Compare commits
263 Commits
754c43340e
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| f1729cf88a | |||
| bee8d80b31 | |||
| ed95412e3e | |||
| d70752a12d | |||
| 5bb43fa8a3 | |||
| 5cd3341aec | |||
| 06ddca1f27 | |||
| 51ad120eb7 | |||
| 15dbbe9c54 | |||
| 2606b44dd8 | |||
| 89c91cf21b | |||
| 4dc9965839 | |||
| f5cfd5782c | |||
| ecf698b408 | |||
| d0978e6560 | |||
| e3275286a8 | |||
| 1e2242d272 | |||
| b2cf38ffb5 | |||
| 19951f4930 | |||
| bd9c047840 | |||
| 7e5f808217 | |||
| 617322bcb2 | |||
| 783ec3b045 | |||
| b021f0d615 | |||
| 5218277fe6 | |||
| 183e009202 | |||
| 4e94c71a19 | |||
| 92a8b0ea1a | |||
| 26f39de220 | |||
| 19e4ca4336 | |||
| 115ba76e37 | |||
| 973ec7adc8 | |||
| 5e91362308 | |||
| cac925e192 | |||
|
756e348765
|
|||
| 2812fdffcb | |||
| ab9ea26b2a | |||
| baa8ee8d0d | |||
| 2e2692d874 | |||
| c73c9967b4 | |||
| 50af593199 | |||
|
000469e532
|
|||
| 9d558b6a41 | |||
| 6c98ac5557 | |||
| 3814651b0a | |||
| cbd6ae7a63 | |||
| a531bbc8fc | |||
| 4c6d48d7c0 | |||
|
4b8744ba9b
|
|||
|
7133fc0bce
|
|||
|
21edfd013b
|
|||
| 059716b051 | |||
|
5eb48c1780
|
|||
| 16e18559a7 | |||
| 7eb5955522 | |||
| 211c6e6457 | |||
| 11fe3a56ed | |||
| e370d886e4 | |||
| a4f1bb387d | |||
|
a18068049c
|
|||
|
893e4dcdcd
|
|||
| 69e567019a | |||
|
83ae01546e
|
|||
| dda824ed85 | |||
| d9cf9933b5 | |||
| e77df9141a | |||
| 41b487d74e | |||
| 00b485e1d9 | |||
| dfd4f10a25 | |||
| 952c740694 | |||
| 2b3309d08b | |||
| 09e133dce6 | |||
|
1d9f190374
|
|||
| 07f5a9f744 | |||
| 49c246784d | |||
|
45abe7cb15
|
|||
| 24c511cf5c | |||
| cda969c82e | |||
| 0f1f4fceae | |||
| 3e74fdd963 | |||
| 63ab99c97e | |||
| ae66189fd6 | |||
| 70aa5ba32c | |||
| 2acc12539e | |||
| 67ab70be5e | |||
| 7523585b38 | |||
| a2c68d21f7 | |||
| 6e3c50a62a | |||
| 991a107065 | |||
| 6855804559 | |||
| 7116704004 | |||
| 7aa84c9a7a | |||
| df991298d7 | |||
| 986b27f0d5 | |||
| eee3baddde | |||
| 668a091ccd | |||
| 6ae696821d | |||
| 61735b1796 | |||
| 8d4bf9b40f | |||
| 897cdab3e8 | |||
| 1469c919fa | |||
| 18fe759b4c | |||
| 51be442112 | |||
| 4b03368b12 | |||
| 13695b5f7b | |||
| 3c8d2c6915 | |||
| 86fc433317 | |||
| 0c353cff7d | |||
| 928bede6fd | |||
| 292cb42d7a | |||
| 674c448840 | |||
| cccd3dd7d5 | |||
| 68faa18141 | |||
| 7ce4e513bd | |||
| 7851dcb703 | |||
| 49d2b4fdbb | |||
| a3581a2365 | |||
| 971d33ff97 | |||
| a7e439c11d | |||
| 015b9d5833 | |||
| 624743d7d1 | |||
| 60168571fe | |||
| 1ed8bc13a1 | |||
|
95a8d3291a
|
|||
| 3de27b278b | |||
|
0e8585572c
|
|||
|
24f1f2fd2c
|
|||
|
8e410f761a
|
|||
| 16178cf2d6 | |||
| 15fe5001b2 | |||
| be09398708 | |||
| 06a7d1b923 | |||
| 5b868f2c5c | |||
| b4a0195b23 | |||
| b5ee9f199b | |||
| 6357a0908d | |||
| eb7d30ca6c | |||
| 15ef00e534 | |||
| 00657dcd34 | |||
| aad04e120b | |||
|
59d8e157e2
|
|||
| b7a4c814b3 | |||
| 5de65dd94b | |||
| 560d199980 | |||
|
c548b3e15f
|
|||
|
b5c24dc26f
|
|||
| 7369ad3c8a | |||
| d0f54c9033 | |||
| 2badb27df6 | |||
| a446325956 | |||
| eff44720a4 | |||
| 235fc7b95b | |||
| ddcf43420e | |||
| e46b148a8f | |||
| 8888bf63d9 | |||
| cd2983c683 | |||
| c684615012 | |||
| ad9bb1eaf9 | |||
| 658d09c113 | |||
| 1ffcdca37e | |||
| 5be14ba40d | |||
| df7c242782 | |||
| 0344d7207c | |||
| c51971f31e | |||
| f7d6f95fa2 | |||
| d26d1f13b3 | |||
| d4db2c5fe4 | |||
| 55d65c6537 | |||
| 08e28d5d1a | |||
| 06ecb840c5 | |||
| f71a42850f | |||
| a00b2bc41d | |||
| 47131ab623 | |||
| 460e91e89c | |||
| 9a6c286256 | |||
| 282cd9286f | |||
| b27a419158 | |||
| a7ccd3b123 | |||
| d4e0d09fa9 | |||
| 323b710a0b | |||
| 626d9125fa | |||
| 41dd40c7b6 | |||
| 5f3a97c525 | |||
| b5468a1100 | |||
| f07ac5158c | |||
| 892e326a8d | |||
| 4dda76f6a5 | |||
| 3f255816b1 | |||
| 9477342a70 | |||
| 3f6e99c34f | |||
| 5c72985801 | |||
|
8a88f21e14
|
|||
| bd3bbf66ec | |||
|
dac7f16f04
|
|||
| acf97bb584 | |||
| 9fccca2284 | |||
| dede8518f2 | |||
|
7d26a7ec39
|
|||
| 3ba39a584e | |||
| bff34addae | |||
|
421c7b4a7c
|
|||
|
e09f1c19ce
|
|||
|
a5498c0954
|
|||
|
3cc00d5a83
|
|||
|
06960f3a1d
|
|||
|
ec5e227994
|
|||
|
78fb7c27d9
|
|||
|
dfe6fa412b
|
|||
| 9ec7603348 | |||
|
026f6dccb8
|
|||
|
d3c3ba2191
|
|||
| ab9bb43beb | |||
| d46bbca804 | |||
| 50e5a2952e | |||
| 764a922dbe | |||
| 288a474c85 | |||
| 3a4bb4d0d7 | |||
| 836b1078fb | |||
| c9f9d78d32 | |||
| 67e179a494 | |||
|
750d11b021
|
|||
| d7607dcde3 | |||
| aa3fa4e5fb | |||
| f37a6a4ef1 | |||
| 784d1bc983 | |||
| 141151a00b | |||
| 29d147c304 | |||
| 83728881d7 | |||
|
009890e282
|
|||
| 1d2f4d3e2d | |||
|
7bb2d3c8b6
|
|||
|
abf3348f01
|
|||
|
eddd083cd0
|
|||
|
e2a6ec8cf5
|
|||
|
78e2acf660
|
|||
|
abb0398024
|
|||
|
6f19c8007f
|
|||
|
35dd11d3a0
|
|||
|
5343526316
|
|||
|
24cb34c148
|
|||
| d6e8622d3e | |||
| 5930c714c3 | |||
| e5fbce570f | |||
| e9e08cd8c4 | |||
| 63b9402351 | |||
| a4b28d5f47 | |||
|
9020797b65
|
|||
| 20c8eb60aa | |||
|
3ba4c25906
|
|||
|
ebe80fcef4
|
|||
|
67d3ea0919
|
|||
|
9566f84266
|
|||
|
29c01eba3a
|
|||
| ceaa394088 | |||
| ec931f86d6 | |||
| 8f67789af6 | |||
| bc4b4079f2 | |||
| 952ed4a075 | |||
| 7dec0dbd30 | |||
| 24b7133646 | |||
| 9a6ee23ff4 | |||
| 10542a23bf | |||
| f0dccf7df8 |
@@ -4,10 +4,10 @@ description: Atlantis map and simulation service
|
|||||||
type: application
|
type: application
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
# to the chart and its templates, including the app version.
|
# to the chart and its templates, including the app version.
|
||||||
version: v1.42.29
|
version: v2.24.9
|
||||||
# This is the version number of the application being deployed. This version number should be
|
# This is the version number of the application being deployed. This version number should be
|
||||||
# incremented each time you make changes to the application.
|
# incremented each time you make changes to the application.
|
||||||
appVersion: v1.42.29
|
appVersion: v2.24.9
|
||||||
dependencies:
|
dependencies:
|
||||||
- name: diagrid-dashboard
|
- name: diagrid-dashboard
|
||||||
version: "0.1.0"
|
version: "0.1.0"
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
image:
|
image:
|
||||||
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
|
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
|
||||||
tag: v1.42.29
|
tag: v2.24.9
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
init:
|
init:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|||||||
@@ -13,9 +13,9 @@ type: application
|
|||||||
# This is the chart version. This version number should be incremented each time you make changes
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
# to the chart and its templates, including the app version.
|
# to the chart and its templates, including the app version.
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
version: v1.42.29
|
version: v2.24.9
|
||||||
# This is the version number of the application being deployed. This version number should be
|
# This is the version number of the application being deployed. This version number should be
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
# It is recommended to use it with quotes.
|
# It is recommended to use it with quotes.
|
||||||
appVersion: "v1.42.29"
|
appVersion: "v2.24.9"
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ image:
|
|||||||
# This sets the pull policy for images.
|
# This sets the pull policy for images.
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
# Overrides the image tag whose default is the chart appVersion.
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
tag: v1.42.29
|
tag: v2.24.9
|
||||||
# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
- name: gitlab-pull-secret
|
- name: gitlab-pull-secret
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: proteus
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
type: application
|
||||||
|
version: v2.24.9
|
||||||
|
appVersion: "v2.24.9"
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
{{- if eq .Values.environment "prod" }}
|
||||||
|
apiVersion: temporal.io/v1alpha1
|
||||||
|
kind: WorkerResourceTemplate
|
||||||
|
metadata:
|
||||||
|
name: proteus-prod-hpa
|
||||||
|
namespace: proteus
|
||||||
|
spec:
|
||||||
|
workerDeploymentRef:
|
||||||
|
name: proteus-prod
|
||||||
|
template:
|
||||||
|
apiVersion: autoscaling/v2
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
spec:
|
||||||
|
scaleTargetRef: {} # NOTE: controller injects the versioned Deployment
|
||||||
|
minReplicas: 2
|
||||||
|
maxReplicas: 10
|
||||||
|
metrics:
|
||||||
|
- type: External
|
||||||
|
external:
|
||||||
|
metric:
|
||||||
|
name: temporal_approximate_backlog_count
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
task_type: "Activity"
|
||||||
|
target:
|
||||||
|
type: AverageValue
|
||||||
|
averageValue: "2"
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
target:
|
||||||
|
type: Utilization
|
||||||
|
averageUtilization: 70
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if eq .Values.environment "beta" }}
|
||||||
|
apiVersion: temporal.io/v1alpha1
|
||||||
|
kind: WorkerResourceTemplate
|
||||||
|
metadata:
|
||||||
|
name: proteus-beta-hpa
|
||||||
|
namespace: proteus
|
||||||
|
spec:
|
||||||
|
workerDeploymentRef:
|
||||||
|
name: proteus-beta
|
||||||
|
template:
|
||||||
|
apiVersion: autoscaling/v2
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
spec:
|
||||||
|
scaleTargetRef: {}
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 2
|
||||||
|
metrics:
|
||||||
|
- type: External
|
||||||
|
external:
|
||||||
|
metric:
|
||||||
|
name: temporal_approximate_backlog_count
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
task_type: "Activity"
|
||||||
|
target:
|
||||||
|
type: AverageValue
|
||||||
|
averageValue: "2"
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
target:
|
||||||
|
type: Utilization
|
||||||
|
averageUtilization: 70
|
||||||
|
{{- end }}
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
|
{{- if eq .Values.environment "prod" }}
|
||||||
apiVersion: temporal.io/v1alpha1
|
apiVersion: temporal.io/v1alpha1
|
||||||
kind: Connection
|
kind: Connection
|
||||||
metadata:
|
metadata:
|
||||||
@@ -5,3 +6,4 @@ metadata:
|
|||||||
namespace: proteus
|
namespace: proteus
|
||||||
spec:
|
spec:
|
||||||
hostPort: temporal-frontend.temporal:7233
|
hostPort: temporal-frontend.temporal:7233
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{{- if eq .Values.environment "prod" }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolume
|
||||||
|
metadata:
|
||||||
|
name: pv-proteus-ceph-archives
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteMany
|
||||||
|
capacity:
|
||||||
|
storage: 1Gi
|
||||||
|
csi:
|
||||||
|
driver: rook-ceph.cephfs.csi.ceph.com
|
||||||
|
nodeStageSecretRef:
|
||||||
|
name: rook-csi-cephfs-node
|
||||||
|
namespace: rook-ceph
|
||||||
|
volumeAttributes:
|
||||||
|
clusterID: rook-ceph
|
||||||
|
fsName: data
|
||||||
|
rootPath: /
|
||||||
|
staticVolume: "true"
|
||||||
|
volumeHandle: pv-proteus-ceph-archives
|
||||||
|
persistentVolumeReclaimPolicy: Retain
|
||||||
|
volumeMode: Filesystem
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: proteus-ceph-archives
|
||||||
|
namespace: proteus
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteMany
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 1Gi
|
||||||
|
storageClassName: ""
|
||||||
|
volumeMode: Filesystem
|
||||||
|
volumeName: pv-proteus-ceph-archives
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,204 @@
|
|||||||
|
{{- if eq .Values.environment "prod" }}
|
||||||
|
apiVersion: temporal.io/v1alpha1
|
||||||
|
kind: WorkerDeployment
|
||||||
|
metadata:
|
||||||
|
name: proteus-prod
|
||||||
|
namespace: proteus
|
||||||
|
spec:
|
||||||
|
replicas: 2
|
||||||
|
workerOptions:
|
||||||
|
temporalNamespace: prod-atlantis
|
||||||
|
connectionRef:
|
||||||
|
name: temporal
|
||||||
|
rollout:
|
||||||
|
strategy: AllAtOnce
|
||||||
|
sunset: {}
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
runAsGroup: 0
|
||||||
|
volumes:
|
||||||
|
- name: archives
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: proteus-ceph-archives
|
||||||
|
containers:
|
||||||
|
- name: proteus
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: "1"
|
||||||
|
memory: 1Gi
|
||||||
|
limits:
|
||||||
|
cpu: "2"
|
||||||
|
memory: 4Gi
|
||||||
|
env:
|
||||||
|
- name: TEMPORAL_TASK_QUEUES
|
||||||
|
value: plume,xtract
|
||||||
|
- name: TEMPORAL_NAMESPACE
|
||||||
|
value: prod-atlantis
|
||||||
|
- name: APP_ENV
|
||||||
|
value: prod
|
||||||
|
- name: ARCHIVE_PVC
|
||||||
|
value: prod-queue-ceph-archives
|
||||||
|
- name: MAX_CONCURRENT_ACTIVITIES
|
||||||
|
value: "2"
|
||||||
|
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||||
|
value: http://10.255.241.12:4317
|
||||||
|
volumeMounts:
|
||||||
|
- name: archives
|
||||||
|
mountPath: /data
|
||||||
|
ports:
|
||||||
|
- name: health
|
||||||
|
containerPort: 8080
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 6
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /readyz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if eq .Values.environment "beta" }}
|
||||||
|
apiVersion: temporal.io/v1alpha1
|
||||||
|
kind: WorkerDeployment
|
||||||
|
metadata:
|
||||||
|
name: proteus-beta
|
||||||
|
namespace: proteus
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
workerOptions:
|
||||||
|
temporalNamespace: beta-atlantis
|
||||||
|
connectionRef:
|
||||||
|
name: temporal
|
||||||
|
rollout:
|
||||||
|
strategy: AllAtOnce
|
||||||
|
sunset: {}
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
runAsGroup: 0
|
||||||
|
volumes:
|
||||||
|
- name: archives
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: proteus-ceph-archives
|
||||||
|
containers:
|
||||||
|
- name: proteus
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 256Mi
|
||||||
|
env:
|
||||||
|
- name: TEMPORAL_TASK_QUEUES
|
||||||
|
value: plume,xtract
|
||||||
|
- name: TEMPORAL_NAMESPACE
|
||||||
|
value: beta-atlantis
|
||||||
|
- name: APP_ENV
|
||||||
|
value: beta
|
||||||
|
- name: ARCHIVE_PVC
|
||||||
|
value: prod-queue-ceph-archives
|
||||||
|
- name: MAX_CONCURRENT_ACTIVITIES
|
||||||
|
value: "2"
|
||||||
|
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||||
|
value: http://10.255.241.12:4317
|
||||||
|
volumeMounts:
|
||||||
|
- name: archives
|
||||||
|
mountPath: /data
|
||||||
|
ports:
|
||||||
|
- name: health
|
||||||
|
containerPort: 8080
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 6
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /readyz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if eq .Values.environment "staging" }}
|
||||||
|
apiVersion: temporal.io/v1alpha1
|
||||||
|
kind: WorkerDeployment
|
||||||
|
metadata:
|
||||||
|
name: proteus-staging
|
||||||
|
namespace: proteus
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
workerOptions:
|
||||||
|
temporalNamespace: staging-atlantis
|
||||||
|
connectionRef:
|
||||||
|
name: temporal
|
||||||
|
rollout:
|
||||||
|
strategy: AllAtOnce
|
||||||
|
sunset: {}
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
runAsGroup: 0
|
||||||
|
volumes:
|
||||||
|
- name: archives
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: proteus-ceph-archives
|
||||||
|
containers:
|
||||||
|
- name: proteus
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 256Mi
|
||||||
|
limits:
|
||||||
|
memory: 1Gi
|
||||||
|
env:
|
||||||
|
- name: TEMPORAL_TASK_QUEUES
|
||||||
|
value: plume,xtract
|
||||||
|
- name: TEMPORAL_NAMESPACE
|
||||||
|
value: staging-atlantis
|
||||||
|
- name: MAX_CONCURRENT_ACTIVITIES
|
||||||
|
value: "10"
|
||||||
|
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||||
|
value: http://10.255.241.12:4317
|
||||||
|
volumeMounts:
|
||||||
|
- name: archives
|
||||||
|
mountPath: /data
|
||||||
|
ports:
|
||||||
|
- name: health
|
||||||
|
containerPort: 8080
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 6
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /readyz
|
||||||
|
port: health
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 15
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
# Default values for proteus.
|
||||||
|
# This chart is installed three times, like atlantis: "proteus" (environment: prod, this
|
||||||
|
# file's defaults), "proteus-staging" (environment: staging, values-staging.yaml), and
|
||||||
|
# "proteus-beta" (environment: beta, values-beta.yaml). Each release has its own Values scope,
|
||||||
|
# so all three can use the plain `image` key without colliding — the publish-container CI action
|
||||||
|
# bumps .image.tag here directly on a tagged release (same convention as charts/atlantis/values.yaml)
|
||||||
|
# and bumps values-staging.yaml's .image.tag on every merge to main. Beta's tag is manually pinned,
|
||||||
|
# same as atlantis's values-beta.yaml.gotmpl.
|
||||||
|
image:
|
||||||
|
repository: git.oceanbox.io/oceanbox/poseidon/proteus
|
||||||
|
tag: "v2.24.9"
|
||||||
|
environment: prod
|
||||||
@@ -4,10 +4,10 @@ description: A Helm chart for Kubernetes
|
|||||||
type: application
|
type: application
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
# to the chart and its templates, including the app version.
|
# to the chart and its templates, including the app version.
|
||||||
version: v1.42.29
|
version: v2.24.9
|
||||||
# This is the version number of the application being deployed. This version number should be
|
# This is the version number of the application being deployed. This version number should be
|
||||||
# incremented each time you make changes to the application.
|
# incremented each time you make changes to the application.
|
||||||
appVersion: v1.42.29
|
appVersion: v2.24.9
|
||||||
dependencies:
|
dependencies:
|
||||||
- name: diagrid-dashboard
|
- name: diagrid-dashboard
|
||||||
version: "0.1.0"
|
version: "0.1.0"
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
image:
|
image:
|
||||||
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
|
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
|
||||||
tag: v1.42.29
|
tag: v2.24.9
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
init:
|
init:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ releases:
|
|||||||
- name: argocd
|
- name: argocd
|
||||||
namespace: argocd
|
namespace: argocd
|
||||||
chart: argo/argo-cd
|
chart: argo/argo-cd
|
||||||
version: 9.5.21
|
version: 9.7.1
|
||||||
condition: argo.enabled
|
condition: argo.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/argo/values/argocd.yaml.gotmpl
|
- ../values/argo/values/argocd.yaml.gotmpl
|
||||||
@@ -43,7 +43,7 @@ releases:
|
|||||||
- name: argo-workflows
|
- name: argo-workflows
|
||||||
namespace: argocd
|
namespace: argocd
|
||||||
chart: argo/argo-workflows
|
chart: argo/argo-workflows
|
||||||
version: 1.0.16
|
version: 1.0.23
|
||||||
condition: argo.workflows.enabled
|
condition: argo.workflows.enabled
|
||||||
missingFileHandler: Info
|
missingFileHandler: Info
|
||||||
- name: manifests
|
- name: manifests
|
||||||
|
|||||||
@@ -0,0 +1,53 @@
|
|||||||
|
bases:
|
||||||
|
- ../envs/environments.yaml.gotmpl
|
||||||
|
|
||||||
|
repositories:
|
||||||
|
- name: clickhouse
|
||||||
|
url: ghcr.io/clickhouse
|
||||||
|
oci: true
|
||||||
|
|
||||||
|
commonLabels:
|
||||||
|
tier: system
|
||||||
|
|
||||||
|
releases:
|
||||||
|
- name: clickhouse-operator
|
||||||
|
namespace: clickhouse
|
||||||
|
chart: clickhouse/clickhouse-operator-helm
|
||||||
|
version: 0.0.6
|
||||||
|
condition: clickhouse.enabled
|
||||||
|
values:
|
||||||
|
- ../values/clickhouse/values/operator.yaml.gotmpl
|
||||||
|
missingFileHandler: Info
|
||||||
|
- name: clickhouse-cluster
|
||||||
|
namespace: clickhouse
|
||||||
|
chart: clickhouse/clickhouse-cluster-helm
|
||||||
|
version: 0.0.6
|
||||||
|
condition: clickhouse.enabled
|
||||||
|
needs:
|
||||||
|
- clickhouse/clickhouse-operator
|
||||||
|
values:
|
||||||
|
- ../values/clickhouse/values/cluster.yaml.gotmpl
|
||||||
|
postRenderer: ../bin/kustomizer
|
||||||
|
postRendererArgs:
|
||||||
|
- ../values/clickhouse/kustomize/{{ .Environment.Name }}
|
||||||
|
missingFileHandler: Info
|
||||||
|
- name: manifests
|
||||||
|
namespace: clickhouse
|
||||||
|
chart: manifests
|
||||||
|
condition: clickhouse.enabled
|
||||||
|
missingFileHandler: Info
|
||||||
|
values:
|
||||||
|
- ../values/env.yaml
|
||||||
|
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
|
||||||
|
- ../values/clickhouse/env.yaml.gotmpl
|
||||||
|
- ../values/clickhouse/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
|
||||||
|
hooks:
|
||||||
|
- events: [ prepare, cleanup ]
|
||||||
|
showlogs: true
|
||||||
|
command: ../bin/helmify
|
||||||
|
args:
|
||||||
|
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
|
||||||
|
- '{{`{{ .Release.Chart }}`}}'
|
||||||
|
- '{{`{{ .Environment.Name }}`}}'
|
||||||
|
- ../values/clickhouse/manifests
|
||||||
|
- manifests
|
||||||
@@ -13,7 +13,7 @@ releases:
|
|||||||
- name: dragonfly
|
- name: dragonfly
|
||||||
namespace: dragonfly
|
namespace: dragonfly
|
||||||
chart: dragonfly/dragonfly-operator
|
chart: dragonfly/dragonfly-operator
|
||||||
version: v1.5.0
|
version: v1.6.1
|
||||||
condition: dragonfly.enabled
|
condition: dragonfly.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/dragonfly/values/dragonfly.yaml.gotmpl
|
- ../values/dragonfly/values/dragonfly.yaml.gotmpl
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ releases:
|
|||||||
- name: ingress-haproxy
|
- name: ingress-haproxy
|
||||||
namespace: ingress-haproxy
|
namespace: ingress-haproxy
|
||||||
chart: haproxytech/kubernetes-ingress
|
chart: haproxytech/kubernetes-ingress
|
||||||
version: 1.52.0
|
version: 1.52.1
|
||||||
condition: haproxy.enabled
|
condition: haproxy.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/ingress-haproxy/values/ingress-haproxy.yaml.gotmpl
|
- ../values/ingress-haproxy/values/ingress-haproxy.yaml.gotmpl
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ releases:
|
|||||||
- name: kueue
|
- name: kueue
|
||||||
namespace: kueue-system
|
namespace: kueue-system
|
||||||
chart: oci://registry.k8s.io/kueue/charts/kueue
|
chart: oci://registry.k8s.io/kueue/charts/kueue
|
||||||
version: 0.17.3
|
version: 0.18.1
|
||||||
condition: kueue.enabled
|
condition: kueue.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/kueue/values/values.yaml
|
- ../values/kueue/values/values.yaml
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ releases:
|
|||||||
namespace: {{ .Environment.Name }}-openfga
|
namespace: {{ .Environment.Name }}-openfga
|
||||||
{{- end }}
|
{{- end }}
|
||||||
chart: openfga/openfga
|
chart: openfga/openfga
|
||||||
version: 0.3.8
|
version: 0.3.10
|
||||||
condition: openfga.enabled
|
condition: openfga.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/openfga/values/values.yaml
|
- ../values/openfga/values/values.yaml
|
||||||
|
|||||||
@@ -12,10 +12,10 @@ releases:
|
|||||||
- name: opentelemetry-collector
|
- name: opentelemetry-collector
|
||||||
namespace: otel
|
namespace: otel
|
||||||
chart: open-telemetry/opentelemetry-collector
|
chart: open-telemetry/opentelemetry-collector
|
||||||
version: 0.158.1
|
version: 0.159.1
|
||||||
condition: otel.enabled
|
condition: otel.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/opentelemetry-collector/values/values.yaml
|
- ../values/opentelemetry-collector/values/values.yaml.gotmpl
|
||||||
- ../values/opentelemetry-collector/values/values-{{ .Environment.Name }}.yaml
|
- ../values/opentelemetry-collector/values/values-{{ .Environment.Name }}.yaml
|
||||||
postRenderer: ../bin/kustomizer
|
postRenderer: ../bin/kustomizer
|
||||||
postRendererArgs:
|
postRendererArgs:
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ releases:
|
|||||||
- name: plugin-barman-cloud
|
- name: plugin-barman-cloud
|
||||||
namespace: cnpg
|
namespace: cnpg
|
||||||
chart: cloudnative-pg/plugin-barman-cloud
|
chart: cloudnative-pg/plugin-barman-cloud
|
||||||
version: 0.6.0
|
version: 0.7.0
|
||||||
condition: postgres_operator.enabled
|
condition: postgres_operator.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/postgres-operator/values/plugin-barman-cloud.yaml.gotmpl
|
- ../values/postgres-operator/values/plugin-barman-cloud.yaml.gotmpl
|
||||||
|
|||||||
@@ -5,6 +5,27 @@ commonLabels:
|
|||||||
tier: system
|
tier: system
|
||||||
|
|
||||||
releases:
|
releases:
|
||||||
|
- name: proteus
|
||||||
|
namespace: proteus
|
||||||
|
chart: ../charts/proteus
|
||||||
|
condition: proteus.enabled
|
||||||
|
values:
|
||||||
|
- ../values/proteus/values/values-prod.yaml
|
||||||
|
missingFileHandler: Info
|
||||||
|
- name: proteus-staging
|
||||||
|
namespace: proteus
|
||||||
|
chart: ../charts/proteus
|
||||||
|
condition: proteus.enabled
|
||||||
|
values:
|
||||||
|
- ../values/proteus/values/values-staging.yaml
|
||||||
|
missingFileHandler: Info
|
||||||
|
- name: proteus-beta
|
||||||
|
namespace: proteus
|
||||||
|
chart: ../charts/proteus
|
||||||
|
condition: proteus.enabled
|
||||||
|
values:
|
||||||
|
- ../values/proteus/values/values-beta.yaml
|
||||||
|
missingFileHandler: Info
|
||||||
- name: manifests
|
- name: manifests
|
||||||
namespace: proteus
|
namespace: proteus
|
||||||
chart: manifests
|
chart: manifests
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ releases:
|
|||||||
- name: spegel
|
- name: spegel
|
||||||
namespace: spegel
|
namespace: spegel
|
||||||
chart: spegel/spegel
|
chart: spegel/spegel
|
||||||
version: 0.7.1
|
version: 0.7.4
|
||||||
condition: spegel.enabled
|
condition: spegel.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/spegel/values/spegel.yaml.gotmpl
|
- ../values/spegel/values/spegel.yaml.gotmpl
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ releases:
|
|||||||
- name: temporal
|
- name: temporal
|
||||||
namespace: temporal
|
namespace: temporal
|
||||||
chart: temporal/temporal
|
chart: temporal/temporal
|
||||||
version: 1.2.0
|
version: 1.6.0
|
||||||
condition: temporal.enabled
|
condition: temporal.enabled
|
||||||
missingFileHandler: Info
|
missingFileHandler: Info
|
||||||
values:
|
values:
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ releases:
|
|||||||
- name: umami
|
- name: umami
|
||||||
namespace: analytics
|
namespace: analytics
|
||||||
chart: umami/umami
|
chart: umami/umami
|
||||||
version: 7.9.4
|
version: 7.10.10
|
||||||
condition: umami.enabled
|
condition: umami.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/umami/values/values.yaml
|
- ../values/umami/values/values.yaml
|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
bases:
|
||||||
|
- ../envs/environments.yaml.gotmpl
|
||||||
|
|
||||||
|
repositories:
|
||||||
|
- name: upterm
|
||||||
|
url: https://upterm.dev
|
||||||
|
|
||||||
|
commonLabels:
|
||||||
|
tier: system
|
||||||
|
|
||||||
|
releases:
|
||||||
|
- name: uptermd
|
||||||
|
namespace: uptermd
|
||||||
|
chart: upterm/uptermd
|
||||||
|
version: 0.2.0
|
||||||
|
condition: uptermd.enabled
|
||||||
|
values:
|
||||||
|
- ../values/uptermd/values/values.yaml
|
||||||
|
- ../values/uptermd/values/values-{{ .Environment.Name }}.yaml
|
||||||
|
postRenderer: ../bin/kustomizer
|
||||||
|
postRendererArgs:
|
||||||
|
- ../values/uptermd/kustomize/{{ .Environment.Name }}
|
||||||
|
missingFileHandler: Info
|
||||||
|
- name: manifests
|
||||||
|
namespace: uptermd
|
||||||
|
chart: manifests
|
||||||
|
condition: uptermd.enabled
|
||||||
|
missingFileHandler: Info
|
||||||
|
values:
|
||||||
|
- ../values/env.yaml
|
||||||
|
- ../values/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml
|
||||||
|
- ../values/uptermd/env.yaml.gotmpl
|
||||||
|
- ../values/uptermd/env-{{ requiredEnv "ARGOCD_ENV_CLUSTER_NAME" }}.yaml.gotmpl
|
||||||
|
hooks:
|
||||||
|
- events: [ prepare, cleanup ]
|
||||||
|
showlogs: true
|
||||||
|
command: ../bin/helmify
|
||||||
|
args:
|
||||||
|
- '{{`{{ if eq .Event.Name "prepare" }}build{{ else }}clean{{ end }}`}}'
|
||||||
|
- '{{`{{ .Release.Chart }}`}}'
|
||||||
|
- '{{`{{ .Environment.Name }}`}}'
|
||||||
|
- ../values/uptermd/manifests
|
||||||
|
- manifests
|
||||||
@@ -15,7 +15,7 @@ releases:
|
|||||||
- name: velero
|
- name: velero
|
||||||
namespace: velero
|
namespace: velero
|
||||||
chart: velero/velero
|
chart: velero/velero
|
||||||
version: 12.0.3
|
version: 12.1.0
|
||||||
condition: velero.enabled
|
condition: velero.enabled
|
||||||
values:
|
values:
|
||||||
- ../values/velero/values/velero.yaml.gotmpl
|
- ../values/velero/values/velero.yaml.gotmpl
|
||||||
|
|||||||
@@ -27,5 +27,6 @@ argocd:
|
|||||||
image: "git.oceanbox.io/platform/manifests/helmfile-cmp:latest"
|
image: "git.oceanbox.io/platform/manifests/helmfile-cmp:latest"
|
||||||
imagePullSecrets:
|
imagePullSecrets:
|
||||||
- gitlab-pull-secret
|
- gitlab-pull-secret
|
||||||
|
webhookSecret: ""
|
||||||
additional_rbac_settings:
|
additional_rbac_settings:
|
||||||
- g, "eb17a659-4ce6-41bc-9153-d9b117c44479", role:org-admin
|
- g, "eb17a659-4ce6-41bc-9153-d9b117c44479", role:org-admin
|
||||||
|
|||||||
@@ -6,160 +6,163 @@ metadata:
|
|||||||
namespace: argocd
|
namespace: argocd
|
||||||
spec:
|
spec:
|
||||||
clusterResourceWhitelist:
|
clusterResourceWhitelist:
|
||||||
- group: '*'
|
- group: "*"
|
||||||
kind: '*'
|
kind: "*"
|
||||||
description: sys components project
|
description: sys components project
|
||||||
destinations:
|
destinations:
|
||||||
- namespace: default
|
- namespace: default
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: argocd
|
- namespace: argocd
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: kube-system
|
- namespace: kube-system
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: ingress-nginx
|
- namespace: ingress-nginx
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: prometheus
|
- namespace: prometheus
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: cnpg
|
- namespace: cnpg
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: cert-manager
|
- namespace: cert-manager
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: kubernetes-dashboard
|
- namespace: kubernetes-dashboard
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: rabbitmq
|
- namespace: rabbitmq
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: sealed-secrets
|
- namespace: sealed-secrets
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: gitlab
|
- namespace: gitlab
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: thanos
|
- namespace: thanos
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: linkerd
|
- namespace: linkerd
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: linkerd-multicluster
|
- namespace: linkerd-multicluster
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: observability
|
- namespace: observability
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: kyverno
|
- namespace: kyverno
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: velero
|
- namespace: velero
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: loki
|
- namespace: loki
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: tempo
|
- namespace: tempo
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: x509-exporter
|
- namespace: x509-exporter
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: mariadb-operator
|
- namespace: mariadb-operator
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: dragonfly
|
- namespace: dragonfly
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: cilium-spire
|
- namespace: cilium-spire
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: cilium-test
|
- namespace: cilium-test
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: cilium-secrets
|
- namespace: cilium-secrets
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: openfga
|
- namespace: openfga
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: staging-openfga
|
- namespace: staging-openfga
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: dapr-system
|
- namespace: dapr-system
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: rook-ceph
|
- namespace: rook-ceph
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: csi-addon-manager
|
- namespace: csi-addon-manager
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: headscale
|
- namespace: headscale
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: drupal
|
- namespace: drupal
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: otel
|
- namespace: otel
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: opentelemetry
|
- namespace: opentelemetry
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: ncps
|
- namespace: ncps
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: slinky
|
- namespace: slinky
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: slurm
|
- namespace: slurm
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: spegel
|
- namespace: spegel
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: uptime
|
- namespace: uptime
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: gitea
|
- namespace: gitea
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: postfix
|
- namespace: postfix
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: jobset-system
|
- namespace: jobset-system
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: ingress-haproxy
|
- namespace: ingress-haproxy
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: dex
|
- namespace: dex
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: cra-agent
|
- namespace: cra-agent
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: catalyst
|
- namespace: catalyst
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: niks3
|
- namespace: niks3
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: temporal
|
- namespace: temporal
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: ingest
|
- namespace: ingest
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
- namespace: proteus
|
- namespace: proteus
|
||||||
server: https://kubernetes.default.svc
|
server: https://kubernetes.default.svc
|
||||||
|
- namespace: clickhouse
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
sourceRepos:
|
sourceRepos:
|
||||||
- https://argoproj.github.io/argo-helm
|
- https://argoproj.github.io/argo-helm
|
||||||
- https://kubernetes-sigs.github.io/metrics-server/
|
- https://kubernetes-sigs.github.io/metrics-server/
|
||||||
- https://git.oceanbox.io/platform/manifests.git
|
- https://git.oceanbox.io/platform/manifests.git
|
||||||
- https://git.oceanbox.io/platform/manifests
|
- https://git.oceanbox.io/platform/manifests
|
||||||
- https://git.oceanbox.io/oceanbox/manifests.git
|
- https://git.oceanbox.io/oceanbox/manifests.git
|
||||||
- https://kubernetes.github.io/ingress-nginx
|
- https://kubernetes.github.io/ingress-nginx
|
||||||
- https://cloudnative-pg.github.io/charts
|
- https://cloudnative-pg.github.io/charts
|
||||||
- https://charts.jetstack.io
|
- https://charts.jetstack.io
|
||||||
- https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
|
- https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
|
||||||
- https://github.com/kubernetes/dashboard
|
- https://github.com/kubernetes/dashboard
|
||||||
- https://bitnami-labs.github.io/sealed-secrets
|
- https://bitnami-labs.github.io/sealed-secrets
|
||||||
- https://prometheus-community.github.io/helm-charts
|
- https://prometheus-community.github.io/helm-charts
|
||||||
- https://github.com/prometheus-community/helm-charts.git
|
- https://github.com/prometheus-community/helm-charts.git
|
||||||
- https://charts.gitlab.io/
|
- https://charts.gitlab.io/
|
||||||
- https://charts.bitnami.com/bitnami
|
- https://charts.bitnami.com/bitnami
|
||||||
- https://helm.linkerd.io/stable
|
- https://helm.linkerd.io/stable
|
||||||
- https://github.com/jaegertracing/jaeger-operator
|
- https://github.com/jaegertracing/jaeger-operator
|
||||||
- https://kyverno.github.io/kyverno/
|
- https://kyverno.github.io/kyverno/
|
||||||
- https://vmware-tanzu.github.io/helm-charts
|
- https://vmware-tanzu.github.io/helm-charts
|
||||||
- https://grafana.github.io/helm-charts
|
- https://grafana.github.io/helm-charts
|
||||||
- https://charts.enix.io
|
- https://charts.enix.io
|
||||||
- https://helm.mariadb.com/mariadb-operator
|
- https://helm.mariadb.com/mariadb-operator
|
||||||
- https://helm.mariadb.com/mariadb-operator-crds
|
- https://helm.mariadb.com/mariadb-operator-crds
|
||||||
- https://helm.mariadb.com
|
- https://helm.mariadb.com
|
||||||
- https://helm.cilium.io
|
- https://helm.cilium.io
|
||||||
- https://chartmuseum.github.io/charts
|
- https://chartmuseum.github.io/charts
|
||||||
- https://dapr.github.io/helm-charts
|
- https://dapr.github.io/helm-charts
|
||||||
- https://charts.gabe565.com
|
- https://charts.gabe565.com
|
||||||
- ghcr.io/gabe565/charts
|
- ghcr.io/gabe565/charts
|
||||||
- https://open-telemetry.github.io/opentelemetry-helm-charts
|
- https://open-telemetry.github.io/opentelemetry-helm-charts
|
||||||
- https://ghcr.io/slinkyproject/charts/slurm-operator
|
- https://ghcr.io/slinkyproject/charts/slurm-operator
|
||||||
- https://ghcr.io/slinkyproject/charts/slurm-operator-crds
|
- https://ghcr.io/slinkyproject/charts/slurm-operator-crds
|
||||||
- https://bokysan.github.io/docker-postfix/
|
- https://bokysan.github.io/docker-postfix/
|
||||||
- ghcr.io/slinkyproject/charts
|
- ghcr.io/slinkyproject/charts
|
||||||
- ghcr.io/slinkyproject/charts/slurm-operator
|
- ghcr.io/slinkyproject/charts/slurm-operator
|
||||||
- ghcr.io/slinkyproject/charts/slurm-operator-crds
|
- ghcr.io/slinkyproject/charts/slurm-operator-crds
|
||||||
- ghcr.io/spegel-org/helm-charts
|
- ghcr.io/spegel-org/helm-charts
|
||||||
- quay.io/cilium/charts
|
- quay.io/cilium/charts
|
||||||
- quay.io/jetstack/charts
|
- quay.io/jetstack/charts
|
||||||
- quay.io/enix/charts
|
- quay.io/enix/charts
|
||||||
- registry.k8s.io/jobset/charts/jobset
|
- registry.k8s.io/jobset/charts/jobset
|
||||||
- ghcr.io/dragonflydb/dragonfly-operator/helm/dragonfly-operator
|
- ghcr.io/dragonflydb/dragonfly-operator/helm/dragonfly-operator
|
||||||
- docker.gitea.com
|
- docker.gitea.com
|
||||||
- https://operator.mariadb.com/mariadb-enterprise-operator
|
- https://operator.mariadb.com/mariadb-enterprise-operator
|
||||||
- https://ot-container-kit.github.io/helm-charts
|
- https://ot-container-kit.github.io/helm-charts
|
||||||
- https://operator.mariadb.com
|
- https://operator.mariadb.com
|
||||||
- https://twin.github.io/helm-charts
|
- https://twin.github.io/helm-charts
|
||||||
- https://charts.dexidp.io
|
- https://charts.dexidp.io
|
||||||
- public.ecr.aws/diagrid/catalyst
|
- public.ecr.aws/diagrid/catalyst
|
||||||
- ghcr.io/haproxytech/helm-charts
|
- ghcr.io/haproxytech/helm-charts
|
||||||
- https://go.temporal.io/helm-charts
|
- https://go.temporal.io/helm-charts
|
||||||
- docker.io/temporalio
|
- docker.io/temporalio
|
||||||
|
- ghcr.io/clickhouse
|
||||||
|
|||||||
@@ -49,8 +49,8 @@ configs:
|
|||||||
name: {{ .name }}
|
name: {{ .name }}
|
||||||
config:
|
config:
|
||||||
issuer: https://login.microsoftonline.com/{{ .tenant }}/v2.0
|
issuer: https://login.microsoftonline.com/{{ .tenant }}/v2.0
|
||||||
clientID: ${{ .name | replace "-" "_" }}_client_id
|
clientID: ${{ .secret_ref.name }}:client_id
|
||||||
clientSecret: ${{ .name | replace "-" "_" }}_client_secret
|
clientSecret: ${{ .secret_ref.name }}:client_secret
|
||||||
insecureSkipEmailVerified: true
|
insecureSkipEmailVerified: true
|
||||||
requestedIDTokenClaims:
|
requestedIDTokenClaims:
|
||||||
groups:
|
groups:
|
||||||
@@ -62,7 +62,7 @@ configs:
|
|||||||
- email
|
- email
|
||||||
- groups
|
- groups
|
||||||
staticClients:
|
staticClients:
|
||||||
- id: ${{ .name | replace "-" "_" }}_client_id
|
- id: ${{ .secret_ref.name }}:client_id
|
||||||
name: Kubernetes
|
name: Kubernetes
|
||||||
# These are kubectl oidc plugin internal URLs
|
# These are kubectl oidc plugin internal URLs
|
||||||
redirectURIs:
|
redirectURIs:
|
||||||
@@ -99,6 +99,11 @@ configs:
|
|||||||
argo-helm:
|
argo-helm:
|
||||||
type: helm
|
type: helm
|
||||||
url: https://argoproj.github.io/argo-helm
|
url: https://argoproj.github.io/argo-helm
|
||||||
|
{{- if .Values.argocd.webhookSecret }}
|
||||||
|
secret:
|
||||||
|
extra:
|
||||||
|
webhook.gitea.secret: {{ .Values.argocd.webhookSecret }}
|
||||||
|
{{- end }}
|
||||||
# UI changes based on env
|
# UI changes based on env
|
||||||
styles: |
|
styles: |
|
||||||
/* blue, orange, red depending on env */
|
/* blue, orange, red depending on env */
|
||||||
@@ -129,29 +134,11 @@ controller:
|
|||||||
cpu: {{ .Values.argocd.resources.controller.cpu | default "250m" }}
|
cpu: {{ .Values.argocd.resources.controller.cpu | default "250m" }}
|
||||||
memory: {{ .Values.argocd.resources.controller.memory | default "1000Mi" }}
|
memory: {{ .Values.argocd.resources.controller.memory | default "1000Mi" }}
|
||||||
|
|
||||||
# Mount azure ca as file for SAML auth
|
|
||||||
dex:
|
dex:
|
||||||
metrics:
|
metrics:
|
||||||
enabled: true
|
enabled: true
|
||||||
serviceMonitor:
|
serviceMonitor:
|
||||||
enabled: true
|
enabled: true
|
||||||
{{- with .Values.clusterConfig.oidc }}
|
|
||||||
env:
|
|
||||||
{{- range . }}
|
|
||||||
{{- if eq .group "devel" }}
|
|
||||||
- name: {{ .name | replace "-" "_" }}_client_secret
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .secret_ref.name }}
|
|
||||||
key: client_secret
|
|
||||||
- name: {{ .name | replace "-" "_" }}_client_id
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: {{ .secret_ref.name }}
|
|
||||||
key: client_id
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
redis:
|
redis:
|
||||||
metrics:
|
metrics:
|
||||||
|
|||||||
@@ -1,13 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: beta-atlantis-actor-config
|
|
||||||
data:
|
|
||||||
KUEUE_NAMESPACE: "prod-queue"
|
|
||||||
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.4.4"
|
|
||||||
XTRACT_QUEUE: "prod-queue"
|
|
||||||
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.4.4"
|
|
||||||
PLUME_QUEUE: "prod-queue"
|
|
||||||
TEMPORAL_ADDRESS: "temporal-frontend.temporal:7233"
|
|
||||||
TEMPORAL_NAMESPACE: "beta-atlantis"
|
|
||||||
TEMPORAL_TASK_QUEUE: "atlantis"
|
|
||||||
@@ -12,4 +12,4 @@
|
|||||||
path: /spec/template/spec/containers/0/envFrom/-
|
path: /spec/template/spec/containers/0/envFrom/-
|
||||||
value:
|
value:
|
||||||
configMapRef:
|
configMapRef:
|
||||||
name: beta-atlantis-actor-config
|
name: beta-atlantis-temporal-config
|
||||||
@@ -14,7 +14,7 @@ patches:
|
|||||||
resources:
|
resources:
|
||||||
- ../base
|
- ../base
|
||||||
- rbac.yaml
|
- rbac.yaml
|
||||||
- actor-config.yaml
|
- temporal-config.yaml
|
||||||
- tracing.yaml
|
- tracing.yaml
|
||||||
- bindings.yaml
|
- bindings.yaml
|
||||||
- pubsub.yaml
|
- pubsub.yaml
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resourceNames:
|
resourceNames:
|
||||||
- beta-atlantis-appsettings
|
- beta-atlantis-appsettings
|
||||||
- beta-atlantis-actor-config
|
- beta-atlantis-temporal-config
|
||||||
resources:
|
resources:
|
||||||
- configmaps
|
- configmaps
|
||||||
verbs:
|
verbs:
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: beta-atlantis-temporal-config
|
||||||
|
data:
|
||||||
|
TEMPORAL_ADDRESS: "temporal-grpc.ekman.oceanbox.io:443"
|
||||||
|
TEMPORAL_TLS: "true"
|
||||||
|
TEMPORAL_NAMESPACE: "beta-atlantis"
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: staging-atlantis-actor-config
|
|
||||||
data:
|
|
||||||
XTRACT_IMAGE: "git.oceanbox.io/oceanbox/katamari/excavator:v1.4.0"
|
|
||||||
XTRACT_QUEUE: "dev-queue"
|
|
||||||
PLUME_IMAGE: "git.oceanbox.io/oceanbox/katamari/plume:v1.4.0"
|
|
||||||
PLUME_QUEUE: "dev-queue"
|
|
||||||
TEMPORAL_ADDRESS: "temporal-frontend.temporal:7233"
|
|
||||||
TEMPORAL_NAMESPACE: "staging-atlantis"
|
|
||||||
TEMPORAL_TASK_QUEUE: "atlantis"
|
|
||||||
@@ -12,4 +12,4 @@
|
|||||||
path: /spec/template/spec/containers/0/envFrom/-
|
path: /spec/template/spec/containers/0/envFrom/-
|
||||||
value:
|
value:
|
||||||
configMapRef:
|
configMapRef:
|
||||||
name: staging-atlantis-actor-config
|
name: staging-atlantis-temporal-config
|
||||||
@@ -14,7 +14,7 @@ resources:
|
|||||||
- ../base
|
- ../base
|
||||||
- rbac.yaml
|
- rbac.yaml
|
||||||
- secrets.yaml
|
- secrets.yaml
|
||||||
- actor-config.yaml
|
- temporal-config.yaml
|
||||||
- tracing.yaml
|
- tracing.yaml
|
||||||
- bindings.yaml
|
- bindings.yaml
|
||||||
- pubsub.yaml
|
- pubsub.yaml
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resourceNames:
|
resourceNames:
|
||||||
- staging-atlantis-appsettings
|
- staging-atlantis-appsettings
|
||||||
- staging-atlantis-actor-config
|
- staging-atlantis-temporal-config
|
||||||
resources:
|
resources:
|
||||||
- configmaps
|
- configmaps
|
||||||
verbs:
|
verbs:
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: staging-atlantis-temporal-config
|
||||||
|
data:
|
||||||
|
TEMPORAL_ADDRESS: "temporal-grpc.ekman.oceanbox.io:443"
|
||||||
|
TEMPORAL_TLS: "true"
|
||||||
|
TEMPORAL_NAMESPACE: "staging-atlantis"
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
{{- if .Values.clusterConfig.cilium.enabled }}
|
||||||
|
apiVersion: cilium.io/v2
|
||||||
|
kind: CiliumNetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: allow-temporal
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
endpointSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: atlantis
|
||||||
|
egress:
|
||||||
|
- toFQDNs:
|
||||||
|
- matchName: temporal-grpc.ekman.oceanbox.io
|
||||||
|
toPorts:
|
||||||
|
- ports:
|
||||||
|
- port: "443"
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
@@ -2,7 +2,7 @@ replicaCount: 1
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
|
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
|
||||||
tag: v2.17.0
|
tag: v2.24.3
|
||||||
|
|
||||||
podAnnotations:
|
podAnnotations:
|
||||||
dapr.io/app-id: "beta-atlantis"
|
dapr.io/app-id: "beta-atlantis"
|
||||||
@@ -11,7 +11,7 @@ env:
|
|||||||
- name: APP_NAMESPACE
|
- name: APP_NAMESPACE
|
||||||
value: beta-atlantis
|
value: beta-atlantis
|
||||||
- name: APP_VERSION
|
- name: APP_VERSION
|
||||||
value: "2.17.0-beta"
|
value: "2.24.3-beta"
|
||||||
- name: LOG_LEVEL
|
- name: LOG_LEVEL
|
||||||
value: "1"
|
value: "1"
|
||||||
- name: ANALYTICS_WEB_ID
|
- name: ANALYTICS_WEB_ID
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
image:
|
image:
|
||||||
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
|
repository: git.oceanbox.io/oceanbox/poseidon/atlantis
|
||||||
tag: 04417cca-debug
|
tag: 752b39da-debug
|
||||||
podAnnotations:
|
podAnnotations:
|
||||||
dapr.io/app-id: "staging-atlantis"
|
dapr.io/app-id: "staging-atlantis"
|
||||||
env:
|
env:
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
clickhouse:
|
||||||
|
enabled: true
|
||||||
|
s3:
|
||||||
|
enabled: true
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
clickhouse:
|
||||||
|
enabled: false
|
||||||
|
autosync: true
|
||||||
|
clusterName: clickhouse
|
||||||
|
keeperName: clickhouse-keeper
|
||||||
|
serviceName: clickhouse-clickhouse-headless
|
||||||
|
storageClass: managed-nfs-storage
|
||||||
|
storage: 50Gi
|
||||||
|
keeperStorage: 5Gi
|
||||||
|
keeperReplicas: 3
|
||||||
|
resources:
|
||||||
|
cpuRequest: "1"
|
||||||
|
memoryRequest: 4Gi
|
||||||
|
memoryLimit: 8Gi
|
||||||
|
database: otel
|
||||||
|
user: default
|
||||||
|
credentialsSecret: clickhouse-credentials
|
||||||
|
credentialsKey: password
|
||||||
|
s3:
|
||||||
|
enabled: false
|
||||||
|
endpoint: "http://10.255.241.30:30080"
|
||||||
|
bucket: clickhouse
|
||||||
|
secret: clickhouse-s3
|
||||||
|
moveFactor: 0.2
|
||||||
|
ttl:
|
||||||
|
logs: 720h
|
||||||
|
traces: 336h
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
{{- if .Values.clusterConfig.argo.enabled }}
|
||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: clickhouse
|
||||||
|
namespace: argocd
|
||||||
|
annotations:
|
||||||
|
argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true
|
||||||
|
finalizers:
|
||||||
|
- resources-finalizer.argocd.argoproj.io
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: clickhouse
|
||||||
|
server: 'https://kubernetes.default.svc'
|
||||||
|
sources:
|
||||||
|
- repoURL: {{ .Values.clusterConfig.manifests }}
|
||||||
|
targetRevision: HEAD
|
||||||
|
path: helmfile.d
|
||||||
|
plugin:
|
||||||
|
name: helmfile-cmp
|
||||||
|
env:
|
||||||
|
- name: CLUSTER_NAME
|
||||||
|
value: {{ .Values.clusterConfig.cluster }}
|
||||||
|
- name: HELMFILE_ENVIRONMENT
|
||||||
|
value: default
|
||||||
|
- name: HELMFILE_FILE_PATH
|
||||||
|
value: clickhouse.yaml.gotmpl
|
||||||
|
project: sys
|
||||||
|
syncPolicy:
|
||||||
|
managedNamespaceMetadata:
|
||||||
|
labels:
|
||||||
|
component: sys
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
- ApplyOutOfSyncOnly=true
|
||||||
|
- ServerSideApply=true
|
||||||
|
{{- if .Values.clickhouse.autosync }}
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
# selfHeal: false
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
{{- if .Values.clusterConfig.cilium.enabled }}
|
||||||
|
apiVersion: cilium.io/v2
|
||||||
|
kind: CiliumNetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: allow-prometheus
|
||||||
|
namespace: clickhouse
|
||||||
|
spec:
|
||||||
|
description: Allow Grafana queries and Prometheus metric scraping
|
||||||
|
endpointSelector:
|
||||||
|
matchLabels: {}
|
||||||
|
ingress:
|
||||||
|
- fromEndpoints:
|
||||||
|
- matchLabels:
|
||||||
|
io.kubernetes.pod.namespace: prometheus
|
||||||
|
toPorts:
|
||||||
|
- ports:
|
||||||
|
- port: "9000"
|
||||||
|
protocol: TCP
|
||||||
|
- port: "8123"
|
||||||
|
protocol: TCP
|
||||||
|
- port: "8080"
|
||||||
|
protocol: TCP
|
||||||
|
- port: "9363"
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
{{- if .Values.clusterConfig.cilium.enabled }}
|
||||||
|
apiVersion: cilium.io/v2
|
||||||
|
kind: CiliumNetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: allow-intra
|
||||||
|
namespace: clickhouse
|
||||||
|
spec:
|
||||||
|
description: Allow all intra-namespace traffic (operator, ClickHouse servers, Keeper)
|
||||||
|
endpointSelector:
|
||||||
|
matchLabels: {}
|
||||||
|
ingress:
|
||||||
|
- fromEndpoints:
|
||||||
|
- matchLabels:
|
||||||
|
io.kubernetes.pod.namespace: clickhouse
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
{{- if .Values.clusterConfig.cilium.enabled }}
|
||||||
|
apiVersion: cilium.io/v2
|
||||||
|
kind: CiliumNetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: allow-otel-write
|
||||||
|
namespace: clickhouse
|
||||||
|
spec:
|
||||||
|
description: Allow the opentelemetry collector to write to ClickHouse
|
||||||
|
endpointSelector:
|
||||||
|
matchLabels: {}
|
||||||
|
ingress:
|
||||||
|
- fromEndpoints:
|
||||||
|
- matchLabels:
|
||||||
|
io.kubernetes.pod.namespace: otel
|
||||||
|
toPorts:
|
||||||
|
- ports:
|
||||||
|
- port: "9000"
|
||||||
|
protocol: TCP
|
||||||
|
- port: "8123"
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
imageTag: "24.8"
|
||||||
|
|
||||||
|
clickhouse:
|
||||||
|
enabled: true
|
||||||
|
meta:
|
||||||
|
name: {{ .Values.clickhouse.clusterName }}
|
||||||
|
spec:
|
||||||
|
shards: 1
|
||||||
|
replicas: 1
|
||||||
|
podTemplate:
|
||||||
|
nodeHostnameKey: kubernetes.io/hostname
|
||||||
|
settings:
|
||||||
|
defaultUserPassword:
|
||||||
|
secret:
|
||||||
|
name: {{ .Values.clickhouse.credentialsSecret }}
|
||||||
|
key: {{ .Values.clickhouse.credentialsKey }}
|
||||||
|
# Single replica: no cross-replica database sync needed. The operator's sync also
|
||||||
|
# breaks on the OTel-created (non-replicated) `otel` database. Revisit for multi-replica HA.
|
||||||
|
enableDatabaseSync: false
|
||||||
|
{{- if .Values.clickhouse.s3.enabled }}
|
||||||
|
extraConfig:
|
||||||
|
storage_configuration:
|
||||||
|
disks:
|
||||||
|
s3:
|
||||||
|
type: s3
|
||||||
|
endpoint: {{ .Values.clickhouse.s3.endpoint }}/{{ .Values.clickhouse.s3.bucket }}/data/
|
||||||
|
use_environment_credentials: true
|
||||||
|
policies:
|
||||||
|
tiered:
|
||||||
|
volumes:
|
||||||
|
hot:
|
||||||
|
disk: default
|
||||||
|
cold:
|
||||||
|
disk: s3
|
||||||
|
move_factor: {{ .Values.clickhouse.s3.moveFactor }}
|
||||||
|
merge_tree:
|
||||||
|
storage_policy: tiered
|
||||||
|
{{- end }}
|
||||||
|
containerTemplate:
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: {{ .Values.clickhouse.resources.cpuRequest }}
|
||||||
|
memory: {{ .Values.clickhouse.resources.memoryRequest }}
|
||||||
|
limits:
|
||||||
|
memory: {{ .Values.clickhouse.resources.memoryLimit }}
|
||||||
|
{{- if .Values.clickhouse.s3.enabled }}
|
||||||
|
env:
|
||||||
|
- name: AWS_ACCESS_KEY_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.clickhouse.s3.secret }}
|
||||||
|
key: AWS_ACCESS_KEY_ID
|
||||||
|
- name: AWS_SECRET_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.clickhouse.s3.secret }}
|
||||||
|
key: AWS_SECRET_ACCESS_KEY
|
||||||
|
{{- end }}
|
||||||
|
dataVolumeClaimSpec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
storageClassName: {{ .Values.clickhouse.storageClass }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.clickhouse.storage }}
|
||||||
|
|
||||||
|
keeper:
|
||||||
|
enabled: true
|
||||||
|
meta:
|
||||||
|
name: {{ .Values.clickhouse.keeperName }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.clickhouse.keeperReplicas }}
|
||||||
|
podTemplate:
|
||||||
|
nodeHostnameKey: kubernetes.io/hostname
|
||||||
|
podDisruptionBudget:
|
||||||
|
maxUnavailable: 1
|
||||||
|
dataVolumeClaimSpec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
storageClassName: {{ .Values.clickhouse.storageClass }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.clickhouse.keeperStorage }}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
# clickhouse-operator-helm values (chart defaults)
|
||||||
@@ -38,4 +38,4 @@ volumeMounts:
|
|||||||
readOnly: true
|
readOnly: true
|
||||||
subPath: appsettings.json
|
subPath: appsettings.json
|
||||||
image:
|
image:
|
||||||
tag: e2ec1157-debug
|
tag: 7a4a367d-debug
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
fullnameOverride: staging-docs
|
fullnameOverride: staging-docs
|
||||||
image:
|
image:
|
||||||
tag: "9fe77f4b-debug"
|
tag: "511c128c-debug"
|
||||||
ingress:
|
ingress:
|
||||||
enabled: true
|
enabled: true
|
||||||
className: "haproxy"
|
className: "haproxy"
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ replicaCount: 1
|
|||||||
image:
|
image:
|
||||||
registry: "docker.gitea.com"
|
registry: "docker.gitea.com"
|
||||||
repository: gitea
|
repository: gitea
|
||||||
tag: "1.26.2"
|
tag: "1.26.4"
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
@@ -75,10 +75,11 @@ gitea:
|
|||||||
USERNAME: "nickname"
|
USERNAME: "nickname"
|
||||||
mailer:
|
mailer:
|
||||||
ENABLED: true
|
ENABLED: true
|
||||||
FROM: "gitea@oceanbox.io"
|
FROM: "\"Oceanbox Gitea\" <no-reply@oceanbox.io>"
|
||||||
PROTOCOL: "smtp"
|
PROTOCOL: "smtp+starttls"
|
||||||
SMTP_ADDR: "postfix-mail.postfix.svc.cluster.local"
|
SMTP_ADDR: "mx.itpartner.no"
|
||||||
SMTP_PORT: 587
|
SMTP_PORT: 587
|
||||||
|
USER: "no-reply@oceanbox.io"
|
||||||
database:
|
database:
|
||||||
DB_TYPE: postgres
|
DB_TYPE: postgres
|
||||||
MAX_OPEN_CONNS: 90
|
MAX_OPEN_CONNS: 90
|
||||||
@@ -104,6 +105,11 @@ gitea:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: gitea-s3
|
name: gitea-s3
|
||||||
key: secret_key
|
key: secret_key
|
||||||
|
- name: GITEA__mailer__PASSWD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: gitea-smtp
|
||||||
|
key: password
|
||||||
- name: GITEA__DATABASE__PASSWD
|
- name: GITEA__DATABASE__PASSWD
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
|
|||||||
@@ -118,6 +118,7 @@ configMaps:
|
|||||||
"elianne.ersdal@oceanbox.io",
|
"elianne.ersdal@oceanbox.io",
|
||||||
"hanskristian.djuve@oceanbox.io",
|
"hanskristian.djuve@oceanbox.io",
|
||||||
"erlend.mundal@oceanbox.io",
|
"erlend.mundal@oceanbox.io",
|
||||||
|
"hanna.fagrell@oceanbox.io",
|
||||||
],
|
],
|
||||||
"group:manager": [
|
"group:manager": [
|
||||||
"svenn.hanssen@oceanbox.io",
|
"svenn.hanssen@oceanbox.io",
|
||||||
@@ -130,7 +131,6 @@ configMaps:
|
|||||||
"group:intern": [
|
"group:intern": [
|
||||||
"haavahak@stud.ntnu.no",
|
"haavahak@stud.ntnu.no",
|
||||||
"haavahak@ntnu.no",
|
"haavahak@ntnu.no",
|
||||||
"hanna.fagrell@oceanbox.io",
|
|
||||||
],
|
],
|
||||||
"group:ceph": [
|
"group:ceph": [
|
||||||
"jonas.juselius@oceanbox.io",
|
"jonas.juselius@oceanbox.io",
|
||||||
@@ -153,8 +153,6 @@ configMaps:
|
|||||||
"hosts": {
|
"hosts": {
|
||||||
"ingress.ekman.tos": "10.255.241.99/32",
|
"ingress.ekman.tos": "10.255.241.99/32",
|
||||||
"ingress.ceph.tos": "10.255.241.10/32",
|
"ingress.ceph.tos": "10.255.241.10/32",
|
||||||
"ingress.ceph.vtn": "172.16.239.50/32",
|
|
||||||
"ingress.adm.ceph.vtn": "172.16.239.51/32",
|
|
||||||
"ingress.oceanbox.tos": "10.255.241.11/32",
|
"ingress.oceanbox.tos": "10.255.241.11/32",
|
||||||
"manage.ekman.tos": "10.255.241.99/32",
|
"manage.ekman.tos": "10.255.241.99/32",
|
||||||
"k8s.oceanbox.tos": "10.255.241.200/32",
|
"k8s.oceanbox.tos": "10.255.241.200/32",
|
||||||
@@ -165,9 +163,11 @@ configMaps:
|
|||||||
"dc.tos.net": "10.255.241.0/24",
|
"dc.tos.net": "10.255.241.0/24",
|
||||||
"gbe100.tos.net": "10.255.244.0/24",
|
"gbe100.tos.net": "10.255.244.0/24",
|
||||||
"mgmt.tos.net": "10.255.240.0/24",
|
"mgmt.tos.net": "10.255.240.0/24",
|
||||||
"dc.vtn.net": "172.16.239.0/24",
|
|
||||||
"mgmt.vtn.net": "172.16.238.0/24",
|
|
||||||
"dc.hel1.net": "10.0.1.0/24",
|
"dc.hel1.net": "10.0.1.0/24",
|
||||||
|
"n1.hel0": "65.109.27.97/32",
|
||||||
|
"n2.hel0": "65.21.138.120/32",
|
||||||
|
"n3.hel0": "95.217.77.113/32",
|
||||||
|
"n4.hel0": "135.181.77.161/32",
|
||||||
},
|
},
|
||||||
"acls": [
|
"acls": [
|
||||||
{
|
{
|
||||||
@@ -183,10 +183,12 @@ configMaps:
|
|||||||
"dc.tos.net:*",
|
"dc.tos.net:*",
|
||||||
"mgmt.tos.net:*",
|
"mgmt.tos.net:*",
|
||||||
"office.tos.net:*",
|
"office.tos.net:*",
|
||||||
"dc.vtn.net:*",
|
|
||||||
"mgmt.vtn.net:*",
|
|
||||||
"dc.hel1.net:*",
|
"dc.hel1.net:*",
|
||||||
"100.64.0.0/10:*",
|
"100.64.0.0/10:*",
|
||||||
|
"n1.hel0:*",
|
||||||
|
"n2.hel0:*",
|
||||||
|
"n3.hel0:*",
|
||||||
|
"n4.hel0:*",
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -332,14 +334,6 @@ configMaps:
|
|||||||
{ "name": "kueue.dev.tos.obx", "type": "A", "value": "10.255.241.99" },
|
{ "name": "kueue.dev.tos.obx", "type": "A", "value": "10.255.241.99" },
|
||||||
{ "name": "slurm-agent.rossby.oceanbox.io", "type": "A", "value": "172.16.239.222" },
|
{ "name": "slurm-agent.rossby.oceanbox.io", "type": "A", "value": "172.16.239.222" },
|
||||||
|
|
||||||
{ "name": "argocd.adm.vtn.obx", "type": "A", "value": "172.16.239.221" },
|
|
||||||
{ "name": "grafana.adm.vtn.obx", "type": "A", "value": "172.16.239.221" },
|
|
||||||
{ "name": "prometheus.adm.vtn.obx", "type": "A", "value": "172.16.239.221" },
|
|
||||||
{ "name": "alertmanager.adm.vtn.obx", "type": "A", "value": "172.16.239.221" },
|
|
||||||
{ "name": "slurm-agent.adm.vtn.obx", "type": "A", "value": "172.16.239.221" },
|
|
||||||
|
|
||||||
{ "name": "kueue.dev.vtn.obx", "type": "A", "value": "172.16.239.221" },
|
|
||||||
|
|
||||||
{ "name": "dashboard.ob-ceph.local", "type": "A", "value": "10.255.241.10" },
|
{ "name": "dashboard.ob-ceph.local", "type": "A", "value": "10.255.241.10" },
|
||||||
{ "name": "grafana.ob-ceph.local", "type": "A", "value": "10.255.241.10" },
|
{ "name": "grafana.ob-ceph.local", "type": "A", "value": "10.255.241.10" },
|
||||||
{ "name": "s3.ob-ceph.local", "type": "A", "value": "10.255.241.10" },
|
{ "name": "s3.ob-ceph.local", "type": "A", "value": "10.255.241.10" },
|
||||||
@@ -356,12 +350,6 @@ configMaps:
|
|||||||
{ "name": "alertmanager.ceph.tos.obx", "type": "A", "value": "10.255.241.10" },
|
{ "name": "alertmanager.ceph.tos.obx", "type": "A", "value": "10.255.241.10" },
|
||||||
{ "name": "hubble.ceph.tos.obx", "type": "A", "value": "10.255.241.10" },
|
{ "name": "hubble.ceph.tos.obx", "type": "A", "value": "10.255.241.10" },
|
||||||
|
|
||||||
{ "name": "dashboard.ceph.vtn.obx", "type": "A", "value": "172.16.239.50" },
|
|
||||||
{ "name": "grafana.ceph.vtn.obx", "type": "A", "value": "172.16.239.50" },
|
|
||||||
{ "name": "prometheus.ceph.vtn.obx", "type": "A", "value": "172.16.239.50" },
|
|
||||||
{ "name": "alertmanager.ceph.vtn.obx", "type": "A", "value": "172.16.239.50" },
|
|
||||||
{ "name": "hubble.ceph.vtn.obx", "type": "A", "value": "172.16.239.50" },
|
|
||||||
|
|
||||||
{ "name": "jonas-atlantis.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
{ "name": "jonas-atlantis.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
||||||
{ "name": "jonas-sorcerer.ekman.oceanbox.io", "type": "A", "value": "10.255.241.99" },
|
{ "name": "jonas-sorcerer.ekman.oceanbox.io", "type": "A", "value": "10.255.241.99" },
|
||||||
{ "name": "stig-atlantis.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
{ "name": "stig-atlantis.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
||||||
@@ -380,5 +368,10 @@ configMaps:
|
|||||||
{ "name": "ole-atlantis.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
{ "name": "ole-atlantis.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
||||||
{ "name": "ole-maps.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
{ "name": "ole-maps.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
||||||
{ "name": "ole-sorcerer.ekman.oceanbox.io", "type": "A", "value": "10.255.241.99" },
|
{ "name": "ole-sorcerer.ekman.oceanbox.io", "type": "A", "value": "10.255.241.99" },
|
||||||
{ "name": "ole-codex.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" }
|
{ "name": "ole-codex.dev.oceanbox.io", "type": "A", "value": "10.255.241.11" },
|
||||||
|
|
||||||
|
{ "name": "controlplane-1.hel0.oceanbox.io", "type": "A", "value": "65.109.27.97" },
|
||||||
|
{ "name": "controlplane-2.hel0.oceanbox.io", "type": "A", "value": "65.21.138.120" },
|
||||||
|
{ "name": "controlplane-3.hel0.oceanbox.io", "type": "A", "value": "95.217.77.113" },
|
||||||
|
{ "name": "worker-1.hel0.oceanbox.io", "type": "A", "value": "135.181.77.161" }
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ spec:
|
|||||||
runAsGroup: 0
|
runAsGroup: 0
|
||||||
containers:
|
containers:
|
||||||
- name: ingest-py
|
- name: ingest-py
|
||||||
image: git.oceanbox.io/oceanbox/churn/ingest-py:v2.3.11
|
image: git.oceanbox.io/oceanbox/churn/ingest-py:v0.1.6
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
memory: 512Mi
|
memory: 512Mi
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ spec:
|
|||||||
runAsGroup: 0
|
runAsGroup: 0
|
||||||
containers:
|
containers:
|
||||||
- name: ingest
|
- name: ingest
|
||||||
image: git.oceanbox.io/oceanbox/churn/ingest:v2.3.11
|
image: git.oceanbox.io/oceanbox/churn/ingest:v0.1.6
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
memory: 512Mi
|
memory: 512Mi
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
loki:
|
loki:
|
||||||
enabled: true
|
enabled: false
|
||||||
autosync: false
|
autosync: false
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
loki:
|
loki:
|
||||||
enabled: true
|
enabled: false
|
||||||
autosync: true
|
autosync: true
|
||||||
compactor: true
|
compactor: true
|
||||||
s3:
|
s3:
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
image:
|
image:
|
||||||
tag: "ae027c94-debug"
|
tag: "5b60b5ed-debug"
|
||||||
env:
|
env:
|
||||||
- name: APP_VERSION
|
- name: APP_VERSION
|
||||||
value: "0.0.0"
|
value: "0.0.0"
|
||||||
|
|||||||
+24
-4
@@ -4,6 +4,14 @@ image:
|
|||||||
service:
|
service:
|
||||||
type: LoadBalancer
|
type: LoadBalancer
|
||||||
loadBalancerIP: 10.255.241.12
|
loadBalancerIP: 10.255.241.12
|
||||||
|
{{- if .Values.clickhouse.enabled }}
|
||||||
|
extraEnvs:
|
||||||
|
- name: CH_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.clickhouse.credentialsSecret }}
|
||||||
|
key: {{ .Values.clickhouse.credentialsKey }}
|
||||||
|
{{- end }}
|
||||||
config:
|
config:
|
||||||
# receivers:
|
# receivers:
|
||||||
# prometheus/collector:
|
# prometheus/collector:
|
||||||
@@ -31,6 +39,20 @@ config:
|
|||||||
endpoint: http://loki-write-headless.loki:3100/otlp
|
endpoint: http://loki-write-headless.loki:3100/otlp
|
||||||
tls:
|
tls:
|
||||||
insecure: true
|
insecure: true
|
||||||
|
{{- if .Values.clickhouse.enabled }}
|
||||||
|
clickhouse:
|
||||||
|
endpoint: tcp://{{ .Values.clickhouse.serviceName }}.clickhouse.svc:9000?dial_timeout=10s
|
||||||
|
database: {{ .Values.clickhouse.database }}
|
||||||
|
username: {{ .Values.clickhouse.user }}
|
||||||
|
password: ${env:CH_PASSWORD}
|
||||||
|
create_schema: true
|
||||||
|
logs_table_name: otel_logs
|
||||||
|
traces_table_name: otel_traces
|
||||||
|
ttl: {{ .Values.clickhouse.ttl.logs }}
|
||||||
|
timeout: 10s
|
||||||
|
retry_on_failure:
|
||||||
|
enabled: true
|
||||||
|
{{- end }}
|
||||||
debug/metrics:
|
debug/metrics:
|
||||||
verbosity: detailed
|
verbosity: detailed
|
||||||
debug/traces:
|
debug/traces:
|
||||||
@@ -45,8 +67,7 @@ config:
|
|||||||
traces:
|
traces:
|
||||||
receivers: [otlp] # zipkin
|
receivers: [otlp] # zipkin
|
||||||
processors: [batch]
|
processors: [batch]
|
||||||
exporters: [otlp]
|
exporters: [clickhouse]
|
||||||
# exporters: [otlphttp/traces,debug/traces]
|
|
||||||
metrics:
|
metrics:
|
||||||
receivers: [otlp,prometheus] # prometheus/collector
|
receivers: [otlp,prometheus] # prometheus/collector
|
||||||
processors: [batch]
|
processors: [batch]
|
||||||
@@ -55,8 +76,7 @@ config:
|
|||||||
logs:
|
logs:
|
||||||
receivers: [otlp]
|
receivers: [otlp]
|
||||||
processors: [batch]
|
processors: [batch]
|
||||||
exporters: [otlphttp/logs]
|
exporters: [clickhouse]
|
||||||
# exporters: [otlphttp/logs,debug/logs]
|
|
||||||
ports:
|
ports:
|
||||||
metrics:
|
metrics:
|
||||||
enabled: true
|
enabled: true
|
||||||
@@ -11,10 +11,7 @@ prometheus:
|
|||||||
persistence: true
|
persistence: true
|
||||||
plugins:
|
plugins:
|
||||||
- volkovlabs-image-panel
|
- volkovlabs-image-panel
|
||||||
- marcusolsson-static-datasource
|
|
||||||
- marcusolsson-calendar-panel
|
|
||||||
- grafana-clock-panel
|
- grafana-clock-panel
|
||||||
- redis-datasource
|
|
||||||
thanos:
|
thanos:
|
||||||
enabled: true
|
enabled: true
|
||||||
coredns:
|
coredns:
|
||||||
|
|||||||
@@ -108,11 +108,43 @@ grafana:
|
|||||||
defaultDashboardsEnabled: {{ .Values.prometheus.grafana.defaultDashboardsEnabled }}
|
defaultDashboardsEnabled: {{ .Values.prometheus.grafana.defaultDashboardsEnabled }}
|
||||||
deploymentStrategy:
|
deploymentStrategy:
|
||||||
type: Recreate
|
type: Recreate
|
||||||
{{- if .Values.prometheus.grafana.plugins }}
|
{{- if .Values.prometheus.grafana.persistence }}
|
||||||
|
# This init container re-syncs the DB admin password
|
||||||
|
# to the secret before Grafana starts, so the reload can never 401 again.
|
||||||
|
extraInitContainers:
|
||||||
|
- name: sync-admin-password
|
||||||
|
image: docker.io/grafana/grafana:13.0.1-security-01
|
||||||
|
command:
|
||||||
|
- /bin/sh
|
||||||
|
- -c
|
||||||
|
- grafana cli --homepath=/usr/share/grafana admin reset-admin-password "{{ `$GF_ADMIN_PW` }}" || true
|
||||||
|
env:
|
||||||
|
- name: GF_PATHS_DATA
|
||||||
|
value: /var/lib/grafana
|
||||||
|
- name: GF_ADMIN_PW
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: prometheus-grafana
|
||||||
|
key: admin-password
|
||||||
|
volumeMounts:
|
||||||
|
- name: storage
|
||||||
|
mountPath: /var/lib/grafana
|
||||||
|
{{- end }}
|
||||||
|
{{- if or .Values.prometheus.grafana.plugins .Values.clickhouse.enabled }}
|
||||||
plugins:
|
plugins:
|
||||||
{{- range .Values.prometheus.grafana.plugins }}
|
{{- range .Values.prometheus.grafana.plugins }}
|
||||||
- {{ . }}
|
- {{ . }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- if .Values.clickhouse.enabled }}
|
||||||
|
- grafana-clickhouse-datasource
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.clickhouse.enabled }}
|
||||||
|
envValueFrom:
|
||||||
|
CLICKHOUSE_PASSWORD:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.clickhouse.credentialsSecret }}
|
||||||
|
key: {{ .Values.clickhouse.credentialsKey }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
grafana.ini:
|
grafana.ini:
|
||||||
server:
|
server:
|
||||||
@@ -219,9 +251,34 @@ grafana:
|
|||||||
createPrometheusReplicasDatasources: false
|
createPrometheusReplicasDatasources: false
|
||||||
label: grafana_datasource
|
label: grafana_datasource
|
||||||
{{ end }}
|
{{ end }}
|
||||||
{{- if or .Values.loki.enabled .Values.prometheus.additionalDataSources }}
|
{{- if or .Values.loki.enabled .Values.clickhouse.enabled .Values.prometheus.additionalDataSources }}
|
||||||
additionalDataSources:
|
additionalDataSources:
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- if .Values.clickhouse.enabled }}
|
||||||
|
- name: ClickHouse
|
||||||
|
type: grafana-clickhouse-datasource
|
||||||
|
uid: clickhouse
|
||||||
|
access: proxy
|
||||||
|
editable: false
|
||||||
|
jsonData:
|
||||||
|
host: {{ .Values.clickhouse.serviceName }}.clickhouse.svc
|
||||||
|
port: 9000
|
||||||
|
protocol: native
|
||||||
|
username: {{ .Values.clickhouse.user }}
|
||||||
|
defaultDatabase: {{ .Values.clickhouse.database }}
|
||||||
|
logs:
|
||||||
|
defaultDatabase: {{ .Values.clickhouse.database }}
|
||||||
|
defaultTable: otel_logs
|
||||||
|
otelEnabled: true
|
||||||
|
otelVersion: latest
|
||||||
|
traces:
|
||||||
|
defaultDatabase: {{ .Values.clickhouse.database }}
|
||||||
|
defaultTable: otel_traces
|
||||||
|
otelEnabled: true
|
||||||
|
otelVersion: latest
|
||||||
|
secureJsonData:
|
||||||
|
password: ${CLICKHOUSE_PASSWORD}
|
||||||
|
{{- end }}
|
||||||
{{- if .Values.tempo.enabled }}
|
{{- if .Values.tempo.enabled }}
|
||||||
- name: Tempo
|
- name: Tempo
|
||||||
type: tempo
|
type: tempo
|
||||||
|
|||||||
@@ -16,9 +16,6 @@ spec:
|
|||||||
- ports:
|
- ports:
|
||||||
- port: "7233"
|
- port: "7233"
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
# k8s API server (for batch/v1 Job create/poll/delete)
|
|
||||||
- toEntities:
|
|
||||||
- kube-apiserver
|
|
||||||
# DNS
|
# DNS
|
||||||
- toEndpoints:
|
- toEndpoints:
|
||||||
- matchLabels:
|
- matchLabels:
|
||||||
@@ -30,13 +27,11 @@ spec:
|
|||||||
protocol: UDP
|
protocol: UDP
|
||||||
- port: "53"
|
- port: "53"
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
# RabbitMQ on oceanbox via NodePort (prod: 30672, staging: 31672)
|
# OTel collector (tos1 LoadBalancer 10.255.241.12) for Temporal traces, exported cross-cluster
|
||||||
- toCIDR:
|
- toCIDR:
|
||||||
- 10.255.241.0/24
|
- 10.255.241.12/32
|
||||||
toPorts:
|
toPorts:
|
||||||
- ports:
|
- ports:
|
||||||
- port: "30672"
|
- port: "4317"
|
||||||
protocol: TCP
|
|
||||||
- port: "31672"
|
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -1,55 +0,0 @@
|
|||||||
# TODO: the SA the temporal-worker-controller assigns to the pod (assumed `default`).
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: proteus-dev-queue
|
|
||||||
namespace: dev-queue
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["batch"]
|
|
||||||
resources: ["jobs"]
|
|
||||||
verbs: ["create", "delete", "get", "list", "watch"]
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["pods", "pods/log"]
|
|
||||||
verbs: ["get", "list"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: proteus-dev-queue
|
|
||||||
namespace: dev-queue
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: proteus-dev-queue
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: default
|
|
||||||
namespace: proteus
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: proteus-prod-queue
|
|
||||||
namespace: prod-queue
|
|
||||||
rules:
|
|
||||||
- apiGroups: ["batch"]
|
|
||||||
resources: ["jobs"]
|
|
||||||
verbs: ["create", "delete", "get", "list", "watch"]
|
|
||||||
- apiGroups: [""]
|
|
||||||
resources: ["pods", "pods/log"]
|
|
||||||
verbs: ["get", "list"]
|
|
||||||
---
|
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: RoleBinding
|
|
||||||
metadata:
|
|
||||||
name: proteus-prod-queue
|
|
||||||
namespace: prod-queue
|
|
||||||
roleRef:
|
|
||||||
apiGroup: rbac.authorization.k8s.io
|
|
||||||
kind: Role
|
|
||||||
name: proteus-prod-queue
|
|
||||||
subjects:
|
|
||||||
- kind: ServiceAccount
|
|
||||||
name: default
|
|
||||||
namespace: proteus
|
|
||||||
@@ -1,138 +0,0 @@
|
|||||||
# TEMPORAL_NAMESPACE : {env}-atlantis
|
|
||||||
# ARCHIVE_PVC : the queue's archive PVC (prod+beta -> prod-queue, staging -> dev-queue)
|
|
||||||
# PROTEUS_EVENTS_QUEUE : {env}-proteus-job-events (queue the env's Atlantis binding reads)
|
|
||||||
# RABBITMQ_CONNSTRING secret : the broker that env's Atlantis consumes from (prod+beta share prod)
|
|
||||||
# ---
|
|
||||||
# apiVersion: temporal.io/v1alpha1
|
|
||||||
# kind: WorkerDeployment
|
|
||||||
# metadata:
|
|
||||||
# name: proteus-prod
|
|
||||||
# namespace: proteus
|
|
||||||
# spec:
|
|
||||||
# replicas: 1
|
|
||||||
# workerOptions:
|
|
||||||
# temporalNamespace: prod-atlantis
|
|
||||||
# connectionRef:
|
|
||||||
# name: temporal
|
|
||||||
# rollout:
|
|
||||||
# strategy: AllAtOnce
|
|
||||||
# sunset: {}
|
|
||||||
# template:
|
|
||||||
# spec:
|
|
||||||
# securityContext:
|
|
||||||
# runAsUser: 0
|
|
||||||
# runAsGroup: 0
|
|
||||||
# containers:
|
|
||||||
# - name: proteus
|
|
||||||
# image: git.oceanbox.io/oceanbox/poseidon/proteus:CHANGEME
|
|
||||||
# resources:
|
|
||||||
# requests:
|
|
||||||
# memory: 256Mi
|
|
||||||
# limits:
|
|
||||||
# memory: 1Gi
|
|
||||||
# env:
|
|
||||||
# - name: TEMPORAL_TASK_QUEUES
|
|
||||||
# value: plume,xtract
|
|
||||||
# - name: TEMPORAL_NAMESPACE
|
|
||||||
# value: prod-atlantis
|
|
||||||
# - name: APP_ENV
|
|
||||||
# value: prod
|
|
||||||
# - name: ARCHIVE_PVC
|
|
||||||
# value: prod-queue-ceph-archives
|
|
||||||
# - name: PROTEUS_EVENTS_QUEUE
|
|
||||||
# value: prod-proteus-job-events
|
|
||||||
# - name: RABBITMQ_CONNSTRING
|
|
||||||
# valueFrom:
|
|
||||||
# secretKeyRef:
|
|
||||||
# name: proteus-rabbitmq-prod
|
|
||||||
# key: connString
|
|
||||||
# ---
|
|
||||||
# apiVersion: temporal.io/v1alpha1
|
|
||||||
# kind: WorkerDeployment
|
|
||||||
# metadata:
|
|
||||||
# name: proteus-beta
|
|
||||||
# namespace: proteus
|
|
||||||
# spec:
|
|
||||||
# replicas: 1
|
|
||||||
# workerOptions:
|
|
||||||
# temporalNamespace: beta-atlantis
|
|
||||||
# connectionRef:
|
|
||||||
# name: temporal
|
|
||||||
# rollout:
|
|
||||||
# strategy: AllAtOnce
|
|
||||||
# sunset: {}
|
|
||||||
# template:
|
|
||||||
# spec:
|
|
||||||
# securityContext:
|
|
||||||
# runAsUser: 0
|
|
||||||
# runAsGroup: 0
|
|
||||||
# containers:
|
|
||||||
# - name: proteus
|
|
||||||
# image: git.oceanbox.io/oceanbox/poseidon/proteus:CHANGEME
|
|
||||||
# resources:
|
|
||||||
# requests:
|
|
||||||
# memory: 256Mi
|
|
||||||
# limits:
|
|
||||||
# memory: 1Gi
|
|
||||||
# env:
|
|
||||||
# - name: TEMPORAL_TASK_QUEUES
|
|
||||||
# value: plume,xtract
|
|
||||||
# - name: TEMPORAL_NAMESPACE
|
|
||||||
# value: beta-atlantis
|
|
||||||
# - name: APP_ENV
|
|
||||||
# value: beta
|
|
||||||
# # beta schedules into prod-queue (same as prod), so the same archive PVC.
|
|
||||||
# - name: ARCHIVE_PVC
|
|
||||||
# value: prod-queue-ceph-archives
|
|
||||||
# - name: PROTEUS_EVENTS_QUEUE
|
|
||||||
# value: beta-proteus-job-events
|
|
||||||
# # beta shares the prod broker (its Atlantis binding uses prod-atlantis-rabbitmq).
|
|
||||||
# - name: RABBITMQ_CONNSTRING
|
|
||||||
# valueFrom:
|
|
||||||
# secretKeyRef:
|
|
||||||
# name: proteus-rabbitmq-prod
|
|
||||||
# key: connString
|
|
||||||
# ---
|
|
||||||
apiVersion: temporal.io/v1alpha1
|
|
||||||
kind: WorkerDeployment
|
|
||||||
metadata:
|
|
||||||
name: proteus-staging
|
|
||||||
namespace: proteus
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
workerOptions:
|
|
||||||
temporalNamespace: staging-atlantis
|
|
||||||
connectionRef:
|
|
||||||
name: temporal
|
|
||||||
rollout:
|
|
||||||
strategy: AllAtOnce
|
|
||||||
sunset: {}
|
|
||||||
template:
|
|
||||||
spec:
|
|
||||||
securityContext:
|
|
||||||
runAsUser: 0
|
|
||||||
runAsGroup: 0
|
|
||||||
containers:
|
|
||||||
- name: proteus
|
|
||||||
image: git.oceanbox.io/oceanbox/poseidon/proteus:v2.17.0
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: 256Mi
|
|
||||||
limits:
|
|
||||||
memory: 1Gi
|
|
||||||
env:
|
|
||||||
- name: TEMPORAL_TASK_QUEUES
|
|
||||||
value: plume,xtract
|
|
||||||
- name: TEMPORAL_NAMESPACE
|
|
||||||
value: staging-atlantis
|
|
||||||
- name: APP_ENV
|
|
||||||
value: staging
|
|
||||||
- name: ARCHIVE_PVC
|
|
||||||
value: dev-queue-ceph-archives
|
|
||||||
- name: PROTEUS_EVENTS_QUEUE
|
|
||||||
value: staging-proteus-job-events
|
|
||||||
- name: RABBITMQ_CONNSTRING
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: proteus-rabbitmq-staging
|
|
||||||
key: connString
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
image:
|
||||||
|
repository: git.oceanbox.io/oceanbox/poseidon/proteus
|
||||||
|
tag: v2.24.2
|
||||||
|
environment: beta
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
environment: prod
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
image:
|
||||||
|
repository: git.oceanbox.io/oceanbox/poseidon/proteus
|
||||||
|
tag: 7a4a367d-debug
|
||||||
|
environment: staging
|
||||||
@@ -22,9 +22,4 @@
|
|||||||
value:
|
value:
|
||||||
secretRef:
|
secretRef:
|
||||||
name: beta-sorcerer-env
|
name: beta-sorcerer-env
|
||||||
- op: add
|
|
||||||
path: /spec/template/spec/containers/0/envFrom/-
|
|
||||||
value:
|
|
||||||
configMapRef:
|
|
||||||
name: beta-sorcerer-kueue-config
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: beta-sorcerer-kueue-config
|
|
||||||
data:
|
|
||||||
KUEUE_NAMESPACE: "prod-queue"
|
|
||||||
KUEUE_ARCHIVE_PVC: "prod-queue-ceph-archives"
|
|
||||||
@@ -19,7 +19,6 @@ resources:
|
|||||||
- configurations.yaml
|
- configurations.yaml
|
||||||
- keyvault.yaml
|
- keyvault.yaml
|
||||||
- rbac.yaml
|
- rbac.yaml
|
||||||
- kueue-config.yaml
|
|
||||||
- secretstore.yaml
|
- secretstore.yaml
|
||||||
- statestore.yaml
|
- statestore.yaml
|
||||||
- tracing.yaml
|
- tracing.yaml
|
||||||
@@ -8,7 +8,6 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resourceNames:
|
resourceNames:
|
||||||
- beta-sorcerer-appsettings
|
- beta-sorcerer-appsettings
|
||||||
- beta-sorcerer-kueue-config
|
|
||||||
resources:
|
resources:
|
||||||
- configmaps
|
- configmaps
|
||||||
verbs:
|
verbs:
|
||||||
@@ -24,24 +23,6 @@ rules:
|
|||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
|
||||||
- jobset.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- jobsets
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- pods/log
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
|
|||||||
@@ -22,9 +22,4 @@
|
|||||||
value:
|
value:
|
||||||
secretRef:
|
secretRef:
|
||||||
name: staging-sorcerer-env
|
name: staging-sorcerer-env
|
||||||
- op: add
|
|
||||||
path: /spec/template/spec/containers/0/envFrom/-
|
|
||||||
value:
|
|
||||||
configMapRef:
|
|
||||||
name: staging-sorcerer-kueue-config
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ConfigMap
|
|
||||||
metadata:
|
|
||||||
name: staging-sorcerer-kueue-config
|
|
||||||
data:
|
|
||||||
KUEUE_NAMESPACE: "dev-queue"
|
|
||||||
KUEUE_ARCHIVE_PVC: "dev-queue-ceph-archives"
|
|
||||||
@@ -19,7 +19,6 @@ resources:
|
|||||||
- configurations.yaml
|
- configurations.yaml
|
||||||
- keyvault.yaml
|
- keyvault.yaml
|
||||||
- rbac.yaml
|
- rbac.yaml
|
||||||
- kueue-config.yaml
|
|
||||||
- secretstore.yaml
|
- secretstore.yaml
|
||||||
- statestore.yaml
|
- statestore.yaml
|
||||||
- tracing.yaml
|
- tracing.yaml
|
||||||
|
|||||||
@@ -8,7 +8,6 @@ rules:
|
|||||||
- ""
|
- ""
|
||||||
resourceNames:
|
resourceNames:
|
||||||
- staging-sorcerer-appsettings
|
- staging-sorcerer-appsettings
|
||||||
- staging-sorcerer-kueue-config
|
|
||||||
resources:
|
resources:
|
||||||
- configmaps
|
- configmaps
|
||||||
verbs:
|
verbs:
|
||||||
@@ -24,24 +23,6 @@ rules:
|
|||||||
verbs:
|
verbs:
|
||||||
- get
|
- get
|
||||||
- watch
|
- watch
|
||||||
- apiGroups:
|
|
||||||
- jobset.x-k8s.io
|
|
||||||
resources:
|
|
||||||
- jobsets
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- watch
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
- pods/log
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
---
|
---
|
||||||
apiVersion: rbac.authorization.k8s.io/v1
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
kind: RoleBinding
|
kind: RoleBinding
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
image:
|
image:
|
||||||
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
|
repository: git.oceanbox.io/oceanbox/poseidon/sorcerer
|
||||||
tag: e2ec1157-debug
|
tag: 752b39da-debug
|
||||||
podAnnotations:
|
podAnnotations:
|
||||||
dapr.io/enabled: "true"
|
dapr.io/enabled: "true"
|
||||||
dapr.io/app-id: "staging-sorcerer"
|
dapr.io/app-id: "staging-sorcerer"
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{{- if .Values.clusterConfig.cilium.enabled }}
|
||||||
|
apiVersion: cilium.io/v2
|
||||||
|
kind: CiliumClusterwideNetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: allow-itpartner-mail-egress
|
||||||
|
spec:
|
||||||
|
endpointSelector: {}
|
||||||
|
egress:
|
||||||
|
- toFQDNs:
|
||||||
|
- matchName: mx.itpartner.no
|
||||||
|
toPorts:
|
||||||
|
- ports:
|
||||||
|
- port: "587"
|
||||||
|
protocol: TCP
|
||||||
|
- port: "465"
|
||||||
|
protocol: TCP
|
||||||
|
{{- end }}
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
tempo:
|
tempo:
|
||||||
enabled: true
|
enabled: false
|
||||||
autosync: false
|
autosync: false
|
||||||
s3:
|
s3:
|
||||||
endpoint: 10.255.241.30:30080
|
endpoint: 10.255.241.30:30080
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
temporal:
|
temporal:
|
||||||
enabled: true
|
enabled: true
|
||||||
autosync: false
|
autosync: true
|
||||||
ingress: true
|
ingress: true
|
||||||
grpcIngress: true
|
grpcIngress: true
|
||||||
workerController: true
|
workerController: true
|
||||||
|
|||||||
@@ -8,6 +8,8 @@ metadata:
|
|||||||
cert-manager.io/cluster-issuer: {{ .Values.clusterConfig.ingress_clusterissuer }}
|
cert-manager.io/cluster-issuer: {{ .Values.clusterConfig.ingress_clusterissuer }}
|
||||||
nginx.ingress.kubernetes.io/backend-protocol: HTTP
|
nginx.ingress.kubernetes.io/backend-protocol: HTTP
|
||||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-busy-buffers-size: "24k"
|
||||||
oceanbox.io/expose: internal
|
oceanbox.io/expose: internal
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: temporal
|
app.kubernetes.io/name: temporal
|
||||||
|
|||||||
@@ -60,4 +60,19 @@ spec:
|
|||||||
protocol: UDP
|
protocol: UDP
|
||||||
- port: "53"
|
- port: "53"
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
|
---
|
||||||
|
apiVersion: cilium.io/v2
|
||||||
|
kind: CiliumNetworkPolicy
|
||||||
|
metadata:
|
||||||
|
name: allow-web-oidc-login
|
||||||
|
namespace: temporal
|
||||||
|
spec:
|
||||||
|
description: Allow Temporal Web UI OIDC login to Entra ID
|
||||||
|
endpointSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/component: web
|
||||||
|
egress:
|
||||||
|
- toFQDNs:
|
||||||
|
- matchName: login.microsoftonline.com
|
||||||
|
- matchPattern: '*.microsoftonline.com'
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -12,9 +12,20 @@ spec:
|
|||||||
initdb:
|
initdb:
|
||||||
database: temporal
|
database: temporal
|
||||||
owner: temporal
|
owner: temporal
|
||||||
|
# headroom for ~240 server connections (30/pod x 8 pods) plus CNPG's own
|
||||||
|
postgresql:
|
||||||
|
parameters:
|
||||||
|
max_connections: "300"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 1Gi
|
||||||
|
limits:
|
||||||
|
cpu: "2"
|
||||||
|
memory: 2Gi
|
||||||
storage:
|
storage:
|
||||||
resizeInUseVolumes: true
|
resizeInUseVolumes: true
|
||||||
size: 10Gi
|
size: 20Gi
|
||||||
---
|
---
|
||||||
apiVersion: postgresql.cnpg.io/v1
|
apiVersion: postgresql.cnpg.io/v1
|
||||||
kind: Database
|
kind: Database
|
||||||
|
|||||||
@@ -1,8 +1,11 @@
|
|||||||
server:
|
server:
|
||||||
|
replicaCount: 2
|
||||||
config:
|
config:
|
||||||
|
logLevel: "info"
|
||||||
persistence:
|
persistence:
|
||||||
defaultStore: default
|
defaultStore: default
|
||||||
visibilityStore: visibility
|
visibilityStore: visibility
|
||||||
|
# immutable after first deploy
|
||||||
numHistoryShards: 512
|
numHistoryShards: 512
|
||||||
datastores:
|
datastores:
|
||||||
default:
|
default:
|
||||||
@@ -20,7 +23,7 @@ server:
|
|||||||
maxConns: 20
|
maxConns: 20
|
||||||
maxIdleConns: 20
|
maxIdleConns: 20
|
||||||
maxConnLifetime: "1h"
|
maxConnLifetime: "1h"
|
||||||
# TODO: migrate visibility to Elasticsearch for advanced visibility search.
|
# NOTE: Postgres 12+ gives advanced visibility; no Elasticsearch needed.
|
||||||
visibility:
|
visibility:
|
||||||
sql:
|
sql:
|
||||||
createDatabase: false
|
createDatabase: false
|
||||||
@@ -41,8 +44,129 @@ server:
|
|||||||
timerType: histogram
|
timerType: histogram
|
||||||
listenAddress: "0.0.0.0:9090"
|
listenAddress: "0.0.0.0:9090"
|
||||||
|
|
||||||
|
metrics:
|
||||||
|
serviceMonitor:
|
||||||
|
enabled: true
|
||||||
|
interval: 30s
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 512Mi
|
||||||
|
limits:
|
||||||
|
cpu: "1"
|
||||||
|
memory: 1Gi
|
||||||
|
|
||||||
|
frontend:
|
||||||
|
podDisruptionBudget:
|
||||||
|
maxUnavailable: 1
|
||||||
|
topologySpreadConstraints:
|
||||||
|
- maxSkew: 1
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
whenUnsatisfiable: ScheduleAnyway
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: temporal
|
||||||
|
app.kubernetes.io/instance: temporal
|
||||||
|
app.kubernetes.io/component: frontend
|
||||||
|
|
||||||
|
history:
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 768Mi
|
||||||
|
limits:
|
||||||
|
cpu: "1"
|
||||||
|
memory: 1536Mi
|
||||||
|
podDisruptionBudget:
|
||||||
|
maxUnavailable: 1
|
||||||
|
topologySpreadConstraints:
|
||||||
|
- maxSkew: 1
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
whenUnsatisfiable: ScheduleAnyway
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: temporal
|
||||||
|
app.kubernetes.io/instance: temporal
|
||||||
|
app.kubernetes.io/component: history
|
||||||
|
|
||||||
|
matching:
|
||||||
|
podDisruptionBudget:
|
||||||
|
maxUnavailable: 1
|
||||||
|
topologySpreadConstraints:
|
||||||
|
- maxSkew: 1
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
whenUnsatisfiable: ScheduleAnyway
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: temporal
|
||||||
|
app.kubernetes.io/instance: temporal
|
||||||
|
app.kubernetes.io/component: matching
|
||||||
|
|
||||||
|
worker:
|
||||||
|
podDisruptionBudget:
|
||||||
|
maxUnavailable: 1
|
||||||
|
topologySpreadConstraints:
|
||||||
|
- maxSkew: 1
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
whenUnsatisfiable: ScheduleAnyway
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: temporal
|
||||||
|
app.kubernetes.io/instance: temporal
|
||||||
|
app.kubernetes.io/component: worker
|
||||||
|
|
||||||
|
# no persistent debug pod; use temporalio/admin-tools on demand
|
||||||
|
admintools:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
web:
|
web:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
replicaCount: 2
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 128Mi
|
||||||
|
limits:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 256Mi
|
||||||
|
podDisruptionBudget:
|
||||||
|
maxUnavailable: 1
|
||||||
|
topologySpreadConstraints:
|
||||||
|
- maxSkew: 1
|
||||||
|
topologyKey: kubernetes.io/hostname
|
||||||
|
whenUnsatisfiable: ScheduleAnyway
|
||||||
|
labelSelector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: temporal
|
||||||
|
app.kubernetes.io/instance: temporal
|
||||||
|
app.kubernetes.io/component: web
|
||||||
|
# NOTE: native OIDC SSO via Entra ID (same oceanbox-oidc secret as Grafana); gates UI login only
|
||||||
|
additionalEnv:
|
||||||
|
- name: TEMPORAL_AUTH_ENABLED
|
||||||
|
value: "true"
|
||||||
|
- name: TEMPORAL_AUTH_TYPE
|
||||||
|
value: "oidc"
|
||||||
|
- name: TEMPORAL_AUTH_PROVIDER_URL
|
||||||
|
value: "https://login.microsoftonline.com/3f737008-e9a0-4485-9d27-40329d288089/v2.0"
|
||||||
|
- name: TEMPORAL_AUTH_CLIENT_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: oceanbox-oidc
|
||||||
|
key: client_id
|
||||||
|
- name: TEMPORAL_AUTH_CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: oceanbox-oidc
|
||||||
|
key: client_secret
|
||||||
|
- name: TEMPORAL_AUTH_CALLBACK_URL
|
||||||
|
value: "https://temporal.ekman.oceanbox.io/auth/sso/callback"
|
||||||
|
- name: TEMPORAL_AUTH_SCOPES
|
||||||
|
value: "openid,profile,email,offline_access"
|
||||||
|
|
||||||
schema:
|
schema:
|
||||||
useHelmHooks: false
|
useHelmHooks: false
|
||||||
|
# NOTE: run as an ArgoCD sync hook so the controller-mutated Job isn't diffed and stays OutOfSync forever
|
||||||
|
jobAnnotations:
|
||||||
|
argocd.argoproj.io/hook: Sync
|
||||||
|
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ image:
|
|||||||
# -- image pull policy
|
# -- image pull policy
|
||||||
# pullPolicy:
|
# pullPolicy:
|
||||||
# -- Overrides the image tag
|
# -- Overrides the image tag
|
||||||
tag: "3.1.0"
|
tag: "3.2.0"
|
||||||
|
|
||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
uptermd:
|
||||||
|
enabled: true
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
uptermd:
|
||||||
|
enabled: false
|
||||||
|
autosync: false
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- _manifest.yaml
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
kind: Ingress
|
||||||
|
name: uptermd
|
||||||
|
patch: |
|
||||||
|
$patch: delete
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: uptermd
|
||||||
|
- target:
|
||||||
|
group: cert-manager.io
|
||||||
|
kind: Issuer
|
||||||
|
name: uptermd-letsencrypt
|
||||||
|
patch: |
|
||||||
|
$patch: delete
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Issuer
|
||||||
|
metadata:
|
||||||
|
name: uptermd-letsencrypt
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: uptermd
|
||||||
|
namespace: uptermd
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: uptermd
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/cluster-issuer: ca-issuer
|
||||||
|
haproxy.org/backend-protocol: h1
|
||||||
|
haproxy.org/timeout-tunnel: "3600s"
|
||||||
|
haproxy.org/timeout-client: "3600s"
|
||||||
|
haproxy.org/timeout-server: "3600s"
|
||||||
|
spec:
|
||||||
|
ingressClassName: haproxy
|
||||||
|
rules:
|
||||||
|
- host: upterm.hel1.obx
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: uptermd
|
||||||
|
port:
|
||||||
|
number: 80
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- upterm.hel1.obx
|
||||||
|
secretName: uptermd-tls
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
{{- if .Values.clusterConfig.argo.enabled }}
|
||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: uptermd
|
||||||
|
namespace: argocd
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
namespace: uptermd
|
||||||
|
server: 'https://kubernetes.default.svc'
|
||||||
|
sources:
|
||||||
|
- repoURL: {{ .Values.clusterConfig.manifests }}
|
||||||
|
targetRevision: HEAD
|
||||||
|
path: helmfile.d
|
||||||
|
plugin:
|
||||||
|
name: helmfile-cmp
|
||||||
|
env:
|
||||||
|
- name: CLUSTER_NAME
|
||||||
|
value: {{ .Values.clusterConfig.cluster }}
|
||||||
|
- name: HELMFILE_ENVIRONMENT
|
||||||
|
value: default
|
||||||
|
- name: HELMFILE_FILE_PATH
|
||||||
|
value: uptermd.yaml.gotmpl
|
||||||
|
project: sys
|
||||||
|
syncPolicy:
|
||||||
|
managedNamespaceMetadata:
|
||||||
|
labels:
|
||||||
|
component: sys
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
- ApplyOutOfSyncOnly=true
|
||||||
|
- ServerSideApply=true
|
||||||
|
{{- if .Values.uptermd.autosync }}
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
websocket:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: 512Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 512Mi
|
||||||
|
|
||||||
|
# No SSH host key is provided, so uptermd generates an ephemeral one on each
|
||||||
|
# pod start
|
||||||
|
host_keys: {}
|
||||||
|
|
||||||
|
authorized_keys: []
|
||||||
Reference in New Issue
Block a user