Baseline: pr1 HYC下载站 v2.3 before security/functional fixes
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# ============================================
|
||||
# HYC下载站 Helm Chart
|
||||
# ============================================
|
||||
|
||||
apiVersion: v2
|
||||
name: hyc-download-station
|
||||
description: HYC下载站 v2.3 - 镜像文件服务器 + 下载加速源
|
||||
version: 2.2.0
|
||||
appVersion: "2.2.0"
|
||||
keywords:
|
||||
- download-station
|
||||
- mirror
|
||||
- docker-registry
|
||||
- apt-mirror
|
||||
- pypi-mirror
|
||||
home: https://github.com/hyc-download-station
|
||||
maintainers:
|
||||
- name: HYC Team
|
||||
email: [email protected]
|
||||
dependencies:
|
||||
- name: postgresql
|
||||
version: 12.x.x
|
||||
condition: postgresql.enabled
|
||||
repository: "https://charts.bitnami.com/bitnami"
|
||||
- name: redis
|
||||
version: 18.x.x
|
||||
condition: redis.enabled
|
||||
repository: "https://charts.bitnami.com/bitnami"
|
||||
@@ -0,0 +1,31 @@
|
||||
=============================================
|
||||
HYC下载站 v2.3 已成功部署!
|
||||
=============================================
|
||||
|
||||
1. 获取应用 URL:
|
||||
|
||||
{{- if .Values.ingress.enabled }}
|
||||
{{- range $host := .Values.ingress.hosts }}
|
||||
http://{{ $host.host }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
# Port Forward (开发环境)
|
||||
kubectl port-forward svc/{{ include "hyc.fullname" . }} {{ .Values.service.port }}:{{ .Values.service.port }}
|
||||
|
||||
# 访问地址
|
||||
http://localhost:{{ .Values.service.port }}
|
||||
{{- end }}
|
||||
|
||||
2. 管理界面:
|
||||
http://<your-url>/api/ui/
|
||||
|
||||
3. API 文档:
|
||||
http://<your-url>/api/docs/
|
||||
|
||||
4. 查看状态:
|
||||
kubectl get pods -l {{ include "hyc.selectorLabels" . | trimSuffix "-" | replace "=" "=" | replace " " "" }}
|
||||
|
||||
5. 查看日志:
|
||||
kubectl logs -l {{ include "hyc.selectorLabels" . | trimSuffix "-" | replace "=" "=" | replace " " "" }} -f
|
||||
|
||||
=============================================
|
||||
@@ -0,0 +1,59 @@
|
||||
{{/*
|
||||
创建完整名称
|
||||
*/}}
|
||||
{{- define "hyc.fullname" -}}
|
||||
{{- printf "%s-%s" .Release.Name (include "hyc.name" .) | trunc 63 -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
标签
|
||||
*/}}
|
||||
{{- define "hyc.labels" -}}
|
||||
helm.sh/chart: {{ include "hyc.chart" . }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
app.kubernetes.io/part-of: {{ .Chart.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
选择器标签
|
||||
*/}}
|
||||
{{- define "hyc.selectorLabels" -}}
|
||||
app.kubernetes.io/name: {{ include "hyc.name" . }}
|
||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
图表名称
|
||||
*/}}
|
||||
{{- define "hyc.name" -}}
|
||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
图表版本
|
||||
*/}}
|
||||
{{- define "hyc.chart" -}}
|
||||
{{- printf "%s-%s" .Chart.Name .Chart.Version -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
PostgreSQL 主机
|
||||
*/}}
|
||||
{{- define "hyc.postgresql.host" -}}
|
||||
{{- if .Values.postgresql.enabled -}}
|
||||
{{- printf "%s-%s" .Release.Name "postgresql" -}}
|
||||
{{- else -}}
|
||||
{{- .Values.config.database.postgresql.host | default "localhost" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Redis 主机
|
||||
*/}}
|
||||
{{- define "hyc.redis.host" -}}
|
||||
{{- if .Values.redis.enabled -}}
|
||||
{{- printf "%s-%s" .Release.Name "redis" -}}
|
||||
{{- else -}}
|
||||
{{- .Values.config.database.redis.host | default "localhost" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,142 @@
|
||||
{{- if not .Values.postgresql.enabled }}
|
||||
{{- if not .Values.redis.enabled }}
|
||||
---
|
||||
# 独立部署 (无依赖)
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-config
|
||||
data:
|
||||
HYC_HOST: {{ .Values.config.host | quote }}
|
||||
HYC_PORT: {{ .Values.config.port | quote }}
|
||||
HYC_BASE_DIR: {{ .Values.config.baseDir | quote }}
|
||||
HYC_CACHE_DIR: {{ .Values.config.cacheDir | quote }}
|
||||
HYC_ENABLE_MONITOR: {{ .Values.config.enableMonitor | quote }}
|
||||
HYC_ENABLE_SYNC: {{ .Values.config.enableSync | quote }}
|
||||
HYC_ENABLE_MIRRORS: {{ .Values.config.enableMirrors | quote }}
|
||||
HYC_ENABLE_WS: {{ .Values.config.enableWs | quote }}
|
||||
HYC_ENABLE_SSE: {{ .Values.config.enableSse | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-secrets
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{- if .Values.postgresql.enabled }}
|
||||
DB_HOST: {{ include "hyc.postgresql.host" . }}
|
||||
DB_PORT: "5432"
|
||||
DB_NAME: {{ .Values.postgresql.auth.database }}
|
||||
DB_USER: {{ .Values.postgresql.auth.username }}
|
||||
DB_PASSWORD: {{ .Values.postgresql.auth.password }}
|
||||
{{- else if .Values.config.database.external.enabled }}
|
||||
DB_CONN_STR: {{ .Values.config.database.external.connectionString }}
|
||||
{{- end }}
|
||||
{{- if .Values.redis.enabled }}
|
||||
REDIS_HOST: {{ include "hyc.redis.host" . }}
|
||||
REDIS_PORT: "6379"
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "hyc.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "hyc.selectorLabels" . | nindent 8 }}
|
||||
spec:
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: {{ .Values.config.port }}
|
||||
name: http
|
||||
envFrom:
|
||||
{{- if not .Values.postgresql.enabled }}
|
||||
{{- if not .Values.config.database.external.enabled }}
|
||||
- configMapRef:
|
||||
name: {{ include "hyc.fullname" . }}-config
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
- secretRef:
|
||||
name: {{ include "hyc.fullname" . }}-secrets
|
||||
volumeMounts:
|
||||
- name: data-volume
|
||||
mountPath: /data
|
||||
- name: downloads-volume
|
||||
mountPath: {{ .Values.config.baseDir }}
|
||||
- name: caches-volume
|
||||
mountPath: {{ .Values.config.cacheDir }}
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
{{- if .Values.livenessProbe.enabled }}
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /api/v1/health
|
||||
port: {{ .Values.config.port }}
|
||||
initialDelaySeconds: {{ .Values.livenessProbe.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.livenessProbe.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.livenessProbe.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.livenessProbe.failureThreshold }}
|
||||
{{- end }}
|
||||
{{- if .Values.readinessProbe.enabled }}
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /api/v1/health
|
||||
port: {{ .Values.config.port }}
|
||||
initialDelaySeconds: {{ .Values.readinessProbe.initialDelaySeconds }}
|
||||
periodSeconds: {{ .Values.readinessProbe.periodSeconds }}
|
||||
timeoutSeconds: {{ .Values.readinessProbe.timeoutSeconds }}
|
||||
failureThreshold: {{ .Values.readinessProbe.failureThreshold }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: data-volume
|
||||
{{- if .Values.persistence.data.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "hyc.fullname" . }}-data-pvc
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
- name: downloads-volume
|
||||
{{- if .Values.persistence.downloads.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "hyc.fullname" . }}-downloads-pvc
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
- name: caches-volume
|
||||
{{- if .Values.persistence.caches.enabled }}
|
||||
persistentVolumeClaim:
|
||||
claimName: {{ include "hyc.fullname" . }}-caches-pvc
|
||||
{{- else }}
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,37 @@
|
||||
{{- if .Values.autoscaling.enabled }}
|
||||
---
|
||||
apiVersion: autoscaling/v2
|
||||
kind: HorizontalPodAutoscaler
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-hpa
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
scaleTargetRef:
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
name: {{ include "hyc.fullname" . }}
|
||||
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||
metrics:
|
||||
{{- toYaml .Values.autoscaling.metrics | nindent 4 }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.metrics.enabled }}
|
||||
---
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-monitor
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
release: {{ .Values.metrics.release }}
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "hyc.selectorLabels" . | nindent 6 }}
|
||||
endpoints:
|
||||
- port: http
|
||||
path: /metrics
|
||||
interval: {{ .Values.metrics.interval }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,56 @@
|
||||
{{- if .Values.persistence.data.enabled }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-data-pvc
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.data.size }}
|
||||
{{- if .Values.persistence.data.storageClass }}
|
||||
storageClassName: {{ .Values.persistence.data.storageClass }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.persistence.downloads.enabled }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-downloads-pvc
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.downloads.size }}
|
||||
{{- if .Values.persistence.downloads.storageClass }}
|
||||
storageClassName: {{ .Values.persistence.downloads.storageClass }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.persistence.caches.enabled }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-caches-pvc
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: {{ .Values.persistence.caches.size }}
|
||||
{{- if .Values.persistence.caches.storageClass }}
|
||||
storageClassName: {{ .Values.persistence.caches.storageClass }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
spec:
|
||||
type: {{ .Values.service.type }}
|
||||
ports:
|
||||
- port: {{ .Values.service.port }}
|
||||
targetPort: http
|
||||
protocol: TCP
|
||||
name: http
|
||||
selector:
|
||||
{{- include "hyc.selectorLabels" . | nindent 4 }}
|
||||
|
||||
{{- if .Values.ingress.enabled }}
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ include "hyc.fullname" . }}-ingress
|
||||
labels:
|
||||
{{- include "hyc.labels" . | nindent 4 }}
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/proxy-body-size: "2G"
|
||||
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
|
||||
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
|
||||
spec:
|
||||
ingressClassName: {{ .Values.ingress.className }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- toYaml .Values.ingress.tls | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- toYaml .Values.ingress.hosts | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,169 @@
|
||||
# ============================================
|
||||
# HYC下载站 Helm Chart - 默认配置
|
||||
# ============================================
|
||||
|
||||
# 副本数
|
||||
replicaCount: 2
|
||||
|
||||
# 镜像配置
|
||||
image:
|
||||
repository: hyc-download-station
|
||||
tag: v2.3
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
# 镜像拉取密钥 (如需要私有仓库)
|
||||
imagePullSecrets: []
|
||||
|
||||
# 服务配置
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 8080
|
||||
|
||||
# 入口配置 (Ingress)
|
||||
ingress:
|
||||
enabled: true
|
||||
className: nginx
|
||||
hosts:
|
||||
- host: hyc.example.com
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
tls: []
|
||||
# - secretName: hyc-tls
|
||||
# hosts:
|
||||
# - hyc.example.com
|
||||
|
||||
# 资源配置
|
||||
resources:
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: 2000m
|
||||
memory: 2Gi
|
||||
|
||||
# 持久化配置
|
||||
persistence:
|
||||
data:
|
||||
enabled: true
|
||||
storageClass: ""
|
||||
size: 10Gi
|
||||
downloads:
|
||||
enabled: true
|
||||
storageClass: ""
|
||||
size: 100Gi
|
||||
caches:
|
||||
enabled: true
|
||||
storageClass: ""
|
||||
size: 50Gi
|
||||
|
||||
# PostgreSQL (可选)
|
||||
postgresql:
|
||||
enabled: false
|
||||
auth:
|
||||
database: hyc
|
||||
username: postgres
|
||||
password: "postgres-password"
|
||||
|
||||
# Redis (可选)
|
||||
redis:
|
||||
enabled: false
|
||||
auth:
|
||||
enabled: true
|
||||
password: "redis-password"
|
||||
|
||||
# 应用配置
|
||||
config:
|
||||
# 基础配置
|
||||
host: "0.0.0.0"
|
||||
port: 8080
|
||||
baseDir: "/downloads"
|
||||
apiVersion: "v2"
|
||||
|
||||
# 功能开关
|
||||
enableMonitor: true
|
||||
enableSync: true
|
||||
enableMirrors: true
|
||||
enableWs: true
|
||||
enableSse: true
|
||||
|
||||
# 数据库配置
|
||||
database:
|
||||
enabled: true
|
||||
type: "postgresql"
|
||||
syncInterval: 60
|
||||
|
||||
# 速率限制
|
||||
rateLimit:
|
||||
requestsPerMinute: 100
|
||||
burstLimit: 20
|
||||
|
||||
# 安全配置
|
||||
security:
|
||||
# IP 白名单/黑名单
|
||||
ip:
|
||||
whitelist: []
|
||||
blacklist: []
|
||||
|
||||
# SSL/TLS
|
||||
ssl:
|
||||
enabled: false
|
||||
cert: ""
|
||||
key: ""
|
||||
|
||||
# 节点选择器
|
||||
nodeSelector: {}
|
||||
|
||||
# 容忍
|
||||
tolerations: []
|
||||
|
||||
# 亲和性
|
||||
affinity: {}
|
||||
|
||||
# 探针
|
||||
livenessProbe:
|
||||
enabled: true
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
|
||||
readinessProbe:
|
||||
enabled: true
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
timeoutSeconds: 3
|
||||
failureThreshold: 3
|
||||
|
||||
# 滚动更新策略
|
||||
rollingUpdate:
|
||||
maxSurge: 1
|
||||
maxUnavailable: 0
|
||||
|
||||
# 拓扑分布 (可选)
|
||||
topologySpreadConstraints: []
|
||||
|
||||
# 自动扩缩容
|
||||
autoscaling:
|
||||
enabled: true
|
||||
minReplicas: 2
|
||||
maxReplicas: 10
|
||||
metrics:
|
||||
- type: Resource
|
||||
resource:
|
||||
name: cpu
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: 70
|
||||
- type: Resource
|
||||
resource:
|
||||
name: memory
|
||||
target:
|
||||
type: Utilization
|
||||
averageUtilization: 80
|
||||
|
||||
# 监控指标
|
||||
metrics:
|
||||
enabled: false
|
||||
release: prometheus
|
||||
interval: 15s
|
||||
Reference in New Issue
Block a user