-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdeployment.yml
More file actions
72 lines (72 loc) · 2.55 KB
/
Copy pathdeployment.yml
File metadata and controls
72 lines (72 loc) · 2.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
apiVersion: apps/v1
kind: Deployment
metadata:
name: vacation-planner-appconfig
namespace: vacation-planner-appconfig
labels:
app: vacation-planner-appconfig
spec:
replicas: 3
selector:
matchLabels:
app: vacation-planner-appconfig
strategy:
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
type: RollingUpdate
minReadySeconds: 5
template:
metadata:
labels:
app: vacation-planner-appconfig
spec:
nodeSelector:
kubernetes.io/os: linux
# The same service account the provider uses. The pods get it so the two objects they consume and
# the identity that produced them stay visibly connected; the application itself never calls Azure,
# which is why there is no azure.workload.identity/use label on this pod template.
serviceAccountName: vacation-planner-appconfig-sa
containers:
- name: vacation-planner-appconfig
image: <your-registry>.azurecr.io/vacation-planner-appconfig:v1
imagePullPolicy: Always
ports:
- name: http
containerPort: 8080
# Every setting comes from the two objects the App Configuration Kubernetes Provider generates,
# taken wholesale rather than key by key: the store is the single source of truth, so a key added
# there reaches the pods without editing this manifest. The ConfigMap carries PG_HOST, PG_PORT,
# PG_DATABASE, LOGIN_NAME, DEBUG and CONFIG_VERSION; the Secret carries PG_USER, PG_PASSWORD and
# SECRET_KEY, resolved from Key Vault references.
#
# Environment variables are immutable once a container has started, so a refreshed ConfigMap
# reaches the pods only after `kubectl rollout restart`. See the README.
envFrom:
- configMapRef:
name: vacation-planner-appconfig-config
- secretRef:
name: vacation-planner-appconfig-secrets
resources:
requests:
cpu: "200m"
memory: "256Mi"
limits:
cpu: "1000m"
memory: "512Mi"
livenessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 30
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 10
periodSeconds: 10
timeoutSeconds: 3
failureThreshold: 3