Переделка CI/CD

This commit is contained in:
2025-09-09 12:43:41 +03:00
parent 68bf3f9056
commit 9c8261d031
6 changed files with 398 additions and 213 deletions
+27 -31
View File
@@ -1,53 +1,49 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
app: "{{ .Chart.Name }}"
stand: "{{ .Values.stand }}"
name: "{{ .Chart.Name }}"
app: '{{ .Chart.Name }}'
stand: '{{ .Values.stand }}'
name: '{{ .Chart.Name }}'
spec:
replicas: 1
selector:
matchLabels:
app: "{{ .Chart.Name }}"
stand: "{{ .Values.stand }}"
app: '{{ .Chart.Name }}'
stand: '{{ .Values.stand }}'
template:
metadata:
labels:
app: "{{ .Chart.Name }}"
stand: "{{ .Values.stand }}"
app: '{{ .Chart.Name }}'
stand: '{{ .Values.stand }}'
contragentCode: 'WZ01112'
billingObject: 'None'
spec:
{{- if .Values.vault.enabled }}
serviceAccountName: "{{ .Values.vault.serviceAccountName }}"
{{- if .Values.vault.enable }}
serviceAccountName: '{{ .Values.serviceAccountRole }}'
{{- end }}
containers:
# Основное приложение
- name: app
image: "{{ .Values.mainContainer.image.repository }}:{{ .Values.mainContainer.image.tag }}"
- image: '{{ .Values.deployment.image.repository }}:{{.Values.deployment.image.tag }}'
imagePullPolicy: IfNotPresent
name: app
ports:
- containerPort: {{ .Values.mainContainer.containerPort }}
protocol: TCP
resources:
{{- toYaml .Values.mainContainer.resources | nindent 12 }}
- containerPort: {{ .Values.deployment.containerPort }}
protocol: TCP
readinessProbe:
failureThreshold: 3
initialDelaySeconds: 10
periodSeconds: 30
successThreshold: 1
timeoutSeconds: 2
{{- toYaml .Values.mainContainer.readinessProbe | nindent 12 }}
{{- toYaml (omit .Values.deployment.readinessProbe "httpGet") | nindent 12 }}
httpGet:
{{- toYaml .Values.deployment.readinessProbe.httpGet | nindent 14 }}
port: {{ .Values.deployment.containerPort }}
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 30
periodSeconds: 10
successThreshold: 1
timeoutSeconds: 1
{{- toYaml .Values.mainContainer.livenessProbe | nindent 12 }}
{{- if .Values.vault.enabled }}
{{- toYaml (omit .Values.deployment.livenessProbe "tcpSocket") | nindent 12 }}
tcpSocket:
port: {{ .Values.deployment.containerPort }}
resources:
{{- toYaml .Values.deployment.resources | nindent 12 }}
{{- if .Values.vault.enable }}
envFrom:
- secretRef:
name: "{{ .Values.vault.target.name }}"
- secretRef:
name: '{{ .Chart.Name }}-secrets'
{{- end }}
+8 -8
View File
@@ -2,15 +2,15 @@
apiVersion: v1
kind: Service
metadata:
name: "{{ .Chart.Name }}"
name: '{{ .Chart.Name }}'
labels:
app: "{{ .Chart.Name }}"
stand: "{{ .Values.stand }}"
app: '{{ .Chart.Name }}'
stand: '{{ .Values.stand }}'
spec:
ports:
- port: {{ .Values.mainContainer.containerPort }}
targetPort: {{ .Values.mainContainer.containerPort }}
protocol: TCP
- port: {{ .Values.deployment.containerPort }}
targetPort: {{ .Values.deployment.containerPort }}
protocol: TCP
selector:
app: "{{ .Chart.Name }}"
stand: "{{ .Values.stand }}"
app: '{{ .Chart.Name }}'
stand: '{{ .Values.stand }}'
+13 -10
View File
@@ -1,20 +1,23 @@
{{- if .Values.vault.enabled }}
{{- if .Values.vault.enable }}
---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: "{{ .Chart.Name }}"
name: '{{ .Chart.Name }}'
labels:
app: '{{ .Chart.Name }}'
spec:
refreshInterval: "60s"
refreshInterval: '60s'
secretStoreRef:
name: "{{ .Values.vault.secretStore }}"
name: '{{ .Values.vault.secretStore }}' # имя SecretStore
kind: SecretStore
target:
name: "{{ .Values.vault.target.name }}"
name: '{{ .Chart.Name }}-secrets' # имя будущего секрета kubernetes
data:
{{- range .Values.vault.data }}
- secretKey: {{ .secretKey }}
{{- range .Values.vault.secrets }}
- secretKey: {{ . }}
remoteRef:
key: "{{ .remoteRef.key }}"
property: "{{ .remoteRef.property }}"
{{- end }}
key: "deck/kubernetes/{{ $.Values.stand }}/{{ $.Chart.Name }}"
property: {{ . }}
{{- end }}
{{- end }}