diff --git a/etc/azure/cert-manager.md b/etc/azure/cert-manager.md index 13fdd863..354d952f 100644 --- a/etc/azure/cert-manager.md +++ b/etc/azure/cert-manager.md @@ -3,7 +3,7 @@ * Create the namespace for ingress-basic ```bash - kubectl create namespace cert-ingress-basic + kubectl create namespace ingress-basic ``` * Add the Jetstack Helm repository. @@ -39,7 +39,7 @@ kubectl get pods --namespace ingress-basic -o wide ``` -* Create `ClusterIssuer` with name of `tls-cluster-issuer-prod.yml` for the production certificate through `Let's Encrypt ACME` (Automated Certificate Management Environment) with following content by importing YAML file on Ranhcer and save it under `k8s` folder. *Note that certificate will only be created after annotating and updating the `Ingress` resource.* +* Create `ClusterIssuer` with name of `cluster-issuer.yml` for the production certificate through `Let's Encrypt ACME` (Automated Certificate Management Environment) with following content and save it under `azure/k8s` folder. *Note that certificate will only be created after annotating and updating the `Ingress` resource.* ```yaml apiVersion: cert-manager.io/v1 @@ -69,4 +69,3 @@ kubectl apply -f etc/azure/cluster-issuer.yaml kubectl get clusterissuers letsencrypt -n ingress-basic -o wide ``` -* Issue production Let’s Encrypt Certificate by annotating and adding ingress resource diff --git a/etc/azure/k8s/eshoponabp/charts/web/values.yaml b/etc/azure/k8s/eshoponabp/charts/web/values.yaml index ae67275d..4a3f419d 100644 --- a/etc/azure/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/azure/k8s/eshoponabp/charts/web/values.yaml @@ -1,18 +1,18 @@ config: - selfUrl: https://www.admin.eshoponabp.com + selfUrl: https://www.eshoponabp.com gatewayUrl: "https://gateway.eshoponabp.com/" authServer: authority: https://auth.eshoponabp.com requireHttpsMetadata: "false" ingress: - host: admin.eshoponabp.com + host: eshop-st-web tlsSecret: eshop-wildcard-tls image: - repository: "volocr.azurecr.io/eshoponabp/app-web" + repository: eshoponabp/app-web tag: latest - + pullPolicy: IfNotPresent # Extra environment variables or configurations env: {} diff --git a/etc/azure/scripts/cluster-issuer.yaml b/etc/azure/scripts/cluster-issuer.yaml index c3445a09..8c0ef9c9 100644 --- a/etc/azure/scripts/cluster-issuer.yaml +++ b/etc/azure/scripts/cluster-issuer.yaml @@ -5,7 +5,7 @@ metadata: spec: acme: server: https://acme-v02.api.letsencrypt.org/directory - email: info@volosoft.com + email: selman.koc@volosoft.com privateKeySecretRef: name: letsencrypt solvers: diff --git a/etc/azure/scripts/corednsms.yaml b/etc/azure/scripts/corednsms.yaml deleted file mode 100644 index e8909107..00000000 --- a/etc/azure/scripts/corednsms.yaml +++ /dev/null @@ -1,8 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: coredns-custom - namespace: kube-system -data: - Corefile.override: | - rewrite name substring account.eshoponabp.io es-az-account \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml index 30e7e89e..03fcc9e8 100644 --- a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml @@ -7,14 +7,15 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt nginx.ingress.kubernetes.io/configuration-snippet: | more_set_input_headers "from-ingress: true"; spec: ingressClassName: nginx tls: - hosts: - - "eshop-st-authserver" - secretName: "eshop-wildcard-tls" + - {{ .Values.ingress.host }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml index a8d988f6..ef98642c 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml @@ -10,15 +10,16 @@ metadata: {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} {{- if eq .Release.Name "es-az" }} - - {{ print "www." .Values.global.ingress.host }} + - {{ print "www." .Values.ingress.host }} {{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: {{- if eq .Release.Name "es-az" }} - host: "{{ print "www." .Values.ingress.host }}" diff --git a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml index 0dedb3d3..ef98642c 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml @@ -10,6 +10,7 @@ metadata: {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: @@ -18,7 +19,7 @@ spec: {{- if eq .Release.Name "es-az" }} - {{ print "www." .Values.ingress.host }} {{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: {{- if eq .Release.Name "es-az" }} - host: "{{ print "www." .Values.ingress.host }}" diff --git a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml index 18a5ed2f..ef98642c 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml @@ -10,6 +10,7 @@ metadata: {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: @@ -18,12 +19,12 @@ spec: {{- if eq .Release.Name "es-az" }} - {{ print "www." .Values.ingress.host }} {{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: {{- if eq .Release.Name "es-az" }} - host: "{{ print "www." .Values.ingress.host }}" {{- else }} - - host: "{{ .Values.ingress.host }}" + - host: "{{ .Values.ingress.host }}" {{- end }} http: paths: diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml index bbade7db..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml @@ -7,24 +7,15 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" -{{- if eq .Release.Name "es-az" }} - nginx.ingress.kubernetes.io/from-to-www-redirect: "true" -{{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} -{{- if eq .Release.Name "eh-es" }} - - {{ print "www." .Values.ingress.host }} -{{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: -{{- if eq .Release.Name "eh-es" }} - - host: "{{ print "www." .Values.ingress.host }}" -{{- else }} - host: "{{ .Values.ingress.host }}" -{{- end }} http: paths: - path: / diff --git a/etc/k8s/eshoponabp/charts/web/values.yaml b/etc/k8s/eshoponabp/charts/web/values.yaml index 9a3418b7..a3f873eb 100644 --- a/etc/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/k8s/eshoponabp/charts/web/values.yaml @@ -1,8 +1,8 @@ config: - selfUrl: https://eshop-st-web - gatewayUrl: "https://eshop-st-gateway-web/" + selfUrl: https://www.admin.eshoponabp.com + gatewayUrl: "https://www.gateway.eshoponabp.com/" authServer: - authority: http://eshop-st-authserver + authority: https://auth.eshoponabp.com requireHttpsMetadata: "false" ingress: diff --git a/etc/k8s/eshoponabp/values.azure.yaml b/etc/k8s/eshoponabp/values.azure.yaml new file mode 100644 index 00000000..53c1fad1 --- /dev/null +++ b/etc/k8s/eshoponabp/values.azure.yaml @@ -0,0 +1,354 @@ +# auth-server sub-chart override +authserver: + config: + selfUrl: https://auth.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://identity.eshoponabp.com,https://administration.eshoponabp.com,https://basket.eshoponabp.com,https://catalog.eshoponabp.com,https://order.eshoponabp.com,https://payment.eshoponabp.com + allowedRedirectUrls: https://admin.eshoponabp.com + connectionStrings: + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + identityService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + ingress: + host: auth.eshoponabp.com + tlsSecret: eshop-wildcard-tls + image: + repository: "volocr.azurecr.io/eshoponabp/app-authserver" + tag: latest + +# web sub-chart override +web: + config: + selfUrl: https://admin.eshoponabp.com + gatewayUrl: https://www.gateway.eshoponabp.com + ingress: + host: admin.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/app-web" + tag: latest + +# public-web sub-chart override +public-web: + config: + selfUrl: https://www.eshoponabp.com + gatewayUrl: https://www.gateway-public.eshoponabp.com + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + ingress: + host: eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/app-publicweb" + tag: latest + +# identity-service sub-chart override +identity: + config: + selfUrl: https://identity.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com + connectionStrings: + identityService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false" + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + identityServerClients: # Seeded Clients + webRootUrl: https://admin.eshoponabp.com/ + publicWebRootUrl: https://www.eshoponabp.com/ + webGatewayRootUrl: https://www.gateway.eshoponabp.com/ + publicWebGatewayRootUrl: https://www.gateway-public.eshoponabp.com/ + identityServiceRootUrl: https://identity.eshoponabp.com/ + administrationServiceRootUrl: https://administration.eshoponabp.com/ + accountServiceRootUrl: https://auth.eshoponabp.com + basketServiceRootUrl: https://basket.eshoponabp.com/ + catalogServiceRootUrl: https://catalog.eshoponabp.com + orderingServiceRootUrl: https://order.eshoponabp.com + paymentServiceRootUrl: https://payment.eshoponabp.com + ingress: + host: identity.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-identity" + tag: latest + +# administration sub-chart override +administration: + config: + selfUrl: https://administration.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://eshop-az-gateway-internal + connectionStrings: + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + remoteServices: + abpIdentityBaseUrl: https://identity.eshoponabp.com + useCurrentToken: "false" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions + authority: https://auth.eshoponabp.com + ingress: + host: administration.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-administration" + tag: latest + +# gateway-web sub-chart override +gateway-web: + config: + selfUrl: https://www.gateway.eshoponabp.com + corsOrigins: https://admin.eshoponabp.com + globalConfigurationBaseUrl: http://eshop-az-gateway-public + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + ingress: + host: gateway.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/gateway-web" + tag: latest + reRoutes: + accountService: + url: https://auth.eshoponabp.com + identityService: + url: http://eshop-az-identity + administrationService: + url: http://eshop-az-administration + +# gateway-web-public sub-chart override +gateway-web-public: + config: + selfUrl: https://www.gateway-public.eshoponabp.com + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + ingress: + host: gateway-public.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/gateway-web-public" + tag: latest + reRoutes: + accountService: + url: https://auth.eshoponabp.com + identityService: + url: http://eshop-az-identity + administrationService: + url: http://eshop-az-administration + catalogService: + url: http://eshop-az-catalog + basketService: + url: http://eshop-az-basket + orderingService: + url: http://eshop-az-ordering + paymentService: + url: http://eshop-az-payment + +# basket-service sub-chart override +basket: + config: + selfUrl: https://basket.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://publicweb.eshoponabp.com + connectionStrings: + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + remoteServices: + catalogBaseUrl: http://eshop-az-catalog + catalogGrpcUrl: http://eshop-az-catalog + ingress: + host: basket.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-basket" + tag: latest + +# catalog-service sub-chart override +catalog: + config: + selfUrl: https://catalog.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://publicweb.eshoponabp.com,https://admin.eshoponabp.com + connectionStrings: + catalogService: "mongodb://es-az-mongodb/EShopOnAbp_Catalog" + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + kestrel: + httpUrl: http://eshop-az-catalog:80 + httpProtocols: Http1AndHttp2 + grpcUrl: http://eshop-az-catalog:81 + grpcProtocols: Http2 + ingress: + host: catalog.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-catalog" + tag: latest + +# ordering-service sub-chart override +ordering: + config: + selfUrl: https://order.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com + connectionStrings: + orderingService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false" + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + ingress: + host: order.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-ordering" + tag: latest + +# payment-service sub-chart override +payment: + config: + selfUrl: https://payment.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com + connectionStrings: + paymentService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false" + administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: es-az-redis + rabbitmqHost: es-az-rabbitmq + elasticsearchHost: es-az-elasticsearch + ingress: + host: payment.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-payment" + tag: latest + +# Default values for eshoponabp. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. + +replicaCount: 1 + +image: + repository: nginx + pullPolicy: IfNotPresent + # Overrides the image tag whose default is the chart appVersion. + tag: "" + +imagePullSecrets: [] +nameOverride: "" +fullnameOverride: "" + +serviceAccount: + # Specifies whether a service account should be created + create: true + # Annotations to add to the service account + annotations: {} + # The name of the service account to use. + # If not set and create is true, a name is generated using the fullname template + name: "" + +podAnnotations: {} + +podSecurityContext: {} + # fsGroup: 2000 + +securityContext: {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + +service: + type: ClusterIP + port: 80 + +ingress: + enabled: false + className: "" + annotations: {} + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: "true" + hosts: + - host: chart-example.local + paths: + - path: / + pathType: ImplementationSpecific + tls: [] + # - secretName: chart-example-tls + # hosts: + # - chart-example.local + +resources: {} + # We usually recommend not to specify default resources and to leave this as a conscious + # choice for the user. This also increases chances charts run on environments with little + # resources, such as Minikube. If you do want to specify resources, uncomment the following + # lines, adjust them as necessary, and remove the curly braces after 'resources:'. + # limits: + # cpu: 100m + # memory: 128Mi + # requests: + # cpu: 100m + # memory: 128Mi + +autoscaling: + enabled: false + minReplicas: 1 + maxReplicas: 100 + targetCPUUtilizationPercentage: 80 + # targetMemoryUtilizationPercentage: 80 + +nodeSelector: {} + +tolerations: [] + +affinity: {} \ No newline at end of file