Compare commits
54 Commits
Author | SHA1 | Date | |
---|---|---|---|
066078f23c
|
|||
f201287a9b
|
|||
4fd8dd78ef
|
|||
16139755e5
|
|||
8e960419b4
|
|||
e23ece0d76
|
|||
499724ba76
|
|||
2fd3c801de
|
|||
da9a06dc24
|
|||
57e913d4e9
|
|||
623a5904f3
|
|||
adb6cdcdbc
|
|||
ab31f56380
|
|||
28b65a160b
|
|||
5c6845a914
|
|||
c63aa3490d
|
|||
9ab21f0e18
|
|||
4506628803
|
|||
795889afad
|
|||
27f10e0671
|
|||
249d067c0e
|
|||
2c71dfac86
|
|||
f0f439fb6d
|
|||
b8737c2583
|
|||
8baed7389c
|
|||
f61eb8acb7
|
|||
c153a0af33
|
|||
d6d129bb69
|
|||
71d7685549
|
|||
a0fc202e86
|
|||
4af74c77b2
|
|||
bee86998bd
|
|||
26d615632a
|
|||
69c6b30255
|
|||
c068eacf58
|
|||
89367e3169
|
|||
42e6830cca
|
|||
8e9a37b477
|
|||
7831c5da16
|
|||
8667d0571f
|
|||
bb7f309b34
|
|||
9b2d2f9522
|
|||
a30c6d7cb8
|
|||
20c34f3c76
|
|||
dc9b8b7cc7
|
|||
149b42825f
|
|||
2285def168
|
|||
a83fa30cd4
|
|||
37694a38d7
|
|||
3505820213
|
|||
69aa675f26
|
|||
4148b9910a
|
|||
f8050ca69e
|
|||
10c01f6ede
|
@ -19,11 +19,17 @@ jobs:
|
|||||||
checks: write
|
checks: write
|
||||||
contents: write
|
contents: write
|
||||||
steps:
|
steps:
|
||||||
|
- name: Login to Docker
|
||||||
|
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
|
||||||
|
with:
|
||||||
|
username: ${{ vars.DOCKERHUB_USERNAME }}
|
||||||
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: Ruby Setup
|
- name: Ruby Setup
|
||||||
uses: ruby/setup-ruby@v1
|
uses: ruby/setup-ruby@dffc446db9ba5a0c4446edb5bca1c5c473a806c5 # v1.235.0
|
||||||
with:
|
with:
|
||||||
ruby-version: '3.4'
|
ruby-version: '3.4'
|
||||||
bundler-cache: true
|
bundler-cache: true
|
||||||
@ -39,10 +45,10 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
|
|
||||||
- name: Test
|
- name: Test
|
||||||
uses: ruby/setup-ruby@v1
|
uses: ruby/setup-ruby@dffc446db9ba5a0c4446edb5bca1c5c473a806c5 # v1.235.0
|
||||||
with:
|
with:
|
||||||
ruby-version: '3.4'
|
ruby-version: '3.4'
|
||||||
bundler-cache: true
|
bundler-cache: true
|
||||||
@ -57,18 +63,50 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
DOCKER_ORG: ryanc
|
DOCKER_ORG: ryanc
|
||||||
DOCKER_LATEST: latest
|
DOCKER_LATEST: latest
|
||||||
|
defaults:
|
||||||
|
run:
|
||||||
|
shell: bash
|
||||||
|
outputs:
|
||||||
|
metadata: ${{ steps.output.outputs.metadata }}
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||||
with:
|
with:
|
||||||
fetch-depth: 0 # all history for all branches and tags
|
fetch-depth: 0 # all history for all branches and tags
|
||||||
|
|
||||||
- name: Docker meta
|
- name: Prepare
|
||||||
|
id: prep
|
||||||
|
run: |
|
||||||
|
VERSION="sha-${GITHUB_SHA::8}"
|
||||||
|
if [[ "$GITHUB_REF" == refs/tags/* ]]; then
|
||||||
|
VERSION="${GITHUB_REF/refs\/tags\//}"
|
||||||
|
fi
|
||||||
|
printf "GITHUB_REF=%s\n" "$GITHUB_REF"
|
||||||
|
printf "GITHUB_SHA=%s\n" "$GITHUB_SHA"
|
||||||
|
printf "VERSION=%s\n" "$VERSION" | tee -a "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
- name: Set up QEMU
|
||||||
|
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
|
||||||
|
|
||||||
|
- name: Set up Docker Buildx
|
||||||
|
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
|
||||||
|
|
||||||
|
- name: Login to Gitea registry
|
||||||
|
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
|
||||||
|
with:
|
||||||
|
registry: git.kill0.net
|
||||||
|
username: ${{ secrets.DOCKER_USERNAME }}
|
||||||
|
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||||
|
|
||||||
|
- name: Docker meta (debian)
|
||||||
id: meta
|
id: meta
|
||||||
uses: docker/metadata-action@v5
|
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
|
||||||
with:
|
with:
|
||||||
images: |
|
images: |
|
||||||
git.kill0.net/ryanc/kubernaut
|
git.kill0.net/ryanc/kubernaut
|
||||||
|
flavor: |
|
||||||
|
latest=auto
|
||||||
|
bake-target: docker-metadata-action
|
||||||
tags: |
|
tags: |
|
||||||
type=schedule
|
type=schedule
|
||||||
type=ref,event=branch
|
type=ref,event=branch
|
||||||
@ -78,19 +116,41 @@ jobs:
|
|||||||
type=semver,pattern={{major}}
|
type=semver,pattern={{major}}
|
||||||
type=sha
|
type=sha
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Docker meta (alpine)
|
||||||
uses: docker/setup-buildx-action@v3
|
id: meta-alpine
|
||||||
|
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
|
||||||
- name: Login to Gitea registry
|
|
||||||
uses: docker/login-action@v3
|
|
||||||
with:
|
with:
|
||||||
registry: git.kill0.net
|
images: |
|
||||||
username: ${{ secrets.DOCKER_USERNAME }}
|
git.kill0.net/ryanc/kubernaut
|
||||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
bake-target: docker-metadata-action-alpine
|
||||||
|
flavor: |
|
||||||
|
latest=auto
|
||||||
|
suffix=-alpine,onlatest=true
|
||||||
|
tags: |
|
||||||
|
type=schedule
|
||||||
|
type=ref,event=branch
|
||||||
|
type=ref,event=pr
|
||||||
|
type=semver,pattern={{version}}
|
||||||
|
type=semver,pattern={{major}}.{{minor}}
|
||||||
|
type=semver,pattern={{major}}
|
||||||
|
type=sha
|
||||||
|
|
||||||
- name: Docker build and push
|
- name: Docker build and push
|
||||||
uses: docker/build-push-action@v5
|
uses: docker/bake-action@76f9fa3a758507623da19f6092dc4089a7e61592 # v6.6.0
|
||||||
with:
|
with:
|
||||||
push: ${{ github.event_name != 'pull_request' }}
|
push: ${{ github.event_name != 'pull_request' }}
|
||||||
tags: ${{ steps.meta.outputs.tags }}
|
files: |
|
||||||
labels: ${{ steps.meta.outputs.labels }}
|
./docker-bake.hcl
|
||||||
|
cwd://${{ steps.meta.outputs.bake-file }}
|
||||||
|
cwd://${{ steps.meta-alpine.outputs.bake-file }}
|
||||||
|
|
||||||
|
- name: Setup Helm
|
||||||
|
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 # v4.3.0
|
||||||
|
|
||||||
|
- name: Publish Helm chart
|
||||||
|
if: ${{ contains(github.ref, 'refs/tags/') }}
|
||||||
|
run: |
|
||||||
|
HELM_VERSION="${{ steps.prep.outputs.VERSION }}"
|
||||||
|
HELM_VERSION="${HELM_VERSION#v}"
|
||||||
|
helm package charts/kubernaut
|
||||||
|
helm push "kubernaut-${HELM_VERSION}.tgz" oci://git.kill0.net/ryanc/helm-charts
|
||||||
|
40
Dockerfile
40
Dockerfile
@ -1,40 +0,0 @@
|
|||||||
FROM ruby:alpine AS base
|
|
||||||
|
|
||||||
WORKDIR /app
|
|
||||||
|
|
||||||
RUN <<EOT
|
|
||||||
gem update --system --no-document
|
|
||||||
gem install -N bundler
|
|
||||||
apk update
|
|
||||||
apk upgrade --no-cache
|
|
||||||
EOT
|
|
||||||
|
|
||||||
|
|
||||||
FROM base AS build
|
|
||||||
|
|
||||||
RUN <<EOT
|
|
||||||
apk add gcc musl-dev ruby-dev make
|
|
||||||
EOT
|
|
||||||
|
|
||||||
COPY Gemfile* .
|
|
||||||
|
|
||||||
RUN <<EOT
|
|
||||||
bundle config set --local without development
|
|
||||||
bundle install
|
|
||||||
EOT
|
|
||||||
|
|
||||||
|
|
||||||
FROM base
|
|
||||||
|
|
||||||
# RUN useradd ruby --home /app --shell /bin/sh
|
|
||||||
RUN adduser ruby -h /app -D
|
|
||||||
|
|
||||||
USER ruby:ruby
|
|
||||||
|
|
||||||
COPY --from=build /usr/local/bundle /usr/local/bundle
|
|
||||||
COPY --from=build --chown=ruby:ruby /app /app
|
|
||||||
|
|
||||||
COPY --chown=ruby:ruby . .
|
|
||||||
|
|
||||||
EXPOSE 4567
|
|
||||||
CMD [ "bundle", "exec", "rackup", "--host", "0.0.0.0", "--port", "4567" ]
|
|
1
Gemfile
1
Gemfile
@ -3,7 +3,6 @@ source "https://rubygems.org"
|
|||||||
gem "sinatra"
|
gem "sinatra"
|
||||||
gem "sinatra-contrib"
|
gem "sinatra-contrib"
|
||||||
gem "puma"
|
gem "puma"
|
||||||
gem "rackup"
|
|
||||||
|
|
||||||
gem "anyflake"
|
gem "anyflake"
|
||||||
gem "ksuid"
|
gem "ksuid"
|
||||||
|
54
Gemfile.lock
54
Gemfile.lock
@ -4,22 +4,22 @@ GEM
|
|||||||
anyflake (0.0.1)
|
anyflake (0.0.1)
|
||||||
ast (2.4.3)
|
ast (2.4.3)
|
||||||
base64 (0.2.0)
|
base64 (0.2.0)
|
||||||
bigdecimal (3.1.8)
|
bigdecimal (3.1.9)
|
||||||
csv (3.3.0)
|
csv (3.3.4)
|
||||||
diff-lcs (1.6.0)
|
diff-lcs (1.6.1)
|
||||||
httparty (0.22.0)
|
httparty (0.23.1)
|
||||||
csv
|
csv
|
||||||
mini_mime (>= 1.0.0)
|
mini_mime (>= 1.0.0)
|
||||||
multi_xml (>= 0.5.2)
|
multi_xml (>= 0.5.2)
|
||||||
json (2.10.2)
|
json (2.11.3)
|
||||||
jwt (2.10.1)
|
jwt (2.10.1)
|
||||||
base64
|
base64
|
||||||
ksuid (1.0.0)
|
ksuid (1.0.0)
|
||||||
language_server-protocol (3.17.0.4)
|
language_server-protocol (3.17.0.4)
|
||||||
lint_roller (1.1.0)
|
lint_roller (1.1.0)
|
||||||
logger (1.6.6)
|
logger (1.7.0)
|
||||||
mini_mime (1.1.5)
|
mini_mime (1.1.5)
|
||||||
minitest (5.25.4)
|
minitest (5.25.5)
|
||||||
multi_json (1.15.0)
|
multi_json (1.15.0)
|
||||||
multi_xml (0.7.1)
|
multi_xml (0.7.1)
|
||||||
bigdecimal (~> 3.1)
|
bigdecimal (~> 3.1)
|
||||||
@ -27,15 +27,15 @@ GEM
|
|||||||
ruby2_keywords (~> 0.0.1)
|
ruby2_keywords (~> 0.0.1)
|
||||||
nanoid (2.0.0)
|
nanoid (2.0.0)
|
||||||
nio4r (2.7.4)
|
nio4r (2.7.4)
|
||||||
parallel (1.26.3)
|
parallel (1.27.0)
|
||||||
parser (3.3.7.2)
|
parser (3.3.8.0)
|
||||||
ast (~> 2.4.1)
|
ast (~> 2.4.1)
|
||||||
racc
|
racc
|
||||||
prism (1.3.0)
|
prism (1.4.0)
|
||||||
puma (6.6.0)
|
puma (6.6.0)
|
||||||
nio4r (~> 2.0)
|
nio4r (~> 2.0)
|
||||||
racc (1.8.1)
|
racc (1.8.1)
|
||||||
rack (3.1.11)
|
rack (3.1.13)
|
||||||
rack-protection (4.1.1)
|
rack-protection (4.1.1)
|
||||||
base64 (>= 0.1.0)
|
base64 (>= 0.1.0)
|
||||||
logger (>= 1.6.0)
|
logger (>= 1.6.0)
|
||||||
@ -45,11 +45,9 @@ GEM
|
|||||||
rack (>= 3.0.0)
|
rack (>= 3.0.0)
|
||||||
rack-test (2.2.0)
|
rack-test (2.2.0)
|
||||||
rack (>= 1.3)
|
rack (>= 1.3)
|
||||||
rackup (2.2.1)
|
|
||||||
rack (>= 3)
|
|
||||||
rainbow (3.1.1)
|
rainbow (3.1.1)
|
||||||
rake (13.2.1)
|
rake (13.2.1)
|
||||||
rbs (3.8.1)
|
rbs (3.9.2)
|
||||||
logger
|
logger
|
||||||
regexp_parser (2.10.0)
|
regexp_parser (2.10.0)
|
||||||
rspec (3.13.0)
|
rspec (3.13.0)
|
||||||
@ -65,7 +63,7 @@ GEM
|
|||||||
diff-lcs (>= 1.2.0, < 2.0)
|
diff-lcs (>= 1.2.0, < 2.0)
|
||||||
rspec-support (~> 3.13.0)
|
rspec-support (~> 3.13.0)
|
||||||
rspec-support (3.13.2)
|
rspec-support (3.13.2)
|
||||||
rubocop (1.73.2)
|
rubocop (1.75.4)
|
||||||
json (~> 2.3)
|
json (~> 2.3)
|
||||||
language_server-protocol (~> 3.17.0.2)
|
language_server-protocol (~> 3.17.0.2)
|
||||||
lint_roller (~> 1.1.0)
|
lint_roller (~> 1.1.0)
|
||||||
@ -73,16 +71,17 @@ GEM
|
|||||||
parser (>= 3.3.0.2)
|
parser (>= 3.3.0.2)
|
||||||
rainbow (>= 2.2.2, < 4.0)
|
rainbow (>= 2.2.2, < 4.0)
|
||||||
regexp_parser (>= 2.9.3, < 3.0)
|
regexp_parser (>= 2.9.3, < 3.0)
|
||||||
rubocop-ast (>= 1.38.0, < 2.0)
|
rubocop-ast (>= 1.44.0, < 2.0)
|
||||||
ruby-progressbar (~> 1.7)
|
ruby-progressbar (~> 1.7)
|
||||||
unicode-display_width (>= 2.4.0, < 4.0)
|
unicode-display_width (>= 2.4.0, < 4.0)
|
||||||
rubocop-ast (1.41.0)
|
rubocop-ast (1.44.1)
|
||||||
parser (>= 3.3.7.2)
|
parser (>= 3.3.7.2)
|
||||||
rubocop-performance (1.24.0)
|
prism (~> 1.4)
|
||||||
|
rubocop-performance (1.25.0)
|
||||||
lint_roller (~> 1.1)
|
lint_roller (~> 1.1)
|
||||||
rubocop (>= 1.72.1, < 2.0)
|
rubocop (>= 1.75.0, < 2.0)
|
||||||
rubocop-ast (>= 1.38.0, < 2.0)
|
rubocop-ast (>= 1.38.0, < 2.0)
|
||||||
ruby-lsp (0.23.11)
|
ruby-lsp (0.23.15)
|
||||||
language_server-protocol (~> 3.17.0)
|
language_server-protocol (~> 3.17.0)
|
||||||
prism (>= 1.2, < 2.0)
|
prism (>= 1.2, < 2.0)
|
||||||
rbs (>= 3, < 4)
|
rbs (>= 3, < 4)
|
||||||
@ -102,19 +101,19 @@ GEM
|
|||||||
rack-protection (= 4.1.1)
|
rack-protection (= 4.1.1)
|
||||||
sinatra (= 4.1.1)
|
sinatra (= 4.1.1)
|
||||||
tilt (~> 2.0)
|
tilt (~> 2.0)
|
||||||
sorbet-runtime (0.5.11911)
|
sorbet-runtime (0.5.12043)
|
||||||
standard (1.47.0)
|
standard (1.49.0)
|
||||||
language_server-protocol (~> 3.17.0.2)
|
language_server-protocol (~> 3.17.0.2)
|
||||||
lint_roller (~> 1.0)
|
lint_roller (~> 1.0)
|
||||||
rubocop (~> 1.73.0)
|
rubocop (~> 1.75.2)
|
||||||
standard-custom (~> 1.0.0)
|
standard-custom (~> 1.0.0)
|
||||||
standard-performance (~> 1.7)
|
standard-performance (~> 1.8)
|
||||||
standard-custom (1.0.2)
|
standard-custom (1.0.2)
|
||||||
lint_roller (~> 1.0)
|
lint_roller (~> 1.0)
|
||||||
rubocop (~> 1.50)
|
rubocop (~> 1.50)
|
||||||
standard-performance (1.7.0)
|
standard-performance (1.8.0)
|
||||||
lint_roller (~> 1.1)
|
lint_roller (~> 1.1)
|
||||||
rubocop-performance (~> 1.24.0)
|
rubocop-performance (~> 1.25.0)
|
||||||
tilt (2.6.0)
|
tilt (2.6.0)
|
||||||
ulid (1.4.0)
|
ulid (1.4.0)
|
||||||
unicode-display_width (3.1.4)
|
unicode-display_width (3.1.4)
|
||||||
@ -137,7 +136,6 @@ DEPENDENCIES
|
|||||||
nanoid
|
nanoid
|
||||||
puma
|
puma
|
||||||
rack-test
|
rack-test
|
||||||
rackup
|
|
||||||
rake
|
rake
|
||||||
rspec
|
rspec
|
||||||
ruby-lsp
|
ruby-lsp
|
||||||
@ -148,4 +146,4 @@ DEPENDENCIES
|
|||||||
uuid7
|
uuid7
|
||||||
|
|
||||||
BUNDLED WITH
|
BUNDLED WITH
|
||||||
2.6.6
|
2.6.8
|
||||||
|
54
app.rb
54
app.rb
@ -2,6 +2,7 @@ require "bundler/setup"
|
|||||||
require "sinatra"
|
require "sinatra"
|
||||||
require "sinatra/cookies"
|
require "sinatra/cookies"
|
||||||
require "sinatra/multi_route"
|
require "sinatra/multi_route"
|
||||||
|
require "sinatra/quiet_logger"
|
||||||
require "time"
|
require "time"
|
||||||
require "fileutils"
|
require "fileutils"
|
||||||
require "json"
|
require "json"
|
||||||
@ -20,6 +21,8 @@ $LOAD_PATH.unshift File.dirname(__FILE__) + "/lib"
|
|||||||
|
|
||||||
require "config"
|
require "config"
|
||||||
|
|
||||||
|
VERSION = "0.2.1"
|
||||||
|
|
||||||
CHUNK_SIZE = 1024**2
|
CHUNK_SIZE = 1024**2
|
||||||
SESSION_SECRET_HEX_LENGTH = 64
|
SESSION_SECRET_HEX_LENGTH = 64
|
||||||
JWT_SECRET_HEX_LENGTH = 64
|
JWT_SECRET_HEX_LENGTH = 64
|
||||||
@ -50,9 +53,12 @@ DURATION_PARTS = [
|
|||||||
|
|
||||||
config = Config.new
|
config = Config.new
|
||||||
|
|
||||||
|
set :quiet_logger_prefixes, %w[livez readyz]
|
||||||
set :session_secret, config.session_secret.unwrap
|
set :session_secret, config.session_secret.unwrap
|
||||||
set :public_folder, __dir__ + "/static"
|
set :public_folder, __dir__ + "/static"
|
||||||
|
|
||||||
|
register Sinatra::QuietLogger
|
||||||
|
|
||||||
module Sinatra
|
module Sinatra
|
||||||
module RequestHeadersHelper
|
module RequestHeadersHelper
|
||||||
def req_headers
|
def req_headers
|
||||||
@ -111,7 +117,6 @@ class TickTock
|
|||||||
def initialize
|
def initialize
|
||||||
@pid = ppid
|
@pid = ppid
|
||||||
@procfs_f = format "/proc/%s/stat", @pid
|
@procfs_f = format "/proc/%s/stat", @pid
|
||||||
puts @pid
|
|
||||||
end
|
end
|
||||||
|
|
||||||
def uptime
|
def uptime
|
||||||
@ -162,7 +167,7 @@ class Sleep
|
|||||||
include State
|
include State
|
||||||
|
|
||||||
def initialize
|
def initialize
|
||||||
@file = "/dev/shm/sleep"
|
@file = "/dev/shm/sleepy"
|
||||||
end
|
end
|
||||||
|
|
||||||
def asleep?
|
def asleep?
|
||||||
@ -179,20 +184,11 @@ class Sleep
|
|||||||
end
|
end
|
||||||
|
|
||||||
def ppid
|
def ppid
|
||||||
pid = Process.pid
|
pid = ENV.fetch "PUMA_PID", Process.pid
|
||||||
# self
|
begin
|
||||||
ps = File.open "/proc/#{pid}/stat", &:readline
|
Integer pid
|
||||||
ps = ps.split(" ")
|
rescue ArgumentError
|
||||||
ppid = Integer(ps[3])
|
-1
|
||||||
|
|
||||||
# ppid
|
|
||||||
ps = File.open "/proc/#{ppid}/stat", &:readline
|
|
||||||
ps = ps.split(" ")
|
|
||||||
|
|
||||||
if ps[1].include? "ruby"
|
|
||||||
ppid
|
|
||||||
else
|
|
||||||
pid
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
@ -230,6 +226,8 @@ end
|
|||||||
|
|
||||||
enable :sessions
|
enable :sessions
|
||||||
|
|
||||||
|
puts "#{NAME} #{VERSION} staring, per aspera ad astra"
|
||||||
|
|
||||||
configure do
|
configure do
|
||||||
mime_type :json, "application/json"
|
mime_type :json, "application/json"
|
||||||
end
|
end
|
||||||
@ -303,31 +301,31 @@ get "/headers", provides: "json" do
|
|||||||
jsonify h, pretty:
|
jsonify h, pretty:
|
||||||
end
|
end
|
||||||
|
|
||||||
get "/livez" do
|
get "/uptime", provides: "json" do
|
||||||
error 503 unless Health.instance.healthy?
|
|
||||||
|
|
||||||
return Health.instance.to_json if request.env["HTTP_ACCEPT"] == "application/json"
|
|
||||||
|
|
||||||
Health.instance.to_s
|
|
||||||
end
|
|
||||||
|
|
||||||
get "/livez/uptime" do
|
|
||||||
tt = TickTock.new
|
tt = TickTock.new
|
||||||
x = {started_at: tt.started_at, seconds: tt.uptime.to_i, human: human_time(tt.uptime.to_i)}
|
x = {started_at: tt.started_at, seconds: tt.uptime.to_i, human: human_time(tt.uptime.to_i)}
|
||||||
|
|
||||||
jsonify x
|
jsonify x
|
||||||
end
|
end
|
||||||
|
|
||||||
post "/livez/toggle" do
|
post "/api/livez/toggle" do
|
||||||
Health.instance.toggle
|
Health.instance.toggle
|
||||||
"ok\n"
|
"ok\n"
|
||||||
end
|
end
|
||||||
|
|
||||||
post "/livez/sleep" do
|
post "/api/livez/sleep" do
|
||||||
Sleep.instance.toggle
|
Sleep.instance.toggle
|
||||||
"ok\n"
|
"ok\n"
|
||||||
end
|
end
|
||||||
|
|
||||||
|
get "/livez" do
|
||||||
|
error 503 unless Health.instance.healthy?
|
||||||
|
|
||||||
|
return Health.instance.to_json if request.env["HTTP_ACCEPT"] == "application/json"
|
||||||
|
|
||||||
|
Health.instance.to_s
|
||||||
|
end
|
||||||
|
|
||||||
get "/readyz" do
|
get "/readyz" do
|
||||||
error 503 unless Ready.instance.ready?
|
error 503 unless Ready.instance.ready?
|
||||||
|
|
||||||
@ -376,7 +374,7 @@ post "/halt" do
|
|||||||
nil
|
nil
|
||||||
end
|
end
|
||||||
|
|
||||||
get "/pid" do
|
get "/pid", provides: "json" do
|
||||||
pretty = params.key? :pretty
|
pretty = params.key? :pretty
|
||||||
|
|
||||||
jsonify({ppid: ppid, pid: Process.pid}, pretty:)
|
jsonify({ppid: ppid, pid: Process.pid}, pretty:)
|
||||||
|
23
charts/kubernaut/.helmignore
Normal file
23
charts/kubernaut/.helmignore
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
24
charts/kubernaut/Chart.yaml
Normal file
24
charts/kubernaut/Chart.yaml
Normal file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: kubernaut
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.2.1
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "0.2.1"
|
22
charts/kubernaut/templates/NOTES.txt
Normal file
22
charts/kubernaut/templates/NOTES.txt
Normal file
@ -0,0 +1,22 @@
|
|||||||
|
1. Get the application URL by running these commands:
|
||||||
|
{{- if .Values.ingress.enabled }}
|
||||||
|
{{- range $host := .Values.ingress.hosts }}
|
||||||
|
{{- range .paths }}
|
||||||
|
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else if contains "NodePort" .Values.service.type }}
|
||||||
|
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "kubernaut.fullname" . }})
|
||||||
|
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||||
|
echo http://$NODE_IP:$NODE_PORT
|
||||||
|
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||||
|
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||||
|
You can watch its status by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "kubernaut.fullname" . }}'
|
||||||
|
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "kubernaut.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
||||||
|
echo http://$SERVICE_IP:{{ .Values.service.port }}
|
||||||
|
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||||
|
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "kubernaut.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
||||||
|
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
||||||
|
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||||
|
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
||||||
|
{{- end }}
|
62
charts/kubernaut/templates/_helpers.tpl
Normal file
62
charts/kubernaut/templates/_helpers.tpl
Normal file
@ -0,0 +1,62 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "kubernaut.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "kubernaut.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "kubernaut.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "kubernaut.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "kubernaut.chart" . }}
|
||||||
|
{{ include "kubernaut.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "kubernaut.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "kubernaut.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "kubernaut.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "kubernaut.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
8
charts/kubernaut/templates/configmap.yaml
Normal file
8
charts/kubernaut/templates/configmap.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ .Release.Name }}-configmap
|
||||||
|
data:
|
||||||
|
{{- with.Values.cat }}
|
||||||
|
KUBERNAUT_CAT: {{ toYaml . }}
|
||||||
|
{{- end }}
|
78
charts/kubernaut/templates/deployment.yaml
Normal file
78
charts/kubernaut/templates/deployment.yaml
Normal file
@ -0,0 +1,78 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "kubernaut.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "kubernaut.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 8 }}
|
||||||
|
{{- with .Values.podLabels }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "kubernaut.serviceAccountName" . }}
|
||||||
|
{{- with .Values.podSecurityContext }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
{{- with .Values.securityContext }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
{{- with .Values.livenessProbe }}
|
||||||
|
livenessProbe:
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.readinessProbe }}
|
||||||
|
readinessProbe:
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.resources }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.volumeMounts }}
|
||||||
|
volumeMounts:
|
||||||
|
{{- toYaml . | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.volumes }}
|
||||||
|
volumes:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
32
charts/kubernaut/templates/hpa.yaml
Normal file
32
charts/kubernaut/templates/hpa.yaml
Normal file
@ -0,0 +1,32 @@
|
|||||||
|
{{- if .Values.autoscaling.enabled }}
|
||||||
|
apiVersion: autoscaling/v2
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: {{ include "kubernaut.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
scaleTargetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: {{ include "kubernaut.fullname" . }}
|
||||||
|
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||||
|
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||||
|
metrics:
|
||||||
|
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
target:
|
||||||
|
type: Utilization
|
||||||
|
averageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: memory
|
||||||
|
target:
|
||||||
|
type: Utilization
|
||||||
|
averageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
43
charts/kubernaut/templates/ingress.yaml
Normal file
43
charts/kubernaut/templates/ingress.yaml
Normal file
@ -0,0 +1,43 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ include "kubernaut.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.ingress.className }}
|
||||||
|
ingressClassName: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
{{- range .paths }}
|
||||||
|
- path: {{ .path }}
|
||||||
|
{{- with .pathType }}
|
||||||
|
pathType: {{ . }}
|
||||||
|
{{- end }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ include "kubernaut.fullname" $ }}
|
||||||
|
port:
|
||||||
|
number: {{ $.Values.service.port }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
15
charts/kubernaut/templates/service.yaml
Normal file
15
charts/kubernaut/templates/service.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "kubernaut.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "kubernaut.selectorLabels" . | nindent 4 }}
|
13
charts/kubernaut/templates/serviceaccount.yaml
Normal file
13
charts/kubernaut/templates/serviceaccount.yaml
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "kubernaut.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
automountServiceAccountToken: {{ .Values.serviceAccount.automount }}
|
||||||
|
{{- end }}
|
15
charts/kubernaut/templates/tests/test-connection.yaml
Normal file
15
charts/kubernaut/templates/tests/test-connection.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "kubernaut.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "kubernaut.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "kubernaut.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
123
charts/kubernaut/values.yaml
Normal file
123
charts/kubernaut/values.yaml
Normal file
@ -0,0 +1,123 @@
|
|||||||
|
# Default values for kubernaut.
|
||||||
|
# This is a YAML-formatted file.
|
||||||
|
# Declare variables to be passed into your templates.
|
||||||
|
|
||||||
|
# This will set the replicaset count more information can be found here: https://kubernetes.io/docs/concepts/workloads/controllers/replicaset/
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
# This sets the container image more information can be found here: https://kubernetes.io/docs/concepts/containers/images/
|
||||||
|
image:
|
||||||
|
repository: git.kill0.net/ryanc/kubernaut
|
||||||
|
# This sets the pull policy for images.
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: ""
|
||||||
|
|
||||||
|
# This is for the secrets for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||||
|
imagePullSecrets: []
|
||||||
|
# This is to override the chart name.
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
# This section builds out the service account more information can be found here: https://kubernetes.io/docs/concepts/security/service-accounts/
|
||||||
|
serviceAccount:
|
||||||
|
# Specifies whether a service account should be created
|
||||||
|
create: true
|
||||||
|
# Automatically mount a ServiceAccount's API credentials?
|
||||||
|
automount: true
|
||||||
|
# Annotations to add to the service account
|
||||||
|
annotations: {}
|
||||||
|
# The name of the service account to use.
|
||||||
|
# If not set and create is true, a name is generated using the fullname template
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
# This is for setting Kubernetes Annotations to a Pod.
|
||||||
|
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
|
||||||
|
podAnnotations: {}
|
||||||
|
# This is for setting Kubernetes Labels to a Pod.
|
||||||
|
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
|
||||||
|
podLabels: {}
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
# This is for setting up a service more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/
|
||||||
|
service:
|
||||||
|
# This sets the service type more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types
|
||||||
|
type: ClusterIP
|
||||||
|
# This sets the ports more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#field-spec-ports
|
||||||
|
port: 4567
|
||||||
|
|
||||||
|
# This block is for setting up the ingress for more information can be found here: https://kubernetes.io/docs/concepts/services-networking/ingress/
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: ""
|
||||||
|
annotations: {}
|
||||||
|
# kubernetes.io/ingress.class: nginx
|
||||||
|
# kubernetes.io/tls-acme: "true"
|
||||||
|
hosts:
|
||||||
|
- host:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: ImplementationSpecific
|
||||||
|
tls: []
|
||||||
|
# - secretName: chart-example-tls
|
||||||
|
# hosts:
|
||||||
|
# - chart-example.local
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
# requests:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
|
||||||
|
# This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /livez
|
||||||
|
port: http
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /readyz
|
||||||
|
port: http
|
||||||
|
|
||||||
|
# This section is for setting up autoscaling more information can be found here: https://kubernetes.io/docs/concepts/workloads/autoscaling/
|
||||||
|
autoscaling:
|
||||||
|
enabled: true
|
||||||
|
minReplicas: 2
|
||||||
|
maxReplicas: 100
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
# targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
# Additional volumes on the output Deployment definition.
|
||||||
|
volumes: []
|
||||||
|
# - name: foo
|
||||||
|
# secret:
|
||||||
|
# secretName: mysecret
|
||||||
|
# optional: false
|
||||||
|
|
||||||
|
# Additional volumeMounts on the output Deployment definition.
|
||||||
|
volumeMounts: []
|
||||||
|
# - name: foo
|
||||||
|
# mountPath: "/etc/foo"
|
||||||
|
# readOnly: true
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
5
config/puma.rb
Normal file
5
config/puma.rb
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
ENV["PUMA_PID"] = Process.pid.to_s
|
||||||
|
|
||||||
|
port ENV.fetch("PORT", 4567)
|
||||||
|
|
||||||
|
pidfile ENV["PIDFILE"] if ENV["PIDFILE"]
|
22
docker-bake.hcl
Normal file
22
docker-bake.hcl
Normal file
@ -0,0 +1,22 @@
|
|||||||
|
group "default" {
|
||||||
|
targets = [ "bookworm", "alpine" ]
|
||||||
|
}
|
||||||
|
|
||||||
|
target "docker-metadata-action" {}
|
||||||
|
target "docker-metadata-action-alpine" {}
|
||||||
|
|
||||||
|
target "_common" {
|
||||||
|
args = {
|
||||||
|
RUBY_VERSION = "3.4.3"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
target "bookworm" {
|
||||||
|
dockerfile = "./dockerfiles/bookworm.Dockerfile"
|
||||||
|
inherits = [ "_common", "docker-metadata-action" ]
|
||||||
|
}
|
||||||
|
|
||||||
|
target "alpine" {
|
||||||
|
dockerfile = "./dockerfiles/alpine.Dockerfile"
|
||||||
|
inherits = [ "_common", "docker-metadata-action-alpine" ]
|
||||||
|
}
|
51
dockerfiles/alpine.Dockerfile
Normal file
51
dockerfiles/alpine.Dockerfile
Normal file
@ -0,0 +1,51 @@
|
|||||||
|
ARG RUBY_VERSION="3.4.3"
|
||||||
|
FROM docker.io/library/ruby:${RUBY_VERSION}-alpine AS base
|
||||||
|
|
||||||
|
WORKDIR /kubernaut
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
apk update -q
|
||||||
|
apk add bash jemalloc
|
||||||
|
rm -rf /var/cache/apk
|
||||||
|
gem update --system --no-document
|
||||||
|
gem install -N bundler
|
||||||
|
EOT
|
||||||
|
|
||||||
|
ENV RACK_ENV="production" \
|
||||||
|
BUNDLE_DEPLOYMENT=true \
|
||||||
|
BUNDLE_PATH="/usr/local/bundle" \
|
||||||
|
BUNDLE_WITHOUT="development test"
|
||||||
|
|
||||||
|
FROM base AS build
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
apk add musl-dev gcc make
|
||||||
|
rm -rf /var/cache/apk
|
||||||
|
EOT
|
||||||
|
|
||||||
|
COPY Gemfile Gemfile.lock ./
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
bundle install
|
||||||
|
rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git
|
||||||
|
EOT
|
||||||
|
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
FROM base
|
||||||
|
|
||||||
|
ENV PORT=4567
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
addgroup --system --gid 666 kubernaut
|
||||||
|
adduser --system --uid 666 --ingroup kubernaut --shell /bin/bash --disabled-password kubernaut
|
||||||
|
EOT
|
||||||
|
|
||||||
|
COPY --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}"
|
||||||
|
COPY --from=build /kubernaut /kubernaut
|
||||||
|
|
||||||
|
USER kubernaut:kubernaut
|
||||||
|
|
||||||
|
EXPOSE $PORT
|
||||||
|
ENTRYPOINT [ "/kubernaut/dockerfiles/entrypoint.sh" ]
|
||||||
|
CMD [ "bundle", "exec", "puma" ]
|
52
dockerfiles/bookworm.Dockerfile
Normal file
52
dockerfiles/bookworm.Dockerfile
Normal file
@ -0,0 +1,52 @@
|
|||||||
|
ARG RUBY_VERSION="3.4.3"
|
||||||
|
FROM docker.io/library/ruby:${RUBY_VERSION}-slim-bookworm AS base
|
||||||
|
|
||||||
|
WORKDIR /kubernaut
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
apt-get update -qq
|
||||||
|
apt-get install --yes --no-install-recommends libjemalloc2
|
||||||
|
rm -rf /var/lib/apt/lists /var/cache/apt/archives
|
||||||
|
gem update --system --no-document
|
||||||
|
gem install -N bundler
|
||||||
|
EOT
|
||||||
|
|
||||||
|
ENV RACK_ENV="production" \
|
||||||
|
BUNDLE_DEPLOYMENT=true \
|
||||||
|
BUNDLE_PATH="/usr/local/bundle" \
|
||||||
|
BUNDLE_WITHOUT="development test"
|
||||||
|
|
||||||
|
FROM base AS build
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
apt-get update -qq
|
||||||
|
apt-get install --yes --no-install-recommends gcc make libc-dev
|
||||||
|
rm -rf /var/lib/apt/lists /var/cache/apt/archives
|
||||||
|
EOT
|
||||||
|
|
||||||
|
COPY Gemfile Gemfile.lock ./
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
bundle install
|
||||||
|
rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git
|
||||||
|
EOT
|
||||||
|
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
FROM base
|
||||||
|
|
||||||
|
ENV PORT=4567
|
||||||
|
|
||||||
|
RUN <<EOT
|
||||||
|
groupadd --system --gid 666 kubernaut
|
||||||
|
useradd --system --uid 666 --gid kubernaut --create-home --shell /bin/bash kubernaut
|
||||||
|
EOT
|
||||||
|
|
||||||
|
COPY --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}"
|
||||||
|
COPY --from=build /kubernaut /kubernaut
|
||||||
|
|
||||||
|
USER kubernaut:kubernaut
|
||||||
|
|
||||||
|
EXPOSE $PORT
|
||||||
|
ENTRYPOINT [ "/kubernaut/dockerfiles/entrypoint.sh" ]
|
||||||
|
CMD [ "bundle", "exec", "puma" ]
|
15
dockerfiles/entrypoint.sh
Executable file
15
dockerfiles/entrypoint.sh
Executable file
@ -0,0 +1,15 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# output debugging info
|
||||||
|
ruby --version
|
||||||
|
printf "rubygems %s\n" "$(gem --version)"
|
||||||
|
bundle version
|
||||||
|
|
||||||
|
if [ -z "${LD_PRELOAD+x}" ]; then
|
||||||
|
LD_PRELOAD="$(find /usr/lib -name libjemalloc.so.2 -print -quit)"
|
||||||
|
export LD_PRELOAD
|
||||||
|
fi
|
||||||
|
|
||||||
|
exec "${@}"
|
@ -16,7 +16,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
containers:
|
containers:
|
||||||
- name: kubernaut
|
- name: kubernaut
|
||||||
image: git.kill0.net/ryanc/kubernaut:latest
|
image: git.kill0.net/ryanc/kubernaut:0.2.1
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
ports:
|
ports:
|
||||||
- name: sinatra-web
|
- name: sinatra-web
|
||||||
|
Reference in New Issue
Block a user