One chart whose values.yaml is a near-literal transcription of infra/docker-compose.yml, rendered by three generic templates (Deployment, Job, Service) over a `workloads` map — so the two stacks can be diffed by eye instead of by archaeology, and adding a service is a values edit. Platform-forced deviations, each commented where it appears: - `args`, never `command`: compose replaces the image CMD, Kubernetes replaces the ENTRYPOINT. The chart fails to render on `command`, because the symptom (postgres refusing to run as root, Keycloak exec-ing `start-dev`) is nothing like the cause. - The four Django services apply their own setup_configuration in the web pod rather than in a separate init Job: both scripts migrate, and without compose's depends_on they race the same database. - OpenZaak and Objecten are addressed by service FQDN, because Django rejects a single-label host in a URL — the reason compose passes container IPs around. - NodePorts, no ingress; databases are emptyDir until persistence.storageClass is set, so the stack comes up on a cluster with no CSI driver. The upstream config inputs stay in the repo and become ConfigMaps via infra/helm/seed-configmaps.sh — the Kubernetes sibling of infra/seed-config.sh — so the compose stack and the chart cannot fork. infra/helm/registry.yaml runs an in-cluster registry because Talos cannot side-load an image and a laptop-side one needs a root-level firewall change.
26 lines
882 B
Plaintext
26 lines
882 B
Plaintext
{{ .Chart.Name }} {{ .Chart.Version }} deployed to namespace {{ .Release.Namespace }}.
|
|
|
|
Watch it converge (the upstream Django services migrate on first boot, so the
|
|
first bring-up takes a few minutes):
|
|
|
|
kubectl -n {{ .Release.Namespace }} get pods -w
|
|
kubectl -n {{ .Release.Namespace }} get jobs
|
|
|
|
Every bootstrap Job must reach Completions 1/1:
|
|
{{- range $name, $w := .Values.workloads }}
|
|
{{- if and (ne $w.enabled false) $w.job }}
|
|
- {{ $name }}
|
|
{{- end }}
|
|
{{- end }}
|
|
|
|
Open in a browser (add {{ .Values.host }} to /etc/hosts if you use a name):
|
|
{{- range $name, $port := .Values.nodePorts }}
|
|
{{- $w := index $.Values.workloads $name }}
|
|
{{- if ne $w.enabled false }}
|
|
{{ printf "%-16s http://%s:%v" $name $.Values.host $port }}
|
|
{{- end }}
|
|
{{- end }}
|
|
|
|
Test users are in docs/synthetic-data.md. If a pod is stuck in
|
|
ContainerCreating on a missing ConfigMap, run: make k8s-seed
|