feat(k8s): Helm chart for the whole stack on a single-node cluster (refs #25)
One chart whose values.yaml is a near-literal transcription of infra/docker-compose.yml, rendered by three generic templates (Deployment, Job, Service) over a `workloads` map — so the two stacks can be diffed by eye instead of by archaeology, and adding a service is a values edit. Platform-forced deviations, each commented where it appears: - `args`, never `command`: compose replaces the image CMD, Kubernetes replaces the ENTRYPOINT. The chart fails to render on `command`, because the symptom (postgres refusing to run as root, Keycloak exec-ing `start-dev`) is nothing like the cause. - The four Django services apply their own setup_configuration in the web pod rather than in a separate init Job: both scripts migrate, and without compose's depends_on they race the same database. - OpenZaak and Objecten are addressed by service FQDN, because Django rejects a single-label host in a URL — the reason compose passes container IPs around. - NodePorts, no ingress; databases are emptyDir until persistence.storageClass is set, so the stack comes up on a cluster with no CSI driver. The upstream config inputs stay in the repo and become ConfigMaps via infra/helm/seed-configmaps.sh — the Kubernetes sibling of infra/seed-config.sh — so the compose stack and the chart cannot fork. infra/helm/registry.yaml runs an in-cluster registry because Talos cannot side-load an image and a laptop-side one needs a root-level firewall change.
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
{{- /*
|
||||
Service names are the compose service names, verbatim: the portals' Caddy
|
||||
proxies to http://bff:8080 and the upstream setup_configuration files name
|
||||
http://openzaak:8000 / http://nrc-web:8000, so in-cluster DNS has to answer to
|
||||
exactly those names. Do not rename a workload without checking both.
|
||||
|
||||
.Values.nodePorts is the single place a port is published outside the cluster;
|
||||
a workload listed there gets a NodePort on its first (only) port.
|
||||
*/ -}}
|
||||
{{- range $name, $w := .Values.workloads }}
|
||||
{{- if and (ne $w.enabled false) $w.ports }}
|
||||
{{- $nodePort := index $.Values.nodePorts $name }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ $name }}
|
||||
labels:
|
||||
{{- include "big.labels" (dict "root" $ "name" $name) | nindent 4 }}
|
||||
spec:
|
||||
type: {{ if $nodePort }}NodePort{{ else }}ClusterIP{{ end }}
|
||||
selector:
|
||||
app.kubernetes.io/name: {{ $name }}
|
||||
app.kubernetes.io/instance: {{ $.Release.Name }}
|
||||
ports:
|
||||
{{- range $i, $p := $w.ports }}
|
||||
- name: {{ $p.name }}
|
||||
port: {{ $p.port }}
|
||||
targetPort: {{ $p.targetPort | default $p.port }}
|
||||
{{- if and $nodePort (eq $i 0) }}
|
||||
nodePort: {{ $nodePort }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
Reference in New Issue
Block a user