erp-java/services/system-tool-service/k8s/deployment.yaml

211 lines
4.7 KiB
YAML

apiVersion: v1
kind: Namespace
metadata:
name: erp-prod
labels:
name: erp-prod
environment: production
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: system-tool-service
namespace: erp-prod
labels:
app: system-tool-service
---
apiVersion: v1
kind: Secret
metadata:
name: system-tool-service-secrets
namespace: erp-prod
type: Opaque
stringData:
DB_PASSWORD: "REPLACE_WITH_DB_PASSWORD"
REDIS_PASSWORD: "REPLACE_WITH_REDIS_PASSWORD"
---
apiVersion: v1
kind: ConfigMap
metadata:
name: system-tool-service-config
namespace: erp-prod
data:
SPRING_PROFILES_ACTIVE: "prod"
JAVA_OPTS: "-Xms256m -Xmx512m -XX:+UseG1GC"
NACOS_HOST: "nacos"
NACOS_NAMESPACE: "prod"
NACOS_PORT: "8848"
DB_HOST: "mysql"
DB_PORT: "3306"
DB_NAME: "erp_java"
DB_USERNAME: "erp_user"
REDIS_HOST: "redis"
REDIS_PORT: "6379"
SERVER_PORT: "8087"
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: system-tool-service
namespace: erp-prod
labels:
app: system-tool-service
version: v1
tier: backend
spec:
replicas: 1
revisionHistoryLimit: 10
selector:
matchLabels:
app: system-tool-service
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
template:
metadata:
labels:
app: system-tool-service
version: v1
tier: backend
annotations:
prometheus.io/scrape: "true"
prometheus.io/port: "8087"
prometheus.io/path: "/actuator/prometheus"
spec:
serviceAccountName: system-tool-service
securityContext:
runAsNonRoot: true
runAsUser: 1001
fsGroup: 1001
containers:
- name: system-tool-service
image: registry.erpzbbh.cn/erp/system-tool-service:1.0.0
imagePullPolicy: Always
ports:
- name: http
containerPort: 8087
protocol: TCP
envFrom:
- configMapRef:
name: system-tool-service-config
- secretRef:
name: system-tool-service-secrets
resources:
requests:
memory: "256Mi"
cpu: "100m"
limits:
memory: "512Mi"
cpu: "500m"
livenessProbe:
httpGet:
path: /actuator/health/liveness
port: http
initialDelaySeconds: 60
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /actuator/health/readiness
port: http
initialDelaySeconds: 30
periodSeconds: 5
timeoutSeconds: 3
failureThreshold: 3
startupProbe:
httpGet:
path: /actuator/health/liveness
port: http
initialDelaySeconds: 10
periodSeconds: 5
failureThreshold: 30
lifecycle:
preStop:
exec:
command: ["sh", "-c", "sleep 10"]
volumeMounts:
- name: app-logs
mountPath: /app/logs
volumes:
- name: app-logs
emptyDir: {}
---
apiVersion: v1
kind: Service
metadata:
name: system-tool-service
namespace: erp-prod
spec:
type: ClusterIP
ports:
- name: http
port: 8087
targetPort: http
selector:
app: system-tool-service
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: system-tool-service-ingress
namespace: erp-prod
annotations:
nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
ingressClassName: nginx
tls:
- hosts:
- systemtool.erpzbbh.cn
secretName: system-tool-service-tls
rules:
- host: systemtool.erpzbbh.cn
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: system-tool-service
port:
name: http
---
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: system-tool-service-hpa
namespace: erp-prod
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: system-tool-service
minReplicas: 1
maxReplicas: 5
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 70
- type: Resource
resource:
name: memory
target:
type: Utilization
averageUtilization: 80
---
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: system-tool-service-pdb
namespace: erp-prod
spec:
minAvailable: 1
selector:
matchLabels:
app: system-tool-service