Merge pull request #1100 from Infisical/migrate-to-standalone-infisical

Migrate to standalone infisical
This commit is contained in:
Maidul Islam
2023-10-19 16:07:55 +01:00
committed by GitHub
16 changed files with 55 additions and 485 deletions
+1 -1
View File
@@ -6,7 +6,7 @@ services:
restart: unless-stopped restart: unless-stopped
depends_on: depends_on:
- mongo - mongo
image: infisical/backend:test image: infisical/infisical:test
command: npm run start command: npm run start
environment: environment:
- NODE_ENV=production - NODE_ENV=production
+2 -28
View File
@@ -1,29 +1,3 @@
# secretScanningGitApp:
# enabled: false
# deploymentAnnotations:
# secrets.infisical.com/auto-reload: "true"
# image:
# repository: infisical/staging_deployment_secret-scanning-git-app
frontend:
enabled: true
name: frontend
podAnnotations: {}
deploymentAnnotations:
secrets.infisical.com/auto-reload: "true"
replicaCount: 2
image:
repository: infisical/staging_deployment_frontend
tag: "latest"
pullPolicy: Always
kubeSecretRef: managed-secret-frontend
service:
annotations: {}
type: ClusterIP
nodePort: ""
frontendEnvironmentVariables: null
backend: backend:
enabled: true enabled: true
name: backend name: backend
@@ -32,7 +6,7 @@ backend:
secrets.infisical.com/auto-reload: "true" secrets.infisical.com/auto-reload: "true"
replicaCount: 2 replicaCount: 2
image: image:
repository: infisical/staging_deployment_backend repository: infisical/staging_infisical
tag: "latest" tag: "latest"
pullPolicy: Always pullPolicy: Always
kubeSecretRef: managed-backend-secret kubeSecretRef: managed-backend-secret
@@ -63,7 +37,7 @@ ingress:
enabled: true enabled: true
# annotations: # annotations:
# kubernetes.io/ingress.class: "nginx" # kubernetes.io/ingress.class: "nginx"
# cert-manager.io/issuer: letsencrypt-nginx # cert-manager.io/issuer: letsencrypt-nginx
hostName: gamma.infisical.com ## <- Replace with your own domain hostName: gamma.infisical.com ## <- Replace with your own domain
frontend: frontend:
path: / path: /
+12 -59
View File
@@ -2,7 +2,7 @@ name: Build, Publish and Deploy to Gamma
on: [workflow_dispatch] on: [workflow_dispatch]
jobs: jobs:
backend-image: infisical-image:
name: Build backend image name: Build backend image
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
@@ -32,8 +32,9 @@ jobs:
project: 64mmf0n610 project: 64mmf0n610
token: ${{ secrets.DEPOT_PROJECT_TOKEN }} token: ${{ secrets.DEPOT_PROJECT_TOKEN }}
load: true load: true
context: backend context: .
tags: infisical/backend:test file: Dockerfile.standalone-infisical
tags: infisical/infisical:test
- name: ⏻ Spawn backend container and dependencies - name: ⏻ Spawn backend container and dependencies
run: | run: |
docker compose -f .github/resources/docker-compose.be-test.yml up --wait --quiet-pull docker compose -f .github/resources/docker-compose.be-test.yml up --wait --quiet-pull
@@ -49,68 +50,20 @@ jobs:
project: 64mmf0n610 project: 64mmf0n610
token: ${{ secrets.DEPOT_PROJECT_TOKEN }} token: ${{ secrets.DEPOT_PROJECT_TOKEN }}
push: true push: true
context: backend context: .
file: Dockerfile.standalone-infisical
tags: | tags: |
infisical/staging_deployment_backend:${{ steps.commit.outputs.short }} infisical/staging_infisical:${{ steps.commit.outputs.short }}
infisical/staging_deployment_backend:latest infisical/staging_infisical:latest
platforms: linux/amd64,linux/arm64 platforms: linux/amd64,linux/arm64
build-args: |
POSTHOG_API_KEY=${{ secrets.PUBLIC_POSTHOG_API_KEY }}
INFISICAL_PLATFORM_VERSION=${{ steps.extract_version.outputs.version }}
frontend-image:
name: Build frontend image
runs-on: ubuntu-latest
steps:
- name: ☁️ Checkout source
uses: actions/checkout@v3
- name: Save commit hashes for tag
id: commit
uses: pr-mpt/actions-commit-hash@v2
- name: 🔧 Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- name: 🐋 Login to Docker Hub
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Set up Depot CLI
uses: depot/setup-action@v1
- name: 📦 Build frontend and export to Docker
uses: depot/build-push-action@v1
with:
load: true
token: ${{ secrets.DEPOT_PROJECT_TOKEN }}
project: 64mmf0n610
context: frontend
tags: infisical/staging_deployment_frontend:test
build-args: |
POSTHOG_API_KEY=${{ secrets.PUBLIC_POSTHOG_API_KEY }}
NEXT_INFISICAL_PLATFORM_VERSION=${{ steps.extract_version.outputs.version }}
- name: ⏻ Spawn frontend container
run: |
docker run -d --rm --name infisical-frontend-test infisical/staging_deployment_frontend:test
- name: 🧪 Test frontend image
run: |
./.github/resources/healthcheck.sh infisical-frontend-test
- name: ⏻ Shut down frontend container
run: |
docker stop infisical-frontend-test
- name: 🏗️ Build frontend and push
uses: depot/build-push-action@v1
with:
project: 64mmf0n610
push: true
token: ${{ secrets.DEPOT_PROJECT_TOKEN }}
context: frontend
tags: |
infisical/staging_deployment_frontend:${{ steps.commit.outputs.short }}
infisical/staging_deployment_frontend:latest
platforms: linux/amd64,linux/arm64
build-args: |
POSTHOG_API_KEY=${{ secrets.PUBLIC_POSTHOG_API_KEY }}
NEXT_INFISICAL_PLATFORM_VERSION=${{ steps.extract_version.outputs.version }}
gamma-deployment: gamma-deployment:
name: Deploy to gamma name: Deploy to gamma
runs-on: ubuntu-latest runs-on: ubuntu-latest
needs: [frontend-image, backend-image] needs: [infisical-image]
steps: steps:
- name: ☁️ Checkout source - name: ☁️ Checkout source
uses: actions/checkout@v3 uses: actions/checkout@v3
+3 -29
View File
@@ -1,46 +1,20 @@
version: "3" version: "3"
services: services:
nginx:
container_name: infisical-nginx
image: nginx
restart: always
ports:
- 80:80
- 443:443
volumes:
- ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
depends_on:
- frontend
- backend
networks:
- infisical
backend: backend:
container_name: infisical-backend container_name: infisical-backend
restart: unless-stopped restart: unless-stopped
depends_on: depends_on:
- mongo - mongo
image: infisical/backend image: infisical/infisical:latest
env_file: .env env_file: .env
ports:
- 80:8080
environment: environment:
- NODE_ENV=production - NODE_ENV=production
networks: networks:
- infisical - infisical
frontend:
container_name: infisical-frontend
restart: unless-stopped
depends_on:
- backend
image: infisical/frontend
env_file: .env
environment:
# - NEXT_PUBLIC_POSTHOG_API_KEY=${POSTHOG_PROJECT_API_KEY}
- INFISICAL_TELEMETRY_ENABLED=${TELEMETRY_ENABLED}
networks:
- infisical
redis: redis:
image: redis image: redis
container_name: infisical-dev-redis container_name: infisical-dev-redis
+1 -10
View File
@@ -3,7 +3,7 @@ title: "All environment variables"
description: "Configure your environment variables when self-hosting Infisical." description: "Configure your environment variables when self-hosting Infisical."
--- ---
## Backend environment variables ## Environment variables
Depending on your chosen self hosted deployment method, you may need to configured at least the required environment variable listed below. Depending on your chosen self hosted deployment method, you may need to configured at least the required environment variable listed below.
Other environment variables are listed below to increase the functionality of your self hosted instance based on your use case. Other environment variables are listed below to increase the functionality of your self hosted instance based on your use case.
@@ -232,12 +232,3 @@ Infisical uses Sentry to report error logs
<ParamField query="TELEMETRY_ENABLED" type="string" default="true" optional></ParamField> <ParamField query="TELEMETRY_ENABLED" type="string" default="true" optional></ParamField>
</Tab> </Tab>
</Tabs> </Tabs>
## Frontend environment variables
<ParamField
query="TELEMETRY_ENABLED"
type="string"
default="true"
optional
></ParamField>
@@ -31,7 +31,7 @@ primary_region = "iad"
MONGO_URL = <> MONGO_URL = <>
[http_service] [http_service]
internal_port = 80 internal_port = 8080
``` ```
@@ -23,40 +23,27 @@ helm repo update
## Add Helm values ## Add Helm values
Create a values.yaml file to configure various installation settings, such as the docker image tags and environment variables for both the frontend and backend. To explore all configurable properties for your values file, [visit this page](https://github.com/Infisical/infisical/tree/main/helm-charts/infisical). Create a values.yaml file to configure various installation settings, such as the docker image tags and environment variables. To explore all configurable properties for your values file, [visit this page](https://github.com/Infisical/infisical/tree/main/helm-charts/infisical).
#### Set image tags #### Set image tags
By default, the application will use the latest tag to retrieve the required Docker images, which may be appropriate for most cases. By default, the application will use the `latest` docker image tag. This is okay for test environments; however, for production deployments it is important to pin your deployment to a particular docker image tag to prevent receiving unintended changes.
However, it's important to specify a particular version of Infisical during installation to prevent any significant updates from disrupting your deployment.
View [properties for frontend and backend](https://github.com/Infisical/infisical/tree/main/helm-charts/infisical#parameters).
<Tip> <Tip>
To find the latest version number of Infisical, follow the links below To find the latest version number of Infisical, click [here](https://hub.docker.com/r/infisical/infisical/tags)
- [frontend Docker image](https://hub.docker.com/r/infisical/frontend/tags)
- [backend Docker image](https://hub.docker.com/r/infisical/backend/tags)
</Tip> </Tip>
```yaml simple-values-example.yaml ```yaml simple-values-example.yaml
frontend:
name: frontend
replicaCount: 2
image:
repository: infisical/frontend
tag: "v0.34.2" # <--- frontend version
pullPolicy: Always
backend: backend:
replicaCount: 2 replicaCount: 2
image: image:
repository: infisical/backend repository: infisical/infisical
tag: "v0.34.2" # <--- backend version tag: "v0.39.5"
pullPolicy: Always pullPolicy: Always
``` ```
#### Configure environment variables #### Configure environment variables
You can configure environment variables for the frontend and backend in your Helm values file under the property `frontendEnvironmentVariables` and `backendEnvironmentVariables` respectively. View configurable [environment variables](../configuration/envars). You can configure environment variables for your instance of Infisical though the Helm values file under the property `backendEnvironmentVariables`. View configurable [environment variables](../configuration/envars).
Infisical requires the following backend environment variables to be defined: _`ENCRYPTION_KEY`_, _`JWT_SIGNUP_SECRET`_, _`JWT_REFRESH_SECRET`_, _`JWT_AUTH_SECRET`_, _`JWT_MFA_SECRET`_ and _`JWT_SERVICE_SECRET`_. Infisical requires the following backend environment variables to be defined: _`ENCRYPTION_KEY`_, _`JWT_SIGNUP_SECRET`_, _`JWT_REFRESH_SECRET`_, _`JWT_AUTH_SECRET`_, _`JWT_MFA_SECRET`_ and _`JWT_SERVICE_SECRET`_.
@@ -87,38 +74,30 @@ Infisical uses Nginx to route external traffic. You can install Nginx along with
... ...
ingress: ingress:
nginx: nginx:
enabled: false #<-- if you would like to install nginx along with Infisical enabled: true #<-- if you would like to install nginx along with Infisical
``` ```
#### Database #### Database
Infisical uses a document database as its persistence layer. With this Helm chart, you spin up a MongoDB instance power by Bitnami along side other Infisical services in your cluster. Infisical uses a MongoDB as its persistence layer. With this Helm chart, a MongoDB instance is automatically spun up for use with Infisical.
When persistence is enabled, the data will be stored as Kubernetes Persistence Volume. View all [properties for mongodb](https://github.com/Infisical/infisical/tree/main/helm-charts/infisical). When persistence is enabled, the data will be stored as Kubernetes Persistence Volume. View all [properties for mongodb](https://github.com/Infisical/infisical/tree/main/helm-charts/infisical).
```yaml simple-values-example.yaml ```yaml simple-values-example.yaml
mongodb: mongodb:
enabled: false enabled: true
persistence: persistence:
enabled: false enabled: false
``` ```
To increase data redundancy, we recommend that you use a managed document database service such as AWS Document DB, MongoDB or similar services instead. To achieve high availability and data redundancy, we recommend that you use a managed document database service such as AWS Document DB, MongoDB or similar services instead of the in cluster database.
Managed database connection string can be set in the `backendEnvironmentVariables`. Managed database connection string can be set in the `backendEnvironmentVariables`.
#### Example helm values #### Example helm values
```yaml simple-values-example.yaml ```yaml simple-values-example.yaml
frontend:
name: frontend
replicaCount: 2
image:
repository: infisical/frontend
tag: "v0.34.2" # <--- frontend version
pullPolicy: Always
backend: backend:
replicaCount: 2 replicaCount: 2
image: image:
repository: infisical/backend repository: infisical/infisical
tag: "v0.34.2" # <--- backend version tag: "v0.39.5"
pullPolicy: Always pullPolicy: Always
backendEnvironmentVariables: backendEnvironmentVariables:
@@ -126,7 +105,7 @@ backendEnvironmentVariables:
ingress: ingress:
nginx: nginx:
enabled: true #<-- if you would like to install nginx along with Infisical enabled: true
``` ```
@@ -136,22 +115,6 @@ ingress:
nginx: nginx:
enabled: true enabled: true
frontend:
enabled: true
name: frontend
podAnnotations: {}
deploymentAnnotations: {}
replicaCount: 4
image:
repository: infisical/frontend
tag: "v0.34.2" # <--- frontend version
pullPolicy: IfNotPresent
kubeSecretRef: null
service:
annotations: {}
type: ClusterIP
nodePort: ""
backend: backend:
enabled: true enabled: true
name: backend name: backend
@@ -159,8 +122,8 @@ ingress:
deploymentAnnotations: {} deploymentAnnotations: {}
replicaCount: 4 replicaCount: 4
image: image:
repository: infisical/backend repository: infisical/infisical
tag: "v0.34.2" # <--- backend version tag: "v0.39.5"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
kubeSecretRef: null kubeSecretRef: null
service: service:
@@ -176,26 +139,9 @@ ingress:
## Mongo DB persistence ## Mongo DB persistence
mongodb: mongodb:
enabled: false
persistence:
enabled: false
ingress:
enabled: true enabled: true
annotations: persistence:
cert-manager.io/cluster-issuer: "letsencrypt-prod" # <-- if you are setting up HTTPS enabled: true
hostName: app.infisical.com ## <- Replace with your own domain
frontend:
path: /
pathType: Prefix
backend:
path: /api
pathType: Prefix
tls: # <-- if you are setting up HTTPS
- secretName: echo-tls
hosts:
- app.infisical.com
``` ```
</Accordion> </Accordion>
@@ -58,7 +58,7 @@ Add the required environment variables listed below to your docker run command.
Once you have added the required environment variables to your docker run command, execute it in your terminal. Once you have added the required environment variables to your docker run command, execute it in your terminal.
```bash ```bash
docker run -p 80:80 \ docker run -p 80:8080 \
-e ENCRYPTION_KEY=f40c9178624764ad85a6830b37ce239a \ -e ENCRYPTION_KEY=f40c9178624764ad85a6830b37ce239a \
-e JWT_SIGNUP_SECRET=38ea90fb7998b92176080f457d890392 \ -e JWT_SIGNUP_SECRET=38ea90fb7998b92176080f457d890392 \
-e JWT_REFRESH_SECRET=7764c7bbf3928ad501591a3e005eb364 \ -e JWT_REFRESH_SECRET=7764c7bbf3928ad501591a3e005eb364 \
+1 -1
View File
@@ -7,7 +7,7 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes # This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version. # to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/) # Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.3.5 version: 0.4.0
# This is the version number of the application being deployed. This version number should be # This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to # incremented each time you make changes to the application. Versions are not expected to
+2 -26
View File
@@ -4,7 +4,6 @@ This is the Infisical application Helm chart. This chart includes the following
| Service | Description | | Service | Description |
| ---------- | ----------------------------------- | | ---------- | ----------------------------------- |
| `frontend` | Infisical's Web UI |
| `backend` | Infisical's API | | `backend` | Infisical's API |
| `mongodb` | Infisical's database | | `mongodb` | Infisical's database |
| `redis` | Infisical's cache service | | `redis` | Infisical's cache service |
@@ -59,28 +58,6 @@ kubectl get secrets -n <namespace> <secret-name> \
| `nameOverride` | Override release name | `""` | | `nameOverride` | Override release name | `""` |
| `fullnameOverride` | Override release fullname | `""` | | `fullnameOverride` | Override release fullname | `""` |
### Infisical frontend parameters
| Name | Description | Value |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| `frontend.enabled` | Enable frontend | `true` |
| `frontend.name` | Frontend name | `frontend` |
| `frontend.fullnameOverride` | Frontend fullnameOverride | `""` |
| `frontend.podAnnotations` | Frontend pod annotations | `{}` |
| `frontend.deploymentAnnotations` | Frontend deployment annotations | `{}` |
| `frontend.replicaCount` | Frontend replica count | `2` |
| `frontend.image.repository` | Frontend image repository | `infisical/frontend` |
| `frontend.image.tag` | Frontend image tag | `latest` |
| `frontend.image.pullPolicy` | Frontend image pullPolicy | `IfNotPresent` |
| `frontend.resources.limits.memory` | container memory limit [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | `100Mi` |
| `frontend.resources.requests.cpu` | container CPU request [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | `100m` |
| `frontend.affinity` | Frontend pod affinity | `{}` |
| `frontend.kubeSecretRef` | Backend secret resource reference name (containing required [frontend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) | `""` |
| `frontend.service.annotations` | Backend service annotations | `{}` |
| `frontend.service.type` | Backend service type | `ClusterIP` |
| `frontend.service.nodePort` | Backend service nodePort (used if above type is `NodePort`) | `""` |
| `frontendEnvironmentVariables.SITE_URL` | Absolute URL including the protocol (e.g. https://app.infisical.com) | `infisical.local` |
### Infisical backend parameters ### Infisical backend parameters
| Name | Description | Value | | Name | Description | Value |
@@ -91,11 +68,9 @@ kubectl get secrets -n <namespace> <secret-name> \
| `backend.podAnnotations` | Backend pod annotations | `{}` | | `backend.podAnnotations` | Backend pod annotations | `{}` |
| `backend.deploymentAnnotations` | Backend deployment annotations | `{}` | | `backend.deploymentAnnotations` | Backend deployment annotations | `{}` |
| `backend.replicaCount` | Backend replica count | `2` | | `backend.replicaCount` | Backend replica count | `2` |
| `backend.image.repository` | Backend image repository | `infisical/backend` | | `backend.image.repository` | Backend image repository | `infisical/infisical` |
| `backend.image.tag` | Backend image tag | `latest` | | `backend.image.tag` | Backend image tag | `latest` |
| `backend.image.pullPolicy` | Backend image pullPolicy | `IfNotPresent` | | `backend.image.pullPolicy` | Backend image pullPolicy | `IfNotPresent` |
| `backend.resources.limits.memory` | container memory limit [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | `200Mi` |
| `backend.resources.requests.cpu` | container CPU request [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | `150m` |
| `backend.affinity` | Backend pod affinity | `{}` | | `backend.affinity` | Backend pod affinity | `{}` |
| `backend.kubeSecretRef` | Backend secret resource reference name (containing required [backend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) | `""` | | `backend.kubeSecretRef` | Backend secret resource reference name (containing required [backend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) | `""` |
| `backend.service.annotations` | Backend service annotations | `{}` | | `backend.service.annotations` | Backend service annotations | `{}` |
@@ -197,6 +172,7 @@ kubectl get secrets -n <namespace> <secret-name> \
## Persistence ## Persistence
The database persistence is enabled by default, your volumes will remain on your cluster even after uninstalling the chart. To disable persistence, set this value `mongodb.persistence.enabled: false` The database persistence is enabled by default, your volumes will remain on your cluster even after uninstalling the chart. To disable persistence, set this value `mongodb.persistence.enabled: false`
-29
View File
@@ -2,34 +2,6 @@
-- Infisical Helm Chart -- -- Infisical Helm Chart --
__ __
( _) ( _)
/ / \\ / /\_\_
/ / \\ / / | \ \
/ / \\ / / |\ \ \
/ / , \ , / / /| \ \
/ / |\_ /| / / / \ \_\
/ / |\/ _ '_|\ / / / \ \\
| / |/ 0 \0\\ / | | \ \\
| |\| \_\_ / / | \ \\
| | |/ \.\ o\o) / \ | \\
\ | /\\`v-v / | | \\
| \/ /_| \\_| / | | \ \\
| | /__/_ / _____ | | \ \\
\| [__] \_/ |_________ \ | \ ()
/ [___] ( \ \ |\ | | //
| [___] |\| \| / |/
/| [____] \ |/\ / / ||
( \ [____ / ) _\ \ \ \| | ||
\ \ [_____| / / __/ \ / / //
| \ [_____/ / / \ | \/ //
| / '----| /=\____ _/ | / //
__ / / | / ___/ _/\ \ | ||
(/-(/-\) / \ (/\/\)/ | / | /
(/\/\) / / //
_________/ / /
\____________/ (
██╗███╗ ██╗███████╗██╗███████╗██╗ ██████╗ █████╗ ██╗ ██╗███╗ ██╗███████╗██╗███████╗██╗ ██████╗ █████╗ ██╗
██║████╗ ██║██╔════╝██║██╔════╝██║██╔════╝██╔══██╗██║ ██║████╗ ██║██╔════╝██║██╔════╝██║██╔════╝██╔══██╗██║
██║██╔██╗ ██║█████╗ ██║███████╗██║██║ ███████║██║ ██║██╔██╗ ██║█████╗ ██║███████╗██║██║ ███████║██║
@@ -46,7 +18,6 @@
│ Visit < https://infisical.com/docs/self-hosting/overview > for further documentation about self-hosting! │ Visit < https://infisical.com/docs/self-hosting/overview > for further documentation about self-hosting!
│ │
│ Current installation (infisical) : │ Current installation (infisical) :
│ • infisical-frontend : {{ .Values.frontend.enabled }}
│ • infisical-backend : {{ .Values.backend.enabled }} │ • infisical-backend : {{ .Values.backend.enabled }}
│ • mongodb : {{ .Values.mongodb.enabled }} │ • mongodb : {{ .Values.mongodb.enabled }}
│ • mailhog : {{ .Values.mailhog.enabled }} │ • mailhog : {{ .Values.mailhog.enabled }}
@@ -41,16 +41,6 @@ component: {{ .Values.backend.name | quote }}
{{ include "infisical.common.matchLabels" . }} {{ include "infisical.common.matchLabels" . }}
{{- end -}} {{- end -}}
{{- define "infisical.frontend.labels" -}}
{{ include "infisical.frontend.matchLabels" . }}
{{ include "infisical.common.metaLabels" . }}
{{- end -}}
{{- define "infisical.frontend.matchLabels" -}}
component: {{ .Values.frontend.name | quote }}
{{ include "infisical.common.matchLabels" . }}
{{- end -}}
{{- define "infisical.mongodb.labels" -}} {{- define "infisical.mongodb.labels" -}}
{{ include "infisical.mongodb.matchLabels" . }} {{ include "infisical.mongodb.matchLabels" . }}
{{ include "infisical.common.metaLabels" . }} {{ include "infisical.common.metaLabels" . }}
@@ -78,22 +68,6 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
{{/*
Create a fully qualified frontend name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
*/}}
{{- define "infisical.frontend.fullname" -}}
{{- if .Values.frontend.fullnameOverride -}}
{{- .Values.frontend.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default .Chart.Name .Values.nameOverride -}}
{{- if contains $name .Release.Name -}}
{{- printf "%s-%s" .Release.Name .Values.frontend.name | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- printf "%s-%s-%s" .Release.Name $name .Values.frontend.name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{/* {{/*
Create a fully qualified mongodb name. Create a fully qualified mongodb name.
@@ -36,17 +36,17 @@ spec:
readinessProbe: readinessProbe:
httpGet: httpGet:
path: /api/status path: /api/status
port: 4000 port: 8080
initialDelaySeconds: 10 initialDelaySeconds: 50
periodSeconds: 10 periodSeconds: 30
ports: ports:
- containerPort: 4000 - containerPort: 8080
envFrom: envFrom:
- secretRef: - secretRef:
name: {{ $backend.kubeSecretRef | default (include "infisical.backend.fullname" .) }} name: {{ $backend.kubeSecretRef | default (include "infisical.backend.fullname" .) }}
{{- if $backend.resources }} # {{- if $backend.resources }}
resources: {{- toYaml $backend.resources | nindent 12 }} # resources: {{- toYaml $backend.resources | nindent 12 }}
{{- end }} # {{- end }}
--- ---
apiVersion: v1 apiVersion: v1
@@ -65,8 +65,8 @@ spec:
{{- include "infisical.backend.matchLabels" . | nindent 8 }} {{- include "infisical.backend.matchLabels" . | nindent 8 }}
ports: ports:
- protocol: TCP - protocol: TCP
port: 4000 port: 8080
targetPort: 4000 # container port targetPort: 8080 # container port
{{- if eq $backend.service.type "NodePort" }} {{- if eq $backend.service.type "NodePort" }}
nodePort: {{ $backend.service.nodePort }} nodePort: {{ $backend.service.nodePort }}
{{- end }} {{- end }}
@@ -1,94 +0,0 @@
{{- $frontend := .Values.frontend }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "infisical.frontend.fullname" . }}
annotations:
updatedAt: {{ now | date "2006-01-01 MST 15:04:05" | quote }}
{{- with .Values.frontend.deploymentAnnotations }}
{{- toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "infisical.frontend.labels" . | nindent 4 }}
spec:
replicas: {{ $frontend.replicaCount }}
selector:
matchLabels:
{{- include "infisical.frontend.matchLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "infisical.frontend.matchLabels" . | nindent 8 }}
annotations:
updatedAt: {{ now | date "2006-01-01 MST 15:04:05" | quote }}
{{- with $frontend.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- with $frontend.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: {{ template "infisical.name" . }}-{{ $frontend.name }}
image: "{{ $frontend.image.repository }}:{{ $frontend.image.tag | default "latest" }}"
imagePullPolicy: {{ $frontend.image.pullPolicy }}
readinessProbe:
httpGet:
path: /
port: 3000
initialDelaySeconds: 10
periodSeconds: 10
envFrom:
- secretRef:
name: {{ $frontend.kubeSecretRef | default (include "infisical.frontend.fullname" .) }}
ports:
- containerPort: 3000
{{- if $frontend.resources }}
resources: {{- toYaml $frontend.resources | nindent 12 }}
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: {{ include "infisical.frontend.fullname" . }}
labels:
{{- include "infisical.frontend.labels" . | nindent 4 }}
{{- with $frontend.service.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
type: {{ $frontend.service.type }}
selector:
{{- include "infisical.frontend.matchLabels" . | nindent 8 }}
ports:
- protocol: TCP
port: 3000 # service
targetPort: 3000 # container port
{{- if eq $frontend.service.type "NodePort" }}
nodePort: {{ $frontend.service.nodePort }}
{{- end }}
---
{{ if not $frontend.kubeSecretRef }}
apiVersion: v1
kind: Secret
metadata:
name: {{ include "infisical.frontend.fullname" . }}
annotations:
"helm.sh/resource-policy": "keep"
type: Opaque
stringData:
{{- $requiredVars := dict }}
{{- $secretObj := (lookup "v1" "Secret" .Release.Namespace (include "infisical.frontend.fullname" .)) | default dict }}
{{- $secretData := (get $secretObj "data") | default dict }}
{{ range $key, $value := .Values.frontendEnvironmentVariables }}
{{- $default := get $requiredVars $key -}}
{{- $current := get $secretData $key | b64dec -}}
{{- $v := $value | default ($current | default $default) -}}
{{ $key }}: {{ $v | quote }}
{{ end -}}
{{- end }}
+4 -11
View File
@@ -30,27 +30,20 @@ spec:
rules: rules:
- http: - http:
paths: paths:
- path: {{ $ingress.frontend.path }} - path: /
pathType: {{ $ingress.frontend.pathType }} pathType: Prefix
backend:
service:
name: {{ include "infisical.frontend.fullname" . }}
port:
number: 3000
- path: {{ $ingress.backend.path }}
pathType: {{ $ingress.backend.pathType }}
backend: backend:
service: service:
name: {{ include "infisical.backend.fullname" . }} name: {{ include "infisical.backend.fullname" . }}
port: port:
number: 4000 number: 8080
- path: /ss-webhook - path: /ss-webhook
pathType: Exact pathType: Exact
backend: backend:
service: service:
name: {{ include "infisical.backend.fullname" . }} name: {{ include "infisical.backend.fullname" . }}
port: port:
number: 4000 number: 8080
{{- if $ingress.hostName }} {{- if $ingress.hostName }}
host: {{ $ingress.hostName }} host: {{ $ingress.hostName }}
{{- end }} {{- end }}
+1 -89
View File
@@ -8,76 +8,6 @@ nameOverride: ""
## ##
fullnameOverride: "" fullnameOverride: ""
## @section Infisical frontend parameters
## Documentation : https://infisical.com/docs/self-hosting/deployments/kubernetes
##
frontend:
## @param frontend.enabled Enable frontend
##
enabled: true
## @param frontend.name Frontend name
##
name: frontend
## @param frontend.fullnameOverride Frontend fullnameOverride
##
fullnameOverride: ""
## @param frontend.podAnnotations Frontend pod annotations
##
podAnnotations: {}
## @param frontend.deploymentAnnotations Frontend deployment annotations
##
deploymentAnnotations: {}
## @param frontend.replicaCount Frontend replica count
##
replicaCount: 2
## Frontend image parameters
##
image:
## @param frontend.image.repository Frontend image repository
##
repository: infisical/frontend
## @param frontend.image.tag Frontend image tag
##
tag: "latest"
## @param frontend.image.pullPolicy Frontend image pullPolicy
##
pullPolicy: IfNotPresent
## @param frontend.resources.limits.memory container memory limit [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
## @param frontend.resources.requests.cpu container CPU request [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
##
resources:
limits:
memory: 100Mi
requests:
cpu: 100m
## @param frontend.affinity Frontend pod affinity
##
affinity: {}
## @param frontend.kubeSecretRef Backend secret resource reference name (containing required [frontend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars))
##
kubeSecretRef: ""
## Frontend service
##
service:
## @param frontend.service.annotations Backend service annotations
##
annotations: {}
## @param frontend.service.type Backend service type
##
type: ClusterIP
## @param frontend.service.nodePort Backend service nodePort (used if above type is `NodePort`)
##
nodePort: ""
## Frontend variables configuration
## Documentation : https://infisical.com/docs/self-hosting/configuration/envars
##
frontendEnvironmentVariables:
## @param frontendEnvironmentVariables.SITE_URL Absolute URL including the protocol (e.g. https://app.infisical.com)
##
SITE_URL: infisical.local
## @section Infisical backend parameters ## @section Infisical backend parameters
## Documentation : https://infisical.com/docs/self-hosting/deployments/kubernetes ## Documentation : https://infisical.com/docs/self-hosting/deployments/kubernetes
## ##
@@ -106,21 +36,13 @@ backend:
image: image:
## @param backend.image.repository Backend image repository ## @param backend.image.repository Backend image repository
## ##
repository: infisical/backend repository: infisical/infisical
## @param backend.image.tag Backend image tag ## @param backend.image.tag Backend image tag
## ##
tag: "latest" tag: "latest"
## @param backend.image.pullPolicy Backend image pullPolicy ## @param backend.image.pullPolicy Backend image pullPolicy
## ##
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
## @param backend.resources.limits.memory container memory limit [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
## @param backend.resources.requests.cpu container CPU request [check the offical kubernetes documentations](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/)
##
resources:
limits:
memory: 200Mi
requests:
cpu: 150m
## @param backend.affinity Backend pod affinity ## @param backend.affinity Backend pod affinity
## ##
affinity: {} affinity: {}
@@ -349,16 +271,6 @@ ingress:
## Replace with your own domain ## Replace with your own domain
## ##
hostName: "" hostName: ""
## @skip ingress.frontend
##
frontend:
path: /
pathType: Prefix
## @skip ingress.backend
##
backend:
path: /api
pathType: Prefix
## @param ingress.tls Ingress TLS hosts (matching above hostName) ## @param ingress.tls Ingress TLS hosts (matching above hostName)
## Replace with your own domain ## Replace with your own domain
## ##