Files
poimen-memory/k8s/app/memory-app-deployment.yaml
T

104 lines
2.3 KiB
YAML
Raw Normal View History

---
apiVersion: apps/v1
kind: Deployment
metadata:
name: memory-app
namespace: poimen
labels:
app: memory-service
spec:
replicas: 2
selector:
matchLabels:
app: memory-service
template:
metadata:
labels:
app: memory-service
annotations:
# Trigger pod restart if ConfigMap changes
checksum/config: "synthesis-endpoints"
spec:
serviceAccountName: memory-app
containers:
- name: memory-app
image: forgejo.riotpiao.com/rock/poimen-memory:latest
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 8080
protocol: TCP
# ConfigMap-injected env vars (decrypted by ArgoCD+KSOPS from .enc.yaml)
envFrom:
- configMapRef:
name: synthesis-endpoints
# Individual env vars for app config
env:
- name: RUST_LOG
value: "info,memory=debug"
- name: PORT
value: "8080"
# JWT secret from vault (NOT ConfigMap)
- name: JWT_SECRET
valueFrom:
secretKeyRef:
name: jwt-secrets
key: signing-key
livenessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 10
periodSeconds: 30
readinessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 5
periodSeconds: 10
resources:
requests:
memory: "256Mi"
cpu: "100m"
limits:
memory: "1Gi"
cpu: "500m"
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
capabilities:
drop:
- ALL
# ArgoCD uses KSOPS plugin to decrypt synthesis-endpoints.enc.yaml
# before creating the ConfigMap in the cluster
---
apiVersion: v1
kind: Service
metadata:
name: memory-service
namespace: poimen
labels:
app: memory-service
spec:
type: ClusterIP
ports:
- port: 80
targetPort: http
protocol: TCP
name: http
selector:
app: memory-service