# 控制面 Deployment + Service(Phase 3:deployMode=k8s 起每用户 DSH Pod)。 # 依赖:secret `dsh-pg`(key: url = Postgres DSN)、`dsh-secret`(key: key = # 共享加密密钥)、imagePullSecret `dsh-acr-pull`、ServiceAccount # `dsh-orchestrator`(deploy/03-rbac.yaml)。镜像由 CI push 到 ACR。 apiVersion: apps/v1 kind: Deployment metadata: name: dsh-orchestrator namespace: dsh spec: replicas: 3 selector: matchLabels: app: dsh-orchestrator template: metadata: labels: app: dsh-orchestrator spec: imagePullSecrets: - name: dsh-acr-pull serviceAccountName: dsh-orchestrator containers: - name: orchestrator image: registry.example.com/dsh/dshs:0.2.0 imagePullPolicy: Always args: ["--host", "0.0.0.0"] env: - name: DSHS_DB_URL valueFrom: secretKeyRef: name: dsh-pg key: url - name: DSHS_SECRET valueFrom: secretKeyRef: name: dsh-secret key: key - name: DSHS_SECURE_COOKIES value: "true" - name: DSHS_BASE_DOMAIN value: "dsh.example.com" - name: DSHS_COOKIE_DOMAIN value: ".dsh.example.com" - name: DSHS_DEPLOY_MODE value: "k8s" - name: DSHS_NAMESPACE value: "dsh" - name: DSHS_DSH_IMAGE value: "registry.example.com/dsh/dsh:0.1.1-rc.2" - name: DSHS_CONTROL_PLANE_IMAGE value: "registry.example.com/dsh/dshs:0.2.0" - name: POD_NAME valueFrom: fieldRef: fieldPath: metadata.name ports: - containerPort: 3080 volumeMounts: - name: tmp mountPath: /tmp securityContext: runAsNonRoot: true runAsUser: 65532 allowPrivilegeEscalation: false capabilities: drop: ["ALL"] seccompProfile: type: RuntimeDefault readOnlyRootFilesystem: true resources: requests: cpu: "250m" memory: "256Mi" limits: cpu: "1" memory: "1Gi" volumes: - name: tmp emptyDir: {} --- apiVersion: v1 kind: Service metadata: name: dsh-orchestrator namespace: dsh spec: selector: app: dsh-orchestrator ports: - port: 3080 targetPort: 3080 type: ClusterIP --- apiVersion: policy/v1 kind: PodDisruptionBudget metadata: name: dsh-orchestrator namespace: dsh spec: minAvailable: 2 selector: matchLabels: app: dsh-orchestrator