From 8f6bf4605b021bc7569a32c8d6aa2ec9f0385791 Mon Sep 17 00:00:00 2001 From: berkansasmaz Date: Mon, 31 Jan 2022 16:11:23 +0300 Subject: [PATCH] chore: periodically renew the account website certificate --- .../renew-account-certificate-pipeline.yml | 71 +++++++++++++++++-- .../scripts/renew-account-certificate.ps1 | 12 ---- etc/k8s/README.md | 1 + 3 files changed, 68 insertions(+), 16 deletions(-) delete mode 100644 etc/azure/scripts/renew-account-certificate.ps1 diff --git a/etc/azure/renew-account-certificate-pipeline.yml b/etc/azure/renew-account-certificate-pipeline.yml index 8683004..de8d92c 100644 --- a/etc/azure/renew-account-certificate-pipeline.yml +++ b/etc/azure/renew-account-certificate-pipeline.yml @@ -1,12 +1,75 @@ schedules: - cron: 0 0 23 * * - displayName: Monhtly renew the account website certificate + displayName: Monthly renew the account website certificate branches: include: - main steps: -- task: PowerShell@2 - displayName: Renew the certificate +- task: Kubernetes@1 inputs: - filePath: 'etc/azure/scripts/renew-account-certificate.ps1' + connectionType: 'Azure Resource Manager' + azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)' + azureResourceGroup: 'volo' + kubernetesCluster: 'volo' + namespace: 'kube-system' + command: 'delete' + arguments: '-f etc/azure/scripts/corednsms.yaml --ignore-not-found=true' + secretType: 'dockerRegistry' + containerRegistryType: 'Azure Container Registry' +- task: Kubernetes@1 + inputs: + connectionType: 'Azure Resource Manager' + azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)' + azureResourceGroup: 'volo' + kubernetesCluster: 'volo' + namespace: 'kube-system' + command: 'delete' + arguments: 'pod -l k8s-app=kube-dns --ignore-not-found=true' + secretType: 'dockerRegistry' + containerRegistryType: 'Azure Container Registry' +- task: Kubernetes@1 + inputs: + connectionType: 'Azure Resource Manager' + azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)' + azureResourceGroup: 'volo' + kubernetesCluster: 'volo' + namespace: 'kube-system' + command: 'rollout' + arguments: 'status deployment coredns' + secretType: 'dockerRegistry' + containerRegistryType: 'Azure Container Registry' +- task: Kubernetes@1 + inputs: + continueOnError: true + connectionType: 'Azure Resource Manager' + azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)' + azureResourceGroup: 'volo' + kubernetesCluster: 'volo' + namespace: 'eventhub' + command: 'delete' + arguments: 'certificate eh-az-account-tls' + secretType: 'dockerRegistry' + containerRegistryType: 'Azure Container Registry' +- task: Kubernetes@1 + inputs: + connectionType: 'Azure Resource Manager' + azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)' + azureResourceGroup: 'volo' + kubernetesCluster: 'volo' + namespace: 'kube-system' + command: 'apply' + arguments: '-f etc/azure/scripts/corednsms.yaml' + secretType: 'dockerRegistry' + containerRegistryType: 'Azure Container Registry' +- task: Kubernetes@1 + inputs: + connectionType: 'Azure Resource Manager' + azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)' + azureResourceGroup: 'volo' + kubernetesCluster: 'volo' + namespace: 'kube-system' + command: 'delete' + arguments: 'pod -l k8s-app=kube-dns' + secretType: 'dockerRegistry' + containerRegistryType: 'Azure Container Registry' diff --git a/etc/azure/scripts/renew-account-certificate.ps1 b/etc/azure/scripts/renew-account-certificate.ps1 deleted file mode 100644 index e560644..0000000 --- a/etc/azure/scripts/renew-account-certificate.ps1 +++ /dev/null @@ -1,12 +0,0 @@ -$currentFolder = $PSScriptRoot -Set-Location $currentFolder - -kubectl delete -f .\corednsms.yaml --ignore-not-found=true -kubectl delete pod --namespace kube-system -l k8s-app=kube-dns --ignore-not-found=true -kubectl rollout status deployment --namespace kube-system coredns -kubectl delete certificate eh-az-account-tls - -sleep 60 - -kubectl apply -f .\corednsms.yaml -kubectl delete pod --namespace kube-system -l k8s-app=kube-dns \ No newline at end of file diff --git a/etc/k8s/README.md b/etc/k8s/README.md index 15d3797..a1b57ca 100644 --- a/etc/k8s/README.md +++ b/etc/k8s/README.md @@ -18,6 +18,7 @@ * Run `build-images.ps1` in the `scripts` directory. * Run `minikube-load-images.ps1` in the `scripts` directory(only for `minikube`). +* Run `kubectl config set-context --current --namespace=eventhub` * Run `deploy-staging.ps1` in the `helm-chart` directory. It is deployed with the `eventhub` namespace. * *You may wait ~30 seconds on first run for preparing the database*. * Browse https://eh-st-www and https://eh-st-admin