Add VictoriaMetrics observability stack + sync catalog for monitoring test
- VM stack 10 charts: victoria-metrics-cluster/auth, victoria-logs-cluster, victoria-metrics-agent/alert, opentelemetry-collector, kube-state-metrics, prometheus-node-exporter, alertmanager, perses (JWT/OIDC, Infisical-ready) - ArgoCD ApplicationSet (syncWave) + per-chart dip-values overlays - doc/victoria-metrics-architecture.md, define-chart-resources updates - includes pending working-tree changes (mlflow, kubeflow, apisix, CLAUDE.md) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
1. Get the application URL by running these commands:
|
||||
{{- if .Values.ingress.enabled }}
|
||||
{{- range $host := .Values.ingress.hosts }}
|
||||
{{- range .paths }}
|
||||
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- else if contains "NodePort" .Values.service.type }}
|
||||
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "apisix.fullname" . }}-gateway)
|
||||
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||
echo http://$NODE_IP:$NODE_PORT
|
||||
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "apisix.fullname" . }}-gateway'
|
||||
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "apisix.fullname" . }}-gateway --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
||||
echo http://$SERVICE_IP:{{ .Values.service.http.servicePort }}
|
||||
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "apisix.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
||||
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:80
|
||||
{{- end }}
|
||||
@@ -0,0 +1,159 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
{{/*
|
||||
Expand the name of the chart.
|
||||
*/}}
|
||||
{{- define "apisix.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create a default fully qualified app name.
|
||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||
If release name contains chart name it will be used as a full name.
|
||||
*/}}
|
||||
{{- define "apisix.fullname" -}}
|
||||
{{- if .Values.fullnameOverride }}
|
||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||
{{- if contains $name .Release.Name }}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||
{{- else }}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create chart name and version as used by the chart label.
|
||||
*/}}
|
||||
{{- define "apisix.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Common labels
|
||||
*/}}
|
||||
{{- define "apisix.labels" -}}
|
||||
helm.sh/chart: {{ include "apisix.chart" . }}
|
||||
{{ include "apisix.selectorLabels" . }}
|
||||
{{- if .Chart.AppVersion }}
|
||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||
{{- end }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Selector labels
|
||||
*/}}
|
||||
{{- define "apisix.selectorLabels" -}}
|
||||
{{- if .Values.service.labelsOverride }}
|
||||
{{- tpl (.Values.service.labelsOverride | toYaml) . }}
|
||||
{{- else }}
|
||||
app.kubernetes.io/name: {{ include "apisix.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Create the name of the service account to use
|
||||
*/}}
|
||||
{{- define "apisix.serviceAccountName" -}}
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
{{- default (include "apisix.fullname" .) .Values.serviceAccount.name }}
|
||||
{{- else }}
|
||||
{{- default "default" .Values.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Renders a value that contains template.
|
||||
Usage:
|
||||
{{ include "apisix.tplvalues.render" ( dict "value" .Values.path.to.the.Value "context" $) }}
|
||||
*/}}
|
||||
{{- define "apisix.tplvalues.render" -}}
|
||||
{{- if typeIs "string" .value }}
|
||||
{{- tpl .value .context }}
|
||||
{{- else }}
|
||||
{{- tpl (.value | toYaml) .context }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "apisix.basePluginAttrs" -}}
|
||||
{{- if .Values.apisix.prometheus.enabled }}
|
||||
prometheus:
|
||||
export_addr:
|
||||
ip: 0.0.0.0
|
||||
port: {{ .Values.apisix.prometheus.containerPort }}
|
||||
export_uri: {{ .Values.apisix.prometheus.path }}
|
||||
metric_prefix: {{ .Values.apisix.prometheus.metricPrefix }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.customPlugins.enabled }}
|
||||
{{- range $plugin := .Values.apisix.customPlugins.plugins }}
|
||||
{{- if $plugin.attrs }}
|
||||
{{ $plugin.name }}: {{- $plugin.attrs | toYaml | nindent 2 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "apisix.pluginAttrs" -}}
|
||||
{{- merge .Values.apisix.pluginAttrs (include "apisix.basePluginAttrs" . | fromYaml) | toYaml -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Scheme to use while connecting etcd
|
||||
*/}}
|
||||
{{- define "apisix.etcd.auth.scheme" -}}
|
||||
{{- if .Values.etcd.auth.tls.enabled }}
|
||||
{{- "https" }}
|
||||
{{- else }}
|
||||
{{- "http" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Return the name of etcd password secret
|
||||
*/}}
|
||||
{{- define "apisix.etcd.secretName" -}}
|
||||
{{- if and .Values.etcd.enabled .Values.etcd.auth.rbac.create }}
|
||||
{{- template "common.names.fullname" .Subcharts.etcd }}
|
||||
{{- else if .Values.externalEtcd.existingSecret }}
|
||||
{{- print .Values.externalEtcd.existingSecret }}
|
||||
{{- else if .Values.externalEtcd.user }}
|
||||
{{- printf "etcd-%s" (include "apisix.fullname" .) | trunc 63 | trimSuffix "-" }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Return the password key name of etcd secret
|
||||
*/}}
|
||||
{{- define "apisix.etcd.secretPasswordKey" -}}
|
||||
{{- if .Values.etcd.enabled }}
|
||||
{{- print "etcd-root-password" }}
|
||||
{{- else }}
|
||||
{{- print .Values.externalEtcd.secretPasswordKey }}
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Key to use to fetch admin token from secret
|
||||
*/}}
|
||||
{{- define "apisix.admin.credentials.secretAdminKey" -}}
|
||||
{{- if .Values.apisix.admin.credentials.secretAdminKey }}
|
||||
{{- .Values.apisix.admin.credentials.secretAdminKey }}
|
||||
{{- else }}
|
||||
{{- "admin" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/*
|
||||
Key to use to fetch viewer token from secret
|
||||
*/}}
|
||||
{{- define "apisix.admin.credentials.secretViewerKey" -}}
|
||||
{{- if .Values.apisix.admin.credentials.secretViewerKey }}
|
||||
{{- .Values.apisix.admin.credentials.secretViewerKey }}
|
||||
{{- else }}
|
||||
{{- "viewer" }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,26 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if and (eq .Values.apisix.deployment.mode "standalone") (not .Values.apisix.deployment.standalone.existingConfigMap) }}
|
||||
kind: ConfigMap
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: apisix.yaml
|
||||
data:
|
||||
apisix.yaml: |
|
||||
{{- .Values.apisix.deployment.standalone.config | nindent 4 }}
|
||||
#END
|
||||
{{- end }}
|
||||
@@ -0,0 +1,26 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if .Values.rbac.create }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["endpoints"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if .Values.rbac.create }}
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: {{ include "apisix.serviceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
{{- end }}
|
||||
@@ -0,0 +1,410 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
config.yaml: |-
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
{{- if .Values.apisix.fullCustomConfig.enabled }}
|
||||
{{- range $key, $value := .Values.apisix.fullCustomConfig.config }}
|
||||
{{ $key }}:
|
||||
{{- include "apisix.tplvalues.render" (dict "value" $value "context" $) | nindent 6 }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
apisix: # universal configurations
|
||||
{{- if not (eq .Values.apisix.deployment.role "control_plane") }}
|
||||
node_listen: # APISIX listening port
|
||||
- {{ .Values.service.http.containerPort }}
|
||||
{{- with .Values.service.http.additionalContainerPorts }}
|
||||
{{- toYaml . | nindent 8}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
enable_heartbeat: true
|
||||
enable_admin: {{ .Values.apisix.admin.enabled }}
|
||||
enable_admin_cors: {{ .Values.apisix.admin.cors }}
|
||||
enable_debug: false
|
||||
{{- if or .Values.apisix.customPlugins.enabled .Values.apisix.luaModuleHook.enabled }}
|
||||
extra_lua_path: {{ .Values.apisix.customPlugins.luaPath }};{{ .Values.apisix.luaModuleHook.luaPath }}
|
||||
{{- end }}
|
||||
|
||||
enable_control: {{ .Values.control.enabled }}
|
||||
{{- if .Values.control.enabled }}
|
||||
control:
|
||||
ip: {{ default "127.0.0.1" .Values.control.service.ip }}
|
||||
port: {{ default 9090 .Values.control.service.port }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.luaModuleHook.enabled }}
|
||||
lua_module_hook: {{ .Values.apisix.luaModuleHook.hookPoint | quote }}
|
||||
{{- end }}
|
||||
|
||||
enable_dev_mode: false # Sets nginx worker_processes to 1 if set to true
|
||||
enable_reuseport: true # Enable nginx SO_REUSEPORT switch if set to true.
|
||||
enable_ipv6: {{ .Values.apisix.enableIPv6 }} # Enable nginx IPv6 resolver
|
||||
enable_http2: {{ .Values.apisix.enableHTTP2 }}
|
||||
enable_server_tokens: {{ .Values.apisix.enableServerTokens }} # Whether the APISIX version number should be shown in Server header
|
||||
|
||||
# proxy_protocol: # Proxy Protocol configuration
|
||||
# listen_http_port: 9181 # The port with proxy protocol for http, it differs from node_listen and admin_listen.
|
||||
# # This port can only receive http request with proxy protocol, but node_listen & admin_listen
|
||||
# # can only receive http request. If you enable proxy protocol, you must use this port to
|
||||
# # receive http request with proxy protocol
|
||||
# listen_https_port: 9182 # The port with proxy protocol for https
|
||||
# enable_tcp_pp: true # Enable the proxy protocol for tcp proxy, it works for stream_proxy.tcp option
|
||||
# enable_tcp_pp_to_upstream: true # Enables the proxy protocol to the upstream server
|
||||
|
||||
proxy_cache: # Proxy Caching configuration
|
||||
cache_ttl: 10s # The default caching time if the upstream does not specify the cache time
|
||||
zones: # The parameters of a cache
|
||||
- name: disk_cache_one # The name of the cache, administrator can be specify
|
||||
# which cache to use by name in the admin api
|
||||
memory_size: 50m # The size of shared memory, it's used to store the cache index
|
||||
disk_size: 1G # The size of disk, it's used to store the cache data
|
||||
disk_path: "/tmp/disk_cache_one" # The path to store the cache data
|
||||
cache_levels: "1:2" # The hierarchy levels of a cache
|
||||
# - name: disk_cache_two
|
||||
# memory_size: 50m
|
||||
# disk_size: 1G
|
||||
# disk_path: "/tmp/disk_cache_two"
|
||||
# cache_levels: "1:2"
|
||||
|
||||
router:
|
||||
http: {{ .Values.apisix.router.http }} # radixtree_uri: match route by uri(base on radixtree)
|
||||
# radixtree_host_uri: match route by host + uri(base on radixtree)
|
||||
# radixtree_uri_with_parameter: match route by uri with parameters
|
||||
ssl: 'radixtree_sni' # radixtree_sni: match route by SNI(base on radixtree)
|
||||
|
||||
{{- $proxy_mode := "" }}
|
||||
{{- if and .Values.service.stream.enabled .Values.service.http.enabled }}
|
||||
{{- $proxy_mode = "http&stream" }}
|
||||
{{- else if .Values.service.http.enabled }}
|
||||
{{- $proxy_mode = "http" }}
|
||||
{{- else if .Values.service.stream.enabled }}
|
||||
{{- $proxy_mode = "stream" }}
|
||||
{{- end }}
|
||||
|
||||
proxy_mode: {{ $proxy_mode }}
|
||||
|
||||
{{- if or (index .Values "ingress-controller" "enabled") (and .Values.service.stream.enabled (or (gt (len .Values.service.stream.tcp) 0) (gt (len .Values.service.stream.udp) 0))) }}
|
||||
stream_proxy: # TCP/UDP proxy
|
||||
{{- if or (index .Values "ingress-controller" "enabled") (gt (len .Values.service.stream.tcp) 0) }}
|
||||
tcp: # TCP proxy port list
|
||||
{{- if gt (len .Values.service.stream.tcp) 0}}
|
||||
{{- range .Values.service.stream.tcp }}
|
||||
{{- if kindIs "map" . }}
|
||||
- addr: {{ .addr }}
|
||||
{{- if hasKey . "tls" }}
|
||||
tls: {{ .tls }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
- {{ . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- else}}
|
||||
- 9100
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if or (index .Values "ingress-controller" "enabled") (gt (len .Values.service.stream.udp) 0) }}
|
||||
udp: # UDP proxy port list
|
||||
{{- if gt (len .Values.service.stream.udp) 0}}
|
||||
{{- range .Values.service.stream.udp }}
|
||||
- {{ . }}
|
||||
{{- end }}
|
||||
{{- else}}
|
||||
- 9200
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
# dns_resolver:
|
||||
# {{- range $resolver := .Values.apisix.dns.resolvers }}
|
||||
# - {{ $resolver }}
|
||||
# {{- end }}
|
||||
dns_resolver_valid: {{.Values.apisix.dns.validity}}
|
||||
resolver_timeout: {{.Values.apisix.dns.timeout}}
|
||||
ssl:
|
||||
enable: {{ .Values.apisix.ssl.enabled }}
|
||||
listen:
|
||||
- port: {{ .Values.apisix.ssl.containerPort }}
|
||||
enable_http3: {{ .Values.apisix.ssl.enableHTTP3 }}
|
||||
{{- with .Values.apisix.ssl.additionalContainerPorts }}
|
||||
{{- toYaml . | nindent 10}}
|
||||
{{- end }}
|
||||
ssl_protocols: {{ .Values.apisix.ssl.sslProtocols | quote }}
|
||||
ssl_ciphers: {{ .Values.apisix.ssl.sslCiphers | quote }}
|
||||
{{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.existingCASecret }}
|
||||
ssl_trusted_certificate: "/usr/local/apisix/conf/ssl/{{ .Values.apisix.ssl.certCAFilename }}"
|
||||
{{- end }}
|
||||
{{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.fallbackSNI }}
|
||||
fallback_sni: {{ .Values.apisix.ssl.fallbackSNI | quote }}
|
||||
{{- end }}
|
||||
{{- $useTraditionalYaml := and (eq .Values.apisix.deployment.role "traditional") (eq .Values.apisix.deployment.role_traditional.config_provider "yaml") }}
|
||||
{{- if $useTraditionalYaml }}
|
||||
status:
|
||||
ip: {{ default "127.0.0.1" .Values.apisix.status.ip }}
|
||||
port: {{ default "7085" (.Values.apisix.status.port | toString) }}
|
||||
{{- end}}
|
||||
|
||||
{{ if .Values.apisix.trustedAddresses }}
|
||||
trusted_addresses:
|
||||
{{- toYaml .Values.apisix.trustedAddresses | nindent 8 }}
|
||||
{{ end }}
|
||||
|
||||
nginx_config: # config for render the template to genarate nginx.conf
|
||||
error_log: "{{ .Values.apisix.nginx.logs.errorLog }}"
|
||||
error_log_level: "{{ .Values.apisix.nginx.logs.errorLogLevel }}" # warn,error
|
||||
worker_processes: "{{ .Values.apisix.nginx.workerProcesses }}"
|
||||
enable_cpu_affinity: {{ and true .Values.apisix.nginx.enableCPUAffinity }}
|
||||
worker_rlimit_nofile: {{ default "20480" .Values.apisix.nginx.workerRlimitNofile }} # the number of files a worker process can open, should be larger than worker_connections
|
||||
event:
|
||||
worker_connections: {{ default "10620" .Values.apisix.nginx.workerConnections }}
|
||||
{{- with .Values.apisix.nginx.envs }}
|
||||
envs:
|
||||
{{- range $env := . }}
|
||||
- {{ $env }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.metaLuaSharedDicts }}
|
||||
meta:
|
||||
lua_shared_dict:
|
||||
{{- range $dict := .Values.apisix.nginx.metaLuaSharedDicts }}
|
||||
{{ $dict.name }}: {{ $dict.size }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
http:
|
||||
enable_access_log: {{ .Values.apisix.nginx.logs.enableAccessLog }}
|
||||
{{- if .Values.apisix.nginx.logs.enableAccessLog }}
|
||||
access_log: "{{ .Values.apisix.nginx.logs.accessLog }}"
|
||||
access_log_format: '{{ .Values.apisix.nginx.logs.accessLogFormat }}'
|
||||
access_log_format_escape: {{ .Values.apisix.nginx.logs.accessLogFormatEscape }}
|
||||
{{- end }}
|
||||
keepalive_timeout: {{ .Values.apisix.nginx.keepaliveTimeout | quote }}
|
||||
client_header_timeout: 60s # timeout for reading client request header, then 408 (Request Time-out) error is returned to the client
|
||||
client_body_timeout: 60s # timeout for reading client request body, then 408 (Request Time-out) error is returned to the client
|
||||
send_timeout: 10s # timeout for transmitting a response to the client.then the connection is closed
|
||||
underscores_in_headers: "on" # default enables the use of underscores in client request header fields
|
||||
real_ip_header: "X-Real-IP" # http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_header
|
||||
real_ip_from: # http://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from
|
||||
- 127.0.0.1
|
||||
- 'unix:'
|
||||
{{- if .Values.apisix.nginx.customLuaSharedDicts }}
|
||||
custom_lua_shared_dict: # add custom shared cache to nginx.conf
|
||||
{{- range $dict := .Values.apisix.nginx.customLuaSharedDicts }}
|
||||
{{ $dict.name }}: {{ $dict.size }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.luaSharedDicts }}
|
||||
lua_shared_dict:
|
||||
{{- range $dict := .Values.apisix.nginx.luaSharedDicts }}
|
||||
{{ $dict.name }}: {{ $dict.size }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.configurationSnippet.main }}
|
||||
main_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.main | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.configurationSnippet.httpStart }}
|
||||
http_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpStart | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.configurationSnippet.httpEnd }}
|
||||
http_end_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpEnd | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.configurationSnippet.httpSrv }}
|
||||
http_server_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpSrv | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.configurationSnippet.httpAdmin }}
|
||||
http_admin_configuration_snippet: {{ toYaml .Values.apisix.nginx.configurationSnippet.httpAdmin | indent 6 }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.nginx.configurationSnippet.stream }}
|
||||
stream_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.stream | indent 6 }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.discovery.enabled }}
|
||||
discovery:
|
||||
{{- range $key, $value := .Values.apisix.discovery.registry }}
|
||||
{{- if $value }}
|
||||
{{ $key }}:
|
||||
{{- include "apisix.tplvalues.render" (dict "value" $value "context" $) | nindent 8 }}
|
||||
{{- else }}
|
||||
{{ $key }}: {}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.vault.enabled }}
|
||||
vault:
|
||||
host: {{ .Values.apisix.vault.host }}
|
||||
timeout: {{ .Values.apisix.vault.timeout }}
|
||||
token: {{ .Values.apisix.vault.token }}
|
||||
prefix: {{ .Values.apisix.vault.prefix }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.plugins }}
|
||||
plugins: # plugin list
|
||||
{{- range $plugin := .Values.apisix.plugins }}
|
||||
{{- if ne $plugin "" }}
|
||||
- {{ $plugin }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.customPlugins.enabled }}
|
||||
{{- range $plugin := .Values.apisix.customPlugins.plugins }}
|
||||
- {{ $plugin.name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.stream_plugins }}
|
||||
stream_plugins:
|
||||
{{- range $plugin := .Values.apisix.stream_plugins }}
|
||||
{{- if ne $plugin "" }}
|
||||
- {{ $plugin }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.extPlugin.enabled }}
|
||||
ext-plugin:
|
||||
cmd:
|
||||
{{- range $arg := .Values.apisix.extPlugin.cmd }}
|
||||
- {{ $arg }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if or .Values.apisix.pluginAttrs .Values.apisix.customPlugins.enabled .Values.apisix.prometheus.enabled}}
|
||||
{{- $pluginAttrs := include "apisix.pluginAttrs" . -}}
|
||||
{{- if gt (len ($pluginAttrs | fromYaml)) 0 }}
|
||||
plugin_attr: {{- $pluginAttrs | nindent 6 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.wasm.enabled }}
|
||||
wasm:
|
||||
plugins:
|
||||
{{- toYaml .Values.apisix.wasm.plugins | nindent 8 }}
|
||||
{{- end }}
|
||||
|
||||
deployment:
|
||||
role: {{ .Values.apisix.deployment.role }}
|
||||
|
||||
{{- if eq .Values.apisix.deployment.role "traditional" }}
|
||||
role_traditional:
|
||||
config_provider: {{ default "etcd" .Values.apisix.deployment.role_traditional.config_provider }}
|
||||
{{- end }}
|
||||
|
||||
{{- if eq .Values.apisix.deployment.role "control_plane" }}
|
||||
role_control_plane:
|
||||
config_provider: etcd
|
||||
{{- end }}
|
||||
|
||||
{{- if eq .Values.apisix.deployment.role "data_plane" }}
|
||||
role_data_plane:
|
||||
config_provider: {{- eq .Values.apisix.deployment.mode "standalone" | ternary "yaml" "etcd" | indent 1 }}
|
||||
{{- end }}
|
||||
|
||||
{{- if not (eq .Values.apisix.deployment.role "data_plane") }}
|
||||
admin:
|
||||
{{- if .Values.etcd.enabled }}
|
||||
enable_admin_ui: {{ .Values.apisix.admin.enable_admin_ui }}
|
||||
{{- end }}
|
||||
allow_admin: # http://nginx.org/en/docs/http/ngx_http_access_module.html#allow
|
||||
{{- if .Values.apisix.admin.allow.ipList }}
|
||||
{{- range $ips := .Values.apisix.admin.allow.ipList }}
|
||||
- {{ $ips }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
- 0.0.0.0/0
|
||||
{{- end}}
|
||||
{{- if (index .Values "ingress-controller" "enabled") }}
|
||||
- 0.0.0.0/0
|
||||
{{- end}}
|
||||
# - "::/64"
|
||||
{{- if .Values.apisix.admin.enabled }}
|
||||
admin_listen:
|
||||
ip: {{ .Values.apisix.admin.ip }}
|
||||
port: {{ .Values.apisix.admin.port }}
|
||||
{{- end }}
|
||||
# Default token when use API to call for Admin API.
|
||||
# *NOTE*: Highly recommended to modify this value to protect APISIX's Admin API.
|
||||
# Disabling this configuration item means that the Admin API does not
|
||||
# require any authentication.
|
||||
admin_key:
|
||||
# admin: can everything for configuration data
|
||||
- name: "admin"
|
||||
{{- if .Values.apisix.admin.credentials.secretName }}
|
||||
key: ${{"{{"}}APISIX_ADMIN_KEY{{"}}"}}
|
||||
{{- else }}
|
||||
key: {{ .Values.apisix.admin.credentials.admin }}
|
||||
{{- end }}
|
||||
role: admin
|
||||
# viewer: only can view configuration data
|
||||
- name: "viewer"
|
||||
{{- if .Values.apisix.admin.credentials.secretName }}
|
||||
key: ${{"{{"}}APISIX_VIEWER_KEY{{"}}"}}
|
||||
{{- else }}
|
||||
key: {{ .Values.apisix.admin.credentials.viewer }}
|
||||
{{- end }}
|
||||
role: viewer
|
||||
{{- end }}
|
||||
{{- if not (eq .Values.apisix.deployment.mode "standalone")}}
|
||||
etcd:
|
||||
{{- if .Values.etcd.enabled }}
|
||||
host: # it's possible to define multiple etcd hosts addresses of the same etcd cluster.
|
||||
{{- if .Values.etcd.fullnameOverride }}
|
||||
- "{{ include "apisix.etcd.auth.scheme" . }}://{{ .Values.etcd.fullnameOverride }}:{{ .Values.etcd.service.port }}"
|
||||
{{- else }}
|
||||
- "{{ include "apisix.etcd.auth.scheme" . }}://{{ .Release.Name }}-etcd.{{ .Release.Namespace }}.svc.{{ .Values.etcd.clusterDomain }}:{{ .Values.etcd.service.port }}"
|
||||
{{- end}}
|
||||
{{- else }}
|
||||
host: # it's possible to define multiple etcd hosts addresses of the same etcd cluster.
|
||||
{{- range $value := .Values.externalEtcd.host }}
|
||||
- "{{ $value }}" # multiple etcd address
|
||||
{{- end}}
|
||||
{{- end }}
|
||||
prefix: {{ .Values.etcd.prefix | quote }} # configuration prefix in etcd
|
||||
timeout: {{ .Values.etcd.timeout }} # 30 seconds
|
||||
{{- if and (not .Values.etcd.enabled) .Values.externalEtcd.user }}
|
||||
user: {{ .Values.externalEtcd.user | quote }}
|
||||
password: "{{ print "${{ APISIX_ETCD_PASSWORD }}" }}"
|
||||
{{- else if and .Values.etcd.enabled .Values.etcd.auth.rbac.create }}
|
||||
user: "root"
|
||||
password: "{{ print "${{APISIX_ETCD_PASSWORD}}" }}"
|
||||
{{- end }}
|
||||
{{- if .Values.etcd.auth.tls.enabled }}
|
||||
tls:
|
||||
cert: "/etcd-ssl/{{ .Values.etcd.auth.tls.certFilename }}"
|
||||
key: "/etcd-ssl/{{ .Values.etcd.auth.tls.certKeyFilename }}"
|
||||
verify: {{ .Values.etcd.auth.tls.verify }}
|
||||
sni: "{{ .Values.etcd.auth.tls.sni }}"
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -0,0 +1,313 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
apiVersion: apps/v1
|
||||
kind: {{ ternary "DaemonSet" "Deployment" .Values.useDaemonSet }}
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
spec:
|
||||
{{- if and (not .Values.useDaemonSet) (not .Values.autoscaling.enabled) }}
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
{{- end }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "apisix.selectorLabels" . | nindent 6 }}
|
||||
{{- if .Values.updateStrategy }}
|
||||
{{- if (not .Values.useDaemonSet) }}
|
||||
strategy: {{ toYaml .Values.updateStrategy | nindent 4 }}
|
||||
{{- else }}
|
||||
updateStrategy: {{ toYaml .Values.updateStrategy | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }}
|
||||
{{- with .Values.podAnnotations }}
|
||||
{{ tpl (toYaml .) $ | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "apisix.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
{{- with .Values.global.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- range $.Values.global.imagePullSecrets }}
|
||||
- name: {{ . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
serviceAccountName: {{ include "apisix.serviceAccountName" . }}
|
||||
{{- with .Values.podSecurityContext }}
|
||||
securityContext:
|
||||
{{- . | toYaml | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.priorityClassName }}
|
||||
priorityClassName: {{ . }}
|
||||
{{- end }}
|
||||
containers:
|
||||
{{- $useTraditionalYaml := and (eq .Values.apisix.deployment.role "traditional") (eq .Values.apisix.deployment.role_traditional.config_provider "yaml") }}
|
||||
- name: {{ .Chart.Name }}
|
||||
{{- with .Values.securityContext }}
|
||||
securityContext:
|
||||
{{- . | toYaml | nindent 12 }}
|
||||
{{- end }}
|
||||
image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}"
|
||||
{{- if eq .Values.apisix.deployment.mode "standalone" }}
|
||||
command: ["sh", "-c","ln -s /apisix-config/apisix.yaml /usr/local/apisix/conf/apisix.yaml && /docker-entrypoint.sh docker-start"]
|
||||
{{- end }}
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
env:
|
||||
{{- if .Values.timezone }}
|
||||
- name: TZ
|
||||
value: {{ .Values.timezone }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraEnvVars }}
|
||||
{{- include "apisix.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.admin.credentials.secretName }}
|
||||
- name: APISIX_ADMIN_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.apisix.admin.credentials.secretName }}
|
||||
key: {{ include "apisix.admin.credentials.secretAdminKey" . }}
|
||||
- name: APISIX_VIEWER_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ .Values.apisix.admin.credentials.secretName }}
|
||||
key: {{ include "apisix.admin.credentials.secretViewerKey" . }}
|
||||
{{- end }}
|
||||
|
||||
{{- if or (and .Values.etcd.enabled .Values.etcd.auth.rbac.create) (and (not .Values.etcd.enabled) .Values.externalEtcd.user) }}
|
||||
- name: APISIX_ETCD_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "apisix.etcd.secretName" . }}
|
||||
key: {{ include "apisix.etcd.secretPasswordKey" . }}
|
||||
{{- end }}
|
||||
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: {{ .Values.service.http.containerPort }}
|
||||
protocol: TCP
|
||||
{{- range .Values.service.http.additionalContainerPorts }}
|
||||
- name: http-{{ .port | toString }}
|
||||
containerPort: {{ .port }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
- name: tls
|
||||
containerPort: {{ .Values.apisix.ssl.containerPort }}
|
||||
protocol: TCP
|
||||
{{- range .Values.apisix.ssl.additionalContainerPorts }}
|
||||
- name: tls-{{ .port | toString }}
|
||||
containerPort: {{ .port }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.admin.enabled }}
|
||||
- name: admin
|
||||
containerPort: {{ .Values.apisix.admin.port }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if .Values.control.enabled }}
|
||||
- name: control
|
||||
containerPort: {{ .Values.control.service.port }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.prometheus.enabled }}
|
||||
- name: prometheus
|
||||
containerPort: {{ .Values.apisix.prometheus.containerPort }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if and .Values.service.stream.enabled (or (gt (len .Values.service.stream.tcp) 0) (gt (len .Values.service.stream.udp) 0)) }}
|
||||
{{- with .Values.service.stream }}
|
||||
{{- if (gt (len .tcp) 0) }}
|
||||
{{- range $index, $port := .tcp }}
|
||||
- name: proxy-tcp-{{ $index | toString }}
|
||||
{{- if kindIs "map" $port }}
|
||||
containerPort: {{ splitList ":" ($port.addr | toString) | last }}
|
||||
{{- else }}
|
||||
containerPort: {{ $port }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if (gt (len .udp) 0) }}
|
||||
{{- range $index, $port := .udp }}
|
||||
- name: proxy-udp-{{ $index | toString }}
|
||||
containerPort: {{ $port }}
|
||||
protocol: UDP
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if $useTraditionalYaml }}
|
||||
- name: status
|
||||
containerPort: {{ default 7085 .Values.apisix.status.port }}
|
||||
protocol: TCP
|
||||
{{- end}}
|
||||
|
||||
{{- if ne .Values.apisix.deployment.role "control_plane" }}
|
||||
readinessProbe:
|
||||
failureThreshold: 6
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
successThreshold: 1
|
||||
{{- if $useTraditionalYaml }}
|
||||
httpGet:
|
||||
path: /status/ready
|
||||
port: {{ default 7085 .Values.apisix.status.port }}
|
||||
{{- else }}
|
||||
tcpSocket:
|
||||
port: {{ .Values.service.http.containerPort }}
|
||||
{{- end}}
|
||||
timeoutSeconds: 1
|
||||
{{- end }}
|
||||
lifecycle:
|
||||
preStop:
|
||||
exec:
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- "sleep 30"
|
||||
volumeMounts:
|
||||
{{- if eq .Values.apisix.deployment.mode "standalone" }}
|
||||
- mountPath: /apisix-config
|
||||
name: apisix-admin
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.setIDFromPodUID }}
|
||||
- mountPath: /usr/local/apisix/conf/apisix.uid
|
||||
name: id
|
||||
subPath: apisix.uid
|
||||
{{- end }}
|
||||
- mountPath: /usr/local/apisix/conf/config.yaml
|
||||
name: apisix-config
|
||||
subPath: config.yaml
|
||||
{{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.existingCASecret }}
|
||||
- mountPath: /usr/local/apisix/conf/ssl/{{ .Values.apisix.ssl.certCAFilename }}
|
||||
name: ssl
|
||||
subPath: {{ .Values.apisix.ssl.certCAFilename }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.etcd.auth.tls.enabled }}
|
||||
- mountPath: /etcd-ssl
|
||||
name: etcd-ssl
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.customPlugins.enabled }}
|
||||
{{- range $plugin := .Values.apisix.customPlugins.plugins }}
|
||||
{{- range $mount := $plugin.configMap.mounts }}
|
||||
{{- if ne $plugin.configMap.name "" }}
|
||||
- mountPath: {{ $mount.path }}
|
||||
name: plugin-{{ $plugin.configMap.name }}
|
||||
subPath: {{ $mount.key }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.luaModuleHook.enabled }}
|
||||
{{- range $mount := .Values.apisix.luaModuleHook.configMapRef.mounts }}
|
||||
- mountPath: {{ $mount.path }}
|
||||
name: lua-module-hook
|
||||
subPath: {{ $mount.key }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraVolumeMounts }}
|
||||
{{- toYaml .Values.extraVolumeMounts | nindent 12 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
{{- if .Values.extraContainers }}
|
||||
{{- toYaml .Values.extraContainers | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.hostNetwork }}
|
||||
hostNetwork: true
|
||||
dnsPolicy: ClusterFirstWithHostNet
|
||||
{{- end }}
|
||||
hostNetwork: {{ .Values.hostNetwork }}
|
||||
initContainers:
|
||||
{{- if .Values.etcd.enabled }}
|
||||
- name: wait-etcd
|
||||
image: {{ .Values.initContainer.image }}:{{ .Values.initContainer.tag }}
|
||||
{{- if .Values.etcd.fullnameOverride }}
|
||||
command: ['sh', '-c', "until nc -z {{ .Values.etcd.fullnameOverride }} {{ .Values.etcd.service.port }}; do echo waiting for etcd `date`; sleep 2; done;"]
|
||||
{{ else }}
|
||||
command: ['sh', '-c', "until nc -z {{ .Release.Name }}-etcd.{{ .Release.Namespace }}.svc.{{ .Values.etcd.clusterDomain }} {{ .Values.etcd.service.port }}; do echo waiting for etcd `date`; sleep 2; done;"]
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraInitContainers }}
|
||||
{{- toYaml .Values.extraInitContainers | nindent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
{{- if eq .Values.apisix.deployment.mode "standalone" }}
|
||||
- configMap:
|
||||
name: {{ .Values.apisix.deployment.standalone.existingConfigMap | default "apisix.yaml" }}
|
||||
name: apisix-admin
|
||||
{{- end }}
|
||||
- configMap:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
name: apisix-config
|
||||
{{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.existingCASecret }}
|
||||
- secret:
|
||||
secretName: {{ .Values.apisix.ssl.existingCASecret | quote }}
|
||||
name: ssl
|
||||
{{- end }}
|
||||
{{- if .Values.etcd.auth.tls.enabled }}
|
||||
- secret:
|
||||
secretName: {{ .Values.etcd.auth.tls.existingSecret | quote }}
|
||||
name: etcd-ssl
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.apisix.setIDFromPodUID }}
|
||||
- downwardAPI:
|
||||
items:
|
||||
- path: "apisix.uid"
|
||||
fieldRef:
|
||||
fieldPath: metadata.uid
|
||||
name: id
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.customPlugins.enabled }}
|
||||
{{- range $plugin := .Values.apisix.customPlugins.plugins }}
|
||||
{{- if ne $plugin.configMap.name "" }}
|
||||
- name: plugin-{{ $plugin.configMap.name }}
|
||||
configMap:
|
||||
name: {{ $plugin.configMap.name }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.luaModuleHook.enabled }}
|
||||
- name: lua-module-hook
|
||||
configMap:
|
||||
name: {{ .Values.apisix.luaModuleHook.configMapRef.name }}
|
||||
{{- end }}
|
||||
{{- if .Values.extraVolumes }}
|
||||
{{- toYaml .Values.extraVolumes | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- tpl (. | toYaml) $ | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,10 @@
|
||||
{{- if and .Values.externalEtcd.user (and (not .Values.etcd.enabled) (not .Values.externalEtcd.existingSecret)) }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "apisix.etcd.secretName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
type: Opaque
|
||||
data:
|
||||
{{ .Values.externalEtcd.secretPasswordKey }}: {{ .Values.externalEtcd.password | b64enc | quote }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,8 @@
|
||||
{{- range .Values.extraDeploy }}
|
||||
---
|
||||
{{- if typeIs "string" . }}
|
||||
{{- tpl . $ }}
|
||||
{{- else }}
|
||||
{{- tpl (. | toYaml) $ }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,69 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if .Values.autoscaling.enabled }}
|
||||
|
||||
apiVersion: autoscaling/{{ .Values.autoscaling.version }}
|
||||
kind: HorizontalPodAutoscaler
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
spec:
|
||||
scaleTargetRef:
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||
metrics:
|
||||
{{- if eq .Values.autoscaling.version "v2" }}
|
||||
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||
- type: Resource
|
||||
resource:
|
||||
name: cpu
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||
- type: Resource
|
||||
resource:
|
||||
name: memory
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||
{{- end }}
|
||||
|
||||
{{- else }}
|
||||
|
||||
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||
- type: Resource
|
||||
resource:
|
||||
name: cpu
|
||||
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||
{{- end }}
|
||||
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||
- type: Resource
|
||||
resource:
|
||||
name: memory
|
||||
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||
{{- end }}
|
||||
|
||||
{{- end}}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,76 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if (and .Values.apisix.admin.enabled .Values.apisix.admin.ingress.enabled) -}}
|
||||
{{- $fullName := include "apisix.fullname" . -}}
|
||||
{{- $svcPort := .Values.apisix.admin.servicePort -}}
|
||||
{{- if and .Values.apisix.admin.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
|
||||
{{- if not (hasKey .Values.apisix.admin.ingress.annotations "kubernetes.io/ingress.class") }}
|
||||
{{- $_ := set .Values.apisix.admin.ingress.annotations "kubernetes.io/ingress.class" .Values.apisix.admin.ingress.className}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.Version }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.Version }}
|
||||
apiVersion: networking.k8s.io/v1beta1
|
||||
{{- else -}}
|
||||
apiVersion: extensions/v1beta1
|
||||
{{- end }}
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ $fullName }}-admin
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
{{- with .Values.apisix.admin.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if and .Values.apisix.admin.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
|
||||
ingressClassName: {{ .Values.apisix.admin.ingress.className }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.admin.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.apisix.admin.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .Values.apisix.admin.ingress.hosts }}
|
||||
- host: {{ .host | quote }}
|
||||
http:
|
||||
paths:
|
||||
{{- range .paths }}
|
||||
- path: {{ . }}
|
||||
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.Version }}
|
||||
pathType: ImplementationSpecific
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}-admin
|
||||
port:
|
||||
number: {{ $svcPort }}
|
||||
{{- else }}
|
||||
backend:
|
||||
serviceName: {{ $fullName }}-admin
|
||||
servicePort: {{ $svcPort }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,76 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if (and .Values.control.enabled .Values.control.ingress.enabled) -}}
|
||||
{{- $fullName := include "apisix.fullname" . -}}
|
||||
{{- $svcPort := .Values.control.servicePort -}}
|
||||
{{- if and .Values.control.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
|
||||
{{- if not (hasKey .Values.control.ingress.annotations "kubernetes.io/ingress.class") }}
|
||||
{{- $_ := set .Values.control.ingress.annotations "kubernetes.io/ingress.class" .Values.control.ingress.className}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.Version }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.Version }}
|
||||
apiVersion: networking.k8s.io/v1beta1
|
||||
{{- else -}}
|
||||
apiVersion: extensions/v1beta1
|
||||
{{- end }}
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ $fullName }}-control
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
{{- with .Values.control.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if and .Values.control.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
|
||||
ingressClassName: {{ .Values.control.ingress.className }}
|
||||
{{- end }}
|
||||
{{- if .Values.control.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.control.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .Values.control.ingress.hosts }}
|
||||
- host: {{ .host | quote }}
|
||||
http:
|
||||
paths:
|
||||
{{- range .paths }}
|
||||
- path: {{ . }}
|
||||
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.Version }}
|
||||
pathType: ImplementationSpecific
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}-control
|
||||
port:
|
||||
number: {{ $svcPort }}
|
||||
{{- else }}
|
||||
backend:
|
||||
serviceName: {{ $fullName }}-control
|
||||
servicePort: {{ $svcPort }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,76 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if (.Values.ingress.enabled) -}}
|
||||
{{- $fullName := include "apisix.fullname" . -}}
|
||||
{{- $svcPort := .Values.ingress.servicePort | default .Values.service.http.servicePort -}}
|
||||
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
|
||||
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
|
||||
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.Version }}
|
||||
apiVersion: networking.k8s.io/v1
|
||||
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.Version }}
|
||||
apiVersion: networking.k8s.io/v1beta1
|
||||
{{- else -}}
|
||||
apiVersion: extensions/v1beta1
|
||||
{{- end }}
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ $fullName }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
|
||||
ingressClassName: {{ .Values.ingress.className }}
|
||||
{{- end }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ . | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .Values.ingress.hosts }}
|
||||
- host: {{ .host | quote }}
|
||||
http:
|
||||
paths:
|
||||
{{- range .paths }}
|
||||
- path: {{ . }}
|
||||
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.Version }}
|
||||
pathType: ImplementationSpecific
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}-gateway
|
||||
port:
|
||||
number: {{ $svcPort }}
|
||||
{{- else }}
|
||||
backend:
|
||||
serviceName: {{ $fullName }}-gateway
|
||||
servicePort: {{ $svcPort }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,38 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if (.Values.podDisruptionBudget.enabled) }}
|
||||
{{ if semverCompare "<1.21-0" .Capabilities.KubeVersion.Version -}}
|
||||
apiVersion: policy/v1beta1
|
||||
{{- else -}}
|
||||
apiVersion: policy/v1
|
||||
{{- end }}
|
||||
kind: PodDisruptionBudget
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
spec:
|
||||
{{- if .Values.podDisruptionBudget.minAvailable }}
|
||||
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
|
||||
{{- else }}
|
||||
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
|
||||
{{- end }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "apisix.selectorLabels" . | nindent 6 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,58 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
{{ if (.Values.apisix.admin.enabled) }}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}-admin
|
||||
namespace: {{ .Release.Namespace }}
|
||||
annotations:
|
||||
{{- range $key, $value := .Values.apisix.admin.annotations }}
|
||||
{{ $key }}: {{ $value | quote }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
app.kubernetes.io/service: apisix-admin
|
||||
spec:
|
||||
type: {{ .Values.apisix.admin.type }}
|
||||
{{- if eq .Values.apisix.admin.type "LoadBalancer" }}
|
||||
{{- if .Values.apisix.admin.loadBalancerIP }}
|
||||
loadBalancerIP: {{ .Values.apisix.admin.loadBalancerIP }}
|
||||
{{- end }}
|
||||
{{- if .Values.apisix.admin.loadBalancerSourceRanges }}
|
||||
loadBalancerSourceRanges:
|
||||
{{- range $cidr := .Values.apisix.admin.loadBalancerSourceRanges }}
|
||||
- {{ $cidr }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if gt (len .Values.apisix.admin.externalIPs) 0 }}
|
||||
externalIPs:
|
||||
{{- range $ip := .Values.apisix.admin.externalIPs }}
|
||||
- {{ $ip }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: apisix-admin
|
||||
port: {{ .Values.apisix.admin.servicePort }}
|
||||
targetPort: {{ .Values.apisix.admin.port }}
|
||||
{{- if (and (eq .Values.apisix.admin.type "NodePort") (not (empty .Values.apisix.admin.nodePort))) }}
|
||||
nodePort: {{ .Values.apisix.admin.nodePort }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
selector:
|
||||
{{- include "apisix.selectorLabels" . | nindent 4 }}
|
||||
{{ end }}
|
||||
@@ -0,0 +1,58 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
{{ if (and .Values.apisix.enabled .Values.control.enabled) }}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}-control
|
||||
namespace: {{ .Release.Namespace }}
|
||||
annotations:
|
||||
{{- range $key, $value := .Values.control.service.annotations }}
|
||||
{{ $key }}: {{ $value | quote }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
app.kubernetes.io/service: apisix-control
|
||||
spec:
|
||||
type: {{ .Values.control.service.type }}
|
||||
{{- if eq .Values.control.service.type "LoadBalancer" }}
|
||||
{{- if .Values.control.service.loadBalancerIP }}
|
||||
loadBalancerIP: {{ .Values.control.service.loadBalancerIP }}
|
||||
{{- end }}
|
||||
{{- if .Values.control.service.loadBalancerSourceRanges }}
|
||||
loadBalancerSourceRanges:
|
||||
{{- range $cidr := .Values.control.service.loadBalancerSourceRanges }}
|
||||
- {{ $cidr }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if gt (len .Values.control.service.externalIPs) 0 }}
|
||||
externalIPs:
|
||||
{{- range $ip := .Values.control.service.externalIPs }}
|
||||
- {{ $ip }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: apisix-control
|
||||
port: {{ .Values.control.service.servicePort }}
|
||||
targetPort: {{ .Values.control.service.port }}
|
||||
{{- if (and (eq .Values.control.service.type "NodePort") (not (empty .Values.control.service.nodePort))) }}
|
||||
nodePort: {{ .Values.control.service.nodePort }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
selector:
|
||||
{{- include "apisix.selectorLabels" . | nindent 4 }}
|
||||
{{ end }}
|
||||
@@ -0,0 +1,106 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}-gateway
|
||||
namespace: {{ .Release.Namespace }}
|
||||
annotations:
|
||||
{{- range $key, $value := .Values.service.annotations }}
|
||||
{{ $key }}: {{ $value | quote }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
app.kubernetes.io/service: apisix-gateway
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy }}
|
||||
{{- if eq .Values.service.type "LoadBalancer" }}
|
||||
{{- if .Values.service.loadBalancerIP }}
|
||||
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
|
||||
{{- end }}
|
||||
{{- if .Values.service.loadBalancerSourceRanges }}
|
||||
loadBalancerSourceRanges:
|
||||
{{- range $cidr := .Values.service.loadBalancerSourceRanges }}
|
||||
- {{ $cidr }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if gt (len .Values.service.externalIPs) 0 }}
|
||||
externalIPs:
|
||||
{{- range $ip := .Values.service.externalIPs }}
|
||||
- {{ $ip }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
{{- if .Values.service.http.enabled }}
|
||||
- name: apisix-gateway
|
||||
port: {{ .Values.service.http.servicePort }}
|
||||
targetPort: {{ .Values.service.http.containerPort }}
|
||||
{{- if (and (eq .Values.service.type "NodePort") (not (empty .Values.service.http.nodePort))) }}
|
||||
nodePort: {{ .Values.service.http.nodePort }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- range .Values.service.http.additionalContainerPorts }}
|
||||
- name: apisix-gateway-{{ .port | toString }}
|
||||
port: {{ .port }}
|
||||
targetPort: {{ .port }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- if or .Values.apisix.ssl.enabled }}
|
||||
- name: apisix-gateway-tls
|
||||
port: {{ .Values.service.tls.servicePort }}
|
||||
targetPort: {{ .Values.apisix.ssl.containerPort }}
|
||||
{{- if (and (eq .Values.service.type "NodePort") (not (empty .Values.service.tls.nodePort))) }}
|
||||
nodePort: {{ .Values.service.tls.nodePort }}
|
||||
{{- end }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- range .Values.apisix.ssl.additionalContainerPorts }}
|
||||
- name: apisix-gateway-tls-{{ .port | toString }}
|
||||
port: {{ .port }}
|
||||
targetPort: {{ .port }}
|
||||
{{- end }}
|
||||
{{- if and .Values.service.stream.enabled (or (gt (len .Values.service.stream.tcp) 0) (gt (len .Values.service.stream.udp) 0)) }}
|
||||
{{- with .Values.service.stream }}
|
||||
{{- if (gt (len .tcp) 0) }}
|
||||
{{- range $index, $port := .tcp }}
|
||||
- name: proxy-tcp-{{ $index | toString }}
|
||||
{{- if kindIs "map" $port }}
|
||||
port: {{ splitList ":" ($port.addr | toString) | last }}
|
||||
targetPort: {{ splitList ":" ($port.addr | toString) | last }}
|
||||
protocol: TCP
|
||||
{{- else }}
|
||||
port: {{ $port }}
|
||||
targetPort: {{ $port }}
|
||||
protocol: TCP
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if (gt (len .udp) 0) }}
|
||||
{{- range $index, $port := .udp }}
|
||||
- name: proxy-udp-{{ $index | toString }}
|
||||
port: {{ $port }}
|
||||
targetPort: {{ $port }}
|
||||
protocol: UDP
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
selector:
|
||||
{{- include "apisix.selectorLabels" . | nindent 4 }}
|
||||
@@ -0,0 +1,34 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
{{- if .Values.apisix.prometheus.enabled}}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "apisix.fullname" . }}-prometheus-metrics
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
app.kubernetes.io/service: apisix-prometheus-metrics
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- name: prometheus
|
||||
port: {{ .Values.apisix.prometheus.containerPort }}
|
||||
targetPort: {{ .Values.apisix.prometheus.containerPort }}
|
||||
protocol: TCP
|
||||
selector:
|
||||
{{- include "apisix.selectorLabels" . | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,44 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if .Values.metrics.serviceMonitor.enabled }}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: {{ .Values.metrics.serviceMonitor.name | default (include "apisix.fullname" .) }}
|
||||
namespace: {{ .Values.metrics.serviceMonitor.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
{{- if .Values.metrics.serviceMonitor.labels }}
|
||||
{{- toYaml .Values.metrics.serviceMonitor.labels | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.metrics.serviceMonitor.annotations }}
|
||||
annotations: {{- toYaml .Values.metrics.serviceMonitor.annotations | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
namespaceSelector:
|
||||
matchNames:
|
||||
- {{ .Values.metrics.serviceMonitor.namespace | default .Release.Namespace }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "apisix.labels" . | nindent 6 }}
|
||||
app.kubernetes.io/service: apisix-prometheus-metrics
|
||||
endpoints:
|
||||
- scheme: http
|
||||
targetPort: prometheus
|
||||
path: {{ .Values.apisix.prometheus.path }}
|
||||
interval: {{ .Values.metrics.serviceMonitor.interval }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,29 @@
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
{{- if .Values.serviceAccount.create }}
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: {{ include "apisix.serviceAccountName" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "apisix.labels" . | nindent 4 }}
|
||||
{{- with .Values.serviceAccount.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
Reference in New Issue
Block a user