complete helm chart without DB

This commit is contained in:
Maidul Islam
2022-12-04 17:57:28 -05:00
parent 57762ab73c
commit 89c625750a
9 changed files with 61 additions and 221 deletions
@@ -1,62 +0,0 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "infisical.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "infisical.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "infisical.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "infisical.labels" -}}
helm.sh/chart: {{ include "infisical.chart" . }}
{{ include "infisical.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "infisical.selectorLabels" -}}
app.kubernetes.io/name: {{ include "infisical.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "infisical.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "infisical.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}
@@ -1,9 +1,10 @@
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: infisical-backend name: {{ .Release.Name }}-backend-deployment
labels: labels:
app: backend app: backend
namespace: {{ .Values.namespace }}
spec: spec:
replicas: {{ .Values.backend.replicaCount }} replicas: {{ .Values.backend.replicaCount }}
selector: selector:
@@ -17,15 +18,21 @@ spec:
containers: containers:
- name: backend - name: backend
image: infisical/backend image: infisical/backend
imagePullPolicy: {{ .Values.backend.image.pullPolicy }}
ports: ports:
- containerPort: 4000 - containerPort: 4000
env: env:
{{- range $key, $value := .Values.secrets }}
- name: {{ $key }}
value: {{ $value }}
{{- end }}
--- ---
apiVersion: v1 apiVersion: v1
kind: Service kind: Service
metadata: metadata:
name: infisical-backend-service name: infisical-backend-service
namespace: {{ .Values.namespace }}
spec: spec:
selector: selector:
app: backend app: backend
@@ -1,61 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "infisical.fullname" . }}
labels:
{{- include "infisical.labels" . | nindent 4 }}
spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "infisical.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "infisical.selectorLabels" . | nindent 8 }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "infisical.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
protocol: TCP
livenessProbe:
httpGet:
path: /
port: http
readinessProbe:
httpGet:
path: /
port: http
resources:
{{- toYaml .Values.resources | nindent 12 }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
@@ -1,9 +1,10 @@
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: infisical-frontend name: {{ .Release.Name }}-frontend-deployment
labels: labels:
app: frontend app: frontend
namespace: {{ .Values.namespace }}
spec: spec:
replicas: {{ .Values.frontend.replicaCount }} replicas: {{ .Values.frontend.replicaCount }}
selector: selector:
@@ -17,6 +18,7 @@ spec:
containers: containers:
- name: frontend - name: frontend
image: infisical/frontend image: infisical/frontend
imagePullPolicy: {{ .Values.frontend.image.pullPolicy }}
ports: ports:
- containerPort: 4000 - containerPort: 4000
--- ---
@@ -24,6 +26,7 @@ apiVersion: v1
kind: Service kind: Service
metadata: metadata:
name: infisical-frontend-service name: infisical-frontend-service
namespace: {{ .Values.namespace }}
spec: spec:
selector: selector:
app: frontend app: frontend
+14 -37
View File
@@ -1,31 +1,13 @@
{{- if .Values.ingress.enabled -}}
{{- $fullName := include "infisical.fullname" . -}}
{{- $svcPort := .Values.service.port -}}
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
{{- end }}
{{- end }}
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
apiVersion: networking.k8s.io/v1 apiVersion: networking.k8s.io/v1
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
apiVersion: networking.k8s.io/v1beta1
{{- else -}}
apiVersion: extensions/v1beta1
{{- end }}
kind: Ingress kind: Ingress
metadata: metadata:
name: {{ $fullName }} name: infisical-ingress
labels: namespace: {{ .Values.namespace }}
{{- include "infisical.labels" . | nindent 4 }}
{{- with .Values.ingress.annotations }} {{- with .Values.ingress.annotations }}
annotations: annotations:
{{- toYaml . | nindent 4 }} {{- toYaml . | nindent 4 }}
{{- end }} {{- end }}
spec: spec:
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
ingressClassName: {{ .Values.ingress.className }}
{{- end }}
{{- if .Values.ingress.tls }} {{- if .Values.ingress.tls }}
tls: tls:
{{- range .Values.ingress.tls }} {{- range .Values.ingress.tls }}
@@ -37,25 +19,20 @@ spec:
{{- end }} {{- end }}
{{- end }} {{- end }}
rules: rules:
{{- range .Values.ingress.hosts }} - host: {{ .Values.ingress.hostName}}
- host: {{ .host | quote }}
http: http:
paths: paths:
{{- range .paths }} - path: /
- path: {{ .path }} pathType: Prefix
{{- if and .pathType (semverCompare ">=1.18-0" $.Capabilities.KubeVersion.GitVersion) }}
pathType: {{ .pathType }}
{{- end }}
backend: backend:
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.GitVersion }}
service: service:
name: {{ $fullName }} name: infisical-frontend-service
port: port:
number: {{ $svcPort }} number: 3000
{{- else }} - path: /api
serviceName: {{ $fullName }} pathType: Prefix
servicePort: {{ $svcPort }} backend:
{{- end }} service:
{{- end }} name: infisical-backend-service
{{- end }} port:
{{- end }} number: 4000
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: infisical
@@ -1,10 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: {{ .Values.secrets.name | default infisicalSecrets }}
type: {{ .Values.secrets.type }}
data:
{{- range $key, $val := .Values.secrets.all }}
{{"SECRET_"}}{{ $key }}: {{ $val | b64enc | quote }}
{{- end}}
@@ -1,15 +0,0 @@
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "infisical.fullname" . }}-test-connection"
labels:
{{- include "infisical.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "infisical.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never
+21 -24
View File
@@ -1,39 +1,36 @@
# Default values for Infisical namespace: infisical
frontend: frontend:
replicaCount: 1 replicaCount: 1
image: image:
repository: repository:
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion. tag: "latest"
tag: ""
backend: backend:
replicaCount: 1 replicaCount: 1
image: image:
repository: repository:
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion. tag: "latest"
tag: ""
ingress: ingress:
enabled: false enabled: false
className: "" annotations: []
annotations: {} hostName: example.com
# kubernetes.io/ingress.class: nginx tls: {}
# kubernetes.io/tls-acme: "true"
hosts: secrets:
- host: chart-example.local PRIVATE_KEY: REQUIRED
paths: PUBLIC_KEY: REQUIRED
- path: / ENCRYPTION_KEY: REQUIRED
pathType: ImplementationSpecific JWT_SIGNUP_SECRET: REQUIRED
tls: [] JWT_REFRESH_SECRET: REQUIRED
# - secretName: chart-example-tls JWT_AUTH_SECRET: REQUIRED
# hosts: NODE_ENV: development
# - chart-example.local SMTP_HOST: REQUIRED
SMTP_NAME: REQUIRED
SMTP_USERNAME: REQUIRED
SMTP_PASSWORD: REQUIRED
MONGO_URL: REQUIRED
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80