Browse Source

Merge pull request #225 from abpframework/gterdem/v8_k8s_update

Update Kubernetes deployment to v8
pull/227/head
selman koc 3 years ago
committed by GitHub
parent
commit
42655a2db2
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
  1. 4
      apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs
  2. 4
      etc/README.md
  3. 31
      etc/k8s/eshoponabp/README.md
  4. 8
      etc/k8s/eshoponabp/charts/administration/templates/administration-deployment.yaml
  5. 2
      etc/k8s/eshoponabp/charts/administration/templates/administration-service.yaml
  6. 6
      etc/k8s/eshoponabp/charts/administration/values.yaml
  7. 6
      etc/k8s/eshoponabp/charts/authserver/Chart.yaml
  8. 55
      etc/k8s/eshoponabp/charts/authserver/templates/authserver-deployment.yaml
  9. 20
      etc/k8s/eshoponabp/charts/authserver/values-st.yaml
  10. 28
      etc/k8s/eshoponabp/charts/authserver/values.yaml
  11. 4
      etc/k8s/eshoponabp/charts/basket/templates/basket-deployment.yaml
  12. 2
      etc/k8s/eshoponabp/charts/basket/templates/basket-service.yaml
  13. 1
      etc/k8s/eshoponabp/charts/basket/values.yaml
  14. 6
      etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml
  15. 2
      etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml
  16. 3
      etc/k8s/eshoponabp/charts/catalog/values.yaml
  17. 4
      etc/k8s/eshoponabp/charts/cmskit/templates/cmskit-deployment.yaml
  18. 2
      etc/k8s/eshoponabp/charts/cmskit/templates/cmskit-service.yaml
  19. 1
      etc/k8s/eshoponabp/charts/cmskit/values.yaml
  20. 293
      etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-configmap.yaml
  21. 2
      etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml
  22. 2
      etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-service.yaml
  23. 24
      etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml
  24. 248
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml
  25. 6
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-deployment.yaml
  26. 2
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-service.yaml
  27. 14
      etc/k8s/eshoponabp/charts/gateway-web/values.yaml
  28. 62
      etc/k8s/eshoponabp/charts/identity/templates/identity-deployment.yaml
  29. 2
      etc/k8s/eshoponabp/charts/identity/templates/identity-service.yaml
  30. 8
      etc/k8s/eshoponabp/charts/identity/values.yaml
  31. 6
      etc/k8s/eshoponabp/charts/keycloak/Chart.yaml
  32. 63
      etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-deployment.yaml
  33. 0
      etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-ingress.yaml
  34. 4
      etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-service.yaml
  35. 38
      etc/k8s/eshoponabp/charts/keycloak/values.yaml
  36. 72
      etc/k8s/eshoponabp/charts/ordering/templates/ordering-deployment.yaml
  37. 2
      etc/k8s/eshoponabp/charts/ordering/templates/ordering-service.yaml
  38. 1
      etc/k8s/eshoponabp/charts/ordering/values.yaml
  39. 4
      etc/k8s/eshoponabp/charts/payment/templates/payment-deployment.yaml
  40. 2
      etc/k8s/eshoponabp/charts/payment/templates/payment-service.yaml
  41. 1
      etc/k8s/eshoponabp/charts/payment/values.yaml
  42. 2
      etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml
  43. 2
      etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml
  44. 2
      etc/k8s/eshoponabp/charts/public-web/templates/public-web-service.yaml
  45. 2
      etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml
  46. 2
      etc/k8s/eshoponabp/templates/NOTES.txt
  47. 228
      etc/k8s/eshoponabp/values.st.yaml
  48. 168
      etc/k8s/eshoponabp/values.yaml
  49. 113
      gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.Staging.json
  50. 3
      gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json
  51. 118
      gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json
  52. 3
      gateways/web/src/EShopOnAbp.WebGateway/appsettings.json
  53. 69
      gateways/web/src/EShopOnAbp.WebGateway/yarp.json
  54. 432
      services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/DbMigrations/KeycloakDataSeeder.cs
  55. 1
      services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/EShopOnAbp.IdentityService.HttpApi.Host.csproj
  56. 2
      services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json
  57. 12
      shared/EShopOnAbp.Shared.Hosting.Gateways/YarpSwaggerUIBuilderExtensions.cs
  58. 17
      shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs

4
apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs

@ -215,7 +215,7 @@ public class EShopOnAbpPublicWebModule : AbpModule
{
// Intercept the redirection so the browser navigates to the right URL in your host
ctx.ProtocolMessage.IssuerAddress = configuration["AuthServer:Authority"].EnsureEndsWith('/') +
"connect/authorize";
"protocol/openid-connect/auth";
if (previousOnRedirectToIdentityProvider != null)
{
@ -228,7 +228,7 @@ public class EShopOnAbpPublicWebModule : AbpModule
{
// Intercept the redirection for signout so the browser navigates to the right URL in your host
ctx.ProtocolMessage.IssuerAddress = configuration["AuthServer:Authority"].EnsureEndsWith('/') +
"connect/endsession";
"protocol/openid-connect/logout";
if (previousOnRedirectToIdentityProviderForSignOut != null)
{

4
etc/README.md

@ -73,7 +73,7 @@ mkcert -install
Create certificate for the eshopOnAbp domains using the mkcert command below:
```powershell
mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-cmskit" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public"
mkcert "eshoponabp.dev" "*.eshoponabp.dev"
```
At the end of the output you will see something like
@ -84,5 +84,5 @@ Copy the cert name and key name below to create tls secret
```powershell
kubectl create namespace eshop
kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem
kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshoponabp.dev+1.pem --key=./eshoponabp.dev+1-key.pem
```

31
etc/k8s/eshoponabp/README.md

@ -44,18 +44,18 @@ mkcert -install
Create certificate for the eshopOnAbp domains using the mkcert command below:
```powershell
mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-cmskit" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public"
mkcert "eshoponabp.dev" "*.eshoponabp.dev"
```
At the end of the output you will see something like
The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem"
The certificate is at "./eshoponabp.dev+1.pem" and the key at "./eshoponabp.dev+1-key.pem"
Copy the cert name and key name below to create tls secret
```powershell
kubectl create namespace eshop
kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem
kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshoponabp.dev+1.pem --key=./eshoponabp.dev+1-key.pem
```
## How to run?
@ -63,18 +63,19 @@ kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.p
* Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`, in linux and macos: `/etc/hosts` ):
````powershell
127.0.0.1 eshop-st-web
127.0.0.1 eshop-st-public-web
127.0.0.1 eshop-st-authserver
127.0.0.1 eshop-st-identity
127.0.0.1 eshop-st-administration
127.0.0.1 eshop-st-basket
127.0.0.1 eshop-st-catalog
127.0.0.1 eshop-st-ordering
127.0.0.1 eshop-st-cmskit
127.0.0.1 eshop-st-payment
127.0.0.1 eshop-st-gateway-web
127.0.0.1 eshop-st-gateway-web-public
127.0.0.1 admin.eshoponabp.dev
127.0.0.1 eshoponabp.dev
127.0.0.1 account.eshoponabp.dev
127.0.0.1 identity.eshoponabp.dev
127.0.0.1 administration.eshoponabp.dev
127.0.0.1 product.eshoponabp.dev
127.0.0.1 basket.eshoponabp.dev
127.0.0.1 catalog.eshoponabp.dev
127.0.0.1 ordering.eshoponabp.dev
127.0.0.1 cmskit.eshoponabp.dev
127.0.0.1 payment.eshoponabp.dev
127.0.0.1 gateway-web.eshoponabp.dev
127.0.0.1 gateway-public.eshoponabp.dev
````
* Run `helm upgrade --install eshop-st abp-charts/eshoponabp --namespace eshop --create-namespace`

8
etc/k8s/eshoponabp/charts/administration/templates/administration-deployment.yaml

@ -17,7 +17,7 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:
@ -29,10 +29,6 @@ spec:
value: "{{ .Values.config.remoteServices.useCurrentToken }}"
- name: App__CorsOrigins
value: "{{ .Values.config.corsOrigins }}"
- name: IdentityClients__Default__Authority
value: "{{ .Values.synchedCommunication.authority }}"
- name: IdentityClients__Default__RequireHttps
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "ConnectionStrings__AdministrationService"
value: "{{ .Values.config.connectionStrings.administrationService }}"
- name: "DOTNET_ENVIRONMENT"
@ -43,6 +39,8 @@ spec:
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__MetadataAddress"
value: "{{ .Values.config.authServer.metadataAddress }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"

2
etc/k8s/eshoponabp/charts/administration/templates/administration-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

6
etc/k8s/eshoponabp/charts/administration/values.yaml

@ -4,10 +4,10 @@ config:
connectionStrings:
administrationService: #
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak:8080
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: #
useCurrentToken: "false"
@ -25,7 +25,7 @@ synchedCommunication:
scope: # "IdentityService"
ingress:
host: eshop-st-administration
host: administration.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:

6
etc/k8s/eshoponabp/charts/authserver/Chart.yaml

@ -1,6 +0,0 @@
apiVersion: v2
name: authserver
appVersion: "1.0"
description: eShopOnAbp AuthServer Application
version: 1.0.0
type: application

55
etc/k8s/eshoponabp/charts/authserver/templates/authserver-deployment.yaml

@ -1,55 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
selector:
matchLabels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
template:
metadata:
labels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
containers:
- image: {{ .Values.image.repository }}:{{ .Values.image.tag }}
imagePullPolicy: {{ .Values.image.pullPolicy }}
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
- name: https
containerPort: 443
env:
- name: App__SelfUrl
value: "{{ .Values.config.selfUrl }}"
- name: App__CorsOrigins
value: "{{ .Values.config.corsOrigins }}"
- name: App__RedirectAllowedUrls
value: "{{ .Values.config.allowedRedirectUrls }}"
- name: "ConnectionStrings__IdentityService"
value: "{{ .Values.config.connectionStrings.identityService }}"
- name: "ConnectionStrings__AdministrationService"
value: "{{ .Values.config.connectionStrings.administrationService }}"
- name: "AuthServer__Authority"
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"
value: "{{ .Values.config.authServer.swaggerClientSecret }}"
- name: "DOTNET_ENVIRONMENT"
value: "{{ .Values.config.dotnetEnv }}"
- name: "Redis__Configuration"
value: "{{ .Values.config.redisHost }}"
- name: "StringEncryption__DefaultPassPhrase"
value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}"
- name: "RabbitMQ__Connections__Default__HostName"
value: "{{ .Values.config.rabbitmqHost }}"
- name: "ElasticSearch__Url"
value: "{{ .Values.config.elasticsearchHost }}"
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

20
etc/k8s/eshoponabp/charts/authserver/values-st.yaml

@ -1,20 +0,0 @@
config:
selfUrl: https://demomicro-st-authserver.eshoponabp.com
corsOrigins: https://demomicro-st-gateway.eshoponabp.com,https://demomicro-st-gateway-public.eshoponabp.com,https://demomicro-st-identity.eshoponabp.com,https://demomicro-st-administration.eshoponabp.com,https://demomicro-st-basket.eshoponabp.com,https://demomicro-st-catalog.eshoponabp.com,https://demomicro-st-order.eshoponabp.com,https://demomicro-st-cmskit.eshoponabp.com,https://demomicro-st-payment.eshoponabp.com,https://demomicro-st-admin.eshoponabp.com,https://demomicro-st-eshoponabp.com
allowedRedirectUrls: https://demomicro-st-admin.eshoponabp.com
authServer:
authority: https://demomicro-st-authserver.eshoponabp.com
requireHttpsMetadata: "false"
connectionStrings:
administrationService: "Host=postgresdb-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
identityService: "Host=postgresdb-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
dotnetEnv: Production
redisHost: redis-redis
rabbitmqHost: rabbitmq-rabbitmq
elasticsearchHost: elasticsearch-elasticsearch
ingress:
host: demomicro-st-authserver.eshoponabp.com
tlsSecret: eshop-wildcard-tls
image:
repository: "volocr.azurecr.io/demomicro/app-authserver"
tag: 1.0.1

28
etc/k8s/eshoponabp/charts/authserver/values.yaml

@ -1,28 +0,0 @@
config:
selfUrl: # https://eshop-st-authserver
corsOrigins: # https://eshop-st-identity,https://eshop-st-administration
allowedRedirectUrls: https://eshop-st-web
connectionStrings:
administrationService: #
identityService: #
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: #
redisHost: #
rabbitmqHost: #
elasticsearchHost: #
stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8
ingress:
host: eshop-st-authserver
tlsSecret: eshop-wildcard-tls
image:
repository: eshoponabp/app-authserver
tag: latest
pullPolicy: IfNotPresent
env: {}

4
etc/k8s/eshoponabp/charts/basket/templates/basket-deployment.yaml

@ -17,7 +17,7 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:
@ -39,6 +39,8 @@ spec:
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__MetadataAddress"
value: "{{ .Values.config.authServer.metadataAddress }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"

2
etc/k8s/eshoponabp/charts/basket/templates/basket-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

1
etc/k8s/eshoponabp/charts/basket/values.yaml

@ -6,6 +6,7 @@ config:
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: "WebGateway_Swagger"
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging

6
etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml

@ -17,14 +17,14 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
protocol: TCP
- name: grpc
containerPort: 81
protocol: TCP
env:
- name: "ASPNETCORE_URLS"
value: "http://+:80;http://+:81"
value: "http://+:8080;http://+:81"
- name: "DOTNET_ENVIRONMENT"
value: "{{ .Values.config.dotnetEnv }}"
- name: App__SelfUrl
@ -45,6 +45,8 @@ spec:
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__MetadataAddress"
value: "{{ .Values.config.authServer.metadataAddress }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"

2
etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "http"
port: 80
port: 8080
targetPort: http
protocol: TCP
- name: grpc

3
etc/k8s/eshoponabp/charts/catalog/values.yaml

@ -7,6 +7,7 @@ config:
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging
@ -16,7 +17,7 @@ config:
stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8
grpcPort: 81
kestrel:
httpUrl: http://eshop-st-catalog:80
httpUrl: http://eshop-st-catalog:8080
httpProtocols: Http1AndHttp2
grpcUrl: http://eshop-st-catalog:81
grpcProtocols: Http2

4
etc/k8s/eshoponabp/charts/cmskit/templates/cmskit-deployment.yaml

@ -17,7 +17,7 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:
@ -41,6 +41,8 @@ spec:
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__MetadataAddress"
value: "{{ .Values.config.authServer.metadataAddress }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"

2
etc/k8s/eshoponabp/charts/cmskit/templates/cmskit-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

1
etc/k8s/eshoponabp/charts/cmskit/values.yaml

@ -7,6 +7,7 @@ config:
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:

293
etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-configmap.yaml

@ -5,115 +5,210 @@ metadata:
data:
yarp.json: |-
{
"ReverseProxy": {
"Routes": {
"Account Service": {
"ClusterId": "account-cluster",
"Match": {
"Path": "/api/account/{**everything}"
}
},
"Administration Service": {
"ClusterId": "administration-cluster",
"Match": {
"Path": "/api/abp/{**everything}"
}
},
"Catalog Service": {
"ClusterId": "catalog-cluster",
"Match": {
"Path": "/api/catalog/{**everything}"
}
},
"Basket Service": {
"ClusterId": "basket-cluster",
"Match": {
"Path": "/api/basket/{**everything}"
}
},
"Ordering Service": {
"ClusterId": "ordering-cluster",
"Match": {
"Path": "/api/ordering/{**everything}"
}
},
"Cmskit Service": {
"ClusterId": "cmskit-cluster",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
},
"Payment Service": {
"ClusterId": "payment-cluster",
"Match": {
"Path": "/api/payment/{**everything}"
}
},
"product-picture-route": {
"ClusterId": "product-picture-cluster",
"Match": {
"Path": "/product-images/{**everything}",
"Methods" : [ "GET" ]
}
}
},
"Clusters": {
"account-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.accountService.url }}"
"ReverseProxy": {
"Routes": {
"AbpApi": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/abp/{**catch-all}"
}
}
},
"administration-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}"
},
"Identity Service": {
"ClusterId": "Identity",
"Match": {
"Path": "/api/identity/{**everything}"
}
}
},
"catalog-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.catalogService.url }}"
},
"Identity Service Swagger": {
"ClusterId": "Identity",
"Match": {
"Path": "/swagger-json/Identity/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Identity" }
]
},
"FeatureManagement": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/feature-management/{**everything}"
}
}
},
"product-picture-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.catalogService.url }}"
},
"PermissionManagement": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/permission-management/{**everything}"
}
}
},
"basket-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.basketService.url }}"
},
"SettingManagement": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/setting-management/{**everything}"
}
}
},
"ordering-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.orderingService.url }}"
},
"Administration ServiceSwagger": {
"ClusterId": "Administration",
"Match": {
"Path": "/swagger-json/Administration/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Administration" }
]
},
"Catalog Service": {
"ClusterId": "Catalog",
"Match": {
"Path": "/api/catalog/{**everything}"
}
}
},
"cmskit-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.cmskitService.url }}"
},
"Catalog Service Swagger": {
"ClusterId": "Catalog",
"Match": {
"Path": "/swagger-json/Catalog/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Catalog" }
]
},
"ProductPictures": {
"ClusterId": "Catalog",
"Match": {
"Path": "/product-images/{**everything}",
"Methods": [ "GET" ]
}
}
},
"Basket Service": {
"ClusterId": "Basket",
"Match": {
"Path": "/api/basket/{**everything}"
}
},
"Basket Service Swagger": {
"ClusterId": "Basket",
"Match": {
"Path": "/swagger-json/Basket/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Basket" }
]
},
"Ordering Service": {
"ClusterId": "Ordering",
"Match": {
"Path": "/api/ordering/{**everything}"
}
},
"Ordering Service Swagger": {
"ClusterId": "Ordering",
"Match": {
"Path": "/swagger-json/Ordering/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Ordering" }
]
},
"Cmskit Service": {
"ClusterId": "CmsKit",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
},
"Cmskit Service Swagger": {
"ClusterId": "CmsKit",
"Match": {
"Path": "/swagger-json/Cmskit/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Cmskit" }
]
},
"Payment Service": {
"ClusterId": "Payment",
"Match": {
"Path": "/api/payment/{**everything}"
}
},
"Payment Service Swagger": {
"ClusterId": "Payment",
"Match": {
"Path": "/swagger-json/payment/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/payment" }
]
},
},
"payment-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.paymentService.url }}"
"Clusters": {
"Identity": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.identityService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.identityService.dns }}"
}
}
}
},
"Administration": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.administrationService.dns }}"
}
}
}
},
"Catalog": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.catalogService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.catalogService.dns }}"
}
}
}
},
"Basket": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.basketService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.basketService.dns }}"
}
}
}
},
"Ordering": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.orderingService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.orderingService.dns }}"
}
}
}
},
"CmsKit": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.cmskitService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.cmskitService.dns }}"
}
}
}
},
"Payment": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.paymentService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.paymentService.dns }}"
}
}
}
}
}
}
}
}

2
etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml

@ -27,6 +27,8 @@ spec:
env:
- name: App__SelfUrl
value: "{{ .Values.config.selfUrl }}"
- name: App__IsOnK8s
value: "{{ .Values.config.isOnK8s }}"
- name: "DOTNET_ENVIRONMENT"
value: "{{ .Values.config.dotnetEnv }}"
- name: "Redis__Configuration"

2
etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

24
etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml

@ -1,5 +1,6 @@
config:
selfUrl: https://eshop-st-gateway-public-web
isOnK8s: "true"
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
@ -11,22 +12,27 @@ config:
elasticsearchHost: eshop-st-elasticsearch
reRoutes:
accountService:
url: https://eshop-st-authserver
identityService:
url: https://eshop-st-identity
url: http://eshop-st-identity
dns: https://identity.eshoponabp.dev
administrationService:
url: https://eshop-st-administration
url: http://eshop-st-administration
dns: https://administration.eshoponabp.dev
catalogService:
url: https://eshop-st-catalog
url: http://eshop-st-catalog
dns: https://catalog.eshoponabp.dev
basketService:
url: https://eshop-st-basket
url: http://eshop-st-basket
dns: https://basket.eshoponabp.dev
orderingService:
url: https://eshop-st-ordering
url: http://eshop-st-ordering
dns: https://ordering.eshoponabp.dev
cmskitService:
url: https://eshop-st-cmskit
url: http://eshop-st-cmskit
dns: https://cmskit.eshoponabp.dev
paymentService:
url: https://eshop-st-payment
url: http://eshop-st-payment
dns: https://payment.eshoponabp.dev
ingress:
host: eshop-st-gateway-web-public

248
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml

@ -5,127 +5,153 @@ metadata:
data:
yarp.json: |-
{
"ReverseProxy": {
"Routes": {
"Account Service": {
"ClusterId": "account-cluster",
"Match": {
"Path": "/api/account/{**everything}"
}
},
"Identity Service": {
"ClusterId": "identity-cluster",
"Match": {
"Path": "/api/identity/{**everything}"
}
},
"Administration Service": {
"ClusterId": "administration-cluster",
"Match": {
"Path": "/api/abp/{**everything}"
}
},
"feature-management-route": {
"ClusterId": "feature-management-cluster",
"Match": {
"Path": "/api/feature-management/{**everything}"
}
},
"permission-management-route": {
"ClusterId": "permission-management-cluster",
"Match": {
"Path": "/api/permission-management/{**everything}"
}
},
"setting-management-route": {
"ClusterId": "setting-management-cluster",
"Match": {
"Path": "/api/setting-management/{**everything}"
}
},
"Catalog Service": {
"ClusterId": "catalogCluster",
"Match": {
"Path": "/api/catalog/{**everything}"
}
},
"Ordering Service": {
"ClusterId": "orderingCluster",
"Match": {
"Path": "/api/ordering/{**everything}"
}
},
"Cmskit Service": {
"ClusterId": "cmskitCluster",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
}
},
"Clusters": {
"account-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.accountService.url }}"
"ReverseProxy": {
"Routes": {
"AbpApi": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/abp/{**catch-all}"
}
}
},
"identity-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.identityService.url }}"
},
"Identity Service": {
"ClusterId": "Identity",
"Match": {
"Path": "/api/identity/{**everything}"
}
}
},
"administration-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}"
},
"Identity Service Swagger": {
"ClusterId": "Identity",
"Match": {
"Path": "/swagger-json/Identity/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Identity" }
]
},
"FeatureManagement": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/feature-management/{**everything}"
}
}
},
"feature-management-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}"
},
"PermissionManagement": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/permission-management/{**everything}"
}
}
},
"permission-management-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}"
},
"SettingManagement": {
"ClusterId": "Administration",
"Match": {
"Path": "/api/setting-management/{**everything}"
}
}
},
"setting-management-cluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}"
},
"Administration Service Swagger": {
"ClusterId": "Administration",
"Match": {
"Path": "/swagger-json/Administration/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Administration" }
]
},
"Catalog Service": {
"ClusterId": "Catalog",
"Match": {
"Path": "/api/catalog/{**everything}"
}
}
},
"catalogCluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.catalogService.url }}"
},
"Catalog Service Swagger": {
"ClusterId": "Catalog",
"Match": {
"Path": "/swagger-json/Catalog/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Catalog" }
]
},
"Ordering Service": {
"ClusterId": "Ordering",
"Match": {
"Path": "/api/ordering/{**everything}"
}
}
},
"orderingCluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.orderingService.url }}"
},
"Ordering Service Swagger": {
"ClusterId": "Ordering",
"Match": {
"Path": "/swagger-json/Ordering/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Ordering" }
]
},
"Cmskit Service": {
"ClusterId": "Cmskit",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
}
},
"cmskitCluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.cmskitService.url }}"
},
"Cmskit Service Swagger": {
"ClusterId": "Cmskit",
"Match": {
"Path": "/swagger-json/Cmskit/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Cmskit" }
]
}
},
"Clusters": {
"Identity": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.identityService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.identityService.dns }}"
}
}
}
},
"Administration": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.administrationService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.administrationService.dns }}"
}
}
}
},
"Catalog": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.catalogService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.catalogService.dns }}"
}
}
}
},
"Ordering": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.orderingService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.orderingService.dns }}"
}
}
}
},
"Cmskit": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.cmskitService.url }}",
"MetaData": {
"PublicAddress": "{{ .Values.reRoutes.cmskitService.dns }}"
}
}
}
}
}
}
}
}

6
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-deployment.yaml

@ -28,9 +28,9 @@ spec:
- name: App__SelfUrl
value: "{{ .Values.config.selfUrl }}"
- name: App__CorsOrigins
value: "{{ .Values.config.corsOrigins }}"
- name: GlobalConfiguration__BaseUrl
value: "{{ .Values.config.globalConfigurationBaseUrl }}"
value: "{{ .Values.config.corsOrigins }}"
- name: App__IsOnK8s
value: "{{ .Values.config.isOnK8s }}"
- name: "DOTNET_ENVIRONMENT"
value: "{{ .Values.config.dotnetEnv }}"
- name: "Redis__Configuration"

2
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

14
etc/k8s/eshoponabp/charts/gateway-web/values.yaml

@ -1,7 +1,7 @@
config:
selfUrl: # https://eshop-st-gateway-web
corsOrigins: # localhost:4200
globalConfigurationBaseUrl: # http://eshop-st-gateway-web
isOnK8s: "true"
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
@ -13,16 +13,22 @@ config:
elasticsearchHost: #
stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8
reRoutes:
accountService:
url: http://eshop-st-authserver
identityService:
url: http://eshop-st-identity
dns: https://identity.eshoponabp.dev
administrationService:
url: http://eshop-st-administration
dns: https://administration.eshoponabp.dev
catalogService:
url: http://eshop-st-catalog
dns: https://catalog.eshoponabp.dev
orderingService:
url: http://eshop-st-order
url: http://eshop-st-ordering
dns: https://ordering.eshoponabp.dev
cmskitService:
url: http://eshop-st-cmskit
dns: https://cmskit.eshoponabp.dev
ingress:
host: # eshop-st-gateway-web
tlsSecret: eshop-wildcard-tls

62
etc/k8s/eshoponabp/charts/identity/templates/identity-deployment.yaml

@ -17,7 +17,7 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:
@ -36,41 +36,51 @@ spec:
- name: "RabbitMQ__Connections__Default__HostName"
value: "{{ .Values.config.rabbitmqHost }}"
- name: "ElasticSearch__Url"
value: "{{ .Values.config.elasticsearchHost }}"
value: "{{ .Values.config.elasticsearchHost }}"
- name: "Keycloak__url"
value: "{{ .Values.config.keycloak.url }}"
- name: "Keycloak__adminUsername"
value: "{{ .Values.config.keycloak.adminUsername }}"
- name: "Keycloak__adminPassword"
value: "{{ .Values.config.keycloak.adminPassword }}"
- name: "Keycloak__realmName"
value: "{{ .Values.config.keycloak.realmName }}"
- name: "AuthServer__Authority"
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__MetadataAddress"
value: "{{ .Values.config.authServer.metadataAddress }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"
value: "{{ .Values.config.authServer.swaggerClientSecret }}"
- name: "StringEncryption__DefaultPassPhrase"
value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}"
- name: "IdentityServerClients__Web__RootUrl"
value: {{ .Values.identityServerClients.webRootUrl }}
- name: "IdentityServerClients__PublicWeb__RootUrl"
value: {{ .Values.identityServerClients.publicWebRootUrl }}
- name: "IdentityServerClients__PublicWebGateway__RootUrl"
value: {{ .Values.identityServerClients.publicWebGatewayRootUrl }}
- name: "IdentityServerClients__WebGateway__RootUrl"
value: {{ .Values.identityServerClients.webGatewayRootUrl }}
- name: "IdentityServerClients__IdentityService__RootUrl"
value: {{ .Values.identityServerClients.identityServiceRootUrl }}
- name: "IdentityServerClients__AdministrationService__RootUrl"
value: {{ .Values.identityServerClients.administrationServiceRootUrl }}
- name: "IdentityServerClients__AccountService__RootUrl"
value: {{ .Values.identityServerClients.accountServiceRootUrl }}
- name: "IdentityServerClients__BasketService__RootUrl"
value: {{ .Values.identityServerClients.basketServiceRootUrl }}
- name: "IdentityServerClients__CatalogService__RootUrl"
value: {{ .Values.identityServerClients.catalogServiceRootUrl }}
- name: "IdentityServerClients__OrderingService__RootUrl"
value: {{ .Values.identityServerClients.orderingServiceRootUrl }}
- name: "IdentityServerClients__CmskitService__RootUrl"
value: {{ .Values.identityServerClients.cmskitServiceRootUrl }}
- name: "IdentityServerClients__PaymentService__RootUrl"
value: {{ .Values.identityServerClients.paymentServiceRootUrl }}
- name: "Clients__Web__RootUrl"
value: {{ .Values.keycloakClients.webRootUrl }}
- name: "Clients__PublicWeb__RootUrl"
value: {{ .Values.keycloakClients.publicWebRootUrl }}
- name: "Clients__PublicWebGateway__RootUrl"
value: {{ .Values.keycloakClients.publicWebGatewayRootUrl }}
- name: "Clients__WebGateway__RootUrl"
value: {{ .Values.keycloakClients.webGatewayRootUrl }}
- name: "Clients__IdentityService__RootUrl"
value: {{ .Values.keycloakClients.identityServiceRootUrl }}
- name: "Clients__AdministrationService__RootUrl"
value: {{ .Values.keycloakClients.administrationServiceRootUrl }}
- name: "Clients__AccountService__RootUrl"
value: {{ .Values.keycloakClients.accountServiceRootUrl }}
- name: "Clients__BasketService__RootUrl"
value: {{ .Values.keycloakClients.basketServiceRootUrl }}
- name: "Clients__CatalogService__RootUrl"
value: {{ .Values.keycloakClients.catalogServiceRootUrl }}
- name: "Clients__OrderingService__RootUrl"
value: {{ .Values.keycloakClients.orderingServiceRootUrl }}
- name: "Clients__CmskitService__RootUrl"
value: {{ .Values.keycloakClients.cmskitServiceRootUrl }}
- name: "Clients__PaymentService__RootUrl"
value: {{ .Values.keycloakClients.paymentServiceRootUrl }}
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

2
etc/k8s/eshoponabp/charts/identity/templates/identity-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

8
etc/k8s/eshoponabp/charts/identity/values.yaml

@ -7,8 +7,14 @@ config:
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
keycloak:
url: http://eshop-st-keycloak:8080
adminUsername: admin
adminPassword: 1q2w3E*
realmName: master
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
@ -16,7 +22,7 @@ config:
stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8
# Seeded clients
identityServerClients:
keycloakClients:
webRootUrl: #
publicWebRootUrl: #
webGatewayRootUrl: #

6
etc/k8s/eshoponabp/charts/keycloak/Chart.yaml

@ -0,0 +1,6 @@
apiVersion: v2
name: keycloak
appVersion: "1.0"
description: Keycloak openid-provider instance
version: 1.0.0
type: application

63
etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-deployment.yaml

@ -0,0 +1,63 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
selector:
matchLabels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
template:
metadata:
labels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
containers:
- image: {{ .Values.image.repository }}:{{ .Values.image.tag }}
imagePullPolicy: {{ .Values.image.pullPolicy }}
args: ["start", "--cache-stack=kubernetes"]
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 8080
- name: https
containerPort: 8443
env:
- name: "KC_DB"
value: "{{ .Values.config.kcDb }}"
- name: "KC_DB_URL"
value: "{{ .Values.config.kcDbUrl }}"
- name: "KC_DB_URL_HOST"
value: "{{ .Values.config.kcDbUrlHost }}"
- name: "KC_DB_URL_PORT"
value: "{{ .Values.config.kcDbUrlPort }}"
- name: "KC_DB_URL_DATABASE"
value: "{{ .Values.config.kcDbUrlDatabase }}"
- name: "KC_DB_USERNAME"
value: "{{ .Values.config.kcDbUsername }}"
- name: "KC_DB_PASSWORD"
value: "{{ .Values.config.kcDbPassword }}"
- name: "KEYCLOAK_ADMIN"
value: "{{ .Values.config.keycloakAdmin }}"
- name: "KEYCLOAK_ADMIN_PASSWORD"
value: "{{ .Values.config.keycloakAdminPassword }}"
- name: "KC_HEALTH_ENABLED"
value: "{{ .Values.config.kcHealthEnabled }}"
- name: "KC_HTTP_RELATIVE_PATH"
value: "{{ .Values.config.kcHttpRelativePath }}"
- name: "KC_PROXY"
value: "{{ .Values.config.kcProxy }}"
- name: "PROXY_ADDRESS_FORWARDING"
value: "{{ .Values.config.proxyAddressForwarding }}"
- name: "KC_HTTP_ENABLED"
value: "{{ .Values.config.kcHttpEnabled }}"
- name: "KC_HOSTNAME_URL"
value: "{{ .Values.config.kcHostnameUrl }}"
- name: "KC_HOSTNAME_ADMIN_URL"
value: "{{ .Values.config.kcHostnameAdminUrl }}"
- name: "jgroups.dns.query"
value: "{{ .Values.config.jgroupsDnsQuery }}"
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

0
etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml → etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-ingress.yaml

4
etc/k8s/eshoponabp/charts/authserver/templates/authserver-service.yaml → etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-service.yaml

@ -5,10 +5,12 @@ metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
type: ClusterIP
ports:
- name: "80"
port: 80
targetPort: 8080
- name: "443"
port: 443
selector:
app: {{ .Release.Name }}-{{ .Chart.Name }}
app: {{ .Release.Name }}-{{ .Chart.Name }}

38
etc/k8s/eshoponabp/charts/keycloak/values.yaml

@ -0,0 +1,38 @@
config:
kcDb: postgres
kcDbUrl: jdbc:postgresql://eshop-st-postgresdb:5432/keycloak
kcDbUrlHost: eshop-st-postgresdb
kcDbUrlPort: 5432
kcDbUrlDatabase: keycloak
kcDbUsername: postgres
kcDbPassword: myPassw0rd
keycloakAdmin: admin
keycloakAdminPassword: 1q2w3E*
kcHealthEnabled: true
kcHttpRelativePath : /
kcProxy: edge
proxyAddressForwarding: true
kcHttpEnabled: true
kcHostnameUrl: https://account.eshoponabp.dev
kcHostnameAdminUrl: https://account.eshoponabp.dev
jgroupsDnsQuery: eshop-st-keycloak
ingress:
host: account.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: quay.io/keycloak/keycloak
tag: 21.1.1
pullPolicy: IfNotPresent
# command:
# - "/opt/keycloak/bin/kc.sh"
# - "start"
# - "--auto-build"
# - "--http-enabled=true"
# - "--http-port=8080"
# - "--hostname-strict=false"
# - "--hostname-strict-https=false"
env: {}

72
etc/k8s/eshoponabp/charts/ordering/templates/ordering-deployment.yaml

@ -14,40 +14,52 @@ spec:
containers:
- image: {{ .Values.image.repository }}:{{ .Values.image.tag }}
imagePullPolicy: {{ .Values.image.pullPolicy }}
args: ["start", "--cache-stack=kubernetes"]
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:
- name: App__SelfUrl
value: "{{ .Values.config.selfUrl }}"
- name: App__CorsOrigins
value: "{{ .Values.config.corsOrigins }}"
- name: "ConnectionStrings__OrderingService"
value: {{ .Values.config.connectionStrings.orderingService }}
- name: "ConnectionStrings__AdministrationService"
value: {{ .Values.config.connectionStrings.administrationService }}
- name: "DOTNET_ENVIRONMENT"
value: "{{ .Values.config.dotnetEnv }}"
- name: "Redis__Configuration"
value: "{{ .Values.config.redisHost }}"
- name: "RabbitMQ__Connections__Default__HostName"
value: "{{ .Values.config.rabbitmqHost }}"
- name: "ElasticSearch__Url"
value: "{{ .Values.config.elasticsearchHost }}"
- name: "AuthServer__Authority"
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"
value: "{{ .Values.config.authServer.swaggerClientSecret }}"
- name: "StringEncryption__DefaultPassPhrase"
value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}"
containerPort: 8443
env:
- name: "KC_DB"
value: "{{ .Values.config.kcDb }}"
- name: "KC_DB_URL"
value: "{{ .Values.config.kcDbUrl }}"
- name: "KC_DB_URL_HOST"
value: "{{ .Values.config.kcDbUrlHost }}"
- name: "KC_DB_URL_PORT"
value: "{{ .Values.config.kcDbUrlPort }}"
- name: "KC_DB_URL_DATABASE"
value: "{{ .Values.config.kcDbUrlDatabase }}"
- name: "KC_DB_USERNAME"
value: "{{ .Values.config.kcDbUsername }}"
- name: "KC_DB_PASSWORD"
value: "{{ .Values.config.kcDbPassword }}"
- name: "KEYCLOAK_ADMIN"
value: "{{ .Values.config.keycloakAdmin }}"
- name: "KEYCLOAK_ADMIN_PASSWORD"
value: "{{ .Values.config.keycloakAdminPassword }}"
- name: "KC_HEALTH_ENABLED"
value: "{{ .Values.config.kcHealthEnabled }}"
- name: "KC_HTTP_RELATIVE_PATH"
value: "{{ .Values.config.kcHttpRelativePath }}"
- name: "KC_PROXY"
value: "{{ .Values.config.kcProxy }}"
- name: "PROXY_ADDRESS_FORWARDING"
value: "{{ .Values.config.proxyAddressForwarding }}"
- name: "KC_HTTP_ENABLED"
value: "{{ .Values.config.kcHttpEnabled }}"
- name: "KC_HOSTNAME_URL"
value: "{{ .Values.config.kcHostnameUrl }}"
- name: "KC_HOSTNAME_ADMIN_URL"
value: "{{ .Values.config.kcHostnameAdminUrl }}"
- name: "jgroups.dns.query"
value: "{{ .Values.config.jgroupsDnsQuery }}"
- name: "KC_HOSTNAME_STRICT_BACKCHANNEL"
value: "{{ .Values.config.kcHostnameStrictBackchannel }}"
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

2
etc/k8s/eshoponabp/charts/ordering/templates/ordering-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

1
etc/k8s/eshoponabp/charts/ordering/values.yaml

@ -7,6 +7,7 @@ config:
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging

4
etc/k8s/eshoponabp/charts/payment/templates/payment-deployment.yaml

@ -17,7 +17,7 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:
@ -41,6 +41,8 @@ spec:
value: "{{ .Values.config.authServer.authority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServer.requireHttpsMetadata }}"
- name: "AuthServer__MetadataAddress"
value: "{{ .Values.config.authServer.metadataAddress }}"
- name: "AuthServer__SwaggerClientId"
value: "{{ .Values.config.authServer.swaggerClientId }}"
- name: "AuthServer__SwaggerClientSecret"

2
etc/k8s/eshoponabp/charts/payment/templates/payment-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

1
etc/k8s/eshoponabp/charts/payment/values.yaml

@ -7,6 +7,7 @@ config:
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak:8080
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging

2
etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml

@ -28,6 +28,8 @@ spec:
env:
- name: POSTGRES_PASSWORD
value: "myPassw0rd"
- name: POSTGRES_DB
value: "keycloak"
{{- if eq .Release.Name "eshop-az" }}
volumeClaimTemplates:
- metadata:

2
etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml

@ -17,7 +17,7 @@ spec:
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
containerPort: 8080
- name: https
containerPort: 443
env:

2
etc/k8s/eshoponabp/charts/public-web/templates/public-web-service.yaml

@ -7,7 +7,7 @@ metadata:
spec:
ports:
- name: "80"
port: 80
port: 8080
- name: "443"
port: 443
selector:

2
etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml

@ -18,7 +18,7 @@ data:
"clientId": "Web",
"responseType": "code",
"responseType": "{{ .Values.config.authServer.responseType }}",
"scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService",
"scope": "offline_access openid profile email phone roles AdministrationService IdentityService BasketService CatalogService OrderingService PaymentService CmskitService",
"strictDiscoveryDocumentValidation": {{ .Values.config.authServer.strictDiscoveryDocumentValidation }},
"skipIssuerCheck": {{ .Values.config.authServer.skipIssuerCheck }}
},

2
etc/k8s/eshoponabp/templates/NOTES.txt

@ -1,6 +1,6 @@
1. Web (Back Office) angular application URL:{{- if .Values.web.config.selfUrl }} {{ .Values.web.config.selfUrl }} {{- end }}
2. Public Web mvc application URL:{{- if index .Values "public-web" "config" "selfUrl" }} {{ index .Values "public-web" "config" "selfUrl" }} {{- end }}
3. Authentication Server URL:{{- if .Values.authserver.config.selfUrl }} {{ .Values.authserver.config.selfUrl }}
3. Authentication Server URL:{{- if .Values.keycloak.ingress.host }} {{ .Values.keycloak.ingress.host }}
For RabbitMq Administration use:
"kubectl port-forward services/{{ .Release.Name }}-rabbitmq 15672:15672 -n {{ .Release.Namespace }}"

228
etc/k8s/eshoponabp/values.st.yaml

@ -1,41 +1,46 @@
# auth-server sub-chart override
authserver:
keycloak:
config:
selfUrl: https://eshop-st-authserver
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-identity,https://eshop-st-administration,https://eshop-st-basket,https://eshop-st-catalog,https://eshop-st-ordering,https://eshop-st-cmskit,https://eshop-st-payment,https://eshop-st-web,https://eshop-st-public-web
allowedRedirectUrls: https://eshop-st-web
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
identityService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
kcDb: postgres
kcDbUrl: jdbc:postgresql://eshop-st-postgresdb:5432/keycloak
kcDbUrlHost: eshop-st-postgresdb
kcDbUrlPort: 5432
kcDbUrlDatabase: keycloak
kcDbUsername: postgres
kcDbPassword: myPassw0rd
keycloakAdmin: admin
keycloakAdminPassword: 1q2w3E*
kcHealthEnabled: true
kcHttpRelativePath : /
kcProxy: edge
proxyAddressForwarding: true
kcHttpEnabled: true
kcHostnameUrl: https://account.eshoponabp.dev
kcHostnameAdminUrl: https://account.eshoponabp.dev
jgroupsDnsQuery: eshop-st-keycloak:8080
kcHostnameStrictBackchannel: false
ingress:
host: eshop-st-authserver
host: account.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/app-authserver"
tag: 1.0.0
repository: quay.io/keycloak/keycloak
tag: 21.1.1
pullPolicy: IfNotPresent
# web sub-chart override
web:
config:
selfUrl: https://eshop-st-web
gatewayUrl: https://eshop-st-gateway-web
selfUrl: https://admin.eshoponabp.dev
gatewayUrl: https://gateway-web.eshoponabp.dev
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: false
responseType: "code"
strictDiscoveryDocumentValidation: false
skipIssuerCheck: true
ingress:
host: eshop-st-web
host: admin.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/app-web"
@ -44,19 +49,19 @@ web:
# public-web sub-chart override
public-web:
config:
selfUrl: https://eshop-st-public-web
gatewayUrl: http://eshop-st-gateway-web-public/
selfUrl: https://eshoponabp.dev
gatewayUrl: http://eshop-st-gateway-web-public:8080/
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
isOnProd: "false"
metaAddress: http://eshop-st-authserver
isOnProd: "true"
metaAddress: http://eshop-st-keycloak/realms/master
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-public-web
host: eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/app-publicweb"
@ -65,35 +70,41 @@ public-web:
# identity-service sub-chart override
identity:
config:
selfUrl: https://eshop-st-identity
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://identity.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
identityService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
keycloak:
url: http://eshop-st-keycloak
adminUsername: admin
adminPassword: 1q2w3E*
realmName: master
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
identityServerClients: # Seeded Clients
webRootUrl: https://eshop-st-web/
publicWebRootUrl: https://eshop-st-public-web/
webGatewayRootUrl: https://eshop-st-gateway-web/
publicWebGatewayRootUrl: https://eshop-st-gateway-web-public/
identityServiceRootUrl: https://eshop-st-identity/
administrationServiceRootUrl: https://eshop-st-administration/
accountServiceRootUrl: https://eshop-st-authserver/
basketServiceRootUrl: https://eshop-st-basket/
catalogServiceRootUrl: https://eshop-st-catalog/
orderingServiceRootUrl: https://eshop-st-ordering/
cmskitServiceRootUrl: https://eshop-st-cmskit/
paymentServiceRootUrl: https://eshop-st-payment/
keycloakClients: # Seeded Clients
webRootUrl: https://admin.eshoponabp.dev/
publicWebRootUrl: https://eshoponabp.dev/
webGatewayRootUrl: https://gateway-web.eshoponabp.dev/
publicWebGatewayRootUrl: https://gateway-public.eshoponabp.dev/
identityServiceRootUrl: https://identity.eshoponabp.dev/
administrationServiceRootUrl: https://administration.eshoponabp.dev/
accountServiceRootUrl: https://account.eshoponabp.dev/
basketServiceRootUrl: https://basket.eshoponabp.dev/
catalogServiceRootUrl: https://catalog.eshoponabp.dev/
orderingServiceRootUrl: https://ordering.eshoponabp.dev/
cmskitServiceRootUrl: https://cmskit.eshoponabp.dev/
paymentServiceRootUrl: https://payment.eshoponabp.dev/
ingress:
host: eshop-st-identity
host: identity.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-identity"
@ -102,26 +113,27 @@ identity:
# administration sub-chart override
administration:
config:
selfUrl: https://eshop-st-administration
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://administration.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: http://eshop-st-identity
abpIdentityBaseUrl: http://identity.eshoponabp.dev
useCurrentToken: "false"
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions
authority: http://eshop-st-authserver
authority: http://account.eshoponabp.dev
ingress:
host: eshop-st-administration
host: administration.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-administration"
@ -130,11 +142,10 @@ administration:
# gateway-web sub-chart override
gateway-web:
config:
selfUrl: https://eshop-st-gateway-web
corsOrigins: https://eshop-st-web
globalConfigurationBaseUrl: http://eshop-st-gateway-public
selfUrl: https://gateway-web.eshoponabp.dev
corsOrigins: http://admin.eshoponabp.dev,https://admin.eshoponabp.dev
authServer:
authority: http://eshop-st-authserver
authority: http://account.eshoponabp.dev
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -143,31 +154,34 @@ gateway-web:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-gateway-web
host: gateway-web.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/gateway-web"
tag: 1.0.0
reRoutes:
accountService:
url: http://eshop-st-authserver
identityService:
url: http://eshop-st-identity
url: http://eshop-st-identity:8080
dns: https://identity.eshoponabp.dev
administrationService:
url: http://eshop-st-administration
url: http://eshop-st-administration:8080
dns: https://administration.eshoponabp.dev
catalogService:
url: http://eshop-st-catalog
url: http://eshop-st-catalog:8080
dns: https://catalog.eshoponabp.dev
orderingService:
url: http://eshop-st-ordering
url: http://eshop-st-ordering:8080
dns: https://ordering.eshoponabp.dev
cmskitService:
url: http://eshop-st-cmskit
url: http://eshop-st-cmskit:8080
dns: https://cmskit.eshoponabp.dev
# gateway-web-public sub-chart override
gateway-web-public:
config:
selfUrl: https://eshop-st-gateway-web-public
selfUrl: https://gateway-public.eshoponabp.dev
authServer:
authority: http://eshop-st-authserver
authority: http://account.eshoponabp.dev
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -176,39 +190,45 @@ gateway-web-public:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-gateway-web-public
host: gateway-public.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/gateway-web-public"
tag: 1.0.0
reRoutes:
accountService:
url: http://eshop-st-authserver
identityService:
url: http://eshop-st-identity
url: http://eshop-st-identity:8080
dns: https://identity.eshoponabp.dev
administrationService:
url: http://eshop-st-administration
url: http://eshop-st-administration:8080
dns: https://administration.eshoponabp.dev
catalogService:
url: http://eshop-st-catalog
url: http://eshop-st-catalog:8080
dns: https://catalog.eshoponabp.dev
basketService:
url: http://eshop-st-basket
url: http://eshop-st-basket:8080
dns: https://basket.eshoponabp.dev
orderingService:
url: http://eshop-st-ordering
url: http://eshop-st-ordering:8080
dns: https://ordering.eshoponabp.dev
cmskitService:
url: http://eshop-st-cmskit
url: http://eshop-st-cmskit:8080
dns: https://cmskit.eshoponabp.dev
paymentService:
url: http://eshop-st-payment
url: http://eshop-st-payment:8080
dns: https://payment.eshoponabp.dev
# basket-service sub-chart override
basket:
config:
selfUrl: https://eshop-st-basket
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web
selfUrl: https://basket.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://eshoponabp.dev
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging
@ -216,10 +236,10 @@ basket:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
remoteServices:
catalogBaseUrl: http://eshop-st-catalog:80
catalogBaseUrl: http://eshop-st-catalog:8080
catalogGrpcUrl: http://eshop-st-catalog:81
ingress:
host: eshop-st-basket
host: basket.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-basket"
@ -228,14 +248,15 @@ basket:
# catalog-service sub-chart override
catalog:
config:
selfUrl: https://eshop-st-catalog
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web,https://eshop-st-web
selfUrl: https://catalog.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
catalogService: "mongodb://eshop-st-mongodb/EShopOnAbp_Catalog"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging
@ -243,12 +264,12 @@ catalog:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
kestrel:
httpUrl: http://eshop-st-catalog:80
httpUrl: http://eshop-st-catalog:8080
httpProtocols: Http1AndHttp2
grpcUrl: http://eshop-st-catalog:81
grpcProtocols: Http2
ingress:
host: eshop-st-catalog
host: catalog.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-catalog"
@ -257,14 +278,15 @@ catalog:
# ordering-service sub-chart override
ordering:
config:
selfUrl: https://eshop-st-ordering
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://ordering.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
orderingService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Staging
@ -272,7 +294,7 @@ ordering:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-ordering
host: ordering.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-ordering"
@ -281,26 +303,27 @@ ordering:
# cmskit-service sub-chart override
cmskit:
config:
selfUrl: https://eshop-st-cmskit
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://cmskit.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
cmskitervice: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Cmskit;User ID=postgres;password=myPassw0rd;Pooling=false"
cmskitService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Cmskit;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev/realms/master
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://eshop-st-identity
abpIdentityBaseUrl: https://identity.eshoponabp.dev
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions
authority: http://eshop-st-authserver
authority: http://account.eshoponabp.dev
ingress:
host: eshop-st-cmskit
host: cmskit.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-cmskit"
@ -309,24 +332,25 @@ cmskit:
# payment-service sub-chart override
payment:
config:
selfUrl: https://eshop-st-payment
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://payment.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
paymentService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://account.eshoponabp.dev
requireHttpsMetadata: "false"
metadataAddress: http://eshop-st-keycloak/realms/master
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://eshop-st-identity
abpIdentityBaseUrl: https://identity.eshoponabp.dev
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-payment
host: payment.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-payment"

168
etc/k8s/eshoponabp/values.yaml

@ -1,41 +1,35 @@
# auth-server sub-chart override
authserver:
keycloak:
config:
selfUrl: https://eshop-st-authserver
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-identity,https://eshop-st-administration,https://eshop-st-basket,https://eshop-st-catalog,https://eshop-st-ordering,https://eshop-st-cmskit,https://eshop-st-payment,https://eshop-st-web,https://eshop-st-public-web
allowedRedirectUrls: https://eshop-st-web
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
identityService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
dbVendor: postgres
dbAddr: eshop-st-postgresdb
dbDatabase: keycloak
dbUser: postgres
dbPassword: myPassw0rd
keycloakAdmin: admin
keycloakAdminPassword: 1q2w3E*
kcHealthEnabled: true
ingress:
host: eshop-st-authserver
host: account.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "ghcr.io/volosoft/eshoponabp/app-authserver"
tag: latest
repository: quay.io/keycloak/keycloak
tag: 19.0.2
pullPolicy: IfNotPresent
# web sub-chart override
web:
config:
selfUrl: https://eshop-st-web
gatewayUrl: https://eshop-st-gateway-web
selfUrl: https://admin.eshoponabp.dev
gatewayUrl: https://gateway-web.eshoponabp.dev
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev
requireHttpsMetadata: false
responseType: "code"
strictDiscoveryDocumentValidation: false
skipIssuerCheck: true
ingress:
host: eshop-st-web
host: admin.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/app-web"
@ -44,19 +38,19 @@ web:
# public-web sub-chart override
public-web:
config:
selfUrl: https://eshop-st-public-web
gatewayUrl: http://eshop-st-gateway-web-public/
selfUrl: https://eshoponabp.dev
gatewayUrl: https://gateway-public.eshoponabp.dev/
authServer:
authority: http://eshop-st-authserver
authority: https://account.eshoponabp.dev
requireHttpsMetadata: "false"
isOnProd: "false"
metaAddress: http://eshop-st-authserver
metaAddress: http://eshop-st-keycloak
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-public-web
host: eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/app-publicweb"
@ -65,13 +59,13 @@ public-web:
# identity-service sub-chart override
identity:
config:
selfUrl: https://eshop-st-identity
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://identity.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev
connectionStrings:
identityService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -80,20 +74,20 @@ identity:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
identityServerClients: # Seeded Clients
webRootUrl: https://eshop-st-web/
publicWebRootUrl: https://eshop-st-public-web/
webGatewayRootUrl: https://eshop-st-gateway-web/
publicWebGatewayRootUrl: https://eshop-st-gateway-web-public/
identityServiceRootUrl: https://eshop-st-identity/
administrationServiceRootUrl: https://eshop-st-administration/
accountServiceRootUrl: https://eshop-st-authserver/
basketServiceRootUrl: https://eshop-st-basket/
catalogServiceRootUrl: https://eshop-st-catalog/
orderingServiceRootUrl: https://eshop-st-ordering/
cmskitServiceRootUrl: https://eshop-st-cmskit/
paymentServiceRootUrl: https://eshop-st-payment/
webRootUrl: https://admin.eshoponabp.dev/
publicWebRootUrl: https://eshoponabp.dev/
webGatewayRootUrl: https://gateway-web.eshoponabp.dev/
publicWebGatewayRootUrl: https://gateway-public.eshoponabp.dev/
identityServiceRootUrl: https://identity.eshoponabp.dev/
administrationServiceRootUrl: https://administration.eshoponabp.dev/
accountServiceRootUrl: https://account.eshoponabp.dev/
basketServiceRootUrl: https://basket.eshoponabp.dev/
catalogServiceRootUrl: https://catalog.eshoponabp.dev/
orderingServiceRootUrl: https://ordering.eshoponabp.dev/
cmskitServiceRootUrl: https://cmskit.eshoponabp.dev/
paymentServiceRootUrl: https://payment.eshoponabp.dev/
ingress:
host: eshop-st-identity
host: identity.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-identity"
@ -102,26 +96,26 @@ identity:
# administration sub-chart override
administration:
config:
selfUrl: https://eshop-st-administration
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://administration.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://eshop-st-identity
abpIdentityBaseUrl: https://identity.eshoponabp.dev
useCurrentToken: "false"
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions
authority: https://eshop-st-authserver
authority: https://account.eshoponabp.dev
ingress:
host: eshop-st-administration
host: administration.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-administration"
@ -130,11 +124,11 @@ administration:
# gateway-web sub-chart override
gateway-web:
config:
selfUrl: https://eshop-st-gateway-web
corsOrigins: https://eshop-st-web
globalConfigurationBaseUrl: http://eshop-st-gateway-public
selfUrl: https://gateway-web.eshoponabp.dev
corsOrigins: https://admin.eshoponabp.dev
globalConfigurationBaseUrl: http://eshop-st-gateway-web-public
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -143,14 +137,14 @@ gateway-web:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-gateway-web
host: gateway-web.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/gateway-web"
tag: 1.0.0
reRoutes:
accountService:
url: http://eshop-st-authserver
url: http://eshop-st-keycloak
identityService:
url: http://eshop-st-identity
administrationService:
@ -165,9 +159,9 @@ gateway-web:
# gateway-web-public sub-chart override
gateway-web-public:
config:
selfUrl: https://eshop-st-gateway-web-public
selfUrl: https://gateway-public.eshoponabp.dev
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -176,14 +170,12 @@ gateway-web-public:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-gateway-web-public
host: gateway-public.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/gateway-web-public"
tag: 1.0.0
reRoutes:
accountService:
url: http://eshop-st-authserver
identityService:
url: http://eshop-st-identity
administrationService:
@ -197,17 +189,17 @@ gateway-web-public:
cmskitService:
url: http://eshop-st-cmskit
paymentService:
url: http://eshop-st-payment
url: http://eshop-st-payment
# basket-service sub-chart override
basket:
config:
selfUrl: https://eshop-st-basket
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web
selfUrl: https://basket.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://eshoponabp.dev
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -219,7 +211,7 @@ basket:
catalogBaseUrl: http://eshop-st-catalog:80
catalogGrpcUrl: http://eshop-st-catalog:81
ingress:
host: eshop-st-basket
host: basket.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-basket"
@ -228,13 +220,13 @@ basket:
# catalog-service sub-chart override
catalog:
config:
selfUrl: https://eshop-st-catalog
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web,https://eshop-st-web
selfUrl: https://catalog.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev,https://eshoponabp.dev,https://admin.eshoponabp.dev
connectionStrings:
catalogService: "mongodb://eshop-st-mongodb/EShopOnAbp_Catalog"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -248,7 +240,7 @@ catalog:
grpcUrl: http://eshop-st-catalog:81
grpcProtocols: Http2
ingress:
host: eshop-st-catalog
host: catalog.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-catalog"
@ -257,13 +249,13 @@ catalog:
# ordering-service sub-chart override
ordering:
config:
selfUrl: https://eshop-st-ordering
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://ordering.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev
connectionStrings:
orderingService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -272,7 +264,7 @@ ordering:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-ordering
host: ordering.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-ordering"
@ -281,50 +273,52 @@ ordering:
# cmskit-service sub-chart override
cmskit:
config:
selfUrl: https://eshop-st-cmskit
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://cmskit.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev
connectionStrings:
cmskitService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Cmskit;User ID=postgres;password=myPassw0rd;Pooling=false"
cmskitervice: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Cmskit;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://eshop-st-identity
abpIdentityBaseUrl: https://identity.eshoponabp.dev
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions
authority: https://eshop-st-authserver
authority: https://admin.eshoponabp.dev
ingress:
host: eshop-st-cmskit
host: cmskit.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "ghcr.io/volosoft/eshoponabp/service-cmskit"
tag: 1.0.1
repository: "eshoponabp/service-cmskit"
tag: 1.0.0
# payment-service sub-chart override
payment:
config:
selfUrl: https://eshop-st-payment
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public
selfUrl: https://payment.eshoponabp.dev
corsOrigins: https://gateway-web.eshoponabp.dev,https://gateway-public.eshoponabp.dev
connectionStrings:
paymentService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://identity.eshoponabp.dev
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
ingress:
host: eshop-st-payment
host: payment.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: "eshoponabp/service-payment"

113
gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.Staging.json

@ -1,113 +0,0 @@
{
"ReverseProxy": {
"Routes": {
"Account Service": {
"ClusterId": "accountCluster",
"Match": {
"Path": "/api/account/{**everything}"
}
},
"Administration Service": {
"ClusterId": "administrationCluster",
"Match": {
"Path": "/api/abp/{**everything}"
}
},
"Catalog Service": {
"ClusterId": "catalogCluster",
"Match": {
"Path": "/api/catalog/{**everything}"
}
},
"Basket Service": {
"ClusterId": "basketCluster",
"Match": {
"Path": "/api/basket/{**everything}"
}
},
"Ordering Service": {
"ClusterId": "orderingCluster",
"Match": {
"Path": "/api/ordering/{**everything}"
}
},
"Payment Service": {
"ClusterId": "paymentCluster",
"Match": {
"Path": "/api/payment/{**everything}"
}
},
"Cmskit Service": {
"ClusterId": "cmskitCluster",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
},
"product-picture-route": {
"ClusterId": "productPictureCluster",
"Match": {
"Path": "/product-images/{**everything}",
"Methods": [ "GET" ]
}
}
},
"Clusters": {
"accountCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-authserver"
}
}
},
"administrationCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-administration"
}
}
},
"catalogCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-catalog"
}
}
},
"basketCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-basket"
}
}
},
"orderingCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-ordering"
}
}
},
"paymentCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-payment"
}
}
},
"cmskitCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-cmskit"
}
}
},
"productPictureCluster": {
"Destinations": {
"destination1": {
"Address": "http://eshop-st-catalog"
}
}
}
}
}
}

3
gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json

@ -1,7 +1,8 @@
{
"App": {
"SelfUrl": "https://localhost:44373",
"CorsOrigins": "https://localhost:44335"
"CorsOrigins": "https://localhost:44335",
"IsOnK8s": "false"
},
"AuthServer": {
"Authority": "http://localhost:8080/realms/master",

118
gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json

@ -2,19 +2,19 @@
"ReverseProxy": {
"Routes": {
"AbpApi": {
"ClusterId": "administrationCluster",
"ClusterId": "Administration",
"Match": {
"Path": "/api/abp/{**catch-all}"
}
},
"Identity Service": {
"ClusterId": "identityCluster",
"ClusterId": "Identity",
"Match": {
"Path": "/api/identity/{**everything}"
}
},
"Identity Service Swagger": {
"ClusterId": "identityCluster",
"ClusterId": "Identity",
"Match": {
"Path": "/swagger-json/Identity/swagger/v1/swagger.json"
},
@ -23,25 +23,25 @@
]
},
"FeatureManagement": {
"ClusterId": "feature-management-cluster",
"ClusterId": "Administration",
"Match": {
"Path": "/api/feature-management/{**everything}"
}
},
"PermissionManagement": {
"ClusterId": "permission-management-cluster",
"ClusterId": "Administration",
"Match": {
"Path": "/api/permission-management/{**everything}"
}
},
"SettingManagement": {
"ClusterId": "setting-management-cluster",
"ClusterId": "Administration",
"Match": {
"Path": "/api/setting-management/{**everything}"
}
},
"Administration Service Swagger": {
"ClusterId": "administrationCluster",
"ClusterId": "Administration",
"Match": {
"Path": "/swagger-json/Administration/swagger/v1/swagger.json"
},
@ -64,27 +64,36 @@
{ "PathRemovePrefix": "/swagger-json/Catalog" }
]
},
"product-picture-route": {
"ClusterId": "productPictureCluster",
"ProductPictures": {
"ClusterId": "catalogCluster",
"Match": {
"Path": "/product-images/{**everything}",
"Methods": [ "GET" ]
}
},
"Basket Service": {
"ClusterId": "basketCluster",
"ClusterId": "Basket",
"Match": {
"Path": "/api/basket/{**everything}"
}
},
"Basket Service Swagger": {
"ClusterId": "Basket",
"Match": {
"Path": "/swagger-json/Basket/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Basket" }
]
},
"Ordering Service": {
"ClusterId": "orderingCluster",
"ClusterId": "Ordering",
"Match": {
"Path": "/api/ordering/{**everything}"
}
},
"Ordering Service Swagger": {
"ClusterId": "orderingCluster",
"ClusterId": "Ordering",
"Match": {
"Path": "/swagger-json/Ordering/swagger/v1/swagger.json"
},
@ -93,13 +102,13 @@
]
},
"Cmskit Service": {
"ClusterId": "cmskitCluster",
"ClusterId": "CmsKit",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
},
"Cmskit Service Swagger": {
"ClusterId": "cmskitCluster",
"ClusterId": "CmsKit",
"Match": {
"Path": "/swagger-json/Cmskit/swagger/v1/swagger.json"
},
@ -108,80 +117,89 @@
]
},
"Payment Service": {
"ClusterId": "paymentCluster",
"ClusterId": "Payment",
"Match": {
"Path": "/api/payment/{**everything}"
}
},
"Payment Service Swagger": {
"ClusterId": "Payment",
"Match": {
"Path": "/swagger-json/Payment/swagger/v1/swagger.json"
},
"Transforms": [
{ "PathRemovePrefix": "/swagger-json/Payment" }
]
}
},
"Clusters": {
"identityCluster": {
"Identity": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44351"
"Address": "https://localhost:44351",
"MetaData": {
"PublicAddress": "https://identity.eshoponabp.dev"
}
}
}
},
"administrationCluster": {
"Administration": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44353"
}
}
},
"permission-management-cluster": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44353"
}
}
},
"setting-management-cluster": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44353"
}
"Address": "https://localhost:44353",
"MetaData": {
"PublicAddress": "https://admininstration.eshop.dev"
}
}
}
},
"catalogCluster": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44354"
}
}
},
"basketCluster": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44355"
"Address": "https://localhost:44354",
"MetaData": {
"PublicAddress": "https://admininstration.eshoponabp.dev"
}
}
}
},
"orderingCluster": {
"Basket": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44356"
"Address": "https://localhost:44355",
"MetaData": {
"PublicAddress": "https://basket.eshoponabp.dev"
}
}
}
},
"cmskitCluster": {
"Ordering": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44358"
"Address": "https://localhost:44356",
"MetaData": {
"PublicAddress": "https://ordering.eshoponabp.dev"
}
}
}
},
"productPictureCluster": {
"CmsKit": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44354"
"Address": "https://localhost:44358",
"MetaData": {
"PublicAddress": "https://cmskit.eshoponabp.dev"
}
}
}
},
"paymentCluster": {
"Payment": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44357"
"Address": "https://localhost:44357",
"MetaData": {
"PublicAddress": "https://payment.eshoponabp.dev"
}
}
}
}

3
gateways/web/src/EShopOnAbp.WebGateway/appsettings.json

@ -1,7 +1,8 @@
{
"App": {
"SelfUrl": "https://localhost:44372",
"CorsOrigins": "http://localhost:4200"
"CorsOrigins": "http://localhost:4200,https://localhost:4200",
"IsOnK8s": "false"
},
"AuthServer": {
"Authority": "http://localhost:8080/realms/master",

69
gateways/web/src/EShopOnAbp.WebGateway/yarp.json

@ -2,19 +2,19 @@
"ReverseProxy": {
"Routes": {
"AbpApi": {
"ClusterId": "administrationCluster",
"ClusterId": "Administration",
"Match": {
"Path": "/api/abp/{**catch-all}"
}
},
"Identity Service": {
"ClusterId": "identityCluster",
"ClusterId": "Identity",
"Match": {
"Path": "/api/identity/{**everything}"
}
},
"Identity Service Swagger": {
"ClusterId": "identityCluster",
"ClusterId": "Identity",
"Match": {
"Path": "/swagger-json/Identity/swagger/v1/swagger.json"
},
@ -41,7 +41,7 @@
}
},
"Administration Service Swagger": {
"ClusterId": "administrationCluster",
"ClusterId": "Administration",
"Match": {
"Path": "/swagger-json/Administration/swagger/v1/swagger.json"
},
@ -50,13 +50,13 @@
]
},
"Catalog Service": {
"ClusterId": "catalogCluster",
"ClusterId": "Catalog",
"Match": {
"Path": "/api/catalog/{**everything}"
}
},
"Catalog Service Swagger": {
"ClusterId": "catalogCluster",
"ClusterId": "Catalog",
"Match": {
"Path": "/swagger-json/Catalog/swagger/v1/swagger.json"
},
@ -65,13 +65,13 @@
]
},
"Ordering Service": {
"ClusterId": "orderingCluster",
"ClusterId": "Ordering",
"Match": {
"Path": "/api/ordering/{**everything}"
}
},
"Ordering Service Swagger": {
"ClusterId": "orderingCluster",
"ClusterId": "Ordering",
"Match": {
"Path": "/swagger-json/Ordering/swagger/v1/swagger.json"
},
@ -80,13 +80,13 @@
]
},
"Cmskit Service": {
"ClusterId": "cmskitCluster",
"ClusterId": "CmsKit",
"Match": {
"Path": "/api/cmskit/{**everything}"
}
},
"Cmskit Service Swagger": {
"ClusterId": "cmskitCluster",
"ClusterId": "CmsKit",
"Match": {
"Path": "/swagger-json/Cmskit/swagger/v1/swagger.json"
},
@ -96,52 +96,53 @@
}
},
"Clusters": {
"identityCluster": {
"Identity": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44351"
"Address": "https://localhost:44351",
"MetaData": {
"PublicAddress": "https://identity.eshoponabp.dev"
}
}
}
},
"administrationCluster": {
"Administration": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44353"
"Address": "https://localhost:44353",
"MetaData": {
"PublicAddress": "https://administration.eshoponabp.dev"
}
}
}
},
"permission-management-cluster": {
"Catalog": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44353"
"Address": "https://localhost:44354",
"MetaData": {
"PublicAddress": "https://catalog.eshoponabp.dev"
}
}
}
},
"setting-management-cluster": {
"Ordering": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44353"
"Address": "https://localhost:44356",
"MetaData": {
"PublicAddress": "https://ordering.eshoponabp.dev"
}
}
}
},
"catalogCluster": {
"CmsKit": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44354"
}
}
},
"orderingCluster": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44356"
}
}
},
"cmskitCluster": {
"Destinations": {
"destination1": {
"Address": "https://localhost:44358"
"Address": "https://localhost:44358",
"MetaData": {
"PublicAddress": "https://cmskit.eshoponabp.dev"
}
}
}
}

432
services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/DbMigrations/KeycloakDataSeeder.cs

@ -0,0 +1,432 @@
using System;
using System.Collections.Generic;
using System.Linq;
using System.Threading.Tasks;
using EShopOnAbp.IdentityService.Keycloak.Service;
using Keycloak.Net;
using Keycloak.Net.Models.Clients;
using Keycloak.Net.Models.ClientScopes;
using Keycloak.Net.Models.ProtocolMappers;
using Microsoft.Extensions.Configuration;
using Microsoft.Extensions.Logging;
using Microsoft.Extensions.Options;
using Volo.Abp.Data;
using Volo.Abp.DependencyInjection;
namespace EShopOnAbp.IdentityService.DbMigrations;
public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency
{
private readonly KeycloakClient _keycloakClient;
private readonly KeycloakClientOptions _keycloakOptions;
private readonly ILogger<KeyCloakDataSeeder> _logger;
private readonly IConfiguration _configuration;
public KeyCloakDataSeeder(IOptions<KeycloakClientOptions> keycloakClientOptions, ILogger<KeyCloakDataSeeder> logger,
IConfiguration configuration)
{
_logger = logger;
_configuration = configuration;
_keycloakOptions = keycloakClientOptions.Value;
_keycloakClient = new KeycloakClient(
_keycloakOptions.Url,
_keycloakOptions.AdminUserName,
_keycloakOptions.AdminPassword
);
}
public async Task SeedAsync(DataSeedContext context)
{
await UpdateRealmSettingsAsync();
await UpdateAdminUserAsync();
await CreateRoleMapperAsync(); // roles scope
await CreateClientScopesAsync();
await CreateClientsAsync();
}
private async Task UpdateRealmSettingsAsync()
{
var masterRealm = await _keycloakClient.GetRealmAsync(_keycloakOptions.RealmName);
if (masterRealm.AccessTokenLifespan != 30 * 60)
{
masterRealm.AccessTokenLifespan = 30 * 60;
await _keycloakClient.UpdateRealmAsync(_keycloakOptions.RealmName, masterRealm);
}
}
private async Task CreateRoleMapperAsync()
{
var roleScope = (await _keycloakClient.GetClientScopesAsync(_keycloakOptions.RealmName))
.FirstOrDefault(q => q.Name == "roles");
if (roleScope == null)
return;
if (!roleScope.ProtocolMappers.Any(q => q.Name == "roles"))
{
await _keycloakClient.CreateProtocolMapperAsync(_keycloakOptions.RealmName, roleScope.Id,
new ProtocolMapper()
{
Name = "roles",
Protocol = "openid-connect",
_ProtocolMapper = "oidc-usermodel-realm-role-mapper",
Config = new Dictionary<string, string>()
{
{ "access.token.claim", "true" },
{ "id.token.claim", "true" },
{ "claim.name", "role" },
{ "multivalued", "true" },
{ "userinfo.token.claim", "true" },
}
});
}
}
private async Task CreateClientScopesAsync()
{
await CreateScopeAsync("AdministrationService");
await CreateScopeAsync("IdentityService");
await CreateScopeAsync("BasketService");
await CreateScopeAsync("CatalogService");
await CreateScopeAsync("OrderingService");
await CreateScopeAsync("PaymentService");
await CreateScopeAsync("CmskitService");
}
private async Task CreateScopeAsync(string scopeName)
{
var scope = (await _keycloakClient.GetClientScopesAsync(_keycloakOptions.RealmName))
.FirstOrDefault(q => q.Name == scopeName);
if (scope == null)
{
scope = new ClientScope
{
Name = scopeName,
Description = scopeName + " scope",
Protocol = "openid-connect",
Attributes = new Attributes
{
ConsentScreenText = scopeName,
DisplayOnConsentScreen = "true",
IncludeInTokenScope = "true"
},
ProtocolMappers = new List<ProtocolMapper>()
{
new ProtocolMapper()
{
Name = scopeName,
Protocol = "openid-connect",
_ProtocolMapper = "oidc-audience-mapper",
Config =
new
Dictionary<string, string>
{
{ "id.token.claim", "false" },
{ "access.token.claim", "true" },
{ "included.custom.audience", scopeName }
}
}
}
};
await _keycloakClient.CreateClientScopeAsync(_keycloakOptions.RealmName, scope);
}
}
private async Task CreateClientsAsync()
{
await CreatePublicWebClientAsync();
await CreateSwaggerClientAsync();
await CreateWebClientAsync();
// await CreateCmskitClientAsync();
// await CreateAdministrationClientAsync();
}
private async Task CreateAdministrationClientAsync()
{
var administrationClient =
(await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName,
clientId: "EShopOnAbp_AdministrationService"))
.FirstOrDefault();
if (administrationClient == null)
{
administrationClient = new Client()
{
ClientId = "EShopOnAbp_AdministrationService",
Name = "Administration service client",
Protocol = "openid-connect",
PublicClient = false,
ImplicitFlowEnabled = false,
AuthorizationServicesEnabled = false,
StandardFlowEnabled = false,
DirectAccessGrantsEnabled = false,
ServiceAccountsEnabled = true,
Secret = "1q2w3e*"
};
administrationClient.Attributes = new Dictionary<string, object>()
{
{ "oauth2.device.authorization.grant.enabled", false },
{ "oidc.ciba.grant.enabled", false }
};
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, administrationClient);
await AddOptionalClientScopesAsync(
"EShopOnAbp_AdministrationService",
new List<string>
{
"IdentityService"
}
);
var insertedClient =
(await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "EShopOnAbp_AdministrationService"))
.First();
var clientIdProtocolMapper = insertedClient.ProtocolMappers.First(q => q.Name == "Client ID");
clientIdProtocolMapper.Config["claim.name"] = "client_id";
var result = await _keycloakClient.UpdateClientAsync(_keycloakOptions.RealmName, insertedClient.Id,
insertedClient);
}
}
private async Task CreateCmskitClientAsync()
{
var cmsKitClient =
(await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "EShopOnAbp_CmskitService"))
.FirstOrDefault();
if (cmsKitClient == null)
{
cmsKitClient = new Client()
{
ClientId = "EShopOnAbp_CmskitService",
Name = "Cmskit microservice client",
Protocol = "openid-connect",
PublicClient = false,
ImplicitFlowEnabled = false,
AuthorizationServicesEnabled = false,
StandardFlowEnabled = false,
DirectAccessGrantsEnabled = false,
ServiceAccountsEnabled = true,
Secret = "1q2w3e*"
};
cmsKitClient.Attributes = new Dictionary<string, object>()
{
{ "oauth2.device.authorization.grant.enabled", false },
{ "oidc.ciba.grant.enabled", false },
{ "client_credentials.use_refresh_token", false }
};
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, cmsKitClient);
await AddOptionalClientScopesAsync(
"EShopOnAbp_CmskitService",
new List<string>
{
"IdentityService"
}
);
var insertedClient =
(await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "EShopOnAbp_CmskitService"))
.First();
var clientIdProtocolMapper = insertedClient.ProtocolMappers.First(q => q.Name == "Client ID");
clientIdProtocolMapper.Config["claim.name"] = "client_id";
var result = await _keycloakClient.UpdateClientAsync(_keycloakOptions.RealmName, insertedClient.Id,
insertedClient);
}
}
private async Task CreateWebClientAsync()
{
var webClient = (await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "Web"))
.FirstOrDefault();
if (webClient == null)
{
var webRootUrl = _configuration[$"Clients:Web:RootUrl"];
webClient = new Client
{
ClientId = "Web",
Name = "Angular Back-Office Web Application",
Protocol = "openid-connect",
Enabled = true,
BaseUrl = webRootUrl,
RedirectUris = new List<string>
{
$"{webRootUrl.TrimEnd('/')}"
},
FrontChannelLogout = true,
PublicClient = true
};
webClient.Attributes = new Dictionary<string, object>
{
{ "post.logout.redirect.uris", $"{webRootUrl.TrimEnd('/')}" }
};
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, webClient);
await AddOptionalClientScopesAsync(
"Web",
new List<string>
{
"AdministrationService", "IdentityService", "BasketService", "CatalogService",
"OrderingService", "PaymentService", "CmskitService"
}
);
}
}
private async Task CreateSwaggerClientAsync()
{
var swaggerClient =
(await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "SwaggerClient"))
.FirstOrDefault();
if (swaggerClient == null)
{
var webGatewaySwaggerRootUrl = _configuration[$"Clients:WebGateway:RootUrl"].TrimEnd('/');
var publicWebGatewayRootUrl = _configuration[$"Clients:PublicWebGateway:RootUrl"].TrimEnd('/');
var accountServiceRootUrl = _configuration[$"Clients:AccountService:RootUrl"].TrimEnd('/');
var identityServiceRootUrl = _configuration[$"Clients:IdentityService:RootUrl"].TrimEnd('/');
var administrationServiceRootUrl = _configuration[$"Clients:AdministrationService:RootUrl"].TrimEnd('/');
var catalogServiceRootUrl = _configuration[$"Clients:CatalogService:RootUrl"].TrimEnd('/');
var basketServiceRootUrl = _configuration[$"Clients:BasketService:RootUrl"].TrimEnd('/');
var orderingServiceRootUrl = _configuration[$"Clients:OrderingService:RootUrl"].TrimEnd('/');
var paymentServiceRootUrl = _configuration[$"Clients:PaymentService:RootUrl"].TrimEnd('/');
var cmskitServiceRootUrl = _configuration[$"Clients:CmskitService:RootUrl"].TrimEnd('/');
swaggerClient = new Client
{
ClientId = "SwaggerClient",
Name = "Swagger Client Application",
Protocol = "openid-connect",
Enabled = true,
RedirectUris = new List<string>
{
$"{webGatewaySwaggerRootUrl}/swagger/oauth2-redirect.html", // WebGateway redirect uri
$"{publicWebGatewayRootUrl}/swagger/oauth2-redirect.html", // PublicWebGateway redirect uri
$"{accountServiceRootUrl}/swagger/oauth2-redirect.html", // AccountService redirect uri
$"{identityServiceRootUrl}/swagger/oauth2-redirect.html", // IdentityService redirect uri
$"{administrationServiceRootUrl}/swagger/oauth2-redirect.html", // AdministrationService redirect uri
$"{catalogServiceRootUrl}/swagger/oauth2-redirect.html", // CatalogService redirect uri
$"{basketServiceRootUrl}/swagger/oauth2-redirect.html", // BasketService redirect uri
$"{orderingServiceRootUrl}/swagger/oauth2-redirect.html", // OrderingService redirect uri
$"{paymentServiceRootUrl}/swagger/oauth2-redirect.html", // PaymentService redirect uri
$"{cmskitServiceRootUrl}/swagger/oauth2-redirect.html" // CmskitService redirect uri
},
FrontChannelLogout = true,
PublicClient = true
};
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, swaggerClient);
await AddOptionalClientScopesAsync(
"SwaggerClient",
new List<string>
{
"AdministrationService", "IdentityService", "BasketService", "CatalogService",
"OrderingService", "PaymentService", "CmskitService"
}
);
}
}
private async Task CreatePublicWebClientAsync()
{
var publicWebClient = (await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "PublicWeb"))
.FirstOrDefault();
if (publicWebClient == null)
{
var publicWebRootUrl = _configuration[$"Clients:PublicWeb:RootUrl"];
publicWebClient = new Client
{
ClientId = "PublicWeb",
Name = "Public Web Application",
Protocol = "openid-connect",
Enabled = true,
BaseUrl = publicWebRootUrl,
RedirectUris = new List<string>
{
$"{publicWebRootUrl.TrimEnd('/')}/signin-oidc"
},
FrontChannelLogout = true,
PublicClient = true,
ImplicitFlowEnabled = true // for hybrid flow
};
publicWebClient.Attributes = new Dictionary<string, object>
{
{ "post.logout.redirect.uris", $"{publicWebRootUrl.TrimEnd('/')}/signout-callback-oidc" }
};
await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, publicWebClient);
await AddOptionalClientScopesAsync(
"PublicWeb",
new List<string>
{
"AdministrationService", "IdentityService", "BasketService", "CatalogService",
"OrderingService", "PaymentService", "CmskitService"
}
);
}
}
private async Task AddOptionalClientScopesAsync(string clientName, List<string> scopes)
{
var client = (await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: clientName))
.FirstOrDefault();
if (client == null)
{
_logger.LogError($"Couldn't find {clientName}! Could not seed optional scopes!");
return;
}
var clientOptionalScopes =
(await _keycloakClient.GetOptionalClientScopesAsync(_keycloakOptions.RealmName, client.Id)).ToList();
var clientScopes = (await _keycloakClient.GetClientScopesAsync(_keycloakOptions.RealmName)).ToList();
foreach (var scope in scopes)
{
if (!clientOptionalScopes.Any(q => q.Name == scope))
{
var serviceScope = clientScopes.First(q => q.Name == scope);
_logger.LogInformation($"Seeding {scope} scope to {clientName}.");
await _keycloakClient.UpdateOptionalClientScopeAsync(_keycloakOptions.RealmName, client.Id,
serviceScope.Id);
}
}
}
private async Task UpdateAdminUserAsync()
{
var users = await _keycloakClient.GetUsersAsync(_keycloakOptions.RealmName, username: "admin");
var adminUser = users.FirstOrDefault();
if (adminUser == null)
{
throw new Exception(
"Keycloak admin user is not provided, check if KEYCLOAK_ADMIN environment variable is passed properly.");
}
if (string.IsNullOrEmpty(adminUser.Email))
{
adminUser.Email = "admin@abp.io";
adminUser.FirstName = "admin";
adminUser.EmailVerified = true;
_logger.LogInformation("Updating admin user with email and first name...");
await _keycloakClient.UpdateUserAsync(_keycloakOptions.RealmName, adminUser.Id, adminUser);
}
}
}

1
services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/EShopOnAbp.IdentityService.HttpApi.Host.csproj

@ -6,6 +6,7 @@
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Keycloak.Net.Core" Version="1.0.22" />
<PackageReference Include="Microsoft.EntityFrameworkCore.Tools" Version="8.0.0">
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>

2
services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json

@ -47,7 +47,7 @@
"ElasticSearch": {
"Url": "http://localhost:9200"
},
"IdentityServerClients": {
"Clients": {
"Web": {
"RootUrl": "http://localhost:4200"
},

12
shared/EShopOnAbp.Shared.Hosting.Gateways/YarpSwaggerUIBuilderExtensions.cs

@ -1,4 +1,5 @@
using System.Linq;
using System;
using System.Linq;
using Microsoft.AspNetCore.Builder;
using Microsoft.Extensions.Configuration;
using Microsoft.Extensions.DependencyInjection;
@ -41,7 +42,14 @@ public static class YarpSwaggerUIBuilderExtensions
continue;
}
options.SwaggerEndpoint($"{clusterGroup.Value.Address}/swagger/v1/swagger.json", $"{routeConfig.RouteId} API");
var baseUrl = clusterGroup.Value.Address;
if (Convert.ToBoolean(configuration["App:IsOnK8s"])) // If the application is running on K8s, the swagger.json should be reached from public dns.
{
baseUrl = clusterGroup.Value.Metadata?["PublicAddress"];
}
options.SwaggerEndpoint($"{baseUrl}/swagger/v1/swagger.json", $"{routeConfig.RouteId} API");
options.OAuthClientId(configuration["AuthServer:SwaggerClientId"]);
}
});

17
shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs

@ -1,6 +1,7 @@
using Microsoft.AspNetCore.Authentication.JwtBearer;
using System;
using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.Extensions.DependencyInjection;
using System;
using Microsoft.IdentityModel.Tokens;
using Volo.Abp.Modularity;
namespace EShopOnAbp.Shared.Hosting.Microservices;
@ -19,6 +20,18 @@ public static class JwtBearerConfigurationHelper
options.Authority = configuration["AuthServer:Authority"];
options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]);
options.Audience = audience;
// IDX10204: Unable to validate issuer on K8s if not set
options.TokenValidationParameters = new TokenValidationParameters()
{
ValidIssuers = new[]
{ configuration["AuthServer:Authority"], configuration["AuthServer:MetadataAddress"] },
// IDX10500: Signature validation failed. No security keys were provided to validate the signature on K8s
SignatureValidator = delegate(string token, TokenValidationParameters parameters)
{
var jwt = new Microsoft.IdentityModel.JsonWebTokens.JsonWebToken(token);
return jwt;
}
};
});
}
}
Loading…
Cancel
Save