ci: CICD-сборка (Gitea Actions: bootJar → docker → helm-publish) + helm-чарт
Build Media Mirror API / Build and publish (release) Successful in 27s
Build Media Mirror API / Build and publish (release) Successful in 27s
- workflow на release published: bootJar, build-docker (media-mirror/*), helm-publish (9.9.9 → tag) - helm: Chart.yaml placeholder 9.9.9, values, templates (deployment/service/configmap/secret) - env: DB, S3, Jellyfin через secret
This commit is contained in:
@@ -0,0 +1,35 @@
|
|||||||
|
name: 'Build Media Mirror API'
|
||||||
|
|
||||||
|
on:
|
||||||
|
release:
|
||||||
|
types: [published]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
deploy-dev:
|
||||||
|
name: 'Build and publish'
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: 'Checkout'
|
||||||
|
uses: https://github.com/actions/checkout@v4
|
||||||
|
|
||||||
|
- name: 'Config gradle repository replace'
|
||||||
|
uses: https://git.binom.pw/otp/devops/config-gradle@main
|
||||||
|
|
||||||
|
- name: 'Build bootJar'
|
||||||
|
uses: https://git.binom.pw/subochev/devops/build-gradle@main
|
||||||
|
with:
|
||||||
|
target: bootJar
|
||||||
|
|
||||||
|
- name: Build Docker Image
|
||||||
|
uses: https://git.binom.pw/subochev/devops/build-docker@main
|
||||||
|
with:
|
||||||
|
image_name: "media-mirror/api"
|
||||||
|
tags: latest ${{ gitea.ref_name }}
|
||||||
|
context: './'
|
||||||
|
|
||||||
|
- name: 'Publishing Helm'
|
||||||
|
uses: https://git.binom.pw/subochev/devops/helm-publish@main
|
||||||
|
with:
|
||||||
|
chart_directory: 'helm'
|
||||||
|
helm_version: ${{ gitea.ref_name }}
|
||||||
|
helm_version_placeholder: '9.9.9'
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: media-mirror-api
|
||||||
|
description: Координатор зеркал — REST API, очередь задач в Postgres
|
||||||
|
type: application
|
||||||
|
version: "9.9.9"
|
||||||
|
appVersion: "9.9.9"
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-main-config
|
||||||
|
data:
|
||||||
|
application.yaml: |
|
||||||
|
server:
|
||||||
|
port: {{ $.Values.port }}
|
||||||
|
forward-headers-strategy: framework
|
||||||
|
|
||||||
|
app:
|
||||||
|
jellyfin:
|
||||||
|
url: {{ $.Values.app.jellyfin.url | quote }}
|
||||||
|
s3:
|
||||||
|
url: {{ $.Values.app.s3.url | quote }}
|
||||||
|
access-key: ${S3_ACCESS_KEY}
|
||||||
|
secret-key: ${S3_SECRET_KEY}
|
||||||
|
bucket: {{ $.Values.app.s3.bucket }}
|
||||||
|
region: {{ $.Values.app.s3.region }}
|
||||||
|
prefix: {{ $.Values.app.s3.prefix }}
|
||||||
|
|
||||||
|
spring:
|
||||||
|
datasource:
|
||||||
|
url: jdbc:postgresql://{{ $.Values.db.host }}:{{ $.Values.db.port }}/{{ $.Values.db.name }}
|
||||||
|
username: ${DB_USER}
|
||||||
|
password: ${DB_PASSWORD}
|
||||||
|
hikari:
|
||||||
|
maximum-pool-size: {{ $.Values.db.maxConnections }}
|
||||||
|
flyway:
|
||||||
|
enabled: true
|
||||||
|
locations: classpath:db/migration
|
||||||
|
|
||||||
|
management:
|
||||||
|
server:
|
||||||
|
port: {{ $.Values.managementPort }}
|
||||||
|
endpoints:
|
||||||
|
web:
|
||||||
|
exposure:
|
||||||
|
include: env, health, info
|
||||||
@@ -0,0 +1,122 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: "{{ $.Release.Name }}-{{ $.Chart.Name }}"
|
||||||
|
labels:
|
||||||
|
{{- if $.Values.labels }}
|
||||||
|
{{- toYaml $.Values.labels | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/name: {{ $.Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ $.Release.Name }}
|
||||||
|
app.kubernetes.io/version: {{ $.Chart.AppVersion | quote }}
|
||||||
|
spec:
|
||||||
|
{{- if not $.Values.autoscaling.enabled }}
|
||||||
|
{{ if $.Values.replicaCount }}
|
||||||
|
replicas: {{ $.Values.replicaCount }}
|
||||||
|
{{ else }}
|
||||||
|
replicas: 1
|
||||||
|
{{ end }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app.kubernetes.io/name: {{ $.Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ $.Release.Name }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
annotations:
|
||||||
|
metric.binom.pw/enabled: '{{ $.Values.metrics }}'
|
||||||
|
{{ if ($.Values.metrics) }}
|
||||||
|
metric.binom.pw/url: ":{{ $.Values.managementPort }}/actuator/prometheus"
|
||||||
|
{{ end }}
|
||||||
|
{{- with $.Values.podAnnotations }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: {{ $.Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ $.Release.Name }}
|
||||||
|
spec:
|
||||||
|
{{- with $.Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
volumes:
|
||||||
|
- name: application-properties-volume
|
||||||
|
configMap:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-main-config
|
||||||
|
items:
|
||||||
|
- key: application.yaml
|
||||||
|
path: application.yaml
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml $.Values.podSecurityContext | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ $.Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml $.Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ $.Values.image.name }}:{{ default $.Chart.AppVersion $.Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ $.Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: SPRING_CONFIG_ADDITIONAL_LOCATION
|
||||||
|
value: "file:/opt/app/config/application.yaml"
|
||||||
|
- name: DB_USER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-secret
|
||||||
|
key: dbUser
|
||||||
|
- name: DB_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-secret
|
||||||
|
key: dbPassword
|
||||||
|
- name: DB_URL
|
||||||
|
value: "jdbc:postgresql://{{ $.Values.db.host }}:{{ $.Values.db.port }}/{{ $.Values.db.name }}"
|
||||||
|
- name: S3_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-secret
|
||||||
|
key: app.s3.accessKey
|
||||||
|
- name: S3_SECRET_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-secret
|
||||||
|
key: app.s3.secretKey
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: '/opt/app/config'
|
||||||
|
name: application-properties-volume
|
||||||
|
readOnly: true
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ $.Values.port }}
|
||||||
|
protocol: TCP
|
||||||
|
- name: management
|
||||||
|
containerPort: {{ $.Values.managementPort }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: '/actuator/health/liveness'
|
||||||
|
port: management
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
periodSeconds: 10
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: '/actuator/health/readiness'
|
||||||
|
port: management
|
||||||
|
initialDelaySeconds: 25
|
||||||
|
periodSeconds: 10
|
||||||
|
{{- if $.Values.resources }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml $.Values.resources | nindent 12 }}
|
||||||
|
{{- else }}
|
||||||
|
resources: { }
|
||||||
|
{{ end }}
|
||||||
|
{{- with $.Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with $.Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with $.Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ $.Release.Name }}-{{ $.Chart.Name }}-secret
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
dbUser: {{ (required "DB user не установлен" $.Values.db.user) | b64enc | quote }}
|
||||||
|
dbPassword: {{ (required "DB password не установлен" $.Values.db.password) | b64enc | quote }}
|
||||||
|
accessKey: {{ (required "Accesskey не установлен" $.Values.app.s3.accessKey) | b64enc | quote }}
|
||||||
|
secretKey: {{ (required "Secretkey не установлен" $.Values.app.s3.secretKey) | b64enc | quote }}
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: "{{ $.Release.Name }}-{{ $.Chart.Name }}"
|
||||||
|
labels:
|
||||||
|
{{- if $.Values.labels }}
|
||||||
|
{{- toYaml $.Values.labels | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/name: {{ $.Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ $.Release.Name }}
|
||||||
|
spec:
|
||||||
|
ports:
|
||||||
|
- port: {{ $.Values.port }}
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
- port: {{ $.Values.managementPort }}
|
||||||
|
protocol: TCP
|
||||||
|
name: management
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/name: {{ $.Chart.Name }}
|
||||||
|
app.kubernetes.io/instance: {{ $.Release.Name }}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
labels: []
|
||||||
|
metrics: true
|
||||||
|
managementPort: 9090
|
||||||
|
port: 8080
|
||||||
|
|
||||||
|
imagePullSecrets: null
|
||||||
|
|
||||||
|
image:
|
||||||
|
name: 'media-mirror/api'
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
db:
|
||||||
|
host: null
|
||||||
|
port: 5432
|
||||||
|
name: glasses
|
||||||
|
user: null
|
||||||
|
password: null
|
||||||
|
maxConnections: 10
|
||||||
|
|
||||||
|
app:
|
||||||
|
jellyfin:
|
||||||
|
url: null
|
||||||
|
s3:
|
||||||
|
url: null
|
||||||
|
accessKey: null
|
||||||
|
secretKey: null
|
||||||
|
bucket: media
|
||||||
|
region: us-east-1
|
||||||
|
prefix: mirror
|
||||||
|
|
||||||
|
securityContext:
|
||||||
|
privileged: false
|
||||||
Reference in New Issue
Block a user