Browse Source

Merge pull request #114 from abpframework/skoc10/azure

eShopOnAbp: Deploy to Azure (AKS)
pull/117/head
Galip Tolga Erdem 4 years ago
committed by GitHub
parent
commit
b66bc88ad9
No known key found for this signature in database GPG Key ID: 4AEE18F83AFDEB23
  1. 22
      apps/angular/dynamic-env.json
  2. 71
      etc/k8s/azure/scripts/cert-manager.md
  3. 18
      etc/k8s/azure/scripts/cluster-issuer.yaml
  4. 69
      etc/k8s/azure/scripts/install-ingress.ps1
  5. 36
      etc/k8s/azure/scripts/push-images.ps1
  6. 3
      etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml
  7. 5
      etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml
  8. 3
      etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml
  9. 1
      etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml
  10. 3
      etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml
  11. 2
      etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml
  12. 11
      etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml
  13. 26
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml
  14. 9
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml
  15. 4
      etc/k8s/eshoponabp/charts/gateway-web/values.yaml
  16. 3
      etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml
  17. 4
      etc/k8s/eshoponabp/charts/mongodb/templates/mongodb-deployment.yaml
  18. 3
      etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml
  19. 3
      etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml
  20. 4
      etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml
  21. 2
      etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml
  22. 11
      etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml
  23. 1
      etc/k8s/eshoponabp/charts/public-web/values.yaml
  24. 40
      etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml
  25. 2
      etc/k8s/eshoponabp/charts/web/templates/web-deployment.yaml
  26. 13
      etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml
  27. 10
      etc/k8s/eshoponabp/charts/web/values.yaml
  28. 366
      etc/k8s/eshoponabp/values.azure.yaml

22
apps/angular/dynamic-env.json

@ -1,21 +1 @@
{
"production": true,
"application": {
"baseUrl":"https://eshop-st-web",
"name": "EShopOnAbp",
"logoUrl": ""
},
"oAuthConfig": {
"issuer": "https://eshop-st-authserver",
"redirectUri": "https://eshop-st-web",
"clientId": "Web",
"responseType": "code",
"scope": "offline_access openid profile email phone IdentityService AdministrationService"
},
"apis": {
"default": {
"url": "https://eshop-st-gateway-web",
"rootNamespace": "EShopOnAbp"
}
}
}
{}

71
etc/k8s/azure/scripts/cert-manager.md

@ -0,0 +1,71 @@
* Install the `cert-manager` on petclinic cluster. See [Cert-Manager info](https://cert-manager.io/docs/).
* Create the namespace for ingress-basic
```bash
kubectl create namespace ingress-basic
```
* Add the Jetstack Helm repository.
```bash
helm repo add jetstack https://charts.jetstack.io
```
* Update your local Helm chart repository.
```bash
helm repo update
```
* Install the `Custom Resource Definition` resources separately
```bash
kubectl apply -f https://github.com/jetstack/cert-manager/releases/download/v1.7.1/cert-manager.crds.yaml
```
* Install the cert-manager Helm chart
```bash
helm install \
cert-manager jetstack/cert-manager \
--namespace ingress-basic \
--version v1.7.1
```
* Verify that the cert-manager is deployed correctly.
```bash
kubectl get pods --namespace ingress-basic -o wide
```
* Create `ClusterIssuer` with name of `cluster-issuer.yml` for the production certificate through `Let's Encrypt ACME` (Automated Certificate Management Environment) with following content and save it under `azure/k8s` folder. *Note that certificate will only be created after annotating and updating the `Ingress` resource.*
```yaml
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt
spec:
acme:
# The ACME server URL
server: https://acme-v02.api.letsencrypt.org/directory
# Email address used for ACME registration
email: info@volosoft.com
# Name of a secret used to store the ACME account private key
privateKeySecretRef:
name: letsencrypt
# Enable the HTTP-01 challenge provider
solvers:
- http01:
ingress:
class: nginx
```
* Check if `ClusterIssuer` resource is created.
```bash
kubectl apply -f etc/azure/cluster-issuer.yaml
kubectl get clusterissuers letsencrypt -n ingress-basic -o wide
```

18
etc/k8s/azure/scripts/cluster-issuer.yaml

@ -0,0 +1,18 @@
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt
spec:
acme:
# The ACME server URL
server: https://acme-v02.api.letsencrypt.org/directory
# Email address used for ACME registration
email: info@volosoft.com
# Name of a secret used to store the ACME account private key
privateKeySecretRef:
name: letsencrypt
# Enable the HTTP-01 challenge provider
solvers:
- http01:
ingress:
class: nginx

69
etc/k8s/azure/scripts/install-ingress.ps1

@ -0,0 +1,69 @@
$REGISTRY_NAME="volocr.azurecr.io"
$ACR_URL="volocr.azurecr.io"
$CONTROLLER_REGISTRY="k8s.gcr.io"
$CONTROLLER_IMAGE="ingress-nginx/controller"
$CONTROLLER_TAG="v0.48.1"
$PATCH_REGISTRY="docker.io"
$PATCH_IMAGE="jettech/kube-webhook-certgen"
$PATCH_TAG="v1.5.1"
$DEFAULTBACKEND_REGISTRY="k8s.gcr.io"
$DEFAULTBACKEND_IMAGE="defaultbackend-amd64"
$DEFAULTBACKEND_TAG="1.5"
$CERT_MANAGER_REGISTRY="quay.io"
$CERT_MANAGER_TAG="v1.3.1"
$CERT_MANAGER_IMAGE_CONTROLLER="jetstack/cert-manager-controller"
$CERT_MANAGER_IMAGE_WEBHOOK="jetstack/cert-manager-webhook"
$CERT_MANAGER_IMAGE_CAINJECTOR="jetstack/cert-manager-cainjector"
az acr import --name $REGISTRY_NAME --source ${CONTROLLER_REGISTRY}/${CONTROLLER_IMAGE}:${CONTROLLER_TAG} --image ${CONTROLLER_IMAGE}:${CONTROLLER_TAG}
az acr import --name $REGISTRY_NAME --source ${PATCH_REGISTRY}/${PATCH_IMAGE}:${PATCH_TAG} --image ${PATCH_IMAGE}:${PATCH_TAG}
az acr import --name $REGISTRY_NAME --source ${DEFAULTBACKEND_REGISTRY}/${DEFAULTBACKEND_IMAGE}:${DEFAULTBACKEND_TAG} --image ${DEFAULTBACKEND_IMAGE}:${DEFAULTBACKEND_TAG}
az acr import --name $REGISTRY_NAME --source ${CERT_MANAGER_REGISTRY}/${CERT_MANAGER_IMAGE_CONTROLLER}:${CERT_MANAGER_TAG} --image ${CERT_MANAGER_IMAGE_CONTROLLER}:${CERT_MANAGER_TAG}
az acr import --name $REGISTRY_NAME --source ${CERT_MANAGER_REGISTRY}/${CERT_MANAGER_IMAGE_WEBHOOK}:${CERT_MANAGER_TAG} --image ${CERT_MANAGER_IMAGE_WEBHOOK}:${CERT_MANAGER_TAG}
az acr import --name $REGISTRY_NAME --source ${CERT_MANAGER_REGISTRY}/${CERT_MANAGER_IMAGE_CAINJECTOR}:${CERT_MANAGER_TAG} --image ${CERT_MANAGER_IMAGE_CAINJECTOR}:${CERT_MANAGER_TAG}
# Create a namespace for your ingress resources
kubectl create namespace ingress-basic
# Add the ingress-nginx repository
helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
# Use Helm to deploy an NGINX ingress controller
helm install nginx-ingress ingress-nginx/ingress-nginx `
--namespace ingress-basic `
--set controller.replicaCount=1 `
--set controller.nodeSelector."kubernetes\.io/os"=linux `
--set controller.image.registry=$ACR_URL `
--set controller.image.image=$CONTROLLER_IMAGE `
--set controller.image.tag=$CONTROLLER_TAG `
--set controller.image.digest="" `
--set controller.admissionWebhooks.patch.nodeSelector."kubernetes\.io/os"=linux `
--set controller.admissionWebhooks.patch.image.registry=$ACR_URL `
--set controller.admissionWebhooks.patch.image.image=$PATCH_IMAGE `
--set controller.admissionWebhooks.patch.image.tag=$PATCH_TAG `
--set defaultBackend.nodeSelector."kubernetes\.io/os"=linux `
--set defaultBackend.image.registry=$ACR_URL `
--set defaultBackend.image.image=$DEFAULTBACKEND_IMAGE `
--set defaultBackend.image.tag=$DEFAULTBACKEND_TAG
# Label the ingress-basic namespace to disable resource validation
kubectl label namespace ingress-basic cert-manager.io/disable-validation=true
# Add the Jetstack Helm repository
helm repo add jetstack https://charts.jetstack.io
# Update your local Helm chart repository cache
helm repo update
# Install the cert-manager Helm chart
helm install cert-manager jetstack/cert-manager `
--namespace ingress-basic `
--version ${CERT_MANAGER_TAG} `
--set installCRDs=true `
--set nodeSelector."kubernetes\.io/os"=linux `
--set image.repository=${ACR_URL}/${CERT_MANAGER_IMAGE_CONTROLLER} `
--set image.tag=${CERT_MANAGER_TAG} `
--set webhook.image.repository=${ACR_URL}/${CERT_MANAGER_IMAGE_WEBHOOK} `
--set webhook.image.tag=${CERT_MANAGER_TAG} `
--set cainjector.image.repository=${ACR_URL}/${CERT_MANAGER_IMAGE_CAINJECTOR} `
--set cainjector.image.tag=${CERT_MANAGER_TAG}

36
etc/k8s/azure/scripts/push-images.ps1

@ -0,0 +1,36 @@
param ($version='latest')
az acr login --name volocr
docker tag eshoponabp/app-web:$version volocr.azurecr.io/eshoponabp/app-web:$version
docker push volocr.azurecr.io/eshoponabp/app-web:$version
docker tag eshoponabp/app-authserver:$version volocr.azurecr.io/eshoponabp/app-authserver:$version
docker push volocr.azurecr.io/eshoponabp/app-authserver:$version
docker tag eshoponabp/app-publicweb:$version volocr.azurecr.io/eshoponabp/app-publicweb:$version
docker push volocr.azurecr.io/eshoponabp/app-publicweb:$version
docker tag eshoponabp/gateway-web:$version volocr.azurecr.io/eshoponabp/gateway-web:$version
docker push volocr.azurecr.io/c:$version
docker tag eshoponabp/gateway-web-public:$version volocr.azurecr.io/eshoponabp/gateway-web-public:$version
docker push volocr.azurecr.io/eshoponabp/gateway-web-public:$version
docker tag eshoponabp/service-identity:$version volocr.azurecr.io/eshoponabp/service-identity:$version
docker push volocr.azurecr.io/eshoponabp/service-identity:$version
docker tag eshoponabp/service-administration:$version volocr.azurecr.io/eshoponabp/service-administration:$version
docker push volocr.azurecr.io/eshoponabp/service-administration:$version
docker tag eshoponabp/service-basket:$version volocr.azurecr.io/eshoponabp/service-basket:$version
docker push volocr.azurecr.io/eshoponabp/service-basket:$version
docker tag eshoponabp/service-catalog:$version volocr.azurecr.io/eshoponabp/service-catalog:$version
docker push volocr.azurecr.io/eshoponabp/service-catalog:$version
docker tag eshoponabp/service-ordering:$version volocr.azurecr.io/eshoponabp/service-ordering:$version
docker push volocr.azurecr.io/eshoponabp/service-ordering:$version
docker tag eshoponabp/service-payment:$version volocr.azurecr.io/eshoponabp/service-payment:$version
docker push volocr.azurecr.io/eshoponabp/service-payment:$version

3
etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

5
etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml

@ -7,14 +7,15 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
nginx.ingress.kubernetes.io/configuration-snippet: |
more_set_input_headers "from-ingress: true";
spec:
ingressClassName: nginx
tls:
- hosts:
- "eshop-st-authserver"
secretName: "eshop-wildcard-tls"
- {{ .Values.ingress.host }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

3
etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

1
etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml

@ -18,6 +18,7 @@ spec:
ports:
- name: http
containerPort: 80
protocol: TCP
- name: grpc
containerPort: 81
protocol: TCP

3
etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

2
etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml

@ -8,6 +8,8 @@ spec:
ports:
- name: "http"
port: 80
targetPort: http
protocol: TCP
- name: grpc
targetPort: grpc
protocol: TCP

11
etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml

@ -7,20 +7,21 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.global.ingress.host }}
{{- if eq .Release.Name "eshop-az" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
- host: "{{ print "www." .Values.ingress.host }}"
{{- else }}
- host: "{{ .Values.ingress.host }}"

26
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml

@ -42,6 +42,18 @@ data:
"Match": {
"Path": "/api/setting-management/{**everything}"
}
},
"Catalog Service": {
"ClusterId": "catalogCluster",
"Match": {
"Path": "/api/catalog/{**everything}"
}
},
"Ordering Service": {
"ClusterId": "orderingCluster",
"Match": {
"Path": "/api/ordering/{**everything}"
}
}
},
"Clusters": {
@ -86,6 +98,20 @@ data:
"Address": "{{ .Values.reRoutes.administrationService.url }}"
}
}
},
"catalogCluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.catalogService.url }}"
}
}
},
"orderingCluster": {
"Destinations": {
"destination1": {
"Address": "{{ .Values.reRoutes.orderingService.url }}"
}
}
}
}
}

9
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml

@ -7,20 +7,21 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
- host: "{{ print "www." .Values.ingress.host }}"
{{- else }}
- host: "{{ .Values.ingress.host }}"

4
etc/k8s/eshoponabp/charts/gateway-web/values.yaml

@ -19,6 +19,10 @@ reRoutes:
url: http://eshop-st-identity
administrationService:
url: http://eshop-st-administration
catalogService:
url: http://eshop-st-catalog
orderingService:
url: http://eshop-st-order
ingress:
host: # eshop-st-gateway-web
tlsSecret: eshop-wildcard-tls

3
etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

4
etc/k8s/eshoponabp/charts/mongodb/templates/mongodb-deployment.yaml

@ -16,7 +16,7 @@ spec:
containers:
- image: "mongo:4.2"
name: {{ .Release.Name }}-{{ .Chart.Name }}
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
volumeMounts:
- mountPath: "/data/db"
name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume
@ -25,7 +25,7 @@ spec:
ports:
- name: mongo
containerPort: 27017
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
volumeClaimTemplates:
- metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume

3
etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

3
etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

4
etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml

@ -16,7 +16,7 @@ spec:
containers:
- image: "postgres:14.1"
name: {{ .Release.Name }}-{{ .Chart.Name }}
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
volumeMounts:
- mountPath: "/var/opt/postgres"
name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume
@ -28,7 +28,7 @@ spec:
env:
- name: POSTGRES_PASSWORD
value: "myPassw0rd"
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
volumeClaimTemplates:
- metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume

2
etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml

@ -39,6 +39,8 @@ spec:
value: "{{ .Values.config.rabbitmqHost }}"
- name: "ElasticSearch__Url"
value: "{{ .Values.config.elasticsearchHost }}"
- name: "ReverseProxy__Clusters__cluster1__Destinations__destination1__Address"
value: "{{ .Values.config.gatewayUrl }}"
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

11
etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml

@ -7,23 +7,24 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "es-az" }}
{{- if eq .Release.Name "eshop-az" }}
- host: "{{ print "www." .Values.ingress.host }}"
{{- else }}
- host: "{{ .Values.ingress.host }}"
- host: "{{ .Values.ingress.host }}"
{{- end }}
http:
paths:

1
etc/k8s/eshoponabp/charts/public-web/values.yaml

@ -9,6 +9,7 @@ config:
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8
ingress:
host: eshop-st-public-web

40
etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml

@ -5,24 +5,24 @@ metadata:
data:
dynamic-env.json: |-
{
"production": "true",
"application": {
"baseUrl": "{{ .Values.config.selfUrl }}",
"name": "EShopOnAbp",
"logoUrl": ""
},
"oAuthConfig": {
"issuer": "{{ .Values.config.authServer.authority }}",
"redirectUri": "{{ .Values.config.selfUrl }}",
"requireHttps": "{{ .Values.config.authServer.requireHttpsMetadata }}",
"clientId": "Web",
"responseType": "code",
"scope": "offline_access openid profile email phone IdentityService AdministrationService"
},
"apis": {
"default": {
"url": "{{ .Values.config.gatewayUrl }}",
"rootNamespace": "EShopOnAbp"
}
}
"production": "true",
"application": {
"baseUrl": "{{ .Values.config.selfUrl }}",
"name": "EShopOnAbp",
"logoUrl": ""
},
"oAuthConfig": {
"issuer": "{{ .Values.config.authServer.authority }}",
"redirectUri": "{{ .Values.config.selfUrl }}",
"requireHttps": "{{ .Values.config.authServer.requireHttpsMetadata }}",
"clientId": "Web",
"responseType": "{{ .Values.config.authServer.responseType }}",
"scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService"
},
"apis": {
"default": {
"url": "{{ .Values.config.gatewayUrl }}",
"rootNamespace": "EShopOnAbp"
}
}
}

2
etc/k8s/eshoponabp/charts/web/templates/web-deployment.yaml

@ -22,7 +22,7 @@ spec:
containerPort: 443
volumeMounts:
- name: config-volume
mountPath: /app/dynamic-env.json
mountPath: /usr/share/nginx/html/dynamic-env.json
subPath: dynamic-env.json
env:
{{- if .Values.env }}

13
etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml

@ -7,24 +7,15 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
{{- if eq .Release.Name "es-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "eh-es" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "eh-es" }}
- host: "{{ print "www." .Values.ingress.host }}"
{{- else }}
- host: "{{ .Values.ingress.host }}"
{{- end }}
http:
paths:
- path: /

10
etc/k8s/eshoponabp/charts/web/values.yaml

@ -1,10 +1,10 @@
config:
selfUrl: https://eshop-st-web
gatewayUrl: "https://eshop-st-gateway-web/"
selfUrl: https://admin.eshoponabp.com
gatewayUrl: https://www.gateway.eshoponabp.com/
authServer:
authority: http://eshop-st-authserver
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
responseType: "code"
ingress:
host: eshop-st-web
tlsSecret: eshop-wildcard-tls
@ -15,4 +15,4 @@ image:
pullPolicy: IfNotPresent
# Extra environment variables or configurations
env: {}
env: {}

366
etc/k8s/eshoponabp/values.azure.yaml

@ -0,0 +1,366 @@
# auth-server sub-chart override
authserver:
config:
selfUrl: https://auth.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://identity.eshoponabp.com,https://administration.eshoponabp.com,https://basket.eshoponabp.com,https://catalog.eshoponabp.com,https://order.eshoponabp.com,https://payment.eshoponabp.com,https://admin.eshoponabp.com,https://eshoponabp.com
allowedRedirectUrls: https://admin.eshoponabp.com
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
connectionStrings:
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
identityService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
ingress:
host: auth.eshoponabp.com
tlsSecret: eshop-wildcard-tls
image:
repository: "volocr.azurecr.io/eshoponabp/app-authserver"
tag: latest
# web sub-chart override
web:
config:
selfUrl: https://admin.eshoponabp.com
gatewayUrl: https://www.gateway.eshoponabp.com
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
responseType: "code"
ingress:
host: admin.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/app-web"
tag: latest
# public-web sub-chart override
public-web:
config:
selfUrl: https://www.eshoponabp.com
gatewayUrl: https://www.gateway-public.eshoponabp.com/
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
ingress:
host: eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/app-publicweb"
tag: latest
# identity-service sub-chart override
identity:
config:
selfUrl: https://identity.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com
connectionStrings:
identityService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
identityServerClients: # Seeded Clients
webRootUrl: https://admin.eshoponabp.com/
publicWebRootUrl: https://www.eshoponabp.com/
webGatewayRootUrl: https://www.gateway.eshoponabp.com/
publicWebGatewayRootUrl: https://www.gateway-public.eshoponabp.com/
identityServiceRootUrl: https://identity.eshoponabp.com/
administrationServiceRootUrl: https://administration.eshoponabp.com/
accountServiceRootUrl: https://auth.eshoponabp.com
basketServiceRootUrl: https://basket.eshoponabp.com/
catalogServiceRootUrl: https://catalog.eshoponabp.com
orderingServiceRootUrl: https://order.eshoponabp.com
paymentServiceRootUrl: https://payment.eshoponabp.com
ingress:
host: identity.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-identity"
tag: latest
# administration sub-chart override
administration:
config:
selfUrl: https://administration.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://eshop-az-gateway-internal
connectionStrings:
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://identity.eshoponabp.com
useCurrentToken: "false"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions
authority: https://auth.eshoponabp.com
ingress:
host: administration.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-administration"
tag: latest
# gateway-web sub-chart override
gateway-web:
config:
selfUrl: https://www.gateway.eshoponabp.com
corsOrigins: https://admin.eshoponabp.com
globalConfigurationBaseUrl: http://eshop-az-gateway-public
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
ingress:
host: gateway.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/gateway-web"
tag: latest
reRoutes:
accountService:
url: http://eshop-az-authserver
identityService:
url: http://eshop-az-identity
administrationService:
url: http://eshop-az-administration
catalogService:
url: http://eshop-az-catalog
orderingService:
url: http://eshop-az-ordering
# gateway-web-public sub-chart override
gateway-web-public:
config:
selfUrl: https://www.gateway-public.eshoponabp.com
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
ingress:
host: gateway-public.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/gateway-web-public"
tag: latest
reRoutes:
accountService:
url: http://eshop-az-authserver
identityService:
url: http://eshop-az-identity
administrationService:
url: http://eshop-az-administration
catalogService:
url: http://eshop-az-catalog
basketService:
url: http://eshop-az-basket
orderingService:
url: http://eshop-az-ordering
paymentService:
url: http://eshop-az-payment
# basket-service sub-chart override
basket:
config:
selfUrl: https://basket.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://www.eshoponabp.com
connectionStrings:
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
remoteServices:
catalogBaseUrl: http://eshop-az-catalog:80
catalogGrpcUrl: http://eshop-az-catalog:81
ingress:
host: basket.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-basket"
tag: latest
# catalog-service sub-chart override
catalog:
config:
selfUrl: https://catalog.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://www.eshoponabp.com,https://admin.eshoponabp.com
connectionStrings:
catalogService: "mongodb://eshop-az-mongodb/EShopOnAbp_Catalog"
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
kestrel:
httpUrl: http://eshop-az-catalog:80
httpProtocols: Http1AndHttp2
grpcUrl: http://eshop-az-catalog:81
grpcProtocols: Http2
ingress:
host: catalog.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-catalog"
tag: latest
# ordering-service sub-chart override
ordering:
config:
selfUrl: https://order.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com
connectionStrings:
orderingService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
ingress:
host: order.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-ordering"
tag: latest
# payment-service sub-chart override
payment:
config:
selfUrl: https://payment.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com
connectionStrings:
paymentService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-az-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: eshop-az-redis
rabbitmqHost: eshop-az-rabbitmq
elasticsearchHost: eshop-az-elasticsearch
ingress:
host: payment.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-payment"
tag: latest
# Default values for eshoponabp.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: nginx
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: ""
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
serviceAccount:
# Specifies whether a service account should be created
create: true
# Annotations to add to the service account
annotations: {}
# The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
podAnnotations: {}
podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
service:
type: ClusterIP
port: 80
ingress:
enabled: false
className: ""
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
hosts:
- host: chart-example.local
paths:
- path: /
pathType: ImplementationSpecific
tls: []
# - secretName: chart-example-tls
# hosts:
# - chart-example.local
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80
nodeSelector: {}
tolerations: []
affinity: {}
Loading…
Cancel
Save