init
This commit is contained in:
73
k8s/backend.yaml
Normal file
73
k8s/backend.yaml
Normal file
@ -0,0 +1,73 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: backend-config
|
||||
namespace: python-navigator-demo
|
||||
data:
|
||||
DB_HOST: postgres
|
||||
DB_PORT: "5432"
|
||||
DB_NAME: python-navigator-demo
|
||||
DB_USER: python-navigator-demo
|
||||
DEX_ISSUER: https://dex.127.0.0.1.sslip.io/
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: backend-secret
|
||||
namespace: python-navigator-demo
|
||||
type: Opaque
|
||||
stringData:
|
||||
DB_PASSWORD: python-navigator-demo
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: backend
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: backend
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: backend
|
||||
spec:
|
||||
containers:
|
||||
- name: backend
|
||||
image: navigator-demo-backend:latest
|
||||
imagePullPolicy: Never # Для локальной разработки
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: backend-config
|
||||
- secretRef:
|
||||
name: backend-secret
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /api/health
|
||||
port: 8000
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /api/health
|
||||
port: 8000
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 5
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: backend
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
selector:
|
||||
app: backend
|
||||
ports:
|
||||
- port: 8000
|
||||
targetPort: 8000
|
||||
type: ClusterIP
|
||||
|
||||
12
k8s/dex-authenticator.yaml
Normal file
12
k8s/dex-authenticator.yaml
Normal file
@ -0,0 +1,12 @@
|
||||
apiVersion: deckhouse.io/v1
|
||||
kind: DexAuthenticator
|
||||
metadata:
|
||||
name: python-navigator-demo-auth
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
applicationDomain: python-navigator-demo.127.0.0.1.sslip.io
|
||||
sendAuthorizationHeader: true
|
||||
applicationIngressCertificateSecretName: python-navigator-demo-tls
|
||||
applicationIngressClassName: nginx
|
||||
keepUsersLoggedInFor: 24h
|
||||
|
||||
34
k8s/frontend.yaml
Normal file
34
k8s/frontend.yaml
Normal file
@ -0,0 +1,34 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: frontend
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: frontend
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: frontend
|
||||
spec:
|
||||
containers:
|
||||
- name: frontend
|
||||
image: python-navigator-demo-frontend:latest
|
||||
imagePullPolicy: Never
|
||||
ports:
|
||||
- containerPort: 80
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: frontend
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
selector:
|
||||
app: frontend
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
type: ClusterIP
|
||||
|
||||
41
k8s/ingress.yaml
Normal file
41
k8s/ingress.yaml
Normal file
@ -0,0 +1,41 @@
|
||||
# Единый Ingress с аутентификацией для всего приложения
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: python-navigator-demo
|
||||
namespace: python-navigator-demo
|
||||
annotations:
|
||||
nginx.ingress.kubernetes.io/auth-signin: https://$host/dex-authenticator/sign_in
|
||||
nginx.ingress.kubernetes.io/auth-url: https://python-navigator-demo-auth-dex-authenticator.python-navigator-demo.svc.cluster.local/dex-authenticator/auth
|
||||
nginx.ingress.kubernetes.io/auth-response-headers: X-Auth-Request-User,X-Auth-Request-Email,Authorization
|
||||
nginx.ingress.kubernetes.io/configuration-snippet: |
|
||||
proxy_set_header X-Auth-Request-User $http_x_auth_request_user;
|
||||
proxy_set_header X-Auth-Request-Email $http_x_auth_request_email;
|
||||
proxy_set_header Authorization $http_authorization;
|
||||
spec:
|
||||
ingressClassName: nginx
|
||||
tls:
|
||||
- hosts:
|
||||
- python-navigator-demo.127.0.0.1.sslip.io
|
||||
secretName: python-navigator-demo-tls
|
||||
rules:
|
||||
- host: python-navigator-demo.127.0.0.1.sslip.io
|
||||
http:
|
||||
paths:
|
||||
# API запросы идут напрямую в backend
|
||||
- path: /api
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: backend
|
||||
port:
|
||||
number: 8000
|
||||
# Все остальное идет в frontend
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: frontend
|
||||
port:
|
||||
number: 80
|
||||
|
||||
5
k8s/namespace.yaml
Normal file
5
k8s/namespace.yaml
Normal file
@ -0,0 +1,5 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: python-navigator-demo
|
||||
|
||||
199
k8s/postgres.yaml
Normal file
199
k8s/postgres.yaml
Normal file
@ -0,0 +1,199 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: postgres-secret
|
||||
namespace: python-navigator-demo
|
||||
type: Opaque
|
||||
stringData:
|
||||
POSTGRES_DB: python-navigator-demo
|
||||
POSTGRES_USER: python-navigator-demo
|
||||
POSTGRES_PASSWORD: python-navigator-demo
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: postgres-pvc
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: postgres-init
|
||||
namespace: python-navigator-demo
|
||||
data:
|
||||
init.sql: |
|
||||
-- Создание таблиц для демо-приложения
|
||||
|
||||
-- Организации
|
||||
CREATE TABLE IF NOT EXISTS organizations (
|
||||
id SERIAL PRIMARY KEY,
|
||||
name VARCHAR(255) NOT NULL,
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
|
||||
-- Пользователи
|
||||
CREATE TABLE IF NOT EXISTS users (
|
||||
id SERIAL PRIMARY KEY,
|
||||
email VARCHAR(255) UNIQUE NOT NULL,
|
||||
full_name VARCHAR(255) NOT NULL,
|
||||
organization_id INTEGER REFERENCES organizations(id),
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
|
||||
-- Роли
|
||||
CREATE TABLE IF NOT EXISTS roles (
|
||||
id SERIAL PRIMARY KEY,
|
||||
name VARCHAR(100) UNIQUE NOT NULL,
|
||||
description TEXT,
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
|
||||
-- Связь пользователей и ролей
|
||||
CREATE TABLE IF NOT EXISTS user_roles (
|
||||
user_id INTEGER REFERENCES users(id) ON DELETE CASCADE,
|
||||
role_id INTEGER REFERENCES roles(id) ON DELETE CASCADE,
|
||||
assigned_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||
PRIMARY KEY (user_id, role_id)
|
||||
);
|
||||
|
||||
-- Доступные ссылки
|
||||
CREATE TABLE IF NOT EXISTS links (
|
||||
id SERIAL PRIMARY KEY,
|
||||
title VARCHAR(255) NOT NULL,
|
||||
url VARCHAR(512) NOT NULL,
|
||||
description TEXT,
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
|
||||
-- Связь ролей и доступных ссылок
|
||||
CREATE TABLE IF NOT EXISTS role_links (
|
||||
role_id INTEGER REFERENCES roles(id) ON DELETE CASCADE,
|
||||
link_id INTEGER REFERENCES links(id) ON DELETE CASCADE,
|
||||
PRIMARY KEY (role_id, link_id)
|
||||
);
|
||||
|
||||
-- Заполнение тестовыми данными
|
||||
|
||||
-- Организации
|
||||
INSERT INTO organizations (name) VALUES
|
||||
('Acme Corporation'),
|
||||
('Tech Innovators Inc'),
|
||||
('Global Solutions Ltd');
|
||||
|
||||
-- Роли
|
||||
INSERT INTO roles (name, description) VALUES
|
||||
('admin', 'Администратор с полным доступом'),
|
||||
('developer', 'Разработчик с доступом к техническим ресурсам'),
|
||||
('user', 'Обычный пользователь с базовым доступом'),
|
||||
('manager', 'Менеджер с доступом к управленческим ресурсам');
|
||||
|
||||
-- Пользователи (используйте реальные email из Dex)
|
||||
INSERT INTO users (email, full_name, organization_id) VALUES
|
||||
('egor.muratov@gmail.com', 'Иван Администраторов', 1),
|
||||
('developer@example.com', 'Мария Разработчикова', 2),
|
||||
('user@example.com', 'Петр Пользователев', 3),
|
||||
('manager@example.com', 'Анна Менеджерова', 1);
|
||||
|
||||
-- Назначение ролей пользователям
|
||||
-- admin@example.com - admin + developer
|
||||
INSERT INTO user_roles (user_id, role_id) VALUES
|
||||
(1, 1), -- admin role
|
||||
(1, 2); -- developer role
|
||||
|
||||
-- developer@example.com - developer + user
|
||||
INSERT INTO user_roles (user_id, role_id) VALUES
|
||||
(2, 2), -- developer role
|
||||
(2, 3); -- user role
|
||||
|
||||
-- user@example.com - user
|
||||
INSERT INTO user_roles (user_id, role_id) VALUES
|
||||
(3, 3); -- user role
|
||||
|
||||
-- manager@example.com - manager + user
|
||||
INSERT INTO user_roles (user_id, role_id) VALUES
|
||||
(4, 4), -- manager role
|
||||
(4, 3); -- user role
|
||||
|
||||
-- Ссылки
|
||||
INSERT INTO links (title, url, description) VALUES
|
||||
('Панель администрирования', 'https://admin.example.com', 'Управление системой'),
|
||||
('Мониторинг', 'https://monitoring.example.com', 'Grafana и Prometheus'),
|
||||
('CI/CD', 'https://ci.example.com', 'Jenkins/GitLab CI'),
|
||||
('Документация API', 'https://docs.example.com', 'Swagger документация'),
|
||||
('Git Repository', 'https://git.example.com', 'Репозиторий проекта'),
|
||||
('Дашборд проектов', 'https://projects.example.com', 'Управление проектами'),
|
||||
('Отчеты', 'https://reports.example.com', 'Аналитика и отчеты'),
|
||||
('База знаний', 'https://wiki.example.com', 'Корпоративная wiki');
|
||||
|
||||
-- Связь ролей и ссылок
|
||||
-- admin - доступ ко всему
|
||||
INSERT INTO role_links (role_id, link_id) VALUES
|
||||
(1, 1), (1, 2), (1, 3), (1, 4), (1, 5), (1, 6), (1, 7), (1, 8);
|
||||
|
||||
-- developer - технические ресурсы
|
||||
INSERT INTO role_links (role_id, link_id) VALUES
|
||||
(2, 2), (2, 3), (2, 4), (2, 5), (2, 8);
|
||||
|
||||
-- user - базовые ресурсы
|
||||
INSERT INTO role_links (role_id, link_id) VALUES
|
||||
(3, 8);
|
||||
|
||||
-- manager - управленческие ресурсы
|
||||
INSERT INTO role_links (role_id, link_id) VALUES
|
||||
(4, 6), (4, 7), (4, 8);
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: postgres
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: postgres
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: postgres
|
||||
spec:
|
||||
containers:
|
||||
- name: postgres
|
||||
image: postgres:15-alpine
|
||||
ports:
|
||||
- containerPort: 5432
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: postgres-secret
|
||||
volumeMounts:
|
||||
- name: postgres-storage
|
||||
mountPath: /var/lib/postgresql/data
|
||||
- name: init-script
|
||||
mountPath: /docker-entrypoint-initdb.d
|
||||
volumes:
|
||||
- name: postgres-storage
|
||||
persistentVolumeClaim:
|
||||
claimName: postgres-pvc
|
||||
- name: init-script
|
||||
configMap:
|
||||
name: postgres-init
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: postgres
|
||||
namespace: python-navigator-demo
|
||||
spec:
|
||||
selector:
|
||||
app: postgres
|
||||
ports:
|
||||
- port: 5432
|
||||
targetPort: 5432
|
||||
type: ClusterIP
|
||||
|
||||
Reference in New Issue
Block a user