From 283957ee310a1dfe913f164cad1f8f6c2b1563fb Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 02:17:57 +0300 Subject: [PATCH 01/17] added http url to catalog-service for internal network --- .../EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json index 5d2eda53..13824033 100644 --- a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json +++ b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json @@ -44,6 +44,10 @@ "Kestrel": { "Endpoints": { "Http": { + "Url": "http://localhost:5000", + "Protocols": "Http1AndHttp2" + }, + "Https": { "Url": "https://localhost:44354", "Protocols": "Http1AndHttp2" }, From ebb38a987f2e7c3a0891f8e5d111e6cdaf1bd8e9 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 02:19:09 +0300 Subject: [PATCH 02/17] moved yarp settings to appsettings docker-compose can not override yarp.json. Maybe use in appsettings json file --- .../appsettings.json | 98 ++++++++++++++++++ .../src/EShopOnAbp.WebPublicGateway/yarp.json | 99 +------------------ 2 files changed, 99 insertions(+), 98 deletions(-) diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json index f1417cac..936faa9b 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json @@ -22,5 +22,103 @@ }, "ElasticSearch": { "Url": "http://localhost:9200" + }, + "ReverseProxy": { + "Routes": { + "Account Service": { + "ClusterId": "account_cluster", + "Match": { + "Path": "/api/account/{**everything}" + } + }, + "Administration Service": { + "ClusterId": "administration_cluster", + "Match": { + "Path": "/api/abp/{**everything}" + } + }, + "Catalog Service": { + "ClusterId": "catalog_cluster", + "Match": { + "Path": "/api/catalog/{**everything}" + } + }, + "Basket Service": { + "ClusterId": "basket_cluster", + "Match": { + "Path": "/api/basket/{**everything}" + } + }, + "Ordering Service": { + "ClusterId": "ordering_cluster", + "Match": { + "Path": "/api/ordering/{**everything}" + } + }, + "Payment Service": { + "ClusterId": "payment_cluster", + "Match": { + "Path": "/api/payment/{**everything}" + } + }, + "product-picture-route": { + "ClusterId": "product_picture_cluster", + "Match": { + "Path": "/product-images/{**everything}", + "Methods" : [ "GET" ] + } + } + }, + "Clusters": { + "account-cluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44330" + } + } + }, + "administration_cluster": { + "Destinations": { + "destination1": { + "Address": "http://localhost:44353" + } + } + }, + "catalog_cluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44354" + } + } + }, + "product_picture_cluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44354" + } + } + }, + "basket_cluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44355" + } + } + }, + "ordering_cluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44356" + } + } + }, + "payment_cluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44357" + } + } + } + } } } diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json index 7e3b617a..19682d92 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json @@ -1,100 +1,3 @@ { - "ReverseProxy": { - "Routes": { - "Account Service": { - "ClusterId": "account-cluster", - "Match": { - "Path": "/api/account/{**everything}" - } - }, - "Administration Service": { - "ClusterId": "administration-cluster", - "Match": { - "Path": "/api/abp/{**everything}" - } - }, - "Catalog Service": { - "ClusterId": "catalog-cluster", - "Match": { - "Path": "/api/catalog/{**everything}" - } - }, - "Basket Service": { - "ClusterId": "basket-cluster", - "Match": { - "Path": "/api/basket/{**everything}" - } - }, - "Ordering Service": { - "ClusterId": "ordering-cluster", - "Match": { - "Path": "/api/ordering/{**everything}" - } - }, - "Payment Service": { - "ClusterId": "payment-cluster", - "Match": { - "Path": "/api/payment/{**everything}" - } - }, - "product-picture-route": { - "ClusterId": "product-picture-cluster", - "Match": { - "Path": "/product-images/{**everything}", - "Methods" : [ "GET" ] - } - } - }, - "Clusters": { - "account-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44330" - } - } - }, - "administration-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44353" - } - } - }, - "catalog-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44354" - } - } - }, - "product-picture-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44354" - } - } - }, - "basket-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44355" - } - } - }, - "ordering-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44356" - } - } - }, - "payment-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44357" - } - } - } - } - } + } \ No newline at end of file From 382899d23cf675c9c4549b21727f110e6eac14ab Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 02:19:42 +0300 Subject: [PATCH 03/17] added basket, ordering, payment, public-web and publicweb-gateway configurations --- etc/docker/docker-compose.yml | 165 +++++++++++++++++++++++++++++++++- 1 file changed, 162 insertions(+), 3 deletions(-) diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index c418cbd7..75b6f621 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -60,6 +60,37 @@ services: volumes: - ../dev-cert:/root/certificate + basket-service: + image: eshoponabp/service-basket:latest + container_name: basket-service-container + build: + context: ../../ + dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - RemoteServices__Catalog__BaseUrl=https://catalog-service + - RemoteServices__Catalog__GrpcUrl=http://catalog-service + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + ports: + - "44355:443" + depends_on: + redis: + condition: service_healthy + mongodb: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate + catalog-service: image: eshoponabp/service-catalog:latest container_name: catalog-service-container @@ -68,10 +99,11 @@ services: dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile environment: - ASPNETCORE_ENVIRONMENT=Staging - - ASPNETCORE_URLS=https://+:443;http://+:81; + - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Kestrel__EndPoints__Http__Url=https://docker.host.internal:443 + - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 + - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -79,6 +111,7 @@ services: - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44354:443" + - "5000:80" - "81:81" depends_on: redis: @@ -91,7 +124,133 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ../dev-cert:/root/certificate + + ordering-service: + image: eshoponabp/service-ordering:latest + container_name: ordering-service-container + build: + context: ../../ + dockerfile: services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - ConnectionStrings__OrderingService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + ports: + - "44356:443" + depends_on: + redis: + condition: service_healthy + postgres-db: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate + + payment-service: + image: eshoponabp/service-payment:latest + container_name: payment-service-container + build: + context: ../../ + dockerfile: services/payment/src/EShopOnAbp.PaymentService.HttpApi.Host/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - ConnectionStrings__PaymentService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Payment;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - Payment__PayPal__ClientId=PAYPAL_CLIENT_ID + - Payment__PayPal__Secret=PAYPAL_SECRET + - Payment__PayPal__Environment=Sandbox + + ports: + - "44357:443" + depends_on: + redis: + condition: service_healthy + postgres-db: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate + + app-publicweb: + image: eshoponabp/app-publicweb:latest + container_name: app-publicweb-container + build: + context: ../../ + dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - RemoteServices__Default__BaseUrl=http://gateway-web-public + + ports: + - "44335:443" + depends_on: + redis: + condition: service_healthy + mongodb: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate + + gateway-web-public: + image: eshoponabp/gateway-web-public:latest + container_name: gateway-web-public-container + build: + context: ../../ + dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + # - ReverseProxy__Clusters__account-cluster__Destinations__destination1__Address= + - ReverseProxy__Clusters__administration_cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__catalog_cluster__Destinations__destination1__Address=http://catalog-service + - ReverseProxy__Clusters__basket_cluster__Destinations__destination1__Address=http://basket-service + - ReverseProxy__Clusters__ordering_cluster__Destinations__destination1__Address=http://ordering-service + - ReverseProxy__Clusters__payment_cluster__Destinations__destination1__Address=http://payment-service + + ports: + - "44373:443" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate networks: From bcc4e68bca056be5cc93dbce04d530ea615a0d0b Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 17:41:48 +0300 Subject: [PATCH 04/17] updated CorsOrigins and redirectUrls of auth-server --- apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json index 290fc0f6..047dd51c 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.json @@ -1,8 +1,8 @@ { "App": { "SelfUrl": "https://localhost:44330", - "CorsOrigins": "https://*.EShopOnAbp.com,http://localhost:4200,https://localhost:44307,https://localhost:44351,https://localhost:44353,https://localhost:44354,https://localhost:44355,https://localhost:44356,https://localhost:44357,https://localhost:44372,https://localhost:44373,http://localhost:4200", - "RedirectAllowedUrls": "http://localhost:4200,https://localhost:44307" + "CorsOrigins": "http://localhost:4200,https://localhost:44351,https://localhost:44353,https://localhost:44354,https://localhost:44355,https://localhost:44356,https://localhost:44357", + "RedirectAllowedUrls": "http://localhost:4200" }, "Logging": { "LogLevel": { From bb3f9a3ff2cdcb2fd312acf740d870d2e996c945 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 18:51:39 +0300 Subject: [PATCH 05/17] renamed and updated yarpJson builder to add environment variables --- .../src/EShopOnAbp.WebPublicGateway/Program.cs | 2 +- gateways/web/src/EShopOnAbp.WebGateway/Program.cs | 2 +- .../GatewayHostBuilderExtensions.cs | 11 ++++++----- 3 files changed, 8 insertions(+), 7 deletions(-) diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs index d60f0442..bb1e553f 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/Program.cs @@ -23,7 +23,7 @@ public class Program var builder = WebApplication.CreateBuilder(args); builder.Host .AddAppSettingsSecretsJson() - .AddOcelotJson() + .AddYarpJson() .UseAutofac() .UseSerilog(); diff --git a/gateways/web/src/EShopOnAbp.WebGateway/Program.cs b/gateways/web/src/EShopOnAbp.WebGateway/Program.cs index 244114fe..a8e13d49 100644 --- a/gateways/web/src/EShopOnAbp.WebGateway/Program.cs +++ b/gateways/web/src/EShopOnAbp.WebGateway/Program.cs @@ -22,7 +22,7 @@ public class Program var builder = WebApplication.CreateBuilder(args); builder.Host .AddAppSettingsSecretsJson() - .AddOcelotJson() + .AddYarpJson() .UseAutofac() .UseSerilog(); diff --git a/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs b/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs index a2663f9a..c22d86b7 100644 --- a/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs +++ b/shared/EShopOnAbp.Shared.Hosting.Gateways/GatewayHostBuilderExtensions.cs @@ -6,7 +6,7 @@ public static class AbpHostingHostBuilderExtensions { public const string AppYarpJsonPath = "yarp.json"; - public static IHostBuilder AddOcelotJson( + public static IHostBuilder AddYarpJson( this IHostBuilder hostBuilder, bool optional = true, bool reloadOnChange = true, @@ -15,10 +15,11 @@ public static class AbpHostingHostBuilderExtensions return hostBuilder.ConfigureAppConfiguration((_, builder) => { builder.AddJsonFile( - path: AppYarpJsonPath, - optional: optional, - reloadOnChange: reloadOnChange - ); + path: AppYarpJsonPath, + optional: optional, + reloadOnChange: reloadOnChange + ) + .AddEnvironmentVariables(); }); } } \ No newline at end of file From 6e17430f9b322e9514f748780ba18ae82734f989 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 19:00:37 +0300 Subject: [PATCH 06/17] Moved reverse proxy configuration to yarp file and environment file --- .../appsettings.Docker.json | 100 +++++++++++++++++ .../appsettings.json | 100 +---------------- .../src/EShopOnAbp.WebPublicGateway/yarp.json | 101 +++++++++++++++++- .../appsettings.Docker.json | 86 +++++++++++++++ 4 files changed, 286 insertions(+), 101 deletions(-) create mode 100644 gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.Docker.json create mode 100644 gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.Docker.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.Docker.json new file mode 100644 index 00000000..0787bce9 --- /dev/null +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.Docker.json @@ -0,0 +1,100 @@ +{ + "ReverseProxy": { + "Routes": { + "Account Service": { + "ClusterId": "accountCluster", + "Match": { + "Path": "/api/account/{**everything}" + } + }, + "Administration Service": { + "ClusterId": "administrationCluster", + "Match": { + "Path": "/api/abp/{**everything}" + } + }, + "Catalog Service": { + "ClusterId": "catalogCluster", + "Match": { + "Path": "/api/catalog/{**everything}" + } + }, + "Basket Service": { + "ClusterId": "basketCluster", + "Match": { + "Path": "/api/basket/{**everything}" + } + }, + "Ordering Service": { + "ClusterId": "orderingCluster", + "Match": { + "Path": "/api/ordering/{**everything}" + } + }, + "Payment Service": { + "ClusterId": "paymentCluster", + "Match": { + "Path": "/api/payment/{**everything}" + } + }, + "product-picture-route": { + "ClusterId": "productPictureCluster", + "Match": { + "Path": "/product-images/{**everything}", + "Methods" : [ "GET" ] + } + } + }, + "Clusters": { + "accountCluster": { + "Destinations": { + "destination1": { + "Address": "http://app-authserver" + } + } + }, + "administrationCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "catalogCluster": { + "Destinations": { + "destination1": { + "Address": "http://catalog-service" + } + } + }, + "basketCluster": { + "Destinations": { + "destination1": { + "Address": "http://basket-service" + } + } + }, + "orderingCluster": { + "Destinations": { + "destination1": { + "Address": "http://ordering-service" + } + } + }, + "paymentCluster": { + "Destinations": { + "destination1": { + "Address": "http://payment-service" + } + } + }, + "productPictureCluster": { + "Destinations": { + "destination1": { + "Address": "http://catalog-service" + } + } + } + } + } +} diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json index 936faa9b..119795be 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/appsettings.json @@ -22,103 +22,5 @@ }, "ElasticSearch": { "Url": "http://localhost:9200" - }, - "ReverseProxy": { - "Routes": { - "Account Service": { - "ClusterId": "account_cluster", - "Match": { - "Path": "/api/account/{**everything}" - } - }, - "Administration Service": { - "ClusterId": "administration_cluster", - "Match": { - "Path": "/api/abp/{**everything}" - } - }, - "Catalog Service": { - "ClusterId": "catalog_cluster", - "Match": { - "Path": "/api/catalog/{**everything}" - } - }, - "Basket Service": { - "ClusterId": "basket_cluster", - "Match": { - "Path": "/api/basket/{**everything}" - } - }, - "Ordering Service": { - "ClusterId": "ordering_cluster", - "Match": { - "Path": "/api/ordering/{**everything}" - } - }, - "Payment Service": { - "ClusterId": "payment_cluster", - "Match": { - "Path": "/api/payment/{**everything}" - } - }, - "product-picture-route": { - "ClusterId": "product_picture_cluster", - "Match": { - "Path": "/product-images/{**everything}", - "Methods" : [ "GET" ] - } - } - }, - "Clusters": { - "account-cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44330" - } - } - }, - "administration_cluster": { - "Destinations": { - "destination1": { - "Address": "http://localhost:44353" - } - } - }, - "catalog_cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44354" - } - } - }, - "product_picture_cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44354" - } - } - }, - "basket_cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44355" - } - } - }, - "ordering_cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44356" - } - } - }, - "payment_cluster": { - "Destinations": { - "destination1": { - "Address": "https://localhost:44357" - } - } - } - } - } + } } diff --git a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json index 19682d92..2f586248 100644 --- a/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json +++ b/gateways/web-public/src/EShopOnAbp.WebPublicGateway/yarp.json @@ -1,3 +1,100 @@ { - -} \ No newline at end of file + "ReverseProxy": { + "Routes": { + "Account Service": { + "ClusterId": "accountCluster", + "Match": { + "Path": "/api/account/{**everything}" + } + }, + "Administration Service": { + "ClusterId": "administrationCluster", + "Match": { + "Path": "/api/abp/{**everything}" + } + }, + "Catalog Service": { + "ClusterId": "catalogCluster", + "Match": { + "Path": "/api/catalog/{**everything}" + } + }, + "Basket Service": { + "ClusterId": "basketCluster", + "Match": { + "Path": "/api/basket/{**everything}" + } + }, + "Ordering Service": { + "ClusterId": "orderingCluster", + "Match": { + "Path": "/api/ordering/{**everything}" + } + }, + "Payment Service": { + "ClusterId": "paymentCluster", + "Match": { + "Path": "/api/payment/{**everything}" + } + }, + "product-picture-route": { + "ClusterId": "productPictureCluster", + "Match": { + "Path": "/product-images/{**everything}", + "Methods" : [ "GET" ] + } + } + }, + "Clusters": { + "accountCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44330" + } + } + }, + "administrationCluster": { + "Destinations": { + "destination1": { + "Address": "http://localhost:44353" + } + } + }, + "catalogCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44354" + } + } + }, + "basketCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44355" + } + } + }, + "orderingCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44356" + } + } + }, + "paymentCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44357" + } + } + }, + "productPictureCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44354" + } + } + } + } + } +} diff --git a/gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json b/gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json new file mode 100644 index 00000000..db306048 --- /dev/null +++ b/gateways/web/src/EShopOnAbp.WebGateway/appsettings.Docker.json @@ -0,0 +1,86 @@ +{ + "ReverseProxy": { + "Routes": { + "Account Service": { + "ClusterId": "accountCluster", + "Match": { + "Path": "/api/account/{**everything}" + } + }, + "Identity Service": { + "ClusterId": "identityCluster", + "Match": { + "Path": "/api/identity/{**everything}" + } + }, + "Administration Service": { + "ClusterId": "administrationCluster", + "Match": { + "Path": "/api/abp/{**everything}" + } + }, + "feature-management-route": { + "ClusterId": "featureManagementCluster", + "Match": { + "Path": "/api/feature-management/{**everything}" + } + }, + "permission-management-route": { + "ClusterId": "permissionManagementCluster", + "Match": { + "Path": "/api/permission-management/{**everything}" + } + }, + "setting-management-route": { + "ClusterId": "settingManagementCluster", + "Match": { + "Path": "/api/setting-management/{**everything}" + } + } + }, + "Clusters": { + "accountCluster": { + "Destinations": { + "destination1": { + "Address": "http://app-authserver" + } + } + }, + "identityCluster": { + "Destinations": { + "destination1": { + "Address": "http://identity-service" + } + } + }, + "administrationCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "featureManagementCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "permissionManagementCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + }, + "settingManagementCluster": { + "Destinations": { + "destination1": { + "Address": "http://administration-service" + } + } + } + } + } +} From 4b2e38556924331acc2d6728e842724528356a39 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 29 Mar 2022 19:17:49 +0300 Subject: [PATCH 07/17] Updated web-gateway configuration --- etc/docker/docker-compose.yml | 149 ++++++++++++++---- .../web/src/EShopOnAbp.WebGateway/yarp.json | 38 ++++- 2 files changed, 147 insertions(+), 40 deletions(-) diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 75b6f621..217dd07b 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -59,25 +59,28 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - - basket-service: - image: eshoponabp/service-basket:latest - container_name: basket-service-container + catalog-service: + image: eshoponabp/service-catalog:latest + container_name: catalog-service-container build: context: ../../ - dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile + dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile environment: - ASPNETCORE_ENVIRONMENT=Staging - - ASPNETCORE_URLS=https://+:443;http://+:80; + - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 + - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 + - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - RemoteServices__Catalog__BaseUrl=https://catalog-service - - RemoteServices__Catalog__GrpcUrl=http://catalog-service + - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - - "44355:443" + - "44354:443" + - "5000:80" + - "81:81" depends_on: redis: condition: service_healthy @@ -91,28 +94,24 @@ services: volumes: - ../dev-cert:/root/certificate - catalog-service: - image: eshoponabp/service-catalog:latest - container_name: catalog-service-container + basket-service: + image: eshoponabp/service-basket:latest + container_name: basket-service-container build: context: ../../ - dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile + dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile environment: - ASPNETCORE_ENVIRONMENT=Staging - - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; + - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 - - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 - - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog + - RemoteServices__Catalog__BaseUrl=https://catalog-service + - RemoteServices__Catalog__GrpcUrl=http://catalog-service - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - - "44354:443" - - "5000:80" - - "81:81" + - "44355:443" depends_on: redis: condition: service_healthy @@ -174,7 +173,6 @@ services: - Payment__PayPal__ClientId=PAYPAL_CLIENT_ID - Payment__PayPal__Secret=PAYPAL_SECRET - Payment__PayPal__Environment=Sandbox - ports: - "44357:443" depends_on: @@ -190,6 +188,60 @@ services: volumes: - ../dev-cert:/root/certificate + app-web: + image: eshoponabp/app-web:latest + container_name: app-web-container + build: + context: ../../ + dockerfile: apps/angular/Dockerfile + environment: + - RabbitMQ__Connections__Default__HostName=rabbitmq + - RemoteServices__Default__BaseUrl=http://gateway-web-public + ports: + - "4200:80" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate + app-authserver: + image: eshoponabp/app-authserver:latest + container_name: app-authserver-container + build: + context: ../../ + dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - App__SelfUrl=https://app-authserver + - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service + - App__RedirectAllowedUrls=http://app-web + - AuthServer__Authority=https://app-authserver + - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + ports: + - "44330:443" + depends_on: + redis: + condition: service_healthy + postgres-db: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate app-publicweb: image: eshoponabp/app-publicweb:latest container_name: app-publicweb-container @@ -204,14 +256,11 @@ services: - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - RemoteServices__Default__BaseUrl=http://gateway-web-public - ports: - "44335:443" depends_on: redis: condition: service_healthy - mongodb: - condition: service_healthy rabbitmq: condition: service_healthy restart: on-failure @@ -220,25 +269,57 @@ services: volumes: - ../dev-cert:/root/certificate + gateway-web: + image: eshoponabp/gateway-web:latest + container_name: gateway-web-container + build: + context: ../../ + dockerfile: gateways/web/src/EShopOnAbp.WebGateway/Dockerfile + environment: + - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_URLS=https://+:443;http://+:80; + - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - Redis__Configuration=redis + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver + - ReverseProxy__Clusters__identityCluster__Destinations__destination1__Address=http://identity-service + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service + - ReverseProxy__Clusters__feature-management-cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__permission-management-cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__setting-management-cluster__Destinations__destination1__Address=http://administration-service + ports: + - "44372:443" + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network + volumes: + - ../dev-cert:/root/certificate gateway-web-public: image: eshoponabp/gateway-web-public:latest container_name: gateway-web-public-container build: context: ../../ - dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile + dockerfile: gateways/web-public/src/EShopOnAbp.WebPublicGateway/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Staging #Or use Docker ASPNETCORE_ENVIRONMENT and remove env override - decide - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - # - ReverseProxy__Clusters__account-cluster__Destinations__destination1__Address= - - ReverseProxy__Clusters__administration_cluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__catalog_cluster__Destinations__destination1__Address=http://catalog-service - - ReverseProxy__Clusters__basket_cluster__Destinations__destination1__Address=http://basket-service - - ReverseProxy__Clusters__ordering_cluster__Destinations__destination1__Address=http://ordering-service - - ReverseProxy__Clusters__payment_cluster__Destinations__destination1__Address=http://payment-service - + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service + - ReverseProxy__Clusters__basketCluster__Destinations__destination1__Address=http://basket-service + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service + - ReverseProxy__Clusters__paymentCluster__Destinations__destination1__Address=http://payment-service + - ReverseProxy__Clusters__productPictureCluster__Destinations__destination1__Address=http://catalog-service ports: - "44373:443" depends_on: diff --git a/gateways/web/src/EShopOnAbp.WebGateway/yarp.json b/gateways/web/src/EShopOnAbp.WebGateway/yarp.json index 424e598e..d14ce8ee 100644 --- a/gateways/web/src/EShopOnAbp.WebGateway/yarp.json +++ b/gateways/web/src/EShopOnAbp.WebGateway/yarp.json @@ -2,19 +2,19 @@ "ReverseProxy": { "Routes": { "Account Service": { - "ClusterId": "account-cluster", + "ClusterId": "accountCluster", "Match": { "Path": "/api/account/{**everything}" } }, "Identity Service": { - "ClusterId": "identity-cluster", + "ClusterId": "identityCluster", "Match": { "Path": "/api/identity/{**everything}" } }, "Administration Service": { - "ClusterId": "administration-cluster", + "ClusterId": "administrationCluster", "Match": { "Path": "/api/abp/{**everything}" } @@ -36,24 +36,36 @@ "Match": { "Path": "/api/setting-management/{**everything}" } + }, + "Catalog Service": { + "ClusterId": "catalogCluster", + "Match": { + "Path": "/api/catalog/{**everything}" + } + }, + "Ordering Service": { + "ClusterId": "orderingCluster", + "Match": { + "Path": "/api/ordering/{**everything}" + } } }, "Clusters": { - "account-cluster": { + "accountCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44330" } } }, - "identity-cluster": { + "identityCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44351" } } }, - "administration-cluster": { + "administrationCluster": { "Destinations": { "destination1": { "Address": "https://localhost:44353" @@ -80,6 +92,20 @@ "Address": "https://localhost:44353" } } + }, + "catalogCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44354" + } + } + }, + "orderingCluster": { + "Destinations": { + "destination1": { + "Address": "https://localhost:44356" + } + } } } } From aa584417a492b5282522bee1a777076d0bc9ebc4 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 30 Mar 2022 01:23:01 +0300 Subject: [PATCH 08/17] updated app configurations --- etc/docker/docker-compose.yml | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 217dd07b..652f42c5 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -29,7 +29,6 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - identity-service: image: eshoponabp/service-identity:latest container_name: identity-service-container @@ -93,7 +92,6 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - basket-service: image: eshoponabp/service-basket:latest container_name: basket-service-container @@ -124,7 +122,6 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - ordering-service: image: eshoponabp/service-ordering:latest container_name: ordering-service-container @@ -154,7 +151,6 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - payment-service: image: eshoponabp/service-payment:latest container_name: payment-service-container @@ -187,7 +183,6 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - app-web: image: eshoponabp/app-web:latest container_name: app-web-container @@ -216,7 +211,7 @@ services: context: ../../ dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Development - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 @@ -225,11 +220,13 @@ services: - App__SelfUrl=https://app-authserver - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service - App__RedirectAllowedUrls=http://app-web - - AuthServer__Authority=https://app-authserver + - AuthServer__Authority=http://app-authserver + - AuthServer__RequireHttpsMetadata=false - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44330:443" + - "5001:80" depends_on: redis: condition: service_healthy @@ -255,7 +252,11 @@ services: - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq + - App__SelfUrl=https://app-publicweb + - AuthServer__Authority=http://app-authserver + - AuthServer__RequireHttpsMetadata=false - RemoteServices__Default__BaseUrl=http://gateway-web-public + - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://gateway-web-public ports: - "44335:443" depends_on: @@ -268,7 +269,6 @@ services: - eshoponabp-network volumes: - ../dev-cert:/root/certificate - gateway-web: image: eshoponabp/gateway-web:latest container_name: gateway-web-container @@ -333,7 +333,6 @@ services: volumes: - ../dev-cert:/root/certificate - networks: eshoponabp-network: external: true \ No newline at end of file From 24e7f8c6f286a890c9500ec890c7212867acfa50 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 30 Mar 2022 21:37:54 +0300 Subject: [PATCH 09/17] added environment files for Docker --- .../EShopOnAbpAuthServerModule.cs | 1 + .../appsettings.Docker.json | 42 ++++++++++++ .../appsettings.Docker.json | 60 +++++++++++++++++ .../appsettings.Docker.json | 51 +++++++++++++++ .../appsettings.Docker.json | 35 ++++++++++ .../appsettings.Docker.json | 46 +++++++++++++ .../appsettings.Docker.json | 65 +++++++++++++++++++ .../appsettings.Docker.json | 30 +++++++++ 8 files changed, 330 insertions(+) create mode 100644 apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json create mode 100644 apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json create mode 100644 services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json create mode 100644 services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json create mode 100644 services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.Docker.json create mode 100644 services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json create mode 100644 services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs index 8b57f016..11f59d6e 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs @@ -185,6 +185,7 @@ public class EShopOnAbpAuthServerModule : AbpModule app.UseJwtTokenMiddleware(); app.UseAbpSerilogEnrichers(); app.UseUnitOfWork(); + app.UseForwardedHeaders(); app.UseIdentityServer(); app.UseAuthorization(); app.UseSwagger(); diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json new file mode 100644 index 00000000..211c73ff --- /dev/null +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json @@ -0,0 +1,42 @@ +{ + "App": { + "SelfUrl": "https://app-authserver", + "CorsOrigins": "http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service", + "RedirectAllowedUrls": "http://app-web" + }, + "Logging": { + "LogLevel": { + "Default": "Information", + "Microsoft": "Warning", + "Microsoft.Hosting.Lifetime": "Information" + } + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "AllowedHosts": "*", + "ConnectionStrings": { + "IdentityService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false;", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "StringEncryption": { + "DefaultPassPhrase": "gsKnGZ041HLL4IM8" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_AuthServer", + "ExchangeName": "EShopOnAbp" + } + } +} diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json new file mode 100644 index 00000000..9eb3dd5b --- /dev/null +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json @@ -0,0 +1,60 @@ +{ + "App": { + "SelfUrl": "https://app-publicweb" + }, + "Logging": { + "LogLevel": { + "Default": "Information", + "Microsoft": "Warning", + "Microsoft.Hosting.Lifetime": "Information" + } + }, + "AllowedHosts": "*", + "RemoteServices": { + "Default": { + "BaseUrl": "http://gateway-web-public" + } + }, + "StringEncryption": { + "DefaultPassPhrase": "gsKnGZ041HLL4IM8" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_PublicWeb", + "ExchangeName": "EShopOnAbp" + } + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "ClientId": "PublicWeb", + "ClientSecret": "1q2w3e*" + }, + "ReverseProxy": { + "Routes": { + "route1" : { + "ClusterId": "cluster1", + "Match": { + "Path": "/api/{**anypath}" + } + } + }, + "Clusters": { + "cluster1": { + "Destinations": { + "destination1": { + "Address": "http://gateway-web-public" + } + } + } + } + } +} \ No newline at end of file diff --git a/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..3031859f --- /dev/null +++ b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,51 @@ +{ + "App": { + "SelfUrl": "https://administration-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "RemoteServices": { + "AbpIdentity": { + "BaseUrl": "http://identity-service", + "UseCurrentAccessToken": "false" + } + }, + "IdentityClients": { + "Default": { + "GrantType": "client_credentials", + "ClientId": "EShopOnAbp_AdministrationService", + "ClientSecret": "1q2w3e*", + "Authority": "http://app-authserver", + "Scope": "IdentityService" + } + }, + "Logging": { + "LogLevel": { + "Default": "Information", + "Microsoft": "Warning", + "Microsoft.Hosting.Lifetime": "Information" + } + }, + "ConnectionStrings": { + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_AdministrationService", + "ExchangeName": "EShopOnAbp" + } + } +} diff --git a/services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json b/services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json new file mode 100644 index 00000000..b8f4a343 --- /dev/null +++ b/services/basket/src/EShopOnAbp.BasketService/appsettings.Docker.json @@ -0,0 +1,35 @@ +{ + "App": { + "SelfUrl": "https://basket-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "RemoteServices": { + "Catalog": { + "BaseUrl": "https://catalog-service", + "GrpcUrl": "http://catalog-service" + } + }, + "ConnectionStrings": { + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_BasketService", + "ExchangeName": "EShopOnAbp" + } + } +} \ No newline at end of file diff --git a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.Docker.json b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..7ec5db5e --- /dev/null +++ b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,46 @@ +{ + "App": { + "SelfUrl": "https://catalog-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "ConnectionStrings": { + "CatalogService": "mongodb://mongodb/EShopOnAbp_Catalog", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_CatalogService", + "ExchangeName": "EShopOnAbp" + } + }, + "Kestrel": { + "Endpoints": { + "Http": { + "Url": "http://localhost:5000", + "Protocols": "Http1AndHttp2" + }, + "Https": { + "Url": "https://localhost:44354", + "Protocols": "Http1AndHttp2" + }, + "gRPC": { + "Url": "http://localhost:81", + "Protocols": "Http2" + } + } + } +} diff --git a/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..0f625175 --- /dev/null +++ b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,65 @@ +{ + "App": { + "SelfUrl": "https://identity-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "ConnectionStrings": { + "IdentityService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false;", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_IdentityService", + "ExchangeName": "EShopOnAbp" + } + }, + "IdentityServerClients": { + "Web": { + "RootUrl": "http://localhost:4200" + }, + "PublicWeb": { + "RootUrl": "https://localhost:44335/" + }, + "WebGateway": { + "RootUrl": "https://localhost:44372" + }, + "PublicWebGateway": { + "RootUrl": "https://localhost:44373" + }, + "AccountService": { + "RootUrl": "https://localhost:44330" + }, + "IdentityService": { + "RootUrl": "https://localhost:44351" + }, + "AdministrationService": { + "RootUrl": "https://localhost:44353" + }, + "CatalogService": { + "RootUrl": "https://localhost:44354" + }, + "BasketService": { + "RootUrl": "https://localhost:44355" + }, + "OrderingService": { + "RootUrl": "https://localhost:44356" + }, + "PaymentService": { + "RootUrl": "https://localhost:44357" + } + } +} diff --git a/services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json b/services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json new file mode 100644 index 00000000..309876d0 --- /dev/null +++ b/services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/appsettings.Docker.json @@ -0,0 +1,30 @@ +{ + "App": { + "SelfUrl": "https://ordering-service", + "CorsOrigins": "https://gateway-web,gateway-web-public" + }, + "AuthServer": { + "Authority": "http://app-authserver", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "WebGateway_Swagger", + "SwaggerClientSecret": "1q2w3e*" + }, + "ConnectionStrings": { + "OrderingService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false", + "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" + }, + "Redis": { + "Configuration": "redis" + }, + "RabbitMQ": { + "Connections": { + "Default": { + "HostName": "rabbitmq" + } + }, + "EventBus": { + "ClientName": "EShopOnAbp_OrderingService", + "ExchangeName": "EShopOnAbp" + } + } +} \ No newline at end of file From 61afd863f7182eb30c1788ac0e2000ea7997b104 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Thu, 31 Mar 2022 00:33:17 +0300 Subject: [PATCH 10/17] added ps cert generator --- .../EShopOnAbpAuthServerModule.cs | 1 - .../appsettings.Docker.json | 11 --- .../appsettings.Docker.json | 11 --- etc/docker/certs/generate_certs.ps1 | 60 ++++++++++++++ etc/docker/docker-compose.yml | 78 +++++++++---------- 5 files changed, 99 insertions(+), 62 deletions(-) create mode 100644 etc/docker/certs/generate_certs.ps1 diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs index 11f59d6e..8b57f016 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs @@ -185,7 +185,6 @@ public class EShopOnAbpAuthServerModule : AbpModule app.UseJwtTokenMiddleware(); app.UseAbpSerilogEnrichers(); app.UseUnitOfWork(); - app.UseForwardedHeaders(); app.UseIdentityServer(); app.UseAuthorization(); app.UseSwagger(); diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json index 211c73ff..5e2fe164 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/appsettings.Docker.json @@ -4,27 +4,16 @@ "CorsOrigins": "http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service", "RedirectAllowedUrls": "http://app-web" }, - "Logging": { - "LogLevel": { - "Default": "Information", - "Microsoft": "Warning", - "Microsoft.Hosting.Lifetime": "Information" - } - }, "AuthServer": { "Authority": "http://app-authserver", "RequireHttpsMetadata": "false", "SwaggerClientId": "WebGateway_Swagger", "SwaggerClientSecret": "1q2w3e*" }, - "AllowedHosts": "*", "ConnectionStrings": { "IdentityService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false;", "AdministrationService": "User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false;" }, - "StringEncryption": { - "DefaultPassPhrase": "gsKnGZ041HLL4IM8" - }, "Redis": { "Configuration": "redis" }, diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json index 9eb3dd5b..47024036 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.Docker.json @@ -2,22 +2,11 @@ "App": { "SelfUrl": "https://app-publicweb" }, - "Logging": { - "LogLevel": { - "Default": "Information", - "Microsoft": "Warning", - "Microsoft.Hosting.Lifetime": "Information" - } - }, - "AllowedHosts": "*", "RemoteServices": { "Default": { "BaseUrl": "http://gateway-web-public" } }, - "StringEncryption": { - "DefaultPassPhrase": "gsKnGZ041HLL4IM8" - }, "Redis": { "Configuration": "redis" }, diff --git a/etc/docker/certs/generate_certs.ps1 b/etc/docker/certs/generate_certs.ps1 new file mode 100644 index 00000000..449c232c --- /dev/null +++ b/etc/docker/certs/generate_certs.ps1 @@ -0,0 +1,60 @@ +# Source: https://stackoverflow.com/a/62060315 +# Generate self-signed certificate to be used by IdentityServer. +# When using localhost - API cannot see the IdentityServer from within the docker-compose'd network. +# You have to run this script as Administrator (open Powershell by right click -> Run as Administrator). + +$rootCN = "eShopOnAbp" +$authserverCNs = "app-authserver", "localhost" +$publicWebCNs = "app-public-web", "localhost" +$administrationServiceCNs = "administration-service", "localhost" +$identityServiceCNs = "identity-service", "localhost" +$catalogServiceCNs = "catalog-service", "localhost" +$basketServiceCNs = "basket-service", "localhost" +$orderingServiceCNs = "ordering-service", "localhost" +$paymentServiceCNs = "payment-service", "localhost" + +$alreadyExistingCertsRoot = Get-ChildItem -Path Cert:\LocalMachine\My -Recurse | Where-Object {$_.Subject -eq "CN=$rootCN"} + +if ($alreadyExistingCertsRoot.Count -eq 1) { + Write-Output "Skipping creating Root CA certificate as it already exists." + $rootCA = [Microsoft.CertificateServices.Commands.Certificate] $alreadyExistingCertsRoot[0] +} else { + $rootCA = New-SelfSignedCertificate -Subject $rootCN -KeyUsageProperty Sign -KeyUsage CertSign -CertStoreLocation Cert:\LocalMachine\My +} + +$authserverCert = New-SelfSignedCertificate -DnsName $authserverCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $publicWebCert = New-SelfSignedCertificate -DnsName $publicWebCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $administrationServiceCert = New-SelfSignedCertificate -DnsName $administrationServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $identityServiceCert = New-SelfSignedCertificate -DnsName $identityServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $catalogServiceCert = New-SelfSignedCertificate -DnsName $catalogServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $basketServiceCert = New-SelfSignedCertificate -DnsName $basketServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $orderingServiceCert = New-SelfSignedCertificate -DnsName $orderingServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My +# $paymentServiceCert = New-SelfSignedCertificate -DnsName $paymentServiceCNs -Signer $rootCN -CertStoreLocation Cert:\LocalMachine\My + +$password = ConvertTo-SecureString -String "8b6039b6-c67a-448b-977b-0ce6d3fcfd49" -Force -AsPlainText + +Export-PfxCertificate -Cert $rootCA -FilePath eShopOnAbp-root-cert.pfx -Password $password | Out-Null +Export-PfxCertificate -Cert $authserverCert -FilePath app-authserver-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $publicWebCert -FilePath app-public-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $administrationServiceCert -FilePath administration-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $identityServiceCert -FilePath identity-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $catalogServiceCert -FilePath catalog-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $basketServiceCert -FilePath basket-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $orderingServiceCert -FilePath ordering-service-cert.pfx -Password $password | Out-Null +# Export-PfxCertificate -Cert $paymentServiceCert -FilePath payment-service-cert.pfx -Password $password | Out-Null + +# Export .cer to be converted to .crt to be trusted within the Docker container. +Export-Certificate -Cert $rootCA -FilePath eShopOnAbp-root-cert.cer -Type CERT | Out-Null + +# Trust it on your host machine. +$store = New-Object System.Security.Cryptography.X509Certificates.X509Store "Root","LocalMachine" +$store.Open("ReadWrite") + +$rootCertAlreadyTrusted = ($store.Certificates | Where-Object {$_.Subject -eq "CN=$rootCN"} | Measure-Object).Count -eq 1 + +if ($rootCertAlreadyTrusted -eq $false) { + Write-Output "Adding the root CA certificate to the trust store." + $store.Add($rootCA) +} + +$store.Close() \ No newline at end of file diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 652f42c5..a0134896 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -8,13 +8,13 @@ services: context: ../../ dockerfile: services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44353:443" depends_on: @@ -36,7 +36,7 @@ services: context: ../../ dockerfile: services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80 - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 @@ -65,17 +65,17 @@ services: context: ../../ dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44354:443" - "5000:80" @@ -99,15 +99,15 @@ services: context: ../../ dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - RemoteServices__Catalog__BaseUrl=https://catalog-service - - RemoteServices__Catalog__GrpcUrl=http://catalog-service - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - RemoteServices__Catalog__BaseUrl=https://catalog-service + # - RemoteServices__Catalog__GrpcUrl=http://catalog-service + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44355:443" depends_on: @@ -129,7 +129,7 @@ services: context: ../../ dockerfile: services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 @@ -158,7 +158,7 @@ services: context: ../../ dockerfile: services/payment/src/EShopOnAbp.PaymentService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 @@ -211,22 +211,22 @@ services: context: ../../ dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Development + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; + - ASPNETCORE_HTTPS_PORT=44330 - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - App__SelfUrl=https://app-authserver - - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service - - App__RedirectAllowedUrls=http://app-web - - AuthServer__Authority=http://app-authserver - - AuthServer__RequireHttpsMetadata=false - - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - App__SelfUrl=https://app-authserver + # - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service + # - App__RedirectAllowedUrls=http://app-web + - AuthServer__Authority=https://app-authserver + - AuthServer__RequireHttpsMetadata=true + # - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; + # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; ports: - "44330:443" - - "5001:80" depends_on: redis: condition: service_healthy @@ -246,17 +246,17 @@ services: context: ../../ dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - - App__SelfUrl=https://app-publicweb - - AuthServer__Authority=http://app-authserver - - AuthServer__RequireHttpsMetadata=false - - RemoteServices__Default__BaseUrl=http://gateway-web-public - - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://gateway-web-public + # - Redis__Configuration=redis + # - RabbitMQ__Connections__Default__HostName=rabbitmq + # - App__SelfUrl=https://app-publicweb + - AuthServer__Authority=https://app-authserver + - AuthServer__RequireHttpsMetadata=true + # - RemoteServices__Default__BaseUrl=http://gateway-web-public + # - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://gateway-web-public ports: - "44335:443" depends_on: @@ -276,7 +276,7 @@ services: context: ../../ dockerfile: gateways/web/src/EShopOnAbp.WebGateway/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging + - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 @@ -308,7 +308,7 @@ services: context: ../../ dockerfile: gateways/web-public/src/EShopOnAbp.WebPublicGateway/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Staging #Or use Docker ASPNETCORE_ENVIRONMENT and remove env override - decide + - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - ASPNETCORE_URLS=https://+:443;http://+:80; - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 From a5e3b3ed8babed9043a34f2bff4ef594309dbfd0 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Sat, 9 Apr 2022 21:50:48 +0300 Subject: [PATCH 11/17] updated docker configuration --- etc/docker/README.md | 14 +++++++++++ etc/docker/certs/eshop-dk.crt | 19 +++++++++++++++ etc/docker/certs/eshop-dk.key | 28 ++++++++++++++++++++++ etc/docker/certs/eshop-ssl.conf | 40 +++++++++++++++++++++++++++++++ etc/docker/docker-compose.yml | 42 ++++++++++++++++----------------- 5 files changed, 122 insertions(+), 21 deletions(-) create mode 100644 etc/docker/README.md create mode 100644 etc/docker/certs/eshop-dk.crt create mode 100644 etc/docker/certs/eshop-dk.key create mode 100644 etc/docker/certs/eshop-ssl.conf diff --git a/etc/docker/README.md b/etc/docker/README.md new file mode 100644 index 00000000..3363c305 --- /dev/null +++ b/etc/docker/README.md @@ -0,0 +1,14 @@ +### Generate Self-Signed Certificate Using OpenSSL + +``` +openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-dk.key -out eshop-dk.crt -subj `"/CN=$certSubj`" -addext `"subjectAltName=DNS:localhost,DNS:host.docker.internal,DNS:app-authserver`" +openssl pkcs12 -export -in eshop-dk.crt -inkey eshop-dk.key -out eshop-dk.pfx -passout pass:8b6039b6-c67a-448b-977b-0ce6d3fcfd49 +``` + +### How to run? + +* Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`): + +````powershell +127.0.0.1 app-authserver +```` \ No newline at end of file diff --git a/etc/docker/certs/eshop-dk.crt b/etc/docker/certs/eshop-dk.crt new file mode 100644 index 00000000..c4fd60fa --- /dev/null +++ b/etc/docker/certs/eshop-dk.crt @@ -0,0 +1,19 @@ +-----BEGIN CERTIFICATE----- +MIIDHzCCAgegAwIBAgIUX5WvovRMAkZTaoZGsFNyyjLU7F8wDQYJKoZIhvcNAQEL +BQAwADAeFw0yMjA0MDkxNjU3NDlaFw0yMzA0MDkxNjU3NDlaMAAwggEiMA0GCSqG +SIb3DQEBAQUAA4IBDwAwggEKAoIBAQD0KAzKq9bop31wIPo06eq4AYhdB0zZA+Eh +4mEOvCZ7MtAWUjkP1LudFF4IBlpIaAG0g6o5IhFRHQOIRfVXYA2NSGK8QpVSfmtk +it+Wc9bVvVJ9kqPhVakQIqhkOH4gPJ5MK/fhB6qSiN0TsbXZSHri6Q47Jd46X2DX +LK8c5/KRyrsFY/IVoSHC5kxyxLSzWK7T7JzqEXNtaVCOVf6difuCzPwiqqCk7WtC +LZcCj7n9m5UjpyOLo4iF8wIUk+IpaGKBxYBJ0MuMa8eG3Oz73JZBTaXAAJszNTgG +TVNYuUmi8z4s+U0p+sPW37hpv83atpPaV2rkyaYmM8DNgLyrPj3zAgMBAAGjgZAw +gY0wHQYDVR0OBBYEFGfpXUNdCmwNsLrHLLvxeQ0qQ3b7MB8GA1UdIwQYMBaAFGfp +XUNdCmwNsLrHLLvxeQ0qQ3b7MA8GA1UdEwEB/wQFMAMBAf8wOgYDVR0RBDMwMYIJ +bG9jYWxob3N0ghRob3N0LmRvY2tlci5pbnRlcm5hbIIOYXBwLWF1dGhzZXJ2ZXIw +DQYJKoZIhvcNAQELBQADggEBANY9ID0BUoIAqB/yfQwaXohG8lx4qwGl3BDBzr/L +N0B47WkemFqYNYsAzwdami8hz7D9JIHXeTH+kcpiNE6jrNW31mEzzcgFkzpZxUkb +39mBB5sDNyFlFdObW8G5s0joL0dm2CJK+ujN12EJucOoeOKZmkD49bxc027rj9vz +rEDk3b6L6wkWPf7bBjtHPLfew0R0j1shdZBQFCNa7HRU+JFSXBqHXQKGdxi0uGbb +ENCmZaYHYA4ZO+deqHYr+HWO1tZPS7Wicm+NMEBKqiPB0hQWqUXnBbe6sWGW5TmP +ihgNWE46+y6LMjmxlGUdJNOHAWJVDijWZMsvwnY+doW89MA= +-----END CERTIFICATE----- diff --git a/etc/docker/certs/eshop-dk.key b/etc/docker/certs/eshop-dk.key new file mode 100644 index 00000000..b43ecb99 --- /dev/null +++ b/etc/docker/certs/eshop-dk.key @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQD0KAzKq9bop31w +IPo06eq4AYhdB0zZA+Eh4mEOvCZ7MtAWUjkP1LudFF4IBlpIaAG0g6o5IhFRHQOI +RfVXYA2NSGK8QpVSfmtkit+Wc9bVvVJ9kqPhVakQIqhkOH4gPJ5MK/fhB6qSiN0T +sbXZSHri6Q47Jd46X2DXLK8c5/KRyrsFY/IVoSHC5kxyxLSzWK7T7JzqEXNtaVCO +Vf6difuCzPwiqqCk7WtCLZcCj7n9m5UjpyOLo4iF8wIUk+IpaGKBxYBJ0MuMa8eG +3Oz73JZBTaXAAJszNTgGTVNYuUmi8z4s+U0p+sPW37hpv83atpPaV2rkyaYmM8DN +gLyrPj3zAgMBAAECggEAZG5tBJk257CtyofmJAnsgRAwVYQBOmt8GgISxorikV7P +db8QtdBd9DlCjK6ASLRvrx9Rz/qRgPocT9vnFa/vIySZaLNC1RInfs4ZNrwjrPwZ +iInfW3tu9bIr7j3Gs9/7hX24kxoiMfCWb9lz4hMMaXZQYkgrZ3uATEKXLZ7DivA5 +2yku9gQdWZlwXSQqWgx2kwZjyRAkUC88HtPfxCkF0NHJur7CgM3UxeFockwfJ+/i +EUFoklMSolIlqivJ1765J17hW7vebBnP7b5SZJFAGjxxhLJ7wQ+FlZiwNEoCLDZx +B7S6ARzzNAdMOsls1DwQWrX5Nupl3XgQRBakMEJxIQKBgQD7WkZV2XDkyEnBYTk2 +e2DYNlFNsJeHhwml0jTBASMGosrwRqFf4DpozFap6UFPHTyhYcGJfEfojG8zrWN+ +MuYT0EzMHtPBPnDSCtKeeZ2wq+ON3gps3lsdIJLgCo9IGbak+90AigzVe5JPykuh +qu6XGs1f/DSGLXAk1IqgsQbrmQKBgQD4q7ardKl0U2m4OiozAZqUR5l1oe+MSdxZ +j3DGkMpOe7F+b63jHtWjEE3MEtzKXsZxOucy5S3OTZs0hdRB+IRP443uNARoaatN +14ZYbvPjmCTn6m6qR+fs7MWesaUStAVgGVWQgWY+4CZz3Zm+UXcmS+QHoiSbGfaz +neI4tFsNawKBgQCyxCLwHgVIAhdK3S4GzLs1K3Spz6YF8wnukNGKT5esuY2iVGmj +ueNw85vTnp0feojLsq4mbWjrQS45z+DKOcMfZm+oYWhzsUgmayIfKhn4NFhUZw59 +HawpzCgKBhifzAH111f4cTbtgsSt0Q/3fI3SlHJrCQIGSDzRRQUPgriMSQKBgGuJ +Llyk/abNb5l4pcka93MKJ4XkOohrZHvieP2Vnbck7JPlzce7DN4QbeRDf/GP3LcY +puSukQl3LBghi7Hfu7AkkrshCYrxr1/hRTq2+IdCwyr7iVHf+J7PoYJIBj+5U93D +9umf28xy+I4Albzk0+beyMS4TKY6KyJvs2WcMQfzAoGARac5umqHTqNubeVoB2EX +BMFj55RDkWH9GU631deMDgfPvymZJ5HI1Dz+jdX7PbOfPbc+5AUN4lZqZw5/2yxN +ps0BUMz1Hr4goeoC0akFsnA5GXoFkhWh6xR45ZRfmPEDYxvk8tqeZvtZns+3AjfR ++C6C4YZdYsgLfWRFtxW3OlA= +-----END PRIVATE KEY----- diff --git a/etc/docker/certs/eshop-ssl.conf b/etc/docker/certs/eshop-ssl.conf new file mode 100644 index 00000000..e82d4494 --- /dev/null +++ b/etc/docker/certs/eshop-ssl.conf @@ -0,0 +1,40 @@ +[req] +default_bits = 2048 +default_keyfile = eshop-dk.key +distinguished_name = req_distinguished_name +req_extensions = req_ext +x509_extensions = v3_ca + +[req_distinguished_name] +commonName = Common Name (e.g. server FQDN or YOUR name) +commonName_default = eshoponabp +commonName_max = 64 + +[req_ext] +subjectAltName = @alt_names + +[v3_ca] +subjectAltName = @alt_names +basicConstraints = critical, CA:false +keyUsage = keyCertSign, cRLSign, digitalSignature,keyEncipherment + +[alt_names] +DNS.1 = localhost +DNS.2 = 127.0.0.1 +DNS.3 = host.docker.internal +DNS.4 = app-authserver +DNS.5 = app-web +DNS.6 = app-publicweb +DNS.7 = gateway-web +DNS.8 = gateway-web-public +DNS.9 = administration-service +DNS.10 = identity-service +DNS.11 = catalog-service +DNS.12 = basket-service +DNS.13 = ordering-service +DNS.14 = payment-service + +# Generate certificate from config +# Use the command: +# 'openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-dk.key -out eshop-dk-cert.pem -config eshop-ssl.conf' + diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index a0134896..01593fbf 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -10,7 +10,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -28,7 +28,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate identity-service: image: eshoponabp/service-identity:latest container_name: identity-service-container @@ -38,7 +38,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80 - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -57,7 +57,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate catalog-service: image: eshoponabp/service-catalog:latest container_name: catalog-service-container @@ -67,7 +67,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 @@ -91,7 +91,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate basket-service: image: eshoponabp/service-basket:latest container_name: basket-service-container @@ -101,7 +101,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -121,7 +121,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate ordering-service: image: eshoponabp/service-ordering:latest container_name: ordering-service-container @@ -131,7 +131,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -150,7 +150,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate payment-service: image: eshoponabp/service-payment:latest container_name: payment-service-container @@ -160,7 +160,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -182,7 +182,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate app-web: image: eshoponabp/app-web:latest container_name: app-web-container @@ -203,7 +203,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate app-authserver: image: eshoponabp/app-authserver:latest container_name: app-authserver-container @@ -214,7 +214,7 @@ services: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - ASPNETCORE_HTTPS_PORT=44330 - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -238,7 +238,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate app-publicweb: image: eshoponabp/app-publicweb:latest container_name: app-publicweb-container @@ -248,7 +248,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -268,7 +268,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate gateway-web: image: eshoponabp/gateway-web:latest container_name: gateway-web-container @@ -278,7 +278,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver @@ -300,7 +300,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate gateway-web-public: image: eshoponabp/gateway-web-public:latest container_name: gateway-web-public-container @@ -310,7 +310,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver @@ -331,7 +331,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate networks: eshoponabp-network: From 2b64e87f86c89a99fff239053dd9c9ef96379df6 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Sat, 9 Apr 2022 21:51:07 +0300 Subject: [PATCH 12/17] updated kubernetes configuration --- .../templates/administration-ingress.yaml | 7 ++- .../charts/administration/values.yaml | 4 +- .../templates/authserver-ingress.yaml | 12 +++-- .../eshoponabp/charts/authserver/values.yaml | 7 ++- .../basket/templates/basket-ingress.yaml | 3 +- etc/k8s/eshoponabp/charts/basket/values.yaml | 2 +- .../catalog/templates/catalog-deployment.yaml | 12 ++--- .../catalog/templates/catalog-ingress.yaml | 2 +- .../catalog/templates/catalog-service.yaml | 8 ++- etc/k8s/eshoponabp/charts/catalog/values.yaml | 11 ++-- .../gateway-web-public-deployment.yaml | 6 +-- .../templates/gateway-web-public-ingress.yaml | 2 +- .../charts/gateway-web-public/values.yaml | 23 ++++----- .../eshoponabp/charts/gateway-web/values.yaml | 2 +- .../identity/templates/identity-ingress.yaml | 2 +- .../eshoponabp/charts/identity/values.yaml | 2 +- .../eshoponabp/charts/ordering/values.yaml | 2 +- etc/k8s/eshoponabp/charts/payment/values.yaml | 2 +- .../templates/public-web-deployment.yaml | 16 +++--- .../eshoponabp/charts/public-web/values.yaml | 6 +-- etc/k8s/eshoponabp/charts/web/values.yaml | 2 +- etc/k8s/eshoponabp/values.yaml | 6 +-- etc/k8s/tls-cert/eshop-demo-tls.conf | 38 ++++++++++++++ etc/k8s/tls-cert/eshop-st-cert.key | 28 +++++++++++ etc/k8s/tls-cert/eshop-st-cert.pem | 50 ++++++++----------- etc/k8s/tls-cert/eshop-st-key.pem | 28 ----------- etc/k8s/tls-cert/eshop-test-tls.crt | 23 +++++++++ etc/k8s/tls-cert/eshop-test-tls.key | 28 +++++++++++ etc/k8s/tls-cert/ingress-tls.yaml | 24 +++++++++ etc/k8s/tls-cert/notes.md | 40 +++++++++++++++ etc/k8s/tls-cert/selfsigned/certificate.yaml | 21 ++++++++ .../tls-cert/selfsigned/cluster-issuer.yaml | 6 +++ etc/k8s/tls-cert/selfsigned/issuer.yaml | 7 +++ etc/k8s/tls-cert/selfsigned/readme.md | 8 +++ 34 files changed, 314 insertions(+), 126 deletions(-) create mode 100644 etc/k8s/tls-cert/eshop-demo-tls.conf create mode 100644 etc/k8s/tls-cert/eshop-st-cert.key delete mode 100644 etc/k8s/tls-cert/eshop-st-key.pem create mode 100644 etc/k8s/tls-cert/eshop-test-tls.crt create mode 100644 etc/k8s/tls-cert/eshop-test-tls.key create mode 100644 etc/k8s/tls-cert/ingress-tls.yaml create mode 100644 etc/k8s/tls-cert/selfsigned/certificate.yaml create mode 100644 etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml create mode 100644 etc/k8s/tls-cert/selfsigned/issuer.yaml create mode 100644 etc/k8s/tls-cert/selfsigned/readme.md diff --git a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml index e843265f..fad0cb65 100644 --- a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml @@ -8,7 +8,12 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt + {{- if eq .Release.Name "es-st" }} + cert-manager.io/cluster-issuer: eshop-issuer + {{- end }} + {{- if eq .Release.Name "es-az" }} + cert-manager.io/issuer: letsencrypt + {{- end }} spec: tls: - hosts: diff --git a/etc/k8s/eshoponabp/charts/administration/values.yaml b/etc/k8s/eshoponabp/charts/administration/values.yaml index 5b0f6c97..3a6e31d8 100644 --- a/etc/k8s/eshoponabp/charts/administration/values.yaml +++ b/etc/k8s/eshoponabp/charts/administration/values.yaml @@ -25,8 +25,8 @@ synchedCommunication: scope: # "IdentityService" ingress: - host: # eshop-st-administration - tlsSecret: eshop-demo-tls + host: eshop-st-administration + tlsSecret: eshop-staging-tls image: repository: eshoponabp/service-administration diff --git a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml index b74c1044..a24245ba 100644 --- a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml @@ -8,14 +8,20 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt nginx.ingress.kubernetes.io/configuration-snippet: | more_set_input_headers "from-ingress: true"; + # cert-manager.io/cluster-issuer: selfsigned-issuer + # {{- if eq .Release.Name "es-st" }} + # cert-manager.io/cluster-issuer: eshop-issuer + # {{- end }} + # {{- if eq .Release.Name "es-az" }} + # cert-manager.io/issuer: letsencrypt + # {{- end }} spec: tls: - hosts: - - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + - "eshop-st-authserver" + secretName: "eshop-test-tls" rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/authserver/values.yaml b/etc/k8s/eshoponabp/charts/authserver/values.yaml index 95f80979..a1b3edb6 100644 --- a/etc/k8s/eshoponabp/charts/authserver/values.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/values.yaml @@ -17,13 +17,12 @@ config: stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: - host: # eshop-st-authserver - tlsSecret: eshop-demo-tls + host: eshop-st-authserver + tlsSecret: eshop-staging-tls image: repository: eshoponabp/app-authserver tag: latest pullPolicy: IfNotPresent -env: {} - \ No newline at end of file +env: {} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml index e843265f..7f7ab322 100644 --- a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml @@ -8,7 +8,8 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt + cert-manager.io/issuer: eshop-issuer + # cert-manager.io/cluster-issuer: letsencrypt spec: tls: - hosts: diff --git a/etc/k8s/eshoponabp/charts/basket/values.yaml b/etc/k8s/eshoponabp/charts/basket/values.yaml index 5571e666..f332621a 100644 --- a/etc/k8s/eshoponabp/charts/basket/values.yaml +++ b/etc/k8s/eshoponabp/charts/basket/values.yaml @@ -19,7 +19,7 @@ config: ingress: host: eshop-st-basket - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/service-basket diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml index 17aef76c..a057014e 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml @@ -18,22 +18,22 @@ spec: ports: - name: http containerPort: 80 - - name: https - containerPort: 443 - name: grpc containerPort: 81 protocol: TCP env: + - name: "ASPNETCORE_URLS" + value: "http://+:80;http://+:81" + - name: "DOTNET_ENVIRONMENT" + value: "{{ .Values.config.dotnetEnv }}" - name: App__SelfUrl value: "{{ .Values.config.selfUrl }}" - name: App__CorsOrigins value: "{{ .Values.config.corsOrigins }}" - name: "ConnectionStrings__CatalogService" - value: {{ .Values.config.connectionStrings.catalogService }} + value: "{{ .Values.config.connectionStrings.catalogService }}" - name: "ConnectionStrings__AdministrationService" - value: {{ .Values.config.connectionStrings.administrationService }} - - name: "DOTNET_ENVIRONMENT" - value: "{{ .Values.config.dotnetEnv }}" + value: "{{ .Values.config.connectionStrings.administrationService }}" - name: "Redis__Configuration" value: "{{ .Values.config.redisHost }}" - name: "RabbitMQ__Connections__Default__HostName" diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml index e843265f..774a82c0 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml @@ -8,7 +8,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt + # cert-manager.io/cluster-issuer: letsencrypt spec: tls: - hosts: diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml index 278771cd..28306a83 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml @@ -6,13 +6,11 @@ metadata: name: {{ .Release.Name }}-{{ .Chart.Name }} spec: ports: - - name: "80" + - name: "http" port: 80 - - name: "443" - port: 443 - - port: {{ .Values.config.grpcPort }} + - name: grpc targetPort: grpc protocol: TCP - name: grpc + port: {{ .Values.config.grpcPort }} selector: app: {{ .Release.Name }}-{{ .Chart.Name }} diff --git a/etc/k8s/eshoponabp/charts/catalog/values.yaml b/etc/k8s/eshoponabp/charts/catalog/values.yaml index d45c8b9e..970e0e02 100644 --- a/etc/k8s/eshoponabp/charts/catalog/values.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/values.yaml @@ -16,20 +16,21 @@ config: stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 grpcPort: 81 kestrel: - httpUrl: # + httpUrl: http://eshop-st-catalog:80 httpProtocols: Http1AndHttp2 - grpcUrl: # + grpcUrl: http://eshop-st-catalog:81 grpcProtocols: Http2 - ingress: host: eshop-st-catalog - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/service-catalog tag: latest pullPolicy: IfNotPresent -env: {} +env: { + # ASPNETCORE_URLS=http://+:80;http://+:81 +} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml index 07cea6b6..5e25b31e 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-deployment.yaml @@ -27,8 +27,6 @@ spec: env: - name: App__SelfUrl value: "{{ .Values.config.selfUrl }}" - - name: GlobalConfiguration__BaseUrl - value: "{{ .Values.config.globalConfigurationBaseUrl }}" - name: "DOTNET_ENVIRONMENT" value: "{{ .Values.config.dotnetEnv }}" - name: "Redis__Configuration" @@ -44,9 +42,7 @@ spec: - name: "AuthServer__SwaggerClientSecret" value: "{{ .Values.config.authServer.swaggerClientSecret }}" - name: "ElasticSearch__Url" - value: "{{ .Values.config.elasticsearchHost }}" - - name: "StringEncryption__DefaultPassPhrase" - value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}" + value: "{{ .Values.config.elasticsearchHost }}" {{- if .Values.env }} {{ toYaml .Values.env | indent 8 }} {{- end }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml index 539025ac..9bcfa428 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml @@ -8,7 +8,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt + cert-manager.io/cluster-issuer: eshop-issuer {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml index c57f2199..bb625762 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml @@ -1,6 +1,5 @@ config: selfUrl: https://eshop-st-gateway-public-web - globalConfigurationBaseUrl: http://eshop-st-gateway-public-web authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -9,33 +8,31 @@ config: dotnetEnv: Staging redisHost: es-st-redis rabbitmqHost: es-st-rabbitmq - elasticsearchHost: # - stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 + elasticsearchHost: es-st-elasticsearch reRoutes: accountService: - url: http://eshop-st-authserver + url: https://eshop-st-authserver identityService: - url: http://eshop-st-identity + url: https://eshop-st-identity administrationService: - url: http://eshop-st-administration + url: https://eshop-st-administration catalogService: - url: http://eshop-st-catalog + url: https://eshop-st-catalog basketService: - url: http://eshop-st-basket + url: https://eshop-st-basket orderingService: - url: http://eshop-st-ordering + url: https://eshop-st-ordering paymentService: - url: http://eshop-st-payment + url: https://eshop-st-payment ingress: host: eshop-st-gateway-web-public - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/gateway-web-public tag: latest pullPolicy: IfNotPresent -env: {} - \ No newline at end of file +env: {} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml index c52bfe5a..4e3ac302 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml @@ -21,7 +21,7 @@ reRoutes: url: http://eshop-st-administration ingress: host: # eshop-st-gateway-web - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/gateway-web diff --git a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml index e843265f..e8030dea 100644 --- a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml @@ -8,7 +8,7 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt + cert-manager.io/cluster-issuer: selfsigned-issuer spec: tls: - hosts: diff --git a/etc/k8s/eshoponabp/charts/identity/values.yaml b/etc/k8s/eshoponabp/charts/identity/values.yaml index f7f0faa7..842fe3ee 100644 --- a/etc/k8s/eshoponabp/charts/identity/values.yaml +++ b/etc/k8s/eshoponabp/charts/identity/values.yaml @@ -32,7 +32,7 @@ identityServerClients: ingress: host: eshop-st-identity - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/service-identity diff --git a/etc/k8s/eshoponabp/charts/ordering/values.yaml b/etc/k8s/eshoponabp/charts/ordering/values.yaml index 70949147..895834ba 100644 --- a/etc/k8s/eshoponabp/charts/ordering/values.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-ordering - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/service-ordering diff --git a/etc/k8s/eshoponabp/charts/payment/values.yaml b/etc/k8s/eshoponabp/charts/payment/values.yaml index a4f316a0..3d5a55d7 100644 --- a/etc/k8s/eshoponabp/charts/payment/values.yaml +++ b/etc/k8s/eshoponabp/charts/payment/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-payment - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/service-payment diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml index 0faddf89..3519d65c 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml @@ -22,23 +22,23 @@ spec: containerPort: 443 env: - name: App__SelfUrl - value: {{ .Values.config.selfUrl}} + value: "{{ .Values.config.selfUrl }}" - name: RemoteServices__Default__BaseUrl - value: {{ .Values.config.gatewayUrl}} + value: "{{ .Values.config.gatewayUrl }}" - name: "AuthServer__Authority" - value: {{ .Values.config.authServer.authority }} + value: "{{ .Values.config.authServer.authority }}" - name: "AuthServer__RequireHttpsMetadata" value: "{{ .Values.config.authServer.requireHttpsMetadata }}" - name: "DOTNET_ENVIRONMENT" - value: {{ .Values.config.dotnetEnv }} + value: "{{ .Values.config.dotnetEnv }}" - name: "Redis__Configuration" - value: {{ .Values.config.redisHost }} + value: "{{ .Values.config.redisHost }}" - name: "StringEncryption__DefaultPassPhrase" - value: {{ .Values.config.stringEncryptionDefaultPassPhrase }} + value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}" - name: "RabbitMQ__Connections__Default__HostName" - value: {{ .Values.config.rabbitmqHost }} + value: "{{ .Values.config.rabbitmqHost }}" - name: "ElasticSearch__Url" - value: {{ .Values.config.elasticsearchHost }} + value: "{{ .Values.config.elasticsearchHost }}" {{- if .Values.env }} {{ toYaml .Values.env | indent 8 }} {{- end }} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/public-web/values.yaml b/etc/k8s/eshoponabp/charts/public-web/values.yaml index 72542a20..ba4f9861 100644 --- a/etc/k8s/eshoponabp/charts/public-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/values.yaml @@ -1,6 +1,6 @@ config: selfUrl: https://eshop-st-public-web - gatewayUrl: "http://eshop-st-gateway-web-public/" + gatewayUrl: https://eshop-st-gateway-web-public authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -11,8 +11,8 @@ config: stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: - host: # eshop-st-public-web - tlsSecret: eshop-demo-tls + host: eshop-st-public-web + tlsSecret: eshop-staging-tls image: repository: eshoponabp/app-publicweb diff --git a/etc/k8s/eshoponabp/charts/web/values.yaml b/etc/k8s/eshoponabp/charts/web/values.yaml index 83e4b444..792ef099 100644 --- a/etc/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/k8s/eshoponabp/charts/web/values.yaml @@ -7,7 +7,7 @@ config: ingress: host: eshop-st-web - tlsSecret: eshop-demo-tls + tlsSecret: eshop-staging-tls image: repository: eshoponabp/app-web diff --git a/etc/k8s/eshoponabp/values.yaml b/etc/k8s/eshoponabp/values.yaml index b3c350d8..81bc1014 100644 --- a/etc/k8s/eshoponabp/values.yaml +++ b/etc/k8s/eshoponabp/values.yaml @@ -13,6 +13,7 @@ authserver: elasticsearchHost: es-st-elasticsearch ingress: host: eshop-st-authserver + tlsSecret: eshop-staging-tls image: repository: "eshoponabp/app-authserver" tag: latest @@ -32,7 +33,7 @@ web: public-web: config: selfUrl: https://eshop-st-public-web - gatewayUrl: "http://eshop-st-gateway-web-public/" + gatewayUrl: http://eshop-st-gateway-web-public authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -123,7 +124,6 @@ gateway-web: redisHost: es-st-redis rabbitmqHost: es-st-rabbitmq elasticsearchHost: es-st-elasticsearch - stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: host: eshop-st-gateway-web image: @@ -141,7 +141,6 @@ gateway-web: gateway-web-public: config: selfUrl: https://eshop-st-gateway-web-public - globalConfigurationBaseUrl: http://eshop-st-gateway-public-web authServer: authority: http://eshop-st-authserver requireHttpsMetadata: "false" @@ -151,7 +150,6 @@ gateway-web-public: redisHost: es-st-redis rabbitmqHost: es-st-rabbitmq elasticsearchHost: es-st-elasticsearch - stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 ingress: host: eshop-st-gateway-web-public image: diff --git a/etc/k8s/tls-cert/eshop-demo-tls.conf b/etc/k8s/tls-cert/eshop-demo-tls.conf new file mode 100644 index 00000000..68e574ef --- /dev/null +++ b/etc/k8s/tls-cert/eshop-demo-tls.conf @@ -0,0 +1,38 @@ +[req] +default_bits = 2048 +default_keyfile = eshop-st.key +distinguished_name = req_distinguished_name +req_extensions = req_ext +x509_extensions = v3_ca + +[req_distinguished_name] +commonName = Common Name (e.g. server FQDN or YOUR name) +commonName_default = eshoponabp +commonName_max = 64 + +[req_ext] +subjectAltName = @alt_names + +[v3_ca] +subjectAltName = @alt_names +basicConstraints = critical, CA:false +keyUsage = keyCertSign, cRLSign, digitalSignature,keyEncipherment + +[alt_names] +DNS.1 = eshop-st-web +DNS.2 = eshop-st-public-web +DNS.3 = eshop-st-authserver +DNS.4 = eshop-st-identity +DNS.5 = eshop-st-administration +DNS.6 = eshop-st-gateway-web +DNS.7 = eshop-st-gateway-web-public +DNS.8 = eshop-st-basket +DNS.9 = eshop-st-catalog +DNS.10 = eshop-st-ordering +DNS.11 = eshop-st-payment + +# Generate certificate from config +# Use the command: +# 'openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-st-cert.key -out eshop-st-cert.pem -config eshop-demo-tls.conf' +# Verify that you have eshop-st-cert.crt and eshop-st-cert.key files under k8s/tls-cert folder +# Run comand : 'kubectl create secret tls eshop-demo-tls --cert=eshop-st-cert.pem --key=eshop-st-cert.key --namespace=eshop' diff --git a/etc/k8s/tls-cert/eshop-st-cert.key b/etc/k8s/tls-cert/eshop-st-cert.key new file mode 100644 index 00000000..fffab06a --- /dev/null +++ b/etc/k8s/tls-cert/eshop-st-cert.key @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQDSgXYuFacjDRuc +yj6oqIV1KlBinfbqnH9xEFOQXN6vFI9v5TzOTXstjCVQKhPWDCw3WSw7ydlAodFa +djeXEjapDGQmAVJk5nmPLv+UCOrZHd6ut8QEMb1cAGtOR71d8CVjWuZx6igGTPTQ +m2efRip0B0mog4j5vc+q8tr0qu+h13TAkivYGPQTvT46p/GypH5xFjAVw9P6IIYP +fr+nm2R/fUV3FEmaUBJmNjjoDJzrtGxe8zWD7vRxIYoNeffzRTMCT622Y8j6TEp2 +rlVPjh9Dp7+Wrj6FxopKBt6j3F5S1NKkEgEID8cL1Aufu0Xk/dWPsSAstVPgA/gf +GIW+7ALHAgMBAAECggEBAL2lmvYL1ecTMRRBdM/3+zxCYedmzwQw9/PBtLczo/9x +84Por65hSZ8QSrF9Jx/JGbDHqr02rX64CmeIZ6633vzPyA4hVLzIky13NxSEMCho +66zWrEbnFOUlD4eXxDg0WUq4ozJvtZ1viYPC7kklKqwbwLWLw0TUR5qIbtDMi1Vu +pyfm2YUtjqx2JPjD2i5juZx3XbgiqncpyRDroY80IqOZ/Kp83eMdst9wyfJaAy0B +kxZjvU1U2exD/l9RxKKreES2Vrbn+PvF3ttTgz/hE1ScBBfMB9kn+37esGZVByjb +ER0GFgt0jOx2ok+n2+zm2Z68IjoYDvsNo586tHoXxrECgYEA75UD5Nt9joCpCWVd +zXBQ8OUJwRU/N74RjBBS/NTT2sZ+q7xYxDx3xPwhyHXI+wwaHClGUE0yx5mrqqON +p3ELpanYdLWcdA6f/bFuuSNOAi7XSc1wCbNkTh5yxIyqWMvEYXqAj1/5T1VJ6+xU +pyKUe1588WKpSURrtGRxu0rKizkCgYEA4O5cJQmBeTlx++iVtONZv7HB371rYt45 +0nkBKfBJOjsVd2sB5f6ry5PaRcJyXamF7QYGgm4xo+KvrfHrf+JjebiJR46tsK0n +y130XjZVi28HPGBUG610zXOH3FgUQiSVbRulG0wzTtFHzdbVHJuTmA65+BZnayhM +WICqyiw0/f8CgYEAuXLmbbr8iFbNAYnmPwSGksEneL7ijVphqMJmCnEPgBQPrw1+ +xH9t0hu8ZrfNl435k/zbAYOQH/Kyb8Zj+s1FT7mV5FlDvo4nh69VXpeWZZgua2FL +LScgKFvnSH79yPgJjc7OPqzyhVcmfikUKb9Zodk064AMO7trh1oMswYkm/kCgYA/ +w/MFYOt+hUWGB4qhTC5+RJNUrWtLDPrRaxJkZEUuJ9/PCdvw6sCjJtgjHJu1Z8Ca +0DF6OmkCL9pj8ogzqedPc3wfeBhPVNdKNOl45+habfBcMmbFrefF8rGaSrH7ikl+ +M+8bjP+ioXu8o+GoiYZO/iXEaf2JiFQUZu2EAQJI2wKBgQCLUuZyV/fx2/90md4W +6GwyMYrA3Z3pVm3WKdphSX8euTTNjOjtwXwZ0iqfGsm0okHC0+DcI9PAhPh99fCB +7miZcUvQmqhmL7rcrOTfPRLVZ9flEVqeq6RCW4ICA2G7+0+eFz87FIl9EHfN9IMU +2mLb5Ph0OuI7W75OBR23qqVk5g== +-----END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/eshop-st-cert.pem b/etc/k8s/tls-cert/eshop-st-cert.pem index 45649b42..f962d807 100644 --- a/etc/k8s/tls-cert/eshop-st-cert.pem +++ b/etc/k8s/tls-cert/eshop-st-cert.pem @@ -1,31 +1,23 @@ -----BEGIN CERTIFICATE----- -MIIFQzCCA6ugAwIBAgIRANj5oNi+QQIoyV51y/ZIJlYwDQYJKoZIhvcNAQELBQAw -gZ8xHjAcBgNVBAoTFW1rY2VydCBkZXZlbG9wbWVudCBDQTE6MDgGA1UECwwxZ3Nl -bmd1bkBHb2toYW5zLU1hY0Jvb2stUHJvLmxvY2FsIChHb2toYW4gU2VuZ3VuKTFB -MD8GA1UEAww4bWtjZXJ0IGdzZW5ndW5AR29raGFucy1NYWNCb29rLVByby5sb2Nh -bCAoR29raGFuIFNlbmd1bikwHhcNMTkwNjAxMDAwMDAwWhcNMzExMTA0MDgyNjUw -WjBlMScwJQYDVQQKEx5ta2NlcnQgZGV2ZWxvcG1lbnQgY2VydGlmaWNhdGUxOjA4 -BgNVBAsMMWdzZW5ndW5AR29raGFucy1NYWNCb29rLVByby5sb2NhbCAoR29raGFu -IFNlbmd1bikwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKu7X3b2Cg -dpBnz90KboUnpWRcCK96oq97pAEbR9sirN3+3jT0JRBY2TYKLDPW8i50QJFbdYE7 -zky58c+RWPrxVDoeqRC8E1+TLsuW+TdMmOL746k36X1VtKy3rqUG9IS6MXjH/MX8 -H1kgldHvE9mFEpyp3q/8cUPHSBUE+M0CA05wlDm8qgkGXcp43qrNElWg5Y2WWWIp -WUm8r5obktSAxhA+ZxFX4cJHFmxKymMqSRStDpTFCIW9C3kx5ierPNQS6g5sSMtW -OuPuh0Uhc0Q0lJBoA7Mj1CGvtO5nld0+6kAK1GMB7Vbigoqd00eqKMYaA3Aa5QZm -bf84wZjofJx1AgMBAAGjggExMIIBLTAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAww -CgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBR6TnYaWT+NPghb -dQnZ+MAbx9UB2DCB1gYDVR0RBIHOMIHLgghlc2hvcC1zdIIXZXNob3Atc3QtYWRt -aW5pc3RyYXRpb26CE2VzaG9wLXN0LWF1dGhzZXJ2ZXKCGWVzaG9wLXN0LWdhdGV3 -YXktaW50ZXJuYWyCG2VzaG9wLXN0LWdhdGV3YXktcHVibGljLXdlYoIUZXNob3At -c3QtZ2F0ZXdheS13ZWKCEWVzaG9wLXN0LWlkZW50aXR5ghNlc2hvcC1zdC1wdWJs -aWMtd2Vigg1lc2hvcC1zdC1zYWFzggxlc2hvcC1zdC13ZWIwDQYJKoZIhvcNAQEL -BQADggGBADjQroM3gD7g56S8bxlUbt1sJYfvo0VCIDPH9aHE3WwhGCOn18SRDOpM -mNw4c0HO+P1+rlCfn2pvN2oQ6v731fQZPpGcE0ljeVrixqfyVvoggGMbOwegvWPh -dPK/cxLi9wYfQtFw5vy8YxsinowSRCQ3KJGxI4fsyjEQu939WvYSPDdEUPx952LR -2pG8yRSso7dixDW4rDCoI/QKM/ImnqsNtZSpGa93HLgjkJr/PsOVMogt8dOsDOkC -vHq9F6TJKTDb7WizMJcE0qfisJgtTC2isvYA3u7kiyfxW26kd1h7s4m3njn+0Sks -0xGcXiYPZm8y/lVrxcF3/QlgOfWfRmls3D17yX28QwuwvNkUv2aSP/WGOMWEtgPD -9WYPk1OhOGFxT3IKu8iw6ITTCKXpcBeQ/QiEuFjo/khDGE4NMSkrp16nVebkAWal -/eufFWZJTzO7kgCmApS2SAhRdsM+JEsioHF/gM2chzV+eP4CCKv3pw5z07eemhx2 -HnEbhDFHEA== +MIIDxjCCAq6gAwIBAgIUavYi4mtz8TCt6EwG/MDNsnykGPMwDQYJKoZIhvcNAQEL +BQAwFTETMBEGA1UEAwwKZXNob3BvbmFicDAeFw0yMjA0MDgxOTAwMDFaFw0yMzA0 +MDgxOTAwMDFaMBUxEzARBgNVBAMMCmVzaG9wb25hYnAwggEiMA0GCSqGSIb3DQEB +AQUAA4IBDwAwggEKAoIBAQDSgXYuFacjDRucyj6oqIV1KlBinfbqnH9xEFOQXN6v +FI9v5TzOTXstjCVQKhPWDCw3WSw7ydlAodFadjeXEjapDGQmAVJk5nmPLv+UCOrZ +Hd6ut8QEMb1cAGtOR71d8CVjWuZx6igGTPTQm2efRip0B0mog4j5vc+q8tr0qu+h +13TAkivYGPQTvT46p/GypH5xFjAVw9P6IIYPfr+nm2R/fUV3FEmaUBJmNjjoDJzr +tGxe8zWD7vRxIYoNeffzRTMCT622Y8j6TEp2rlVPjh9Dp7+Wrj6FxopKBt6j3F5S +1NKkEgEID8cL1Aufu0Xk/dWPsSAstVPgA/gfGIW+7ALHAgMBAAGjggEMMIIBCDCB +6gYDVR0RBIHiMIHfggxlc2hvcC1zdC13ZWKCE2VzaG9wLXN0LXB1YmxpYy13ZWKC +E2VzaG9wLXN0LWF1dGhzZXJ2ZXKCEWVzaG9wLXN0LWlkZW50aXR5ghdlc2hvcC1z +dC1hZG1pbmlzdHJhdGlvboIUZXNob3Atc3QtZ2F0ZXdheS13ZWKCG2VzaG9wLXN0 +LWdhdGV3YXktd2ViLXB1YmxpY4IPZXNob3Atc3QtYmFza2V0ghBlc2hvcC1zdC1j +YXRhbG9nghFlc2hvcC1zdC1vcmRlcmluZ4IQZXNob3Atc3QtcGF5bWVudDAMBgNV +HRMBAf8EAjAAMAsGA1UdDwQEAwIBpjANBgkqhkiG9w0BAQsFAAOCAQEAhJK7TgZw +IVqVbyYHw3M3fH5/tvioZNq0PbYOeWBX/A4ZolE1o5n5wzwk1TcOk7Kg8KdvZPM8 +VZgfx4B/MYaHWmliPx036oB4MJ9zh1D+zPr2kNqUKzY07H1JJDS9BzuBiSnnv7dJ +nuiJnV5F2Uy2cWltCgZ4xZ7xwnlofxIV4EnB88r+Gqz+LNtm1BFF4p5CzSQHcTrc +04H7k7gvITRYq086yuButbYT43uBBVJDEmTWUKMYWgh5K1cbyOUkYmaMCYaUnpNq +tgoZCNrUq3dpv/KsDsxh1bf2W0LsNiu2zExjetqDjoDC4cnCXYOsF7dW0HcnqFCN +PcxxXhW+kcd6+A== -----END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-st-key.pem b/etc/k8s/tls-cert/eshop-st-key.pem deleted file mode 100644 index 146780f7..00000000 --- a/etc/k8s/tls-cert/eshop-st-key.pem +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDKu7X3b2CgdpBn -z90KboUnpWRcCK96oq97pAEbR9sirN3+3jT0JRBY2TYKLDPW8i50QJFbdYE7zky5 -8c+RWPrxVDoeqRC8E1+TLsuW+TdMmOL746k36X1VtKy3rqUG9IS6MXjH/MX8H1kg -ldHvE9mFEpyp3q/8cUPHSBUE+M0CA05wlDm8qgkGXcp43qrNElWg5Y2WWWIpWUm8 -r5obktSAxhA+ZxFX4cJHFmxKymMqSRStDpTFCIW9C3kx5ierPNQS6g5sSMtWOuPu -h0Uhc0Q0lJBoA7Mj1CGvtO5nld0+6kAK1GMB7Vbigoqd00eqKMYaA3Aa5QZmbf84 -wZjofJx1AgMBAAECggEBALvJLd9ZInbf/Bi8uLFt+BbmI1UAkpKU2Nk86+16HKg8 -2ZC4APLY1hCGeoDnusjyIUd7e2jtKdzc1cMzEiI++orJiuBVl/OuOkxZ/ykEBU4F -G9NYaKkqtPbLWWT291O+8KaLJqaQJE/KNcNyIzhB+a1CtSy/4eGChNa1lQq67yJZ -iTFPNSHT1RTzjv2BAuUASq1gK+bX4F65otVYQBMg3JGsfkAdhWPbzEX0XLVpgbh/ -jtyAHSsiWIkyVjXvA3Zjp+3Gmf3dbd/86Uwd4XowPfcSOP4iyd76FS4iTlthsF5D -M0psBOgotVl5RHv2ljOy7fUzrudnSQ0HepgdHed4Em0CgYEA7q+j7cbcb43ZW5Rx -p2pMuuuEeFY+L2Ns8N4t26OoURQCzyACR5H4KgFtrrdqTwQPs7L8SWAjU8SoP2jX -j+4+TJnK/Grt0YQ2pLpEM8j7kjGWfskHDfQhrL3o4VhdCm/1URWYSn7nzdNnX1Fk -ZlKjUJWBXGTvthCUVY9Jk30hU4sCgYEA2XBupvyIpmjoNdsEdwxxSebLyIYu2FA/ -sjI5gdzXIOo9DsFfn9HTNbXyEsiQm9StNXS585jRhyht9OF7SYajrJ/E3O086tf4 -2MmDbUdFdvMdPdGxxTU2mXa9Vd6JASnFG+fSsRhABk57iNzcUE4+PNW1ztLmRyLx -diW9cXjXz/8CgYBxGF43U0utu+uqvgqgRfj3dJL/JfYvJBBBjTTzZndhe3bdR5Bs -8xhAZw7eg1/m8six3/Q0nE4A6iTCbt38/+kbCKAqvEvVQ61UnkGku+2f1sk1Z/Fk -xjGSlSWcaO8k++mkMvRHEByr5SiM/Jby+OMTUtPJwLXocbCnXc6CCP9agwKBgEe7 -I4XLAXmEWjaKDisH28e5b7izK3kI4Dp0/yusIvwkyge4G0ep/LdXUoiHyczemFVu -MHoAC/8+gyepyvYyiIRGILeRO+ttXBaIQ+ck//GBuj/OkYqxR1XRKhzN0PylPvU5 -wPPTQCvUcERyN+v2I+oFxnh4cqc9C9MiGCD68JcZAoGBAIi1RxcWKZUCjSETT1PY -V7j5FIyMzBdUo0RN44eUdeu0CWAOnMG2s26z6fXl7EZp+Em5ee7dYEmSP49X69n9 -T9ueN1LRJaqko45Eo3uPl6rolz5vXcTr2Tooc3yqE3XbRxe2jOeczq06nj06kjuf -hPPdSqjjOwWPy63DWboSkh+0 ------END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/eshop-test-tls.crt b/etc/k8s/tls-cert/eshop-test-tls.crt new file mode 100644 index 00000000..c3a18d04 --- /dev/null +++ b/etc/k8s/tls-cert/eshop-test-tls.crt @@ -0,0 +1,23 @@ +-----BEGIN CERTIFICATE----- +MIIDxjCCAq6gAwIBAgIUWAAiaf6jGeQBXdYnOFUKw+cQIlMwDQYJKoZIhvcNAQEL +BQAwFTETMBEGA1UEAwwKZXNob3BvbmFicDAeFw0yMjA0MDgyMjM4NDVaFw0yMzA0 +MDgyMjM4NDVaMBUxEzARBgNVBAMMCmVzaG9wb25hYnAwggEiMA0GCSqGSIb3DQEB +AQUAA4IBDwAwggEKAoIBAQDaQiJirGIVlbr00M8e1qTWLeIgsMUhLGa8fa/cEMJ7 +uInNm6hkCv1UrxGDKcxBBXs/kt+VYfnjtp+2IBlgv6wbHWftQYEwXxbtvXNIBWIn +GEee9S2uREDm0OHJF/xLEHPvFE15mFeo3bfJ3GIkuXuKu3RzQBre4q2y+1RfHnav +YKF/QIg3oWysnmt5G2wBS7bZvHkjvX7N31g80JU3yYuPkiCJi+PHiQbeyn4Obaf+ +TksoOqrwIO6bYE+cR5v2eLn0nLg/ZYvKSAbmmEiNIja3DRidxM9fYWPQgqVsAGs5 +CqdqH3PX9JNSl2FOQQqPSQ9IUwa5lJogNiSWZVacijh1AgMBAAGjggEMMIIBCDCB +6gYDVR0RBIHiMIHfggxlc2hvcC1zdC13ZWKCE2VzaG9wLXN0LXB1YmxpYy13ZWKC +E2VzaG9wLXN0LWF1dGhzZXJ2ZXKCEWVzaG9wLXN0LWlkZW50aXR5ghdlc2hvcC1z +dC1hZG1pbmlzdHJhdGlvboIUZXNob3Atc3QtZ2F0ZXdheS13ZWKCG2VzaG9wLXN0 +LWdhdGV3YXktd2ViLXB1YmxpY4IPZXNob3Atc3QtYmFza2V0ghBlc2hvcC1zdC1j +YXRhbG9nghFlc2hvcC1zdC1vcmRlcmluZ4IQZXNob3Atc3QtcGF5bWVudDAMBgNV +HRMBAf8EAjAAMAsGA1UdDwQEAwIBpjANBgkqhkiG9w0BAQsFAAOCAQEA0lsXpx1C +ItDk2gwKnUiof90y9iYBIZZ+RyxZlJHXYOTrfzOtg1U5zxZtaTBefPJhjI/hibyu +a2zCUFpc0CBLG8EVzLOv8VJDxiRf93bLP9Eoy40l8MVS8Lt5HVRs8xUiuGvxspwH +7aXAeP0HlykDjt3njwawPRuijFrk2GzQSCkPVh84e7RKTq4TYb1MpRjZw2Q92/NM +v0Zboi7wY0RqakyUHdWpgnWP/5ch8f8mInXkOJiQo0h5fbtrB8UdBGC7Qu1uKgsb +UloHs0w5p0q1AqmtYTJo2FmMP/touls/XhpJ5V0B3X2qh5JISqZiKifkPoJaIKCt +6ivVqCafin3yEQ== +-----END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-test-tls.key b/etc/k8s/tls-cert/eshop-test-tls.key new file mode 100644 index 00000000..3958be9a --- /dev/null +++ b/etc/k8s/tls-cert/eshop-test-tls.key @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDaQiJirGIVlbr0 +0M8e1qTWLeIgsMUhLGa8fa/cEMJ7uInNm6hkCv1UrxGDKcxBBXs/kt+VYfnjtp+2 +IBlgv6wbHWftQYEwXxbtvXNIBWInGEee9S2uREDm0OHJF/xLEHPvFE15mFeo3bfJ +3GIkuXuKu3RzQBre4q2y+1RfHnavYKF/QIg3oWysnmt5G2wBS7bZvHkjvX7N31g8 +0JU3yYuPkiCJi+PHiQbeyn4Obaf+TksoOqrwIO6bYE+cR5v2eLn0nLg/ZYvKSAbm +mEiNIja3DRidxM9fYWPQgqVsAGs5CqdqH3PX9JNSl2FOQQqPSQ9IUwa5lJogNiSW +ZVacijh1AgMBAAECggEAA3CxbA69iQuQI9W6vgiyFnIos001/jzd7bCpefWFqz+Q +ZH5EnDcUISaVRxT8lDXK6IifH5Koxq8VO2CsJbs/sjm3bqTurV2CVgL7czIqhuU6 +E8ZXjvyibUDzniDTqDc9LJKMWhNNpmrAP91KarvFt70Wq85h3guCo2SUwt8PDdqX +nHw0QzBXfkvg9/b90XCXrR/LnIyQ271wONJ1t1updDeo/EZzj/77yFWrvO7zw734 +FqDpfY+VeD9YNQszU40J/CMZa2qKqBXNp68JL2xOSFeHqNKvwKWvP145uGjURblz +Z12NdoKE3WbzMyv9zO1IdocaL1bFtM+7t3B9KFIbQQKBgQDz9ip8+AOTHp3RywUa +PvVGSk3U8+PBX3tTXgmoeRbMJ+xffE8uHMDu710izEvbkxQhAgar5dJH8NiragvW +LVZXCnstJfGI1V3oXnB2Y4BEB1ZTVSV8fuYutm6UhudWebTMg9EndvixK088pjya +GX0nx4MXOWgBo7vgLNXDNQa40QKBgQDlB0XvpJQEBZurz04iEgjXuXHttGQr4kw8 +0DwC2KA1JnEqZFy4CNGQyyIAKG9xDGCeejbwzBXkamPXpZ4Q7/Opv3wbsxzCnZE3 +MX6XUKqx2CfG7lRWwmLybLvRynHhT6LlWouNil/pHKvdv8LF+pu68S7sK24CaMpu +QF8aREHuZQKBgQDBnWBjBcJwhB/kXCeUiNrICjhzBYx/73NE2qD3oAJDzHt/3HxK +sG8+MaHM+C5L+RJEkAMTcbXNeou6ntL+C8U2Fw9i6XYjjpKU1D6U9qrZUqlkQXMa +tuufrxFbtyTqMHUYypS3qWf9081y6Mu30PrPEzwqtlig1H1KkMqlvfOzwQKBgFLS +soPbLHvX21fifAruIqyAr6aama8VAyTq2QjedfFCmaIO8UjMR5zpGL6d4M8s/rPQ +1pV1+GTF5J1TkznkzGUSjjsmJrxqZt1i1Li7vz7ZQGk8PtuxKD8q+zD+2Pf16J6w +g88Hv295ot1qP3GBE1gjaCiX/Ax7ANmmBb5l+MHRAoGAY6MXc6EUdgcLq0p/FbNk +OloFD/iUGNsJfSMxMg3vpWP9PhTSToiVDJrsviFWl2+z4CNicptsqfji237Uu4TP +d8Br0flNjfgyZ6BeRl1Ovgls6hDVgvjl6VWghZw9TfA0pc1ozb5FnUQkTG3+ceBY +KlHxDmv2VwadB8QbmuHqKjc= +-----END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/ingress-tls.yaml b/etc/k8s/tls-cert/ingress-tls.yaml new file mode 100644 index 00000000..f888087d --- /dev/null +++ b/etc/k8s/tls-cert/ingress-tls.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: kuard + annotations: + kubernetes.io/ingress.class: "nginx" + cert-manager.io/issuer: "letsencrypt-staging" + +spec: + tls: + - hosts: + - example.example.com + secretName: quickstart-example-tls + rules: + - host: example.example.com + http: + paths: + - path: / + pathType: Prefix + backend: + service: + name: kuard + port: + number: 80 diff --git a/etc/k8s/tls-cert/notes.md b/etc/k8s/tls-cert/notes.md index d10840d4..9b9fae8e 100644 --- a/etc/k8s/tls-cert/notes.md +++ b/etc/k8s/tls-cert/notes.md @@ -7,3 +7,43 @@ kubectl create secret tls eshop-demo-tls \ --cert=eshop-st-cert.pem \ --key=eshop-st-key.pem ``` + +# Install cert-manager + +`kubectl create namespace eshop` + +Next, use the **`kubectl apply`** command and the **`yaml`** file available online to install the add-on: + +```powershell +kubectl apply --validate=false -f https://github.com/jetstack/cert-manager/releases/download/v1.7.0/cert-manager.yaml +``` + +Now deploy the issuer: + +```powershell +kubectl apply -f .\selfsigned\issuer.yaml +``` + +Now deploy the certificate: + +```powershell +kubectl apply -f .\selfsigned\certificate.yaml +``` + +Check the certificate: + +```powershell +kubectl describe certificate -n=eshop +``` + +Check the secrets: + +```powershell +kubectl get secrets -n=eshop +``` + +You should be seeing `eshop-staging-tls` + +To view information about the Secret, use the **`get secret`** command: + +`kubectl get secret eshop-staging-tls -n cert-manager` diff --git a/etc/k8s/tls-cert/selfsigned/certificate.yaml b/etc/k8s/tls-cert/selfsigned/certificate.yaml new file mode 100644 index 00000000..ec7b9ab2 --- /dev/null +++ b/etc/k8s/tls-cert/selfsigned/certificate.yaml @@ -0,0 +1,21 @@ +apiVersion: cert-manager.io/v1 +kind: Certificate +metadata: + name: selfsigned-cert + namespace: eshop +spec: + dnsNames: + - "*.eshop-st-web" + - "*.eshop-st-public-web" + - "*.eshop-st-authserver" + - "*.eshop-st-identity" + - "*.eshop-st-administration" + - "*.eshop-st-basket" + - "*.eshop-st-catalog" + - "*.eshop-st-ordering" + - "*.eshop-st-payment" + - "*.eshop-st-gateway-web" + - "*.eshop-st-gateway-web-public" + secretName: eshop-single-tls + issuerRef: + name: eshop-issuer \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml b/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml new file mode 100644 index 00000000..c69e8a11 --- /dev/null +++ b/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml @@ -0,0 +1,6 @@ +apiVersion: cert-manager.io/v1 +kind: ClusterIssuer +metadata: + name: selfsigned-issuer +spec: + selfSigned: {} \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/issuer.yaml b/etc/k8s/tls-cert/selfsigned/issuer.yaml new file mode 100644 index 00000000..134fa38c --- /dev/null +++ b/etc/k8s/tls-cert/selfsigned/issuer.yaml @@ -0,0 +1,7 @@ +apiVersion: cert-manager.io/v1 +kind: Issuer +metadata: + name: eshop-issuer + # namespace: eshop +spec: + selfSigned: {} \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/readme.md b/etc/k8s/tls-cert/selfsigned/readme.md new file mode 100644 index 00000000..198b3bc2 --- /dev/null +++ b/etc/k8s/tls-cert/selfsigned/readme.md @@ -0,0 +1,8 @@ +`helm install cert-manager jetstack/cert-manager --namespace cert-manager --create-namespace --version v1.4.0 --set installCRDs=true` +`kubectl create ns eshop` +`kubectl apply -f .\selfsigned\issuer.yaml` + + +```powershell +kubectl create secret tls eshop-demo-tls --cert=eshop-st-cert.pem --key=eshop-st-cert.key -n ingress-nginx +``` \ No newline at end of file From b8707443042562d57f4458c5e2f13634f2e370d2 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Sat, 9 Apr 2022 23:58:31 +0300 Subject: [PATCH 13/17] Delete eshop-dk.crt --- etc/docker/certs/eshop-dk.crt | 19 ------------------- 1 file changed, 19 deletions(-) delete mode 100644 etc/docker/certs/eshop-dk.crt diff --git a/etc/docker/certs/eshop-dk.crt b/etc/docker/certs/eshop-dk.crt deleted file mode 100644 index c4fd60fa..00000000 --- a/etc/docker/certs/eshop-dk.crt +++ /dev/null @@ -1,19 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDHzCCAgegAwIBAgIUX5WvovRMAkZTaoZGsFNyyjLU7F8wDQYJKoZIhvcNAQEL -BQAwADAeFw0yMjA0MDkxNjU3NDlaFw0yMzA0MDkxNjU3NDlaMAAwggEiMA0GCSqG -SIb3DQEBAQUAA4IBDwAwggEKAoIBAQD0KAzKq9bop31wIPo06eq4AYhdB0zZA+Eh -4mEOvCZ7MtAWUjkP1LudFF4IBlpIaAG0g6o5IhFRHQOIRfVXYA2NSGK8QpVSfmtk -it+Wc9bVvVJ9kqPhVakQIqhkOH4gPJ5MK/fhB6qSiN0TsbXZSHri6Q47Jd46X2DX -LK8c5/KRyrsFY/IVoSHC5kxyxLSzWK7T7JzqEXNtaVCOVf6difuCzPwiqqCk7WtC -LZcCj7n9m5UjpyOLo4iF8wIUk+IpaGKBxYBJ0MuMa8eG3Oz73JZBTaXAAJszNTgG -TVNYuUmi8z4s+U0p+sPW37hpv83atpPaV2rkyaYmM8DNgLyrPj3zAgMBAAGjgZAw -gY0wHQYDVR0OBBYEFGfpXUNdCmwNsLrHLLvxeQ0qQ3b7MB8GA1UdIwQYMBaAFGfp -XUNdCmwNsLrHLLvxeQ0qQ3b7MA8GA1UdEwEB/wQFMAMBAf8wOgYDVR0RBDMwMYIJ -bG9jYWxob3N0ghRob3N0LmRvY2tlci5pbnRlcm5hbIIOYXBwLWF1dGhzZXJ2ZXIw -DQYJKoZIhvcNAQELBQADggEBANY9ID0BUoIAqB/yfQwaXohG8lx4qwGl3BDBzr/L -N0B47WkemFqYNYsAzwdami8hz7D9JIHXeTH+kcpiNE6jrNW31mEzzcgFkzpZxUkb -39mBB5sDNyFlFdObW8G5s0joL0dm2CJK+ujN12EJucOoeOKZmkD49bxc027rj9vz -rEDk3b6L6wkWPf7bBjtHPLfew0R0j1shdZBQFCNa7HRU+JFSXBqHXQKGdxi0uGbb -ENCmZaYHYA4ZO+deqHYr+HWO1tZPS7Wicm+NMEBKqiPB0hQWqUXnBbe6sWGW5TmP -ihgNWE46+y6LMjmxlGUdJNOHAWJVDijWZMsvwnY+doW89MA= ------END CERTIFICATE----- From 35595db7b9338b5807e65c7550def2ec0fbaa4ac Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Sat, 9 Apr 2022 23:58:41 +0300 Subject: [PATCH 14/17] Delete eshop-dk.key --- etc/docker/certs/eshop-dk.key | 28 ---------------------------- 1 file changed, 28 deletions(-) delete mode 100644 etc/docker/certs/eshop-dk.key diff --git a/etc/docker/certs/eshop-dk.key b/etc/docker/certs/eshop-dk.key deleted file mode 100644 index b43ecb99..00000000 --- a/etc/docker/certs/eshop-dk.key +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQD0KAzKq9bop31w -IPo06eq4AYhdB0zZA+Eh4mEOvCZ7MtAWUjkP1LudFF4IBlpIaAG0g6o5IhFRHQOI -RfVXYA2NSGK8QpVSfmtkit+Wc9bVvVJ9kqPhVakQIqhkOH4gPJ5MK/fhB6qSiN0T -sbXZSHri6Q47Jd46X2DXLK8c5/KRyrsFY/IVoSHC5kxyxLSzWK7T7JzqEXNtaVCO -Vf6difuCzPwiqqCk7WtCLZcCj7n9m5UjpyOLo4iF8wIUk+IpaGKBxYBJ0MuMa8eG -3Oz73JZBTaXAAJszNTgGTVNYuUmi8z4s+U0p+sPW37hpv83atpPaV2rkyaYmM8DN -gLyrPj3zAgMBAAECggEAZG5tBJk257CtyofmJAnsgRAwVYQBOmt8GgISxorikV7P -db8QtdBd9DlCjK6ASLRvrx9Rz/qRgPocT9vnFa/vIySZaLNC1RInfs4ZNrwjrPwZ -iInfW3tu9bIr7j3Gs9/7hX24kxoiMfCWb9lz4hMMaXZQYkgrZ3uATEKXLZ7DivA5 -2yku9gQdWZlwXSQqWgx2kwZjyRAkUC88HtPfxCkF0NHJur7CgM3UxeFockwfJ+/i -EUFoklMSolIlqivJ1765J17hW7vebBnP7b5SZJFAGjxxhLJ7wQ+FlZiwNEoCLDZx -B7S6ARzzNAdMOsls1DwQWrX5Nupl3XgQRBakMEJxIQKBgQD7WkZV2XDkyEnBYTk2 -e2DYNlFNsJeHhwml0jTBASMGosrwRqFf4DpozFap6UFPHTyhYcGJfEfojG8zrWN+ -MuYT0EzMHtPBPnDSCtKeeZ2wq+ON3gps3lsdIJLgCo9IGbak+90AigzVe5JPykuh -qu6XGs1f/DSGLXAk1IqgsQbrmQKBgQD4q7ardKl0U2m4OiozAZqUR5l1oe+MSdxZ -j3DGkMpOe7F+b63jHtWjEE3MEtzKXsZxOucy5S3OTZs0hdRB+IRP443uNARoaatN -14ZYbvPjmCTn6m6qR+fs7MWesaUStAVgGVWQgWY+4CZz3Zm+UXcmS+QHoiSbGfaz -neI4tFsNawKBgQCyxCLwHgVIAhdK3S4GzLs1K3Spz6YF8wnukNGKT5esuY2iVGmj -ueNw85vTnp0feojLsq4mbWjrQS45z+DKOcMfZm+oYWhzsUgmayIfKhn4NFhUZw59 -HawpzCgKBhifzAH111f4cTbtgsSt0Q/3fI3SlHJrCQIGSDzRRQUPgriMSQKBgGuJ -Llyk/abNb5l4pcka93MKJ4XkOohrZHvieP2Vnbck7JPlzce7DN4QbeRDf/GP3LcY -puSukQl3LBghi7Hfu7AkkrshCYrxr1/hRTq2+IdCwyr7iVHf+J7PoYJIBj+5U93D -9umf28xy+I4Albzk0+beyMS4TKY6KyJvs2WcMQfzAoGARac5umqHTqNubeVoB2EX -BMFj55RDkWH9GU631deMDgfPvymZJ5HI1Dz+jdX7PbOfPbc+5AUN4lZqZw5/2yxN -ps0BUMz1Hr4goeoC0akFsnA5GXoFkhWh6xR45ZRfmPEDYxvk8tqeZvtZns+3AjfR -+C6C4YZdYsgLfWRFtxW3OlA= ------END PRIVATE KEY----- From 09483ba2e8ca42f4061ddfcdde8c3664b4ab3d9e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Go=CC=88khan=20S=CC=A7engu=CC=88n?= Date: Mon, 11 Apr 2022 18:50:20 +0300 Subject: [PATCH 15/17] Add a wildcard certificate generation alternative --- etc/README.md | 2 +- .../templates/administration-ingress.yaml | 8 +--- .../charts/administration/values.yaml | 2 +- .../templates/authserver-ingress.yaml | 11 +---- .../eshoponabp/charts/authserver/values.yaml | 2 +- .../basket/templates/basket-ingress.yaml | 4 +- etc/k8s/eshoponabp/charts/basket/values.yaml | 2 +- .../catalog/templates/catalog-ingress.yaml | 3 +- etc/k8s/eshoponabp/charts/catalog/values.yaml | 2 +- .../templates/gateway-web-public-ingress.yaml | 3 +- .../charts/gateway-web-public/values.yaml | 2 +- .../templates/gateway-web-ingress.yaml | 3 +- .../eshoponabp/charts/gateway-web/values.yaml | 2 +- .../identity/templates/identity-ingress.yaml | 3 +- .../eshoponabp/charts/identity/values.yaml | 2 +- .../ordering/templates/ordering-ingress.yaml | 3 +- .../eshoponabp/charts/ordering/values.yaml | 2 +- .../payment/templates/payment-ingress.yaml | 3 +- etc/k8s/eshoponabp/charts/payment/values.yaml | 2 +- .../templates/public-web-ingress.yaml | 3 +- .../eshoponabp/charts/public-web/values.yaml | 2 +- .../charts/web/templates/web-ingress.yaml | 3 +- etc/k8s/eshoponabp/charts/web/values.yaml | 2 +- etc/k8s/eshoponabp/values.yaml | 2 +- etc/k8s/tls-cert/eshop-demo-tls.conf | 38 ---------------- etc/k8s/tls-cert/eshop-st-cert.key | 28 ------------ etc/k8s/tls-cert/eshop-st-cert.pem | 23 ---------- etc/k8s/tls-cert/eshop-test-tls.crt | 23 ---------- etc/k8s/tls-cert/eshop-test-tls.key | 28 ------------ etc/k8s/tls-cert/ingress-tls.yaml | 24 ----------- etc/k8s/tls-cert/notes.md | 43 +++++-------------- etc/k8s/tls-cert/selfsigned/certificate.yaml | 21 --------- .../tls-cert/selfsigned/cluster-issuer.yaml | 6 --- etc/k8s/tls-cert/selfsigned/issuer.yaml | 7 --- etc/k8s/tls-cert/selfsigned/readme.md | 8 ---- 35 files changed, 35 insertions(+), 287 deletions(-) delete mode 100644 etc/k8s/tls-cert/eshop-demo-tls.conf delete mode 100644 etc/k8s/tls-cert/eshop-st-cert.key delete mode 100644 etc/k8s/tls-cert/eshop-st-cert.pem delete mode 100644 etc/k8s/tls-cert/eshop-test-tls.crt delete mode 100644 etc/k8s/tls-cert/eshop-test-tls.key delete mode 100644 etc/k8s/tls-cert/ingress-tls.yaml delete mode 100644 etc/k8s/tls-cert/selfsigned/certificate.yaml delete mode 100644 etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml delete mode 100644 etc/k8s/tls-cert/selfsigned/issuer.yaml delete mode 100644 etc/k8s/tls-cert/selfsigned/readme.md diff --git a/etc/README.md b/etc/README.md index 3ff8d9a0..5d0853e9 100644 --- a/etc/README.md +++ b/etc/README.md @@ -8,7 +8,7 @@ OR helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx helm repo update -helm install ingress-nginx ingress-nginx/ingress-nginx +helm upgrade --install --version=4.0.19 ingress-nginx ingress-nginx/ingress-nginx ``` * Install [Helm](https://helm.sh/docs/intro/install/) for running helm charts diff --git a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml index fad0cb65..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml @@ -3,18 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - {{- if eq .Release.Name "es-st" }} - cert-manager.io/cluster-issuer: eshop-issuer - {{- end }} - {{- if eq .Release.Name "es-az" }} - cert-manager.io/issuer: letsencrypt - {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/administration/values.yaml b/etc/k8s/eshoponabp/charts/administration/values.yaml index 3a6e31d8..05e9d62c 100644 --- a/etc/k8s/eshoponabp/charts/administration/values.yaml +++ b/etc/k8s/eshoponabp/charts/administration/values.yaml @@ -26,7 +26,7 @@ synchedCommunication: ingress: host: eshop-st-administration - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-administration diff --git a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml index a24245ba..30e7e89e 100644 --- a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml @@ -3,25 +3,18 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" nginx.ingress.kubernetes.io/configuration-snippet: | more_set_input_headers "from-ingress: true"; - # cert-manager.io/cluster-issuer: selfsigned-issuer - # {{- if eq .Release.Name "es-st" }} - # cert-manager.io/cluster-issuer: eshop-issuer - # {{- end }} - # {{- if eq .Release.Name "es-az" }} - # cert-manager.io/issuer: letsencrypt - # {{- end }} spec: + ingressClassName: nginx tls: - hosts: - "eshop-st-authserver" - secretName: "eshop-test-tls" + secretName: "eshop-wildcard-tls" rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/authserver/values.yaml b/etc/k8s/eshoponabp/charts/authserver/values.yaml index a1b3edb6..c498a1ea 100644 --- a/etc/k8s/eshoponabp/charts/authserver/values.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/values.yaml @@ -18,7 +18,7 @@ config: ingress: host: eshop-st-authserver - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-authserver diff --git a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml index 7f7ab322..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml @@ -3,14 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/issuer: eshop-issuer - # cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/basket/values.yaml b/etc/k8s/eshoponabp/charts/basket/values.yaml index f332621a..c69ad16a 100644 --- a/etc/k8s/eshoponabp/charts/basket/values.yaml +++ b/etc/k8s/eshoponabp/charts/basket/values.yaml @@ -19,7 +19,7 @@ config: ingress: host: eshop-st-basket - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-basket diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml index 774a82c0..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - # cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/catalog/values.yaml b/etc/k8s/eshoponabp/charts/catalog/values.yaml index 970e0e02..8e65d499 100644 --- a/etc/k8s/eshoponabp/charts/catalog/values.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/values.yaml @@ -23,7 +23,7 @@ config: ingress: host: eshop-st-catalog - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-catalog diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml index 9bcfa428..a8d988f6 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: eshop-issuer {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml index bb625762..1b30388b 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml @@ -28,7 +28,7 @@ reRoutes: ingress: host: eshop-st-gateway-web-public - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/gateway-web-public diff --git a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml index 8e106909..0dedb3d3 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml index 4e3ac302..49ac9ace 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml @@ -21,7 +21,7 @@ reRoutes: url: http://eshop-st-administration ingress: host: # eshop-st-gateway-web - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/gateway-web diff --git a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml index e8030dea..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: selfsigned-issuer spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/identity/values.yaml b/etc/k8s/eshoponabp/charts/identity/values.yaml index 842fe3ee..34324d0b 100644 --- a/etc/k8s/eshoponabp/charts/identity/values.yaml +++ b/etc/k8s/eshoponabp/charts/identity/values.yaml @@ -32,7 +32,7 @@ identityServerClients: ingress: host: eshop-st-identity - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-identity diff --git a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/ordering/values.yaml b/etc/k8s/eshoponabp/charts/ordering/values.yaml index 895834ba..c9f8a55b 100644 --- a/etc/k8s/eshoponabp/charts/ordering/values.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-ordering - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-ordering diff --git a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/payment/values.yaml b/etc/k8s/eshoponabp/charts/payment/values.yaml index 3d5a55d7..37ffd9cb 100644 --- a/etc/k8s/eshoponabp/charts/payment/values.yaml +++ b/etc/k8s/eshoponabp/charts/payment/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-payment - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-payment diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml index ec4080bc..18a5ed2f 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/public-web/values.yaml b/etc/k8s/eshoponabp/charts/public-web/values.yaml index ba4f9861..7d38cb1f 100644 --- a/etc/k8s/eshoponabp/charts/public-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/values.yaml @@ -12,7 +12,7 @@ config: ingress: host: eshop-st-public-web - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-publicweb diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml index 54a62c3c..bbade7db 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/web/values.yaml b/etc/k8s/eshoponabp/charts/web/values.yaml index 792ef099..9a3418b7 100644 --- a/etc/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/k8s/eshoponabp/charts/web/values.yaml @@ -7,7 +7,7 @@ config: ingress: host: eshop-st-web - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-web diff --git a/etc/k8s/eshoponabp/values.yaml b/etc/k8s/eshoponabp/values.yaml index 81bc1014..6e31550c 100644 --- a/etc/k8s/eshoponabp/values.yaml +++ b/etc/k8s/eshoponabp/values.yaml @@ -13,7 +13,7 @@ authserver: elasticsearchHost: es-st-elasticsearch ingress: host: eshop-st-authserver - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: "eshoponabp/app-authserver" tag: latest diff --git a/etc/k8s/tls-cert/eshop-demo-tls.conf b/etc/k8s/tls-cert/eshop-demo-tls.conf deleted file mode 100644 index 68e574ef..00000000 --- a/etc/k8s/tls-cert/eshop-demo-tls.conf +++ /dev/null @@ -1,38 +0,0 @@ -[req] -default_bits = 2048 -default_keyfile = eshop-st.key -distinguished_name = req_distinguished_name -req_extensions = req_ext -x509_extensions = v3_ca - -[req_distinguished_name] -commonName = Common Name (e.g. server FQDN or YOUR name) -commonName_default = eshoponabp -commonName_max = 64 - -[req_ext] -subjectAltName = @alt_names - -[v3_ca] -subjectAltName = @alt_names -basicConstraints = critical, CA:false -keyUsage = keyCertSign, cRLSign, digitalSignature,keyEncipherment - -[alt_names] -DNS.1 = eshop-st-web -DNS.2 = eshop-st-public-web -DNS.3 = eshop-st-authserver -DNS.4 = eshop-st-identity -DNS.5 = eshop-st-administration -DNS.6 = eshop-st-gateway-web -DNS.7 = eshop-st-gateway-web-public -DNS.8 = eshop-st-basket -DNS.9 = eshop-st-catalog -DNS.10 = eshop-st-ordering -DNS.11 = eshop-st-payment - -# Generate certificate from config -# Use the command: -# 'openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-st-cert.key -out eshop-st-cert.pem -config eshop-demo-tls.conf' -# Verify that you have eshop-st-cert.crt and eshop-st-cert.key files under k8s/tls-cert folder -# Run comand : 'kubectl create secret tls eshop-demo-tls --cert=eshop-st-cert.pem --key=eshop-st-cert.key --namespace=eshop' diff --git a/etc/k8s/tls-cert/eshop-st-cert.key b/etc/k8s/tls-cert/eshop-st-cert.key deleted file mode 100644 index fffab06a..00000000 --- a/etc/k8s/tls-cert/eshop-st-cert.key +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQDSgXYuFacjDRuc -yj6oqIV1KlBinfbqnH9xEFOQXN6vFI9v5TzOTXstjCVQKhPWDCw3WSw7ydlAodFa -djeXEjapDGQmAVJk5nmPLv+UCOrZHd6ut8QEMb1cAGtOR71d8CVjWuZx6igGTPTQ -m2efRip0B0mog4j5vc+q8tr0qu+h13TAkivYGPQTvT46p/GypH5xFjAVw9P6IIYP -fr+nm2R/fUV3FEmaUBJmNjjoDJzrtGxe8zWD7vRxIYoNeffzRTMCT622Y8j6TEp2 -rlVPjh9Dp7+Wrj6FxopKBt6j3F5S1NKkEgEID8cL1Aufu0Xk/dWPsSAstVPgA/gf -GIW+7ALHAgMBAAECggEBAL2lmvYL1ecTMRRBdM/3+zxCYedmzwQw9/PBtLczo/9x -84Por65hSZ8QSrF9Jx/JGbDHqr02rX64CmeIZ6633vzPyA4hVLzIky13NxSEMCho -66zWrEbnFOUlD4eXxDg0WUq4ozJvtZ1viYPC7kklKqwbwLWLw0TUR5qIbtDMi1Vu -pyfm2YUtjqx2JPjD2i5juZx3XbgiqncpyRDroY80IqOZ/Kp83eMdst9wyfJaAy0B -kxZjvU1U2exD/l9RxKKreES2Vrbn+PvF3ttTgz/hE1ScBBfMB9kn+37esGZVByjb -ER0GFgt0jOx2ok+n2+zm2Z68IjoYDvsNo586tHoXxrECgYEA75UD5Nt9joCpCWVd -zXBQ8OUJwRU/N74RjBBS/NTT2sZ+q7xYxDx3xPwhyHXI+wwaHClGUE0yx5mrqqON -p3ELpanYdLWcdA6f/bFuuSNOAi7XSc1wCbNkTh5yxIyqWMvEYXqAj1/5T1VJ6+xU -pyKUe1588WKpSURrtGRxu0rKizkCgYEA4O5cJQmBeTlx++iVtONZv7HB371rYt45 -0nkBKfBJOjsVd2sB5f6ry5PaRcJyXamF7QYGgm4xo+KvrfHrf+JjebiJR46tsK0n -y130XjZVi28HPGBUG610zXOH3FgUQiSVbRulG0wzTtFHzdbVHJuTmA65+BZnayhM -WICqyiw0/f8CgYEAuXLmbbr8iFbNAYnmPwSGksEneL7ijVphqMJmCnEPgBQPrw1+ -xH9t0hu8ZrfNl435k/zbAYOQH/Kyb8Zj+s1FT7mV5FlDvo4nh69VXpeWZZgua2FL -LScgKFvnSH79yPgJjc7OPqzyhVcmfikUKb9Zodk064AMO7trh1oMswYkm/kCgYA/ -w/MFYOt+hUWGB4qhTC5+RJNUrWtLDPrRaxJkZEUuJ9/PCdvw6sCjJtgjHJu1Z8Ca -0DF6OmkCL9pj8ogzqedPc3wfeBhPVNdKNOl45+habfBcMmbFrefF8rGaSrH7ikl+ -M+8bjP+ioXu8o+GoiYZO/iXEaf2JiFQUZu2EAQJI2wKBgQCLUuZyV/fx2/90md4W -6GwyMYrA3Z3pVm3WKdphSX8euTTNjOjtwXwZ0iqfGsm0okHC0+DcI9PAhPh99fCB -7miZcUvQmqhmL7rcrOTfPRLVZ9flEVqeq6RCW4ICA2G7+0+eFz87FIl9EHfN9IMU -2mLb5Ph0OuI7W75OBR23qqVk5g== ------END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/eshop-st-cert.pem b/etc/k8s/tls-cert/eshop-st-cert.pem deleted file mode 100644 index f962d807..00000000 --- a/etc/k8s/tls-cert/eshop-st-cert.pem +++ /dev/null @@ -1,23 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDxjCCAq6gAwIBAgIUavYi4mtz8TCt6EwG/MDNsnykGPMwDQYJKoZIhvcNAQEL -BQAwFTETMBEGA1UEAwwKZXNob3BvbmFicDAeFw0yMjA0MDgxOTAwMDFaFw0yMzA0 -MDgxOTAwMDFaMBUxEzARBgNVBAMMCmVzaG9wb25hYnAwggEiMA0GCSqGSIb3DQEB -AQUAA4IBDwAwggEKAoIBAQDSgXYuFacjDRucyj6oqIV1KlBinfbqnH9xEFOQXN6v -FI9v5TzOTXstjCVQKhPWDCw3WSw7ydlAodFadjeXEjapDGQmAVJk5nmPLv+UCOrZ -Hd6ut8QEMb1cAGtOR71d8CVjWuZx6igGTPTQm2efRip0B0mog4j5vc+q8tr0qu+h -13TAkivYGPQTvT46p/GypH5xFjAVw9P6IIYPfr+nm2R/fUV3FEmaUBJmNjjoDJzr -tGxe8zWD7vRxIYoNeffzRTMCT622Y8j6TEp2rlVPjh9Dp7+Wrj6FxopKBt6j3F5S -1NKkEgEID8cL1Aufu0Xk/dWPsSAstVPgA/gfGIW+7ALHAgMBAAGjggEMMIIBCDCB -6gYDVR0RBIHiMIHfggxlc2hvcC1zdC13ZWKCE2VzaG9wLXN0LXB1YmxpYy13ZWKC -E2VzaG9wLXN0LWF1dGhzZXJ2ZXKCEWVzaG9wLXN0LWlkZW50aXR5ghdlc2hvcC1z -dC1hZG1pbmlzdHJhdGlvboIUZXNob3Atc3QtZ2F0ZXdheS13ZWKCG2VzaG9wLXN0 -LWdhdGV3YXktd2ViLXB1YmxpY4IPZXNob3Atc3QtYmFza2V0ghBlc2hvcC1zdC1j -YXRhbG9nghFlc2hvcC1zdC1vcmRlcmluZ4IQZXNob3Atc3QtcGF5bWVudDAMBgNV -HRMBAf8EAjAAMAsGA1UdDwQEAwIBpjANBgkqhkiG9w0BAQsFAAOCAQEAhJK7TgZw -IVqVbyYHw3M3fH5/tvioZNq0PbYOeWBX/A4ZolE1o5n5wzwk1TcOk7Kg8KdvZPM8 -VZgfx4B/MYaHWmliPx036oB4MJ9zh1D+zPr2kNqUKzY07H1JJDS9BzuBiSnnv7dJ -nuiJnV5F2Uy2cWltCgZ4xZ7xwnlofxIV4EnB88r+Gqz+LNtm1BFF4p5CzSQHcTrc -04H7k7gvITRYq086yuButbYT43uBBVJDEmTWUKMYWgh5K1cbyOUkYmaMCYaUnpNq -tgoZCNrUq3dpv/KsDsxh1bf2W0LsNiu2zExjetqDjoDC4cnCXYOsF7dW0HcnqFCN -PcxxXhW+kcd6+A== ------END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-test-tls.crt b/etc/k8s/tls-cert/eshop-test-tls.crt deleted file mode 100644 index c3a18d04..00000000 --- a/etc/k8s/tls-cert/eshop-test-tls.crt +++ /dev/null @@ -1,23 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDxjCCAq6gAwIBAgIUWAAiaf6jGeQBXdYnOFUKw+cQIlMwDQYJKoZIhvcNAQEL -BQAwFTETMBEGA1UEAwwKZXNob3BvbmFicDAeFw0yMjA0MDgyMjM4NDVaFw0yMzA0 -MDgyMjM4NDVaMBUxEzARBgNVBAMMCmVzaG9wb25hYnAwggEiMA0GCSqGSIb3DQEB -AQUAA4IBDwAwggEKAoIBAQDaQiJirGIVlbr00M8e1qTWLeIgsMUhLGa8fa/cEMJ7 -uInNm6hkCv1UrxGDKcxBBXs/kt+VYfnjtp+2IBlgv6wbHWftQYEwXxbtvXNIBWIn -GEee9S2uREDm0OHJF/xLEHPvFE15mFeo3bfJ3GIkuXuKu3RzQBre4q2y+1RfHnav -YKF/QIg3oWysnmt5G2wBS7bZvHkjvX7N31g80JU3yYuPkiCJi+PHiQbeyn4Obaf+ -TksoOqrwIO6bYE+cR5v2eLn0nLg/ZYvKSAbmmEiNIja3DRidxM9fYWPQgqVsAGs5 -CqdqH3PX9JNSl2FOQQqPSQ9IUwa5lJogNiSWZVacijh1AgMBAAGjggEMMIIBCDCB -6gYDVR0RBIHiMIHfggxlc2hvcC1zdC13ZWKCE2VzaG9wLXN0LXB1YmxpYy13ZWKC -E2VzaG9wLXN0LWF1dGhzZXJ2ZXKCEWVzaG9wLXN0LWlkZW50aXR5ghdlc2hvcC1z -dC1hZG1pbmlzdHJhdGlvboIUZXNob3Atc3QtZ2F0ZXdheS13ZWKCG2VzaG9wLXN0 -LWdhdGV3YXktd2ViLXB1YmxpY4IPZXNob3Atc3QtYmFza2V0ghBlc2hvcC1zdC1j -YXRhbG9nghFlc2hvcC1zdC1vcmRlcmluZ4IQZXNob3Atc3QtcGF5bWVudDAMBgNV -HRMBAf8EAjAAMAsGA1UdDwQEAwIBpjANBgkqhkiG9w0BAQsFAAOCAQEA0lsXpx1C -ItDk2gwKnUiof90y9iYBIZZ+RyxZlJHXYOTrfzOtg1U5zxZtaTBefPJhjI/hibyu -a2zCUFpc0CBLG8EVzLOv8VJDxiRf93bLP9Eoy40l8MVS8Lt5HVRs8xUiuGvxspwH -7aXAeP0HlykDjt3njwawPRuijFrk2GzQSCkPVh84e7RKTq4TYb1MpRjZw2Q92/NM -v0Zboi7wY0RqakyUHdWpgnWP/5ch8f8mInXkOJiQo0h5fbtrB8UdBGC7Qu1uKgsb -UloHs0w5p0q1AqmtYTJo2FmMP/touls/XhpJ5V0B3X2qh5JISqZiKifkPoJaIKCt -6ivVqCafin3yEQ== ------END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-test-tls.key b/etc/k8s/tls-cert/eshop-test-tls.key deleted file mode 100644 index 3958be9a..00000000 --- a/etc/k8s/tls-cert/eshop-test-tls.key +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDaQiJirGIVlbr0 -0M8e1qTWLeIgsMUhLGa8fa/cEMJ7uInNm6hkCv1UrxGDKcxBBXs/kt+VYfnjtp+2 -IBlgv6wbHWftQYEwXxbtvXNIBWInGEee9S2uREDm0OHJF/xLEHPvFE15mFeo3bfJ -3GIkuXuKu3RzQBre4q2y+1RfHnavYKF/QIg3oWysnmt5G2wBS7bZvHkjvX7N31g8 -0JU3yYuPkiCJi+PHiQbeyn4Obaf+TksoOqrwIO6bYE+cR5v2eLn0nLg/ZYvKSAbm -mEiNIja3DRidxM9fYWPQgqVsAGs5CqdqH3PX9JNSl2FOQQqPSQ9IUwa5lJogNiSW -ZVacijh1AgMBAAECggEAA3CxbA69iQuQI9W6vgiyFnIos001/jzd7bCpefWFqz+Q -ZH5EnDcUISaVRxT8lDXK6IifH5Koxq8VO2CsJbs/sjm3bqTurV2CVgL7czIqhuU6 -E8ZXjvyibUDzniDTqDc9LJKMWhNNpmrAP91KarvFt70Wq85h3guCo2SUwt8PDdqX -nHw0QzBXfkvg9/b90XCXrR/LnIyQ271wONJ1t1updDeo/EZzj/77yFWrvO7zw734 -FqDpfY+VeD9YNQszU40J/CMZa2qKqBXNp68JL2xOSFeHqNKvwKWvP145uGjURblz -Z12NdoKE3WbzMyv9zO1IdocaL1bFtM+7t3B9KFIbQQKBgQDz9ip8+AOTHp3RywUa -PvVGSk3U8+PBX3tTXgmoeRbMJ+xffE8uHMDu710izEvbkxQhAgar5dJH8NiragvW -LVZXCnstJfGI1V3oXnB2Y4BEB1ZTVSV8fuYutm6UhudWebTMg9EndvixK088pjya -GX0nx4MXOWgBo7vgLNXDNQa40QKBgQDlB0XvpJQEBZurz04iEgjXuXHttGQr4kw8 -0DwC2KA1JnEqZFy4CNGQyyIAKG9xDGCeejbwzBXkamPXpZ4Q7/Opv3wbsxzCnZE3 -MX6XUKqx2CfG7lRWwmLybLvRynHhT6LlWouNil/pHKvdv8LF+pu68S7sK24CaMpu -QF8aREHuZQKBgQDBnWBjBcJwhB/kXCeUiNrICjhzBYx/73NE2qD3oAJDzHt/3HxK -sG8+MaHM+C5L+RJEkAMTcbXNeou6ntL+C8U2Fw9i6XYjjpKU1D6U9qrZUqlkQXMa -tuufrxFbtyTqMHUYypS3qWf9081y6Mu30PrPEzwqtlig1H1KkMqlvfOzwQKBgFLS -soPbLHvX21fifAruIqyAr6aama8VAyTq2QjedfFCmaIO8UjMR5zpGL6d4M8s/rPQ -1pV1+GTF5J1TkznkzGUSjjsmJrxqZt1i1Li7vz7ZQGk8PtuxKD8q+zD+2Pf16J6w -g88Hv295ot1qP3GBE1gjaCiX/Ax7ANmmBb5l+MHRAoGAY6MXc6EUdgcLq0p/FbNk -OloFD/iUGNsJfSMxMg3vpWP9PhTSToiVDJrsviFWl2+z4CNicptsqfji237Uu4TP -d8Br0flNjfgyZ6BeRl1Ovgls6hDVgvjl6VWghZw9TfA0pc1ozb5FnUQkTG3+ceBY -KlHxDmv2VwadB8QbmuHqKjc= ------END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/ingress-tls.yaml b/etc/k8s/tls-cert/ingress-tls.yaml deleted file mode 100644 index f888087d..00000000 --- a/etc/k8s/tls-cert/ingress-tls.yaml +++ /dev/null @@ -1,24 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: kuard - annotations: - kubernetes.io/ingress.class: "nginx" - cert-manager.io/issuer: "letsencrypt-staging" - -spec: - tls: - - hosts: - - example.example.com - secretName: quickstart-example-tls - rules: - - host: example.example.com - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: kuard - port: - number: 80 diff --git a/etc/k8s/tls-cert/notes.md b/etc/k8s/tls-cert/notes.md index 9b9fae8e..7119f417 100644 --- a/etc/k8s/tls-cert/notes.md +++ b/etc/k8s/tls-cert/notes.md @@ -1,49 +1,26 @@ # Notes -## Creating demo tls cert +## TODO: - section on mkcert -``` -kubectl create secret tls eshop-demo-tls \ - --cert=eshop-st-cert.pem \ - --key=eshop-st-key.pem -``` - -# Install cert-manager - -`kubectl create namespace eshop` - -Next, use the **`kubectl apply`** command and the **`yaml`** file available online to install the add-on: - -```powershell -kubectl apply --validate=false -f https://github.com/jetstack/cert-manager/releases/download/v1.7.0/cert-manager.yaml -``` - -Now deploy the issuer: +### Install mkcert root ca ```powershell -kubectl apply -f .\selfsigned\issuer.yaml +mkcert -install ``` -Now deploy the certificate: +### Run mkcert ```powershell -kubectl apply -f .\selfsigned\certificate.yaml +mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public" ``` -Check the certificate: +At the end of the output you will see something like -```powershell -kubectl describe certificate -n=eshop -``` +The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem" -Check the secrets: +Copy the cert name and key name below to create tls secret ```powershell -kubectl get secrets -n=eshop +kubectl create namespace eshop +kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem ``` - -You should be seeing `eshop-staging-tls` - -To view information about the Secret, use the **`get secret`** command: - -`kubectl get secret eshop-staging-tls -n cert-manager` diff --git a/etc/k8s/tls-cert/selfsigned/certificate.yaml b/etc/k8s/tls-cert/selfsigned/certificate.yaml deleted file mode 100644 index ec7b9ab2..00000000 --- a/etc/k8s/tls-cert/selfsigned/certificate.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: Certificate -metadata: - name: selfsigned-cert - namespace: eshop -spec: - dnsNames: - - "*.eshop-st-web" - - "*.eshop-st-public-web" - - "*.eshop-st-authserver" - - "*.eshop-st-identity" - - "*.eshop-st-administration" - - "*.eshop-st-basket" - - "*.eshop-st-catalog" - - "*.eshop-st-ordering" - - "*.eshop-st-payment" - - "*.eshop-st-gateway-web" - - "*.eshop-st-gateway-web-public" - secretName: eshop-single-tls - issuerRef: - name: eshop-issuer \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml b/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml deleted file mode 100644 index c69e8a11..00000000 --- a/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml +++ /dev/null @@ -1,6 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: ClusterIssuer -metadata: - name: selfsigned-issuer -spec: - selfSigned: {} \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/issuer.yaml b/etc/k8s/tls-cert/selfsigned/issuer.yaml deleted file mode 100644 index 134fa38c..00000000 --- a/etc/k8s/tls-cert/selfsigned/issuer.yaml +++ /dev/null @@ -1,7 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: Issuer -metadata: - name: eshop-issuer - # namespace: eshop -spec: - selfSigned: {} \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/readme.md b/etc/k8s/tls-cert/selfsigned/readme.md deleted file mode 100644 index 198b3bc2..00000000 --- a/etc/k8s/tls-cert/selfsigned/readme.md +++ /dev/null @@ -1,8 +0,0 @@ -`helm install cert-manager jetstack/cert-manager --namespace cert-manager --create-namespace --version v1.4.0 --set installCRDs=true` -`kubectl create ns eshop` -`kubectl apply -f .\selfsigned\issuer.yaml` - - -```powershell -kubectl create secret tls eshop-demo-tls --cert=eshop-st-cert.pem --key=eshop-st-cert.key -n ingress-nginx -``` \ No newline at end of file From f3a3271d3474bfeefc958bd3cd7de05d98d3caa7 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 12 Apr 2022 11:46:50 +0300 Subject: [PATCH 16/17] added cert files to gitignore --- .gitignore | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.gitignore b/.gitignore index 6d18483d..8af19598 100644 --- a/.gitignore +++ b/.gitignore @@ -13,6 +13,9 @@ *.tye *.env .env +*.pem +*.crt +*.key # User-specific files (MonoDevelop/Xamarin Studio) *.userprefs From a723722c9b38c8508ee22533472981a4db48dfa9 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Tue, 12 Apr 2022 11:55:28 +0300 Subject: [PATCH 17/17] Udpated readme with https guide --- etc/README.md | 39 +++++++++++++++++++++++++++++++++++++-- etc/k8s/tls-cert/notes.md | 26 -------------------------- 2 files changed, 37 insertions(+), 28 deletions(-) delete mode 100644 etc/k8s/tls-cert/notes.md diff --git a/etc/README.md b/etc/README.md index 5d0853e9..71d918d3 100644 --- a/etc/README.md +++ b/etc/README.md @@ -1,4 +1,4 @@ - ### Pre-requirements + # Pre-requirements * Docker Desktop with Kubernetes enabled * Install [NGINX ingress](https://kubernetes.github.io/ingress-nginx/deploy/) for k8s @@ -13,7 +13,7 @@ helm upgrade --install --version=4.0.19 ingress-nginx ingress-nginx/ingress-ngin * Install [Helm](https://helm.sh/docs/intro/install/) for running helm charts -### How to run? +# How to run? * Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`): @@ -36,3 +36,38 @@ helm upgrade --install --version=4.0.19 ingress-nginx ingress-nginx/ingress-ngin * *You may wait ~30 seconds on first run for preparing the database*. * Browse https://eshop-st-public-web for public and https://eshop-st-web for web application * Username: `admin`, password: `1q2w3E*`. + +# Running on HTTPS + +You can also run the staging solution on your local kubernetes kluster with https. There are various ways to create self-signed certificate. + +## Installing mkcert +This guide will use mkcert to create self-signed certificates. + +Follow the [installation guide](https://github.com/FiloSottile/mkcert#installation) to install mkcert. + +## Creating mkcert Root CA +Use the command to create root (local) certificate authority for your certificates: +```powershell +mkcert -install +``` + +**Note:** all the certificates created by mkcert certificate creation will be trusted by local machine + +## Run mkcert + +Create certificate for the eshopOnAbp domains using the mkcert command below: +```powershell +mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public" +``` + +At the end of the output you will see something like + +The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem" + +Copy the cert name and key name below to create tls secret + +```powershell +kubectl create namespace eshop +kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem +``` diff --git a/etc/k8s/tls-cert/notes.md b/etc/k8s/tls-cert/notes.md deleted file mode 100644 index 7119f417..00000000 --- a/etc/k8s/tls-cert/notes.md +++ /dev/null @@ -1,26 +0,0 @@ -# Notes - -## TODO: - section on mkcert - -### Install mkcert root ca - -```powershell -mkcert -install -``` - -### Run mkcert - -```powershell -mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public" -``` - -At the end of the output you will see something like - -The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem" - -Copy the cert name and key name below to create tls secret - -```powershell -kubectl create namespace eshop -kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem -```