Files

104 lines
2.8 KiB
YAML
Raw Permalink Normal View History

# 控制面 Deployment + Service(Phase 3:deployMode=k8s 起每用户 DSH Pod)。
# 依赖:secret `dsh-pg`(key: url = Postgres DSN)、`dsh-secret`(key: key =
# 共享加密密钥)、imagePullSecret `dsh-acr-pull`、ServiceAccount
# `dsh-orchestrator`(deploy/03-rbac.yaml)。镜像由 CI push 到 ACR。
apiVersion: apps/v1
kind: Deployment
metadata:
name: dsh-orchestrator
namespace: dsh
spec:
replicas: 3
selector:
matchLabels:
app: dsh-orchestrator
template:
metadata:
labels:
app: dsh-orchestrator
spec:
imagePullSecrets:
- name: dsh-acr-pull
serviceAccountName: dsh-orchestrator
containers:
- name: orchestrator
image: registry.example.com/dsh/dshs:0.2.0
imagePullPolicy: Always
args: ["--host", "0.0.0.0"]
env:
- name: DSHS_DB_URL
valueFrom:
secretKeyRef:
name: dsh-pg
key: url
- name: DSHS_SECRET
valueFrom:
secretKeyRef:
name: dsh-secret
key: key
- name: DSHS_SECURE_COOKIES
value: "true"
- name: DSHS_BASE_DOMAIN
value: "dsh.example.com"
- name: DSHS_COOKIE_DOMAIN
value: ".dsh.example.com"
- name: DSHS_DEPLOY_MODE
value: "k8s"
- name: DSHS_NAMESPACE
value: "dsh"
- name: DSHS_DSH_IMAGE
value: "registry.example.com/dsh/dsh:0.1.1-rc.2"
- name: DSHS_CONTROL_PLANE_IMAGE
value: "registry.example.com/dsh/dshs:0.2.0"
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
ports:
- containerPort: 3080
volumeMounts:
- name: tmp
mountPath: /tmp
securityContext:
runAsNonRoot: true
runAsUser: 65532
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
readOnlyRootFilesystem: true
resources:
requests:
cpu: "250m"
memory: "256Mi"
limits:
cpu: "1"
memory: "1Gi"
volumes:
- name: tmp
emptyDir: {}
---
apiVersion: v1
kind: Service
metadata:
name: dsh-orchestrator
namespace: dsh
spec:
selector:
app: dsh-orchestrator
ports:
- port: 3080
targetPort: 3080
type: ClusterIP
---
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: dsh-orchestrator
namespace: dsh
spec:
minAvailable: 2
selector:
matchLabels:
app: dsh-orchestrator