++ sarex-contour: kafka + rabbitmq
infrastructure/kafka/sarex-contour, infrastructure/rabbitmq/sarex-contour (values по образцу yc-k8s-test, controller-only kafka KRaft, rabbitmq 1 реплика, local-path). Vault для них уже заведён отдельно (terraform environments.sarex-contour.vault, kafka/rabbitmq policy+role+kv). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
49342404c0
commit
0c882d76c2
@ -9,6 +9,8 @@ resources:
|
|||||||
- ../../infrastructure/istio-pilot/sarex-contour
|
- ../../infrastructure/istio-pilot/sarex-contour
|
||||||
- ../../infrastructure/istio-gateway/sarex-contour
|
- ../../infrastructure/istio-gateway/sarex-contour
|
||||||
- ../../infrastructure/vault/sarex-contour
|
- ../../infrastructure/vault/sarex-contour
|
||||||
|
- ../../infrastructure/kafka/sarex-contour
|
||||||
|
- ../../infrastructure/rabbitmq/sarex-contour
|
||||||
|
|
||||||
# apps
|
# apps
|
||||||
- ../../apps/control-interface/sarex-contour
|
- ../../apps/control-interface/sarex-contour
|
||||||
|
|||||||
60
infrastructure/kafka/sarex-contour/kafka.yaml
Normal file
60
infrastructure/kafka/sarex-contour/kafka.yaml
Normal file
@ -0,0 +1,60 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: kafka
|
||||||
|
namespace: kafka
|
||||||
|
spec:
|
||||||
|
interval: 5m
|
||||||
|
timeout: 10m
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
imagePullSecrets:
|
||||||
|
- regcred
|
||||||
|
defaultStorageClass: local-path
|
||||||
|
image:
|
||||||
|
pullSecrets:
|
||||||
|
- regcred
|
||||||
|
controller:
|
||||||
|
replicaCount: 1
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
persistence:
|
||||||
|
size: 8Gi
|
||||||
|
storageClass: local-path
|
||||||
|
overrideConfiguration:
|
||||||
|
authorizer.class.name: org.apache.kafka.metadata.authorizer.StandardAuthorizer
|
||||||
|
allow.everyone.if.no.acl.found: true
|
||||||
|
super.users: User:controller_user;User:inter_broker_user
|
||||||
|
offsets.topic.replication.factor: 1
|
||||||
|
transaction.state.log.replication.factor: 1
|
||||||
|
transaction.state.log.min.isr: 1
|
||||||
|
default.replication.factor: 1
|
||||||
|
min.insync.replicas: 1
|
||||||
|
broker:
|
||||||
|
replicaCount: 0
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
listeners:
|
||||||
|
client:
|
||||||
|
protocol: SASL_SSL
|
||||||
|
sslClientAuth: "none"
|
||||||
|
provisioning:
|
||||||
|
enabled: false
|
||||||
|
sasl:
|
||||||
|
managedExistingSecret:
|
||||||
|
enabled: false
|
||||||
|
existingSecret: ""
|
||||||
|
enabledMechanisms: PLAIN,SCRAM-SHA-512
|
||||||
|
interBrokerMechanism: PLAIN
|
||||||
|
controllerMechanism: PLAIN
|
||||||
|
client:
|
||||||
|
users: []
|
||||||
|
passwords: ""
|
||||||
|
tls:
|
||||||
|
type: PEM
|
||||||
|
vault:
|
||||||
|
enabled: true
|
||||||
|
role: kafka
|
||||||
|
authPath: auth/kubernetes
|
||||||
|
secretPath: secrets/data/kafka/bootstrap
|
||||||
|
clusterIdKey: clusterId
|
||||||
|
interBrokerPasswordKey: interBrokerPassword
|
||||||
|
controllerPasswordKey: controllerPassword
|
||||||
6
infrastructure/kafka/sarex-contour/kustomization.yaml
Normal file
6
infrastructure/kafka/sarex-contour/kustomization.yaml
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: kafka.yaml
|
||||||
6
infrastructure/rabbitmq/sarex-contour/kustomization.yaml
Normal file
6
infrastructure/rabbitmq/sarex-contour/kustomization.yaml
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: rabbitmq.yaml
|
||||||
42
infrastructure/rabbitmq/sarex-contour/rabbitmq.yaml
Normal file
42
infrastructure/rabbitmq/sarex-contour/rabbitmq.yaml
Normal file
@ -0,0 +1,42 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: rabbitmq
|
||||||
|
namespace: rabbitmq
|
||||||
|
spec:
|
||||||
|
interval: 5m
|
||||||
|
timeout: 10m
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
security:
|
||||||
|
allowInsecureImages: true
|
||||||
|
virtualService: null
|
||||||
|
gateway: null
|
||||||
|
certificate: null
|
||||||
|
metrics:
|
||||||
|
serviceMonitor:
|
||||||
|
enabled: false
|
||||||
|
default:
|
||||||
|
enabled: false
|
||||||
|
perObject:
|
||||||
|
enabled: false
|
||||||
|
detailed:
|
||||||
|
enabled: false
|
||||||
|
extraServiceMonitors: []
|
||||||
|
replicaCount: 1
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: 1Gi
|
||||||
|
persistence:
|
||||||
|
storageClass: local-path
|
||||||
|
size: 10Gi
|
||||||
|
auth:
|
||||||
|
securePassword: true
|
||||||
|
existingPasswordSecret: ""
|
||||||
|
vault:
|
||||||
|
enabled: true
|
||||||
|
role: rabbitmq
|
||||||
|
authPath: auth/kubernetes
|
||||||
|
secretPath: secrets/data/rabbitmq/auth
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: password
|
||||||
Loading…
Reference in New Issue
Block a user