-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathdeployment.yml
More file actions
165 lines (157 loc) · 5.97 KB
/
Copy pathdeployment.yml
File metadata and controls
165 lines (157 loc) · 5.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
apiVersion: apps/v1
kind: Deployment
metadata:
name: vacation-planner-file
namespace: vacation-planner-file
labels:
app: vacation-planner-file
spec:
replicas: 3
selector:
matchLabels:
app: vacation-planner-file
strategy:
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
type: RollingUpdate
minReadySeconds: 5
template:
metadata:
labels:
app: vacation-planner-file
spec:
nodeSelector:
kubernetes.io/os: linux
volumes:
# The Azure file share, mounted by the Azure Files CSI driver. All three replicas mount the
# same share, which is what makes the activities they serve identical.
- name: activities
persistentVolumeClaim:
claimName: vacation-planner-file-pvc
# The sample activities the init container copies into the share when they are missing
- name: seed
configMap:
name: vacation-planner-file-seed
# Prepares the file share before the app starts, and runs as root, which is why the app
# container declares its own securityContext instead of the pod declaring it for both.
#
# On NFS it takes ownership of the mount point: an NFS share carries real POSIX ownership,
# arrives owned by root, and ignores the uid and gid mount options that solve this for SMB.
# securityContext.fsGroup is not an alternative: the file.csi.azure.com CSIDriver object
# declares fsGroupPolicy: ReadWriteOnceWithFSType, so the kubelet applies fsGroup only to a
# ReadWriteOnce volume with a file system type, and this volume is ReadWriteMany. Setting
# fsGroup here would silently do nothing. The chown is not recursive: files created by the app
# already belong to it, and a recursive chown over NFS would make every pod start slower as the
# share fills up.
#
# It then seeds the share with the sample activities, skipping the files that are already there,
# so the three replicas starting at the same time cannot conflict.
initContainers:
- name: init-file-share
image: <your-registry>.azurecr.io/vacation-planner-file:v1
imagePullPolicy: Always
securityContext:
runAsUser: 0
runAsGroup: 0
env:
# Set to smb or nfs by 05-deploy-app.sh. The chown must not run on an SMB mount, where it
# fails with EPERM because the CIFS client synthesizes ownership from the mount options.
- name: FILE_SHARE_PROTOCOL
value: smb
- name: ACTIVITIES_DIR
valueFrom:
configMapKeyRef:
name: vacation-planner-file-config
key: ACTIVITIES_DIR
command:
- /bin/sh
- -c
- |
set -e
# A no-op when ACTIVITIES_DIR is the mount point itself, which is the default. It
# matters when it points at a subdirectory of the share: that directory has to exist
# before it can be chowned or seeded, and the app is not able to create it as uid 1000
# on an NFS share owned by root.
mkdir -p "$ACTIVITIES_DIR"
if [ "$FILE_SHARE_PROTOCOL" = "nfs" ]; then
echo "Taking ownership of $ACTIVITIES_DIR as uid 1000..."
chown 1000:1000 "$ACTIVITIES_DIR"
chmod 0755 "$ACTIVITIES_DIR"
fi
for file in /seed/*-activity.txt; do
[ -e "$file" ] || continue
name=$(basename "$file")
if [ -e "$ACTIVITIES_DIR/$name" ]; then
echo "Activity file [$name] already exists in the file share, skipping it..."
continue
fi
echo "Seeding the file share with the activity file [$name]..."
cp "$file" "$ACTIVITIES_DIR/$name"
if [ "$FILE_SHARE_PROTOCOL" = "nfs" ]; then
chown 1000:1000 "$ACTIVITIES_DIR/$name"
fi
done
echo "The file share is ready."
volumeMounts:
- name: activities
mountPath: /data
- name: seed
mountPath: /seed
readOnly: true
resources:
requests:
cpu: "100m"
memory: "128Mi"
limits:
cpu: "500m"
memory: "256Mi"
containers:
- name: vacation-planner-file
image: <your-registry>.azurecr.io/vacation-planner-file:v1
imagePullPolicy: Always
# The image already runs as this user, declared here as well because it is the identity the
# mount options of the SMB volume and the ownership of the NFS share are aligned with.
securityContext:
runAsUser: 1000
runAsGroup: 1000
ports:
- name: http
containerPort: 8080
env:
- name: ACTIVITIES_DIR
valueFrom:
configMapKeyRef:
name: vacation-planner-file-config
key: ACTIVITIES_DIR
- name: SECRET_KEY
valueFrom:
secretKeyRef:
name: vacation-planner-file-secrets
key: SECRET_KEY
volumeMounts:
- name: activities
mountPath: /data
resources:
requests:
cpu: "100m"
memory: "128Mi"
limits:
cpu: "500m"
memory: "256Mi"
livenessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 15
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 3
failureThreshold: 3