
|
# Source: gitea/templates/gitea/config.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: release-name-gitea
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
assertions: |
|
||||||
|
config_environment.sh: |-
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
function env2ini::log() {
|
||||||
|
printf "${1}\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
function env2ini::read_config_to_env() {
|
||||||
|
local section="${1}"
|
||||||
|
local line="${2}"
|
||||||
|
|
||||||
|
if [[ -z "${line}" ]]; then
|
||||||
|
# skip empty line
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 'xargs echo -n' trims all leading/trailing whitespaces and a trailing new line
|
||||||
|
local setting="$(awk -F '=' '{print $1}' <<< "${line}" | xargs echo -n)"
|
||||||
|
|
||||||
|
if [[ -z "${setting}" ]]; then
|
||||||
|
env2ini::log ' ! invalid setting'
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
local value=''
|
||||||
|
local regex="^${setting}(\s*)=(\s*)(.*)"
|
||||||
|
if [[ $line =~ $regex ]]; then
|
||||||
|
value="${BASH_REMATCH[3]}"
|
||||||
|
else
|
||||||
|
env2ini::log ' ! invalid setting'
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
env2ini::log " + '${setting}'"
|
||||||
|
|
||||||
|
if [[ -z "${section}" ]]; then
|
||||||
|
export "GITEA____${setting^^}=${value}" # '^^' makes the variable content uppercase
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
|
||||||
|
local masked_section="${section//./_0X2E_}" # '//' instructs to replace all matches
|
||||||
|
masked_section="${masked_section//-/_0X2D_}"
|
||||||
|
|
||||||
|
export "GITEA__${masked_section^^}__${setting^^}=${value}" # '^^' makes the variable content uppercase
|
||||||
|
}
|
||||||
|
|
||||||
|
function env2ini::reload_preset_envs() {
|
||||||
|
env2ini::log "Reloading preset envs..."
|
||||||
|
|
||||||
|
while read -r line; do
|
||||||
|
if [[ -z "${line}" ]]; then
|
||||||
|
# skip empty line
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 'xargs echo -n' trims all leading/trailing whitespaces and a trailing new line
|
||||||
|
local setting="$(awk -F '=' '{print $1}' <<< "${line}" | xargs echo -n)"
|
||||||
|
|
||||||
|
if [[ -z "${setting}" ]]; then
|
||||||
|
env2ini::log ' ! invalid setting'
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
local value=''
|
||||||
|
local regex="^${setting}(\s*)=(\s*)(.*)"
|
||||||
|
if [[ $line =~ $regex ]]; then
|
||||||
|
value="${BASH_REMATCH[3]}"
|
||||||
|
else
|
||||||
|
env2ini::log ' ! invalid setting'
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
env2ini::log " + '${setting}'"
|
||||||
|
|
||||||
|
export "${setting^^}=${value}" # '^^' makes the variable content uppercase
|
||||||
|
done < "/tmp/existing-envs"
|
||||||
|
|
||||||
|
rm /tmp/existing-envs
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
function env2ini::process_config_file() {
|
||||||
|
local config_file="${1}"
|
||||||
|
local section="$(basename "${config_file}")"
|
||||||
|
|
||||||
|
if [[ $section == '_generals_' ]]; then
|
||||||
|
|
||||||
|
section=''
|
||||||
|
else
|
||||||
|
env2ini::log " ${section}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
while read -r line; do
|
||||||
|
env2ini::read_config_to_env "${section}" "${line}"
|
||||||
|
done < <(awk 1 "${config_file}") # Helm .toYaml trims the trailing new line which breaks line processing; awk 1 ... adds it back while reading
|
||||||
|
}
|
||||||
|
|
||||||
|
function env2ini::load_config_sources() {
|
||||||
|
local path="${1}"
|
||||||
|
|
||||||
|
if [[ -d "${path}" ]]; then
|
||||||
|
env2ini::log "Processing $(basename "${path}")..."
|
||||||
|
|
||||||
|
while read -d '' configFile; do
|
||||||
|
env2ini::process_config_file "${configFile}"
|
||||||
|
done < <(find "${path}" -type l -not -name '..data' -print0)
|
||||||
|
|
||||||
|
env2ini::log "\n"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
function env2ini::generate_initial_secrets() {
|
||||||
|
# These environment variables will either be
|
||||||
|
# - overwritten with user defined values,
|
||||||
|
# - initially used to set up Gitea
|
||||||
|
# Anyway, they won't harm existing app.ini files
|
||||||
|
|
||||||
|
export GITEA__SECURITY__INTERNAL_TOKEN=$(gitea generate secret INTERNAL_TOKEN)
|
||||||
|
export GITEA__SECURITY__SECRET_KEY=$(gitea generate secret SECRET_KEY)
|
||||||
|
export GITEA__OAUTH2__JWT_SECRET=$(gitea generate secret JWT_SECRET)
|
||||||
|
export GITEA__SERVER__LFS_JWT_SECRET=$(gitea generate secret LFS_JWT_SECRET)
|
||||||
|
|
||||||
|
env2ini::log "...Initial secrets generated\n"
|
||||||
|
}
|
||||||
|
|
||||||
|
# save existing envs prior to script execution. Necessary to keep order of preexisting and custom envs
|
||||||
|
env | (grep -e '^GITEA__' || [[ $? == 1 ]]) > /tmp/existing-envs
|
||||||
|
|
||||||
|
# MUST BE CALLED BEFORE OTHER CONFIGURATION
|
||||||
|
env2ini::generate_initial_secrets
|
||||||
|
|
||||||
|
env2ini::load_config_sources '/env-to-ini-mounts/inlines/'
|
||||||
|
env2ini::load_config_sources '/env-to-ini-mounts/additionals/'
|
||||||
|
|
||||||
|
# load existing envs to override auto generated envs
|
||||||
|
env2ini::reload_preset_envs
|
||||||
|
|
||||||
|
env2ini::log "=== All configuration sources loaded ===\n"
|
||||||
|
|
||||||
|
# safety to prevent rewrite of secret keys if an app.ini already exists
|
||||||
|
if [ -f ${GITEA_APP_INI} ]; then
|
||||||
|
env2ini::log 'An app.ini file already exists. To prevent overwriting secret keys, these settings are dropped and remain unchanged:'
|
||||||
|
env2ini::log ' - security.INTERNAL_TOKEN'
|
||||||
|
env2ini::log ' - security.SECRET_KEY'
|
||||||
|
env2ini::log ' - oauth2.JWT_SECRET'
|
||||||
|
env2ini::log ' - server.LFS_JWT_SECRET'
|
||||||
|
|
||||||
|
unset GITEA__SECURITY__INTERNAL_TOKEN
|
||||||
|
unset GITEA__SECURITY__SECRET_KEY
|
||||||
|
unset GITEA__OAUTH2__JWT_SECRET
|
||||||
|
unset GITEA__SERVER__LFS_JWT_SECRET
|
||||||
|
fi
|
||||||
|
|
||||||
|
environment-to-ini -o $GITEA_APP_INI
|
||||||
|
---
|
||||||
|
# Source: gitea/templates/gitea/init.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: release-name-gitea-init
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
configure_gpg_environment.sh: |-
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
gpg --batch --import /raw/private.asc
|
||||||
|
init_directory_structure.sh: |-
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
set -x
|
||||||
|
mkdir -p /data/git/.ssh
|
||||||
|
chmod -R 700 /data/git/.ssh
|
||||||
|
[ ! -d /data/gitea/conf ] && mkdir -p /data/gitea/conf
|
||||||
|
|
||||||
|
# prepare temp directory structure
|
||||||
|
mkdir -p "${GITEA_TEMP}"
|
||||||
|
chmod ug+rwx "${GITEA_TEMP}"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
configure_gitea.sh: |-
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
echo '==== BEGIN GITEA CONFIGURATION ===='
|
||||||
|
|
||||||
|
{ # try
|
||||||
|
gitea migrate
|
||||||
|
} || { # catch
|
||||||
|
echo "Gitea migrate might fail due to database connection...This init-container will try again in a few seconds"
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
function test_redis_connection() {
|
||||||
|
local RETRY=0
|
||||||
|
local MAX=30
|
||||||
|
|
||||||
|
echo 'Wait for redis to become avialable...'
|
||||||
|
until [ "${RETRY}" -ge "${MAX}" ]; do
|
||||||
|
nc -vz -w2 release-name-redis-cluster-headless.gitea.svc.cluster.local 6379 && break
|
||||||
|
RETRY=$[${RETRY}+1]
|
||||||
|
echo "...not ready yet (${RETRY}/${MAX})"
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "${RETRY}" -ge "${MAX}" ]; then
|
||||||
|
echo "Redis not reachable after '${MAX}' attempts!"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
test_redis_connection
|
||||||
|
function configure_admin_user() {
|
||||||
|
local full_admin_list=$(gitea admin user list --admin)
|
||||||
|
local actual_user_table=''
|
||||||
|
|
||||||
|
# We might have distorted output due to warning logs, so we have to detect the actual user table by its headline and trim output above that line
|
||||||
|
local regex="(.*)(ID\s+Username\s+Email\s+IsActive.*)"
|
||||||
|
if [[ "${full_admin_list}" =~ $regex ]]; then
|
||||||
|
actual_user_table=$(echo "${BASH_REMATCH[2]}" | tail -n+2) # tail'ing to drop the table headline
|
||||||
|
else
|
||||||
|
# This code block should never be reached, as long as the output table header remains the same.
|
||||||
|
# If this code block is reached, the regex doesn't match anymore and we probably have to adjust this script.
|
||||||
|
|
||||||
|
echo "ERROR: 'configure_admin_user' was not able to determine the current list of admin users."
|
||||||
|
echo " Please review the output of 'gitea admin user list --admin' shown below."
|
||||||
|
echo " If you think it is an issue with the Helm Chart provisioning, file an issue at https://gitea.com/gitea/helm-chart/issues."
|
||||||
|
echo "DEBUG: Output of 'gitea admin user list --admin'"
|
||||||
|
echo "--"
|
||||||
|
echo "${full_admin_list}"
|
||||||
|
echo "--"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
local ACCOUNT_ID=$(echo "${actual_user_table}" | grep -E "\s+${GITEA_ADMIN_USERNAME}\s+" | awk -F " " "{printf \$1}")
|
||||||
|
if [[ -z "${ACCOUNT_ID}" ]]; then
|
||||||
|
local -a create_args
|
||||||
|
create_args=(--admin --username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}" --email "gitea@local.domain")
|
||||||
|
if [[ "${GITEA_ADMIN_PASSWORD_MODE}" = initialOnlyRequireReset ]]; then
|
||||||
|
create_args+=(--must-change-password=true)
|
||||||
|
else
|
||||||
|
create_args+=(--must-change-password=false)
|
||||||
|
fi
|
||||||
|
echo "No admin user '${GITEA_ADMIN_USERNAME}' found. Creating now..."
|
||||||
|
gitea admin user create "${create_args[@]}"
|
||||||
|
echo '...created.'
|
||||||
|
else
|
||||||
|
if [[ "${GITEA_ADMIN_PASSWORD_MODE}" = keepUpdated ]]; then
|
||||||
|
echo "Admin account '${GITEA_ADMIN_USERNAME}' already exist. Running update to sync password..."
|
||||||
|
# See https://gitea.com/gitea/helm-chart/issues/673
|
||||||
|
# --must-change-password argument was added to change-password, defaulting to true, counter to the previous behavior
|
||||||
|
# which acted as if it were provided with =false. If the argument is present in this version of gitea, then we
|
||||||
|
# should add it to prevent requiring frequent admin password resets.
|
||||||
|
local -a change_args
|
||||||
|
change_args=(--username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}")
|
||||||
|
if gitea admin user change-password --help | grep -qF -- '--must-change-password'; then
|
||||||
|
change_args+=(--must-change-password=false)
|
||||||
|
fi
|
||||||
|
gitea admin user change-password "${change_args[@]}"
|
||||||
|
echo '...password sync done.'
|
||||||
|
else
|
||||||
|
echo "Admin account '${GITEA_ADMIN_USERNAME}' already exist, but update mode is set to '${GITEA_ADMIN_PASSWORD_MODE}'. Skipping."
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
configure_admin_user
|
||||||
|
|
||||||
|
function configure_ldap() {
|
||||||
|
echo 'no ldap configuration... skipping.'
|
||||||
|
}
|
||||||
|
|
||||||
|
configure_ldap
|
||||||
|
|
||||||
|
function configure_oauth() {
|
||||||
|
echo 'no oauth configuration... skipping.'
|
||||||
|
}
|
||||||
|
|
||||||
|
configure_oauth
|
||||||
|
|
||||||
|
echo '==== END GITEA CONFIGURATION ===='
|
||||||
|
|
@ -0,0 +1,18 @@
|
||||||
|
# Source: gitea/templates/gitea/pvc.yaml
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: gitea-shared-storage
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
volumeMode: Filesystem
|
||||||
|
# storageClassName: sc-monitoring
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 500Gi # default: 10Gi
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
# to create 1-1 relationship for pod - persistent volume use unique labels
|
||||||
|
name: gitea-shared-storage-pv
|
||||||
|
|
@ -0,0 +1,6 @@
|
||||||
|
# Need To Change
|
||||||
|
## Secret File
|
||||||
|
* DOMAIN
|
||||||
|
* ROOT_URL
|
||||||
|
* SSH_DOMAIN
|
||||||
|
* ###-password : aWppbmMxMjMh
|
||||||
|
|
@ -0,0 +1,125 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: gitea-shared-storage-pv
|
||||||
|
labels:
|
||||||
|
name: gitea-shared-storage-pv
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 500Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: redis-data-release-name-redis-cluster-0
|
||||||
|
labels:
|
||||||
|
name: redis-data-release-name-redis-cluster-0
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 8Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea_redis_0
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: redis-data-release-name-redis-cluster-1
|
||||||
|
labels:
|
||||||
|
name: redis-data-release-name-redis-cluster-1
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 8Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea_redis_1
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: redis-data-release-name-redis-cluster-2
|
||||||
|
labels:
|
||||||
|
name: redis-data-release-name-redis-cluster-2
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 8Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea_redis_2
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: data-release-name-postgresql-ha-postgresql-0
|
||||||
|
labels:
|
||||||
|
name: data-release-name-postgresql-ha-postgresql-0
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 8Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea_post_0
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: data-release-name-postgresql-ha-postgresql-1
|
||||||
|
labels:
|
||||||
|
name: data-release-name-postgresql-ha-postgresql-1
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 8Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea_post_1
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: data-release-name-postgresql-ha-postgresql-2
|
||||||
|
labels:
|
||||||
|
name: data-release-name-postgresql-ha-postgresql-2
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 8Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/gitea_post_2
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
File diff suppressed because it is too large
Load Diff
|
|
@ -0,0 +1,820 @@
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/pgpool/deployment.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-pgpool
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 4.5.2
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 4.5.2
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
affinity:
|
||||||
|
podAffinity:
|
||||||
|
podAntiAffinity:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- podAffinityTerm:
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
weight: 1
|
||||||
|
nodeAffinity:
|
||||||
|
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 1001
|
||||||
|
fsGroupChangePolicy: Always
|
||||||
|
supplementalGroups: []
|
||||||
|
sysctls: []
|
||||||
|
serviceAccountName: release-name-postgresql-ha
|
||||||
|
# Auxiliary vars to populate environment variables
|
||||||
|
containers:
|
||||||
|
- name: pgpool
|
||||||
|
image: docker.io/bitnami/pgpool:4.5.2-debian-12-r2
|
||||||
|
imagePullPolicy: "IfNotPresent"
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
privileged: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
runAsGroup: 1001
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1001
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
env:
|
||||||
|
- name: BITNAMI_DEBUG
|
||||||
|
value: "false"
|
||||||
|
- name: PGPOOL_BACKEND_NODES
|
||||||
|
value: 0:release-name-postgresql-ha-postgresql-0.release-name-postgresql-ha-postgresql-headless:5432,1:release-name-postgresql-ha-postgresql-1.release-name-postgresql-ha-postgresql-headless:5432,2:release-name-postgresql-ha-postgresql-2.release-name-postgresql-ha-postgresql-headless:5432,
|
||||||
|
- name: PGPOOL_SR_CHECK_USER
|
||||||
|
value: "repmgr"
|
||||||
|
- name: PGPOOL_SR_CHECK_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
key: repmgr-password
|
||||||
|
- name: PGPOOL_SR_CHECK_DATABASE
|
||||||
|
value: "postgres"
|
||||||
|
- name: PGPOOL_ENABLE_LDAP
|
||||||
|
value: "no"
|
||||||
|
- name: PGPOOL_POSTGRES_USERNAME
|
||||||
|
value: "gitea"
|
||||||
|
- name: PGPOOL_POSTGRES_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
key: password
|
||||||
|
- name: PGPOOL_ADMIN_USERNAME
|
||||||
|
value: "admin"
|
||||||
|
- name: PGPOOL_ADMIN_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: release-name-postgresql-ha-pgpool
|
||||||
|
key: admin-password
|
||||||
|
- name: PGPOOL_AUTHENTICATION_METHOD
|
||||||
|
value: "scram-sha-256"
|
||||||
|
- name: PGPOOL_ENABLE_LOAD_BALANCING
|
||||||
|
value: "yes"
|
||||||
|
- name: PGPOOL_DISABLE_LOAD_BALANCE_ON_WRITE
|
||||||
|
value: "transaction"
|
||||||
|
- name: PGPOOL_ENABLE_LOG_CONNECTIONS
|
||||||
|
value: "no"
|
||||||
|
- name: PGPOOL_ENABLE_LOG_HOSTNAME
|
||||||
|
value: "yes"
|
||||||
|
- name: PGPOOL_ENABLE_LOG_PER_NODE_STATEMENT
|
||||||
|
value: "no"
|
||||||
|
- name: PGPOOL_RESERVED_CONNECTIONS
|
||||||
|
value: '1'
|
||||||
|
- name: PGPOOL_CHILD_LIFE_TIME
|
||||||
|
value: ""
|
||||||
|
- name: PGPOOL_ENABLE_TLS
|
||||||
|
value: "no"
|
||||||
|
- name: PGPOOL_HEALTH_CHECK_PSQL_TIMEOUT
|
||||||
|
value: "6"
|
||||||
|
envFrom:
|
||||||
|
ports:
|
||||||
|
- name: postgresql
|
||||||
|
containerPort: 5432
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 5
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 5
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /opt/bitnami/scripts/pgpool/healthcheck.sh
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 5
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 5
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 5
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -ec
|
||||||
|
- PGPASSWORD=${PGPOOL_POSTGRES_PASSWORD} psql -U "gitea" -d "gitea" -h /opt/bitnami/pgpool/tmp -tA -c "SELECT 1" >/dev/null
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 375m
|
||||||
|
ephemeral-storage: 2Gi
|
||||||
|
memory: 384Mi
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
ephemeral-storage: 50Mi
|
||||||
|
memory: 256Mi
|
||||||
|
volumeMounts:
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/pgpool/etc
|
||||||
|
subPath: app-etc-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/pgpool/conf
|
||||||
|
subPath: app-conf-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/pgpool/tmp
|
||||||
|
subPath: app-tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/pgpool/logs
|
||||||
|
subPath: app-logs-dir
|
||||||
|
volumes:
|
||||||
|
- name: empty-dir
|
||||||
|
emptyDir: {}
|
||||||
|
---
|
||||||
|
# Source: gitea/templates/gitea/deployment.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: release-name-gitea
|
||||||
|
namespace: gitea
|
||||||
|
annotations:
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
strategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 0
|
||||||
|
maxSurge: 100%
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
checksum/config: 00fd8064076a446a896870db4974c6590fcf51561cf391547e559011465a57d8
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 1000
|
||||||
|
initContainers:
|
||||||
|
- name: init-directories
|
||||||
|
image: "gitea/gitea:1.22.1-rootless"
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command: ["/usr/sbin/init_directory_structure.sh"]
|
||||||
|
env:
|
||||||
|
- name: GITEA_APP_INI
|
||||||
|
value: /data/gitea/conf/app.ini
|
||||||
|
- name: GITEA_CUSTOM
|
||||||
|
value: /data/gitea
|
||||||
|
- name: GITEA_WORK_DIR
|
||||||
|
value: /data
|
||||||
|
- name: GITEA_TEMP
|
||||||
|
value: /tmp/gitea
|
||||||
|
volumeMounts:
|
||||||
|
- name: init
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
|
||||||
|
securityContext:
|
||||||
|
{}
|
||||||
|
resources:
|
||||||
|
limits: {}
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
- name: init-app-ini
|
||||||
|
image: "gitea/gitea:1.22.1-rootless"
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
command: ["/usr/sbin/config_environment.sh"]
|
||||||
|
env:
|
||||||
|
- name: GITEA_APP_INI
|
||||||
|
value: /data/gitea/conf/app.ini
|
||||||
|
- name: GITEA_CUSTOM
|
||||||
|
value: /data/gitea
|
||||||
|
- name: GITEA_WORK_DIR
|
||||||
|
value: /data
|
||||||
|
- name: GITEA_TEMP
|
||||||
|
value: /tmp/gitea
|
||||||
|
volumeMounts:
|
||||||
|
- name: config
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
- name: inline-config-sources
|
||||||
|
mountPath: /env-to-ini-mounts/inlines/
|
||||||
|
|
||||||
|
securityContext:
|
||||||
|
{}
|
||||||
|
resources:
|
||||||
|
limits: {}
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
- name: configure-gitea
|
||||||
|
image: "gitea/gitea:1.22.1-rootless"
|
||||||
|
command: ["/usr/sbin/configure_gitea.sh"]
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 1000
|
||||||
|
env:
|
||||||
|
- name: GITEA_APP_INI
|
||||||
|
value: /data/gitea/conf/app.ini
|
||||||
|
- name: GITEA_CUSTOM
|
||||||
|
value: /data/gitea
|
||||||
|
- name: GITEA_WORK_DIR
|
||||||
|
value: /data
|
||||||
|
- name: GITEA_TEMP
|
||||||
|
value: /tmp/gitea
|
||||||
|
- name: HOME
|
||||||
|
value: /data/gitea/git
|
||||||
|
- name: GITEA_ADMIN_USERNAME
|
||||||
|
value: "gitea_admin"
|
||||||
|
- name: GITEA_ADMIN_PASSWORD
|
||||||
|
value: "nhn!@#123" # sdjo
|
||||||
|
- name: GITEA_ADMIN_PASSWORD_MODE
|
||||||
|
value: keepUpdated
|
||||||
|
volumeMounts:
|
||||||
|
- name: init
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits: {}
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 128Mi
|
||||||
|
terminationGracePeriodSeconds: 60
|
||||||
|
containers:
|
||||||
|
- name: gitea
|
||||||
|
image: "gitea/gitea:1.22.1-rootless"
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
env:
|
||||||
|
# SSH Port values have to be set here as well for openssh configuration
|
||||||
|
- name: SSH_LISTEN_PORT
|
||||||
|
value: "2222"
|
||||||
|
- name: SSH_PORT
|
||||||
|
value: "22"
|
||||||
|
- name: GITEA_APP_INI
|
||||||
|
value: /data/gitea/conf/app.ini
|
||||||
|
- name: GITEA_CUSTOM
|
||||||
|
value: /data/gitea
|
||||||
|
- name: GITEA_WORK_DIR
|
||||||
|
value: /data
|
||||||
|
- name: GITEA_TEMP
|
||||||
|
value: /tmp/gitea
|
||||||
|
- name: TMPDIR
|
||||||
|
value: /tmp/gitea
|
||||||
|
- name: HOME
|
||||||
|
value: /data/gitea/git
|
||||||
|
ports:
|
||||||
|
- name: ssh
|
||||||
|
containerPort: 2222
|
||||||
|
- name: http
|
||||||
|
containerPort: 3000
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 10
|
||||||
|
initialDelaySeconds: 200
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
tcpSocket:
|
||||||
|
port: http
|
||||||
|
timeoutSeconds: 1
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 3
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
tcpSocket:
|
||||||
|
port: http
|
||||||
|
timeoutSeconds: 1
|
||||||
|
resources:
|
||||||
|
{}
|
||||||
|
securityContext:
|
||||||
|
{}
|
||||||
|
volumeMounts:
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
- name: init
|
||||||
|
secret:
|
||||||
|
secretName: release-name-gitea-init
|
||||||
|
defaultMode: 110
|
||||||
|
- name: config
|
||||||
|
secret:
|
||||||
|
secretName: release-name-gitea
|
||||||
|
defaultMode: 110
|
||||||
|
- name: inline-config-sources
|
||||||
|
secret:
|
||||||
|
secretName: release-name-gitea-inline-config
|
||||||
|
- name: temp
|
||||||
|
emptyDir: {}
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: gitea-shared-storage
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/statefulset.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
namespace: "gitea"
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: data
|
||||||
|
spec:
|
||||||
|
replicas: 3
|
||||||
|
podManagementPolicy: "Parallel"
|
||||||
|
serviceName: release-name-postgresql-ha-postgresql-headless
|
||||||
|
updateStrategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: data
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: data
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
affinity:
|
||||||
|
podAffinity:
|
||||||
|
|
||||||
|
podAntiAffinity:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- podAffinityTerm:
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
weight: 1
|
||||||
|
nodeAffinity:
|
||||||
|
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 1001
|
||||||
|
fsGroupChangePolicy: Always
|
||||||
|
supplementalGroups: []
|
||||||
|
sysctls: []
|
||||||
|
serviceAccountName: release-name-postgresql-ha
|
||||||
|
hostNetwork: false
|
||||||
|
hostIPC: false
|
||||||
|
containers:
|
||||||
|
- name: postgresql
|
||||||
|
image: docker.io/bitnami/postgresql-repmgr:16.3.0-debian-12-r15
|
||||||
|
imagePullPolicy: "IfNotPresent"
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
privileged: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
runAsGroup: 1001
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1001
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
lifecycle:
|
||||||
|
preStop:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /pre-stop.sh
|
||||||
|
- "25"
|
||||||
|
# Auxiliary vars to populate environment variables
|
||||||
|
env:
|
||||||
|
- name: BITNAMI_DEBUG
|
||||||
|
value: "false"
|
||||||
|
# PostgreSQL configuration
|
||||||
|
- name: POSTGRESQL_VOLUME_DIR
|
||||||
|
value: "/bitnami/postgresql"
|
||||||
|
- name: PGDATA
|
||||||
|
value: "/bitnami/postgresql/data"
|
||||||
|
- name: POSTGRES_POSTGRES_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
key: postgres-password
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
value: "gitea"
|
||||||
|
- name: POSTGRES_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
key: password
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value: "gitea"
|
||||||
|
- name: POSTGRESQL_LOG_HOSTNAME
|
||||||
|
value: "true"
|
||||||
|
- name: POSTGRESQL_LOG_CONNECTIONS
|
||||||
|
value: "false"
|
||||||
|
- name: POSTGRESQL_LOG_DISCONNECTIONS
|
||||||
|
value: "false"
|
||||||
|
- name: POSTGRESQL_PGAUDIT_LOG_CATALOG
|
||||||
|
value: "off"
|
||||||
|
- name: POSTGRESQL_CLIENT_MIN_MESSAGES
|
||||||
|
value: "error"
|
||||||
|
- name: POSTGRESQL_SHARED_PRELOAD_LIBRARIES
|
||||||
|
value: "pgaudit, repmgr"
|
||||||
|
- name: POSTGRESQL_ENABLE_TLS
|
||||||
|
value: "no"
|
||||||
|
- name: POSTGRESQL_PORT_NUMBER
|
||||||
|
value: "5432"
|
||||||
|
# Repmgr configuration
|
||||||
|
- name: REPMGR_PORT_NUMBER
|
||||||
|
value: "5432"
|
||||||
|
- name: REPMGR_PRIMARY_PORT
|
||||||
|
value: "5432"
|
||||||
|
- name: MY_POD_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.name
|
||||||
|
- name: REPMGR_UPGRADE_EXTENSION
|
||||||
|
value: "no"
|
||||||
|
- name: REPMGR_PGHBA_TRUST_ALL
|
||||||
|
value: "no"
|
||||||
|
- name: REPMGR_MOUNTED_CONF_DIR
|
||||||
|
value: "/bitnami/repmgr/conf"
|
||||||
|
- name: REPMGR_NAMESPACE
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.namespace
|
||||||
|
- name: REPMGR_PARTNER_NODES
|
||||||
|
value: release-name-postgresql-ha-postgresql-0.release-name-postgresql-ha-postgresql-headless.$(REPMGR_NAMESPACE).svc.cluster.local,release-name-postgresql-ha-postgresql-1.release-name-postgresql-ha-postgresql-headless.$(REPMGR_NAMESPACE).svc.cluster.local,release-name-postgresql-ha-postgresql-2.release-name-postgresql-ha-postgresql-headless.$(REPMGR_NAMESPACE).svc.cluster.local,
|
||||||
|
- name: REPMGR_PRIMARY_HOST
|
||||||
|
value: "release-name-postgresql-ha-postgresql-0.release-name-postgresql-ha-postgresql-headless.$(REPMGR_NAMESPACE).svc.cluster.local"
|
||||||
|
- name: REPMGR_NODE_NAME
|
||||||
|
value: "$(MY_POD_NAME)"
|
||||||
|
- name: REPMGR_NODE_NETWORK_NAME
|
||||||
|
value: "$(MY_POD_NAME).release-name-postgresql-ha-postgresql-headless.$(REPMGR_NAMESPACE).svc.cluster.local"
|
||||||
|
- name: REPMGR_NODE_TYPE
|
||||||
|
value: "data"
|
||||||
|
- name: REPMGR_LOG_LEVEL
|
||||||
|
value: "NOTICE"
|
||||||
|
- name: REPMGR_CONNECT_TIMEOUT
|
||||||
|
value: "5"
|
||||||
|
- name: REPMGR_RECONNECT_ATTEMPTS
|
||||||
|
value: "2"
|
||||||
|
- name: REPMGR_RECONNECT_INTERVAL
|
||||||
|
value: "3"
|
||||||
|
- name: REPMGR_USERNAME
|
||||||
|
value: "repmgr"
|
||||||
|
- name: REPMGR_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
key: repmgr-password
|
||||||
|
- name: REPMGR_DATABASE
|
||||||
|
value: "repmgr"
|
||||||
|
- name: REPMGR_FENCE_OLD_PRIMARY
|
||||||
|
value: "no"
|
||||||
|
- name: REPMGR_CHILD_NODES_CHECK_INTERVAL
|
||||||
|
value: "5"
|
||||||
|
- name: REPMGR_CHILD_NODES_CONNECTED_MIN_COUNT
|
||||||
|
value: "1"
|
||||||
|
- name: REPMGR_CHILD_NODES_DISCONNECT_TIMEOUT
|
||||||
|
value: "30"
|
||||||
|
envFrom:
|
||||||
|
ports:
|
||||||
|
- name: postgresql
|
||||||
|
containerPort: 5432
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 6
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 5
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -ec
|
||||||
|
- 'PGPASSWORD=$POSTGRES_PASSWORD psql -w -U "gitea" -d "gitea" -h 127.0.0.1 -p 5432 -c "SELECT 1"'
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 6
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 5
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- bash
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
exec pg_isready -U "postgres" -h 127.0.0.1 -p 5432
|
||||||
|
[ -f /opt/bitnami/postgresql/tmp/.initialized ] || [ -f /bitnami/postgresql/.initialized ]
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 375m
|
||||||
|
ephemeral-storage: 2Gi
|
||||||
|
memory: 384Mi
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
ephemeral-storage: 50Mi
|
||||||
|
memory: 256Mi
|
||||||
|
volumeMounts:
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/postgresql/conf
|
||||||
|
subPath: app-conf-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/postgresql/tmp
|
||||||
|
subPath: app-tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/repmgr/conf
|
||||||
|
subPath: repmgr-conf-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/repmgr/tmp
|
||||||
|
subPath: repmgr-tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/repmgr/logs
|
||||||
|
subPath: repmgr-logs-dir
|
||||||
|
- name: data
|
||||||
|
mountPath: /bitnami/postgresql
|
||||||
|
- name: hooks-scripts
|
||||||
|
mountPath: /pre-stop.sh
|
||||||
|
subPath: pre-stop.sh
|
||||||
|
- name: hooks-scripts
|
||||||
|
mountPath: /readiness-probe.sh
|
||||||
|
subPath: readiness-probe.sh
|
||||||
|
volumes:
|
||||||
|
- name: empty-dir
|
||||||
|
emptyDir: {}
|
||||||
|
- name: hooks-scripts
|
||||||
|
configMap:
|
||||||
|
name: release-name-postgresql-ha-postgresql-hooks-scripts
|
||||||
|
defaultMode: 0755
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: data
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- "ReadWriteOnce"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: "8Gi"
|
||||||
|
---
|
||||||
|
# Source: cdgitea/charts/redis-cluster/templates/redis-statefulset.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: release-name-redis-cluster
|
||||||
|
namespace: "gitea"
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
spec:
|
||||||
|
updateStrategy:
|
||||||
|
rollingUpdate:
|
||||||
|
partition: 0
|
||||||
|
type: RollingUpdate
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
replicas: 3
|
||||||
|
serviceName: release-name-redis-cluster-headless
|
||||||
|
podManagementPolicy: Parallel
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
annotations:
|
||||||
|
checksum/scripts: f4443ed238f1b19ab40555e6ba2aea56daba79e8270549f884b9b31cf8e0e2ee
|
||||||
|
checksum/secret: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
||||||
|
checksum/config: 958b865b26062946819f240fe4e5fd268b7c3203b944549981f1bd7fdc7947eb
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
hostNetwork: false
|
||||||
|
enableServiceLinks: false
|
||||||
|
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 1001
|
||||||
|
fsGroupChangePolicy: Always
|
||||||
|
supplementalGroups: []
|
||||||
|
sysctls: []
|
||||||
|
serviceAccountName: release-name-redis-cluster
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
affinity:
|
||||||
|
podAffinity:
|
||||||
|
|
||||||
|
podAntiAffinity:
|
||||||
|
preferredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
- podAffinityTerm:
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
weight: 1
|
||||||
|
nodeAffinity:
|
||||||
|
|
||||||
|
containers:
|
||||||
|
- name: release-name-redis-cluster
|
||||||
|
image: docker.io/bitnami/redis-cluster:7.2.5-debian-12-r2
|
||||||
|
imagePullPolicy: "IfNotPresent"
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
privileged: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
runAsGroup: 1001
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1001
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
command: ['/bin/bash', '-c']
|
||||||
|
args:
|
||||||
|
- |
|
||||||
|
# Backwards compatibility change
|
||||||
|
if ! [[ -f /opt/bitnami/redis/etc/redis.conf ]]; then
|
||||||
|
echo COPYING FILE
|
||||||
|
cp /opt/bitnami/redis/etc/redis-default.conf /opt/bitnami/redis/etc/redis.conf
|
||||||
|
fi
|
||||||
|
pod_index=($(echo "$POD_NAME" | tr "-" "\n"))
|
||||||
|
pod_index="${pod_index[-1]}"
|
||||||
|
if [[ "$pod_index" == "0" ]]; then
|
||||||
|
export REDIS_CLUSTER_CREATOR="yes"
|
||||||
|
export REDIS_CLUSTER_REPLICAS="0"
|
||||||
|
fi
|
||||||
|
/opt/bitnami/scripts/redis-cluster/entrypoint.sh /opt/bitnami/scripts/redis-cluster/run.sh
|
||||||
|
env:
|
||||||
|
- name: POD_NAME
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
fieldPath: metadata.name
|
||||||
|
- name: REDIS_NODES
|
||||||
|
value: "release-name-redis-cluster-0.release-name-redis-cluster-headless release-name-redis-cluster-1.release-name-redis-cluster-headless release-name-redis-cluster-2.release-name-redis-cluster-headless "
|
||||||
|
- name: ALLOW_EMPTY_PASSWORD
|
||||||
|
value: "yes"
|
||||||
|
- name: REDIS_AOF_ENABLED
|
||||||
|
value: "yes"
|
||||||
|
- name: REDIS_TLS_ENABLED
|
||||||
|
value: "no"
|
||||||
|
- name: REDIS_PORT_NUMBER
|
||||||
|
value: "6379"
|
||||||
|
ports:
|
||||||
|
- name: tcp-redis
|
||||||
|
containerPort: 6379
|
||||||
|
- name: tcp-redis-bus
|
||||||
|
containerPort: 16379
|
||||||
|
livenessProbe:
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 5
|
||||||
|
# One second longer than command timeout should prevent generation of zombie processes.
|
||||||
|
timeoutSeconds: 6
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 5
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- /scripts/ping_liveness_local.sh 5
|
||||||
|
readinessProbe:
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 5
|
||||||
|
# One second longer than command timeout should prevent generation of zombie processes.
|
||||||
|
timeoutSeconds: 2
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 5
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- /scripts/ping_readiness_local.sh 1
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 150m
|
||||||
|
ephemeral-storage: 2Gi
|
||||||
|
memory: 192Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
ephemeral-storage: 50Mi
|
||||||
|
memory: 128Mi
|
||||||
|
volumeMounts:
|
||||||
|
- name: scripts
|
||||||
|
mountPath: /scripts
|
||||||
|
- name: redis-data
|
||||||
|
mountPath: /bitnami/redis/data
|
||||||
|
subPath:
|
||||||
|
- name: default-config
|
||||||
|
mountPath: /opt/bitnami/redis/etc/redis-default.conf
|
||||||
|
subPath: redis-default.conf
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/redis/etc/
|
||||||
|
subPath: app-conf-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/redis/tmp
|
||||||
|
subPath: app-tmp-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /opt/bitnami/redis/logs
|
||||||
|
subPath: app-logs-dir
|
||||||
|
- name: empty-dir
|
||||||
|
mountPath: /tmp
|
||||||
|
subPath: tmp-dir
|
||||||
|
volumes:
|
||||||
|
- name: scripts
|
||||||
|
configMap:
|
||||||
|
name: release-name-redis-cluster-scripts
|
||||||
|
defaultMode: 0755
|
||||||
|
- name: default-config
|
||||||
|
configMap:
|
||||||
|
name: release-name-redis-cluster-default
|
||||||
|
- name: empty-dir
|
||||||
|
emptyDir: {}
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: redis-data
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- "ReadWriteOnce"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: "8Gi"
|
||||||
|
|
@ -0,0 +1,26 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: ing-gitea
|
||||||
|
namespace: gitea
|
||||||
|
annotations:
|
||||||
|
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-body-size: "0"
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: gitea.nhngpuaas.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: release-name-gitea-http
|
||||||
|
port:
|
||||||
|
number: 3000
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- "gitea.nhngpuaas.com"
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
|
||||||
|
|
@ -0,0 +1,172 @@
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/pgpool/service.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-pgpool
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 4.5.2
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
sessionAffinity: None
|
||||||
|
ports:
|
||||||
|
- name: "postgresql"
|
||||||
|
port: 5432
|
||||||
|
targetPort: postgresql
|
||||||
|
protocol: TCP
|
||||||
|
# nodePort: null
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: pgpool
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/service-headless.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql-headless
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
clusterIP: None
|
||||||
|
publishNotReadyAddresses: false
|
||||||
|
ports:
|
||||||
|
- name: "postgresql"
|
||||||
|
port: 5432
|
||||||
|
targetPort: postgresql
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: data
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/postgresql-ha/templates/postgresql/service.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-postgresql-ha-postgresql
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/version: 16.3.0
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- name: "postgresql"
|
||||||
|
port: 5432
|
||||||
|
targetPort: postgresql
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: postgresql-ha
|
||||||
|
app.kubernetes.io/component: postgresql
|
||||||
|
role: data
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/redis-cluster/templates/headless-svc.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-redis-cluster-headless
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
clusterIP: None
|
||||||
|
publishNotReadyAddresses: true
|
||||||
|
ports:
|
||||||
|
- name: tcp-redis
|
||||||
|
port: 6379
|
||||||
|
targetPort: tcp-redis
|
||||||
|
- name: tcp-redis-bus
|
||||||
|
port: 16379
|
||||||
|
targetPort: tcp-redis-bus
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
---
|
||||||
|
# Source: gitea/charts/redis-cluster/templates/redis-svc.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-redis-cluster
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
app.kubernetes.io/version: 7.2.5
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
sessionAffinity: None
|
||||||
|
ports:
|
||||||
|
- name: tcp-redis
|
||||||
|
port: 6379
|
||||||
|
targetPort: tcp-redis
|
||||||
|
protocol: TCP
|
||||||
|
nodePort: null
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/name: redis-cluster
|
||||||
|
---
|
||||||
|
# Source: gitea/templates/gitea/http-svc.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-gitea-http
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
# annotations:
|
||||||
|
# {}
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
clusterIP: None
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 3000
|
||||||
|
targetPort:
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
---
|
||||||
|
# Source: gitea/templates/gitea/ssh-svc.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: release-name-gitea-ssh
|
||||||
|
namespace: gitea
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
app.kubernetes.io/version: "1.22.1"
|
||||||
|
version: "1.22.1"
|
||||||
|
# annotations:
|
||||||
|
# {}
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
clusterIP: None
|
||||||
|
ports:
|
||||||
|
- name: ssh
|
||||||
|
port: 22
|
||||||
|
targetPort: 2222
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: gitea
|
||||||
|
app.kubernetes.io/instance: release-name
|
||||||
|
|
@ -132,7 +132,6 @@ data:
|
||||||
scgi_temp_path /tmp/scgi_temp;
|
scgi_temp_path /tmp/scgi_temp;
|
||||||
server {
|
server {
|
||||||
listen 8080;
|
listen 8080;
|
||||||
listen [::]:8080;
|
|
||||||
server_name localhost;
|
server_name localhost;
|
||||||
root /usr/share/nginx/html;
|
root /usr/share/nginx/html;
|
||||||
index index.html index.htm;
|
index index.html index.htm;
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: harbor-cacerts
|
||||||
|
namespace: harbor
|
||||||
|
# harbor-corer pod // /etc/core/ca
|
||||||
|
data:
|
||||||
|
cert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURtekNDQW9PZ0F3SUJBZ0lVTFVnOHBsdGlSTDVqSVhzL1ppQ1pacmtncElRd0RRWUpLb1pJaHZjTkFRRUwKQlFBd1hURUxNQWtHQTFVRUJoTUNTMUl4RGpBTUJnTlZCQWdNQlZObGIzVnNNUTB3Q3dZRFZRUUhEQVJKYm1wbApNUTh3RFFZRFZRUUtEQVpwYm1OdmNuQXhEREFLQmdOVkJBc01BMlJsZGpFUU1BNEdBMVVFQXd3SGFXNXFaV2x1Cll6QWVGdzB5TkRFeU1ESXdORFEwTlRkYUZ3MHlOakV5TURJd05EUTBOVGRhTUYweEN6QUpCZ05WQkFZVEFrdFMKTVE0d0RBWURWUVFJREFWVFpXOTFiREVOTUFzR0ExVUVCd3dFU1c1cVpURVBNQTBHQTFVRUNnd0dhVzVqYjNKdwpNUXd3Q2dZRFZRUUxEQU5rWlhZeEVEQU9CZ05WQkFNTUIybHVhbVZwYm1Nd2dnRWlNQTBHQ1NxR1NJYjNEUUVCCkFRVUFBNElCRHdBd2dnRUtBb0lCQVFERmVDRU1iM3Yrbmt1OUJic1FVdUt5dGJabUN5MTdPcDZSTGxmWEZaSTAKbUxLRjZadTlTczh0cmV0VDA3eHZrY2x2YzF4b2ZJMlFWMVFmSkFDQmhqU0FaWUJTbWZhNE5oWExnNEYvcEFSQQpjbStINnR2TGtSNllvZVMvWXVJUDVQVXVxWmt6Ym9ZQWl5T0NUelYxNEhRb25OU20rOFZvSnNMemEwZEZZZklNCmtGOVVsMklFSERmQ2xrQWt1cDNFYlNyMkNTYXdLV3J4OXd2N2cvbXR3ekloL0MwKy81MXh2dFZSSVVUZk1qQlIKUVVWL1VBWEJhS0UvNHlwN1RZaWpHa21WUEJUVTRid2hmcHdNeklUMWxpSjhwaE1qTGZtbDMxd1Q5R1FWYnhyMgpXOU5NdnFQWklMVmx6c1VUcTJyOU13TU8rQ3VreVNWbWRBOXgwenc1MUNGZkFnTUJBQUdqVXpCUk1CMEdBMVVkCkRnUVdCQlFsTWo0YzFmMjg1bmlHREJRcmNlYUp5MDJtalRBZkJnTlZIU01FR0RBV2dCUWxNajRjMWYyODVuaUcKREJRcmNlYUp5MDJtalRBUEJnTlZIUk1CQWY4RUJUQURBUUgvTUEwR0NTcUdTSWIzRFFFQkN3VUFBNElCQVFBTgpBZ0R1OEY3SGVWakZ4bU11NGZZVWZrN0czU1ZObWdacXo0MzhNanhjS2dJYmR6NnE1Q0xTNW1hSng0RitVc2VPCjZaZHBEQm1GSncrK1E4QVUvQ0tLY3dOZC83eGRzSEhEUFY0MFNNVStLc08xT0FJZjBIeFZXV3lFd0VRaW1obFgKWEJBZVJocEF5NHFTNTI1dE11RnUxeFkxOVJJME1VRlpmV05JUW1OZ0N5QWRINkIyY3Z5dmhSU2crRXdhYnV6RQpkdmN6R3JOZm1tUGphMXRZTnBQWGFpQ0hGc2h2QzlJMzZwOEhuYjNKY3VsVSswL2Y3UzRWZGhSTm1nakY1elhMCkl6Wk1TbXhnMnVmc25DNHFhS3FONU9ISi9NbGJIYTRzRFR0cHNLaWNBWUE3aUw2WjFvcmtIeTc1cUdYVlRtekMKU2xkbkxwQWw2cS9wUXg1bUpVdEwKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQ==
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-core
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
CSRF_KEY: Tk9ORjNTYjZoZ2tIdlZmcXNlcTVEdjNhUlBjWDZ6Rjg=
|
||||||
|
HARBOR_ADMIN_PASSWORD: bmhuIUAjMTIz
|
||||||
|
# POSTGRES_PASSWORD --> init파일에 있는 것. database에서 사용하는 변수명
|
||||||
|
POSTGRESQL_PASSWORD: bmhuIUAjMTIz # harbor-core에서 사용하는 변수명
|
||||||
|
REGISTRY_CREDENTIAL_PASSWORD: aGFyYm9yX3JlZ2lzdHJ5X3Bhc3N3b3Jk
|
||||||
|
secret: RTRQY0FxZ3RPVmdKWTBRRw==
|
||||||
|
secretKey: bm90LWEtc2VjdXJlLWtleQ==
|
||||||
|
tls.cert: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURyekNDQXBlZ0F3SUJBZ0lVVzZZZlZMdkhUVEZ6ZU40R05wbmgxZW1XcXpRd0RRWUpLb1pJaHZjTkFRRUwKQlFBd1hURUxNQWtHQTFVRUJoTUNTMUl4RGpBTUJnTlZCQWdNQlZObGIzVnNNUTB3Q3dZRFZRUUhEQVJKYm1wbApNUTh3RFFZRFZRUUtEQVpwYm1OdmNuQXhEREFLQmdOVkJBc01BMlJsZGpFUU1BNEdBMVVFQXd3SGFXNXFaV2x1Cll6QWVGdzB5TkRFeU1ESXdOakV3TlRkYUZ3MHlOakV5TURJd05qRXdOVGRhTUdVeEN6QUpCZ05WQkFZVEFrdFMKTVE0d0RBWURWUVFJREFWVFpXOTFiREVPTUF3R0ExVUVCd3dGUjBGVFFVNHhEREFLQmdOVkJBb01BMlJsWWpFTgpNQXNHQTFVRUN3d0VkR1Z6ZERFWk1CY0dBMVVFQXd3UUtpNXVZWFJwZG1Wa1pXTnJMbU52YlRDQ0FTSXdEUVlKCktvWklodmNOQVFFQkJRQURnZ0VQQURDQ0FRb0NnZ0VCQU11U1JJVUJBMWhSWmd4M3p4djVJeWljMnd3alZUcmkKa3QrQ01CNndTLzQrVDUxMkxnd29PQU9IdnQ1L0hDbEVSUVdWd280ZDN2cDR3WmQ3MktxVXM2Ym9CclZmeWU4bAo1bC84MkpGQkhqNStGWDhtTS8wYldkMHVhV1NVNDdsNHhBTzFwU3V0cXgxdkJQdlI2aC9DT0k4cEpBakVxd1llCjVLU1RGWllKOG5YWXJrbkFhRnl1dnkwZjhNcHdUbW1GWEZWeVZQbGlhZkhYUjFVWVNQUlFIcWo0TXF3VTM4OXMKSjdOOVlsMzBwMVUzVWVMRkx2Q0lEUU1UVFFzbUNSbnA3UzV1VzZETC90eXNwdnAwRVVzcDRHRXRhY3drZU84cwo0UlZqeGEyR0JiUTViSGJ2MGxZLzZBKzk5Szc5U0ZNcksvd1ptM0dSeDkvblJKWXc2OUpLZ2xVQ0F3RUFBYU5mCk1GMHdHd1lEVlIwUkJCUXdFb0lRS2k1dVlYUnBkbVZrWldOckxtTnZiVEFkQmdOVkhRNEVGZ1FVbitzL2oyMzEKcC8ycnFWWFNTSk5IVWZnNU5PQXdId1lEVlIwakJCZ3dGb0FVSlRJK0hOWDl2T1o0aGd3VUszSG1pY3ROcG8wdwpEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJBR2haQVNobU05Mm9yVHo5ZndtOG9qZ25xekZ5dmlGa2lrYjU2MDI4CmZEZXV5M2d2aUZqNHk5a3hlQ1lqdjQ4ZWJ1cHlFL1oyZnJ5eVltWXNOOHNlanNLcTY2V0J1TDh0ZG9TS3ZjcFMKQU1TOU5reEhWZlJvRmFGSmgxZVQ3RzhoYVd0dTdpSUxRUzB5dXZWYkFhMGFPVzRpY3p0eXVlK0MyOXRXS3pLcAp4ZndtOEI5SzFzRVUwdEN2d1R6L2wwTlBpYXdOelNnc3UrWFkwbW1xZ0NQbG1zd2cxRkNwWTUzcHBqRE5NTzJDCnJ5bGhKbnowM2JpS2NQb0VCQlNKZFo2WGt2UG93SUV5bGZ3SWlEV3VNRjFaNzViaTBoaGFFTjRDaVJkeSt4MDkKR1NQa04zMlZ4d3dvTXhHd3A0VWJSS0g4YVR6Q2VWT0ZuaE8xbGp3MVdSR2ZRUWc9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0=
|
||||||
|
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFb3dJQkFBS0NBUUVBeTVKRWhRRURXRkZtREhmUEcva2pLSnpiRENOVk91S1MzNEl3SHJCTC9qNVBuWFl1CkRDZzRBNGUrM244Y0tVUkZCWlhDamgzZStuakJsM3ZZcXBTenB1Z0d0Vi9KN3lYbVgvellrVUVlUG40VmZ5WXoKL1J0WjNTNXBaSlRqdVhqRUE3V2xLNjJySFc4RSs5SHFIOEk0anlra0NNU3JCaDdrcEpNVmxnbnlkZGl1U2NCbwpYSzYvTFIvd3luQk9hWVZjVlhKVStXSnA4ZGRIVlJoSTlGQWVxUGd5ckJUZnoyd25zMzFpWGZTblZUZFI0c1V1CjhJZ05BeE5OQ3lZSkdlbnRMbTVib012KzNLeW0rblFSU3luZ1lTMXB6Q1I0N3l6aEZXUEZyWVlGdERsc2R1L1MKVmovb0Q3MzBydjFJVXlzci9CbWJjWkhIMytkRWxqRHIwa3FDVlFJREFRQUJBb0lCQUZaMGV5Y2xZLzlKS3BiVwo5eDJCTkY1V0oyMURRRG91NllPRTdkektzS3Q4V1NHZGhEYmppYzV1QXpESk9QT0pxK3FRVEwxQWtHYzlpN0pECkJhU0VYTHZneEtDWTJ0RDIvcHo3YkJwY1ZuVGg1VTFIczBLbU1BY1FZL0EwajNaQWhMYXltVUF3bElCK210WTcKc3p2anAxT2RmRkZBL1FVdmI1azVZaXlEY3ZaNjJwL2VaNXdDOXY4dFhjRVpIN2FpVWNKSGM1ajFrRFRpckErawpjWW5xUTJ2NHovWXJKek9Xa2tyTTNudFpOSzM0QzMrMUQrb1d6QjZHNjJJb0JCZnVxVGNJZHgwMXNvbjNIMXVYClpMNHdNbXRLZ0Z0RFJLdEpQNysxOXJsaU1qL09UWEd3WkZlS2c1RGY3T2Y2MFl1em1kVXFhNHQrMXlicHd2RkEKb0U2OW15MENnWUVBM09wcFV1RmZwZUxiRGsvdHJGY3ByNksxaTdubFA0TXowMXhySG03d3VEaS80TWp6VnlkVworZ0t0emYzRm1rNE5iYyt6aGdXblIzN2RheFlzbzVacC9Uck9GemFuNGpIKzhzNU9LWDI2WjBJZjVnQm01NmwzCmtKckU3UnAxMFF3ZE0xRkVQOWtGaFZyK2YzWm5rQ3QyNjQ3aFVWY2Jubk1CUHhZVkNWZzZmOE1DZ1lFQTYrYXoKNG12Y1dSZm1LSFd1dnovRVZPL3lRT3BxOCtkc2l3dXFRZ2xIWm5SZ0Rmc05uZ3NyK3hBaWJoVm94Q3ZZdm84dApnNVVqdXArVklEVFVqRlp6bkd1N2xVWlRyMVBQS1lCS2dtSVVqRkpYQ1JCUUd5akttUG5LYmhJb2RxUWRCV2o3CkIrOTNDeVBsMHRZVWNNMjdEL0E5TDNDaHBJVktxZ25JeHpZZXJBY0NnWUJqS1JFWHM3UUVPUHpNd3RIVFB0aW0KVHFtZ3kxTjhtNzdpaTZSRlo5VERUQzNNajBhekF5U0dXamQ3dEFKRGplOTNML2pNR3JPSVl3aXVMYWpoMFAxSQpQbUlOaDJuNkhTanNBZkNSclM3RGRLbnV5cFZtUE9vL1RVbEJpRlFEL3FVSXlOeVNzQzVMT3Bucnl0RVhwSHJmCnB5VzZKaGh1bWY2Z082QTdybytya3dLQmdIOXVEam4vWGZaYXJKK3FnbzBaR3l0dXVvUktuUi9JSWFBeTJ2UDEKSXphN0lyQXFyNzV4OW40V3h5S0VPaVhPTWJVdWpyMkhzTmM5SVVkV2dvS1VxTHNVank0aDRVN1NqUk8wRTR1LwpBNjZSUkNiSFF4Nkl1SGhPWndWeWxaMFJKZ1FvSTRLejNyQ0w0Ymcwb0xJVzBEZlo1Sk5kMmxPUEZUZ3BOT1kzCjIvVzlBb0dCQU1HRXJtczVrRWZkdDFveXYxUlBwbENSUG1yVCs4TUV1K3lyanJXSXlxWEo4SHcwd09mTlhsTXQKUzhRbFdDb0xnbmFxZU81ZWd6OGF2L2ZVNDhxbU9tTVFPUDRMbWxSSm1ZM1E3MVpCZUc5akxPUFZCZlhFeDVDTQp2d283dFhEU1JKRVdUcGp3dCtUMy9uTlZhMm9QMGNXTUg1akJ0c1ZXMnhrM3F5K0NJWVBqCi0tLS0tRU5EIFJTQSBQUklWQVRFIEtFWS0tLS0t
|
||||||
|
---
|
||||||
|
|
@ -0,0 +1,83 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
kubernetes.io/metadata.name: harbor
|
||||||
|
name: harbor
|
||||||
|
spec:
|
||||||
|
finalizers:
|
||||||
|
- kubernetes
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-database
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
POSTGRES_PASSWORD: bmhuIUAjMTIz
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-jobservice
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
JOBSERVICE_SECRET: akVWbzlyNFJaU2R1clJqUA==
|
||||||
|
REGISTRY_CREDENTIAL_PASSWORD: aGFyYm9yX3JlZ2lzdHJ5X3Bhc3N3b3Jk
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
data:
|
||||||
|
REGISTRY_HTTP_SECRET: dHlCdm41MXpIakxLRm5mRw==
|
||||||
|
REGISTRY_REDIS_PASSWORD: ""
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registry
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
data:
|
||||||
|
REGISTRY_HTPASSWD: aGFyYm9yX3JlZ2lzdHJ5X3VzZXI6JDJhJDEwJG1uRkVSQkVyRmROYnNuZDVHWUxTQXVUOTRaUWxZNGkxU3BtNTk4dWlmV2pLbEJrQnJhbHEu
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registry-htpasswd
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
data: null
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registryctl
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
data:
|
||||||
|
gitHubToken: ""
|
||||||
|
redisURL: cmVkaXM6Ly9oYXJib3ItcmVkaXM6NjM3OS81P2lkbGVfdGltZW91dF9zZWNvbmRzPTMw
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-trivy
|
||||||
|
namespace: harbor
|
||||||
|
type: Opaque
|
||||||
|
|
@ -0,0 +1,90 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: harbor-jobservice-pv
|
||||||
|
labels:
|
||||||
|
name: harbor-jobservice-pv
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteMany
|
||||||
|
capacity:
|
||||||
|
storage: 50Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/harbor-job
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: harbor-registry-pv
|
||||||
|
labels:
|
||||||
|
name: harbor-registry-pv
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteMany
|
||||||
|
capacity:
|
||||||
|
storage: 2000Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/harbor-registry
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: data-harbor-redis-0
|
||||||
|
labels:
|
||||||
|
name: data-harbor-redis-0
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 50Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/harbor_redis
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: data-harbor-trivy-0
|
||||||
|
labels:
|
||||||
|
name: data-harbor-trivy-0
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 200Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/harbor_trivy
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: database-data-harbor-database-0
|
||||||
|
labels:
|
||||||
|
name: database-data-harbor-database-0
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
capacity:
|
||||||
|
storage: 50Gi
|
||||||
|
csi:
|
||||||
|
driver: exa.csi.ddn.com
|
||||||
|
volumeHandle: exa1:/harbor_database
|
||||||
|
volumeAttributes: # volumeAttributes are the alternative of storageClass params for static (precreated) volumes.
|
||||||
|
# mountOptions: ro, noflock # list of options for `mount` command
|
||||||
|
bindMount: "false" # Determines, whether volume will bind mounted or as a separate lustre mount.
|
||||||
|
|
||||||
|
|
@ -0,0 +1,43 @@
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: jobservice
|
||||||
|
release: harbor
|
||||||
|
name: harbor-jobservice
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteMany
|
||||||
|
# storageClassName: sc-monitoring
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
# to create 1-1 relationship for pod - persistent volume use unique labels
|
||||||
|
name: harbor-jobservice-pv
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: registry
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registry
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
# storageClassName: sc-monitoring
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteMany
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 100Gi
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
# to create 1-1 relationship for pod - persistent volume use unique labels
|
||||||
|
name: harbor-registry-pv
|
||||||
|
|
||||||
|
|
@ -0,0 +1,226 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-core
|
||||||
|
namespace: harbor
|
||||||
|
data:
|
||||||
|
_REDIS_URL_CORE: redis://harbor-redis:6379/0?idle_timeout_seconds=30
|
||||||
|
_REDIS_URL_REG: redis://harbor-redis:6379/2?idle_timeout_seconds=30
|
||||||
|
CHART_CACHE_DRIVER: redis
|
||||||
|
CONFIG_PATH: /etc/core/app.conf
|
||||||
|
CORE_LOCAL_URL: http://127.0.0.1:8080
|
||||||
|
CORE_URL: http://harbor-core:80
|
||||||
|
DATABASE_TYPE: postgresql
|
||||||
|
EXT_ENDPOINT: https://registry.gpulive.nhncloud.com
|
||||||
|
HTTP_PROXY: ""
|
||||||
|
HTTPS_PROXY: ""
|
||||||
|
JOBSERVICE_URL: http://harbor-jobservice
|
||||||
|
LOG_LEVEL: info
|
||||||
|
NO_PROXY: harbor-core,harbor-jobservice,harbor-database,harbor-registry,harbor-portal,harbor-trivy,harbor-exporter,127.0.0.1,localhost,.local,.internal
|
||||||
|
PERMITTED_REGISTRY_TYPES_FOR_PROXY_CACHE: docker-hub,harbor,azure-acr,aws-ecr,google-gcr,quay,docker-registry,github-ghcr,jfrog-artifactory
|
||||||
|
PORT: "8080"
|
||||||
|
PORTAL_URL: http://harbor-portal
|
||||||
|
POSTGRESQL_DATABASE: registry
|
||||||
|
POSTGRESQL_HOST: harbor-database
|
||||||
|
POSTGRESQL_MAX_IDLE_CONNS: "100"
|
||||||
|
POSTGRESQL_MAX_OPEN_CONNS: "900"
|
||||||
|
POSTGRESQL_PORT: "5432"
|
||||||
|
POSTGRESQL_SSLMODE: disable
|
||||||
|
POSTGRESQL_USERNAME: postgres
|
||||||
|
QUOTA_UPDATE_PROVIDER: db
|
||||||
|
REGISTRY_CONTROLLER_URL: http://harbor-registry:8080
|
||||||
|
REGISTRY_CREDENTIAL_USERNAME: harbor_registry_user
|
||||||
|
REGISTRY_STORAGE_PROVIDER_NAME: filesystem
|
||||||
|
REGISTRY_URL: http://harbor-registry:5000
|
||||||
|
TOKEN_SERVICE_URL: http://harbor-core:80/service/token
|
||||||
|
TRIVY_ADAPTER_URL: http://harbor-trivy:8080
|
||||||
|
WITH_TRIVY: "true"
|
||||||
|
app.conf: |
|
||||||
|
appname = Harbor
|
||||||
|
runmode = prod
|
||||||
|
enablegzip = true
|
||||||
|
|
||||||
|
[prod]
|
||||||
|
httpport = 8080
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-jobservice
|
||||||
|
namespace: harbor
|
||||||
|
data:
|
||||||
|
config.yml: |
|
||||||
|
#Server listening port
|
||||||
|
protocol: "http"
|
||||||
|
port: 8080
|
||||||
|
worker_pool:
|
||||||
|
workers: 10
|
||||||
|
backend: "redis"
|
||||||
|
redis_pool:
|
||||||
|
redis_url: "redis://harbor-redis:6379/1"
|
||||||
|
namespace: "harbor_job_service_namespace"
|
||||||
|
idle_timeout_second: 3600
|
||||||
|
job_loggers:
|
||||||
|
- name: "FILE"
|
||||||
|
level: INFO
|
||||||
|
settings: # Customized settings of logger
|
||||||
|
base_dir: "/var/log/jobs"
|
||||||
|
sweeper:
|
||||||
|
duration: 14 #days
|
||||||
|
settings: # Customized settings of sweeper
|
||||||
|
work_dir: "/var/log/jobs"
|
||||||
|
metric:
|
||||||
|
enabled: false
|
||||||
|
path: /metrics
|
||||||
|
port: 8001
|
||||||
|
#Loggers for the job service
|
||||||
|
loggers:
|
||||||
|
- name: "STD_OUTPUT"
|
||||||
|
level: INFO
|
||||||
|
reaper:
|
||||||
|
# the max time to wait for a task to finish, if unfinished after max_update_hours, the task will be mark as error, but the task will continue to run, default value is 24
|
||||||
|
max_update_hours: 24
|
||||||
|
# the max time for execution in running state without new task created
|
||||||
|
max_dangling_hours: 168
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-jobservice-env
|
||||||
|
namespace: harbor
|
||||||
|
data:
|
||||||
|
CORE_URL: http://harbor-core:80
|
||||||
|
HTTP_PROXY: ""
|
||||||
|
HTTPS_PROXY: ""
|
||||||
|
JOBSERVICE_WEBHOOK_JOB_HTTP_CLIENT_TIMEOUT: "3"
|
||||||
|
JOBSERVICE_WEBHOOK_JOB_MAX_RETRY: "3"
|
||||||
|
NO_PROXY: harbor-core,harbor-jobservice,harbor-database,harbor-registry,harbor-portal,harbor-trivy,harbor-exporter,127.0.0.1,localhost,.local,.internal
|
||||||
|
REGISTRY_CONTROLLER_URL: http://harbor-registry:8080
|
||||||
|
REGISTRY_CREDENTIAL_USERNAME: harbor_registry_user
|
||||||
|
REGISTRY_URL: http://harbor-registry:5000
|
||||||
|
TOKEN_SERVICE_URL: http://harbor-core:80/service/token
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-portal
|
||||||
|
namespace: harbor
|
||||||
|
data:
|
||||||
|
nginx.conf: |
|
||||||
|
worker_processes auto;
|
||||||
|
pid /tmp/nginx.pid;
|
||||||
|
events {
|
||||||
|
worker_connections 1024;
|
||||||
|
}
|
||||||
|
http {
|
||||||
|
client_body_temp_path /tmp/client_body_temp;
|
||||||
|
proxy_temp_path /tmp/proxy_temp;
|
||||||
|
fastcgi_temp_path /tmp/fastcgi_temp;
|
||||||
|
uwsgi_temp_path /tmp/uwsgi_temp;
|
||||||
|
scgi_temp_path /tmp/scgi_temp;
|
||||||
|
server {
|
||||||
|
listen 8080;
|
||||||
|
server_name localhost;
|
||||||
|
root /usr/share/nginx/html;
|
||||||
|
index index.html index.htm;
|
||||||
|
include /etc/nginx/mime.types;
|
||||||
|
gzip on;
|
||||||
|
gzip_min_length 1000;
|
||||||
|
gzip_proxied expired no-cache no-store private auth;
|
||||||
|
gzip_types text/plain text/css application/json application/javascript application/x-javascript text/xml application/xml application/xml+rss text/javascript;
|
||||||
|
location /devcenter-api-2.0 {
|
||||||
|
try_files $uri $uri/ /swagger-ui-index.html;
|
||||||
|
}
|
||||||
|
location / {
|
||||||
|
try_files $uri $uri/ /index.html;
|
||||||
|
}
|
||||||
|
location = /index.html {
|
||||||
|
add_header Cache-Control "no-store, no-cache, must-revalidate";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registry
|
||||||
|
namespace: harbor
|
||||||
|
data:
|
||||||
|
config.yml: |
|
||||||
|
version: 0.1
|
||||||
|
log:
|
||||||
|
level: info
|
||||||
|
fields:
|
||||||
|
service: registry
|
||||||
|
storage:
|
||||||
|
filesystem:
|
||||||
|
rootdirectory: /storage
|
||||||
|
cache:
|
||||||
|
layerinfo: redis
|
||||||
|
maintenance:
|
||||||
|
uploadpurging:
|
||||||
|
enabled: true
|
||||||
|
age: 168h
|
||||||
|
interval: 24h
|
||||||
|
dryrun: false
|
||||||
|
delete:
|
||||||
|
enabled: true
|
||||||
|
redirect:
|
||||||
|
disable: false
|
||||||
|
redis:
|
||||||
|
addr: harbor-redis:6379
|
||||||
|
db: 2
|
||||||
|
readtimeout: 10s
|
||||||
|
writetimeout: 10s
|
||||||
|
dialtimeout: 10s
|
||||||
|
pool:
|
||||||
|
maxidle: 100
|
||||||
|
maxactive: 500
|
||||||
|
idletimeout: 60s
|
||||||
|
http:
|
||||||
|
addr: :5000
|
||||||
|
#relativeurls: false
|
||||||
|
relativeurls: true
|
||||||
|
# set via environment variable
|
||||||
|
# secret: placeholder
|
||||||
|
debug:
|
||||||
|
addr: localhost:5001
|
||||||
|
auth:
|
||||||
|
htpasswd:
|
||||||
|
realm: harbor-registry-basic-realm
|
||||||
|
path: /etc/registry/passwd
|
||||||
|
validation:
|
||||||
|
disabled: true
|
||||||
|
compatibility:
|
||||||
|
schema1:
|
||||||
|
enabled: true
|
||||||
|
ctl-config.yml: |
|
||||||
|
---
|
||||||
|
protocol: "http"
|
||||||
|
port: 8080
|
||||||
|
log_level: info
|
||||||
|
registry_config: "/etc/registry/config.yml"
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registryctl
|
||||||
|
namespace: harbor
|
||||||
|
|
@ -0,0 +1,804 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-core
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: http-web
|
||||||
|
port: 80
|
||||||
|
targetPort: 8080
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: core
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-database
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- port: 5432
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: database
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-jobservice
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: http-jobservice
|
||||||
|
port: 80
|
||||||
|
targetPort: 8080
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: jobservice
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-portal
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 8080
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: portal
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-redis
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- port: 6379
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: redis
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registry
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: http-registry
|
||||||
|
port: 5000
|
||||||
|
- name: http-controller
|
||||||
|
port: 8080
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: registry
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-trivy
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: http-trivy
|
||||||
|
port: 8080
|
||||||
|
protocol: TCP
|
||||||
|
selector:
|
||||||
|
app: harbor
|
||||||
|
component: trivy
|
||||||
|
release: harbor
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: core
|
||||||
|
release: harbor
|
||||||
|
name: harbor-core
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: core
|
||||||
|
release: harbor
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: core
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- env:
|
||||||
|
- name: CORE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: secret
|
||||||
|
name: harbor-core
|
||||||
|
- name: JOBSERVICE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: JOBSERVICE_SECRET
|
||||||
|
name: harbor-jobservice
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: harbor-core
|
||||||
|
- secretRef:
|
||||||
|
name: harbor-core
|
||||||
|
image: goharbor/harbor-core:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 2
|
||||||
|
httpGet:
|
||||||
|
path: /api/v2.0/ping
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
periodSeconds: 10
|
||||||
|
name: core
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 2
|
||||||
|
httpGet:
|
||||||
|
path: /api/v2.0/ping
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
periodSeconds: 10
|
||||||
|
startupProbe:
|
||||||
|
failureThreshold: 360
|
||||||
|
httpGet:
|
||||||
|
path: /api/v2.0/ping
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/core/app.conf
|
||||||
|
name: config
|
||||||
|
subPath: app.conf
|
||||||
|
- mountPath: /etc/core/key
|
||||||
|
name: secret-key
|
||||||
|
subPath: key
|
||||||
|
- mountPath: /etc/core/private_key.pem
|
||||||
|
name: token-service-private-key
|
||||||
|
subPath: tls.key
|
||||||
|
- mountPath: /etc/core/ca
|
||||||
|
name: ca-download
|
||||||
|
- mountPath: /etc/core/token
|
||||||
|
name: psc
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 10000
|
||||||
|
runAsUser: 10000
|
||||||
|
terminationGracePeriodSeconds: 120
|
||||||
|
volumes:
|
||||||
|
- configMap:
|
||||||
|
items:
|
||||||
|
- key: app.conf
|
||||||
|
path: app.conf
|
||||||
|
name: harbor-core
|
||||||
|
name: config
|
||||||
|
- name: secret-key
|
||||||
|
secret:
|
||||||
|
items:
|
||||||
|
- key: secretKey
|
||||||
|
path: key
|
||||||
|
secretName: harbor-core
|
||||||
|
- name: token-service-private-key
|
||||||
|
secret:
|
||||||
|
secretName: harbor-core
|
||||||
|
- name: ca-download
|
||||||
|
secret:
|
||||||
|
secretName: harbor-cacerts
|
||||||
|
- emptyDir: {}
|
||||||
|
name: psc
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: jobservice
|
||||||
|
release: harbor
|
||||||
|
name: harbor-jobservice
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: jobservice
|
||||||
|
release: harbor
|
||||||
|
strategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: jobservice
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- env:
|
||||||
|
- name: CORE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: secret
|
||||||
|
name: harbor-core
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: harbor-jobservice-env
|
||||||
|
- secretRef:
|
||||||
|
name: harbor-jobservice
|
||||||
|
image: goharbor/harbor-jobservice:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /api/v1/stats
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 300
|
||||||
|
periodSeconds: 10
|
||||||
|
name: jobservice
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /api/v1/stats
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/jobservice/config.yml
|
||||||
|
name: jobservice-config
|
||||||
|
subPath: config.yml
|
||||||
|
- mountPath: /var/log/jobs
|
||||||
|
name: job-logs
|
||||||
|
subPath: null
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 10000
|
||||||
|
runAsUser: 10000
|
||||||
|
terminationGracePeriodSeconds: 120
|
||||||
|
volumes:
|
||||||
|
- configMap:
|
||||||
|
name: harbor-jobservice
|
||||||
|
name: jobservice-config
|
||||||
|
- name: job-logs
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: harbor-jobservice
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: portal
|
||||||
|
release: harbor
|
||||||
|
name: harbor-portal
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: portal
|
||||||
|
release: harbor
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: portal
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- image: goharbor/harbor-portal:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 300
|
||||||
|
periodSeconds: 10
|
||||||
|
name: portal
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 1
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/nginx/nginx.conf
|
||||||
|
name: portal-config
|
||||||
|
subPath: nginx.conf
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 10000
|
||||||
|
runAsUser: 10000
|
||||||
|
volumes:
|
||||||
|
- configMap:
|
||||||
|
name: harbor-portal
|
||||||
|
name: portal-config
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: registry
|
||||||
|
release: harbor
|
||||||
|
name: harbor-registry
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: registry
|
||||||
|
release: harbor
|
||||||
|
strategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: registry
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- args:
|
||||||
|
- serve
|
||||||
|
- /etc/registry/config.yml
|
||||||
|
env: null
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: harbor-registry
|
||||||
|
image: goharbor/registry-photon:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: 5000
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 300
|
||||||
|
periodSeconds: 10
|
||||||
|
name: registry
|
||||||
|
ports:
|
||||||
|
- containerPort: 5000
|
||||||
|
- containerPort: 5001
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: 5000
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 1
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /storage
|
||||||
|
name: registry-data
|
||||||
|
subPath: null
|
||||||
|
- mountPath: /etc/registry/passwd
|
||||||
|
name: registry-htpasswd
|
||||||
|
subPath: passwd
|
||||||
|
- mountPath: /etc/registry/config.yml
|
||||||
|
name: registry-config
|
||||||
|
subPath: config.yml
|
||||||
|
- env:
|
||||||
|
- name: CORE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: secret
|
||||||
|
name: harbor-core
|
||||||
|
- name: JOBSERVICE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: JOBSERVICE_SECRET
|
||||||
|
name: harbor-jobservice
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: harbor-registryctl
|
||||||
|
- secretRef:
|
||||||
|
name: harbor-registry
|
||||||
|
- secretRef:
|
||||||
|
name: harbor-registryctl
|
||||||
|
image: goharbor/harbor-registryctl:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /api/health
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 300
|
||||||
|
periodSeconds: 10
|
||||||
|
name: registryctl
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /api/health
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 1
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /storage
|
||||||
|
name: registry-data
|
||||||
|
subPath: null
|
||||||
|
- mountPath: /etc/registry/config.yml
|
||||||
|
name: registry-config
|
||||||
|
subPath: config.yml
|
||||||
|
- mountPath: /etc/registryctl/config.yml
|
||||||
|
name: registry-config
|
||||||
|
subPath: ctl-config.yml
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 10000
|
||||||
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
|
runAsUser: 10000
|
||||||
|
terminationGracePeriodSeconds: 120
|
||||||
|
volumes:
|
||||||
|
- name: registry-htpasswd
|
||||||
|
secret:
|
||||||
|
items:
|
||||||
|
- key: REGISTRY_HTPASSWD
|
||||||
|
path: passwd
|
||||||
|
secretName: harbor-registry-htpasswd
|
||||||
|
- configMap:
|
||||||
|
name: harbor-registry
|
||||||
|
name: registry-config
|
||||||
|
- name: registry-data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: harbor-registry
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: database
|
||||||
|
release: harbor
|
||||||
|
name: harbor-database
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: database
|
||||||
|
release: harbor
|
||||||
|
serviceName: harbor-database
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: database
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- env:
|
||||||
|
- name: PGDATA
|
||||||
|
value: /var/lib/postgresql/data/pgdata
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: harbor-database
|
||||||
|
image: goharbor/harbor-db:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /docker-healthcheck.sh
|
||||||
|
initialDelaySeconds: 300
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 1
|
||||||
|
name: database
|
||||||
|
readinessProbe:
|
||||||
|
exec:
|
||||||
|
command:
|
||||||
|
- /docker-healthcheck.sh
|
||||||
|
initialDelaySeconds: 1
|
||||||
|
periodSeconds: 10
|
||||||
|
timeoutSeconds: 1
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /var/lib/postgresql/data
|
||||||
|
name: database-data
|
||||||
|
- mountPath: /dev/shm
|
||||||
|
name: shm-volume
|
||||||
|
initContainers:
|
||||||
|
- args:
|
||||||
|
- -c
|
||||||
|
- '[ -e /var/lib/postgresql/data/postgresql.conf ] && [ ! -d /var/lib/postgresql/data/pgdata
|
||||||
|
] && mkdir -m 0700 /var/lib/postgresql/data/pgdata && mv /var/lib/postgresql/data/*
|
||||||
|
/var/lib/postgresql/data/pgdata/ || true'
|
||||||
|
command:
|
||||||
|
- /bin/sh
|
||||||
|
image: goharbor/harbor-db:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
name: data-migrator
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /var/lib/postgresql/data
|
||||||
|
name: database-data
|
||||||
|
- args:
|
||||||
|
- -c
|
||||||
|
- chmod -R 700 /var/lib/postgresql/data/pgdata || true
|
||||||
|
command:
|
||||||
|
- /bin/sh
|
||||||
|
image: goharbor/harbor-db:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
name: data-permissions-ensurer
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /var/lib/postgresql/data
|
||||||
|
name: database-data
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 999
|
||||||
|
runAsUser: 999
|
||||||
|
terminationGracePeriodSeconds: 120
|
||||||
|
volumes:
|
||||||
|
- emptyDir:
|
||||||
|
medium: Memory
|
||||||
|
sizeLimit: 512Mi
|
||||||
|
name: shm-volume
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
annotations: null
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: database-data
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: redis
|
||||||
|
release: harbor
|
||||||
|
name: harbor-redis
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: redis
|
||||||
|
release: harbor
|
||||||
|
serviceName: harbor-redis
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: redis
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- image: goharbor/redis-photon:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
initialDelaySeconds: 300
|
||||||
|
periodSeconds: 10
|
||||||
|
tcpSocket:
|
||||||
|
port: 6379
|
||||||
|
name: redis
|
||||||
|
readinessProbe:
|
||||||
|
initialDelaySeconds: 1
|
||||||
|
periodSeconds: 10
|
||||||
|
tcpSocket:
|
||||||
|
port: 6379
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /var/lib/redis
|
||||||
|
name: data
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 999
|
||||||
|
runAsUser: 999
|
||||||
|
terminationGracePeriodSeconds: 120
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
annotations: null
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: data
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: trivy
|
||||||
|
release: harbor
|
||||||
|
name: harbor-trivy
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: harbor
|
||||||
|
component: trivy
|
||||||
|
release: harbor
|
||||||
|
serviceName: harbor-trivy
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
component: trivy
|
||||||
|
release: harbor
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
containers:
|
||||||
|
- env:
|
||||||
|
- name: HTTP_PROXY
|
||||||
|
value: ""
|
||||||
|
- name: HTTPS_PROXY
|
||||||
|
value: ""
|
||||||
|
- name: NO_PROXY
|
||||||
|
value: harbor-core,harbor-jobservice,harbor-database,harbor-registry,harbor-portal,harbor-trivy,harbor-exporter,127.0.0.1,localhost,.local,.internal
|
||||||
|
- name: SCANNER_LOG_LEVEL
|
||||||
|
value: info
|
||||||
|
- name: SCANNER_TRIVY_CACHE_DIR
|
||||||
|
value: /home/scanner/.cache/trivy
|
||||||
|
- name: SCANNER_TRIVY_REPORTS_DIR
|
||||||
|
value: /home/scanner/.cache/reports
|
||||||
|
- name: SCANNER_TRIVY_DEBUG_MODE
|
||||||
|
value: "false"
|
||||||
|
- name: SCANNER_TRIVY_VULN_TYPE
|
||||||
|
value: os,library
|
||||||
|
- name: SCANNER_TRIVY_TIMEOUT
|
||||||
|
value: 5m0s
|
||||||
|
- name: SCANNER_TRIVY_GITHUB_TOKEN
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: gitHubToken
|
||||||
|
name: harbor-trivy
|
||||||
|
- name: SCANNER_TRIVY_SEVERITY
|
||||||
|
value: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL
|
||||||
|
- name: SCANNER_TRIVY_IGNORE_UNFIXED
|
||||||
|
value: "false"
|
||||||
|
- name: SCANNER_TRIVY_SKIP_UPDATE
|
||||||
|
value: "false"
|
||||||
|
- name: SCANNER_TRIVY_OFFLINE_SCAN
|
||||||
|
value: "false"
|
||||||
|
- name: SCANNER_TRIVY_SECURITY_CHECKS
|
||||||
|
value: vuln
|
||||||
|
- name: SCANNER_TRIVY_INSECURE
|
||||||
|
value: "false"
|
||||||
|
- name: SCANNER_API_SERVER_ADDR
|
||||||
|
value: :8080
|
||||||
|
- name: SCANNER_REDIS_URL
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: redisURL
|
||||||
|
name: harbor-trivy
|
||||||
|
- name: SCANNER_STORE_REDIS_URL
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: redisURL
|
||||||
|
name: harbor-trivy
|
||||||
|
- name: SCANNER_JOB_QUEUE_REDIS_URL
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
key: redisURL
|
||||||
|
name: harbor-trivy
|
||||||
|
image: goharbor/trivy-adapter-photon:v2.11.2
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 10
|
||||||
|
httpGet:
|
||||||
|
path: /probe/healthy
|
||||||
|
port: api-server
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
name: trivy
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: api-server
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 3
|
||||||
|
httpGet:
|
||||||
|
path: /probe/ready
|
||||||
|
port: api-server
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 1
|
||||||
|
memory: 1Gi
|
||||||
|
requests:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 512Mi
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
privileged: false
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /home/scanner/.cache
|
||||||
|
name: data
|
||||||
|
readOnly: false
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 10000
|
||||||
|
runAsUser: 10000
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: data
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 50Gi
|
||||||
|
|
@ -0,0 +1,65 @@
|
||||||
|
apiVersion: networking.istio.io/v1beta1
|
||||||
|
kind: Gateway
|
||||||
|
metadata:
|
||||||
|
name: harbor-gateway
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
istio: ingressgateway
|
||||||
|
servers:
|
||||||
|
- port:
|
||||||
|
number: 80
|
||||||
|
name: http
|
||||||
|
protocol: HTTP
|
||||||
|
hosts:
|
||||||
|
- registry.gpulive.nhncloud.com
|
||||||
|
- port:
|
||||||
|
number: 443
|
||||||
|
name: https
|
||||||
|
protocol: HTTPS
|
||||||
|
tls:
|
||||||
|
mode: SIMPLE
|
||||||
|
credentialName: gpulive-ssl # 반드시 istio-system namespace에 존재해야 함
|
||||||
|
hosts:
|
||||||
|
- registry.gpulive.nhncloud.com
|
||||||
|
---
|
||||||
|
apiVersion: networking.istio.io/v1beta1
|
||||||
|
kind: VirtualService
|
||||||
|
metadata:
|
||||||
|
name: harbor-virtualservice
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
hosts:
|
||||||
|
- registry.gpulive.nhncloud.com
|
||||||
|
gateways:
|
||||||
|
- harbor-gateway
|
||||||
|
http:
|
||||||
|
- match:
|
||||||
|
- uri:
|
||||||
|
exact: /v2/
|
||||||
|
- uri:
|
||||||
|
prefix: /v2/
|
||||||
|
- uri:
|
||||||
|
prefix: /api/
|
||||||
|
- uri:
|
||||||
|
prefix: /service/
|
||||||
|
- uri:
|
||||||
|
prefix: /chartrepo/
|
||||||
|
- uri:
|
||||||
|
prefix: /c/
|
||||||
|
route:
|
||||||
|
- destination:
|
||||||
|
host: harbor-core.harbor.svc.cluster.local
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
- match:
|
||||||
|
- uri:
|
||||||
|
exact: /
|
||||||
|
- uri:
|
||||||
|
prefix: /
|
||||||
|
route:
|
||||||
|
- destination:
|
||||||
|
host: harbor-portal.harbor.svc.cluster.local
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
|
||||||
|
|
@ -0,0 +1,64 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
ingress.kubernetes.io/proxy-body-size: "0"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-body-size: "0"
|
||||||
|
#nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
labels:
|
||||||
|
app: harbor
|
||||||
|
release: harbor
|
||||||
|
name: harbor-ingress
|
||||||
|
namespace: harbor
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- "registry.gpulive.nhncloud.com"
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
rules:
|
||||||
|
- host: registry.gpulive.nhncloud.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: harbor-core
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /api/
|
||||||
|
pathType: Prefix
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: harbor-core
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /service/
|
||||||
|
pathType: Prefix
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: harbor-core
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /v2/
|
||||||
|
pathType: Prefix
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: harbor-core
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /chartrepo/
|
||||||
|
pathType: Prefix
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: harbor-core
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /c/
|
||||||
|
pathType: Prefix
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: harbor-portal
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
|
@ -2,9 +2,8 @@ kind: PersistentVolumeClaim
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
metadata:
|
metadata:
|
||||||
name: test-claim
|
name: test-claim
|
||||||
namespace: istio-system
|
|
||||||
spec:
|
spec:
|
||||||
storageClassName: user-nas
|
storageClassName: nfs-client
|
||||||
accessModes:
|
accessModes:
|
||||||
- ReadWriteMany
|
- ReadWriteMany
|
||||||
resources:
|
resources:
|
||||||
|
|
|
||||||
|
|
@ -2,7 +2,7 @@ apiVersion: v1
|
||||||
kind: Pod
|
kind: Pod
|
||||||
metadata:
|
metadata:
|
||||||
name: nhnent01-pod01
|
name: nhnent01-pod01
|
||||||
namespace: istio-system
|
namespace: default
|
||||||
labels:
|
labels:
|
||||||
app: nginx
|
app: nginx
|
||||||
spec:
|
spec:
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,16 @@
|
||||||
|
# Prometheus에 종속적으로 설치
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- prometheus
|
||||||
|
|
||||||
|
generatorOptions:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
secretGenerator:
|
||||||
|
- name: basic-auth
|
||||||
|
files:
|
||||||
|
- auth
|
||||||
|
type: Opaque
|
||||||
|
|
@ -0,0 +1,34 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/prometheus
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
kind: ConfigMap
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-cm-prometheus-server.yaml
|
||||||
|
- target:
|
||||||
|
kind: Deployment
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-deploy.yaml
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: prometheus-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-ingress_prometheus.yaml
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: prometheus-alertmanager-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-ingress_alertmanager.yaml
|
||||||
|
# - target:
|
||||||
|
# kind: Secret
|
||||||
|
# name: basic-auth
|
||||||
|
# namespace: monitoring
|
||||||
|
# path: patch-basic-auth.yaml
|
||||||
|
|
@ -0,0 +1,335 @@
|
||||||
|
# - "/etc/config/rules/*.yaml" # 수정대상
|
||||||
|
# - "/etc/config/alerts/*.yaml" # 수정대상
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
data:
|
||||||
|
prometheus.yml: |
|
||||||
|
global:
|
||||||
|
evaluation_interval: 1m
|
||||||
|
scrape_interval: 1m
|
||||||
|
scrape_timeout: 10s
|
||||||
|
rule_files:
|
||||||
|
- /etc/config/recording_rules.yml
|
||||||
|
- /etc/config/alerting_rules.yml
|
||||||
|
- "/etc/config/rules/*.yaml"
|
||||||
|
- "/etc/config/alerts/*.yaml"
|
||||||
|
scrape_configs:
|
||||||
|
- job_name: prometheus
|
||||||
|
static_configs:
|
||||||
|
- targets:
|
||||||
|
- localhost:9090
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-apiservers
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: default;kubernetes;https
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
- __meta_kubernetes_endpoint_port_name
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-nodes
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: node
|
||||||
|
relabel_configs:
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_node_label_(.+)
|
||||||
|
- replacement: kubernetes.default.svc:443
|
||||||
|
target_label: __address__
|
||||||
|
- regex: (.+)
|
||||||
|
replacement: /api/v1/nodes/$1/proxy/metrics
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_node_name
|
||||||
|
target_label: __metrics_path__
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-nodes-cadvisor
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: node
|
||||||
|
relabel_configs:
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_node_label_(.+)
|
||||||
|
- replacement: kubernetes.default.svc:443
|
||||||
|
target_label: __address__
|
||||||
|
- regex: (.+)
|
||||||
|
replacement: /api/v1/nodes/$1/proxy/metrics/cadvisor
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_node_name
|
||||||
|
target_label: __metrics_path__
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-service-endpoints
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape
|
||||||
|
- action: drop
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+?)(?::\d+)?;(\d+)
|
||||||
|
replacement: $1:$2
|
||||||
|
source_labels:
|
||||||
|
- __address__
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_port
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-service-endpoints-slow
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+?)(?::\d+)?;(\d+)
|
||||||
|
replacement: $1:$2
|
||||||
|
source_labels:
|
||||||
|
- __address__
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_port
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
scrape_interval: 5m
|
||||||
|
scrape_timeout: 30s
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: prometheus-pushgateway
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: service
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: pushgateway
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_probe
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-services
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: service
|
||||||
|
metrics_path: /probe
|
||||||
|
params:
|
||||||
|
module:
|
||||||
|
- http_2xx
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_probe
|
||||||
|
- source_labels:
|
||||||
|
- __address__
|
||||||
|
target_label: __param_target
|
||||||
|
- replacement: blackbox
|
||||||
|
target_label: __address__
|
||||||
|
- source_labels:
|
||||||
|
- __param_target
|
||||||
|
target_label: instance
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-pods
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape
|
||||||
|
- action: drop
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})
|
||||||
|
replacement: '[$2]:$1'
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);((([0-9]+?)(\.|$)){4})
|
||||||
|
replacement: $2:$1
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_name
|
||||||
|
target_label: pod
|
||||||
|
- action: drop
|
||||||
|
regex: Pending|Succeeded|Failed|Completed
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_phase
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-pods-slow
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})
|
||||||
|
replacement: '[$2]:$1'
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);((([0-9]+?)(\.|$)){4})
|
||||||
|
replacement: $2:$1
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_name
|
||||||
|
target_label: pod
|
||||||
|
- action: drop
|
||||||
|
regex: Pending|Succeeded|Failed|Completed
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_phase
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
scrape_interval: 5m
|
||||||
|
scrape_timeout: 30s
|
||||||
|
alerting:
|
||||||
|
alertmanagers:
|
||||||
|
- kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
relabel_configs:
|
||||||
|
- source_labels: [__meta_kubernetes_namespace]
|
||||||
|
regex: monitoring
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_label_app_kubernetes_io_instance]
|
||||||
|
regex: prometheus
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_label_app_kubernetes_io_name]
|
||||||
|
regex: alertmanager
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_container_port_number]
|
||||||
|
regex: "9093"
|
||||||
|
action: keep
|
||||||
|
|
@ -0,0 +1,19 @@
|
||||||
|
# Source: prometheus/templates/deploy.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: prometheus-server
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/config/alerts
|
||||||
|
name: config-volume2
|
||||||
|
volumes:
|
||||||
|
- configMap:
|
||||||
|
defaultMode: 420
|
||||||
|
name: prometheus-rulefiles
|
||||||
|
name: config-volume2
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
annotations:
|
||||||
|
# 인증 방법 설정: basic auth
|
||||||
|
nginx.ingress.kubernetes.io/auth-type: basic
|
||||||
|
# basic auth 사용자가 들어있는 secret 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-secret: basic-auth
|
||||||
|
# 인증 요청시 나오는 메세지 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-realm: 'Authentication Required - admin'
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: alert.nhngpuaas.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
port:
|
||||||
|
number: 9093
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- alert.nhngpuaas.com
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
|
@ -0,0 +1,22 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: prometheus-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: prometheus.nhngpuaas.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: prometheus-server
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- prometheus.nhngpuaas.com
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
|
@ -0,0 +1,248 @@
|
||||||
|
# Source: prometheus/charts/kube-state-metrics/templates/role.yaml
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: kube-state-metrics-5.28.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: kube-state-metrics
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "2.14.0"
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
rules:
|
||||||
|
|
||||||
|
- apiGroups: ["certificates.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- certificatesigningrequests
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["batch"]
|
||||||
|
resources:
|
||||||
|
- cronjobs
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["extensions", "apps"]
|
||||||
|
resources:
|
||||||
|
- daemonsets
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["extensions", "apps"]
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- endpoints
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["autoscaling"]
|
||||||
|
resources:
|
||||||
|
- horizontalpodautoscalers
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["extensions", "networking.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- ingresses
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["batch"]
|
||||||
|
resources:
|
||||||
|
- jobs
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["coordination.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- limitranges
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["admissionregistration.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- mutatingwebhookconfigurations
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- namespaces
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["networking.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- networkpolicies
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- nodes
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- persistentvolumeclaims
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- persistentvolumes
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["policy"]
|
||||||
|
resources:
|
||||||
|
- poddisruptionbudgets
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["extensions", "apps"]
|
||||||
|
resources:
|
||||||
|
- replicasets
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- replicationcontrollers
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- resourcequotas
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- secrets
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources:
|
||||||
|
- services
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["apps"]
|
||||||
|
resources:
|
||||||
|
- statefulsets
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["storage.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- storageclasses
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["admissionregistration.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- validatingwebhookconfigurations
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
|
||||||
|
- apiGroups: ["storage.k8s.io"]
|
||||||
|
resources:
|
||||||
|
- volumeattachments
|
||||||
|
verbs: ["list", "watch"]
|
||||||
|
---
|
||||||
|
# Source: prometheus/templates/clusterrole.yaml
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- nodes
|
||||||
|
- nodes/proxy
|
||||||
|
- nodes/metrics
|
||||||
|
- services
|
||||||
|
- endpoints
|
||||||
|
- pods
|
||||||
|
- ingresses
|
||||||
|
- configmaps
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- "extensions"
|
||||||
|
- "networking.k8s.io"
|
||||||
|
resources:
|
||||||
|
- ingresses/status
|
||||||
|
- ingresses
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- "discovery.k8s.io"
|
||||||
|
resources:
|
||||||
|
- endpointslices
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- nonResourceURLs:
|
||||||
|
- "/metrics"
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/kube-state-metrics/templates/clusterrolebinding.yaml
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: kube-state-metrics-5.28.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: kube-state-metrics
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "2.14.0"
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
namespace: monitoring
|
||||||
|
---
|
||||||
|
# Source: prometheus/templates/clusterrolebinding.yaml
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: prometheus-server
|
||||||
|
|
@ -0,0 +1,375 @@
|
||||||
|
# Source: prometheus/charts/alertmanager/templates/configmap.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: alertmanager-1.14.0
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v0.28.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
namespace: monitoring
|
||||||
|
data:
|
||||||
|
alertmanager.yml: |
|
||||||
|
global: {}
|
||||||
|
receivers:
|
||||||
|
- name: default-receiver
|
||||||
|
route:
|
||||||
|
group_interval: 5m
|
||||||
|
group_wait: 10s
|
||||||
|
receiver: default-receiver
|
||||||
|
repeat_interval: 3h
|
||||||
|
templates:
|
||||||
|
- /etc/alertmanager/*.tmpl
|
||||||
|
---
|
||||||
|
# Source: prometheus/templates/cm.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
data:
|
||||||
|
allow-snippet-annotations: "false"
|
||||||
|
alerting_rules.yml: |
|
||||||
|
{}
|
||||||
|
alerts: |
|
||||||
|
{}
|
||||||
|
prometheus.yml: |
|
||||||
|
global:
|
||||||
|
evaluation_interval: 1m
|
||||||
|
scrape_interval: 1m
|
||||||
|
scrape_timeout: 10s
|
||||||
|
rule_files:
|
||||||
|
- /etc/config/recording_rules.yml
|
||||||
|
- /etc/config/alerting_rules.yml
|
||||||
|
- /etc/config/rules
|
||||||
|
- /etc/config/alerts
|
||||||
|
scrape_configs:
|
||||||
|
- job_name: prometheus
|
||||||
|
static_configs:
|
||||||
|
- targets:
|
||||||
|
- localhost:9090
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-apiservers
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: default;kubernetes;https
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
- __meta_kubernetes_endpoint_port_name
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-nodes
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: node
|
||||||
|
relabel_configs:
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_node_label_(.+)
|
||||||
|
- replacement: kubernetes.default.svc:443
|
||||||
|
target_label: __address__
|
||||||
|
- regex: (.+)
|
||||||
|
replacement: /api/v1/nodes/$1/proxy/metrics
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_node_name
|
||||||
|
target_label: __metrics_path__
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-nodes-cadvisor
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: node
|
||||||
|
relabel_configs:
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_node_label_(.+)
|
||||||
|
- replacement: kubernetes.default.svc:443
|
||||||
|
target_label: __address__
|
||||||
|
- regex: (.+)
|
||||||
|
replacement: /api/v1/nodes/$1/proxy/metrics/cadvisor
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_node_name
|
||||||
|
target_label: __metrics_path__
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-service-endpoints
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape
|
||||||
|
- action: drop
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+?)(?::\d+)?;(\d+)
|
||||||
|
replacement: $1:$2
|
||||||
|
source_labels:
|
||||||
|
- __address__
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_port
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-service-endpoints-slow
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+?)(?::\d+)?;(\d+)
|
||||||
|
replacement: $1:$2
|
||||||
|
source_labels:
|
||||||
|
- __address__
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_port
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
scrape_interval: 5m
|
||||||
|
scrape_timeout: 30s
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: prometheus-pushgateway
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: service
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: pushgateway
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_probe
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-services
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: service
|
||||||
|
metrics_path: /probe
|
||||||
|
params:
|
||||||
|
module:
|
||||||
|
- http_2xx
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_probe
|
||||||
|
- source_labels:
|
||||||
|
- __address__
|
||||||
|
target_label: __param_target
|
||||||
|
- replacement: blackbox
|
||||||
|
target_label: __address__
|
||||||
|
- source_labels:
|
||||||
|
- __param_target
|
||||||
|
target_label: instance
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-pods
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape
|
||||||
|
- action: drop
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})
|
||||||
|
replacement: '[$2]:$1'
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);((([0-9]+?)(\.|$)){4})
|
||||||
|
replacement: $2:$1
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_name
|
||||||
|
target_label: pod
|
||||||
|
- action: drop
|
||||||
|
regex: Pending|Succeeded|Failed|Completed
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_phase
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-pods-slow
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})
|
||||||
|
replacement: '[$2]:$1'
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);((([0-9]+?)(\.|$)){4})
|
||||||
|
replacement: $2:$1
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_name
|
||||||
|
target_label: pod
|
||||||
|
- action: drop
|
||||||
|
regex: Pending|Succeeded|Failed|Completed
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_phase
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
scrape_interval: 5m
|
||||||
|
scrape_timeout: 30s
|
||||||
|
alerting:
|
||||||
|
alertmanagers:
|
||||||
|
- kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
relabel_configs:
|
||||||
|
- source_labels: [__meta_kubernetes_namespace]
|
||||||
|
regex: monitoring
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_label_app_kubernetes_io_instance]
|
||||||
|
regex: prometheus
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_label_app_kubernetes_io_name]
|
||||||
|
regex: alertmanager
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_container_port_number]
|
||||||
|
regex: "9093"
|
||||||
|
action: keep
|
||||||
|
recording_rules.yml: |
|
||||||
|
{}
|
||||||
|
rules: |
|
||||||
|
{}
|
||||||
|
|
@ -0,0 +1,194 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: prometheus-rulefiles
|
||||||
|
namespace: monitoring
|
||||||
|
data:
|
||||||
|
# Awesome Prometheus alerts
|
||||||
|
################################################################################
|
||||||
|
# Basic resource monitoring prometheus self-monitoring
|
||||||
|
################################################################################
|
||||||
|
prometheus-self-monitoring.yaml: |
|
||||||
|
groups:
|
||||||
|
- name: prometheus-self-monitoring
|
||||||
|
rules:
|
||||||
|
- alert: Watchdog
|
||||||
|
annotations:
|
||||||
|
description: |
|
||||||
|
This is an alert meant to ensure that the entire alerting pipeline is functional.
|
||||||
|
This alert is always firing, therefore it should always be firing in Alertmanager
|
||||||
|
and always fire against a receiver. There are integrations with various notification
|
||||||
|
mechanisms that send a notification when this alert is not firing. For example the
|
||||||
|
"DeadMansSnitch" integration in PagerDuty.
|
||||||
|
runbook_url: https://runbooks.prometheus-operator.dev/runbooks/general/watchdog
|
||||||
|
summary: An alert that should always be firing to certify that Alertmanager
|
||||||
|
is working properly.
|
||||||
|
expr: vector(1)
|
||||||
|
labels:
|
||||||
|
severity: none
|
||||||
|
# Awesome Prometheus alerts
|
||||||
|
################################################################################
|
||||||
|
# Basic resource monitoring host and hardware (node-export)
|
||||||
|
################################################################################
|
||||||
|
prometheus-host-hardware.yaml: |
|
||||||
|
groups:
|
||||||
|
- name: prometheus-host-hardware
|
||||||
|
rules:
|
||||||
|
- alert: HostOutOfMemory (1.2.01)
|
||||||
|
expr: node_memory_MemAvailable_bytes / node_memory_MemTotal_bytes * 100 < 10
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Host out of memory (instance {{ $labels.instance }})
|
||||||
|
description: "Node memory is filling up (< 10% left)\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: HostOutOfDiskSpace (1.2.07)
|
||||||
|
expr: (node_filesystem_avail_bytes * 100) / node_filesystem_size_bytes < 10 and ON (instance, device, mountpoint) node_filesystem_readonly == 0
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Host out of disk space (instance {{ $labels.instance }})
|
||||||
|
description: "Disk is almost full (< 10% left)\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
# Please add ignored mountpoints in node_exporter parameters like
|
||||||
|
# "--collector.filesystem.ignored-mount-points=^/(sys|proc|dev|run)($|/)".
|
||||||
|
# Same rule using "node_filesystem_free_bytes" will fire when disk fills for non-root users.
|
||||||
|
- alert: HostHighCpuLoad (1.2.13)
|
||||||
|
expr: 100 - (avg by(instance) (rate(node_cpu_seconds_total{mode="idle"}[2m])) * 100) > 80
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Host high CPU load (instance {{ $labels.instance }})
|
||||||
|
description: "CPU load is > 80%\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: HostOomKillDetected (1.2.24)
|
||||||
|
expr: increase(node_vmstat_oom_kill[1m]) > 0
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Host OOM kill detected (instance {{ $labels.instance }})
|
||||||
|
description: "OOM kill detected\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
# Awesome Prometheus alerts
|
||||||
|
################################################################################
|
||||||
|
# Basic resource monitoring docker container (google/cAdvisor)
|
||||||
|
################################################################################
|
||||||
|
Prometheus-docker-containers.yaml: |
|
||||||
|
groups:
|
||||||
|
- name: prometheus-docker-containers
|
||||||
|
rules:
|
||||||
|
# This rule can be very noisy in dynamic infra with legitimate container start/stop/deployment.
|
||||||
|
- alert: ContainerKilled (1.3.1)
|
||||||
|
expr: time() - container_last_seen > 60
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Container killed (instance {{ $labels.instance }})
|
||||||
|
description: "A container has disappeared\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
# This rule can be very noisy in dynamic infra with legitimate container start/stop/deployment.
|
||||||
|
- alert: ContainerCpuUsage (1.3.3)
|
||||||
|
expr: (sum(rate(container_cpu_usage_seconds_total{name!=""}[3m])) BY (instance, name) * 100) > 80
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Container CPU usage (instance {{ $labels.instance }})
|
||||||
|
description: "Container CPU usage is above 80%\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
# See https://medium.com/faun/how-much-is-too-much-the-linux-oomkiller-and-used-memory-d32186f29c9d
|
||||||
|
- alert: ContainerMemoryUsage (1.3.4)
|
||||||
|
expr: (sum(container_memory_working_set_bytes{name!=""}) BY (instance, name) / sum(container_spec_memory_limit_bytes > 0) BY (instance, name) * 100) > 80
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Container Memory usage (instance {{ $labels.instance }})
|
||||||
|
description: "Container Memory usage is above 80%\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
# Awesome Prometheus alerts
|
||||||
|
################################################################################
|
||||||
|
# Orchestrators kubernetes (kube-state-metrics)
|
||||||
|
################################################################################
|
||||||
|
prometheus-kubernetes.yaml: |
|
||||||
|
groups:
|
||||||
|
- name: prometheus-kubernetes
|
||||||
|
rules:
|
||||||
|
- alert: KubernetesNodeReady (5.1.01)
|
||||||
|
expr: kube_node_status_condition{condition="Ready",status="true"} == 0
|
||||||
|
for: 10m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes Node ready (instance {{ $labels.instance }})
|
||||||
|
description: "Node {{ $labels.node }} has been unready for a long time\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesOutOfDisk (5.1.04)
|
||||||
|
expr: kube_node_status_condition{condition="OutOfDisk",status="true"} == 1
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes out of disk (instance {{ $labels.instance }})
|
||||||
|
description: "{{ $labels.node }} has OutOfDisk condition\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesContainerOomKiller (5.1.06)
|
||||||
|
expr: (kube_pod_container_status_restarts_total - kube_pod_container_status_restarts_total offset 10m >= 1) and ignoring (reason) min_over_time(kube_pod_container_status_last_terminated_reason{reason="OOMKilled"}[10m]) == 1
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes container oom killer (instance {{ $labels.instance }})
|
||||||
|
description: "Container {{ $labels.container }} in pod {{ $labels.namespace }}/{{ $labels.pod }} has been OOMKilled {{ $value }} times in the last 10 minutes.\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesVolumeOutOfDiskSpace (5.1.10)
|
||||||
|
expr: kubelet_volume_stats_available_bytes / kubelet_volume_stats_capacity_bytes * 100 < 10
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes Volume out of disk space (instance {{ $labels.instance }})
|
||||||
|
description: "Volume is almost full (< 10% left)\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesPersistentvolumeError (5.1.12)
|
||||||
|
expr: kube_persistentvolume_status_phase{phase=~"Failed|Pending", job="kube-state-metrics"} > 0
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes PersistentVolume error (instance {{ $labels.instance }})
|
||||||
|
description: "Persistent volume is in bad state\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesHpaScaleCapability (5.1.16)
|
||||||
|
expr: kube_horizontalpodautoscaler_status_desired_replicas >= kube_horizontalpodautoscaler_spec_max_replicas
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: info
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes HPA scale capability (instance {{ $labels.instance }})
|
||||||
|
description: "The maximum number of desired Pods has been hit\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesPodNotHealthy (5.1.17)
|
||||||
|
expr: min_over_time(sum by (namespace, pod) (kube_pod_status_phase{phase=~"Pending|Unknown|Failed"})[15m:1m]) > 0
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes Pod not healthy (instance {{ $labels.instance }})
|
||||||
|
description: "Pod has been in a non-ready state for longer than 15 minutes.\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesPodCrashLooping (5.1.18)
|
||||||
|
expr: increase(kube_pod_container_status_restarts_total[1m]) > 3
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: warning
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes pod crash looping (instance {{ $labels.instance }})
|
||||||
|
description: "Pod {{ $labels.pod }} is crash looping\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesApiServerErrors (5.1.29)
|
||||||
|
expr: sum(rate(apiserver_request_total{job="apiserver",code=~"^(?:5..)$"}[1m])) / sum(rate(apiserver_request_total{job="apiserver"}[1m])) * 100 > 3
|
||||||
|
for: 2m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes API server errors (instance {{ $labels.instance }})
|
||||||
|
description: "Kubernetes API server is experiencing high error rate\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
- alert: KubernetesClientCertificateExpiresSoon (5.1.32)
|
||||||
|
expr: apiserver_client_certificate_expiration_seconds_count{job="apiserver"} > 0 and histogram_quantile(0.01, sum by (job, le) (rate(apiserver_client_certificate_expiration_seconds_bucket{job="apiserver"}[5m]))) < 24*60*60
|
||||||
|
for: 0m
|
||||||
|
labels:
|
||||||
|
severity: critical
|
||||||
|
annotations:
|
||||||
|
summary: Kubernetes client certificate expires soon (instance {{ $labels.instance }})
|
||||||
|
description: "A client certificate used to authenticate to the apiserver is expiring in less than 24.0 hours.\n VALUE = {{ $value }}\n LABELS = {{ $labels }}"
|
||||||
|
|
@ -0,0 +1,135 @@
|
||||||
|
# Source: prometheus/charts/prometheus-node-exporter/templates/daemonset.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
name: prometheus-prometheus-node-exporter
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-node-exporter-4.43.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/name: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "1.8.2"
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
updateStrategy:
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 1
|
||||||
|
type: RollingUpdate
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
cluster-autoscaler.kubernetes.io/safe-to-evict: "true"
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-node-exporter-4.43.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/name: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "1.8.2"
|
||||||
|
spec:
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 65534
|
||||||
|
runAsGroup: 65534
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65534
|
||||||
|
serviceAccountName: prometheus-prometheus-node-exporter
|
||||||
|
containers:
|
||||||
|
- name: node-exporter
|
||||||
|
image: quay.io/prometheus/node-exporter:v1.8.2
|
||||||
|
imagePullPolicy: Always
|
||||||
|
args:
|
||||||
|
- --path.procfs=/host/proc
|
||||||
|
- --path.sysfs=/host/sys
|
||||||
|
- --path.rootfs=/host/root
|
||||||
|
- --path.udev.data=/host/root/run/udev/data
|
||||||
|
- --web.listen-address=[$(HOST_IP)]:9100
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
env:
|
||||||
|
- name: HOST_IP
|
||||||
|
value: 0.0.0.0
|
||||||
|
ports:
|
||||||
|
- name: metrics
|
||||||
|
containerPort: 9100
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 3
|
||||||
|
httpGet:
|
||||||
|
httpHeaders:
|
||||||
|
path: /
|
||||||
|
port: 9100
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 0
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 1
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 3
|
||||||
|
httpGet:
|
||||||
|
httpHeaders:
|
||||||
|
path: /
|
||||||
|
port: 9100
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 0
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 1
|
||||||
|
volumeMounts:
|
||||||
|
- name: proc
|
||||||
|
mountPath: /host/proc
|
||||||
|
readOnly: true
|
||||||
|
- name: sys
|
||||||
|
mountPath: /host/sys
|
||||||
|
readOnly: true
|
||||||
|
- name: root
|
||||||
|
mountPath: /host/root
|
||||||
|
mountPropagation: HostToContainer
|
||||||
|
readOnly: true
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 50Mi
|
||||||
|
limits:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 100Mi
|
||||||
|
hostNetwork: true
|
||||||
|
hostPID: true
|
||||||
|
hostIPC: false
|
||||||
|
affinity:
|
||||||
|
nodeAffinity:
|
||||||
|
requiredDuringSchedulingIgnoredDuringExecution:
|
||||||
|
nodeSelectorTerms:
|
||||||
|
- matchExpressions:
|
||||||
|
- key: eks.amazonaws.com/compute-type
|
||||||
|
operator: NotIn
|
||||||
|
values:
|
||||||
|
- fargate
|
||||||
|
- key: type
|
||||||
|
operator: NotIn
|
||||||
|
values:
|
||||||
|
- virtual-kubelet
|
||||||
|
nodeSelector:
|
||||||
|
kubernetes.io/os: linux
|
||||||
|
tolerations:
|
||||||
|
- effect: NoSchedule
|
||||||
|
operator: Exists
|
||||||
|
volumes:
|
||||||
|
- name: proc
|
||||||
|
hostPath:
|
||||||
|
path: /proc
|
||||||
|
- name: sys
|
||||||
|
hostPath:
|
||||||
|
path: /sys
|
||||||
|
- name: root
|
||||||
|
hostPath:
|
||||||
|
path: /
|
||||||
|
|
@ -0,0 +1,290 @@
|
||||||
|
# Source: prometheus/charts/kube-state-metrics/templates/deployment.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: kube-state-metrics-5.28.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: kube-state-metrics
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "2.14.0"
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
replicas: 1
|
||||||
|
strategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: kube-state-metrics-5.28.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: kube-state-metrics
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "2.14.0"
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
hostNetwork: false
|
||||||
|
serviceAccountName: prometheus-kube-state-metrics
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 65534
|
||||||
|
runAsGroup: 65534
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65534
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
containers:
|
||||||
|
- name: kube-state-metrics
|
||||||
|
args:
|
||||||
|
- --port=8080
|
||||||
|
- --resources=certificatesigningrequests,configmaps,cronjobs,daemonsets,deployments,endpoints,horizontalpodautoscalers,ingresses,jobs,leases,limitranges,mutatingwebhookconfigurations,namespaces,networkpolicies,nodes,persistentvolumeclaims,persistentvolumes,poddisruptionbudgets,pods,replicasets,replicationcontrollers,resourcequotas,secrets,services,statefulsets,storageclasses,validatingwebhookconfigurations,volumeattachments
|
||||||
|
imagePullPolicy: Always
|
||||||
|
image: registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.0
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: "http"
|
||||||
|
livenessProbe:
|
||||||
|
failureThreshold: 3
|
||||||
|
httpGet:
|
||||||
|
httpHeaders:
|
||||||
|
path: /livez
|
||||||
|
port: 8080
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 5
|
||||||
|
readinessProbe:
|
||||||
|
failureThreshold: 3
|
||||||
|
httpGet:
|
||||||
|
httpHeaders:
|
||||||
|
path: /readyz
|
||||||
|
port: 8081
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
successThreshold: 1
|
||||||
|
timeoutSeconds: 5
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 125Mi
|
||||||
|
limits:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 250Mi
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/prometheus-pushgateway/templates/deployment.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-pushgateway-2.17.0
|
||||||
|
app.kubernetes.io/name: prometheus-pushgateway
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v1.11.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
name: prometheus-prometheus-pushgateway
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
strategy:
|
||||||
|
type: Recreate
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: prometheus-pushgateway
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-pushgateway-2.17.0
|
||||||
|
app.kubernetes.io/name: prometheus-pushgateway
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v1.11.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
serviceAccountName: prometheus-prometheus-pushgateway
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
containers:
|
||||||
|
- name: pushgateway
|
||||||
|
image: "quay.io/prometheus/pushgateway:v1.11.0"
|
||||||
|
imagePullPolicy: Always
|
||||||
|
ports:
|
||||||
|
- name: metrics
|
||||||
|
containerPort: 9091
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /-/healthy
|
||||||
|
port: 9091
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
timeoutSeconds: 10
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /-/ready
|
||||||
|
port: 9091
|
||||||
|
initialDelaySeconds: 10
|
||||||
|
timeoutSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- name: storage-volume
|
||||||
|
mountPath: "/data"
|
||||||
|
subPath: ""
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 256Mi
|
||||||
|
limits:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 512Mi
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 65534
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65534
|
||||||
|
volumes:
|
||||||
|
- name: storage-volume
|
||||||
|
emptyDir: {}
|
||||||
|
---
|
||||||
|
# Source: prometheus/templates/deploy.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
replicas: 1
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
strategy:
|
||||||
|
type: Recreate
|
||||||
|
rollingUpdate: null
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
enableServiceLinks: true
|
||||||
|
serviceAccountName: prometheus-server
|
||||||
|
containers:
|
||||||
|
- name: prometheus-server-configmap-reload
|
||||||
|
image: "quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2"
|
||||||
|
imagePullPolicy: "Always"
|
||||||
|
args:
|
||||||
|
- --watched-dir=/etc/config
|
||||||
|
- --listen-address=0.0.0.0:8080
|
||||||
|
- --reload-url=http://127.0.0.1:9090/-/reload
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: metrics
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: metrics
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 2
|
||||||
|
periodSeconds: 10
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: metrics
|
||||||
|
scheme: HTTP
|
||||||
|
periodSeconds: 10
|
||||||
|
volumeMounts:
|
||||||
|
- name: config-volume
|
||||||
|
mountPath: /etc/config
|
||||||
|
readOnly: true
|
||||||
|
|
||||||
|
- name: prometheus-server
|
||||||
|
image: "quay.io/prometheus/prometheus:v3.1.0"
|
||||||
|
imagePullPolicy: "Always"
|
||||||
|
args:
|
||||||
|
- --storage.tsdb.retention.time=15d
|
||||||
|
- --config.file=/etc/config/prometheus.yml
|
||||||
|
- --storage.tsdb.path=/data
|
||||||
|
- --web.console.libraries=/etc/prometheus/console_libraries
|
||||||
|
- --web.console.templates=/etc/prometheus/consoles
|
||||||
|
- --web.enable-lifecycle
|
||||||
|
ports:
|
||||||
|
- containerPort: 9090
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /-/ready
|
||||||
|
port: 9090
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
periodSeconds: 5
|
||||||
|
timeoutSeconds: 4
|
||||||
|
failureThreshold: 3
|
||||||
|
successThreshold: 1
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /-/healthy
|
||||||
|
port: 9090
|
||||||
|
scheme: HTTP
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 10
|
||||||
|
failureThreshold: 3
|
||||||
|
successThreshold: 1
|
||||||
|
volumeMounts:
|
||||||
|
- name: config-volume
|
||||||
|
mountPath: /etc/config
|
||||||
|
- name: storage-volume
|
||||||
|
mountPath: /data
|
||||||
|
subPath: ""
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 2Gi
|
||||||
|
limits:
|
||||||
|
cpu: 1050m
|
||||||
|
memory: 4Gi
|
||||||
|
dnsPolicy: ClusterFirst
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 65534
|
||||||
|
runAsGroup: 65534
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65534
|
||||||
|
terminationGracePeriodSeconds: 300
|
||||||
|
volumes:
|
||||||
|
- name: config-volume
|
||||||
|
configMap:
|
||||||
|
name: prometheus-server
|
||||||
|
- name: storage-volume
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: prometheus-server
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
annotations:
|
||||||
|
# 인증 방법 설정: basic auth
|
||||||
|
nginx.ingress.kubernetes.io/auth-type: basic
|
||||||
|
# basic auth 사용자가 들어있는 secret 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-secret: basic-auth
|
||||||
|
# 인증 요청시 나오는 메세지 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-realm: 'Authentication Required - admin'
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: alert.cone-chain.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
port:
|
||||||
|
number: 9093
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- prometheus.cone-chain.com
|
||||||
|
secretName: ssl-cc
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: prometheus-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
annotations:
|
||||||
|
# 인증 방법 설정: basic auth
|
||||||
|
nginx.ingress.kubernetes.io/auth-type: basic
|
||||||
|
# basic auth 사용자가 들어있는 secret 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-secret: basic-auth
|
||||||
|
# 인증 요청시 나오는 메세지 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-realm: 'Authentication Required - admin'
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: prometheus.cone-chain.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: prometheus-server
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- prometheus.cone-chain.com
|
||||||
|
secretName: ssl-cc
|
||||||
|
|
@ -0,0 +1,19 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- sa.yaml
|
||||||
|
- cluster_role.yaml
|
||||||
|
- cm.yaml
|
||||||
|
- deploy.yaml
|
||||||
|
- daemonset.yaml
|
||||||
|
- pvc.yaml
|
||||||
|
- service.yaml
|
||||||
|
- state_full_set.yaml
|
||||||
|
# - secret.yaml
|
||||||
|
- ingress_alertmanager.yaml
|
||||||
|
- ingress_prometheus.yaml
|
||||||
|
- cm_custom_alert_rules.yaml
|
||||||
|
|
@ -0,0 +1,6 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: monitoring
|
||||||
|
labels:
|
||||||
|
kubernetes.io/metadata.name: monitoring
|
||||||
|
|
@ -0,0 +1,19 @@
|
||||||
|
# Source: prometheus/templates/pvc.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: "8Gi"
|
||||||
|
|
@ -0,0 +1,76 @@
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/alertmanager/templates/serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: alertmanager-1.14.0
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v0.28.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
namespace: monitoring
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/kube-state-metrics/templates/serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: kube-state-metrics-5.28.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: kube-state-metrics
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "2.14.0"
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
namespace: monitoring
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/prometheus-node-exporter/templates/serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: prometheus-prometheus-node-exporter
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-node-exporter-4.43.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/name: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "1.8.2"
|
||||||
|
automountServiceAccountToken: false
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/prometheus-pushgateway/templates/serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-pushgateway-2.17.0
|
||||||
|
app.kubernetes.io/name: prometheus-pushgateway
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v1.11.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
name: prometheus-prometheus-pushgateway
|
||||||
|
namespace: monitoring
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
---
|
||||||
|
# Source: prometheus/templates/serviceaccount.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
annotations:
|
||||||
|
{}
|
||||||
|
|
@ -0,0 +1,151 @@
|
||||||
|
# Source: prometheus/charts/alertmanager/templates/services.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: alertmanager-1.14.0
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v0.28.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- port: 9093
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/alertmanager/templates/services.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager-headless
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: alertmanager-1.14.0
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v0.28.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
clusterIP: None
|
||||||
|
ports:
|
||||||
|
- port: 9093
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/kube-state-metrics/templates/service.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: prometheus-kube-state-metrics
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: kube-state-metrics-5.28.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: kube-state-metrics
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "2.14.0"
|
||||||
|
annotations:
|
||||||
|
prometheus.io/scrape: 'true'
|
||||||
|
spec:
|
||||||
|
type: "ClusterIP"
|
||||||
|
ports:
|
||||||
|
- name: "http"
|
||||||
|
protocol: TCP
|
||||||
|
port: 8080
|
||||||
|
targetPort: 8080
|
||||||
|
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: kube-state-metrics
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/prometheus-node-exporter/templates/service.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: prometheus-prometheus-node-exporter
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-node-exporter-4.43.1
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
app.kubernetes.io/component: metrics
|
||||||
|
app.kubernetes.io/part-of: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/name: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "1.8.2"
|
||||||
|
annotations:
|
||||||
|
prometheus.io/scrape: "true"
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- port: 9100
|
||||||
|
targetPort: 9100
|
||||||
|
protocol: TCP
|
||||||
|
name: metrics
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: prometheus-node-exporter
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
---
|
||||||
|
# Source: prometheus/charts/prometheus-pushgateway/templates/service.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
prometheus.io/probe: pushgateway
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: prometheus-pushgateway-2.17.0
|
||||||
|
app.kubernetes.io/name: prometheus-pushgateway
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v1.11.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
name: prometheus-prometheus-pushgateway
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
ports:
|
||||||
|
- port: 9091
|
||||||
|
targetPort: 9091
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: prometheus-pushgateway
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
---
|
||||||
|
# Source: prometheus/templates/service.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: v3.1.0
|
||||||
|
helm.sh/chart: prometheus-27.3.1
|
||||||
|
app.kubernetes.io/part-of: prometheus
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
port: 80
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 9090
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/component: server
|
||||||
|
app.kubernetes.io/name: prometheus
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
sessionAffinity: None
|
||||||
|
type: "ClusterIP"
|
||||||
|
|
@ -0,0 +1,90 @@
|
||||||
|
# Source: prometheus/charts/alertmanager/templates/statefulset.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: alertmanager-1.14.0
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
app.kubernetes.io/version: "v0.28.0"
|
||||||
|
app.kubernetes.io/managed-by: Helm
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
minReadySeconds: 0
|
||||||
|
revisionHistoryLimit: 10
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
serviceName: prometheus-alertmanager-headless
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: alertmanager
|
||||||
|
app.kubernetes.io/instance: prometheus
|
||||||
|
spec:
|
||||||
|
nodeSelector:
|
||||||
|
nodegroup: nd
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
serviceAccountName: prometheus-alertmanager
|
||||||
|
securityContext:
|
||||||
|
fsGroup: 65534
|
||||||
|
runAsGroup: 65534
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65534
|
||||||
|
containers:
|
||||||
|
- name: alertmanager
|
||||||
|
securityContext:
|
||||||
|
runAsGroup: 65534
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 65534
|
||||||
|
image: "quay.io/prometheus/alertmanager:v0.28.0"
|
||||||
|
imagePullPolicy: Always
|
||||||
|
env:
|
||||||
|
- name: POD_IP
|
||||||
|
valueFrom:
|
||||||
|
fieldRef:
|
||||||
|
apiVersion: v1
|
||||||
|
fieldPath: status.podIP
|
||||||
|
args:
|
||||||
|
- --storage.path=/alertmanager
|
||||||
|
- --config.file=/etc/alertmanager/alertmanager.yml
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: 9093
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 512Mi
|
||||||
|
limits:
|
||||||
|
cpu: 200m
|
||||||
|
memory: 512Mi
|
||||||
|
volumeMounts:
|
||||||
|
- name: config
|
||||||
|
mountPath: /etc/alertmanager
|
||||||
|
- name: storage
|
||||||
|
mountPath: /alertmanager
|
||||||
|
volumes:
|
||||||
|
- name: config
|
||||||
|
configMap:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: storage
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 2Gi
|
||||||
|
|
@ -0,0 +1 @@
|
||||||
|
admin:$apr1$JIoWDh3p$Mo4E8nEh3beHp9n1IRjmc/
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/grafana
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
kind: ConfigMap
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-cm.yaml
|
||||||
|
- target:
|
||||||
|
kind: Secret
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-secret.yaml
|
||||||
|
- target:
|
||||||
|
kind: Deployment
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-deploy.yaml
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: grafana-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-ingress_grafana.yaml
|
||||||
|
|
@ -0,0 +1,32 @@
|
||||||
|
# 도메인 정보 변경 필요.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: grafana-8.10.0
|
||||||
|
app.kubernetes.io/name: grafana
|
||||||
|
app.kubernetes.io/instance: grafana
|
||||||
|
app.kubernetes.io/version: "11.5.1"
|
||||||
|
data:
|
||||||
|
|
||||||
|
grafana.ini: |
|
||||||
|
[analytics]
|
||||||
|
check_for_updates = true
|
||||||
|
[grafana_net]
|
||||||
|
url = https://grafana.net
|
||||||
|
[log]
|
||||||
|
mode = console
|
||||||
|
[paths]
|
||||||
|
data = /var/lib/grafana/
|
||||||
|
logs = /var/log/grafana
|
||||||
|
plugins = /var/lib/grafana/plugins
|
||||||
|
provisioning = /etc/grafana/provisioning
|
||||||
|
[server]
|
||||||
|
domain = 'grafana.nhngpuaas.com'
|
||||||
|
root_url = 'https://grafana.nhngpuaas.com'
|
||||||
|
[auth.anonymous]
|
||||||
|
enabled = true
|
||||||
|
org_name = Main Org.
|
||||||
|
org_role = Viewer
|
||||||
|
|
@ -0,0 +1,20 @@
|
||||||
|
# Source: grafana/templates/deployment.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: grafana
|
||||||
|
volumeMounts:
|
||||||
|
- name: storage
|
||||||
|
mountPath: "/var/lib/grafana"
|
||||||
|
volumes:
|
||||||
|
- name: storage
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: grafana-pvc
|
||||||
|
# - name: storage
|
||||||
|
# emptyDir: {}
|
||||||
|
|
@ -6,7 +6,7 @@ metadata:
|
||||||
spec:
|
spec:
|
||||||
ingressClassName: nginx
|
ingressClassName: nginx
|
||||||
rules:
|
rules:
|
||||||
- host: grafana.sample.com
|
- host: grafana.nhngpuaas.com
|
||||||
http:
|
http:
|
||||||
paths:
|
paths:
|
||||||
- backend:
|
- backend:
|
||||||
|
|
@ -18,5 +18,7 @@ spec:
|
||||||
pathType: Prefix
|
pathType: Prefix
|
||||||
tls:
|
tls:
|
||||||
- hosts:
|
- hosts:
|
||||||
- grafana.sample.com
|
- grafana.nhngpuaas.com
|
||||||
secretName: ssl-cc
|
secretName: nhngpuaas-ssl
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -0,0 +1,17 @@
|
||||||
|
---
|
||||||
|
# Source: grafana/templates/secret.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: grafana-8.10.0
|
||||||
|
app.kubernetes.io/name: grafana
|
||||||
|
app.kubernetes.io/instance: grafana
|
||||||
|
app.kubernetes.io/version: "11.5.1"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
admin-user: "YWRtaW4="
|
||||||
|
admin-password: "bmhuIUAjMTIz"
|
||||||
|
# ldap-toml: ""
|
||||||
|
|
@ -0,0 +1,17 @@
|
||||||
|
# Prometheus에 종속적으로 설치
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- prometheus
|
||||||
|
- grafana
|
||||||
|
|
||||||
|
generatorOptions:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
secretGenerator:
|
||||||
|
- name: basic-auth
|
||||||
|
files:
|
||||||
|
- auth
|
||||||
|
type: Opaque
|
||||||
|
|
@ -0,0 +1,34 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/prometheus
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
kind: ConfigMap
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-cm-prometheus-server.yaml
|
||||||
|
- target:
|
||||||
|
kind: Deployment
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-deploy.yaml
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: prometheus-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-ingress_prometheus.yaml
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: prometheus-alertmanager-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-ingress_alertmanager.yaml
|
||||||
|
# - target:
|
||||||
|
# kind: Secret
|
||||||
|
# name: basic-auth
|
||||||
|
# namespace: monitoring
|
||||||
|
# path: patch-basic-auth.yaml
|
||||||
|
|
@ -0,0 +1,335 @@
|
||||||
|
# - "/etc/config/rules/*.yaml" # 수정대상
|
||||||
|
# - "/etc/config/alerts/*.yaml" # 수정대상
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
data:
|
||||||
|
prometheus.yml: |
|
||||||
|
global:
|
||||||
|
evaluation_interval: 1m
|
||||||
|
scrape_interval: 1m
|
||||||
|
scrape_timeout: 10s
|
||||||
|
rule_files:
|
||||||
|
- /etc/config/recording_rules.yml
|
||||||
|
- /etc/config/alerting_rules.yml
|
||||||
|
- "/etc/config/rules/*.yaml"
|
||||||
|
- "/etc/config/alerts/*.yaml"
|
||||||
|
scrape_configs:
|
||||||
|
- job_name: prometheus
|
||||||
|
static_configs:
|
||||||
|
- targets:
|
||||||
|
- localhost:9090
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-apiservers
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: default;kubernetes;https
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
- __meta_kubernetes_endpoint_port_name
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-nodes
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: node
|
||||||
|
relabel_configs:
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_node_label_(.+)
|
||||||
|
- replacement: kubernetes.default.svc:443
|
||||||
|
target_label: __address__
|
||||||
|
- regex: (.+)
|
||||||
|
replacement: /api/v1/nodes/$1/proxy/metrics
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_node_name
|
||||||
|
target_label: __metrics_path__
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
job_name: kubernetes-nodes-cadvisor
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: node
|
||||||
|
relabel_configs:
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_node_label_(.+)
|
||||||
|
- replacement: kubernetes.default.svc:443
|
||||||
|
target_label: __address__
|
||||||
|
- regex: (.+)
|
||||||
|
replacement: /api/v1/nodes/$1/proxy/metrics/cadvisor
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_node_name
|
||||||
|
target_label: __metrics_path__
|
||||||
|
scheme: https
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-service-endpoints
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape
|
||||||
|
- action: drop
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+?)(?::\d+)?;(\d+)
|
||||||
|
replacement: $1:$2
|
||||||
|
source_labels:
|
||||||
|
- __address__
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_port
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-service-endpoints-slow
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: endpoints
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+?)(?::\d+)?;(\d+)
|
||||||
|
replacement: $1:$2
|
||||||
|
source_labels:
|
||||||
|
- __address__
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_port
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
scrape_interval: 5m
|
||||||
|
scrape_timeout: 30s
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: prometheus-pushgateway
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: service
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: pushgateway
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_probe
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-services
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: service
|
||||||
|
metrics_path: /probe
|
||||||
|
params:
|
||||||
|
module:
|
||||||
|
- http_2xx
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_service_annotation_prometheus_io_probe
|
||||||
|
- source_labels:
|
||||||
|
- __address__
|
||||||
|
target_label: __param_target
|
||||||
|
- replacement: blackbox
|
||||||
|
target_label: __address__
|
||||||
|
- source_labels:
|
||||||
|
- __param_target
|
||||||
|
target_label: instance
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_service_label_(.+)
|
||||||
|
- source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- source_labels:
|
||||||
|
- __meta_kubernetes_service_name
|
||||||
|
target_label: service
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-pods
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape
|
||||||
|
- action: drop
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})
|
||||||
|
replacement: '[$2]:$1'
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);((([0-9]+?)(\.|$)){4})
|
||||||
|
replacement: $2:$1
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_name
|
||||||
|
target_label: pod
|
||||||
|
- action: drop
|
||||||
|
regex: Pending|Succeeded|Failed|Completed
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_phase
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
- honor_labels: true
|
||||||
|
job_name: kubernetes-pods-slow
|
||||||
|
kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
relabel_configs:
|
||||||
|
- action: keep
|
||||||
|
regex: true
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scrape_slow
|
||||||
|
- action: replace
|
||||||
|
regex: (https?)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_scheme
|
||||||
|
target_label: __scheme__
|
||||||
|
- action: replace
|
||||||
|
regex: (.+)
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_path
|
||||||
|
target_label: __metrics_path__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})
|
||||||
|
replacement: '[$2]:$1'
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: replace
|
||||||
|
regex: (\d+);((([0-9]+?)(\.|$)){4})
|
||||||
|
replacement: $2:$1
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_annotation_prometheus_io_port
|
||||||
|
- __meta_kubernetes_pod_ip
|
||||||
|
target_label: __address__
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_annotation_prometheus_io_param_(.+)
|
||||||
|
replacement: __param_$1
|
||||||
|
- action: labelmap
|
||||||
|
regex: __meta_kubernetes_pod_label_(.+)
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_namespace
|
||||||
|
target_label: namespace
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_name
|
||||||
|
target_label: pod
|
||||||
|
- action: drop
|
||||||
|
regex: Pending|Succeeded|Failed|Completed
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_phase
|
||||||
|
- action: replace
|
||||||
|
source_labels:
|
||||||
|
- __meta_kubernetes_pod_node_name
|
||||||
|
target_label: node
|
||||||
|
scrape_interval: 5m
|
||||||
|
scrape_timeout: 30s
|
||||||
|
alerting:
|
||||||
|
alertmanagers:
|
||||||
|
- kubernetes_sd_configs:
|
||||||
|
- role: pod
|
||||||
|
tls_config:
|
||||||
|
ca_file: /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
|
||||||
|
bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
relabel_configs:
|
||||||
|
- source_labels: [__meta_kubernetes_namespace]
|
||||||
|
regex: monitoring
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_label_app_kubernetes_io_instance]
|
||||||
|
regex: prometheus
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_label_app_kubernetes_io_name]
|
||||||
|
regex: alertmanager
|
||||||
|
action: keep
|
||||||
|
- source_labels: [__meta_kubernetes_pod_container_port_number]
|
||||||
|
regex: "9093"
|
||||||
|
action: keep
|
||||||
|
|
@ -0,0 +1,19 @@
|
||||||
|
# Source: prometheus/templates/deploy.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: prometheus-server
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: prometheus-server
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/config/alerts
|
||||||
|
name: config-volume2
|
||||||
|
volumes:
|
||||||
|
- configMap:
|
||||||
|
defaultMode: 420
|
||||||
|
name: prometheus-rulefiles
|
||||||
|
name: config-volume2
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: prometheus-alertmanager-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
annotations:
|
||||||
|
# 인증 방법 설정: basic auth
|
||||||
|
nginx.ingress.kubernetes.io/auth-type: basic
|
||||||
|
# basic auth 사용자가 들어있는 secret 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-secret: basic-auth
|
||||||
|
# 인증 요청시 나오는 메세지 설정
|
||||||
|
nginx.ingress.kubernetes.io/auth-realm: 'Authentication Required - admin'
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: alert.nhngpuaas.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: prometheus-alertmanager
|
||||||
|
port:
|
||||||
|
number: 9093
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- alert.nhngpuaas.com
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
|
@ -0,0 +1,22 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: prometheus-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: prometheus.nhngpuaas.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: prometheus-server
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- prometheus.nhngpuaas.com
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
|
@ -0,0 +1 @@
|
||||||
|
admin:$apr1$JIoWDh3p$Mo4E8nEh3beHp9n1IRjmc/
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- ../../../base/grafana
|
||||||
|
|
||||||
|
namespace: monitoring
|
||||||
|
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
kind: ConfigMap
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-cm.yaml
|
||||||
|
- target:
|
||||||
|
kind: Secret
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-secret.yaml
|
||||||
|
- target:
|
||||||
|
kind: Deployment
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-deploy.yaml
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: grafana-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
path: patch-ingress_grafana.yaml
|
||||||
|
|
@ -0,0 +1,32 @@
|
||||||
|
# 도메인 정보 변경 필요.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: grafana-8.10.0
|
||||||
|
app.kubernetes.io/name: grafana
|
||||||
|
app.kubernetes.io/instance: grafana
|
||||||
|
app.kubernetes.io/version: "11.5.1"
|
||||||
|
data:
|
||||||
|
|
||||||
|
grafana.ini: |
|
||||||
|
[analytics]
|
||||||
|
check_for_updates = true
|
||||||
|
[grafana_net]
|
||||||
|
url = https://grafana.net
|
||||||
|
[log]
|
||||||
|
mode = console
|
||||||
|
[paths]
|
||||||
|
data = /var/lib/grafana/
|
||||||
|
logs = /var/log/grafana
|
||||||
|
plugins = /var/lib/grafana/plugins
|
||||||
|
provisioning = /etc/grafana/provisioning
|
||||||
|
[server]
|
||||||
|
domain = 'monitoring.gpulive.nhncloud.com'
|
||||||
|
root_url = 'https://monitoring.gpulive.nhncloud.com'
|
||||||
|
[auth.anonymous]
|
||||||
|
enabled = true
|
||||||
|
org_name = Main Org.
|
||||||
|
org_role = Viewer
|
||||||
|
|
@ -0,0 +1,20 @@
|
||||||
|
# Source: grafana/templates/deployment.yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: grafana
|
||||||
|
volumeMounts:
|
||||||
|
- name: storage
|
||||||
|
mountPath: "/var/lib/grafana"
|
||||||
|
volumes:
|
||||||
|
- name: storage
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: grafana-pvc
|
||||||
|
# - name: storage
|
||||||
|
# emptyDir: {}
|
||||||
|
|
@ -0,0 +1,24 @@
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: grafana-ingress
|
||||||
|
namespace: monitoring
|
||||||
|
spec:
|
||||||
|
ingressClassName: nginx
|
||||||
|
rules:
|
||||||
|
- host: grafana.nhngpuaas.com
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- backend:
|
||||||
|
service:
|
||||||
|
name: grafana
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- grafana.nhngpuaas.com
|
||||||
|
secretName: nhngpuaas-ssl
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -0,0 +1,17 @@
|
||||||
|
---
|
||||||
|
# Source: grafana/templates/secret.yaml
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: grafana
|
||||||
|
namespace: monitoring
|
||||||
|
labels:
|
||||||
|
helm.sh/chart: grafana-8.10.0
|
||||||
|
app.kubernetes.io/name: grafana
|
||||||
|
app.kubernetes.io/instance: grafana
|
||||||
|
app.kubernetes.io/version: "11.5.1"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
admin-user: "YWRtaW4="
|
||||||
|
admin-password: "bmhuIUAjMTIz"
|
||||||
|
# ldap-toml: ""
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue