2017-07-17 13:46:05 +02:00
|
|
|
apiVersion: extensions/v1beta1
|
|
|
|
kind: Deployment
|
|
|
|
metadata:
|
2017-08-16 10:44:08 +02:00
|
|
|
name: ngx-instance-0-dep
|
2017-07-17 13:46:05 +02:00
|
|
|
spec:
|
|
|
|
replicas: 1
|
|
|
|
template:
|
|
|
|
metadata:
|
|
|
|
labels:
|
2017-08-16 10:44:08 +02:00
|
|
|
app: ngx-instance-0-dep
|
2017-07-17 13:46:05 +02:00
|
|
|
spec:
|
|
|
|
terminationGracePeriodSeconds: 10
|
|
|
|
containers:
|
2017-08-16 10:44:08 +02:00
|
|
|
- name: nginx
|
2018-05-11 15:23:15 +02:00
|
|
|
image: bigchaindb/nginx_https:2.0.0-alpha5
|
2018-02-22 11:56:58 +01:00
|
|
|
imagePullPolicy: Always
|
2017-07-17 13:46:05 +02:00
|
|
|
env:
|
2018-03-15 16:20:15 +01:00
|
|
|
- name: NODE_FRONTEND_PORT
|
2017-07-17 13:46:05 +02:00
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
2018-03-15 16:20:15 +01:00
|
|
|
key: node-frontend-port
|
2017-07-17 13:46:05 +02:00
|
|
|
- name: HEALTH_CHECK_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
2018-03-20 19:34:01 +01:00
|
|
|
key: node-health-check-port
|
2018-02-27 02:29:44 +01:00
|
|
|
- name: NODE_FQDN
|
2017-07-17 13:46:05 +02:00
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
2018-02-27 02:29:44 +01:00
|
|
|
key: node-fqdn
|
2017-07-17 13:46:05 +02:00
|
|
|
- name: DNS_SERVER
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
2018-03-20 19:34:01 +01:00
|
|
|
key: node-dns-server-ip
|
2017-07-17 13:46:05 +02:00
|
|
|
- name: MONGODB_BACKEND_HOST
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: ngx-mdb-instance-name
|
|
|
|
- name: MONGODB_BACKEND_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: mongodb-backend-port
|
|
|
|
- name: OPENRESTY_BACKEND_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: openresty-backend-port
|
|
|
|
- name: OPENRESTY_BACKEND_HOST
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
2017-08-05 13:07:54 +02:00
|
|
|
key: ngx-openresty-instance-name
|
2017-07-17 13:46:05 +02:00
|
|
|
- name: BIGCHAINDB_BACKEND_HOST
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: ngx-bdb-instance-name
|
|
|
|
- name: BIGCHAINDB_API_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: bigchaindb-api-port
|
|
|
|
- name: BIGCHAINDB_WS_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: bigchaindb-ws-port
|
2018-02-01 13:01:41 +01:00
|
|
|
- name: TM_PUB_KEY_ACCESS_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: tendermint-config
|
2018-04-27 15:54:47 +02:00
|
|
|
key: bdb-pub-key-access
|
2018-02-01 13:01:41 +01:00
|
|
|
- name: TM_P2P_PORT
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: tendermint-config
|
2018-04-27 15:54:47 +02:00
|
|
|
key: bdb-p2p-port
|
2018-02-23 16:00:36 +01:00
|
|
|
- name: AUTHORIZATION_MODE
|
|
|
|
valueFrom:
|
|
|
|
configMapKeyRef:
|
|
|
|
name: vars
|
|
|
|
key: authorization-mode
|
2018-02-26 19:11:28 +01:00
|
|
|
- name: SECRET_ACCESS_TOKEN
|
|
|
|
valueFrom:
|
|
|
|
secretKeyRef:
|
|
|
|
name: nginx-secret-header
|
|
|
|
key: secret-token
|
2017-07-17 13:46:05 +02:00
|
|
|
ports:
|
|
|
|
# return a pretty error message on port 80, since we are expecting
|
|
|
|
# HTTPS traffic.
|
|
|
|
- containerPort: 80
|
|
|
|
protocol: TCP
|
2018-02-22 11:52:41 +01:00
|
|
|
- containerPort: 443
|
2017-07-17 13:46:05 +02:00
|
|
|
protocol: TCP
|
2018-02-22 11:52:41 +01:00
|
|
|
- containerPort: 8888
|
2017-07-17 13:46:05 +02:00
|
|
|
protocol: TCP
|
|
|
|
name: ngx-port
|
2018-02-22 11:52:41 +01:00
|
|
|
- containerPort: 9986
|
2018-02-01 13:01:41 +01:00
|
|
|
protocol: TCP
|
2018-04-27 15:54:47 +02:00
|
|
|
name: bdb-pub-key
|
2018-07-10 14:16:02 +02:00
|
|
|
- containerPort: 26656
|
2018-02-01 13:01:41 +01:00
|
|
|
protocol: TCP
|
2018-04-27 15:54:47 +02:00
|
|
|
name: bdb-p2p-port
|
2017-07-17 13:46:05 +02:00
|
|
|
livenessProbe:
|
|
|
|
httpGet:
|
|
|
|
path: /health
|
|
|
|
port: ngx-port
|
|
|
|
initialDelaySeconds: 15
|
|
|
|
periodSeconds: 15
|
|
|
|
failureThreshold: 3
|
|
|
|
timeoutSeconds: 10
|
|
|
|
resources:
|
|
|
|
limits:
|
|
|
|
cpu: 200m
|
|
|
|
memory: 768Mi
|
|
|
|
volumeMounts:
|
|
|
|
- name: https-certs
|
|
|
|
mountPath: /etc/nginx/ssl/
|
|
|
|
readOnly: true
|
|
|
|
restartPolicy: Always
|
|
|
|
volumes:
|
|
|
|
- name: https-certs
|
|
|
|
secret:
|
|
|
|
secretName: https-certs
|
|
|
|
defaultMode: 0400
|