diff --git a/apps/README.md b/apps/README.md index 7849b43..905277d 100644 --- a/apps/README.md +++ b/apps/README.md @@ -2,6 +2,9 @@ TODO automate this convention: +- Namespace is basically tenant +- 1 cluster per env (multi region workers, single region masters), so env is basically equivalant with cluster + `apps/$NAMESPACE/$APP/$CLUSTER.yaml` ```sh diff --git a/apps/production/actualbudget.yaml b/apps/finance/actualbudget/local.yaml similarity index 100% rename from apps/production/actualbudget.yaml rename to apps/finance/actualbudget/local.yaml diff --git a/apps/local/actualbudget.yaml b/apps/finance/actualbudget/production.yaml similarity index 94% rename from apps/local/actualbudget.yaml rename to apps/finance/actualbudget/production.yaml index 209fd06..0a30c0b 100644 --- a/apps/local/actualbudget.yaml +++ b/apps/finance/actualbudget/production.yaml @@ -47,7 +47,7 @@ spec: annotations: cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - - host: budget.127-0-0-1.nip.io + - host: budget.cloudlab.khuedoan.com paths: - path: / pathType: Prefix @@ -56,7 +56,7 @@ spec: port: http tls: - hosts: - - budget.127-0-0-1.nip.io + - budget.cloudlab.khuedoan.com secretName: actualbudget-tls-certificate persistence: data: diff --git a/apps/khuedoan/homelab-docs/local.yaml b/apps/khuedoan/homelab-docs/local.yaml new file mode 100644 index 0000000..c2ee4dc --- /dev/null +++ b/apps/khuedoan/homelab-docs/local.yaml @@ -0,0 +1,73 @@ +defaultPodOptions: + labels: + "istio.io/dataplane-mode": "ambient" +controllers: + main: + containers: + nginx: + image: + repository: nginx + tag: latest + probes: + readiness: + enabled: true + custom: true + spec: + httpGet: + path: / + port: 80 + initialDelaySeconds: 3 + periodSeconds: 3 + build: + image: + repository: nixos/nix + tag: latest + workingDir: /usr/local/src + command: + - /bin/sh + - -c + args: + - | + nix-shell -p git --command 'git clone https://github.com/khuedoan/homelab .' + + while true; do + nix-shell -p python311Packages.mkdocs-material --command 'mkdocs build' + cp -RT ./site /usr/share/nginx/html + sleep 120 + nix-shell -p git --command 'git fetch origin' + nix-shell -p git --command 'git reset --hard origin/master' + done +service: + main: + controller: main + ports: + http: + port: 80 + protocol: HTTP +ingress: + main: + enabled: true + className: nginx + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + hosts: + - host: homelab.127-0-0-1.nip.io + paths: + - path: / + pathType: ImplementationSpecific + service: + identifier: main + port: http + tls: + - hosts: + - homelab.127-0-0-1.nip.io + secretName: homelab-docs-tls-certificate +persistence: + source: + type: emptyDir + globalMounts: + - path: /usr/local/src + static: + type: emptyDir + globalMounts: + - path: /usr/share/nginx/html diff --git a/apps/khuedoan/homelab-docs/production.yaml b/apps/khuedoan/homelab-docs/production.yaml new file mode 100644 index 0000000..1a2338b --- /dev/null +++ b/apps/khuedoan/homelab-docs/production.yaml @@ -0,0 +1,73 @@ +defaultPodOptions: + labels: + "istio.io/dataplane-mode": "ambient" +controllers: + main: + containers: + nginx: + image: + repository: nginx + tag: latest + probes: + readiness: + enabled: true + custom: true + spec: + httpGet: + path: / + port: 80 + initialDelaySeconds: 3 + periodSeconds: 3 + build: + image: + repository: nixos/nix + tag: latest + workingDir: /usr/local/src + command: + - /bin/sh + - -c + args: + - | + nix-shell -p git --command 'git clone https://github.com/khuedoan/homelab .' + + while true; do + nix-shell -p python311Packages.mkdocs-material --command 'mkdocs build' + cp -RT ./site /usr/share/nginx/html + sleep 120 + nix-shell -p git --command 'git fetch origin' + nix-shell -p git --command 'git reset --hard origin/master' + done +service: + main: + controller: main + ports: + http: + port: 80 + protocol: HTTP +ingress: + main: + enabled: true + className: nginx + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + hosts: + - host: homelab.khuedoan.com + paths: + - path: / + pathType: ImplementationSpecific + service: + identifier: main + port: http + tls: + - hosts: + - homelab.khuedoan.com + secretName: homelab-docs-tls-certificate +persistence: + source: + type: emptyDir + globalMounts: + - path: /usr/local/src + static: + type: emptyDir + globalMounts: + - path: /usr/share/nginx/html diff --git a/apps/khuedoan/notes/local.yaml b/apps/khuedoan/notes/local.yaml new file mode 100644 index 0000000..954d6f2 --- /dev/null +++ b/apps/khuedoan/notes/local.yaml @@ -0,0 +1,44 @@ +defaultPodOptions: + labels: + istio.io/dataplane-mode: ambient +controllers: + main: + type: statefulset + containers: + main: + image: + repository: ghcr.io/silverbulletmd/silverbullet + tag: v2 + envFrom: + - secret: silverbullet +service: + main: + controller: main + ports: + http: + port: 3000 + protocol: HTTP +ingress: + main: + enabled: true + className: nginx + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + hosts: + - host: notes.127-0-0-1.nip.io + paths: + - path: / + pathType: Prefix + service: + identifier: main + port: 3000 + tls: + - hosts: + - notes.127-0-0-1.nip.io + secretName: notes-tls-certificate +persistence: + data: + accessMode: ReadWriteOnce + size: 1Gi + globalMounts: + - path: /space diff --git a/apps/khuedoan/notes/production.yaml b/apps/khuedoan/notes/production.yaml new file mode 100644 index 0000000..0948eb2 --- /dev/null +++ b/apps/khuedoan/notes/production.yaml @@ -0,0 +1,44 @@ +defaultPodOptions: + labels: + istio.io/dataplane-mode: ambient +controllers: + main: + type: statefulset + containers: + main: + image: + repository: ghcr.io/silverbulletmd/silverbullet + tag: v2 + envFrom: + - secret: silverbullet +service: + main: + controller: main + ports: + http: + port: 3000 + protocol: HTTP +ingress: + main: + enabled: true + className: nginx + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + hosts: + - host: notes.cloudlab.khuedoan.com + paths: + - path: / + pathType: Prefix + service: + identifier: main + port: 3000 + tls: + - hosts: + - notes.cloudlab.khuedoan.com + secretName: notes-tls-certificate +persistence: + data: + accessMode: ReadWriteOnce + size: 1Gi + globalMounts: + - path: /space diff --git a/apps/local/blog.yaml b/apps/local/blog.yaml deleted file mode 100644 index c9d7a25..0000000 --- a/apps/local/blog.yaml +++ /dev/null @@ -1,62 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: blog -spec: - destination: - name: in-cluster - namespace: blog - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - "istio.io/dataplane-mode": "ambient" - controllers: - main: - replicas: 2 - strategy: RollingUpdate - containers: - main: - image: - repository: docker.io/khuedoan/blog - tag: 6fbd90b77a81e0bcb330fddaa230feff744a7010 - service: - main: - controller: main - ports: - http: - port: 3000 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: www.127-0-0-1.nip.io - paths: - - path: / - pathType: Prefix - service: - identifier: main - port: 3000 - tls: - - hosts: - - www.127-0-0-1.nip.io - secretName: blog-tls-certificate diff --git a/apps/local/example-service.yaml b/apps/local/example-service.yaml deleted file mode 100644 index af48cb9..0000000 --- a/apps/local/example-service.yaml +++ /dev/null @@ -1,62 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: example-service -spec: - destination: - name: in-cluster - namespace: example-service - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - istio.io/dataplane-mode: ambient - controllers: - main: - replicas: 2 - strategy: RollingUpdate - containers: - main: - image: - repository: zot.zot.svc.cluster.local/example-service - tag: 828c31f942e8913ab2af53a2841c180586c5b7e1 - service: - main: - controller: main - ports: - http: - port: 8080 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: example.127-0-0-1.nip.io - paths: - - path: / - pathType: Prefix - service: - identifier: main - port: 8080 - tls: - - hosts: - - example.127-0-0-1.nip.io - secretName: example-tls-certificate diff --git a/apps/local/homelab-docs.yaml b/apps/local/homelab-docs.yaml deleted file mode 100644 index fdda4d3..0000000 --- a/apps/local/homelab-docs.yaml +++ /dev/null @@ -1,98 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: homelab-docs -spec: - destination: - name: in-cluster - namespace: homelab-docs - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - "istio.io/dataplane-mode": "ambient" - controllers: - main: - containers: - nginx: - image: - repository: nginx - tag: latest - probes: - readiness: - enabled: true - custom: true - spec: - httpGet: - path: / - port: 80 - initialDelaySeconds: 3 - periodSeconds: 3 - build: - image: - repository: nixos/nix - tag: latest - workingDir: /usr/local/src - command: - - /bin/sh - - -c - args: - - | - nix-shell -p git --command 'git clone https://github.com/khuedoan/homelab .' - - while true; do - nix-shell -p python311Packages.mkdocs-material --command 'mkdocs build' - cp -RT ./site /usr/share/nginx/html - sleep 120 - nix-shell -p git --command 'git fetch origin' - nix-shell -p git --command 'git reset --hard origin/master' - done - service: - main: - controller: main - ports: - http: - port: 80 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: homelab.127-0-0-1.nip.io - paths: - - path: / - pathType: ImplementationSpecific - service: - identifier: main - port: http - tls: - - hosts: - - homelab.127-0-0-1.nip.io - secretName: homelab-docs-tls-certificate - persistence: - source: - type: emptyDir - globalMounts: - - path: /usr/local/src - static: - type: emptyDir - globalMounts: - - path: /usr/share/nginx/html diff --git a/apps/local/notes.yaml b/apps/local/notes.yaml deleted file mode 100644 index 809a6ab..0000000 --- a/apps/local/notes.yaml +++ /dev/null @@ -1,69 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: notes -spec: - destination: - name: in-cluster - namespace: notes - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - istio.io/dataplane-mode: ambient - controllers: - main: - type: statefulset - containers: - main: - image: - repository: ghcr.io/silverbulletmd/silverbullet - tag: v2 - envFrom: - - secret: silverbullet - service: - main: - controller: main - ports: - http: - port: 3000 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: notes.127-0-0-1.nip.io - paths: - - path: / - pathType: Prefix - service: - identifier: main - port: 3000 - tls: - - hosts: - - notes.127-0-0-1.nip.io - secretName: notes-tls-certificate - persistence: - data: - accessMode: ReadWriteOnce - size: 1Gi - globalMounts: - - path: /space diff --git a/apps/production/blog.yaml b/apps/production/blog.yaml deleted file mode 100644 index 70d2f43..0000000 --- a/apps/production/blog.yaml +++ /dev/null @@ -1,62 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: blog -spec: - destination: - name: in-cluster - namespace: blog - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - "istio.io/dataplane-mode": "ambient" - controllers: - main: - replicas: 2 - strategy: RollingUpdate - containers: - main: - image: - repository: docker.io/khuedoan/blog - tag: 6fbd90b77a81e0bcb330fddaa230feff744a7010 - service: - main: - controller: main - ports: - http: - port: 3000 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: www.khuedoan.com - paths: - - path: / - pathType: Prefix - service: - identifier: main - port: 3000 - tls: - - hosts: - - www.khuedoan.com - secretName: blog-tls-certificate diff --git a/apps/production/example-service.yaml b/apps/production/example-service.yaml deleted file mode 100644 index c781c72..0000000 --- a/apps/production/example-service.yaml +++ /dev/null @@ -1,62 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: example-service -spec: - destination: - name: in-cluster - namespace: example-service - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - istio.io/dataplane-mode: ambient - controllers: - main: - replicas: 2 - strategy: RollingUpdate - containers: - main: - image: - repository: zot.zot.svc.cluster.local/example-service - tag: 828c31f942e8913ab2af53a2841c180586c5b7e1 - service: - main: - controller: main - ports: - http: - port: 8080 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: example.cloudlab.khuedoan.com - paths: - - path: / - pathType: Prefix - service: - identifier: main - port: 8080 - tls: - - hosts: - - example.cloudlab.khuedoan.com - secretName: example-tls-certificate diff --git a/apps/production/homelab-docs.yaml b/apps/production/homelab-docs.yaml deleted file mode 100644 index b65dc3d..0000000 --- a/apps/production/homelab-docs.yaml +++ /dev/null @@ -1,98 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: homelab-docs -spec: - destination: - name: in-cluster - namespace: homelab-docs - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - "istio.io/dataplane-mode": "ambient" - controllers: - main: - containers: - nginx: - image: - repository: nginx - tag: latest - probes: - readiness: - enabled: true - custom: true - spec: - httpGet: - path: / - port: 80 - initialDelaySeconds: 3 - periodSeconds: 3 - build: - image: - repository: nixos/nix - tag: latest - workingDir: /usr/local/src - command: - - /bin/sh - - -c - args: - - | - nix-shell -p git --command 'git clone https://github.com/khuedoan/homelab .' - - while true; do - nix-shell -p python311Packages.mkdocs-material --command 'mkdocs build' - cp -RT ./site /usr/share/nginx/html - sleep 120 - nix-shell -p git --command 'git fetch origin' - nix-shell -p git --command 'git reset --hard origin/master' - done - service: - main: - controller: main - ports: - http: - port: 80 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: homelab.khuedoan.com - paths: - - path: / - pathType: ImplementationSpecific - service: - identifier: main - port: http - tls: - - hosts: - - homelab.khuedoan.com - secretName: homelab-docs-tls-certificate - persistence: - source: - type: emptyDir - globalMounts: - - path: /usr/local/src - static: - type: emptyDir - globalMounts: - - path: /usr/share/nginx/html diff --git a/apps/production/notes.yaml b/apps/production/notes.yaml deleted file mode 100644 index 0d089a5..0000000 --- a/apps/production/notes.yaml +++ /dev/null @@ -1,69 +0,0 @@ -apiVersion: argoproj.io/v1alpha1 -kind: Application -metadata: - finalizers: - - resources-finalizer.argocd.argoproj.io - name: notes -spec: - destination: - name: in-cluster - namespace: notes - project: default - syncPolicy: - automated: - prune: true - selfHeal: true - syncOptions: - - CreateNamespace=true - - ApplyOutOfSyncOnly=true - - ServerSideApply=true - source: - repoURL: https://bjw-s-labs.github.io/helm-charts - chart: app-template - targetRevision: 3.7.3 - helm: - valuesObject: - defaultPodOptions: - labels: - istio.io/dataplane-mode: ambient - controllers: - main: - type: statefulset - containers: - main: - image: - repository: ghcr.io/silverbulletmd/silverbullet - tag: v2 - envFrom: - - secret: silverbullet - service: - main: - controller: main - ports: - http: - port: 3000 - protocol: HTTP - ingress: - main: - enabled: true - className: nginx - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - hosts: - - host: notes.cloudlab.khuedoan.com - paths: - - path: / - pathType: Prefix - service: - identifier: main - port: 3000 - tls: - - hosts: - - notes.cloudlab.khuedoan.com - secretName: notes-tls-certificate - persistence: - data: - accessMode: ReadWriteOnce - size: 1Gi - globalMounts: - - path: /space diff --git a/apps/test/example/local.yaml b/apps/test/example/local.yaml new file mode 100644 index 0000000..075ff2a --- /dev/null +++ b/apps/test/example/local.yaml @@ -0,0 +1,37 @@ +defaultPodOptions: + labels: + istio.io/dataplane-mode: ambient +controllers: + main: + replicas: 2 + strategy: RollingUpdate + containers: + main: + image: + repository: zot.zot.svc.cluster.local/example-service + tag: 828c31f942e8913ab2af53a2841c180586c5b7e1 +service: + main: + controller: main + ports: + http: + port: 8080 + protocol: HTTP +ingress: + main: + enabled: true + className: nginx + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + hosts: + - host: example.cloudlab.khuedoan.com + paths: + - path: / + pathType: Prefix + service: + identifier: main + port: 8080 + tls: + - hosts: + - example.cloudlab.khuedoan.com + secretName: example-tls-certificate diff --git a/apps/test/example/production.yaml b/apps/test/example/production.yaml new file mode 100644 index 0000000..075ff2a --- /dev/null +++ b/apps/test/example/production.yaml @@ -0,0 +1,37 @@ +defaultPodOptions: + labels: + istio.io/dataplane-mode: ambient +controllers: + main: + replicas: 2 + strategy: RollingUpdate + containers: + main: + image: + repository: zot.zot.svc.cluster.local/example-service + tag: 828c31f942e8913ab2af53a2841c180586c5b7e1 +service: + main: + controller: main + ports: + http: + port: 8080 + protocol: HTTP +ingress: + main: + enabled: true + className: nginx + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + hosts: + - host: example.cloudlab.khuedoan.com + paths: + - path: / + pathType: Prefix + service: + identifier: main + port: 8080 + tls: + - hosts: + - example.cloudlab.khuedoan.com + secretName: example-tls-certificate diff --git a/infra/production/root.hcl b/infra/production/root.hcl index 23b9cd3..e56f092 100644 --- a/infra/production/root.hcl +++ b/infra/production/root.hcl @@ -25,6 +25,7 @@ terraform { } EOF } + generate "provider" { path = "provider.tf" if_exists = "overwrite_terragrunt" diff --git a/apps/local/micropaas.yaml b/platform/local/micropaas.yaml similarity index 98% rename from apps/local/micropaas.yaml rename to platform/local/micropaas.yaml index d6addcc..e56c95e 100644 --- a/apps/local/micropaas.yaml +++ b/platform/local/micropaas.yaml @@ -39,7 +39,7 @@ spec: REGISTRY_HOST: docker.io/khuedoan GITOPS_REPO: cloudlab GIT_USER_NAME: Khue's Bot - GIT_USER_EMAIL: mail@khuedoan.com + GIT_USER_EMAIL: mail@127-0-0-1.nip.io ARGOCD_WEBHOOK_ENDPOINT: http://argocd-server.argocd.svc.cluster.local/api/webhook docker: image: diff --git a/apps/production/micropaas.yaml b/platform/production/micropaas.yaml similarity index 100% rename from apps/production/micropaas.yaml rename to platform/production/micropaas.yaml