diff --git a/.gitignore b/.gitignore index 929aaa1..491f824 100644 --- a/.gitignore +++ b/.gitignore @@ -52,8 +52,8 @@ Thumbs.db *.tmp *.temp -# Kubernetes secrets (sops-encrypted original stays local) -k8s/secret.yaml +# Secrets (sops-encrypted, never commit decrypted) +chart/values-secret.yaml # Melange / apko build artifacts packages/ diff --git a/k8s/deployment.yaml b/k8s/deployment.yaml deleted file mode 100644 index 0c664b9..0000000 --- a/k8s/deployment.yaml +++ /dev/null @@ -1,69 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: apcupsd-client - namespace: apcupsd - labels: - app.kubernetes.io/name: apcupsd-client - app.kubernetes.io/part-of: apcupsd-client -spec: - replicas: 1 - strategy: - type: RollingUpdate - rollingUpdate: - maxUnavailable: 0 - maxSurge: 1 - selector: - matchLabels: - app.kubernetes.io/name: apcupsd-client - template: - metadata: - labels: - app.kubernetes.io/name: apcupsd-client - spec: - securityContext: - runAsUser: 10001 - runAsGroup: 10001 - runAsNonRoot: true - fsGroup: 10001 - containers: - - name: web - image: ghcr.io/k2patel/apcupsd-client:latest - ports: - - containerPort: 8000 - protocol: TCP - envFrom: - - secretRef: - name: apcupsd-client-secret - livenessProbe: - httpGet: - path: /healthz - port: 8000 - initialDelaySeconds: 15 - periodSeconds: 30 - timeoutSeconds: 5 - failureThreshold: 3 - readinessProbe: - httpGet: - path: /readyz - port: 8000 - initialDelaySeconds: 5 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 3 - resources: - requests: - memory: "128Mi" - cpu: "100m" - limits: - memory: "256Mi" - cpu: "500m" - securityContext: - readOnlyRootFilesystem: true - allowPrivilegeEscalation: false - volumeMounts: - - name: tmp - mountPath: /tmp - volumes: - - name: tmp - emptyDir: {} diff --git a/k8s/kustomization.yaml b/k8s/kustomization.yaml deleted file mode 100644 index 321d22e..0000000 --- a/k8s/kustomization.yaml +++ /dev/null @@ -1,10 +0,0 @@ -apiVersion: kustomize.config.k8s.io/v1beta1 -kind: Kustomization - -resources: - - namespace.yaml - - secret.yaml - - redis-statefulset.yaml - - redis-service.yaml - - deployment.yaml - - service.yaml diff --git a/k8s/namespace.yaml b/k8s/namespace.yaml deleted file mode 100644 index 12d715c..0000000 --- a/k8s/namespace.yaml +++ /dev/null @@ -1,6 +0,0 @@ -apiVersion: v1 -kind: Namespace -metadata: - name: apcupsd - labels: - app.kubernetes.io/part-of: apcupsd-client diff --git a/k8s/redis-service.yaml b/k8s/redis-service.yaml deleted file mode 100644 index 8117ca6..0000000 --- a/k8s/redis-service.yaml +++ /dev/null @@ -1,17 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: redis - namespace: apcupsd - labels: - app.kubernetes.io/name: redis - app.kubernetes.io/part-of: apcupsd-client -spec: - type: ClusterIP - selector: - app.kubernetes.io/name: redis - ports: - - name: redis - protocol: TCP - port: 6379 - targetPort: 6379 diff --git a/k8s/redis-statefulset.yaml b/k8s/redis-statefulset.yaml deleted file mode 100644 index 7008a0e..0000000 --- a/k8s/redis-statefulset.yaml +++ /dev/null @@ -1,72 +0,0 @@ -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: redis - namespace: apcupsd - labels: - app.kubernetes.io/name: redis - app.kubernetes.io/part-of: apcupsd-client -spec: - serviceName: redis - replicas: 1 - selector: - matchLabels: - app.kubernetes.io/name: redis - template: - metadata: - labels: - app.kubernetes.io/name: redis - spec: - securityContext: - runAsUser: 999 - runAsGroup: 999 - fsGroup: 999 - containers: - - name: redis - image: redis:7-alpine - command: - - redis-server - - --appendonly - - "yes" - - --appendfsync - - everysec - ports: - - containerPort: 6379 - protocol: TCP - livenessProbe: - exec: - command: - - redis-cli - - ping - initialDelaySeconds: 10 - periodSeconds: 10 - timeoutSeconds: 3 - failureThreshold: 5 - readinessProbe: - exec: - command: - - redis-cli - - ping - initialDelaySeconds: 5 - periodSeconds: 5 - timeoutSeconds: 3 - failureThreshold: 3 - resources: - requests: - memory: "64Mi" - cpu: "50m" - limits: - memory: "128Mi" - cpu: "250m" - volumeMounts: - - name: redis-data - mountPath: /data - volumeClaimTemplates: - - metadata: - name: redis-data - spec: - accessModes: - - ReadWriteOnce - resources: - requests: - storage: 1Gi diff --git a/k8s/secret.yaml.example b/k8s/secret.yaml.example deleted file mode 100644 index 529b988..0000000 --- a/k8s/secret.yaml.example +++ /dev/null @@ -1,31 +0,0 @@ -apiVersion: v1 -kind: Secret -metadata: - name: apcupsd-client-secret - namespace: apcupsd - labels: - app.kubernetes.io/name: apcupsd-client - app.kubernetes.io/part-of: apcupsd-client -type: Opaque -stringData: - # Auth (required in production) - # Generate with: python -c "import secrets; print(secrets.token_urlsafe(32))" - SESSION_SECRET: "" - ADMIN_USERNAME: "admin" - # Generate with: python -c "from passlib.hash import argon2; print(argon2.hash('yourpassword'))" - ADMIN_PASSWORD_HASH: "" - SESSION_MAX_AGE_SECONDS: "1209600" - TRUST_PROXY: "false" - # Redis - REDIS_URL: "redis://redis:6379/0" - # SMTP (optional) - SMTP_PASSWORD: "" - # Network - ALLOW_PRIVATE_IPS: "true" - # Observability - LOG_LEVEL: "INFO" - RATE_LIMIT_ENABLED: "true" - # Locale - TZ: "UTC" - # Legacy migration (unused unless /config is mounted) - UPS_CONFIG_PATH: "/config/ups.yaml" diff --git a/k8s/service.yaml b/k8s/service.yaml deleted file mode 100644 index f1c9b3a..0000000 --- a/k8s/service.yaml +++ /dev/null @@ -1,17 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: apcupsd-client - namespace: apcupsd - labels: - app.kubernetes.io/name: apcupsd-client - app.kubernetes.io/part-of: apcupsd-client -spec: - type: LoadBalancer - selector: - app.kubernetes.io/name: apcupsd-client - ports: - - name: http - protocol: TCP - port: 10280 - targetPort: 8000