diff --git a/apps/angular/dynamic-env.json b/apps/angular/dynamic-env.json index a6f6c356..9e26dfee 100644 --- a/apps/angular/dynamic-env.json +++ b/apps/angular/dynamic-env.json @@ -1,21 +1 @@ -{ - "production": true, - "application": { - "baseUrl":"https://eshop-st-web", - "name": "EShopOnAbp", - "logoUrl": "" - }, - "oAuthConfig": { - "issuer": "https://eshop-st-authserver", - "redirectUri": "https://eshop-st-web", - "clientId": "Web", - "responseType": "code", - "scope": "offline_access openid profile email phone IdentityService AdministrationService" - }, - "apis": { - "default": { - "url": "https://eshop-st-gateway-web", - "rootNamespace": "EShopOnAbp" - } - } -} \ No newline at end of file +{} \ No newline at end of file diff --git a/etc/k8s/azure/scripts/cert-manager.md b/etc/k8s/azure/scripts/cert-manager.md new file mode 100644 index 00000000..354d952f --- /dev/null +++ b/etc/k8s/azure/scripts/cert-manager.md @@ -0,0 +1,71 @@ +* Install the `cert-manager` on petclinic cluster. See [Cert-Manager info](https://cert-manager.io/docs/). + + * Create the namespace for ingress-basic + + ```bash + kubectl create namespace ingress-basic + ``` + + * Add the Jetstack Helm repository. + + ```bash + helm repo add jetstack https://charts.jetstack.io + ``` + + * Update your local Helm chart repository. + + ```bash + helm repo update + ``` + + * Install the `Custom Resource Definition` resources separately + + ```bash + kubectl apply -f https://github.com/jetstack/cert-manager/releases/download/v1.7.1/cert-manager.crds.yaml + ``` + + * Install the cert-manager Helm chart + + ```bash + helm install \ + cert-manager jetstack/cert-manager \ + --namespace ingress-basic \ + --version v1.7.1 + ``` + + * Verify that the cert-manager is deployed correctly. + + ```bash + kubectl get pods --namespace ingress-basic -o wide + ``` + +* Create `ClusterIssuer` with name of `cluster-issuer.yml` for the production certificate through `Let's Encrypt ACME` (Automated Certificate Management Environment) with following content and save it under `azure/k8s` folder. *Note that certificate will only be created after annotating and updating the `Ingress` resource.* + +```yaml +apiVersion: cert-manager.io/v1 +kind: ClusterIssuer +metadata: + name: letsencrypt +spec: + acme: + # The ACME server URL + server: https://acme-v02.api.letsencrypt.org/directory + # Email address used for ACME registration + email: info@volosoft.com + # Name of a secret used to store the ACME account private key + privateKeySecretRef: + name: letsencrypt + # Enable the HTTP-01 challenge provider + solvers: + - http01: + ingress: + class: nginx +``` + +* Check if `ClusterIssuer` resource is created. + +```bash +kubectl apply -f etc/azure/cluster-issuer.yaml +kubectl get clusterissuers letsencrypt -n ingress-basic -o wide +``` + diff --git a/etc/k8s/azure/scripts/cluster-issuer.yaml b/etc/k8s/azure/scripts/cluster-issuer.yaml new file mode 100644 index 00000000..a3d6e7f5 --- /dev/null +++ b/etc/k8s/azure/scripts/cluster-issuer.yaml @@ -0,0 +1,18 @@ +apiVersion: cert-manager.io/v1 +kind: ClusterIssuer +metadata: + name: letsencrypt +spec: + acme: + # The ACME server URL + server: https://acme-v02.api.letsencrypt.org/directory + # Email address used for ACME registration + email: info@volosoft.com + # Name of a secret used to store the ACME account private key + privateKeySecretRef: + name: letsencrypt + # Enable the HTTP-01 challenge provider + solvers: + - http01: + ingress: + class: nginx \ No newline at end of file diff --git a/etc/k8s/azure/scripts/install-ingress.ps1 b/etc/k8s/azure/scripts/install-ingress.ps1 new file mode 100644 index 00000000..153ed91d --- /dev/null +++ b/etc/k8s/azure/scripts/install-ingress.ps1 @@ -0,0 +1,69 @@ +$REGISTRY_NAME="volocr.azurecr.io" +$ACR_URL="volocr.azurecr.io" +$CONTROLLER_REGISTRY="k8s.gcr.io" +$CONTROLLER_IMAGE="ingress-nginx/controller" +$CONTROLLER_TAG="v0.48.1" +$PATCH_REGISTRY="docker.io" +$PATCH_IMAGE="jettech/kube-webhook-certgen" +$PATCH_TAG="v1.5.1" +$DEFAULTBACKEND_REGISTRY="k8s.gcr.io" +$DEFAULTBACKEND_IMAGE="defaultbackend-amd64" +$DEFAULTBACKEND_TAG="1.5" +$CERT_MANAGER_REGISTRY="quay.io" +$CERT_MANAGER_TAG="v1.3.1" +$CERT_MANAGER_IMAGE_CONTROLLER="jetstack/cert-manager-controller" +$CERT_MANAGER_IMAGE_WEBHOOK="jetstack/cert-manager-webhook" +$CERT_MANAGER_IMAGE_CAINJECTOR="jetstack/cert-manager-cainjector" + +az acr import --name $REGISTRY_NAME --source ${CONTROLLER_REGISTRY}/${CONTROLLER_IMAGE}:${CONTROLLER_TAG} --image ${CONTROLLER_IMAGE}:${CONTROLLER_TAG} +az acr import --name $REGISTRY_NAME --source ${PATCH_REGISTRY}/${PATCH_IMAGE}:${PATCH_TAG} --image ${PATCH_IMAGE}:${PATCH_TAG} +az acr import --name $REGISTRY_NAME --source ${DEFAULTBACKEND_REGISTRY}/${DEFAULTBACKEND_IMAGE}:${DEFAULTBACKEND_TAG} --image ${DEFAULTBACKEND_IMAGE}:${DEFAULTBACKEND_TAG} +az acr import --name $REGISTRY_NAME --source ${CERT_MANAGER_REGISTRY}/${CERT_MANAGER_IMAGE_CONTROLLER}:${CERT_MANAGER_TAG} --image ${CERT_MANAGER_IMAGE_CONTROLLER}:${CERT_MANAGER_TAG} +az acr import --name $REGISTRY_NAME --source ${CERT_MANAGER_REGISTRY}/${CERT_MANAGER_IMAGE_WEBHOOK}:${CERT_MANAGER_TAG} --image ${CERT_MANAGER_IMAGE_WEBHOOK}:${CERT_MANAGER_TAG} +az acr import --name $REGISTRY_NAME --source ${CERT_MANAGER_REGISTRY}/${CERT_MANAGER_IMAGE_CAINJECTOR}:${CERT_MANAGER_TAG} --image ${CERT_MANAGER_IMAGE_CAINJECTOR}:${CERT_MANAGER_TAG} + +# Create a namespace for your ingress resources +kubectl create namespace ingress-basic + +# Add the ingress-nginx repository +helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx + +# Use Helm to deploy an NGINX ingress controller +helm install nginx-ingress ingress-nginx/ingress-nginx ` + --namespace ingress-basic ` + --set controller.replicaCount=1 ` + --set controller.nodeSelector."kubernetes\.io/os"=linux ` + --set controller.image.registry=$ACR_URL ` + --set controller.image.image=$CONTROLLER_IMAGE ` + --set controller.image.tag=$CONTROLLER_TAG ` + --set controller.image.digest="" ` + --set controller.admissionWebhooks.patch.nodeSelector."kubernetes\.io/os"=linux ` + --set controller.admissionWebhooks.patch.image.registry=$ACR_URL ` + --set controller.admissionWebhooks.patch.image.image=$PATCH_IMAGE ` + --set controller.admissionWebhooks.patch.image.tag=$PATCH_TAG ` + --set defaultBackend.nodeSelector."kubernetes\.io/os"=linux ` + --set defaultBackend.image.registry=$ACR_URL ` + --set defaultBackend.image.image=$DEFAULTBACKEND_IMAGE ` + --set defaultBackend.image.tag=$DEFAULTBACKEND_TAG + +# Label the ingress-basic namespace to disable resource validation +kubectl label namespace ingress-basic cert-manager.io/disable-validation=true + +# Add the Jetstack Helm repository +helm repo add jetstack https://charts.jetstack.io + +# Update your local Helm chart repository cache +helm repo update + +# Install the cert-manager Helm chart +helm install cert-manager jetstack/cert-manager ` + --namespace ingress-basic ` + --version ${CERT_MANAGER_TAG} ` + --set installCRDs=true ` + --set nodeSelector."kubernetes\.io/os"=linux ` + --set image.repository=${ACR_URL}/${CERT_MANAGER_IMAGE_CONTROLLER} ` + --set image.tag=${CERT_MANAGER_TAG} ` + --set webhook.image.repository=${ACR_URL}/${CERT_MANAGER_IMAGE_WEBHOOK} ` + --set webhook.image.tag=${CERT_MANAGER_TAG} ` + --set cainjector.image.repository=${ACR_URL}/${CERT_MANAGER_IMAGE_CAINJECTOR} ` + --set cainjector.image.tag=${CERT_MANAGER_TAG} \ No newline at end of file diff --git a/etc/k8s/azure/scripts/push-images.ps1 b/etc/k8s/azure/scripts/push-images.ps1 new file mode 100644 index 00000000..49bb9945 --- /dev/null +++ b/etc/k8s/azure/scripts/push-images.ps1 @@ -0,0 +1,36 @@ +param ($version='latest') + +az acr login --name volocr + +docker tag eshoponabp/app-web:$version volocr.azurecr.io/eshoponabp/app-web:$version +docker push volocr.azurecr.io/eshoponabp/app-web:$version + +docker tag eshoponabp/app-authserver:$version volocr.azurecr.io/eshoponabp/app-authserver:$version +docker push volocr.azurecr.io/eshoponabp/app-authserver:$version + +docker tag eshoponabp/app-publicweb:$version volocr.azurecr.io/eshoponabp/app-publicweb:$version +docker push volocr.azurecr.io/eshoponabp/app-publicweb:$version + +docker tag eshoponabp/gateway-web:$version volocr.azurecr.io/eshoponabp/gateway-web:$version +docker push volocr.azurecr.io/c:$version + +docker tag eshoponabp/gateway-web-public:$version volocr.azurecr.io/eshoponabp/gateway-web-public:$version +docker push volocr.azurecr.io/eshoponabp/gateway-web-public:$version + +docker tag eshoponabp/service-identity:$version volocr.azurecr.io/eshoponabp/service-identity:$version +docker push volocr.azurecr.io/eshoponabp/service-identity:$version + +docker tag eshoponabp/service-administration:$version volocr.azurecr.io/eshoponabp/service-administration:$version +docker push volocr.azurecr.io/eshoponabp/service-administration:$version + +docker tag eshoponabp/service-basket:$version volocr.azurecr.io/eshoponabp/service-basket:$version +docker push volocr.azurecr.io/eshoponabp/service-basket:$version + +docker tag eshoponabp/service-catalog:$version volocr.azurecr.io/eshoponabp/service-catalog:$version +docker push volocr.azurecr.io/eshoponabp/service-catalog:$version + +docker tag eshoponabp/service-ordering:$version volocr.azurecr.io/eshoponabp/service-ordering:$version +docker push volocr.azurecr.io/eshoponabp/service-ordering:$version + +docker tag eshoponabp/service-payment:$version volocr.azurecr.io/eshoponabp/service-payment:$version +docker push volocr.azurecr.io/eshoponabp/service-payment:$version \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml index 30e7e89e..03fcc9e8 100644 --- a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml @@ -7,14 +7,15 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt nginx.ingress.kubernetes.io/configuration-snippet: | more_set_input_headers "from-ingress: true"; spec: ingressClassName: nginx tls: - hosts: - - "eshop-st-authserver" - secretName: "eshop-wildcard-tls" + - {{ .Values.ingress.host }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml index a057014e..e66bd8ab 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-deployment.yaml @@ -18,6 +18,7 @@ spec: ports: - name: http containerPort: 80 + protocol: TCP - name: grpc containerPort: 81 protocol: TCP diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml index 28306a83..eae17053 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-service.yaml @@ -8,6 +8,8 @@ spec: ports: - name: "http" port: 80 + targetPort: http + protocol: TCP - name: grpc targetPort: grpc protocol: TCP diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml index a8d988f6..ccba5219 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml @@ -7,20 +7,21 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} -{{- if eq .Release.Name "es-az" }} - - {{ print "www." .Values.global.ingress.host }} +{{- if eq .Release.Name "eshop-az" }} + - {{ print "www." .Values.ingress.host }} {{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} - host: "{{ print "www." .Values.ingress.host }}" {{- else }} - host: "{{ .Values.ingress.host }}" diff --git a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml index 5d905823..6a55b3b1 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-configmap.yaml @@ -42,6 +42,18 @@ data: "Match": { "Path": "/api/setting-management/{**everything}" } + }, + "Catalog Service": { + "ClusterId": "catalogCluster", + "Match": { + "Path": "/api/catalog/{**everything}" + } + }, + "Ordering Service": { + "ClusterId": "orderingCluster", + "Match": { + "Path": "/api/ordering/{**everything}" + } } }, "Clusters": { @@ -86,6 +98,20 @@ data: "Address": "{{ .Values.reRoutes.administrationService.url }}" } } + }, + "catalogCluster": { + "Destinations": { + "destination1": { + "Address": "{{ .Values.reRoutes.catalogService.url }}" + } + } + }, + "orderingCluster": { + "Destinations": { + "destination1": { + "Address": "{{ .Values.reRoutes.orderingService.url }}" + } + } } } } diff --git a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml index 0dedb3d3..ccba5219 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml @@ -7,20 +7,21 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} - {{ print "www." .Values.ingress.host }} {{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} - host: "{{ print "www." .Values.ingress.host }}" {{- else }} - host: "{{ .Values.ingress.host }}" diff --git a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml index 49ac9ace..ab1df0f5 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml @@ -19,6 +19,10 @@ reRoutes: url: http://eshop-st-identity administrationService: url: http://eshop-st-administration + catalogService: + url: http://eshop-st-catalog + orderingService: + url: http://eshop-st-order ingress: host: # eshop-st-gateway-web tlsSecret: eshop-wildcard-tls diff --git a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/mongodb/templates/mongodb-deployment.yaml b/etc/k8s/eshoponabp/charts/mongodb/templates/mongodb-deployment.yaml index 53beb942..fc01540b 100644 --- a/etc/k8s/eshoponabp/charts/mongodb/templates/mongodb-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/mongodb/templates/mongodb-deployment.yaml @@ -16,7 +16,7 @@ spec: containers: - image: "mongo:4.2" name: {{ .Release.Name }}-{{ .Chart.Name }} -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} volumeMounts: - mountPath: "/data/db" name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume @@ -25,7 +25,7 @@ spec: ports: - name: mongo containerPort: 27017 -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} volumeClaimTemplates: - metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume diff --git a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml index de94cec3..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml @@ -7,12 +7,13 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml b/etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml index dba81cf4..50c455a6 100644 --- a/etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/postgres/templates/postgres-deployment.yaml @@ -16,7 +16,7 @@ spec: containers: - image: "postgres:14.1" name: {{ .Release.Name }}-{{ .Chart.Name }} -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} volumeMounts: - mountPath: "/var/opt/postgres" name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume @@ -28,7 +28,7 @@ spec: env: - name: POSTGRES_PASSWORD value: "myPassw0rd" -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} volumeClaimTemplates: - metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-database-volume diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml index 3519d65c..a6202ab9 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-deployment.yaml @@ -39,6 +39,8 @@ spec: value: "{{ .Values.config.rabbitmqHost }}" - name: "ElasticSearch__Url" value: "{{ .Values.config.elasticsearchHost }}" + - name: "ReverseProxy__Clusters__cluster1__Destinations__destination1__Address" + value: "{{ .Values.config.gatewayUrl }}" {{- if .Values.env }} {{ toYaml .Values.env | indent 8 }} {{- end }} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml index 18a5ed2f..ccba5219 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml @@ -7,23 +7,24 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} - {{ print "www." .Values.ingress.host }} {{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: -{{- if eq .Release.Name "es-az" }} +{{- if eq .Release.Name "eshop-az" }} - host: "{{ print "www." .Values.ingress.host }}" {{- else }} - - host: "{{ .Values.ingress.host }}" + - host: "{{ .Values.ingress.host }}" {{- end }} http: paths: diff --git a/etc/k8s/eshoponabp/charts/public-web/values.yaml b/etc/k8s/eshoponabp/charts/public-web/values.yaml index 390281e2..12e3ab42 100644 --- a/etc/k8s/eshoponabp/charts/public-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/values.yaml @@ -9,6 +9,7 @@ config: rabbitmqHost: eshop-st-rabbitmq elasticsearchHost: eshop-st-elasticsearch stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8 + ingress: host: eshop-st-public-web diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml index aa36193a..bdcbe997 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-configmap.yaml @@ -5,24 +5,24 @@ metadata: data: dynamic-env.json: |- { - "production": "true", - "application": { - "baseUrl": "{{ .Values.config.selfUrl }}", - "name": "EShopOnAbp", - "logoUrl": "" - }, - "oAuthConfig": { - "issuer": "{{ .Values.config.authServer.authority }}", - "redirectUri": "{{ .Values.config.selfUrl }}", - "requireHttps": "{{ .Values.config.authServer.requireHttpsMetadata }}", - "clientId": "Web", - "responseType": "code", - "scope": "offline_access openid profile email phone IdentityService AdministrationService" - }, - "apis": { - "default": { - "url": "{{ .Values.config.gatewayUrl }}", - "rootNamespace": "EShopOnAbp" - } - } + "production": "true", + "application": { + "baseUrl": "{{ .Values.config.selfUrl }}", + "name": "EShopOnAbp", + "logoUrl": "" + }, + "oAuthConfig": { + "issuer": "{{ .Values.config.authServer.authority }}", + "redirectUri": "{{ .Values.config.selfUrl }}", + "requireHttps": "{{ .Values.config.authServer.requireHttpsMetadata }}", + "clientId": "Web", + "responseType": "{{ .Values.config.authServer.responseType }}", + "scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService" + }, + "apis": { + "default": { + "url": "{{ .Values.config.gatewayUrl }}", + "rootNamespace": "EShopOnAbp" + } + } } \ No newline at end of file diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-deployment.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-deployment.yaml index cb7edabe..e9c29801 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-deployment.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-deployment.yaml @@ -22,7 +22,7 @@ spec: containerPort: 443 volumeMounts: - name: config-volume - mountPath: /app/dynamic-env.json + mountPath: /usr/share/nginx/html/dynamic-env.json subPath: dynamic-env.json env: {{- if .Values.env }} diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml index bbade7db..8482c393 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml @@ -7,24 +7,15 @@ metadata: nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" -{{- if eq .Release.Name "es-az" }} - nginx.ingress.kubernetes.io/from-to-www-redirect: "true" -{{- end }} + cert-manager.io/cluster-issuer: letsencrypt spec: ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} -{{- if eq .Release.Name "eh-es" }} - - {{ print "www." .Values.ingress.host }} -{{- end }} - secretName: {{ .Values.ingress.tlsSecret }} + secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls rules: -{{- if eq .Release.Name "eh-es" }} - - host: "{{ print "www." .Values.ingress.host }}" -{{- else }} - host: "{{ .Values.ingress.host }}" -{{- end }} http: paths: - path: / diff --git a/etc/k8s/eshoponabp/charts/web/values.yaml b/etc/k8s/eshoponabp/charts/web/values.yaml index 9a3418b7..604bc8fb 100644 --- a/etc/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/k8s/eshoponabp/charts/web/values.yaml @@ -1,10 +1,10 @@ config: - selfUrl: https://eshop-st-web - gatewayUrl: "https://eshop-st-gateway-web/" + selfUrl: https://admin.eshoponabp.com + gatewayUrl: https://www.gateway.eshoponabp.com/ authServer: - authority: http://eshop-st-authserver + authority: https://auth.eshoponabp.com requireHttpsMetadata: "false" - + responseType: "code" ingress: host: eshop-st-web tlsSecret: eshop-wildcard-tls @@ -15,4 +15,4 @@ image: pullPolicy: IfNotPresent # Extra environment variables or configurations -env: {} +env: {} \ No newline at end of file diff --git a/etc/k8s/eshoponabp/values.azure.yaml b/etc/k8s/eshoponabp/values.azure.yaml new file mode 100644 index 00000000..5dddcc35 --- /dev/null +++ b/etc/k8s/eshoponabp/values.azure.yaml @@ -0,0 +1,366 @@ +# auth-server sub-chart override +authserver: + config: + selfUrl: https://auth.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://identity.eshoponabp.com,https://administration.eshoponabp.com,https://basket.eshoponabp.com,https://catalog.eshoponabp.com,https://order.eshoponabp.com,https://payment.eshoponabp.com,https://admin.eshoponabp.com,https://eshoponabp.com + allowedRedirectUrls: https://admin.eshoponabp.com + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + connectionStrings: + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + identityService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + ingress: + host: auth.eshoponabp.com + tlsSecret: eshop-wildcard-tls + image: + repository: "volocr.azurecr.io/eshoponabp/app-authserver" + tag: latest + +# web sub-chart override +web: + config: + selfUrl: https://admin.eshoponabp.com + gatewayUrl: https://www.gateway.eshoponabp.com + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + responseType: "code" + ingress: + host: admin.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/app-web" + tag: latest + +# public-web sub-chart override +public-web: + config: + selfUrl: https://www.eshoponabp.com + gatewayUrl: https://www.gateway-public.eshoponabp.com/ + authServer: + authority: https://auth.eshoponabp.com + requireHttpsMetadata: "false" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + + ingress: + host: eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/app-publicweb" + tag: latest + +# identity-service sub-chart override +identity: + config: + selfUrl: https://identity.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com + connectionStrings: + identityService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false" + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + identityServerClients: # Seeded Clients + webRootUrl: https://admin.eshoponabp.com/ + publicWebRootUrl: https://www.eshoponabp.com/ + webGatewayRootUrl: https://www.gateway.eshoponabp.com/ + publicWebGatewayRootUrl: https://www.gateway-public.eshoponabp.com/ + identityServiceRootUrl: https://identity.eshoponabp.com/ + administrationServiceRootUrl: https://administration.eshoponabp.com/ + accountServiceRootUrl: https://auth.eshoponabp.com + basketServiceRootUrl: https://basket.eshoponabp.com/ + catalogServiceRootUrl: https://catalog.eshoponabp.com + orderingServiceRootUrl: https://order.eshoponabp.com + paymentServiceRootUrl: https://payment.eshoponabp.com + ingress: + host: identity.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-identity" + tag: latest + +# administration sub-chart override +administration: + config: + selfUrl: https://administration.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://eshop-az-gateway-internal + connectionStrings: + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + remoteServices: + abpIdentityBaseUrl: https://identity.eshoponabp.com + useCurrentToken: "false" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions + authority: https://auth.eshoponabp.com + ingress: + host: administration.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-administration" + tag: latest + +# gateway-web sub-chart override +gateway-web: + config: + selfUrl: https://www.gateway.eshoponabp.com + corsOrigins: https://admin.eshoponabp.com + globalConfigurationBaseUrl: http://eshop-az-gateway-public + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + ingress: + host: gateway.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/gateway-web" + tag: latest + reRoutes: + accountService: + url: http://eshop-az-authserver + identityService: + url: http://eshop-az-identity + administrationService: + url: http://eshop-az-administration + catalogService: + url: http://eshop-az-catalog + orderingService: + url: http://eshop-az-ordering + +# gateway-web-public sub-chart override +gateway-web-public: + config: + selfUrl: https://www.gateway-public.eshoponabp.com + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + ingress: + host: gateway-public.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/gateway-web-public" + tag: latest + reRoutes: + accountService: + url: http://eshop-az-authserver + identityService: + url: http://eshop-az-identity + administrationService: + url: http://eshop-az-administration + catalogService: + url: http://eshop-az-catalog + basketService: + url: http://eshop-az-basket + orderingService: + url: http://eshop-az-ordering + paymentService: + url: http://eshop-az-payment + +# basket-service sub-chart override +basket: + config: + selfUrl: https://basket.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://www.eshoponabp.com + connectionStrings: + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + remoteServices: + catalogBaseUrl: http://eshop-az-catalog:80 + catalogGrpcUrl: http://eshop-az-catalog:81 + ingress: + host: basket.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-basket" + tag: latest + +# catalog-service sub-chart override +catalog: + config: + selfUrl: https://catalog.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://www.eshoponabp.com,https://admin.eshoponabp.com + connectionStrings: + catalogService: "mongodb://eshop-az-mongodb/EShopOnAbp_Catalog" + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + kestrel: + httpUrl: http://eshop-az-catalog:80 + httpProtocols: Http1AndHttp2 + grpcUrl: http://eshop-az-catalog:81 + grpcProtocols: Http2 + ingress: + host: catalog.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-catalog" + tag: latest + +# ordering-service sub-chart override +ordering: + config: + selfUrl: https://order.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com + connectionStrings: + orderingService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false" + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + ingress: + host: order.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-ordering" + tag: latest + +# payment-service sub-chart override +payment: + config: + selfUrl: https://payment.eshoponabp.com + corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com + connectionStrings: + paymentService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false" + administrationService: "Host=eshop-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false" + authServer: + authority: http://eshop-az-authserver + requireHttpsMetadata: "false" + swaggerClientId: WebGateway_Swagger + swaggerClientSecret: "1q2w3e*" + dotnetEnv: Production + redisHost: eshop-az-redis + rabbitmqHost: eshop-az-rabbitmq + elasticsearchHost: eshop-az-elasticsearch + ingress: + host: payment.eshoponabp.com + image: + repository: "volocr.azurecr.io/eshoponabp/service-payment" + tag: latest + +# Default values for eshoponabp. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. + +replicaCount: 1 + +image: + repository: nginx + pullPolicy: IfNotPresent + # Overrides the image tag whose default is the chart appVersion. + tag: "" + +imagePullSecrets: [] +nameOverride: "" +fullnameOverride: "" + +serviceAccount: + # Specifies whether a service account should be created + create: true + # Annotations to add to the service account + annotations: {} + # The name of the service account to use. + # If not set and create is true, a name is generated using the fullname template + name: "" + +podAnnotations: {} + +podSecurityContext: {} + # fsGroup: 2000 + +securityContext: {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + +service: + type: ClusterIP + port: 80 + +ingress: + enabled: false + className: "" + annotations: {} + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: "true" + hosts: + - host: chart-example.local + paths: + - path: / + pathType: ImplementationSpecific + tls: [] + # - secretName: chart-example-tls + # hosts: + # - chart-example.local + +resources: {} + # We usually recommend not to specify default resources and to leave this as a conscious + # choice for the user. This also increases chances charts run on environments with little + # resources, such as Minikube. If you do want to specify resources, uncomment the following + # lines, adjust them as necessary, and remove the curly braces after 'resources:'. + # limits: + # cpu: 100m + # memory: 128Mi + # requests: + # cpu: 100m + # memory: 128Mi + +autoscaling: + enabled: false + minReplicas: 1 + maxReplicas: 100 + targetCPUUtilizationPercentage: 80 + # targetMemoryUtilizationPercentage: 80 + +nodeSelector: {} + +tolerations: [] + +affinity: {} \ No newline at end of file