Cross-file `needs:` across separate nested helmfiles didn't resolve in Helmfile v1 (releases defined in sibling files weren't visible to each other's dependency graph) -- confirmed live against the homelab cluster: kafka-cluster failed with "depend(s) on an undefined release" even though strimzi-operator had just been installed successfully by a sibling file. Collapsed releases.d/*.gotmpl into a single helmfile.yaml.gotmpl so the whole release graph is resolved together. Also add a second Ingress (management-service-grpc, backend-protocol: GRPC) scoped to the QueueService gRPC path prefix on the same host/port as the REST ingress. kmsvc-cli dials --server directly via gRPC (default kmsvc.homelab.internal:443 per its README), so raw gRPC needs an external path too, not just REST -- the original "gRPC stays internal" default didn't account for the CLI's own connection model. Add Dockerfile.queue-operator (existed for cmd/server only before).
45 lines
1.1 KiB
YAML
45 lines
1.1 KiB
YAML
namespace: sqs
|
|
replicaCount: 2
|
|
|
|
image:
|
|
repository: forgejo.riotpiao.homelab.com/rock/kafka-management-service
|
|
tag: latest
|
|
pullPolicy: IfNotPresent
|
|
|
|
grpcPort: 9090
|
|
httpPort: 8080
|
|
|
|
env:
|
|
kafkaBrokers: "kmsvc-kafka-bootstrap.sqs.svc.cluster.local:9092"
|
|
redisAddr: "kmsvc-redis-master.sqs.svc.cluster.local:6379"
|
|
authentikIssuerURL: ""
|
|
authentikAudience: ""
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 200m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 512Mi
|
|
|
|
hpa:
|
|
enabled: true
|
|
minReplicas: 2
|
|
maxReplicas: 6
|
|
targetCPUUtilizationPercentage: 70
|
|
targetMemoryUtilizationPercentage: 80
|
|
|
|
ingress:
|
|
enabled: true
|
|
className: nginx
|
|
clusterIssuer: homelab-ca
|
|
host: kmsvc.homelab.internal
|
|
tlsSecretName: kmsvc-tls
|
|
# kmsvc-cli connects via gRPC directly to --server/KMSVC_SERVER (default
|
|
# kmsvc.homelab.internal:443, see kmsvc-cli's README), so raw gRPC needs an
|
|
# external path too — scoped to the gRPC service's own path prefix on the
|
|
# same host/port, rather than opening the whole host to gRPC passthrough.
|
|
grpcEnabled: true
|
|
grpcPathPrefix: /kafkamgmt.v1.QueueService/
|