Files
fluxer/deploy/helm/gateway/templates/statefulsets.yaml
T

256 lines
11 KiB
YAML

{{- if dig "enabled" false .Values.roles }}
{{- $cluster := .Values.cluster | default dict -}}
{{- $distPort := int (dig "erlangDistribution" "port" 8081 $cluster) -}}
{{- $epmdPort := int (dig "erlangDistribution" "epmdPort" 4369 $cluster) -}}
{{- $cookie := dig "erlangCookieSecret" (dict) $cluster -}}
{{- $cookieName := get $cookie "name" | default "fluxer-gateway-erlang-cookie" -}}
{{- $cookieKey := get $cookie "key" | default "cookie" -}}
{{- $nodeBasename := dig "discoveryNodeBasename" "fluxer_gateway" $cluster -}}
{{- $dnsName := dig "discoveryDnsName" "" $cluster -}}
{{- if not $dnsName }}
{{- fail "cluster.discoveryDnsName is required when roles.enabled=true" }}
{{- end }}
{{- $pollIntervalMs := int (dig "discoveryPollIntervalMs" 5000 $cluster) -}}
{{- $gateway := .Values.gateway -}}
{{- $common := .Values.roles.common | default dict -}}
{{- $build := get $gateway "build" | default dict -}}
{{- $hotpatch := get $gateway "hotpatch" | default dict -}}
{{- $hotpatchPublicKeysSecret := get $hotpatch "publicKeysSecret" | default dict -}}
{{- $hotpatchCredentialsSecret := get $hotpatch "cassandraCredentialsSecret" | default dict -}}
{{- $roles := list "sessions" "presence" "guilds" "calls" "push" -}}
{{- range $role := $roles }}
{{- $roleValues := get $.Values.roles $role | default dict -}}
{{- if dig "enabled" true $roleValues }}
{{- $name := printf "gateway-%s" $role -}}
{{- $replicas := int (dig "replicas" (dig "replicas" 1 $common) $roleValues) -}}
{{- $resources := get $roleValues "resources" | default (get $common "resources" | default $gateway.resources) -}}
{{- $nodeSelector := get $roleValues "nodeSelector" | default (get $common "nodeSelector" | default $gateway.nodeSelector) -}}
{{- $tolerations := get $roleValues "tolerations" | default (get $common "tolerations" | default $gateway.tolerations) -}}
{{- $affinity := get $roleValues "affinity" | default (get $common "affinity" | default dict) -}}
{{- $topologySpreadConstraints := get $roleValues "topologySpreadConstraints" | default (get $common "topologySpreadConstraints" | default list) -}}
---
# SPDX-License-Identifier: AGPL-3.0-or-later
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: {{ $name }}
namespace: {{ $.Values.global.namespace }}
labels:
{{- include "fluxer.labels" $ | nindent 4 }}
{{- include "fluxer.selectorLabels" (dict "name" $name "context" $) | nindent 4 }}
spec:
serviceName: fluxer-gateway-headless
replicas: {{ $replicas }}
selector:
matchLabels:
{{- include "fluxer.selectorLabels" (dict "name" $name "context" $) | nindent 6 }}
updateStrategy:
type: RollingUpdate
template:
metadata:
labels:
{{- include "fluxer.labels" $ | nindent 8 }}
{{- include "fluxer.selectorLabels" (dict "name" $name "context" $) | nindent 8 }}
app.kubernetes.io/gateway-role: {{ $role | quote }}
spec:
{{- include "fluxer.imagePullSecrets" $ | nindent 6 }}
terminationGracePeriodSeconds: {{ int (dig "terminationGracePeriodSeconds" 45 $roleValues) }}
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
{{- if $affinity }}
affinity:
{{- toYaml $affinity | nindent 8 }}
{{- end }}
{{- if $topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml $topologySpreadConstraints | nindent 8 }}
{{- else }}
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: {{ $name }}
app.kubernetes.io/instance: {{ $.Release.Name }}
{{- end }}
{{- if $nodeSelector }}
nodeSelector:
{{- toYaml $nodeSelector | nindent 8 }}
{{- end }}
{{- if $tolerations }}
tolerations:
{{- toYaml $tolerations | nindent 8 }}
{{- end }}
containers:
- name: gateway
image: {{ include "fluxer.image" (dict "image" $gateway.image "tag" $gateway.tag "context" $) }}
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false
ports:
- name: http
containerPort: {{ $gateway.port }}
protocol: TCP
- name: epmd
containerPort: {{ $epmdPort }}
protocol: TCP
- name: erl-dist
containerPort: {{ $distPort }}
protocol: TCP
env:
- name: NODE_ENV
value: production
- name: FLUXER_ENV
value: production
- name: FLUXER_GATEWAY_ROLE
value: {{ $role | quote }}
- name: FLUXER_GATEWAY_CLUSTER_ENABLED
value: "true"
- name: FLUXER_GATEWAY_CLUSTER_DISCOVERY_DNS_NAME
value: {{ $dnsName | quote }}
- name: FLUXER_GATEWAY_CLUSTER_DISCOVERY_NODE_BASENAME
value: {{ $nodeBasename | quote }}
- name: FLUXER_GATEWAY_CLUSTER_DISCOVERY_POLL_INTERVAL_MS
value: {{ printf "%d" $pollIntervalMs | quote }}
- name: POD_IP
valueFrom:
fieldRef:
fieldPath: status.podIP
- name: FLUXER_ERLANG_NODE_NAME
value: {{ printf "%s@$(POD_IP)" $nodeBasename | quote }}
- name: FLUXER_ERLANG_DIST_PORT
value: {{ printf "%d" $distPort | quote }}
- name: FLUXER_ERLANG_COOKIE
valueFrom:
secretKeyRef:
name: {{ $cookieName }}
key: {{ $cookieKey }}
{{- if get $build "sha" }}
- name: BUILD_SHA
value: {{ get $build "sha" | quote }}
{{- end }}
{{- if get $build "number" }}
- name: BUILD_NUMBER
value: {{ get $build "number" | quote }}
{{- end }}
{{- if get $build "timestamp" }}
- name: BUILD_TIMESTAMP
value: {{ get $build "timestamp" | quote }}
{{- end }}
{{- if get $build "channel" }}
- name: RELEASE_CHANNEL
value: {{ get $build "channel" | quote }}
{{- end }}
{{- if dig "enabled" false $hotpatch }}
- name: FLUXER_GATEWAY_HOTPATCH_ENABLED
value: "true"
{{- if get $hotpatch "cassandraHosts" }}
- name: FLUXER_GATEWAY_HOTPATCH_CASSANDRA_HOSTS
value: {{ get $hotpatch "cassandraHosts" | quote }}
{{- end }}
- name: FLUXER_GATEWAY_HOTPATCH_CASSANDRA_PORT
value: {{ printf "%d" (int (get $hotpatch "cassandraPort" | default 9042)) | quote }}
- name: FLUXER_GATEWAY_HOTPATCH_CASSANDRA_KEYSPACE
value: {{ get $hotpatch "cassandraKeyspace" | default "fluxer" | quote }}
- name: FLUXER_GATEWAY_HOTPATCH_POLL_INTERVAL_MS
value: {{ printf "%d" (int (get $hotpatch "pollIntervalMs" | default 5000)) | quote }}
- name: FLUXER_GATEWAY_HOTPATCH_STARTUP_SYNC_TIMEOUT_MS
value: {{ printf "%d" (int (get $hotpatch "startupSyncTimeoutMs" | default 30000)) | quote }}
{{- if get $hotpatchPublicKeysSecret "name" }}
- name: FLUXER_GATEWAY_HOTPATCH_PUBLIC_KEYS
valueFrom:
secretKeyRef:
name: {{ get $hotpatchPublicKeysSecret "name" | quote }}
key: {{ get $hotpatchPublicKeysSecret "key" | default "public_keys" | quote }}
{{- end }}
{{- if get $hotpatchCredentialsSecret "name" }}
- name: FLUXER_GATEWAY_HOTPATCH_CASSANDRA_USERNAME
valueFrom:
secretKeyRef:
name: {{ get $hotpatchCredentialsSecret "name" | quote }}
key: {{ get $hotpatchCredentialsSecret "usernameKey" | default "username" | quote }}
- name: FLUXER_GATEWAY_HOTPATCH_CASSANDRA_PASSWORD
valueFrom:
secretKeyRef:
name: {{ get $hotpatchCredentialsSecret "name" | quote }}
key: {{ get $hotpatchCredentialsSecret "passwordKey" | default "password" | quote }}
{{- end }}
{{- end }}
{{- if $.Values.global.env }}
{{- toYaml $.Values.global.env | nindent 12 }}
{{- end }}
{{- if $gateway.env }}
{{- toYaml $gateway.env | nindent 12 }}
{{- end }}
{{- if $common.env }}
{{- toYaml $common.env | nindent 12 }}
{{- end }}
{{- if $roleValues.env }}
{{- toYaml $roleValues.env | nindent 12 }}
{{- end }}
{{- if or $.Values.global.envFrom $gateway.envFrom $common.envFrom $roleValues.envFrom }}
envFrom:
{{- if $.Values.global.envFrom }}
{{- toYaml $.Values.global.envFrom | nindent 12 }}
{{- end }}
{{- if $gateway.envFrom }}
{{- toYaml $gateway.envFrom | nindent 12 }}
{{- end }}
{{- if $common.envFrom }}
{{- toYaml $common.envFrom | nindent 12 }}
{{- end }}
{{- if $roleValues.envFrom }}
{{- toYaml $roleValues.envFrom | nindent 12 }}
{{- end }}
{{- end }}
lifecycle:
preStop:
exec:
command:
- /bin/sh
- -c
- {{ printf "curl -fsS --max-time 2 http://127.0.0.1:%d/_health/drain >/dev/null 2>&1 || true; sleep 20" (int $gateway.port) | quote }}
volumeMounts:
- name: keys
mountPath: /etc/fluxer/keys
readOnly: true
livenessProbe:
httpGet:
path: "/_health"
port: http
initialDelaySeconds: 10
periodSeconds: 15
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
exec:
command:
- /bin/sh
- -c
- {{ printf "curl -fsS --max-time 5 http://127.0.0.1:%d/_health/ready >/dev/null 2>&1 || exit 1" (int $gateway.port) | quote }}
initialDelaySeconds: 5
periodSeconds: 5
timeoutSeconds: 5
failureThreshold: 3
startupProbe:
httpGet:
path: "/_health"
port: http
initialDelaySeconds: 0
periodSeconds: 5
timeoutSeconds: 5
failureThreshold: 30
resources:
{{- toYaml $resources | nindent 12 }}
volumes:
- name: keys
secret:
secretName: fluxer-keys
optional: true
{{ end }}
{{ end }}
{{ end }}