-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path00-variables.sh
More file actions
executable file
·101 lines (88 loc) · 4.4 KB
/
Copy path00-variables.sh
File metadata and controls
executable file
·101 lines (88 loc) · 4.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
# Variables
# Azure Resources
# Every name below can be overridden from the environment. The App Configuration store, the key vault, the
# container registry and the PostgreSQL server all take globally unique names, so a run against a real
# subscription normally needs its own SUFFIX (or PREFIX); the defaults match the cluster created by
# ../../../scripts/01-user-assigned-managed-identity.sh, so on the emulator nothing has to be set.
# SUFFIX=contoso01 LOCATION=westeurope ./01-deploy-resources.sh
PREFIX="${PREFIX:-local}"
SUFFIX="${SUFFIX:-test}"
LOCATION="${LOCATION:-italynorth}"
RESOURCE_GROUP_NAME="${RESOURCE_GROUP_NAME:-${PREFIX}-rg}"
AKS_CLUSTER_NAME="${AKS_CLUSTER_NAME:-${PREFIX}-aks-${SUFFIX}}"
ACR_NAME="${ACR_NAME:-${PREFIX,,}acr${SUFFIX,,}}"
ACR_SKU="${ACR_SKU:-Standard}"
SUBSCRIPTION_NAME=$(az account show --query name --output tsv)
SUBSCRIPTION_ID=$(az account show --query id --output tsv)
TENANT_ID=$(az account show --query tenantId --output tsv)
CURRENT_DIR="$(cd "$(dirname "$0")" && pwd)"
# User-assigned managed identity. The App Configuration Kubernetes Provider authenticates as this identity
# through a federated credential on the cluster's OIDC issuer, so no secret is stored anywhere.
MANAGED_IDENTITY_NAME="${PREFIX}-appconfig-identity-${SUFFIX}"
FEDERATED_IDENTITY_NAME="${PREFIX}-appconfig-federated-identity-${SUFFIX}"
# Azure App Configuration. Holds every setting the app needs: the non-secret values as plain key-values and
# the credentials as Key Vault references.
APP_CONFIG_NAME="${PREFIX}-aks-appconfig-${SUFFIX}"
APP_CONFIG_SKU='Standard'
# Azure Key Vault. Uses the Azure RBAC permission model, which the Key Vault Secrets User role requires.
KEY_VAULT_NAME="${PREFIX}-aks-kv-${SUFFIX}"
KEY_VAULT_RETENTION_DAYS=7
# Key Vault secret names, and the content type that marks an App Configuration key-value as a reference to one.
PG_USER_SECRET_NAME='pg-user'
PG_PASSWORD_SECRET_NAME='pg-password'
SECRET_KEY_SECRET_NAME='secret-key'
KEY_VAULT_REFERENCE_CONTENT_TYPE='application/vnd.microsoft.appconfig.keyvaultref+json;charset=utf-8'
# Role assignments
APP_CONFIG_DATA_READER_ROLE='App Configuration Data Reader'
KEY_VAULT_SECRETS_USER_ROLE='Key Vault Secrets User'
KEY_VAULT_SECRETS_OFFICER_ROLE='Key Vault Secrets Officer'
ROLE_ASSIGNMENT_RETRY_COUNT=10
ROLE_ASSIGNMENT_RETRY_SLEEP=15
SECRET_RETRY_COUNT=10
SECRET_RETRY_SLEEP=15
# Azure Database for PostgreSQL flexible server. Its own server, so this sample and
# web-app-postgresql-flexible-server never share data.
PG_SERVER_NAME="${PREFIX}-pgflex-appconfig-${SUFFIX}"
PG_VERSION='16'
PG_SKU_TIER='Burstable'
PG_SKU_NAME='Standard_B1ms'
PG_STORAGE_SIZE_GB=32
PG_BACKUP_RETENTION_DAYS=7
PG_PORT='5432'
FIREWALL_RULE_NAME='AllowAllIPs'
PG_ADMIN_USER='pgadmin'
PG_ADMIN_PASSWORD='P@ssw0rd1234!'
PG_USER_NAME='testuser'
PG_USER_PASSWORD='TestP@ssw0rd123'
PG_DATABASE_NAME='PlannerDB'
# Application config — must match the seed-row `username` in 01-deploy-resources.sh.
# PostgreSQL `=` is case-sensitive (unlike SQL Server), so this stays lowercase.
LOGIN_NAME='paolo'
# The refresh sentinel. The provider watches this single key and re-reads the whole selection when it
# changes, which is cheaper than polling every key. 01-deploy-resources.sh seeds it to 1 and never
# overwrites it, so a manual bump survives a re-run.
SENTINEL_KEY='CONFIG_VERSION'
SENTINEL_INITIAL_VALUE='1'
REFRESH_INTERVAL='30s'
# AKS App Configuration extension. No version is pinned: the Azure CLI refuses --version unless the
# auto-upgrade mode is `none`, and both Azure and the emulator install their current release (2.6.7 at the
# time of writing) and report it as `currentVersion`.
APP_CONFIG_EXTENSION_NAME='appconfigurationkubernetesprovider'
APP_CONFIG_EXTENSION_TYPE='Microsoft.AppConfiguration'
APP_CONFIG_EXTENSION_NAMESPACE='azappconfig-system'
APP_CONFIG_PROVIDER_DEPLOYMENT='az-appconfig-k8s-provider'
APP_CONFIG_PROVIDER_CRD='azureappconfigurationproviders.azconfig.io'
# Docker Image
IMAGE_NAME="vacation-planner-appconfig"
IMAGE_PULL_POLICY="Always"
IMAGE_TAG="v1"
PORT="8080"
# Kubernetes
NAMESPACE="vacation-planner-appconfig"
DEPLOYMENT_NAME="vacation-planner-appconfig"
SERVICE_NAME="vacation-planner-appconfig"
PROVIDER_NAME="vacation-planner-appconfig"
SERVICE_ACCOUNT_NAME="vacation-planner-appconfig-sa"
# Generated by the App Configuration Kubernetes Provider, not by these scripts.
CONFIGMAP_NAME="vacation-planner-appconfig-config"
K8S_SECRET_NAME="vacation-planner-appconfig-secrets"