Browse Source

Make administration sub-chart self-contained

pull/21/head
Gökhan Şengün 5 years ago
parent
commit
f83cec579d
  1. 53
      etc/k8s/eshoponabp/charts/administration/templates/administration-deploy.yaml
  2. 10
      etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml
  3. 31
      etc/k8s/eshoponabp/charts/administration/templates/administration.yaml
  4. 36
      etc/k8s/eshoponabp/charts/administration/values.yaml
  5. 2
      etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml
  6. 2
      etc/k8s/eshoponabp/charts/gateway-internal/templates/gateway-internal-ingress.yaml
  7. 2
      etc/k8s/eshoponabp/charts/gateway-public-web/templates/gateway-public-web-ingress.yaml
  8. 2
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml
  9. 2
      etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml
  10. 2
      etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml
  11. 2
      etc/k8s/eshoponabp/charts/saas/templates/saas-ingress.yaml
  12. 2
      etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml
  13. 9
      etc/k8s/eshoponabp/notes.md
  14. 24
      etc/k8s/eshoponabp/values.yaml
  15. 36
      etc/k8s/tls-cert/README.md
  16. 31
      etc/k8s/tls-cert/eshop-st-cert.pem
  17. 28
      etc/k8s/tls-cert/eshop-st-key.pem

53
etc/k8s/eshoponabp/charts/administration/templates/administration-deploy.yaml

@ -0,0 +1,53 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
selector:
matchLabels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
template:
metadata:
labels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
containers:
- image: {{ .Values.image.repository }}:{{ .Values.image.tag }}
imagePullPolicy: {{ .Values.image.pullPolicy }}
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
- name: https
containerPort: 443
env:
- name: App__SelfUrl
value: "{{ .Values.config.selfUrl }}"
- name: RemoteServices__Default__BaseUrl
value: "{{ .Values.config.gatewayUrl }}"
- name: App__CorsOrigins
value: "{{ .Values.config.corsOrigins }}"
- name: IdentityClients__IdentityClients__Authority
value: "{{ .Values.config.identityClientAuthority }}"
- name: "ConnectionStrings__AdministrationService"
value: {{ .Values.config.connString }}
- name: "ConnectionStrings__SaasService"
value: {{ .Values.config.saasService.connString }}
- name: "DOTNET_ENVIRONMENT"
value: "{{ .Values.config.dotnetEnv }}"
- name: "Redis__Configuration"
value: "{{ .Values.config.redisHost }}"
- name: "AuthServer__Authority"
value: "{{ .Values.config.authServerAuthority }}"
- name: "AuthServer__RequireHttpsMetadata"
value: "{{ .Values.config.authServerRequireHttpsMetadata }}"
- name: "StringEncryption__DefaultPassPhrase"
value: "{{ .Values.config.stringEncryptionDefaultPassPhrase }}"
- name: "RabbitMQ__Connections__Default__HostName"
value: "{{ .Values.config.rabbitmqHost }}"
- name: "ElasticSearch__Url"
value: "{{ .Values.config.elasticsearchHost }}"
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

10
etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml

@ -6,16 +6,16 @@ metadata:
kubernetes.io/ingress.class: "nginx"
nginx.ingress.kubernetes.io/rewrite-target: /
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: "{{ .Values.global.nginxProxyBufferSize }}"
nginx.ingress.kubernetes.io/proxy-buffers-number: "{{ .Values.global.nginxProxyBuffersNumber }}"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
tls:
- hosts:
- {{ .Values.global.administrationService.domain }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
rules:
- host: "{{ .Values.global.administrationService.domain }}"
- host: "{{ .Values.ingress.host }}"
http:
paths:
- path: /

31
etc/k8s/eshoponabp/charts/administration/templates/administration.yaml

@ -1,31 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
selector:
matchLabels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
template:
metadata:
labels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
containers:
- image: {{ .Values.global.administrationService.containerImage }}:{{ .Values.global.eshoponabpImageVersion }}
imagePullPolicy: {{ .Values.global.imagePullPolicy }}
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
- name: https
containerPort: 443
env:
{{ include "eshoponabp.global.env" . | indent 8 }}
- name: "ConnectionStrings__AdministrationService"
value: {{ .Values.global.administrationService.connString }}
- name: "ConnectionStrings__SaasService"
value: {{ .Values.global.saasService.connString }}
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

36
etc/k8s/eshoponabp/charts/administration/values.yaml

@ -1,10 +1,26 @@
env:
- name: "App__SelfUrl"
value: "https://eshop-st-administration"
- name: "App__CorsOrigins"
value: "https://eshop-st-gateway-web,https://eshop-st-gateway-public-web,https://eshop-st-gateway-internal"
- name: "RemoteServices__Default__BaseUrl"
value: "https://eshop-st-gateway-internal/"
- name: "IdentityClients__IdentityClients__Authority"
value: "https://eshop-st-authserver"
config:
selfUrl: # https://eshop-st-administration
gatewayUrl: # https://eshop-st-gateway-internal/
corsOrigins: # https://eshop-st-gateway-web,https://eshop-st-gateway-public-web,https://eshop-st-gateway-internal
identityClientAuthority: # https://eshop-st-authserver
connString: #
saasService:
connString: #
dotnetEnv: #
redisHost: #
rabbitmqHost: #
elasticsearchHost: #
authServerAuthority: #
authServerRequireHttpsMetadata: #
stringEncryptionDefaultPassPhrase: #
ingress:
host: # eshop-st-administration
tlsSecret: eshop-demo-tls
image:
repository: eshoponabp/service-administration
tag: latest
pullPolicy: IfNotPresent
env: {}

2
etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml

@ -15,7 +15,7 @@ spec:
tls:
- hosts:
- {{ .Values.global.authServer.domain }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
- host: "{{ .Values.global.authServer.domain }}"
http:

2
etc/k8s/eshoponabp/charts/gateway-internal/templates/gateway-internal-ingress.yaml

@ -19,7 +19,7 @@ spec:
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.global.gatewayInternal.domain }}
{{- end }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
{{- if eq .Release.Name "es-az" }}
- host: "{{ print "www." .Values.global.gatewayInternal.domain }}"

2
etc/k8s/eshoponabp/charts/gateway-public-web/templates/gateway-public-web-ingress.yaml

@ -19,7 +19,7 @@ spec:
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.global.gatewayPublicWeb.domain }}
{{- end }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
{{- if eq .Release.Name "es-az" }}
- host: "{{ print "www." .Values.global.gatewayPublicWeb.domain }}"

2
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml

@ -19,7 +19,7 @@ spec:
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.global.gatewayWeb.domain }}
{{- end }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
{{- if eq .Release.Name "es-az" }}
- host: "{{ print "www." .Values.global.gatewayWeb.domain }}"

2
etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml

@ -13,7 +13,7 @@ spec:
tls:
- hosts:
- {{ .Values.global.identityService.domain }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
- host: "{{ .Values.global.identityService.domain }}"
http:

2
etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml

@ -19,7 +19,7 @@ spec:
{{- if eq .Release.Name "eh-az" }}
- {{ print "www." .Values.global.publicWeb.domain }}
{{- end }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
{{- if eq .Release.Name "eh-az" }}
- host: "{{ print "www." .Values.global.publicWeb.domain }}"

2
etc/k8s/eshoponabp/charts/saas/templates/saas-ingress.yaml

@ -13,7 +13,7 @@ spec:
tls:
- hosts:
- {{ .Values.global.saasService.domain }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
- host: "{{ .Values.global.saasService.domain }}"
http:

2
etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml

@ -19,7 +19,7 @@ spec:
{{- if eq .Release.Name "eh-az" }}
- {{ print "www." .Values.global.web.domain }}
{{- end }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
secretName: {{ .Values.global.tlsSecret }}
rules:
{{- if eq .Release.Name "eh-az" }}
- host: "{{ print "www." .Values.global.web.domain }}"

9
etc/k8s/eshoponabp/notes.md

@ -0,0 +1,9 @@
# Notes
## Creating demo tls cert
```
kubectl create secret tls eshop-demo-tls \
--cert=eshop-st-cert.pem \
--key=eshop-st-key.pem
```

24
etc/k8s/eshoponabp/values.yaml

@ -86,10 +86,34 @@ tolerations: []
affinity: {}
# sub-chart overrides
administration:
config:
selfUrl: https://eshop-st-administration
gatewayUrl: https://eshop-st-gateway-internal/
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-public-web,https://eshop-st-gateway-internal
identityClientAuthority: https://eshop-st-authserver
connString: "Server=es-st-sqldb,1433;Database=EShopOnAbp_Administration;User Id=sa;password=myPassw@rd;MultipleActiveResultSets=true"
saasService:
connString: "Server=es-st-sqldb,1433;Database=EShopOnAbp_Saas;User Id=sa;password=myPassw@rd;MultipleActiveResultSets=true"
dotnetEnv: Staging
redisHost: es-st-redis
rabbitmqHost: es-st-rabbitmq
elasticsearchHost: es-st-elasticsearch
authServerAuthority: http://eshop-st-authserver
authServerRequireHttpsMetadata: "false"
stringEncryptionDefaultPassPhrase: gsKnGZ041HLL4IM8
ingress:
host: eshop-st-administration
image:
repository: "eshoponabp/service-administration"
tag: latest
global:
dotnetEnvironment: "Staging"
imagePullPolicy: Never
eshoponabpImageVersion: latest
tlsSecret: eshop-demo-tls
web:
domain: eshop-st-web
url: https://eshop-st-web

36
etc/k8s/tls-cert/README.md

@ -0,0 +1,36 @@
### Pre-requirements
* Docker Desktop with Kubernetes enabled
* Install [NGINX ingress](https://kubernetes.github.io/ingress-nginx/deploy/) for k8s
OR
* Install NGINX ingress using helm
```powershell
helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
helm repo update
helm install ingress-nginx ingress-nginx/ingress-nginx
```
* Install [Helm](https://helm.sh/docs/intro/install/) for running helm charts
### How to run?
* Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`):
````powershell
127.0.0.1 eshop-st-web
127.0.0.1 eshop-st-public-web
127.0.0.1 eshop-st-authserver
127.0.0.1 eshop-st-identity
127.0.0.1 eshop-st-administration
127.0.0.1 eshop-st-saas
127.0.0.1 eshop-st-gateway-web
127.0.0.1 eshop-st-gateway-public-web
127.0.0.1 eshop-st-gateway-internal
````
* Run `build-images.ps1` in the `scripts` directory.
* Run `deploy-staging.ps1` in the `helm-chart` directory. It is deployed with the `eventhub` namespace.
* *You may wait ~30 seconds on first run for preparing the database*.
* Browse https://eshoponabp-public-web and https://eshoponabp-authserver
* Username: `admin`, password: `1q2w3E*`.

31
etc/k8s/tls-cert/eshop-st-cert.pem

@ -0,0 +1,31 @@
-----BEGIN CERTIFICATE-----
MIIFQzCCA6ugAwIBAgIRANj5oNi+QQIoyV51y/ZIJlYwDQYJKoZIhvcNAQELBQAw
gZ8xHjAcBgNVBAoTFW1rY2VydCBkZXZlbG9wbWVudCBDQTE6MDgGA1UECwwxZ3Nl
bmd1bkBHb2toYW5zLU1hY0Jvb2stUHJvLmxvY2FsIChHb2toYW4gU2VuZ3VuKTFB
MD8GA1UEAww4bWtjZXJ0IGdzZW5ndW5AR29raGFucy1NYWNCb29rLVByby5sb2Nh
bCAoR29raGFuIFNlbmd1bikwHhcNMTkwNjAxMDAwMDAwWhcNMzExMTA0MDgyNjUw
WjBlMScwJQYDVQQKEx5ta2NlcnQgZGV2ZWxvcG1lbnQgY2VydGlmaWNhdGUxOjA4
BgNVBAsMMWdzZW5ndW5AR29raGFucy1NYWNCb29rLVByby5sb2NhbCAoR29raGFu
IFNlbmd1bikwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDKu7X3b2Cg
dpBnz90KboUnpWRcCK96oq97pAEbR9sirN3+3jT0JRBY2TYKLDPW8i50QJFbdYE7
zky58c+RWPrxVDoeqRC8E1+TLsuW+TdMmOL746k36X1VtKy3rqUG9IS6MXjH/MX8
H1kgldHvE9mFEpyp3q/8cUPHSBUE+M0CA05wlDm8qgkGXcp43qrNElWg5Y2WWWIp
WUm8r5obktSAxhA+ZxFX4cJHFmxKymMqSRStDpTFCIW9C3kx5ierPNQS6g5sSMtW
OuPuh0Uhc0Q0lJBoA7Mj1CGvtO5nld0+6kAK1GMB7Vbigoqd00eqKMYaA3Aa5QZm
bf84wZjofJx1AgMBAAGjggExMIIBLTAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAww
CgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBR6TnYaWT+NPghb
dQnZ+MAbx9UB2DCB1gYDVR0RBIHOMIHLgghlc2hvcC1zdIIXZXNob3Atc3QtYWRt
aW5pc3RyYXRpb26CE2VzaG9wLXN0LWF1dGhzZXJ2ZXKCGWVzaG9wLXN0LWdhdGV3
YXktaW50ZXJuYWyCG2VzaG9wLXN0LWdhdGV3YXktcHVibGljLXdlYoIUZXNob3At
c3QtZ2F0ZXdheS13ZWKCEWVzaG9wLXN0LWlkZW50aXR5ghNlc2hvcC1zdC1wdWJs
aWMtd2Vigg1lc2hvcC1zdC1zYWFzggxlc2hvcC1zdC13ZWIwDQYJKoZIhvcNAQEL
BQADggGBADjQroM3gD7g56S8bxlUbt1sJYfvo0VCIDPH9aHE3WwhGCOn18SRDOpM
mNw4c0HO+P1+rlCfn2pvN2oQ6v731fQZPpGcE0ljeVrixqfyVvoggGMbOwegvWPh
dPK/cxLi9wYfQtFw5vy8YxsinowSRCQ3KJGxI4fsyjEQu939WvYSPDdEUPx952LR
2pG8yRSso7dixDW4rDCoI/QKM/ImnqsNtZSpGa93HLgjkJr/PsOVMogt8dOsDOkC
vHq9F6TJKTDb7WizMJcE0qfisJgtTC2isvYA3u7kiyfxW26kd1h7s4m3njn+0Sks
0xGcXiYPZm8y/lVrxcF3/QlgOfWfRmls3D17yX28QwuwvNkUv2aSP/WGOMWEtgPD
9WYPk1OhOGFxT3IKu8iw6ITTCKXpcBeQ/QiEuFjo/khDGE4NMSkrp16nVebkAWal
/eufFWZJTzO7kgCmApS2SAhRdsM+JEsioHF/gM2chzV+eP4CCKv3pw5z07eemhx2
HnEbhDFHEA==
-----END CERTIFICATE-----

28
etc/k8s/tls-cert/eshop-st-key.pem

@ -0,0 +1,28 @@
-----BEGIN PRIVATE KEY-----
MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDKu7X3b2CgdpBn
z90KboUnpWRcCK96oq97pAEbR9sirN3+3jT0JRBY2TYKLDPW8i50QJFbdYE7zky5
8c+RWPrxVDoeqRC8E1+TLsuW+TdMmOL746k36X1VtKy3rqUG9IS6MXjH/MX8H1kg
ldHvE9mFEpyp3q/8cUPHSBUE+M0CA05wlDm8qgkGXcp43qrNElWg5Y2WWWIpWUm8
r5obktSAxhA+ZxFX4cJHFmxKymMqSRStDpTFCIW9C3kx5ierPNQS6g5sSMtWOuPu
h0Uhc0Q0lJBoA7Mj1CGvtO5nld0+6kAK1GMB7Vbigoqd00eqKMYaA3Aa5QZmbf84
wZjofJx1AgMBAAECggEBALvJLd9ZInbf/Bi8uLFt+BbmI1UAkpKU2Nk86+16HKg8
2ZC4APLY1hCGeoDnusjyIUd7e2jtKdzc1cMzEiI++orJiuBVl/OuOkxZ/ykEBU4F
G9NYaKkqtPbLWWT291O+8KaLJqaQJE/KNcNyIzhB+a1CtSy/4eGChNa1lQq67yJZ
iTFPNSHT1RTzjv2BAuUASq1gK+bX4F65otVYQBMg3JGsfkAdhWPbzEX0XLVpgbh/
jtyAHSsiWIkyVjXvA3Zjp+3Gmf3dbd/86Uwd4XowPfcSOP4iyd76FS4iTlthsF5D
M0psBOgotVl5RHv2ljOy7fUzrudnSQ0HepgdHed4Em0CgYEA7q+j7cbcb43ZW5Rx
p2pMuuuEeFY+L2Ns8N4t26OoURQCzyACR5H4KgFtrrdqTwQPs7L8SWAjU8SoP2jX
j+4+TJnK/Grt0YQ2pLpEM8j7kjGWfskHDfQhrL3o4VhdCm/1URWYSn7nzdNnX1Fk
ZlKjUJWBXGTvthCUVY9Jk30hU4sCgYEA2XBupvyIpmjoNdsEdwxxSebLyIYu2FA/
sjI5gdzXIOo9DsFfn9HTNbXyEsiQm9StNXS585jRhyht9OF7SYajrJ/E3O086tf4
2MmDbUdFdvMdPdGxxTU2mXa9Vd6JASnFG+fSsRhABk57iNzcUE4+PNW1ztLmRyLx
diW9cXjXz/8CgYBxGF43U0utu+uqvgqgRfj3dJL/JfYvJBBBjTTzZndhe3bdR5Bs
8xhAZw7eg1/m8six3/Q0nE4A6iTCbt38/+kbCKAqvEvVQ61UnkGku+2f1sk1Z/Fk
xjGSlSWcaO8k++mkMvRHEByr5SiM/Jby+OMTUtPJwLXocbCnXc6CCP9agwKBgEe7
I4XLAXmEWjaKDisH28e5b7izK3kI4Dp0/yusIvwkyge4G0ep/LdXUoiHyczemFVu
MHoAC/8+gyepyvYyiIRGILeRO+ttXBaIQ+ck//GBuj/OkYqxR1XRKhzN0PylPvU5
wPPTQCvUcERyN+v2I+oFxnh4cqc9C9MiGCD68JcZAoGBAIi1RxcWKZUCjSETT1PY
V7j5FIyMzBdUo0RN44eUdeu0CWAOnMG2s26z6fXl7EZp+Em5ee7dYEmSP49X69n9
T9ueN1LRJaqko45Eo3uPl6rolz5vXcTr2Tooc3yqE3XbRxe2jOeczq06nj06kjuf
hPPdSqjjOwWPy63DWboSkh+0
-----END PRIVATE KEY-----
Loading…
Cancel
Save