Add custom-values.yaml, CUSTOM-README.md
This commit is contained in:
@@ -0,0 +1,208 @@
|
||||
|
||||
# harbor 배포
|
||||
|
||||
## 1. 배포 방법
|
||||
|
||||
``` sh
|
||||
git clone https://github.com/paasup/dip-catalog.git
|
||||
cd charts/harbor
|
||||
helm upgrade harbor ./ -f custom-values.yaml --install -n harbor --create-namespace
|
||||
```
|
||||
|
||||
## 2.custom-values.yaml 설명
|
||||
|
||||
- custom-values.yaml에 정의된 값에 대한 설명이다.
|
||||
|
||||
### 1) Pod 설정
|
||||
|
||||
- pod 배포에 사용되는 이미지 및 리소스를 설정한다.
|
||||
- pod에서 사용할 볼륨에 대하여 설정한다.
|
||||
|
||||
``` yaml
|
||||
imagePullPolicy: IfNotPresent
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
logLevel: info # log levle 설정 : info, debug
|
||||
|
||||
portal:
|
||||
image:
|
||||
repository: goharbor/harbor-portal # 오프라인 배포시, 내부 reistry 설정 추가
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 50Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
core:
|
||||
image:
|
||||
repository: goharbor/harbor-core # 오프라인 배포시, 내부 reistry 설정 추가
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 50Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
|
||||
jobservice:
|
||||
image:
|
||||
repository: goharbor/harbor-jobservice # 오프라인 배포시, 내부 reistry 설정 추가
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 30Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
|
||||
registry:
|
||||
registry:
|
||||
image:
|
||||
repository: goharbor/registry-photon # 오프라인 배포시, 내부 reistry 설정 추가
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 1000Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 250Mi
|
||||
|
||||
controller:
|
||||
image:
|
||||
repository: goharbor/harbor-registryctl # 오프라인 배포시, 내부 reistry 설정 추가
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
trivy:
|
||||
enabled: true
|
||||
image:
|
||||
repository: goharbor/trivy-adapter-photon # 오프라인 배포시, 내부 reistry 설정 추가
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
persistence:
|
||||
enabled: true
|
||||
persistentVolumeClaim:
|
||||
registry:
|
||||
storageClass: "" # storage class 설정
|
||||
size: 10Gi
|
||||
jobservice:
|
||||
jobLog:
|
||||
storageClass: "" # storage class 설정
|
||||
size: 1Gi
|
||||
redis:
|
||||
storageClass: "" # storage class 설정
|
||||
size: 1Gi
|
||||
trivy:
|
||||
storageClass: "" # storage class 설정
|
||||
size: 1Gi
|
||||
```
|
||||
|
||||
### 2) harbor 설정
|
||||
|
||||
- `externalURL`는 외부에서 접근 가능한 URL을 설정한다.
|
||||
- `harborAdminPassword`는 admin 사용자의 패스워드를 설정한다.
|
||||
- `interanlTLS`는 harbor의 내부에서 사용될 인증서에 대한 설정.
|
||||
|
||||
``` yaml
|
||||
externalURL: https://harbor.example.org
|
||||
harborAdminPassword: "password"
|
||||
internalTLS:
|
||||
enabled: true
|
||||
certSource: "auto"
|
||||
```
|
||||
|
||||
### 3) Ingress 설정
|
||||
|
||||
#### 3.1) tls 시크릿 직접 생성
|
||||
|
||||
- harbor에서 ingress 사용을 위해서는 다음과 같이 설정할 수 있다.
|
||||
|
||||
``` yaml
|
||||
expose:
|
||||
type: ingress
|
||||
tls:
|
||||
enabled: true
|
||||
certSource: secret
|
||||
secret:
|
||||
secretName: "harbor-tls"
|
||||
ingress:
|
||||
hosts:
|
||||
core: harbor.example.org
|
||||
```
|
||||
|
||||
- ingress 사용을 위해서는 인증서를 secret으로 제공해야한다. 로컬 파일을 이용해 secret을 생성하는 방법은 다음과 같다.
|
||||
|
||||
``` shell
|
||||
kubectl create secret tls harbor-tls --cert=<path-to-cert-file> --key=<path-to-key-file> -n <namespace>
|
||||
```
|
||||
|
||||
#### 3.2) cert-manager를 이용한 자동 생성
|
||||
|
||||
- cert manager를 통해 인증서 자동 생성 시 `custom-values.yaml` 수정한다.
|
||||
- `ingress.annotations.cert-manager.io/cluster-issuer`에 미리 배포된 Cluster Issuer의 이름으로 변경한다.
|
||||
|
||||
``` yaml
|
||||
expose:
|
||||
type: ingress
|
||||
tls:
|
||||
enabled: true
|
||||
certSource: secret
|
||||
secret:
|
||||
secretName: "harbor-tls"
|
||||
ingress:
|
||||
hosts:
|
||||
core: harbor.example.org
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/proxy-body-size: "10g"
|
||||
cert-manager.io/cluster-issuer: "selfsigned-issuer" # clusterissuer로 변경
|
||||
```
|
||||
|
||||
### 4) Database 설정
|
||||
|
||||
#### 4.1) 내장 DB
|
||||
|
||||
- 내장 DB를 사용할 때는 `type: internal`로 설정하고 패스워드 및 배포 설정을 입력한다.
|
||||
|
||||
``` yaml
|
||||
database:
|
||||
type: internal
|
||||
internal:
|
||||
image:
|
||||
repository: goharbor/harbor-db
|
||||
password: "postgres"
|
||||
shmSizeLimit: 512Mi
|
||||
```
|
||||
|
||||
#### 4.2) 외부 DB
|
||||
|
||||
- 외부 DB를 사용할 때는 `type: external`로 설정하고 DB 접속 정보를 입력한다.
|
||||
|
||||
``` yaml
|
||||
database:
|
||||
type: external
|
||||
external:
|
||||
host: "postgresql-postgresql-ha-postgresql"
|
||||
port: "5432"
|
||||
username: "postgres"
|
||||
password: "postgres"
|
||||
coreDatabase: "registry"
|
||||
```
|
||||
|
||||
- 참고) harbor-core에서 사용할 DB의 생성용 SQL.
|
||||
|
||||
``` sql
|
||||
CREATE DATABASE registry;
|
||||
GRANT CONNECT ON DATABASE registry TO postgres;
|
||||
```
|
||||
@@ -0,0 +1,144 @@
|
||||
# pod의 이미지, 자원, 배포 관련 설정
|
||||
imagePullPolicy: IfNotPresent
|
||||
updateStrategy:
|
||||
type: Recreate
|
||||
logLevel: info
|
||||
|
||||
portal:
|
||||
image:
|
||||
repository: goharbor/harbor-portal
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 50Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
core:
|
||||
image:
|
||||
repository: goharbor/harbor-core
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 50Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
|
||||
jobservice:
|
||||
image:
|
||||
repository: goharbor/harbor-jobservice
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 30Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
|
||||
registry:
|
||||
registry:
|
||||
image:
|
||||
repository: goharbor/registry-photon
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 1000Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 250Mi
|
||||
|
||||
controller:
|
||||
image:
|
||||
repository: goharbor/harbor-registryctl
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
trivy:
|
||||
enabled: true
|
||||
image:
|
||||
repository: goharbor/trivy-adapter-photon
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
|
||||
persistence:
|
||||
enabled: true
|
||||
persistentVolumeClaim:
|
||||
registry:
|
||||
storageClass: ""
|
||||
size: 10Gi
|
||||
jobservice:
|
||||
jobLog:
|
||||
storageClass: ""
|
||||
size: 1Gi
|
||||
redis:
|
||||
storageClass: ""
|
||||
size: 1Gi
|
||||
trivy:
|
||||
storageClass: ""
|
||||
size: 1Gi
|
||||
|
||||
# harbor 설정
|
||||
externalURL: https://harbor.example.org
|
||||
harborAdminPassword: "password"
|
||||
internalTLS:
|
||||
enabled: true
|
||||
certSource: "auto"
|
||||
|
||||
# ingress 설정
|
||||
expose:
|
||||
type: ingress
|
||||
tls:
|
||||
enabled: true
|
||||
certSource: secret
|
||||
secret:
|
||||
secretName: "harbor-tls"
|
||||
ingress:
|
||||
hosts:
|
||||
core: harbor.example.org
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
nginx.ingress.kubernetes.io/proxy-body-size: "10g"
|
||||
cert-manager.io/cluster-issuer: "selfsigned-issuer"
|
||||
|
||||
database:
|
||||
type: internal
|
||||
internal:
|
||||
image:
|
||||
repository: goharbor/harbor-db
|
||||
password: "postgres"
|
||||
shmSizeLimit: 512Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
# type: external
|
||||
# external:
|
||||
# host: "postgresql-postgresql-ha-postgresql"
|
||||
# port: "5432"
|
||||
# username: "postgres"
|
||||
# password: "postgres"
|
||||
# coreDatabase: "registry"
|
||||
|
||||
redis:
|
||||
type: internal
|
||||
internal:
|
||||
# set the service account to be used, default if left empty
|
||||
image:
|
||||
repository: goharbor/redis-photon
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 100Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 20Mi
|
||||
nodeSelector: {}
|
||||
tolerations: []
|
||||
Reference in New Issue
Block a user