diff --git a/.gitignore b/.gitignore index 6d18483d..8af19598 100644 --- a/.gitignore +++ b/.gitignore @@ -13,6 +13,9 @@ *.tye *.env .env +*.pem +*.crt +*.key # User-specific files (MonoDevelop/Xamarin Studio) *.userprefs diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json new file mode 100644 index 00000000..5e2fe164 --- /dev/null +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json @@ -0,0 +1,31 @@ +{ + "App": { + "SelfUrl": "https://app-authserver", + "CorsOrigins": "http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service", + "RedirectAllowedUrls": "http://app-web" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "ConnectionStrings": { + "IdentityService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false;", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_AuthServer", + "ExchangeName": "EShopOnAbp" + } + } +} diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json index 290fc0f6..047dd51c 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json @@ -1,8 +1,8 @@ { "App": { "SelfUrl": "https://localhost:44330", - "CorsOrigins": "https://*.EShopOnAbp.com,http://localhost:4200,https://localhost:44307,https://localhost:44351,https://localhost:44353,https://localhost:44354,https://localhost:44355,https://localhost:44356,https://localhost:44357,https://localhost:44372,https://localhost:44373,http://localhost:4200", - "RedirectAllowedUrls": "http://localhost:4200,https://localhost:44307" + "CorsOrigins": "http://localhost:4200,https://localhost:44351,https://localhost:44353,https://localhost:44354,https://localhost:44355,https://localhost:44356,https://localhost:44357", + "RedirectAllowedUrls": "http://localhost:4200" }, "Logging": { "LogLevel": { diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json new file mode 100644 index 00000000..47024036 --- /dev/null +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json @@ -0,0 +1,49 @@ +{ + "App": { + "SelfUrl": "https://app-publicweb" + }, + "RemoteServices": { + "Default": { + "BaseUrl": "http://gateway-web-public" + } + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_PublicWeb", + "ExchangeName": "EShopOnAbp" + } + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "ClientId": "PublicWeb", + "ClientSecret": "1q2w3e*" + }, + "ReverseProxy": { + "Routes": { + "route1" : { + "ClusterId": "cluster1", + "Match": { + "Path": "/api/{**anypath}" + } + } + }, + "Clusters": { + "cluster1": { + "Destinations": { + "destination1": { + "Address": "http://gateway-web-public" + } + } + } + } + } +} \ No newline at end of file diff --git a/etc/README.md b/etc/README.md index 3ff8d9a0..71d918d3 100644 --- a/etc/README.md +++ b/etc/README.md @@ -1,4 +1,4 @@ - ### Pre-requirements + # Pre-requirements * Docker Desktop with Kubernetes enabled * Install [NGINX ingress](https://kubernetes.github.io/ingress-nginx/deploy/) for k8s @@ -8,12 +8,12 @@ OR helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx helm repo update -helm install ingress-nginx ingress-nginx/ingress-nginx +helm upgrade --install --version=4.0.19 ingress-nginx ingress-nginx/ingress-nginx ``` * Install [Helm](https://helm.sh/docs/intro/install/) for running helm charts -### How to run? +# How to run? * Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`): @@ -36,3 +36,38 @@ helm install ingress-nginx ingress-nginx/ingress-nginx * *You may wait ~30 seconds on first run for preparing the database*. * Browse https://eshop-st-public-web for public and https://eshop-st-web for web application * Username: `admin`, password: `1q2w3E*`. + +# Running on HTTPS + +You can also run the staging solution on your local kubernetes kluster with https. There are various ways to create self-signed certificate. + +## Installing mkcert +This guide will use mkcert to create self-signed certificates. + +Follow the [installation guide](https://github.com/FiloSottile/mkcert#installation) to install mkcert. + +## Creating mkcert Root CA +Use the command to create root (local) certificate authority for your certificates: +```powershell +mkcert -install +``` + +**Note:** all the certificates created by mkcert certificate creation will be trusted by local machine + +## Run mkcert + +Create certificate for the eshopOnAbp domains using the mkcert command below: +```powershell +mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public" +``` + +At the end of the output you will see something like + +The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem" + +Copy the cert name and key name below to create tls secret + +```powershell +kubectl create namespace eshop +kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem +``` diff --git a/etc/docker/README.md b/etc/docker/README.md new file mode 100644 index 00000000..3363c305 --- /dev/null +++ b/etc/docker/README.md @@ -0,0 +1,14 @@ +### Generate Self-Signed Certificate Using OpenSSL + +``` +openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-dk.key -out eshop-dk.crt -subj `"/CN=$certSubj`" -addext `"subjectAltName=DNS:localhost,DNS:host.docker.internal,DNS:app-authserver`" +openssl pkcs12 -export -in eshop-dk.crt -inkey eshop-dk.key -out eshop-dk.pfx -passout pass:8b6039b6-c67a-448b-977b-0ce6d3fcfd49 +``` + +### How to run? + +* Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`): + +````powershell +127.0.0.1 app-authserver +```` \ No newline at end of file diff --git a/etc/docker/certs/eshop-ssl.conf b/etc/docker/certs/eshop-ssl.conf new file mode 100644 index 00000000..e82d4494 --- /dev/null +++ b/etc/docker/certs/eshop-ssl.conf @@ -0,0 +1,40 @@ +[req] +default_bits = 2048 +default_keyfile = eshop-dk.key +distinguished_name = req_distinguished_name +req_extensions = req_ext +x509_extensions = v3_ca + +[req_distinguished_name] +commonName = Common Name (e.g. server FQDN or YOUR name) +commonName_default = eshoponabp +commonName_max = 64 + +[req_ext] +subjectAltName = @alt_names + +[v3_ca] +subjectAltName = @alt_names +basicConstraints = critical, CA:false +keyUsage = keyCertSign, cRLSign, digitalSignature,keyEncipherment + +[alt_names] +DNS.1 = localhost +DNS.2 = 127.0.0.1 +DNS.3 = host.docker.internal +DNS.4 = app-authserver +DNS.5 = app-web +DNS.6 = app-publicweb +DNS.7 = gateway-web +DNS.8 = gateway-web-public +DNS.9 = administration-service +DNS.10 = identity-service +DNS.11 = catalog-service +DNS.12 = basket-service +DNS.13 = ordering-service +DNS.14 = payment-service + +# Generate certificate from config +# Use the command: +# 'openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-dk.key -out eshop-dk-cert.pem -config eshop-ssl.conf' + diff --git a/etc/docker/certs/generate_certs.ps1 b/etc/docker/certs/generate_certs.ps1 new file mode 100644 index 00000000..449c232c --- /dev/null +++ b/etc/docker/certs/generate_certs.ps1 @@ -0,0 +1,60 @@ +# Source: https://stackoverflow.com/a/62060315 +# Generate self-signed certificate to be used by IdentityServer. +# When using localhost - API cannot see the IdentityServer from within the docker-compose'd network. +# You have to run this script as Administrator (open Powershell by right click -> Run as Administrator). + +$rootCN = "eShopOnAbp" +$authserverCNs = "app-authserver", "localhost" +$publicWebCNs = "app-public-web", "localhost" +$administrationServiceCNs = "administration-service", "localhost" +$identityServiceCNs = "identity-service", "localhost" +$catalogServiceCNs = "catalog-service", "localhost" +$basketServiceCNs = "basket-service", "localhost" +$orderingServiceCNs = "ordering-service", "localhost" +$paymentServiceCNs = "payment-service", "localhost" + +$alreadyExistingCertsRoot = Get-ChildItem -Path Cert:\LocalMachine\My -Recurse | Where-Object {$_.Subject -eq "CN=$rootCN"} + +if ($alreadyExistingCertsRoot.Count -eq 1) { + Write-Output "Skipping creating Root CA certificate as it already exists." + $rootCA = [Microsoft.CertificateServices.Commands.Certificate] $alreadyExistingCertsRoot[0] +} else { + $rootCA = New-SelfSignedCertificate -Subject $rootCN -KeyUsageProperty Sign -KeyUsage CertSign -CertStoreLocation Cert:\LocalMachine\My +} + +$authserverCert = New-SelfSignedCertificate -DnsName $authserverCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $publicWebCert = New-SelfSignedCertificate -DnsName $publicWebCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $administrationServiceCert = New-SelfSignedCertificate -DnsName $administrationServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $identityServiceCert = New-SelfSignedCertificate -DnsName $identityServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $catalogServiceCert = New-SelfSignedCertificate -DnsName $catalogServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $basketServiceCert = New-SelfSignedCertificate -DnsName $basketServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $orderingServiceCert = New-SelfSignedCertificate -DnsName $orderingServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $paymentServiceCert = New-SelfSignedCertificate -DnsName $paymentServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My + +$password = ConvertTo-SecureString -String "8b6039b6-c67a-448b-977b-0ce6d3fcfd49" -Force -AsPlainText + +Export-PfxCertificate -Cert $rootCA -FilePath eShopOnAbp-root-cert.pfx -Password $password | Out-Null +Export-PfxCertificate -Cert $authserverCert -FilePath app-authserver-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $publicWebCert -FilePath app-public-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $administrationServiceCert -FilePath administration-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $identityServiceCert -FilePath identity-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $catalogServiceCert -FilePath catalog-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $basketServiceCert -FilePath basket-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $orderingServiceCert -FilePath ordering-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $paymentServiceCert -FilePath payment-service-cert.pfx -Password $password | Out-Null + +# Export .cer to be converted to .crt to be trusted within the Docker container. +Export-Certificate -Cert $rootCA -FilePath eShopOnAbp-root-cert.cer -Type CERT | Out-Null + +# Trust it on your host machine. +$store = New-Object System.Security.Cryptography.X509Certificates.X509Store "Root","LocalMachine" +$store.Open("ReadWrite") + +$rootCertAlreadyTrusted = ($store.Certificates | Where-Object {$_.Subject -eq "CN=$rootCN"} | Measure-Object).Count -eq 1 + +if ($rootCertAlreadyTrusted -eq $false) { + Write-Output "Adding the root CA certificate to the trust store." + $store.Add($rootCA) +} + +$store.Close() \ No newline at end of file diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index c418cbd7..01593fbf 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -8,13 +8,13 @@ services: context: ../../ dockerfile: services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44353:443" depends_on: @@ -28,8 +28,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate - + - ./certs:/root/certificate identity-service: image: eshoponabp/service-identity:latest container_name: identity-service-container @@ -37,9 +36,9 @@ services: context: ../../ dockerfile: services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80 - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -58,8 +57,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate - + - ./certs:/root/certificate catalog-service: image: eshoponabp/service-catalog:latest container_name: catalog-service-container @@ -67,18 +65,20 @@ services: context: ../../ dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging - - ASPNETCORE_URLS=https://+:443;http://+:81; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Kestrel__EndPoints__Http__Url=https://docker.host.internal:443 + - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 + - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44354:443" + - "5000:80" - "81:81" depends_on: redis: @@ -91,8 +91,247 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate - + - ./certs:/root/certificate + basket-service: + image: eshoponabp/service-basket:latest + container_name: basket-service-container + build: + context: ../../ + dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - RemoteServices__Catalog__BaseUrl=https://catalog-service + # - RemoteServices__Catalog__GrpcUrl=http://catalog-service + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + ports: + - "44355:443" + depends_on: + redis: + condition: service_healthy + mongodb: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + ordering-service: + image: eshoponabp/service-ordering:latest + container_name: ordering-service-container + build: + context: ../../ + dockerfile: services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - ConnectionStrings__OrderingService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + ports: + - "44356:443" + depends_on: + redis: + condition: service_healthy + postgres-db: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + payment-service: + image: eshoponabp/service-payment:latest + container_name: payment-service-container + build: + context: ../../ + dockerfile: services/payment/src/EShopOnAbp.PaymentService.HttpApi.Host/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - ConnectionStrings__PaymentService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Payment;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - Payment__PayPal__ClientId=PAYPAL_CLIENT_ID + - Payment__PayPal__Secret=PAYPAL_SECRET + - Payment__PayPal__Environment=Sandbox + ports: + - "44357:443" + depends_on: + redis: + condition: service_healthy + postgres-db: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + app-web: + image: eshoponabp/app-web:latest + container_name: app-web-container + build: + context: ../../ + dockerfile: apps/angular/Dockerfile + environment: + - RabbitMQ__Connections__Default__HostName=rabbitmq + - RemoteServices__Default__BaseUrl=http://gateway-web-public + ports: + - "4200:80" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + app-authserver: + image: eshoponabp/app-authserver:latest + container_name: app-authserver-container + build: + context: ../../ + dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=https://+:443;http://+:80; + - ASPNETCORE_HTTPS_PORT=44330 + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - App__SelfUrl=https://app-authserver + # - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service + # - App__RedirectAllowedUrls=http://app-web + - AuthServer__Authority=https://app-authserver + - AuthServer__RequireHttpsMetadata=true + # - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + ports: + - "44330:443" + depends_on: + redis: + condition: service_healthy + postgres-db: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + app-publicweb: + image: eshoponabp/app-publicweb:latest + container_name: app-publicweb-container + build: + context: ../../ + dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - App__SelfUrl=https://app-publicweb + - AuthServer__Authority=https://app-authserver + - AuthServer__RequireHttpsMetadata=true + # - RemoteServices__Default__BaseUrl=http://gateway-web-public + # - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://gateway-web-public + ports: + - "44335:443" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + gateway-web: + image: eshoponabp/gateway-web:latest + container_name: gateway-web-container + build: + context: ../../ + dockerfile: gateways/web/src/EShopOnAbp.WebGateway/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver + - ReverseProxy__Clusters__identityCluster__Destinations__destination1__Address=http://identity-service + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service + - ReverseProxy__Clusters__feature-management-cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__permission-management-cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__setting-management-cluster__Destinations__destination1__Address=http://administration-service + ports: + - "44372:443" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate + gateway-web-public: + image: eshoponabp/gateway-web-public:latest + container_name: gateway-web-public-container + build: + context: ../../ + dockerfile: gateways/web-public/src/EShopOnAbp.WebPublicGateway/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service + - ReverseProxy__Clusters__basketCluster__Destinations__destination1__Address=http://basket-service + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service + - ReverseProxy__Clusters__paymentCluster__Destinations__destination1__Address=http://payment-service + - ReverseProxy__Clusters__productPictureCluster__Destinations__destination1__Address=http://catalog-service + ports: + - "44373:443" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ./certs:/root/certificate networks: eshoponabp-network: diff --git a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/administration/values.yaml b/etc/k8s/eshoponabp/charts/administration/values.yaml index 5b0f6c97..05e9d62c 100644 --- a/etc/k8s/eshoponabp/charts/administration/values.yaml +++ b/etc/k8s/eshoponabp/charts/administration/values.yaml @@ -25,8 +25,8 @@ synchedCommunication: scope: # "IdentityService" ingress: - host: # eshop-st-administration - tlsSecret: eshop-demo-tls + host: eshop-st-administration + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-administration diff --git a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml index b74c1044..30e7e89e 100644 --- a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml @@ -3,19 +3,18 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt nginx.ingress.kubernetes.io/configuration-snippet: | more_set_input_headers "from-ingress: true"; spec: + ingressClassName: nginx tls: - hosts: - - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + - "eshop-st-authserver" + secretName: "eshop-wildcard-tls" rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/authserver/values.yaml b/etc/k8s/eshoponabp/charts/authserver/values.yaml index 95f80979..c498a1ea 100644 --- a/etc/k8s/eshoponabp/charts/authserver/values.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/values.yaml @@ -17,13 +17,12 @@ config: stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: - host: # eshop-st-authserver - tlsSecret: eshop-demo-tls + host: eshop-st-authserver + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-authserver tag: latest pullPolicy: IfNotPresent -env: {} - \ No newline at end of file +env: {} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/basket/values.yaml b/etc/k8s/eshoponabp/charts/basket/values.yaml index 5571e666..c69ad16a 100644 --- a/etc/k8s/eshoponabp/charts/basket/values.yaml +++ b/etc/k8s/eshoponabp/charts/basket/values.yaml @@ -19,7 +19,7 @@ config: ingress: host: eshop-st-basket - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-basket diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml index 17aef76c..a057014e 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml @@ -18,22 +18,22 @@ spec: ports: - name: http containerPort: 80 - - name: https - containerPort: 443 - name: grpc containerPort: 81 protocol: TCP env: + - name: "ASPNETCORE_URLS" + value: "http://+:80;http://+:81" + - name: "DOTNET_ENVIRONMENT" + value: "{{ .Values.config.dotnetEnv }}" - name: App__SelfUrl value: "{{ .Values.config.selfUrl }}" - name: App__CorsOrigins value: "{{ .Values.config.corsOrigins }}" - name: "ConnectionStrings__CatalogService" - value: {{ .Values.config.connectionStrings.catalogService }} + value: "{{ .Values.config.connectionStrings.catalogService }}" - name: "ConnectionStrings__AdministrationService" - value: {{ .Values.config.connectionStrings.administrationService }} - - name: "DOTNET_ENVIRONMENT" - value: "{{ .Values.config.dotnetEnv }}" + value: "{{ .Values.config.connectionStrings.administrationService }}" - name: "Redis__Configuration" value: "{{ .Values.config.redisHost }}" - name: "RabbitMQ__Connections__Default__HostName" diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml index 278771cd..28306a83 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml @@ -6,13 +6,11 @@ metadata: name: {{ .Release.Name }}-{{ .Chart.Name }} spec: ports: - - name: "80" + - name: "http" port: 80 - - name: "443" - port: 443 - - port: {{ .Values.config.grpcPort }} + - name: grpc targetPort: grpc protocol: TCP - name: grpc + port: {{ .Values.config.grpcPort }} selector: app: {{ .Release.Name }}-{{ .Chart.Name }} diff --git a/etc/k8s/eshoponabp/charts/catalog/values.yaml b/etc/k8s/eshoponabp/charts/catalog/values.yaml index d45c8b9e..8e65d499 100644 --- a/etc/k8s/eshoponabp/charts/catalog/values.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/values.yaml @@ -16,20 +16,21 @@ config: stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 grpcPort: 81 kestrel: - httpUrl: # + httpUrl: http://eshop-st-catalog:80 httpProtocols: Http1AndHttp2 - grpcUrl: # + grpcUrl: http://eshop-st-catalog:81 grpcProtocols: Http2 - ingress: host: eshop-st-catalog - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-catalog tag: latest pullPolicy: IfNotPresent -env: {} +env: { + # ASPNETCORE_URLS=http://+:80;http://+:81 +} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml index 07cea6b6..5e25b31e 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml @@ -27,8 +27,6 @@ spec: env: - name: App__SelfUrl value: "{{ .Values.config.selfUrl }}" - - name: GlobalConfiguration__BaseUrl - value: "{{ .Values.config.globalConfigurationBaseUrl }}" - name: "DOTNET_ENVIRONMENT" value: "{{ .Values.config.dotnetEnv }}" - name: "Redis__Configuration" @@ -44,9 +42,7 @@ spec: - name: "AuthServer__SwaggerClientSecret" value: "{{ .Values.config.authServer.swaggerClientSecret }}" - name: "ElasticSearch__Url" - value: "{{ .Values.config.elasticsearchHost }}" - - name: "StringEncryption__DefaultPassPhrase" - value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}" + value: "{{ .Values.config.elasticsearchHost }}" {{- if .Values.env }} {{ toYaml .Values.env | indent 8 }} {{- end }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml index 539025ac..a8d988f6 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml index c57f2199..1b30388b 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml @@ -1,6 +1,5 @@ config: selfUrl: https://eshop-st-gateway-public-web - globalConfigurationBaseUrl: http://eshop-st-gateway-public-web authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -9,33 +8,31 @@ config: dotnetEnv: Staging redisHost: es-st-redis rabbitmqHost: es-st-rabbitmq - elasticsearchHost: # - stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 + elasticsearchHost: es-st-elasticsearch reRoutes: accountService: - url: http://eshop-st-authserver + url: https://eshop-st-authserver identityService: - url: http://eshop-st-identity + url: https://eshop-st-identity administrationService: - url: http://eshop-st-administration + url: https://eshop-st-administration catalogService: - url: http://eshop-st-catalog + url: https://eshop-st-catalog basketService: - url: http://eshop-st-basket + url: https://eshop-st-basket orderingService: - url: http://eshop-st-ordering + url: https://eshop-st-ordering paymentService: - url: http://eshop-st-payment + url: https://eshop-st-payment ingress: host: eshop-st-gateway-web-public - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/gateway-web-public tag: latest pullPolicy: IfNotPresent -env: {} - \ No newline at end of file +env: {} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml index 8e106909..0dedb3d3 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml index c52bfe5a..49ac9ace 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml @@ -21,7 +21,7 @@ reRoutes: url: http://eshop-st-administration ingress: host: # eshop-st-gateway-web - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/gateway-web diff --git a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/identity/values.yaml b/etc/k8s/eshoponabp/charts/identity/values.yaml index f7f0faa7..34324d0b 100644 --- a/etc/k8s/eshoponabp/charts/identity/values.yaml +++ b/etc/k8s/eshoponabp/charts/identity/values.yaml @@ -32,7 +32,7 @@ identityServerClients: ingress: host: eshop-st-identity - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-identity diff --git a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/ordering/values.yaml b/etc/k8s/eshoponabp/charts/ordering/values.yaml index 70949147..c9f8a55b 100644 --- a/etc/k8s/eshoponabp/charts/ordering/values.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-ordering - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-ordering diff --git a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/payment/values.yaml b/etc/k8s/eshoponabp/charts/payment/values.yaml index a4f316a0..37ffd9cb 100644 --- a/etc/k8s/eshoponabp/charts/payment/values.yaml +++ b/etc/k8s/eshoponabp/charts/payment/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-payment - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-payment diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml index 0faddf89..3519d65c 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml @@ -22,23 +22,23 @@ spec: containerPort: 443 env: - name: App__SelfUrl - value: {{ .Values.config.selfUrl}} + value: "{{ .Values.config.selfUrl }}" - name: RemoteServices__Default__BaseUrl - value: {{ .Values.config.gatewayUrl}} + value: "{{ .Values.config.gatewayUrl }}" - name: "AuthServer__Authority" - value: {{ .Values.config.authServer.authority }} + value: "{{ .Values.config.authServer.authority }}" - name: "AuthServer__RequireHttpsMetadata" value: "{{ .Values.config.authServer.requireHttpsMetadata }}" - name: "DOTNET_ENVIRONMENT" - value: {{ .Values.config.dotnetEnv }} + value: "{{ .Values.config.dotnetEnv }}" - name: "Redis__Configuration" - value: {{ .Values.config.redisHost }} + value: "{{ .Values.config.redisHost }}" - name: "StringEncryption__DefaultPassPhrase" - value: {{ .Values.config.stringEncryptionDefaultPassPhrase }} + value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}" - name: "RabbitMQ__Connections__Default__HostName" - value: {{ .Values.config.rabbitmqHost }} + value: "{{ .Values.config.rabbitmqHost }}" - name: "ElasticSearch__Url" - value: {{ .Values.config.elasticsearchHost }} + value: "{{ .Values.config.elasticsearchHost }}" {{- if .Values.env }} {{ toYaml .Values.env | indent 8 }} {{- end }} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml index ec4080bc..18a5ed2f 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/public-web/values.yaml b/etc/k8s/eshoponabp/charts/public-web/values.yaml index 72542a20..7d38cb1f 100644 --- a/etc/k8s/eshoponabp/charts/public-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/values.yaml @@ -1,6 +1,6 @@ config: selfUrl: https://eshop-st-public-web - gatewayUrl: "http://eshop-st-gateway-web-public/" + gatewayUrl: https://eshop-st-gateway-web-public authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -11,8 +11,8 @@ config: stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: - host: # eshop-st-public-web - tlsSecret: eshop-demo-tls + host: eshop-st-public-web + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-publicweb diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml index 54a62c3c..bbade7db 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/web/values.yaml b/etc/k8s/eshoponabp/charts/web/values.yaml index 83e4b444..9a3418b7 100644 --- a/etc/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/k8s/eshoponabp/charts/web/values.yaml @@ -7,7 +7,7 @@ config: ingress: host: eshop-st-web - tlsSecret: eshop-demo-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-web diff --git a/etc/k8s/eshoponabp/values.yaml b/etc/k8s/eshoponabp/values.yaml index b3c350d8..6e31550c 100644 --- a/etc/k8s/eshoponabp/values.yaml +++ b/etc/k8s/eshoponabp/values.yaml @@ -13,6 +13,7 @@ authserver: elasticsearchHost: es-st-elasticsearch ingress: host: eshop-st-authserver + tlsSecret: eshop-wildcard-tls image: repository: "eshoponabp/app-authserver" tag: latest @@ -32,7 +33,7 @@ web: public-web: config: selfUrl: https://eshop-st-public-web - gatewayUrl: "http://eshop-st-gateway-web-public/" + gatewayUrl: http://eshop-st-gateway-web-public authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -123,7 +124,6 @@ gateway-web: redisHost: es-st-redis rabbitmqHost: es-st-rabbitmq elasticsearchHost: es-st-elasticsearch - stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: host: eshop-st-gateway-web image: @@ -141,7 +141,6 @@ gateway-web: gateway-web-public: config: selfUrl: https://eshop-st-gateway-web-public - globalConfigurationBaseUrl: http://eshop-st-gateway-public-web authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -151,7 +150,6 @@ gateway-web-public: redisHost: es-st-redis rabbitmqHost: es-st-rabbitmq elasticsearchHost: es-st-elasticsearch - stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: host: eshop-st-gateway-web-public image: diff --git a/etc/k8s/tls-cert/eshop-st-cert.pem b/etc/k8s/tls-cert/eshop-st-cert.pem deleted file mode 100644 index 45649b42..00000000 --- a/etc/k8s/tls-cert/eshop-st-cert.pem +++ /dev/null @@ -1,31 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFQzCCA6ugAwIBAgIRANj5oNi+QQIoyV51y/ZIJlYwDQYJKoZIhvcNAQELBQAw -gZ8xHjAcBgNVBAoTFW1rY2VydCBkZXZlbG9wbWVudCBDQTE6MDgGA1UECwwxZ3Nl -bmd1bkBHb2toYW5zLU1hY0Jvb2stUHJvLmxvY2FsIChHb2toYW4gU2VuZ3VuKTFB -MD8GA1UEAww4bWtjZXJ0IGdzZW5ndW5AR29raGFucy1NYWNCb29rLVByby5sb2Nh -bCAoR29raGFuIFNlbmd1bikwHhcNMTkwNjAxMDAwMDAwWhcNMzExMTA0MDgyNjUw -WjBlMScwJQYDVQQKEx5ta2NlcnQgZGV2ZWxvcG1lbnQgY2VydGlmaWNhdGUxOjA4 -BgNVBAsMMWdzZW5ndW5AR29raGFucy1NYWNCb29rLVByby5sb2NhbCAoR29raGFu -IFNlbmd1bikwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKu7X3b2Cg -dpBnz90KboUnpWRcCK96oq97pAEbR9sirN3+3jT0JRBY2TYKLDPW8i50QJFbdYE7 -zky58c+RWPrxVDoeqRC8E1+TLsuW+TdMmOL746k36X1VtKy3rqUG9IS6MXjH/MX8 -H1kgldHvE9mFEpyp3q/8cUPHSBUE+M0CA05wlDm8qgkGXcp43qrNElWg5Y2WWWIp -WUm8r5obktSAxhA+ZxFX4cJHFmxKymMqSRStDpTFCIW9C3kx5ierPNQS6g5sSMtW -OuPuh0Uhc0Q0lJBoA7Mj1CGvtO5nld0+6kAK1GMB7Vbigoqd00eqKMYaA3Aa5QZm -bf84wZjofJx1AgMBAAGjggExMIIBLTAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAww -CgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBR6TnYaWT+NPghb -dQnZ+MAbx9UB2DCB1gYDVR0RBIHOMIHLgghlc2hvcC1zdIIXZXNob3Atc3QtYWRt -aW5pc3RyYXRpb26CE2VzaG9wLXN0LWF1dGhzZXJ2ZXKCGWVzaG9wLXN0LWdhdGV3 -YXktaW50ZXJuYWyCG2VzaG9wLXN0LWdhdGV3YXktcHVibGljLXdlYoIUZXNob3At -c3QtZ2F0ZXdheS13ZWKCEWVzaG9wLXN0LWlkZW50aXR5ghNlc2hvcC1zdC1wdWJs -aWMtd2Vigg1lc2hvcC1zdC1zYWFzggxlc2hvcC1zdC13ZWIwDQYJKoZIhvcNAQEL -BQADggGBADjQroM3gD7g56S8bxlUbt1sJYfvo0VCIDPH9aHE3WwhGCOn18SRDOpM -mNw4c0HO+P1+rlCfn2pvN2oQ6v731fQZPpGcE0ljeVrixqfyVvoggGMbOwegvWPh -dPK/cxLi9wYfQtFw5vy8YxsinowSRCQ3KJGxI4fsyjEQu939WvYSPDdEUPx952LR -2pG8yRSso7dixDW4rDCoI/QKM/ImnqsNtZSpGa93HLgjkJr/PsOVMogt8dOsDOkC -vHq9F6TJKTDb7WizMJcE0qfisJgtTC2isvYA3u7kiyfxW26kd1h7s4m3njn+0Sks -0xGcXiYPZm8y/lVrxcF3/QlgOfWfRmls3D17yX28QwuwvNkUv2aSP/WGOMWEtgPD -9WYPk1OhOGFxT3IKu8iw6ITTCKXpcBeQ/QiEuFjo/khDGE4NMSkrp16nVebkAWal -/eufFWZJTzO7kgCmApS2SAhRdsM+JEsioHF/gM2chzV+eP4CCKv3pw5z07eemhx2 -HnEbhDFHEA== ------END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-st-key.pem b/etc/k8s/tls-cert/eshop-st-key.pem deleted file mode 100644 index 146780f7..00000000 --- a/etc/k8s/tls-cert/eshop-st-key.pem +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDKu7X3b2CgdpBn -z90KboUnpWRcCK96oq97pAEbR9sirN3+3jT0JRBY2TYKLDPW8i50QJFbdYE7zky5 -8c+RWPrxVDoeqRC8E1+TLsuW+TdMmOL746k36X1VtKy3rqUG9IS6MXjH/MX8H1kg -ldHvE9mFEpyp3q/8cUPHSBUE+M0CA05wlDm8qgkGXcp43qrNElWg5Y2WWWIpWUm8 -r5obktSAxhA+ZxFX4cJHFmxKymMqSRStDpTFCIW9C3kx5ierPNQS6g5sSMtWOuPu -h0Uhc0Q0lJBoA7Mj1CGvtO5nld0+6kAK1GMB7Vbigoqd00eqKMYaA3Aa5QZmbf84 -wZjofJx1AgMBAAECggEBALvJLd9ZInbf/Bi8uLFt+BbmI1UAkpKU2Nk86+16HKg8 -2ZC4APLY1hCGeoDnusjyIUd7e2jtKdzc1cMzEiI++orJiuBVl/OuOkxZ/ykEBU4F -G9NYaKkqtPbLWWT291O+8KaLJqaQJE/KNcNyIzhB+a1CtSy/4eGChNa1lQq67yJZ -iTFPNSHT1RTzjv2BAuUASq1gK+bX4F65otVYQBMg3JGsfkAdhWPbzEX0XLVpgbh/ -jtyAHSsiWIkyVjXvA3Zjp+3Gmf3dbd/86Uwd4XowPfcSOP4iyd76FS4iTlthsF5D -M0psBOgotVl5RHv2ljOy7fUzrudnSQ0HepgdHed4Em0CgYEA7q+j7cbcb43ZW5Rx -p2pMuuuEeFY+L2Ns8N4t26OoURQCzyACR5H4KgFtrrdqTwQPs7L8SWAjU8SoP2jX -j+4+TJnK/Grt0YQ2pLpEM8j7kjGWfskHDfQhrL3o4VhdCm/1URWYSn7nzdNnX1Fk -ZlKjUJWBXGTvthCUVY9Jk30hU4sCgYEA2XBupvyIpmjoNdsEdwxxSebLyIYu2FA/ -sjI5gdzXIOo9DsFfn9HTNbXyEsiQm9StNXS585jRhyht9OF7SYajrJ/E3O086tf4 -2MmDbUdFdvMdPdGxxTU2mXa9Vd6JASnFG+fSsRhABk57iNzcUE4+PNW1ztLmRyLx -diW9cXjXz/8CgYBxGF43U0utu+uqvgqgRfj3dJL/JfYvJBBBjTTzZndhe3bdR5Bs -8xhAZw7eg1/m8six3/Q0nE4A6iTCbt38/+kbCKAqvEvVQ61UnkGku+2f1sk1Z/Fk -xjGSlSWcaO8k++mkMvRHEByr5SiM/Jby+OMTUtPJwLXocbCnXc6CCP9agwKBgEe7 -I4XLAXmEWjaKDisH28e5b7izK3kI4Dp0/yusIvwkyge4G0ep/LdXUoiHyczemFVu -MHoAC/8+gyepyvYyiIRGILeRO+ttXBaIQ+ck//GBuj/OkYqxR1XRKhzN0PylPvU5 -wPPTQCvUcERyN+v2I+oFxnh4cqc9C9MiGCD68JcZAoGBAIi1RxcWKZUCjSETT1PY -V7j5FIyMzBdUo0RN44eUdeu0CWAOnMG2s26z6fXl7EZp+Em5ee7dYEmSP49X69n9 -T9ueN1LRJaqko45Eo3uPl6rolz5vXcTr2Tooc3yqE3XbRxe2jOeczq06nj06kjuf -hPPdSqjjOwWPy63DWboSkh+0 ------END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/notes.md b/etc/k8s/tls-cert/notes.md deleted file mode 100644 index d10840d4..00000000 --- a/etc/k8s/tls-cert/notes.md +++ /dev/null @@ -1,9 +0,0 @@ -# Notes - -## Creating demo tls cert - -``` -kubectl create secret tls eshop-demo-tls \ - --cert=eshop-st-cert.pem \ - --key=eshop-st-key.pem -``` diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs index d60f0442..bb1e553f 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs @@ -23,7 +23,7 @@ public class Program var builder = WebApplication.CreateBuilder(args); builder.Host .AddAppSettingsSecretsJson() - .AddOcelotJson() + .AddYarpJson() .UseAutofac() .UseSerilog(); diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json index f1417cac..119795be 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json @@ -22,5 +22,5 @@ }, "ElasticSearch": { "Url": "http://localhost:9200" - } + } } diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json index 7e3b617a..2f586248 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json @@ -2,43 +2,43 @@ "ReverseProxy": { "Routes": { "Account Service": { - "ClusterId": "account-cluster", + "ClusterId": "accountCluster", "Match": { "Path": "/api/account/{**everything}" } }, "Administration Service": { - "ClusterId": "administration-cluster", + "ClusterId": "administrationCluster", "Match": { "Path": "/api/abp/{**everything}" } }, "Catalog Service": { - "ClusterId": "catalog-cluster", + "ClusterId": "catalogCluster", "Match": { "Path": "/api/catalog/{**everything}" } - }, + }, "Basket Service": { - "ClusterId": "basket-cluster", + "ClusterId": "basketCluster", "Match": { "Path": "/api/basket/{**everything}" } }, "Ordering Service": { - "ClusterId": "ordering-cluster", + "ClusterId": "orderingCluster", "Match": { "Path": "/api/ordering/{**everything}" } }, "Payment Service": { - "ClusterId": "payment-cluster", + "ClusterId": "paymentCluster", "Match": { "Path": "/api/payment/{**everything}" } }, "product-picture-route": { - "ClusterId": "product-picture-cluster", + "ClusterId": "productPictureCluster", "Match": { "Path": "/product-images/{**everything}", "Methods" : [ "GET" ] @@ -46,55 +46,55 @@ } }, "Clusters": { - "account-cluster": { + "accountCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44330" } } }, - "administration-cluster": { + "administrationCluster": { "Destinations": { "destination1": { - "Address": "https://localhost:44353" + "Address": "http://localhost:44353" } } }, - "catalog-cluster": { + "catalogCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44354" } } }, - "product-picture-cluster": { + "basketCluster": { "Destinations": { "destination1": { - "Address": "https://localhost:44354" + "Address": "https://localhost:44355" } } - }, - "basket-cluster": { + }, + "orderingCluster": { "Destinations": { "destination1": { - "Address": "https://localhost:44355" + "Address": "https://localhost:44356" } } }, - "ordering-cluster": { + "paymentCluster": { "Destinations": { "destination1": { - "Address": "https://localhost:44356" + "Address": "https://localhost:44357" } } }, - "payment-cluster": { + "productPictureCluster": { "Destinations": { "destination1": { - "Address": "https://localhost:44357" + "Address": "https://localhost:44354" } } } } } -} \ No newline at end of file +} diff --git a/gateways/web/src/EShopOnAbp.WebGateway/Program.cs b/gateways/web/src/EShopOnAbp.WebGateway/Program.cs index 244114fe..a8e13d49 100644 --- a/gateways/web/src/EShopOnAbp.WebGateway/Program.cs +++ b/gateways/web/src/EShopOnAbp.WebGateway/Program.cs @@ -22,7 +22,7 @@ public class Program var builder = WebApplication.CreateBuilder(args); builder.Host .AddAppSettingsSecretsJson() - .AddOcelotJson() + .AddYarpJson() .UseAutofac() .UseSerilog(); diff --git a/gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json b/gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json new file mode 100644 index 00000000..db306048 --- /dev/null +++ b/gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json @@ -0,0 +1,86 @@ +{ + "ReverseProxy": { + "Routes": { + "Account Service": { + "ClusterId": "accountCluster", + "Match": { + "Path": "/api/account/{**everything}" + } + }, + "Identity Service": { + "ClusterId": "identityCluster", + "Match": { + "Path": "/api/identity/{**everything}" + } + }, + "Administration Service": { + "ClusterId": "administrationCluster", + "Match": { + "Path": "/api/abp/{**everything}" + } + }, + "feature-management-route": { + "ClusterId": "featureManagementCluster", + "Match": { + "Path": "/api/feature-management/{**everything}" + } + }, + "permission-management-route": { + "ClusterId": "permissionManagementCluster", + "Match": { + "Path": "/api/permission-management/{**everything}" + } + }, + "setting-management-route": { + "ClusterId": "settingManagementCluster", + "Match": { + "Path": "/api/setting-management/{**everything}" + } + } + }, + "Clusters": { + "accountCluster": { + "Destinations": { + "destination1": { + "Address": "http://app-authserver" + } + } + }, + "identityCluster": { + "Destinations": { + "destination1": { + "Address": "http://identity-service" + } + } + }, + "administrationCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "featureManagementCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "permissionManagementCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "settingManagementCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + } + } + } +} diff --git a/gateways/web/src/EShopOnAbp.WebGateway/yarp.json b/gateways/web/src/EShopOnAbp.WebGateway/yarp.json index 424e598e..d14ce8ee 100644 --- a/gateways/web/src/EShopOnAbp.WebGateway/yarp.json +++ b/gateways/web/src/EShopOnAbp.WebGateway/yarp.json @@ -2,19 +2,19 @@ "ReverseProxy": { "Routes": { "Account Service": { - "ClusterId": "account-cluster", + "ClusterId": "accountCluster", "Match": { "Path": "/api/account/{**everything}" } }, "Identity Service": { - "ClusterId": "identity-cluster", + "ClusterId": "identityCluster", "Match": { "Path": "/api/identity/{**everything}" } }, "Administration Service": { - "ClusterId": "administration-cluster", + "ClusterId": "administrationCluster", "Match": { "Path": "/api/abp/{**everything}" } @@ -36,24 +36,36 @@ "Match": { "Path": "/api/setting-management/{**everything}" } + }, + "Catalog Service": { + "ClusterId": "catalogCluster", + "Match": { + "Path": "/api/catalog/{**everything}" + } + }, + "Ordering Service": { + "ClusterId": "orderingCluster", + "Match": { + "Path": "/api/ordering/{**everything}" + } } }, "Clusters": { - "account-cluster": { + "accountCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44330" } } }, - "identity-cluster": { + "identityCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44351" } } }, - "administration-cluster": { + "administrationCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44353" @@ -80,6 +92,20 @@ "Address": "https://localhost:44353" } } + }, + "catalogCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44354" + } + } + }, + "orderingCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44356" + } + } } } } diff --git a/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..3031859f --- /dev/null +++ b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,51 @@ +{ + "App": { + "SelfUrl": "https://administration-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "RemoteServices": { + "AbpIdentity": { + "BaseUrl": "http://identity-service", + "UseCurrentAccessToken": "false" + } + }, + "IdentityClients": { + "Default": { + "GrantType": "client_credentials", + "ClientId": "EShopOnAbp_AdministrationService", + "ClientSecret": "1q2w3e*", + "Authority": "http://app-authserver", + "Scope": "IdentityService" + } + }, + "Logging": { + "LogLevel": { + "Default": "Information", + "Microsoft": "Warning", + "Microsoft.Hosting.Lifetime": "Information" + } + }, + "ConnectionStrings": { + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_AdministrationService", + "ExchangeName": "EShopOnAbp" + } + } +} diff --git a/services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json b/services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json new file mode 100644 index 00000000..b8f4a343 --- /dev/null +++ b/services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json @@ -0,0 +1,35 @@ +{ + "App": { + "SelfUrl": "https://basket-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "RemoteServices": { + "Catalog": { + "BaseUrl": "https://catalog-service", + "GrpcUrl": "http://catalog-service" + } + }, + "ConnectionStrings": { + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_BasketService", + "ExchangeName": "EShopOnAbp" + } + } +} \ No newline at end of file diff --git a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json index 7b5799db..645ce941 100644 --- a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json +++ b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json @@ -41,4 +41,4 @@ "ElasticSearch": { "Url": "http://localhost:9200" } -} +} \ No newline at end of file diff --git a/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..0f625175 --- /dev/null +++ b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,65 @@ +{ + "App": { + "SelfUrl": "https://identity-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "ConnectionStrings": { + "IdentityService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false;", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_IdentityService", + "ExchangeName": "EShopOnAbp" + } + }, + "IdentityServerClients": { + "Web": { + "RootUrl": "http://localhost:4200" + }, + "PublicWeb": { + "RootUrl": "https://localhost:44335/" + }, + "WebGateway": { + "RootUrl": "https://localhost:44372" + }, + "PublicWebGateway": { + "RootUrl": "https://localhost:44373" + }, + "AccountService": { + "RootUrl": "https://localhost:44330" + }, + "IdentityService": { + "RootUrl": "https://localhost:44351" + }, + "AdministrationService": { + "RootUrl": "https://localhost:44353" + }, + "CatalogService": { + "RootUrl": "https://localhost:44354" + }, + "BasketService": { + "RootUrl": "https://localhost:44355" + }, + "OrderingService": { + "RootUrl": "https://localhost:44356" + }, + "PaymentService": { + "RootUrl": "https://localhost:44357" + } + } +} diff --git a/services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json b/services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..309876d0 --- /dev/null +++ b/services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,30 @@ +{ + "App": { + "SelfUrl": "https://ordering-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "ConnectionStrings": { + "OrderingService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_OrderingService", + "ExchangeName": "EShopOnAbp" + } + } +} \ No newline at end of file diff --git a/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs b/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs index a2663f9a..c22d86b7 100644 --- a/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs +++ b/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs @@ -6,7 +6,7 @@ public static class AbpHostingHostBuilderExtensions { public const string AppYarpJsonPath = "yarp.json"; - public static IHostBuilder AddOcelotJson( + public static IHostBuilder AddYarpJson( this IHostBuilder hostBuilder, bool optional = true, bool reloadOnChange = true, @@ -15,10 +15,11 @@ public static class AbpHostingHostBuilderExtensions return hostBuilder.ConfigureAppConfiguration((_, builder) => { builder.AddJsonFile( - path: AppYarpJsonPath, - optional: optional, - reloadOnChange: reloadOnChange - ); + path: AppYarpJsonPath, + optional: optional, + reloadOnChange: reloadOnChange + ) + .AddEnvironmentVariables(); }); } } \ No newline at end of file