complete helm chart without DB

This commit is contained in:
Maidul Islam
2022-12-04 17:57:28 -05:00
parent 57762ab73c
commit 89c625750a
9 changed files with 61 additions and 221 deletions
@@ -1,62 +0,0 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "infisical.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "infisical.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}
{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "infisical.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}
{{/*
Common labels
*/}}
{{- define "infisical.labels" -}}
helm.sh/chart: {{ include "infisical.chart" . }}
{{ include "infisical.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}
{{/*
Selector labels
*/}}
{{- define "infisical.selectorLabels" -}}
app.kubernetes.io/name: {{ include "infisical.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}
{{/*
Create the name of the service account to use
*/}}
{{- define "infisical.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "infisical.fullname" .) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}
@@ -1,9 +1,10 @@
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: infisical-backend name: {{ .Release.Name }}-backend-deployment
labels: labels:
app: backend app: backend
namespace: {{ .Values.namespace }}
spec: spec:
replicas: {{ .Values.backend.replicaCount }} replicas: {{ .Values.backend.replicaCount }}
selector: selector:
@@ -17,15 +18,21 @@ spec:
containers: containers:
- name: backend - name: backend
image: infisical/backend image: infisical/backend
imagePullPolicy: {{ .Values.backend.image.pullPolicy }}
ports: ports:
- containerPort: 4000 - containerPort: 4000
env: env:
{{- range $key, $value := .Values.secrets }}
- name: {{ $key }}
value: {{ $value }}
{{- end }}
--- ---
apiVersion: v1 apiVersion: v1
kind: Service kind: Service
metadata: metadata:
name: infisical-backend-service name: infisical-backend-service
namespace: {{ .Values.namespace }}
spec: spec:
selector: selector:
app: backend app: backend
@@ -1,61 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "infisical.fullname" . }}
labels:
{{- include "infisical.labels" . | nindent 4 }}
spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "infisical.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "infisical.selectorLabels" . | nindent 8 }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
serviceAccountName: {{ include "infisical.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.securityContext | nindent 12 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
ports:
- name: http
containerPort: {{ .Values.service.port }}
protocol: TCP
livenessProbe:
httpGet:
path: /
port: http
readinessProbe:
httpGet:
path: /
port: http
resources:
{{- toYaml .Values.resources | nindent 12 }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
@@ -1,9 +1,10 @@
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: infisical-frontend name: {{ .Release.Name }}-frontend-deployment
labels: labels:
app: frontend app: frontend
namespace: {{ .Values.namespace }}
spec: spec:
replicas: {{ .Values.frontend.replicaCount }} replicas: {{ .Values.frontend.replicaCount }}
selector: selector:
@@ -17,6 +18,7 @@ spec:
containers: containers:
- name: frontend - name: frontend
image: infisical/frontend image: infisical/frontend
imagePullPolicy: {{ .Values.frontend.image.pullPolicy }}
ports: ports:
- containerPort: 4000 - containerPort: 4000
--- ---
@@ -24,6 +26,7 @@ apiVersion: v1
kind: Service kind: Service
metadata: metadata:
name: infisical-frontend-service name: infisical-frontend-service
namespace: {{ .Values.namespace }}
spec: spec:
selector: selector:
app: frontend app: frontend
+24 -47
View File
@@ -1,61 +1,38 @@
{{- if .Values.ingress.enabled -}}
{{- $fullName := include "infisical.fullname" . -}}
{{- $svcPort := .Values.service.port -}}
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
{{- end }}
{{- end }}
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
apiVersion: networking.k8s.io/v1 apiVersion: networking.k8s.io/v1
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
apiVersion: networking.k8s.io/v1beta1
{{- else -}}
apiVersion: extensions/v1beta1
{{- end }}
kind: Ingress kind: Ingress
metadata: metadata:
name: {{ $fullName }} name: infisical-ingress
labels: namespace: {{ .Values.namespace }}
{{- include "infisical.labels" . | nindent 4 }}
{{- with .Values.ingress.annotations }} {{- with .Values.ingress.annotations }}
annotations: annotations:
{{- toYaml . | nindent 4 }} {{- toYaml . | nindent 4 }}
{{- end }} {{- end }}
spec: spec:
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }} {{- if .Values.ingress.tls }}
ingressClassName: {{ .Values.ingress.className }}
{{- end }}
{{- if .Values.ingress.tls }}
tls: tls:
{{- range .Values.ingress.tls }} {{- range .Values.ingress.tls }}
- hosts: - hosts:
{{- range .hosts }} {{- range .hosts }}
- {{ . | quote }} - {{ . | quote }}
{{- end }} {{- end }}
secretName: {{ .secretName }} secretName: {{ .secretName }}
{{- end }}
{{- end }} {{- end }}
rules:
{{- range .Values.ingress.hosts }}
- host: {{ .host | quote }}
http:
paths:
{{- range .paths }}
- path: {{ .path }}
{{- if and .pathType (semverCompare ">=1.18-0" $.Capabilities.KubeVersion.GitVersion) }}
pathType: {{ .pathType }}
{{- end }}
backend:
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.GitVersion }}
service:
name: {{ $fullName }}
port:
number: {{ $svcPort }}
{{- else }}
serviceName: {{ $fullName }}
servicePort: {{ $svcPort }}
{{- end }}
{{- end }}
{{- end }}
{{- end }} {{- end }}
rules:
- host: {{ .Values.ingress.hostName}}
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: infisical-frontend-service
port:
number: 3000
- path: /api
pathType: Prefix
backend:
service:
name: infisical-backend-service
port:
number: 4000
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: infisical
@@ -1,10 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: {{ .Values.secrets.name | default infisicalSecrets }}
type: {{ .Values.secrets.type }}
data:
{{- range $key, $val := .Values.secrets.all }}
{{"SECRET_"}}{{ $key }}: {{ $val | b64enc | quote }}
{{- end}}
@@ -1,15 +0,0 @@
apiVersion: v1
kind: Pod
metadata:
name: "{{ include "infisical.fullname" . }}-test-connection"
labels:
{{- include "infisical.labels" . | nindent 4 }}
annotations:
"helm.sh/hook": test
spec:
containers:
- name: wget
image: busybox
command: ['wget']
args: ['{{ include "infisical.fullname" . }}:{{ .Values.service.port }}']
restartPolicy: Never
+21 -24
View File
@@ -1,39 +1,36 @@
# Default values for Infisical namespace: infisical
frontend: frontend:
replicaCount: 1 replicaCount: 1
image: image:
repository: repository:
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion. tag: "latest"
tag: ""
backend: backend:
replicaCount: 1 replicaCount: 1
image: image:
repository: repository:
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion. tag: "latest"
tag: ""
ingress: ingress:
enabled: false enabled: false
className: "" annotations: []
annotations: {} hostName: example.com
# kubernetes.io/ingress.class: nginx tls: {}
# kubernetes.io/tls-acme: "true"
hosts:
- host: chart-example.local
paths:
- path: /
pathType: ImplementationSpecific
tls: []
# - secretName: chart-example-tls
# hosts:
# - chart-example.local
autoscaling: secrets:
enabled: false PRIVATE_KEY: REQUIRED
minReplicas: 1 PUBLIC_KEY: REQUIRED
maxReplicas: 100 ENCRYPTION_KEY: REQUIRED
targetCPUUtilizationPercentage: 80 JWT_SIGNUP_SECRET: REQUIRED
# targetMemoryUtilizationPercentage: 80 JWT_REFRESH_SECRET: REQUIRED
JWT_AUTH_SECRET: REQUIRED
NODE_ENV: development
SMTP_HOST: REQUIRED
SMTP_NAME: REQUIRED
SMTP_USERNAME: REQUIRED
SMTP_PASSWORD: REQUIRED
MONGO_URL: REQUIRED