diff --git a/helm/.helmignore b/helm/.helmignore deleted file mode 100644 index 0e8a0eb..0000000 --- a/helm/.helmignore +++ /dev/null @@ -1,23 +0,0 @@ -# Patterns to ignore when building packages. -# This supports shell glob matching, relative path matching, and -# negation (prefixed with !). Only one pattern per line. -.DS_Store -# Common VCS dirs -.git/ -.gitignore -.bzr/ -.bzrignore -.hg/ -.hgignore -.svn/ -# Common backup files -*.swp -*.bak -*.tmp -*.orig -*~ -# Various IDEs -.project -.idea/ -*.tmproj -.vscode/ diff --git a/helm/Chart.yaml b/helm/Chart.yaml deleted file mode 100644 index 585b890..0000000 --- a/helm/Chart.yaml +++ /dev/null @@ -1,26 +0,0 @@ -apiVersion: v2 -name: sientia-module -description: A generic application helm for Kubernetes. Contains a set of templates - that can be used to deploy a generic sientia python module to a Kubernetes cluster, - based in some git repository and a generic docker image. - -# A chart can be either an 'application' or a 'library' chart. -# -# Application charts are a collection of templates that can be packaged into versioned archives -# to be deployed. -# -# Library charts provide useful utilities or functions for the chart developer. They're included as -# a dependency of application charts to inject those utilities and functions into the rendering -# pipeline. Library charts do not define any templates and therefore cannot be deployed. -type: application - -# This is the chart version. This version number should be incremented each time you make changes -# to the chart and its templates, including the app version. -# Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.0 - -# This is the version number of the application being deployed. This version number should be -# incremented each time you make changes to the application. Versions are not expected to -# follow Semantic Versioning. They should reflect the version the application is using. -# It is recommended to use it with quotes. -appVersion: "1.16.0" diff --git a/helm/README.md b/helm/README.md deleted file mode 100644 index 795d9ac..0000000 --- a/helm/README.md +++ /dev/null @@ -1,73 +0,0 @@ -# How to create an image and deploy this helm chart: - -## Image creation: -### Generate your ssh key to Docker -``` -ssh-keygen -t ed25519 -C "docker-access" -f ~/.ssh/id_ed25519_docker -``` - -Add the public key to yout Git SSH keys in your git platform - -### Enable Docker BuildKit -``` -export DOCKER_BUILDKIT=1 -``` -or make it permanent: -``` -echo '{ "features": { "buildkit": true } }' | sudo tee /etc/docker/daemon.json -sudo systemctl restart docker -``` - -### Build and upload image -``` -make -C docker -``` - -## SSH secrets: - -### Create secret to your git ssh credentials -We need a dedicated keypair to access GitHub from a Kubernetes pod without exposing your user credentials or tokens. -``` -ssh-keygen -t ed25519 -f git_key -C "k8s-deploy-key" -N "" -``` -- ```-t ed25519```: modern, secure key type - -- ```-f git_key```: saves to git_key (private) and git_key.pub (public) - -- ```-C "..."```: comment to identify this key - -- ```-N ""```: no passphrase (for non-interactive use in pods) - -### Add the Public Key to GitHub (Read-Only Deploy Key) -Deploy keys allow read-only access to a specific repo. This avoids using user tokens or giving broad permissions. - -1. Copy your public key: -``` -cat git_key.pub -``` - -2. Go to your GitHub repo → Settings → Deploy Keys - -3. Click “Add deploy key” - -- Title: K8s ReadOnly - -- Key: paste your git_key.pub - -- ✅ Check “Allow read access” - -- ❌ Do NOT check “Allow write access” - -### Create a Kubernetes Secret from the Private Key -Kubernetes Secrets securely store sensitive data like private keys. This secret will later be mounted into your pod for Git to use. -``` -kubectl create secret generic git-ssh-key \ - --namespace sientia-opc \ - --from-file=ssh-privatekey=git_key \ - --type=kubernetes.io/ssh-auth -``` -- ```ssh-privatekey```: required key name for type kubernetes.io/ssh-auth - -- Secret is base64-encoded and stored in Kubernetes (not encrypted unless you're using an external secret manager or encryption at rest is enabled) - - diff --git a/helm/files/github_known_hosts b/helm/files/github_known_hosts deleted file mode 100644 index 10ef85a..0000000 --- a/helm/files/github_known_hosts +++ /dev/null @@ -1,3 +0,0 @@ -github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk= -github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg= -github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl diff --git a/helm/templates/_helpers.tpl b/helm/templates/_helpers.tpl deleted file mode 100644 index f0a073a..0000000 --- a/helm/templates/_helpers.tpl +++ /dev/null @@ -1,62 +0,0 @@ -{{/* -Expand the name of the chart. -*/}} -{{- define "sientia-module.name" -}} -{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* -Create a default fully qualified app name. -We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). -If release name contains chart name it will be used as a full name. -*/}} -{{- define "sientia-module.fullname" -}} -{{- if .Values.fullnameOverride }} -{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- $name := default .Chart.Name .Values.nameOverride }} -{{- if contains $name .Release.Name }} -{{- .Release.Name | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} -{{- end }} -{{- end }} -{{- end }} - -{{/* -Create chart name and version as used by the chart label. -*/}} -{{- define "sientia-module.chart" -}} -{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{/* -Common labels -*/}} -{{- define "sientia-module.labels" -}} -helm.sh/chart: {{ include "sientia-module.chart" . }} -{{ include "sientia-module.selectorLabels" . }} -{{- if .Chart.AppVersion }} -app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} -{{- end }} -app.kubernetes.io/managed-by: {{ .Release.Service }} -{{- end }} - -{{/* -Selector labels -*/}} -{{- define "sientia-module.selectorLabels" -}} -app.kubernetes.io/name: {{ include "sientia-module.name" . }} -app.kubernetes.io/instance: {{ .Release.Name }} -{{- end }} - -{{/* -Create the name of the service account to use -*/}} -{{- define "sientia-module.serviceAccountName" -}} -{{- if .Values.serviceAccount.create }} -{{- default (include "sientia-module.fullname" .) .Values.serviceAccount.name }} -{{- else }} -{{- default "default" .Values.serviceAccount.name }} -{{- end }} -{{- end }} diff --git a/helm/templates/deployment.yaml b/helm/templates/deployment.yaml deleted file mode 100644 index a35f2b6..0000000 --- a/helm/templates/deployment.yaml +++ /dev/null @@ -1,96 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: {{ .Values.nameOverride | default (include "sientia-module.fullname" .) }} - labels: - {{- include "sientia-module.labels" . | nindent 4 }} -spec: - {{- if not .Values.autoscaling.enabled }} - replicas: {{ .Values.replicaCount }} - {{- end }} - selector: - matchLabels: - {{- include "sientia-module.selectorLabels" . | nindent 6 }} - template: - metadata: - {{- with .Values.podAnnotations }} - annotations: - {{- toYaml . | nindent 8 }} - {{- end }} - labels: - {{- include "sientia-module.labels" . | nindent 8 }} - {{- with .Values.podLabels }} - {{- toYaml . | nindent 8 }} - {{- end }} - spec: - {{- with .Values.imagePullSecrets }} - imagePullSecrets: - {{- toYaml . | nindent 8 }} - {{- end }} - serviceAccountName: {{ include "sientia-module.serviceAccountName" . }} - {{- with .Values.podSecurityContext }} - securityContext: - {{- toYaml . | nindent 8 }} - {{- end }} - containers: - - name: {{ .Chart.Name }} - {{- with .Values.securityContext }} - securityContext: - {{- toYaml . | nindent 12 }} - {{- end }} - image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" - imagePullPolicy: {{ .Values.image.pullPolicy }} - ports: - - name: http - containerPort: {{ .Values.service.port }} - protocol: TCP - env: - {{- toYaml .Values.env | nindent 12 }} - {{- with .Values.livenessProbe }} - livenessProbe: - {{- toYaml . | nindent 12 }} - {{- end }} - {{- with .Values.readinessProbe }} - readinessProbe: - {{- toYaml . | nindent 12 }} - {{- end }} - {{- with .Values.resources }} - resources: - {{- toYaml . | nindent 12 }} - {{- end }} - volumeMounts: - {{- if .Values.ssh.enabled }} - - name: ssh-key - mountPath: {{ .Values.ssh.sshPath }} - readOnly: true - - name: ssh-known-hosts - mountPath: {{ .Values.ssh.knownHostsPath }} - readOnly: true - {{- end }} - volumes: - {{- if .Values.ssh.enabled }} - - name: ssh-key - secret: - secretName: {{ .Values.ssh.secretName }} - items: - - key: ssh-privatekey - path: id_ed25519 - - name: ssh-known-hosts - configMap: - name: {{ include "sientia-module.fullname" . }}-ssh-known-hosts - items: - - key: known_hosts - path: known_hosts - {{- end }} - {{- with .Values.nodeSelector }} - nodeSelector: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.affinity }} - affinity: - {{- toYaml . | nindent 8 }} - {{- end }} - {{- with .Values.tolerations }} - tolerations: - {{- toYaml . | nindent 8 }} - {{- end }} diff --git a/helm/templates/hpa.yaml b/helm/templates/hpa.yaml deleted file mode 100644 index 2cbf74e..0000000 --- a/helm/templates/hpa.yaml +++ /dev/null @@ -1,32 +0,0 @@ -{{- if .Values.autoscaling.enabled }} -apiVersion: autoscaling/v2 -kind: HorizontalPodAutoscaler -metadata: - name: {{ include "sientia-module.fullname" . }} - labels: - {{- include "sientia-module.labels" . | nindent 4 }} -spec: - scaleTargetRef: - apiVersion: apps/v1 - kind: Deployment - name: {{ include "sientia-module.fullname" . }} - minReplicas: {{ .Values.autoscaling.minReplicas }} - maxReplicas: {{ .Values.autoscaling.maxReplicas }} - metrics: - {{- if .Values.autoscaling.targetCPUUtilizationPercentage }} - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }} - {{- end }} - {{- if .Values.autoscaling.targetMemoryUtilizationPercentage }} - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }} - {{- end }} -{{- end }} diff --git a/helm/templates/know-hosts-configmap.yaml b/helm/templates/know-hosts-configmap.yaml deleted file mode 100644 index ce38be3..0000000 --- a/helm/templates/know-hosts-configmap.yaml +++ /dev/null @@ -1,7 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ include "sientia-module.fullname" . }}-ssh-known-hosts -data: - known_hosts: | -{{ .Files.Get "files/github_known_hosts" | indent 4 }} diff --git a/helm/templates/service.yaml b/helm/templates/service.yaml deleted file mode 100644 index 7859559..0000000 --- a/helm/templates/service.yaml +++ /dev/null @@ -1,15 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: {{ include "sientia-module.fullname" . }} - labels: - {{- include "sientia-module.labels" . | nindent 4 }} -spec: - type: {{ .Values.service.type }} - ports: - - port: {{ .Values.service.port }} - targetPort: http - protocol: TCP - name: http - selector: - {{- include "sientia-module.selectorLabels" . | nindent 4 }} diff --git a/helm/templates/serviceaccount.yaml b/helm/templates/serviceaccount.yaml deleted file mode 100644 index de4307b..0000000 --- a/helm/templates/serviceaccount.yaml +++ /dev/null @@ -1,13 +0,0 @@ -{{- if .Values.serviceAccount.create -}} -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ include "sientia-module.serviceAccountName" . }} - labels: - {{- include "sientia-module.labels" . | nindent 4 }} - {{- with .Values.serviceAccount.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -automountServiceAccountToken: {{ .Values.serviceAccount.automount }} -{{- end }} diff --git a/helm/values.yaml b/values.yaml similarity index 96% rename from helm/values.yaml rename to values.yaml index 32cc058..8c36400 100644 --- a/helm/values.yaml +++ b/values.yaml @@ -123,7 +123,7 @@ env: - name: GITHUB_REPO_URL value: "git@github.com:Aignosi/sientia-dataops-opc-ingestor.git" - name: GITHUB_BRANCH - value: "SIENTIAPDE-1017-criar-helm-generico-para-os-modulos-do-sientia" + value: "SIENTIAPDE-988-criar-ingestor-opc" - name: PYTHON_APP value: "ingestor.app" @@ -159,4 +159,4 @@ ssh: knownHostsPath: /mnt/known_hosts # kubectl create secret docker-registry docker-hub-secret --namespace sientia-opc --docker-server=http://aignosi.azurecr.io --docker-username=aignosi --docker-password=5I5zpQ6sRaHqX1hD3dr+2mo647yO3FRc359/wu6gsP+ACRDRz5mp -# helm upgrade --install sientia-dataops-opc-ingestor ./helm -n sientia-opc --create-namespace \ No newline at end of file +# helm upgrade --install sientia-dataops-opc-ingestor sientia/sientia-module -n sientia-opc --create-namespace -f ./values.yaml \ No newline at end of file