Baseline: pr1 HYC下载站 v2.3 before security/functional fixes
This commit is contained in:
+157
@@ -0,0 +1,157 @@
|
||||
# ============================================
|
||||
# HYC下载站 v2.3 - Kubernetes 部署指南
|
||||
# ============================================
|
||||
|
||||
## 快速部署
|
||||
|
||||
### 1. 创建命名空间 (可选)
|
||||
```bash
|
||||
kubectl create namespace hyc
|
||||
kubectl config set-context --current --namespace=hyc
|
||||
```
|
||||
|
||||
### 2. 部署应用
|
||||
```bash
|
||||
# 使用内置 PostgreSQL 和 Redis (可选)
|
||||
kubectl apply -f deployment.yaml
|
||||
kubectl apply -f postgres.yaml
|
||||
kubectl apply -f redis.yaml
|
||||
|
||||
# 或只部署应用,使用外部数据库
|
||||
kubectl apply -f deployment.yaml
|
||||
```
|
||||
|
||||
### 3. 验证部署
|
||||
```bash
|
||||
# 查看 Pods
|
||||
kubectl get pods -l app=hyc-download-server
|
||||
|
||||
# 查看日志
|
||||
kubectl logs -l app=hyc-download-server -f
|
||||
|
||||
# 查看服务
|
||||
kubectl get svc hyc-server
|
||||
```
|
||||
|
||||
### 4. 访问应用
|
||||
```bash
|
||||
# Port Forward (开发环境)
|
||||
kubectl port-forward svc/hyc-server 8080:8080
|
||||
|
||||
# 浏览器访问
|
||||
# http://localhost:8080
|
||||
# 管理界面: http://localhost:8080/api/ui/
|
||||
```
|
||||
|
||||
## 生产环境部署
|
||||
|
||||
### 1. 构建并推送镜像
|
||||
```bash
|
||||
# 构建镜像
|
||||
docker build -t hx100cv/hyc-download-station:v2.3 .
|
||||
|
||||
# 推送镜像
|
||||
docker push hx100cv/hyc-download-station:v2.3
|
||||
|
||||
# 更新 deployment.yaml 中的镜像地址
|
||||
```
|
||||
|
||||
### 2. 配置域名和 TLS
|
||||
```bash
|
||||
# 编辑 deployment.yaml,修改 Ingress 配置
|
||||
# 添加 TLS secret
|
||||
kubectl create secret tls hyc-tls-secret --cert=certificate.crt --key=private.key
|
||||
|
||||
# 应用配置
|
||||
kubectl apply -f deployment.yaml
|
||||
```
|
||||
|
||||
### 3. 配置资源限制
|
||||
```yaml
|
||||
# 根据实际需求调整 deployment.yaml 中的资源限制
|
||||
resources:
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: 2000m
|
||||
memory: 2Gi
|
||||
```
|
||||
|
||||
### 4. 配置 HPA (自动扩缩容)
|
||||
```bash
|
||||
# HPA 已内置,查看状态
|
||||
kubectl get hpa hyc-hpa
|
||||
kubectl top pods
|
||||
```
|
||||
|
||||
## 使用外部数据库
|
||||
|
||||
### PostgreSQL
|
||||
```bash
|
||||
# 设置环境变量或 Secret
|
||||
export DB_TYPE=postgresql
|
||||
export DB_HOST=your-postgres-host
|
||||
export DB_PORT=5432
|
||||
export DB_NAME=hyc
|
||||
export DB_USER=postgres
|
||||
export DB_PASSWORD=your-password
|
||||
|
||||
# 或使用连接字符串
|
||||
export DB_CONN_STR=postgresql://user:pass@host:5432/database
|
||||
```
|
||||
|
||||
### MySQL
|
||||
```bash
|
||||
export DB_TYPE=mysql
|
||||
export DB_HOST=your-mysql-host
|
||||
export DB_PORT=3306
|
||||
export DB_NAME=hyc
|
||||
export DB_USER=root
|
||||
export DB_PASSWORD=your-password
|
||||
```
|
||||
|
||||
## 监控
|
||||
|
||||
### Prometheus + Grafana
|
||||
```bash
|
||||
# ServiceMonitor 已内置
|
||||
# 确保 Prometheus Operator 已安装
|
||||
kubectl get servicemonitor hyc-monitor
|
||||
|
||||
# Grafana Dashboard (导入 json/dashboard.json)
|
||||
```
|
||||
|
||||
### 日志
|
||||
```bash
|
||||
# 查看应用日志
|
||||
kubectl logs -l app=hyc-download-server --tail=100
|
||||
|
||||
# 实时日志
|
||||
kubectl logs -l app=hyc-download-server -f
|
||||
```
|
||||
|
||||
## 升级
|
||||
|
||||
```bash
|
||||
# 更新镜像版本
|
||||
kubectl set image deployment/hyc-server hyc-server=hx100cv/hyc-download-station:v2.4
|
||||
|
||||
# 查看滚动更新
|
||||
kubectl rollout status deployment/hyc-server
|
||||
|
||||
# 回滚 (如有问题)
|
||||
kubectl rollout undo deployment/hyc-server
|
||||
```
|
||||
|
||||
## 卸载
|
||||
|
||||
```bash
|
||||
# 删除所有资源
|
||||
kubectl delete -f deployment.yaml
|
||||
kubectl delete -f postgres.yaml
|
||||
kubectl delete -f redis.yaml
|
||||
|
||||
# 删除 PVC (数据将丢失)
|
||||
kubectl delete pvc hyc-data-pvc hyc-downloads-pvc hyc-cache-pvc
|
||||
```
|
||||
@@ -0,0 +1,237 @@
|
||||
# ============================================
|
||||
# HYC下载站 v2.3 - Kubernetes 部署配置
|
||||
# ============================================
|
||||
|
||||
---
|
||||
# ConfigMap - 应用配置
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: hyc-config
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
data:
|
||||
HYC_HOST: "0.0.0.0"
|
||||
HYC_PORT: "8080"
|
||||
HYC_BASE_DIR: "/downloads"
|
||||
HYC_ENABLE_MONITOR: "true"
|
||||
HYC_ENABLE_SYNC: "true"
|
||||
HYC_ENABLE_MIRRORS: "true"
|
||||
HYC_ENABLE_WS: "true"
|
||||
HYC_ENABLE_SSE: "true"
|
||||
|
||||
---
|
||||
# Secret - 数据库凭据
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: hyc-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
# PostgreSQL 凭据
|
||||
DB_HOST: "hyc-postgres"
|
||||
DB_PORT: "5432"
|
||||
DB_NAME: "hyc"
|
||||
DB_USER: "postgres"
|
||||
DB_PASSWORD: "your-password-here"
|
||||
|
||||
# Redis 凭据 (可选)
|
||||
REDIS_HOST: "hyc-redis"
|
||||
REDIS_PORT: "6379"
|
||||
|
||||
---
|
||||
# PersistentVolumeClaim - 数据存储
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: hyc-data-pvc
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Gi
|
||||
|
||||
---
|
||||
# PersistentVolumeClaim - 下载目录
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: hyc-downloads-pvc
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 100Gi
|
||||
|
||||
---
|
||||
# PersistentVolumeClaim - 缓存目录
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: hyc-cache-pvc
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 50Gi
|
||||
|
||||
---
|
||||
# Deployment - 主应用
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: hyc-server
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hyc-download-server
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
spec:
|
||||
containers:
|
||||
- name: hyc-server
|
||||
image: hyc-download-station:v2.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: http
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: hyc-config
|
||||
- secretRef:
|
||||
name: hyc-secrets
|
||||
volumeMounts:
|
||||
- name: data-volume
|
||||
mountPath: /data
|
||||
- name: downloads-volume
|
||||
mountPath: /downloads
|
||||
resources:
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: 2000m
|
||||
memory: 2Gi
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /api/v1/health
|
||||
port: 8080
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /api/v1/health
|
||||
port: 8080
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
volumes:
|
||||
- name: data-volume
|
||||
persistentVolumeClaim:
|
||||
claimName: hyc-data-pvc
|
||||
- name: downloads-volume
|
||||
persistentVolumeClaim:
|
||||
claimName: hyc-downloads-pvc
|
||||
- name: cache-volume
|
||||
persistentVolumeClaim:
|
||||
claimName: hyc-cache-pvc
|
||||
|
||||
---
|
||||
# Service - 内部服务
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hyc-server
|
||||
labels:
|
||||
app: hyc-download-server
|
||||
spec:
|
||||
type: ClusterIP
|
||||
ports:
|
||||
- port: 8080
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
name: http
|
||||
selector:
|
||||
app: hyc-download-server
|
||||
|
||||
---
|
||||
# Ingress - 外部访问
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: hyc-ingress
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/proxy-body-size: "2G"
|
||||
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
rules:
|
||||
- host: hyc.example.com
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: hyc-server
|
||||
port:
|
||||
number: 8080
|
||||
|
||||
---
|
||||
# HorizontalPodAutoscaler - 自动扩缩容
|
||||
apiVersion: autoscaling/v2
|
||||
kind: HorizontalPodAutoscaler
|
||||
metadata:
|
||||
name: hyc-hpa
|
||||
spec:
|
||||
scaleTargetRef:
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
name: hyc-server
|
||||
minReplicas: 2
|
||||
maxReplicas: 10
|
||||
metrics:
|
||||
- type: Resource
|
||||
resource:
|
||||
name: cpu
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: 70
|
||||
- type: Resource
|
||||
resource:
|
||||
name: memory
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: 80
|
||||
|
||||
---
|
||||
# ServiceMonitor - Prometheus 监控
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: hyc-monitor
|
||||
labels:
|
||||
release: prometheus
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hyc-download-server
|
||||
endpoints:
|
||||
- port: http
|
||||
path: /metrics
|
||||
interval: 15s
|
||||
@@ -0,0 +1,28 @@
|
||||
# ============================================
|
||||
# HYC下载站 Helm Chart
|
||||
# ============================================
|
||||
|
||||
apiVersion: v2
|
||||
name: hyc-download-station
|
||||
description: HYC下载站 v2.3 - 镜像文件服务器 + 下载加速源
|
||||
version: 2.2.0
|
||||
appVersion: "2.2.0"
|
||||
keywords:
|
||||
- download-station
|
||||
- mirror
|
||||
- docker-registry
|
||||
- apt-mirror
|
||||
- pypi-mirror
|
||||
home: https://github.com/hyc-download-station
|
||||
maintainers:
|
||||
- name: HYC Team
|
||||
email: [email protected]
|
||||
dependencies:
|
||||
- name: postgresql
|
||||
version: 12.x.x
|
||||
condition: postgresql.enabled
|
||||
repository: "https://charts.bitnami.com/bitnami"
|
||||
- name: redis
|
||||
version: 18.x.x
|
||||
condition: redis.enabled
|
||||
repository: "https://charts.bitnami.com/bitnami"
|
||||
@@ -0,0 +1,31 @@
|
||||
=============================================
|
||||
HYC下载站 v2.3 已成功部署!
|
||||
=============================================
|
||||
|
||||
1. 获取应用 URL:
|
||||
|
||||
{{- if .Values.ingress.enabled }}
|
||||
{{- range $host := .Values.ingress.hosts }}
|
||||
http://{{ $host.host }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
# Port Forward (开发环境)
|
||||
kubectl port-forward svc/{{ include "hyc.fullname" . }} {{ .Values.service.port }}:{{ .Values.service.port }}
|
||||
|
||||
# 访问地址
|
||||
http://localhost:{{ .Values.service.port }}
|
||||
{{- end }}
|
||||
|
||||
2. 管理界面:
|
||||
http://<your-url>/api/ui/
|
||||
|
||||
3. API 文档:
|
||||
http://<your-url>/api/docs/
|
||||
|
||||
4. 查看状态:
|
||||
kubectl get pods -l {{ include "hyc.selectorLabels" . | trimSuffix "-" | replace "=" "=" | replace " " "" }}
|
||||
|
||||
5. 查看日志:
|
||||
kubectl logs -l {{ include "hyc.selectorLabels" . | trimSuffix "-" | replace "=" "=" | replace " " "" }} -f
|
||||
|
||||
=============================================
|
||||
@@ -0,0 +1,59 @@
|
||||
{{/*
|
||||
创建完整名称
|
||||
*/}}
|
||||
{{- define "hyc.fullname" -}}
|
||||
{{- printf "%s-%s" .Release.Name (include "hyc.name" .) | trunc 63 -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
标签
|
||||
*/}}
|
||||
{{- define "hyc.labels" -}}
|
||||
helm.sh/chart: {{ include "hyc.chart" . }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
app.kubernetes.io/part-of: {{ .Chart.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
选择器标签
|
||||
*/}}
|
||||
{{- define "hyc.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "hyc.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
图表名称
|
||||
*/}}
|
||||
{{- define "hyc.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
图表版本
|
||||
*/}}
|
||||
{{- define "hyc.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
PostgreSQL 主机
|
||||
*/}}
|
||||
{{- define "hyc.postgresql.host" -}}
|
||||
{{- if .Values.postgresql.enabled -}}
|
||||
{{- printf "%s-%s" .Release.Name "postgresql" -}}
|
||||
{{- else -}}
|
||||
{{- .Values.config.database.postgresql.host | default "localhost" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Redis 主机
|
||||
*/}}
|
||||
{{- define "hyc.redis.host" -}}
|
||||
{{- if .Values.redis.enabled -}}
|
||||
{{- printf "%s-%s" .Release.Name "redis" -}}
|
||||
{{- else -}}
|
||||
{{- .Values.config.database.redis.host | default "localhost" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,142 @@
|
||||
{{- if not .Values.postgresql.enabled }}
|
||||
{{- if not .Values.redis.enabled }}
|
||||
---
|
||||
# 独立部署 (无依赖)
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-config
|
||||
data:
|
||||
HYC_HOST: {{ .Values.config.host | quote }}
|
||||
HYC_PORT: {{ .Values.config.port | quote }}
|
||||
HYC_BASE_DIR: {{ .Values.config.baseDir | quote }}
|
||||
HYC_CACHE_DIR: {{ .Values.config.cacheDir | quote }}
|
||||
HYC_ENABLE_MONITOR: {{ .Values.config.enableMonitor | quote }}
|
||||
HYC_ENABLE_SYNC: {{ .Values.config.enableSync | quote }}
|
||||
HYC_ENABLE_MIRRORS: {{ .Values.config.enableMirrors | quote }}
|
||||
HYC_ENABLE_WS: {{ .Values.config.enableWs | quote }}
|
||||
HYC_ENABLE_SSE: {{ .Values.config.enableSse | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{- if .Values.postgresql.enabled }}
|
||||
DB_HOST: {{ include "hyc.postgresql.host" . }}
|
||||
DB_PORT: "5432"
|
||||
DB_NAME: {{ .Values.postgresql.auth.database }}
|
||||
DB_USER: {{ .Values.postgresql.auth.username }}
|
||||
DB_PASSWORD: {{ .Values.postgresql.auth.password }}
|
||||
{{- else if .Values.config.database.external.enabled }}
|
||||
DB_CONN_STR: {{ .Values.config.database.external.connectionString }}
|
||||
{{- end }}
|
||||
{{- if .Values.redis.enabled }}
|
||||
REDIS_HOST: {{ include "hyc.redis.host" . }}
|
||||
REDIS_PORT: "6379"
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "hyc.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "hyc.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: {{ .Values.config.port }}
|
||||
name: http
|
||||
envFrom:
|
||||
{{- if not .Values.postgresql.enabled }}
|
||||
{{- if not .Values.config.database.external.enabled }}
|
||||
- configMapRef:
|
||||
name: {{ include "hyc.fullname" . }}-config
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
- secretRef:
|
||||
name: {{ include "hyc.fullname" . }}-secrets
|
||||
volumeMounts:
|
||||
- name: data-volume
|
||||
mountPath: /data
|
||||
- name: downloads-volume
|
||||
mountPath: {{ .Values.config.baseDir }}
|
||||
- name: caches-volume
|
||||
mountPath: {{ .Values.config.cacheDir }}
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
{{- if .Values.livenessProbe.enabled }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /api/v1/health
|
||||
port: {{ .Values.config.port }}
|
||||
initialDelaySeconds: {{ .Values.livenessProbe.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.livenessProbe.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.livenessProbe.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.livenessProbe.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.readinessProbe.enabled }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /api/v1/health
|
||||
port: {{ .Values.config.port }}
|
||||
initialDelaySeconds: {{ .Values.readinessProbe.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.readinessProbe.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.readinessProbe.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.readinessProbe.failureThreshold }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: data-volume
|
||||
{{- if .Values.persistence.data.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "hyc.fullname" . }}-data-pvc
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
- name: downloads-volume
|
||||
{{- if .Values.persistence.downloads.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "hyc.fullname" . }}-downloads-pvc
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
- name: caches-volume
|
||||
{{- if .Values.persistence.caches.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "hyc.fullname" . }}-caches-pvc
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,37 @@
|
||||
{{- if .Values.autoscaling.enabled }}
|
||||
---
|
||||
apiVersion: autoscaling/v2
|
||||
kind: HorizontalPodAutoscaler
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-hpa
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
scaleTargetRef:
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
name: {{ include "hyc.fullname" . }}
|
||||
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||
metrics:
|
||||
{{- toYaml .Values.autoscaling.metrics | nindent 4 }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.metrics.enabled }}
|
||||
---
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-monitor
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
release: {{ .Values.metrics.release }}
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "hyc.selectorLabels" . | nindent 6 }}
|
||||
endpoints:
|
||||
- port: http
|
||||
path: /metrics
|
||||
interval: {{ .Values.metrics.interval }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,56 @@
|
||||
{{- if .Values.persistence.data.enabled }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-data-pvc
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.data.size }}
|
||||
{{- if .Values.persistence.data.storageClass }}
|
||||
storageClassName: {{ .Values.persistence.data.storageClass }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.persistence.downloads.enabled }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-downloads-pvc
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.downloads.size }}
|
||||
{{- if .Values.persistence.downloads.storageClass }}
|
||||
storageClassName: {{ .Values.persistence.downloads.storageClass }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.persistence.caches.enabled }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-caches-pvc
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.caches.size }}
|
||||
{{- if .Values.persistence.caches.storageClass }}
|
||||
storageClassName: {{ .Values.persistence.caches.storageClass }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
- port: {{ .Values.service.port }}
|
||||
targetPort: http
|
||||
protocol: TCP
|
||||
name: http
|
||||
selector:
|
||||
{{- include "hyc.selectorLabels" . | nindent 4 }}
|
||||
|
||||
{{- if .Values.ingress.enabled }}
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-ingress
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/proxy-body-size: "2G"
|
||||
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
|
||||
spec:
|
||||
ingressClassName: {{ .Values.ingress.className }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- toYaml .Values.ingress.tls | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- toYaml .Values.ingress.hosts | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,169 @@
|
||||
# ============================================
|
||||
# HYC下载站 Helm Chart - 默认配置
|
||||
# ============================================
|
||||
|
||||
# 副本数
|
||||
replicaCount: 2
|
||||
|
||||
# 镜像配置
|
||||
image:
|
||||
repository: hyc-download-station
|
||||
tag: v2.3
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
# 镜像拉取密钥 (如需要私有仓库)
|
||||
imagePullSecrets: []
|
||||
|
||||
# 服务配置
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 8080
|
||||
|
||||
# 入口配置 (Ingress)
|
||||
ingress:
|
||||
enabled: true
|
||||
className: nginx
|
||||
hosts:
|
||||
- host: hyc.example.com
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls: []
|
||||
# - secretName: hyc-tls
|
||||
# hosts:
|
||||
# - hyc.example.com
|
||||
|
||||
# 资源配置
|
||||
resources:
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: 2000m
|
||||
memory: 2Gi
|
||||
|
||||
# 持久化配置
|
||||
persistence:
|
||||
data:
|
||||
enabled: true
|
||||
storageClass: ""
|
||||
size: 10Gi
|
||||
downloads:
|
||||
enabled: true
|
||||
storageClass: ""
|
||||
size: 100Gi
|
||||
caches:
|
||||
enabled: true
|
||||
storageClass: ""
|
||||
size: 50Gi
|
||||
|
||||
# PostgreSQL (可选)
|
||||
postgresql:
|
||||
enabled: false
|
||||
auth:
|
||||
database: hyc
|
||||
username: postgres
|
||||
password: "postgres-password"
|
||||
|
||||
# Redis (可选)
|
||||
redis:
|
||||
enabled: false
|
||||
auth:
|
||||
enabled: true
|
||||
password: "redis-password"
|
||||
|
||||
# 应用配置
|
||||
config:
|
||||
# 基础配置
|
||||
host: "0.0.0.0"
|
||||
port: 8080
|
||||
baseDir: "/downloads"
|
||||
apiVersion: "v2"
|
||||
|
||||
# 功能开关
|
||||
enableMonitor: true
|
||||
enableSync: true
|
||||
enableMirrors: true
|
||||
enableWs: true
|
||||
enableSse: true
|
||||
|
||||
# 数据库配置
|
||||
database:
|
||||
enabled: true
|
||||
type: "postgresql"
|
||||
syncInterval: 60
|
||||
|
||||
# 速率限制
|
||||
rateLimit:
|
||||
requestsPerMinute: 100
|
||||
burstLimit: 20
|
||||
|
||||
# 安全配置
|
||||
security:
|
||||
# IP 白名单/黑名单
|
||||
ip:
|
||||
whitelist: []
|
||||
blacklist: []
|
||||
|
||||
# SSL/TLS
|
||||
ssl:
|
||||
enabled: false
|
||||
cert: ""
|
||||
key: ""
|
||||
|
||||
# 节点选择器
|
||||
nodeSelector: {}
|
||||
|
||||
# 容忍
|
||||
tolerations: []
|
||||
|
||||
# 亲和性
|
||||
affinity: {}
|
||||
|
||||
# 探针
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
timeoutSeconds: 3
|
||||
failureThreshold: 3
|
||||
|
||||
# 滚动更新策略
|
||||
rollingUpdate:
|
||||
maxSurge: 1
|
||||
maxUnavailable: 0
|
||||
|
||||
# 拓扑分布 (可选)
|
||||
topologySpreadConstraints: []
|
||||
|
||||
# 自动扩缩容
|
||||
autoscaling:
|
||||
enabled: true
|
||||
minReplicas: 2
|
||||
maxReplicas: 10
|
||||
metrics:
|
||||
- type: Resource
|
||||
resource:
|
||||
name: cpu
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: 70
|
||||
- type: Resource
|
||||
resource:
|
||||
name: memory
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: 80
|
||||
|
||||
# 监控指标
|
||||
metrics:
|
||||
enabled: false
|
||||
release: prometheus
|
||||
interval: 15s
|
||||
@@ -0,0 +1,113 @@
|
||||
# ============================================
|
||||
# PostgreSQL 数据库部署 (可选)
|
||||
# ============================================
|
||||
|
||||
---
|
||||
# StorageClass (如果需要动态供应)
|
||||
apiVersion: storage.k8s.io/v1
|
||||
kind: StorageClass
|
||||
metadata:
|
||||
name: hyc-storage
|
||||
provisioner: kubernetes.io/no-provisioner
|
||||
volumeBindingMode: WaitForFirstConsumer
|
||||
|
||||
---
|
||||
# PersistentVolume - PostgreSQL 数据
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
name: hyc-postgres-pv
|
||||
spec:
|
||||
capacity:
|
||||
storage: 20Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
storageClassName: hyc-storage
|
||||
hostPath:
|
||||
path: /data/hyc-postgres
|
||||
type: DirectoryOrCreate
|
||||
|
||||
---
|
||||
# PersistentVolumeClaim - PostgreSQL
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: hyc-postgres-pvc
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 20Gi
|
||||
storageClassName: hyc-storage
|
||||
|
||||
---
|
||||
# Secret - PostgreSQL 凭据
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: hyc-postgres-secret
|
||||
type: Opaque
|
||||
stringData:
|
||||
POSTGRES_DB: hyc
|
||||
POSTGRES_USER: postgres
|
||||
POSTGRES_PASSWORD: your-secure-password
|
||||
|
||||
---
|
||||
# Service - PostgreSQL
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hyc-postgres
|
||||
spec:
|
||||
selector:
|
||||
app: hyc-postgres
|
||||
ports:
|
||||
- port: 5432
|
||||
targetPort: 5432
|
||||
clusterIP: None
|
||||
|
||||
---
|
||||
# Deployment - PostgreSQL
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: hyc-postgres
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hyc-postgres
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: hyc-postgres
|
||||
spec:
|
||||
containers:
|
||||
- name: postgres
|
||||
image: postgres:15-alpine
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: hyc-postgres-secret
|
||||
volumeMounts:
|
||||
- name: postgres-data
|
||||
mountPath: /var/lib/postgresql/data
|
||||
resources:
|
||||
requests:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: 1000m
|
||||
memory: 1Gi
|
||||
livenessProbe:
|
||||
exec:
|
||||
command:
|
||||
- pg_isready
|
||||
- -U
|
||||
- postgres
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
volumes:
|
||||
- name: postgres-data
|
||||
persistentVolumeClaim:
|
||||
claimName: hyc-postgres-pvc
|
||||
@@ -0,0 +1,93 @@
|
||||
# ============================================
|
||||
# Redis 缓存部署 (可选,用于速率限制)
|
||||
# ============================================
|
||||
|
||||
---
|
||||
# PersistentVolumeClaim - Redis
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: hyc-redis-pvc
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 5Gi
|
||||
|
||||
---
|
||||
# Secret - Redis 凭据 (可选)
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: hyc-redis-secret
|
||||
type: Opaque
|
||||
stringData:
|
||||
REDIS_PASSWORD: your-redis-password
|
||||
|
||||
---
|
||||
# Service - Redis
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hyc-redis
|
||||
spec:
|
||||
selector:
|
||||
app: hyc-redis
|
||||
ports:
|
||||
- port: 6379
|
||||
targetPort: 6379
|
||||
clusterIP: None
|
||||
|
||||
---
|
||||
# Deployment - Redis
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: hyc-redis
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hyc-redis
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: hyc-redis
|
||||
spec:
|
||||
containers:
|
||||
- name: redis
|
||||
image: redis:7-alpine
|
||||
command:
|
||||
- redis-server
|
||||
- --appendonly
|
||||
- "yes"
|
||||
- --maxmemory
|
||||
- "256mb"
|
||||
- --maxmemory-policy
|
||||
- allkeys-lru
|
||||
volumeMounts:
|
||||
- name: redis-data
|
||||
mountPath: /data
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
livenessProbe:
|
||||
exec:
|
||||
command:
|
||||
- redis-cli
|
||||
- ping
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
volumes:
|
||||
- name: redis-data
|
||||
persistentVolumeClaim:
|
||||
claimName: hyc-redis-pvc
|
||||
|
||||
---
|
||||
# RedisCluster (可选,集群模式)
|
||||
# 如果需要高可用,可以改用 Redis Operator
|
||||
Reference in New Issue
Block a user