summaryrefslogtreecommitdiffstats
path: root/kubernetes/aai/charts/aai-gizmo/templates/deployment.yaml
blob: 1e6871274974e8e2bb67da755f43b63e4335dad8 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
@media only all and (prefers-color-scheme: dark) {
.highlight .hll { background-color: #49483e }
.highlight .c { color: #75715e } /* Comment */
.highlight .err { color: #960050; background-color: #1e0010 } /* Error */
.highlight .k { color: #66d9ef } /* Keyword */
.highlight .l { color: #ae81ff } /* Literal */
.highlight .n { color: #f8f8f2 } /* Name */
.highlight .o { color: #f92672 } /* Operator */
.highlight .p { color: #f8f8f2 } /* Punctuation */
.highlight .ch { color: #75715e } /* Comment.Hashbang */
.highlight .cm { color: #75715e } /* Comment.Multiline */
.highlight .cp { color: #75715e } /* Comment.Preproc */
.highlight .cpf { color: #75715e } /* Comment.PreprocFile */
.highlight .c1 { color: #75715e } /* Comment.Single */
.highlight .cs { color: #75715e } /* Comment.Special */
.highlight .gd { color: #f92672 } /* Generic.Deleted */
.highlight .ge { font-style: italic } /* Generic.Emph */
.highlight .gi { color: #a6e22e } /* Generic.Inserted */
.highlight .gs { font-weight: bold } /* Generic.Strong */
.highlight .gu { color: #75715e } /* Generic.Subheading */
.highlight .kc { color: #66d9ef } /* Keyword.Constant */
.highlight .kd { color: #66d9ef } /* Keyword.Declaration */
.highlight .kn { color: #f92672 } /* Keyword.Namespace */
.highlight .kp { color: #66d9ef } /* Keyword.Pseudo */
.highlight .kr { color: #66d9ef } /* Keyword.Reserved */
.highlight .kt { color: #66d9ef } /* Keyword.Type */
.highlight .ld { color: #e6db74 } /* Literal.Date */
.highlight .m { color: #ae81ff } /* Literal.Number */
.highlight .s { color: #e6db74 } /* Literal.String */
.highlight .na { color: #a6e22e } /* Name.Attribute */
.highlight .nb { color: #f8f8f2 } /* Name.Builtin */
.highlight .nc { color: #a6e22e } /* Name.Class */
.highlight .no { color: #66d9ef } /* Name.Constant */
.highlight .nd { color: #a6e22e } /* Name.Decorator */
.highlight .ni { color: #f8f8f2 } /* Name.Entity */
.highlight .ne { color: #a6e22e } /* Name.Exception */
.highlight .nf { color: #a6e22e } /* Name.Function */
.highlight .nl { color: #f8f8f2 } /* Name.Label */
.highlight .nn { color: #f8f8f2 } /* Name.Namespace */
.highlight .nx { color: #a6e22e } /* Name.Other */
.highlight .py { color: #f8f8f2 } /* Name.Property */
.highlight .nt { color: #f92672 } /* Name.Tag */
.highlight .nv { color: #f8f8f2 } /* Name.Variable */
.highlight .ow { color: #f92672 } /* Operator.Word */
.highlight .w { color: #f8f8f2 } /* Text.Whitespace */
.highlight .mb { color: #ae81ff } /* Literal.Number.Bin */
.highlight .mf { color: #ae81ff } /* Literal.Number.Float */
.highlight .mh { color: #ae81ff } /* Literal.Number.Hex */
.highlight .mi { color: #ae81ff } /* Literal.Number.Integer */
.highlight .mo { color: #ae81ff } /* Literal.Number.Oct */
.highlight .sa { color: #e6db74 } /* Literal.String.Affix */
.highlight .sb { color: #e6db74 } /* Literal.String.Backtick */
.highlight .sc { color: #e6db74 } /* Literal.String.Char */
.highlight .dl { color: #e6db74 } /* Literal.String.Delimiter */
.highlight .sd { color: #e6db74 } /* Literal.String.Doc */
.highlight .s2 { color: #e6db74 } /* Literal.String.Double */
.highlight .se { color: #ae81ff } /* Literal.String.Escape */
.highlight .sh { color: #e6db74 } /* Literal.String.Heredoc */
.highlight .si { color: #e6db74 } /* Literal.String.Interpol */
.highlight .sx { color: #e6db74 } /* Literal.String.Other */
.highlight .sr { color: #e6db74 } /* Literal.String.Regex */
.highlight .s1 { color: #e6db74 } /* Literal.String.Single */
.highlight .ss { color: #e6db74 } /* Literal.String.Symbol */
.highlight .bp { color: #f8f8f2 } /* Name.Builtin.Pseudo */
.highlight .fm { color: #a6e22e } /* Name.Function.Magic */
.highlight .vc { color: #f8f8f2 } /* Name.Variable.Class */
.highlight .vg { color: #f8f8f2 } /* Name.Variable.Global */
.highlight .vi { color: #f8f8f2 } /* Name.Variable.Instance */
.highlight .vm { color: #f8f8f2 } /* Name.Variable.Magic */
.highlight .il { color: #ae81ff } /* Literal.Number.Integer.Long */
}
@media (prefers-color-scheme: light) {
.highlight .hll { background-color: #ffffcc }
.highlight .c { color: #888888 } /* Comment */
.highlight .err { color: #a61717; background-color: #e3d2d2 } /* Error */
.highlight .k { color: #008800; font-weight: bold } /* Keyword */
.highlight .ch { color: #888888 } /* Comment.Hashbang */
.highlight .cm { color: #888888 } /* Comment.Multiline */
.highlight .cp { color: #cc0000; font-weight: bold } /* Comment.Preproc */
.highlight .cpf { color: #888888 } /* Comment.PreprocFile */
.highlight .c1 { color: #888888 } /* Comment.Single */
.highlight .cs { color: #cc0000; font-weight: bold; background-color: #fff0f0 } /* Comment.Special */
.highlight .gd { color: #000000; background-color: #ffdddd } /* Generic.Deleted */
.highlight .ge { font-style: italic } /* Generic.Emph */
.highlight .gr { color: #aa0000 } /* Generic.Error */
.highlight .gh { color: #333333 } /* Generic.Heading */
.highlight .gi { color: #000000; background-color: #ddffdd } /* Generic.Inserted */
.highlight .go { color: #888888 } /* Generic.Output */
.highlight .gp { color: #555555 } /* Generic.Prompt */
.highlight .gs { font-weight: bold } /* Generic.Strong */
.highlight .gu { color: #666666 } /* Generic.Subheading */
.highlight .gt { color: #aa0000 } /* Generic.Traceback */
.highlight .kc { color: #008800; font-weight: bold } /* Keyword.Constant */
.highlight .kd { color: #008800; font-weight: bold } /* Keyword.Declaration */
.highlight .kn { color: #008800; font-weight: bold } /* Keyword.Namespace */
.highlight .kp { color: #008800 } /* Keyword.Pseudo */
.highlight .kr { color: #008800; font-weight: bold } /* Keywor
# Copyright © 2018 Amdocs, AT&T
# Modifications Copyright © 2018 Bell Canada
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#       http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: {{ include "common.fullname" . }}
  namespace: {{ include "common.namespace" . }}
  labels:
    app: {{ include "common.name" . }}
    chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
    release: {{ .Release.Name }}
    heritage: {{ .Release.Service }}
spec:
  replicas: {{ .Values.replicaCount }}
  template:
    metadata:
      labels:
        app: {{ include "common.name" . }}
        release: {{ .Release.Name }}
    spec:
    {{ if .Values.global.installSidecarSecurity }}
      hostAliases:
      - ip: {{ .Values.global.aaf.serverIp }}
        hostnames:
        - {{ .Values.global.aaf.serverHostname }}

      initContainers:
        - name: {{ .Values.global.tproxyConfig.name }}
          image: "{{ include "common.repository" . }}/{{ .Values.global.tproxyConfig.image }}"
          imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
          securityContext:
            privileged: true
    {{ end }}
      containers:
        - name: {{ .Chart.Name }}
          image: "{{ include "common.repository" . }}/{{ .Values.image }}"
          imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
          ports:
          - containerPort: {{ .Values.service.internalPort }}
          # disable liveness probe when breakpoints set in debugger
          # so K8s doesn't restart unresponsive container
          {{ if .Values.liveness.enabled }}
          livenessProbe:
            tcpSocket:
              port: {{ .Values.service.internalPort }}
            initialDelaySeconds: {{ .Values.liveness.initialDelaySeconds }}
            periodSeconds: {{ .Values.liveness.periodSeconds }}
          {{ end }}
          readinessProbe:
            tcpSocket:
              port: {{ .Values.service.internalPort }}
            initialDelaySeconds: {{ .Values.readiness.initialDelaySeconds }}
            periodSeconds: {{ .Values.readiness.periodSeconds }}
          env:
            - name: CONFIG_HOME
              value: /opt/app/crud-service/config/
            - name: KEY_STORE_PASSWORD
              valueFrom:
                secretKeyRef:
                  name: {{ template "common.fullname" . }}-pass
                  key: KEY_STORE_PASSWORD
            - name: KEY_MANAGER_PASSWORD
              valueFrom:
                secretKeyRef:
                  name: {{ template "common.fullname" . }}-pass
                  key: KEY_MANAGER_PASSWORD
            - name: SERVICE_BEANS
              value: /opt/app/crud-service/dynamic/conf
          volumeMounts:
          - mountPath: /etc/localtime
            name: localtime
            readOnly: true
          - mountPath: /opt/app/crud-service/config/crud-api.properties
            subPath: crud-api.properties
            name: {{ include "common.fullname" . }}-config
          - mountPath: /opt/app/crud-service/config/schemaIngest.properties
            subPath: schemaIngest.properties
            name: {{ include "common.fullname" . }}-config
          - mountPath: /opt/app/crud-service/config/model/
            name: {{ include "common.fullname" . }}-model-config
          - mountPath: /opt/app/crud-service/config/auth
            name: {{ include "common.fullname" . }}-auth-secret
          - mountPath: /opt/app/crud-service/dynamic/conf/crud-beans.xml
            name: {{ include "common.fullname" . }}-config
            subPath: crud-beans.xml
          - mountPath: /var/log/onap
            name: {{ include "common.fullname" . }}-logs
          - mountPath: /opt/app/crud-api/bundleconfig/etc/logback.xml
            name: {{ include "common.fullname" . }}-logback-config
            subPath: logback.xml
          resources:
{{ include "common.resources" . | indent 12 }}
        {{- if .Values.nodeSelector }}
        nodeSelector:
{{ toYaml .Values.nodeSelector | indent 10 }}
        {{- end -}}
        {{- if .Values.affinity }}
        affinity:
{{ toYaml .Values.affinity | indent 10 }}
        {{- end }}

        - name: filebeat-onap
          image: "{{ .Values.global.loggingRepository }}/{{ .Values.global.loggingImage }}"
          imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
          volumeMounts:
          - mountPath: /usr/share/filebeat/filebeat.yml
            name: filebeat-conf
            subPath: filebeat.yml
          - mountPath: /var/log/onap
            name: {{ include "common.fullname" . }}-logs
          - mountPath: /usr/share/filebeat/data
            name: {{ include "common.fullname" . }}-data-filebeat

    {{ if .Values.global.installSidecarSecurity }}
        - name: {{ .Values.global.rproxy.name }}
          image: "{{ include "common.repository" . }}/{{ .Values.global.rproxy.image }}"
          imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
          env:
          - name: CONFIG_HOME
            value: "/opt/app/rproxy/config"
          - name: KEY_STORE_PASSWORD
            value: {{ .Values.config.keyStorePassword }}
          - name: spring_profiles_active
            value: {{ .Values.global.rproxy.activeSpringProfiles }}
          volumeMounts:
          - name: {{ include "common.fullname" . }}-rproxy-config
            mountPath: /opt/app/rproxy/config/forward-proxy.properties
            subPath: forward-proxy.properties
          - name: {{ include "common.fullname" . }}-rproxy-config
            mountPath: /opt/app/rproxy/config/primary-service.properties
            subPath: primary-service.properties
          - name: {{ include "common.fullname" . }}-rproxy-config
            mountPath: /opt/app/rproxy/config/reverse-proxy.properties
            subPath: reverse-proxy.properties
          - name: {{ include "common.fullname" . }}-rproxy-config
            mountPath: /opt/app/rproxy/config/cadi.properties
            subPath: cadi.properties
          - name: {{ include "common.fullname" . }}-rproxy-log-config
            mountPath: /opt/app/rproxy/config/logback-spring.xml
            subPath: logback-spring.xml
          - name: {{ include "common.fullname" . }}-rproxy-auth-config
            mountPath: /opt/app/rproxy/config/auth/tomcat_keystore
            subPath: tomcat_keystore
          - name: {{ include "common.fullname" . }}-rproxy-auth-config
            mountPath: /opt/app/rproxy/config/auth/client-cert.p12
            subPath: client-cert.p12
          - name: {{ include "common.fullname" . }}-rproxy-auth-config
            mountPath: /opt/app/rproxy/config/auth/uri-authorization.json
            subPath: uri-authorization.json
          - name: {{ include "common.fullname" . }}-rproxy-auth-config
            mountPath: /opt/app/rproxy/config/auth/aaf_truststore.jks
            subPath: aaf_truststore.jks
          - name: {{ include "common.fullname" . }}-rproxy-security-config
            mountPath: /opt/app/rproxy/config/security/keyfile
            subPath: keyfile

          ports:
          - containerPort: {{ .Values.global.rproxy.port }}

        - name: {{ .Values.global.fproxy.name }}
          image: "{{ include "common.repository" . }}/{{ .Values.global.fproxy.image }}"
          imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
          env:
          - name: CONFIG_HOME
            value: "/opt/app/fproxy/config"
          - name: KEY_STORE_PASSWORD
            value: {{ .Values.config.keyStorePassword }}
          - name: spring_profiles_active
            value: {{ .Values.global.fproxy.activeSpringProfiles }}
          volumeMounts:
          - name: {{ include "common.fullname" . }}-fproxy-config
            mountPath: /opt/app/fproxy/config/fproxy.properties
            subPath: fproxy.properties
          - name: {{ include "common.fullname" . }}-fproxy-log-config
            mountPath: /opt/app/fproxy/config/logback-spring.xml
            subPath: logback-spring.xml
          - name: {{ include "common.fullname" . }}-fproxy-auth-config
            mountPath: /opt/app/fproxy/config/auth/tomcat_keystore
            subPath: tomcat_keystore
          - name: {{ include "common.fullname" . }}-fproxy-auth-config
            mountPath: /opt/app/fproxy/config/auth/client-cert.p12
            subPath: client-cert.p12
          ports:
          - containerPort: {{ .Values.global.fproxy.port }}
    {{ end }}

      volumes:
        - name: localtime
          hostPath:
            path: /etc/localtime
        - name: {{ include "common.fullname" . }}-data-filebeat
          emptyDir: {}
        - name: filebeat-conf
          configMap:
            name: {{ include "common.fullname" . }}-filebeat-configmap
        - name: {{ include "common.fullname" . }}-logs
          emptyDir: {}
        - name: {{ include "common.fullname" . }}-auth-secret
          secret:
            secretName: {{ include "common.fullname" . }}-auth
        - name: {{ include "common.fullname" . }}-config
          configMap:
            name: {{ include "common.fullname" . }}-configmap
            items:
            - key: crud-api.properties
              path: crud-api.properties
            - key: schemaIngest.properties
              path: schemaIngest.properties
            - key: crud-beans.xml
              path: crud-beans.xml
        - name: {{ include "common.fullname" . }}-logback-config
          configMap:
            name: {{ include "common.fullname" . }}-log-configmap
            items:
            - key: logback.xml
              path: logback.xml
        - name: {{ include "common.fullname" . }}-model-config
          configMap:
            name: {{ include "common.fullname" . }}-model-configmap
    {{ if .Values.global.installSidecarSecurity }}
        - name: {{ include "common.fullname" . }}-rproxy-config
          configMap:
            name: {{ include "common.fullname" . }}-rproxy-config
        - name: {{ include "common.fullname" . }}-rproxy-log-config
          configMap:
            name: {{ include "common.fullname" . }}-rproxy-log-config
        - name: {{ include "common.fullname" . }}-rproxy-auth-config
          secret:
            secretName: {{ include "common.fullname" . }}-rproxy-auth-config
        - name: {{ include "common.fullname" . }}-rproxy-security-config
          secret:
            secretName: {{ include "common.fullname" . }}-rproxy-security-config
        - name: {{ include "common.fullname" . }}-fproxy-config
          configMap:
            name: {{ include "common.fullname" . }}-fproxy-config
        - name: {{ include "common.fullname" . }}-fproxy-log-config
          configMap:
            name: {{ include "common.fullname" . }}-fproxy-log-config
        - name: {{ include "common.fullname" . }}-fproxy-auth-config
          secret:
            secretName: {{ include "common.fullname" . }}-fproxy-auth-config
    {{ end }}

      imagePullSecrets:
      - name: "{{ include "common.namespace" . }}-docker-registry-key"