Browse Source

chore: periodically renew the account website certificate

pull/89/head
berkansasmaz 5 years ago
parent
commit
8f6bf4605b
No known key found for this signature in database GPG Key ID: 884D815C3F32BE00
  1. 71
      etc/azure/renew-account-certificate-pipeline.yml
  2. 12
      etc/azure/scripts/renew-account-certificate.ps1
  3. 1
      etc/k8s/README.md

71
etc/azure/renew-account-certificate-pipeline.yml

@ -1,12 +1,75 @@
schedules: schedules:
- cron: 0 0 23 * * - cron: 0 0 23 * *
displayName: Monhtly renew the account website certificate displayName: Monthly renew the account website certificate
branches: branches:
include: include:
- main - main
steps: steps:
- task: PowerShell@2 - task: Kubernetes@1
displayName: Renew the certificate
inputs: inputs:
filePath: 'etc/azure/scripts/renew-account-certificate.ps1' connectionType: 'Azure Resource Manager'
azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)'
azureResourceGroup: 'volo'
kubernetesCluster: 'volo'
namespace: 'kube-system'
command: 'delete'
arguments: '-f etc/azure/scripts/corednsms.yaml --ignore-not-found=true'
secretType: 'dockerRegistry'
containerRegistryType: 'Azure Container Registry'
- task: Kubernetes@1
inputs:
connectionType: 'Azure Resource Manager'
azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)'
azureResourceGroup: 'volo'
kubernetesCluster: 'volo'
namespace: 'kube-system'
command: 'delete'
arguments: 'pod -l k8s-app=kube-dns --ignore-not-found=true'
secretType: 'dockerRegistry'
containerRegistryType: 'Azure Container Registry'
- task: Kubernetes@1
inputs:
connectionType: 'Azure Resource Manager'
azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)'
azureResourceGroup: 'volo'
kubernetesCluster: 'volo'
namespace: 'kube-system'
command: 'rollout'
arguments: 'status deployment coredns'
secretType: 'dockerRegistry'
containerRegistryType: 'Azure Container Registry'
- task: Kubernetes@1
inputs:
continueOnError: true
connectionType: 'Azure Resource Manager'
azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)'
azureResourceGroup: 'volo'
kubernetesCluster: 'volo'
namespace: 'eventhub'
command: 'delete'
arguments: 'certificate eh-az-account-tls'
secretType: 'dockerRegistry'
containerRegistryType: 'Azure Container Registry'
- task: Kubernetes@1
inputs:
connectionType: 'Azure Resource Manager'
azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)'
azureResourceGroup: 'volo'
kubernetesCluster: 'volo'
namespace: 'kube-system'
command: 'apply'
arguments: '-f etc/azure/scripts/corednsms.yaml'
secretType: 'dockerRegistry'
containerRegistryType: 'Azure Container Registry'
- task: Kubernetes@1
inputs:
connectionType: 'Azure Resource Manager'
azureSubscriptionEndpoint: 'volosoft (fe02ef9f-9e1c-4e40-b924-505981688dd8)'
azureResourceGroup: 'volo'
kubernetesCluster: 'volo'
namespace: 'kube-system'
command: 'delete'
arguments: 'pod -l k8s-app=kube-dns'
secretType: 'dockerRegistry'
containerRegistryType: 'Azure Container Registry'

12
etc/azure/scripts/renew-account-certificate.ps1

@ -1,12 +0,0 @@
$currentFolder = $PSScriptRoot
Set-Location $currentFolder
kubectl delete -f .\corednsms.yaml --ignore-not-found=true
kubectl delete pod --namespace kube-system -l k8s-app=kube-dns --ignore-not-found=true
kubectl rollout status deployment --namespace kube-system coredns
kubectl delete certificate eh-az-account-tls
sleep 60
kubectl apply -f .\corednsms.yaml
kubectl delete pod --namespace kube-system -l k8s-app=kube-dns

1
etc/k8s/README.md

@ -18,6 +18,7 @@
* Run `build-images.ps1` in the `scripts` directory. * Run `build-images.ps1` in the `scripts` directory.
* Run `minikube-load-images.ps1` in the `scripts` directory(only for `minikube`). * Run `minikube-load-images.ps1` in the `scripts` directory(only for `minikube`).
* Run `kubectl config set-context --current --namespace=eventhub`
* Run `deploy-staging.ps1` in the `helm-chart` directory. It is deployed with the `eventhub` namespace. * Run `deploy-staging.ps1` in the `helm-chart` directory. It is deployed with the `eventhub` namespace.
* *You may wait ~30 seconds on first run for preparing the database*. * *You may wait ~30 seconds on first run for preparing the database*.
* Browse https://eh-st-www and https://eh-st-admin * Browse https://eh-st-www and https://eh-st-admin

Loading…
Cancel
Save