2 # Copyright © 2017 Amdocs, Bell Canada
3 # Copyright (C) 2020 Wipro Limited.
4 # Modifications Copyright © 2018 AT&T,VMware
6 # Licensed under the Apache License, Version 2.0 (the "License");
7 # you may not use this file except in compliance with the License.
8 # You may obtain a copy of the License at
10 # http://www.apache.org/licenses/LICENSE-2.0
12 # Unless required by applicable law or agreed to in writing, software
13 # distributed under the License is distributed on an "AS IS" BASIS,
14 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15 # See the License for the specific language governing permissions and
16 # limitations under the License.
22 name: {{ include "common.fullname" . }}
23 namespace: {{ include "common.namespace" . }}
25 app: {{ include "common.name" . }}
26 chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
27 release: {{ include "common.release" . }}
28 heritage: {{ .Release.Service }}
32 app: {{ include "common.name" . }}
33 replicas: {{ .Values.replicaCount }}
37 app: {{ include "common.name" . }}
38 release: {{ include "common.release" . }}
41 - name: {{ include "common.name" . }}-readiness
47 {{- if (include "common.needTLS" .) }}
56 fieldPath: metadata.namespace
57 image: {{ include "repositoryGenerator.image.readiness" . }}
58 imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
60 {{- if (include "common.needTLS" .) }}
61 - name: {{ include "common.name" . }}-has-sms-readiness
66 until [ $resp = "200" ]; do
67 resp=$(curl -s -o /dev/null -k --write-out %{http_code} https://aaf-sms.{{ include "common.namespace" . }}:10443/v1/sms/domain/has/secret);
76 fieldPath: metadata.namespace
77 image: {{ include "repositoryGenerator.image.curl" . }}
78 imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
80 {{ include "common.certInitializer.initContainer" . | indent 6 }}
83 - name: {{ include "common.name" . }}
84 image: {{ include "repositoryGenerator.repository" . }}/{{ .Values.global.image.optf_has }}
85 imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
86 command: ["/bin/sh","-c"]
87 args: ["/usr/local/bin/uwsgi -s /run/conductor/uwsgi.sock --chmod-socket=777 --wsgi-file /etc/nginx/conductor.wsgi --callable application --set port={{ .Values.uwsgi.internalPort }} --die-on-term --exit-on-reload --pidfile /run/conductor/conductor-uwsgi.pid --enable-threads --workers 6 --master --vacuum --single-interpreter --socket-timeout 10 --max-worker-lifetime 300 --max-requests 100 --no-defer-accept --protocol=uwsgi --socket 0.0.0.0:{{ .Values.uwsgi.internalPort }}"]
89 - containerPort: {{ .Values.uwsgi.internalPort }}
90 # disable liveness probe when breakpoints set in debugger
91 # so K8s doesn't restart unresponsive container
92 {{- if .Values.liveness.enabled }}
95 port: {{ .Values.uwsgi.internalPort }}
96 initialDelaySeconds: {{ .Values.liveness.initialDelaySeconds }}
97 periodSeconds: {{ .Values.liveness.periodSeconds }}
101 port: {{ .Values.uwsgi.internalPort }}
102 initialDelaySeconds: {{ .Values.readiness.initialDelaySeconds }}
103 periodSeconds: {{ .Values.readiness.periodSeconds }}
104 env: {{ include "oof.etcd.env" . | nindent 10 }}
106 - mountPath: /etc/localtime
109 - mountPath: /usr/local/etc/conductor/conductor.conf
110 name: {{ .Values.global.commonConfigPrefix }}-config
111 subPath: conductor.conf
112 - mountPath: /usr/local/bin/log.conf
113 name: {{ .Values.global.commonConfigPrefix }}-config
115 {{- if (include "common.needTLS" .) }}
116 - mountPath: /usr/local/bin/AAF_RootCA.cer
117 name: {{ include "common.fullname" . }}-onap-certs
118 subPath: aaf_root_ca.cer
121 {{ include "common.resources" . | indent 12 }}
122 - name: {{ include "common.name" . }}-nginx
123 image: {{ include "repositoryGenerator.image.nginx" . }}
124 imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
130 {{- if (include "common.needTLS" .) }}
131 grep -v '^$' /opt/bitnami/nginx/ssl/local/org.onap.oof.crt > /tmp/oof.crt
132 cat /tmp/oof.crt /tmp/intermediate_root_ca.pem /tmp/AAF_RootCA.cer >> /opt/bitnami/nginx/org.onap.oof.crt
134 /opt/bitnami/scripts/nginx/entrypoint.sh /opt/bitnami/scripts/nginx/run.sh
136 - containerPort: {{ .Values.service.internalPort }}
137 {{- if .Values.liveness.enabled }}
140 port: {{ .Values.service.internalPort }}
141 initialDelaySeconds: {{ .Values.liveness.initialDelaySeconds }}
142 periodSeconds: {{ .Values.liveness.periodSeconds }}
146 port: {{ .Values.service.internalPort }}
147 initialDelaySeconds: {{ .Values.readiness.initialDelaySeconds }}
148 periodSeconds: {{ .Values.readiness.periodSeconds }}
150 {{ include "common.certInitializer.volumeMount" . | indent 10 }}
151 - mountPath: /etc/localtime
154 - mountPath: /opt/bitnami/nginx/conf/nginx.conf
155 name: {{ .Values.global.commonConfigPrefix }}-config
157 {{- if (include "common.needTLS" .) }}
158 - mountPath: /tmp/AAF_RootCA.cer
159 name: {{ include "common.fullname" . }}-onap-certs
160 subPath: aaf_root_ca.cer
161 - mountPath: /tmp/intermediate_root_ca.pem
162 name: {{ include "common.fullname" . }}-onap-certs
163 subPath: intermediate_root_ca.pem
166 {{ include "common.resources" . | indent 12 }}
167 {{- if .Values.nodeSelector }}
169 {{ toYaml .Values.nodeSelector | indent 10 }}
171 {{- if .Values.affinity }}
173 {{ toYaml .Values.affinity | indent 10 }}
175 serviceAccountName: {{ include "common.fullname" (dict "suffix" "read" "dot" . )}}
177 {{ include "common.certInitializer.volumes" . | nindent 8 }}
181 - name: {{ .Values.global.commonConfigPrefix }}-config
183 name: {{ .Values.global.commonConfigPrefix }}-configmap
187 - key: conductor.conf
191 {{- if (include "common.needTLS" .) }}
192 {{ include "oof.certificate.volume" . | indent 8 }}
195 - name: "{{ include "common.namespace" . }}-docker-registry-key"