main.tf 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167
  1. resource "kubernetes_deployment" "browsh-http-server" {
  2. metadata {
  3. name = "browsh-http-server"
  4. }
  5. spec {
  6. replicas = 2
  7. selector {
  8. match_labels = {
  9. app = "browsh-http-server"
  10. }
  11. }
  12. template {
  13. metadata {
  14. labels = {
  15. app = "browsh-http-server"
  16. }
  17. }
  18. spec {
  19. init_container {
  20. name = "fix-perms"
  21. image = "busybox"
  22. command = [
  23. "sh",
  24. "-c",
  25. "mkdir -p /app/.config/browsh/ && cp /etc/read-only/config.toml /app/.config/browsh/ && /bin/chmod -R 777 /app/.config/browsh/"
  26. ]
  27. volume_mount {
  28. name = "browsh-config"
  29. mount_path = "/etc/read-only"
  30. }
  31. volume_mount {
  32. name = "rw-config"
  33. mount_path = "/app/.config/browsh/"
  34. }
  35. security_context {
  36. run_as_user = 0
  37. }
  38. }
  39. container {
  40. image = "browsh/browsh:v${chomp(file(".browsh_version"))}"
  41. #image = "browsh/browsh:dev"
  42. name = "app"
  43. command = ["/app/browsh", "--http-server-mode", "--debug"]
  44. port {
  45. container_port = 4333
  46. }
  47. resources {
  48. requests {
  49. memory = "500Mi"
  50. cpu = "1000m"
  51. }
  52. limits {
  53. memory = "2Gi"
  54. cpu = "2000m"
  55. }
  56. }
  57. volume_mount {
  58. name = "rw-config"
  59. mount_path = "/app/.config/browsh/"
  60. }
  61. }
  62. volume {
  63. name = "browsh-config"
  64. config_map {
  65. name = "browsh-http-server-config"
  66. }
  67. }
  68. volume {
  69. name = "rw-config"
  70. empty_dir {}
  71. }
  72. }
  73. }
  74. }
  75. }
  76. resource "kubernetes_config_map" "browsh-http-server-config" {
  77. metadata {
  78. name = "browsh-http-server-config"
  79. }
  80. data = {
  81. "config.toml" = file("./http-server/main-config.toml")
  82. }
  83. }
  84. resource "kubernetes_horizontal_pod_autoscaler" "http-server-scaler" {
  85. metadata {
  86. name = "http-server-scaler"
  87. }
  88. spec {
  89. min_replicas = 2
  90. max_replicas = 40
  91. target_cpu_utilization_percentage = "80"
  92. scale_target_ref {
  93. kind = "Deployment"
  94. name = "browsh-http-server"
  95. }
  96. }
  97. }
  98. resource "kubernetes_ingress" "http-server-ingress" {
  99. metadata {
  100. name = "browsh-ingress"
  101. annotations = {
  102. "kubernetes.io/ingress.class" = "nginx"
  103. "certmanager.k8s.io/cluster-issuer": "letsencrypt-prod"
  104. "certmanager.k8s.io/acme-challenge-type": "http01"
  105. }
  106. }
  107. spec {
  108. tls {
  109. hosts = [
  110. "html.brow.sh",
  111. "text.brow.sh"
  112. ]
  113. secret_name = "browsh-tls"
  114. }
  115. backend {
  116. service_name = "browsh-http-server"
  117. service_port = 80
  118. }
  119. rule {
  120. host = "html.brow.sh"
  121. http {
  122. path {
  123. path = "/*"
  124. backend {
  125. service_name = "browsh-http-server"
  126. service_port = 80
  127. }
  128. }
  129. }
  130. }
  131. rule {
  132. host = "text.brow.sh"
  133. http {
  134. path {
  135. path = "/*"
  136. backend {
  137. service_name = "browsh-http-server"
  138. service_port = 80
  139. }
  140. }
  141. }
  142. }
  143. }
  144. }
  145. resource "kubernetes_service" "browsh-http-server" {
  146. metadata {
  147. name = "browsh-http-server"
  148. }
  149. spec {
  150. selector = {
  151. app = "browsh-http-server"
  152. }
  153. port {
  154. name = "http"
  155. port = 80
  156. target_port = 4333
  157. }
  158. }
  159. }