extras/cloudsql/kubernetes-manifests/userservice.yaml (95 lines of code) (raw):

# Copyright 2021 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. apiVersion: apps/v1 kind: Deployment metadata: name: userservice spec: selector: matchLabels: app: userservice template: metadata: labels: app: userservice spec: serviceAccountName: boa-ksa terminationGracePeriodSeconds: 5 containers: - name: userservice image: gcr.io/bank-of-anthos-ci/userservice:v0.5.11@sha256:1559cbd3a9c937c84d067c5599e38c68fb4357215fd9d8de9c80ae81bbba863a volumeMounts: - name: keys mountPath: "/root/.ssh" readOnly: true ports: - name: http-server containerPort: 8080 env: - name: VERSION value: "v0.5.11" - name: PORT value: "8080" - name: ENABLE_TRACING value: "true" - name: TOKEN_EXPIRY_SECONDS value: "3600" - name: PRIV_KEY_PATH value: "/root/.ssh/privatekey" # Valid levels are debug, info, warning, error, critical. If no valid level is set, gunicorn will default to info. - name: LOG_LEVEL value: "info" envFrom: - configMapRef: name: environment-config - configMapRef: name: accounts-db-config readinessProbe: httpGet: path: /ready port: 8080 initialDelaySeconds: 10 periodSeconds: 5 timeoutSeconds: 10 resources: requests: cpu: 100m memory: 64Mi limits: cpu: 500m memory: 256Mi - name: cloudsql-proxy resources: limits: cpu: "200m" memory: "100Mi" image: gcr.io/cloudsql-docker/gce-proxy:1.33.12@sha256:89530a19852370b176e91cfef02a24646019fcbffc7a5332cf2c9423bd5e910f env: - name: CONNECTION_NAME valueFrom: secretKeyRef: name: cloud-sql-admin key: connectionName command: ["/cloud_sql_proxy", "-instances=$(CONNECTION_NAME)=tcp:5432"] securityContext: runAsNonRoot: true volumes: - name: keys secret: secretName: jwt-key items: - key: jwtRS256.key path: privatekey - key: jwtRS256.key.pub path: publickey --- apiVersion: v1 kind: Service metadata: name: userservice spec: type: ClusterIP selector: app: userservice ports: - name: http port: 8080 targetPort: 8080