++ uralkal kafka rabbitmq
This commit is contained in:
parent
98dc78d4a9
commit
26f4d13d47
@ -8,3 +8,5 @@ resources:
|
|||||||
- ../../infrastructure/istio-base/uralkal
|
- ../../infrastructure/istio-base/uralkal
|
||||||
- ../../infrastructure/istio-pilot/uralkal
|
- ../../infrastructure/istio-pilot/uralkal
|
||||||
- ../../infrastructure/istio-gateway/uralkal
|
- ../../infrastructure/istio-gateway/uralkal
|
||||||
|
- ../../infrastructure/rabbitmq/uralkal
|
||||||
|
- ../../infrastructure/kafka/uralkal
|
||||||
|
|||||||
73
infrastructure/kafka/uralkal/kafka.yaml
Normal file
73
infrastructure/kafka/uralkal/kafka.yaml
Normal file
@ -0,0 +1,73 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: kafka
|
||||||
|
namespace: kafka
|
||||||
|
spec:
|
||||||
|
interval: 5m
|
||||||
|
timeout: 10m
|
||||||
|
postRenderers:
|
||||||
|
- kustomize:
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
group: apps
|
||||||
|
version: v1
|
||||||
|
kind: StatefulSet
|
||||||
|
namespace: kafka
|
||||||
|
patch: |-
|
||||||
|
- op: add
|
||||||
|
path: /spec/template/spec/nodeSelector
|
||||||
|
value:
|
||||||
|
dedicated: generic
|
||||||
|
- op: add
|
||||||
|
path: /spec/template/spec/tolerations
|
||||||
|
value: []
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
imagePullSecrets:
|
||||||
|
- regcred
|
||||||
|
defaultStorageClass: local-path
|
||||||
|
image:
|
||||||
|
pullSecrets:
|
||||||
|
- regcred
|
||||||
|
controller:
|
||||||
|
replicaCount: 1
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
persistence:
|
||||||
|
size: 8Gi
|
||||||
|
storageClass: local-path
|
||||||
|
overrideConfiguration:
|
||||||
|
offsets.topic.replication.factor: 1
|
||||||
|
transaction.state.log.replication.factor: 1
|
||||||
|
transaction.state.log.min.isr: 1
|
||||||
|
default.replication.factor: 1
|
||||||
|
min.insync.replicas: 1
|
||||||
|
broker:
|
||||||
|
replicaCount: 0
|
||||||
|
automountServiceAccountToken: true
|
||||||
|
listeners:
|
||||||
|
client:
|
||||||
|
protocol: SASL_SSL
|
||||||
|
sslClientAuth: "none"
|
||||||
|
provisioning:
|
||||||
|
enabled: false
|
||||||
|
sasl:
|
||||||
|
managedExistingSecret:
|
||||||
|
enabled: false
|
||||||
|
existingSecret: ""
|
||||||
|
enabledMechanisms: PLAIN,SCRAM-SHA-512
|
||||||
|
interBrokerMechanism: PLAIN
|
||||||
|
controllerMechanism: PLAIN
|
||||||
|
client:
|
||||||
|
users: []
|
||||||
|
passwords: ""
|
||||||
|
tls:
|
||||||
|
type: PEM
|
||||||
|
vault:
|
||||||
|
enabled: true
|
||||||
|
role: kafka
|
||||||
|
authPath: auth/kubernetes
|
||||||
|
secretPath: secrets/data/kafka/bootstrap
|
||||||
|
clusterIdKey: clusterId
|
||||||
|
interBrokerPasswordKey: interBrokerPassword
|
||||||
|
controllerPasswordKey: controllerPassword
|
||||||
6
infrastructure/kafka/uralkal/kustomization.yaml
Normal file
6
infrastructure/kafka/uralkal/kustomization.yaml
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: kafka.yaml
|
||||||
6
infrastructure/rabbitmq/uralkal/kustomization.yaml
Normal file
6
infrastructure/rabbitmq/uralkal/kustomization.yaml
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: rabbitmq.yaml
|
||||||
104
infrastructure/rabbitmq/uralkal/rabbitmq.yaml
Normal file
104
infrastructure/rabbitmq/uralkal/rabbitmq.yaml
Normal file
@ -0,0 +1,104 @@
|
|||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: rabbitmq
|
||||||
|
namespace: rabbitmq
|
||||||
|
spec:
|
||||||
|
interval: 5m
|
||||||
|
timeout: 10m
|
||||||
|
postRenderers:
|
||||||
|
- kustomize:
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
group: apps
|
||||||
|
version: v1
|
||||||
|
kind: StatefulSet
|
||||||
|
namespace: rabbitmq
|
||||||
|
patch: |-
|
||||||
|
- op: add
|
||||||
|
path: /spec/template/spec/nodeSelector
|
||||||
|
value:
|
||||||
|
dedicated: generic
|
||||||
|
- op: add
|
||||||
|
path: /spec/template/spec/tolerations
|
||||||
|
value: []
|
||||||
|
- target:
|
||||||
|
group: cert-manager.io
|
||||||
|
version: v1
|
||||||
|
kind: Certificate
|
||||||
|
namespace: gateway
|
||||||
|
name: rmq-tls
|
||||||
|
patch: |-
|
||||||
|
$patch: delete
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: rmq-tls
|
||||||
|
namespace: gateway
|
||||||
|
- target:
|
||||||
|
group: networking.istio.io
|
||||||
|
version: v1beta1
|
||||||
|
kind: Gateway
|
||||||
|
namespace: gateway
|
||||||
|
name: rmq-gateway
|
||||||
|
patch: |-
|
||||||
|
$patch: delete
|
||||||
|
apiVersion: networking.istio.io/v1beta1
|
||||||
|
kind: Gateway
|
||||||
|
metadata:
|
||||||
|
name: rmq-gateway
|
||||||
|
namespace: gateway
|
||||||
|
- target:
|
||||||
|
group: networking.istio.io
|
||||||
|
version: v1
|
||||||
|
kind: VirtualService
|
||||||
|
namespace: rabbitmq
|
||||||
|
name: rmq-virt-service
|
||||||
|
patch: |-
|
||||||
|
$patch: delete
|
||||||
|
apiVersion: networking.istio.io/v1
|
||||||
|
kind: VirtualService
|
||||||
|
metadata:
|
||||||
|
name: rmq-virt-service
|
||||||
|
namespace: rabbitmq
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
security:
|
||||||
|
allowInsecureImages: true
|
||||||
|
virtualService: null
|
||||||
|
gateway: null
|
||||||
|
certificate: null
|
||||||
|
metrics:
|
||||||
|
serviceMonitor:
|
||||||
|
enabled: false
|
||||||
|
default:
|
||||||
|
enabled: false
|
||||||
|
perObject:
|
||||||
|
enabled: false
|
||||||
|
detailed:
|
||||||
|
enabled: false
|
||||||
|
extraServiceMonitors: []
|
||||||
|
replicaCount: 1
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: 1Gi
|
||||||
|
persistence:
|
||||||
|
storageClass: local-path
|
||||||
|
size: 10Gi
|
||||||
|
auth:
|
||||||
|
securePassword: true
|
||||||
|
enableLoopbackUser: false
|
||||||
|
existingPasswordSecret: ""
|
||||||
|
vault:
|
||||||
|
enabled: true
|
||||||
|
role: rabbitmq
|
||||||
|
authPath: auth/kubernetes
|
||||||
|
secretPath: secrets/data/rabbitmq/auth
|
||||||
|
usernameKey: username
|
||||||
|
passwordKey: password
|
||||||
|
advancedConfiguration: |-
|
||||||
|
[
|
||||||
|
{rabbit, [
|
||||||
|
{loopback_users, []}
|
||||||
|
]}
|
||||||
|
].
|
||||||
Loading…
Reference in New Issue
Block a user