-
Notifications
You must be signed in to change notification settings - Fork 5
/
deployment-worker.yaml
340 lines (340 loc) · 13 KB
/
deployment-worker.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "wordpress-bedrock.fullname" . }}-worker
labels:
{{ include "wordpress-bedrock.labels" . | indent 4 }}
app.kubernetes.io/component: "worker"
annotations:
{{- if .Values.wordpress.uptime }}
downscaler/uptime: {{.Values.wordpress.uptime}}
{{- end }}
spec:
replicas: {{ .Values.replicaCount }}
selector:
matchLabels:
{{- include "wordpress-bedrock.selectorLabels" . | nindent 6 }}
app.kubernetes.io/component: "worker"
template:
metadata:
labels:
{{- include "wordpress-bedrock.selectorLabels" . | nindent 8 }}
app.kubernetes.io/component: "worker"
{{- with .Values.podLabels }}
{{- toYaml . | nindent 8 }}
{{- end }}
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
checksum/secret: {{ include (print $.Template.BasePath "/secrets.yaml") . | sha256sum }}
{{- with .Values.podAnnotations }}
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
serviceAccountName: {{ template "wordpress-bedrock.serviceAccountName" . }}
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
# extend the pods shutdown grace period from the default of 30s to 60s
terminationGracePeriodSeconds: 60
initContainers:
- name: copy-files
securityContext:
runAsUser: 0
image: "{{ .Values.php.image.repository }}:{{ .Values.php.image.tag }}"
imagePullPolicy: {{ .Values.php.image.pullPolicy }}
command: ['sh', '-c', 'tar cf - . | (cd /tmp; tar xf -);chown -R www-data:2000 /tmp']
volumeMounts:
- name: web-volume
mountPath: /tmp
readOnly: false
resources:
{{- toYaml .Values.init.resources | nindent 12 }}
{{- if .Values.offload.privateKey.enabled }}
- name: prepare-private-key
securityContext:
runAsUser: 0
image: "{{ .Values.php.image.repository }}:{{ .Values.php.image.tag }}"
imagePullPolicy: {{ .Values.php.image.pullPolicy }}
command: ['sh', '-c']
args:
- if [ "$WP_OFFLOAD_PRIVATE_KEY_BASE64" = "" ]; then echo "please define WP_OFFLOAD_PRIVATE_KEY_BASE64"; exit 1; fi;
echo "$WP_OFFLOAD_PRIVATE_KEY_BASE64" | base64 -d > /tmp/"$WP_OFFLOAD_PRIVATE_KEY_FILE_NAME";
env:
- name: WP_OFFLOAD_PRIVATE_KEY_FILE_NAME
value: {{ .Values.offload.privateKey.fileName | quote }}
{{- range $key, $value := .Values.externalSecrets.env }}
{{- if (eq "WP_OFFLOAD_PRIVATE_KEY_BASE64" $key) }}
- name: {{ $key }}
valueFrom:
secretKeyRef:
name: {{ template "wordpress-bedrock.fullname" $ }}
key: {{ $key | lower | replace "_" "-" }}
{{- end }}
{{- end }}
volumeMounts:
- name: key-volume
mountPath: /tmp
readOnly: false
resources:
{{- toYaml .Values.init.resources | nindent 12 }}
{{- end }}
containers:
- name: {{ .Chart.Name }}-nginx
securityContext:
{{- toYaml .Values.nginx.securityContext | nindent 12 }}
image: "{{ .Values.nginx.image.repository }}:{{ .Values.nginx.image.tag }}"
imagePullPolicy: {{ .Values.nginx.image.pullPolicy }}
ports:
- name: http
containerPort: 8080
protocol: TCP
livenessProbe:
{{- toYaml .Values.nginx.livenessProbe | nindent 12 }}
readinessProbe:
{{- toYaml .Values.nginx.readinessProbe | nindent 12 }}
volumeMounts:
- name: config-volume
mountPath: /etc/nginx/conf.d/default.conf
subPath: nginx-default.conf
readOnly: true
- name: web-volume
mountPath: /var/www/html
readOnly: true
- name: uploads-volume
mountPath: /var/www/html/web/app/uploads
readOnly: false
- name: nginx-cache-volume
mountPath: /var/cache/nginx
readOnly: false
- name: nginx-var-run-volume
mountPath: /var/run
readOnly: false
{{- if .Values.nginx.extraVolumeMounts }}
{{- toYaml .Values.nginx.extraVolumeMounts | nindent 10 }}
{{- end }}
lifecycle:
preStop:
exec:
# SIGTERM triggers a quick exit; gracefully terminate instead
command:
- /bin/bash
- -c
- "sleep 30 && /usr/sbin/nginx -s quit"
resources:
{{- toYaml .Values.nginx.resources | nindent 12 }}
- name: {{ .Chart.Name }}-php-fpm
securityContext:
{{- toYaml .Values.php.securityContext | nindent 12 }}
image: "{{ .Values.php.image.repository }}:{{ .Values.php.image.tag }}"
imagePullPolicy: {{ .Values.php.image.pullPolicy }}
ports:
- name: fpm
containerPort: 9000
protocol: TCP
volumeMounts:
- name: config-volume
mountPath: /usr/local/etc/php-fpm.conf
subPath: php-fpm.conf
readOnly: true
- name: web-volume
mountPath: /var/www/html
readOnly: {{ .Values.php.readOnlyWebFilesystem }}
- name: uploads-volume
mountPath: /var/www/html/web/app/uploads
readOnly: false
- name: tmp-volume
mountPath: /tmp
readOnly: false
{{- if .Values.offload.privateKey.enabled }}
- name: key-volume
mountPath: {{ .Values.offload.privateKey.filePath }}
readOnly: true
{{- end }}
{{- if .Values.php.extraVolumeMounts }}
{{- toYaml .Values.php.extraVolumeMounts | nindent 10 }}
{{- end }}
lifecycle:
preStop:
exec:
command:
- /bin/bash
- -c
- "sleep 30"
env:
- name: AWS_ZONE
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: metadata.labels['topology.kubernetes.io/zone']
{{- if $.Values.offload.bucket }}
- name: WP_OFFLOAD_BUCKET
value: {{ $.Values.offload.bucket | quote }}
- name: WP_OFFLOAD_REGION
value: {{ $.Values.offload.region | quote }}
- name: WP_OFFLOAD_DOMAIN
value: {{ $.Values.offload.domain | quote }}
- name: WP_OFFLOAD_CLOUDFRONT
value: {{ $.Values.offload.cloudfront | quote }}
- name: WP_OFFLOAD_LOCAL_DOMAINS
value: {{ $.Values.offload.local_domains | quote }}
{{- end }}
{{- if $.Values.offload.privateKey.enabled }}
- name: WP_OFFLOAD_PRIVATE_KEY_FILE_PATH
value: {{ printf "%s%s" $.Values.offload.privateKey.filePath $.Values.offload.privateKey.fileName | quote }}
{{- end }}
- name: WP_DEFAULT_HOST
value: {{ index $.Values.ingress.hosts 0 "host" | quote }}
- name: WP_PLUGINS
value: {{ join " " $.Values.plugins | quote }}
{{- range $key, $value := .Values.externalSecrets.env }}
{{- if and (not (contains "WORDPRESS_" $key)) (not (contains "_ROOT_" $key)) (not (eq "WP_OFFLOAD_PRIVATE_KEY_BASE64" $key)) }}
- name: {{ $key }}
valueFrom:
secretKeyRef:
name: {{ template "wordpress-bedrock.fullname" $ }}
key: {{ $key | lower | replace "_" "-" }}
{{- end }}
{{- end }}
{{- with .Values.env }}
{{- range $key, $value := . }}
- name: {{ $key }}
value: {{ $value | quote }}
{{- end }}
{{- end }}
resources:
{{- toYaml .Values.php.resources | nindent 12 }}
{{- if ( .Values.monitoring.enabled ) }}
- name: {{ .Chart.Name }}-php-fpm-monitor
securityContext:
{{- toYaml .Values.exporter.phpfpm.securityContext | nindent 12 }}
image: "{{ .Values.exporter.phpfpm.image.repository }}:{{ .Values.exporter.phpfpm.image.tag }}"
imagePullPolicy: {{ .Values.exporter.phpfpm.image.pullPolicy }}
env:
- name: PHP_FPM_WEB_LISTEN_ADDRESS
value: ":{{ .Values.exporter.phpfpm.port }}"
- name: PHP_FPM_WEB_TELEMETRY_PATH
value: {{ .Values.exporter.phpfpm.metrics | quote }}
- name: PHP_FPM_SCRAPE_URI
value: {{ .Values.exporter.phpfpm.scrape_uri | quote }}
- name: PHP_FPM_FIX_PROCESS_COUNT
value: {{ .Values.exporter.phpfpm.fix_process_count | quote }}
- name: PHP_FPM_LOG_LEVEL
value: {{ .Values.exporter.phpfpm.log_level | quote }}
ports:
- name: php-fpm-metrics
containerPort: {{ .Values.exporter.phpfpm.port }}
protocol: TCP
livenessProbe:
httpGet:
path: /
port: php-fpm-metrics
resources:
{{ toYaml .Values.exporter.phpfpm.resources | indent 12 }}
- name: {{ .Chart.Name }}-nginx-monitor
securityContext:
{{- toYaml .Values.exporter.nginx.securityContext | nindent 12 }}
image: "{{ .Values.exporter.nginx.image.repository }}:{{ .Values.exporter.nginx.image.tag }}"
imagePullPolicy: {{ .Values.exporter.nginx.image.pullPolicy }}
env:
- name: LISTEN_ADDRESS
value: ":{{ .Values.exporter.nginx.port }}"
- name: TELEMETRY_PATH
value: {{ .Values.exporter.nginx.telemetry_path | quote }}
- name: NGINX_PLUS
value: {{ .Values.exporter.nginx.nginx_plus | quote }}
- name: SCRAPE_URI
value: {{ .Values.exporter.nginx.scrape_uri | quote }}
- name: SSL_VERIFY
value: {{ .Values.exporter.nginx.ssl_verify | quote }}
- name: TIMEOUT
value: {{ .Values.exporter.nginx.timeout | quote }}
- name: NGINX_RETRIES
value: {{ .Values.exporter.nginx.nginx_retries | quote }}
- name: NGINX_RETRY_INTERVAL
value: {{ .Values.exporter.nginx.nginx_retry_interval | quote }}
args:
- --nginx.scrape-uri={{ .Values.exporter.nginx.scrape_uri }}
ports:
- name: nginx-metrics
containerPort: {{ .Values.exporter.nginx.port }}
protocol: TCP
livenessProbe:
httpGet:
path: /metrics
port: nginx-metrics
resources:
{{ toYaml .Values.exporter.nginx.resources | indent 12 }}
{{- end }}
volumes:
- name: config-volume
configMap:
# Provide the name of the ConfigMap containing the files you want
# to add to the container
name: {{ include "wordpress-bedrock.fullname" . }}
- name: tmp-volume
emptyDir: {}
- name: nginx-cache-volume
emptyDir: {}
- name: nginx-var-run-volume
emptyDir: {}
- name: web-volume
emptyDir: {}
- name: uploads-volume
emptyDir: {}
{{- if .Values.offload.privateKey.enabled }}
- name: key-volume
emptyDir: {}
{{- end }}
{{- range $key, $value := .Values.php.extraVolumeMounts }}
{{- if not (contains "efs" $value.name ) }}
- name: {{ $value.name }}
emptyDir: {}
{{- end }}
{{- end }}
{{- if .Values.efs.enabled }}
- name: efs
persistentVolumeClaim:
claimName: {{ $.Release.Name }}
{{- end }}
{{- with .Values.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if .Values.karpenter.optimization }}
{{- include "wordpress-bedrock.archSelector" . | trim | nindent 6 }}
{{- else }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- end }}
topologySpreadConstraints:
- labelSelector:
matchLabels:
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/component: "worker"
{{- if semverCompare ">=1.27-0" $.Capabilities.KubeVersion.GitVersion }}
matchLabelKeys:
- pod-template-hash
{{- end }}
maxSkew: 1
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: ScheduleAnyway
- labelSelector:
matchLabels:
app.kubernetes.io/instance: {{ .Release.Name }}
app.kubernetes.io/component: "worker"
{{- if semverCompare ">=1.27-0" $.Capabilities.KubeVersion.GitVersion }}
matchLabelKeys:
- pod-template-hash
{{- end }}
maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: DoNotSchedule