Add melange/apko build pipeline and Kubernetes manifests

- Add melange.yaml for distroless package build
- Add apko.yaml for minimal container image
- Add GitHub Actions workflow for melange/apko CI build
- Add Kubernetes manifests (deployment, service, configmap, secret, redis)
- Update Dockerfile, .gitignore, and docker-compose.yml
This commit is contained in:
Ketan Patel committed 2026-04-16 18:38:13 -04:00
1 parent cc3581aa4d
commit 9c49e79657
15 files changed
+382 -7

No files matched your search

+17
View File
@@ -0,0 +1,17 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: apcupsd-client-config
namespace: apcupsd
labels:
app.kubernetes.io/name: apcupsd-client
app.kubernetes.io/part-of: apcupsd-client
data:
REDIS_URL: "redis://redis:6379/0"
LOG_LEVEL: "info"
TZ: "UTC"
ALLOW_PRIVATE_IPS: "true"
TRUST_PROXY: "true"
RATE_LIMIT_ENABLED: "true"
ADMIN_USERNAME: "admin"
SESSION_MAX_AGE_SECONDS: "86400"
+71
View File
@@ -0,0 +1,71 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: apcupsd-client
namespace: apcupsd
labels:
app.kubernetes.io/name: apcupsd-client
app.kubernetes.io/part-of: apcupsd-client
spec:
replicas: 1
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 0
maxSurge: 1
selector:
matchLabels:
app.kubernetes.io/name: apcupsd-client
template:
metadata:
labels:
app.kubernetes.io/name: apcupsd-client
spec:
securityContext:
runAsUser: 10001
runAsGroup: 10001
runAsNonRoot: true
fsGroup: 10001
containers:
- name: web
image: ghcr.io/k2patel/apcupsd-client:latest
ports:
- containerPort: 8000
protocol: TCP
envFrom:
- configMapRef:
name: apcupsd-client-config
- secretRef:
name: apcupsd-client-secret
livenessProbe:
httpGet:
path: /healthz
port: 8000
initialDelaySeconds: 15
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /readyz
port: 8000
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
resources:
requests:
memory: "128Mi"
cpu: "100m"
limits:
memory: "256Mi"
cpu: "500m"
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
volumeMounts:
- name: tmp
mountPath: /tmp
volumes:
- name: tmp
emptyDir: {}
+11
View File
@@ -0,0 +1,11 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- configmap.yaml
- secret.yaml
- redis-statefulset.yaml
- redis-service.yaml
- deployment.yaml
- service.yaml
+6
View File
@@ -0,0 +1,6 @@
apiVersion: v1
kind: Namespace
metadata:
name: apcupsd
labels:
app.kubernetes.io/part-of: apcupsd-client
+17
View File
@@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: redis
namespace: apcupsd
labels:
app.kubernetes.io/name: redis
app.kubernetes.io/part-of: apcupsd-client
spec:
type: ClusterIP
selector:
app.kubernetes.io/name: redis
ports:
- name: redis
protocol: TCP
port: 6379
targetPort: 6379
+72
View File
@@ -0,0 +1,72 @@
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: redis
namespace: apcupsd
labels:
app.kubernetes.io/name: redis
app.kubernetes.io/part-of: apcupsd-client
spec:
serviceName: redis
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: redis
template:
metadata:
labels:
app.kubernetes.io/name: redis
spec:
securityContext:
runAsUser: 999
runAsGroup: 999
fsGroup: 999
containers:
- name: redis
image: redis:7-alpine
command:
- redis-server
- --appendonly
- "yes"
- --appendfsync
- everysec
ports:
- containerPort: 6379
protocol: TCP
livenessProbe:
exec:
command:
- redis-cli
- ping
initialDelaySeconds: 10
periodSeconds: 10
timeoutSeconds: 3
failureThreshold: 5
readinessProbe:
exec:
command:
- redis-cli
- ping
initialDelaySeconds: 5
periodSeconds: 5
timeoutSeconds: 3
failureThreshold: 3
resources:
requests:
memory: "64Mi"
cpu: "50m"
limits:
memory: "128Mi"
cpu: "250m"
volumeMounts:
- name: redis-data
mountPath: /data
volumeClaimTemplates:
- metadata:
name: redis-data
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
+14
View File
@@ -0,0 +1,14 @@
apiVersion: v1
kind: Secret
metadata:
name: apcupsd-client-secret
namespace: apcupsd
labels:
app.kubernetes.io/name: apcupsd-client
app.kubernetes.io/part-of: apcupsd-client
type: Opaque
stringData:
SESSION_SECRET: "CHANGE_ME_TO_A_RANDOM_SECRET"
# Optional — uncomment and set as needed:
# SMTP_PASSWORD: ""
# ADMIN_PASSWORD_HASH: ""
+17
View File
@@ -0,0 +1,17 @@
apiVersion: v1
kind: Service
metadata:
name: apcupsd-client
namespace: apcupsd
labels:
app.kubernetes.io/name: apcupsd-client
app.kubernetes.io/part-of: apcupsd-client
spec:
type: LoadBalancer
selector:
app.kubernetes.io/name: apcupsd-client
ports:
- name: http
protocol: TCP
port: 10280
targetPort: 8000