[VFC] Use common secret template for DB root password
[oom.git] / kubernetes / vfc / charts / vfc-vnfres / templates / deployment.yaml
1 # Copyright © 2017 Amdocs, Bell Canada
2 #
3 # Licensed under the Apache License, Version 2.0 (the "License");
4 # you may not use this file except in compliance with the License.
5 # You may obtain a copy of the License at
6 #
7 #       http://www.apache.org/licenses/LICENSE-2.0
8 #
9 # Unless required by applicable law or agreed to in writing, software
10 # distributed under the License is distributed on an "AS IS" BASIS,
11 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 # See the License for the specific language governing permissions and
13 # limitations under the License.
14
15 apiVersion: extensions/v1beta1
16 kind: Deployment
17 metadata:
18   name: {{ include "common.fullname" . }}
19   namespace: {{ include "common.namespace" . }}
20   labels:
21     app: {{ include "common.name" . }}
22     chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
23     release: {{ include "common.release" . }}
24     heritage: {{ .Release.Service }}
25 spec:
26   replicas: {{ .Values.replicaCount }}
27   template:
28     metadata:
29       labels:
30         app: {{ include "common.name" . }}
31         release: {{ include "common.release" . }}
32       annotations:
33         sidecar.istio.io/inject: "{{.Values.istioSidecar}}"
34     spec:
35       initContainers:
36       - command:
37         - /root/ready.py
38         args:
39         - --container-name
40         - {{ .Values.config.mariadbService }}
41         env:
42         - name: NAMESPACE
43           valueFrom:
44             fieldRef:
45               apiVersion: v1
46               fieldPath: metadata.namespace
47         image: "{{ .Values.global.readinessRepository }}/{{ .Values.global.readinessImage }}"
48         imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
49         name: {{ include "common.name" . }}-readiness
50       containers:
51         - name: {{ include "common.name" . }}
52           command:
53             - sh
54           args:
55             - -c
56             - 'MYSQL_AUTH=root:${MYSQL_ROOT_PASSWORD} ./docker-entrypoint.sh'
57           image: "{{ include "common.repository" . }}/{{ .Values.image }}"
58           imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
59           ports:
60           - containerPort: {{ .Values.service.internalPort }}
61           # disable liveness probe when breakpoints set in debugger
62           # so K8s doesn't restart unresponsive container
63           {{ if .Values.liveness.enabled }}
64           livenessProbe:
65             tcpSocket:
66               port: {{ .Values.service.internalPort }}
67             initialDelaySeconds: {{ .Values.liveness.initialDelaySeconds }}
68             periodSeconds: {{ .Values.liveness.periodSeconds }}
69           {{ end }}
70           readinessProbe:
71             tcpSocket:
72               port: {{ .Values.service.internalPort }}
73             initialDelaySeconds: {{ .Values.readiness.initialDelaySeconds }}
74             periodSeconds: {{ .Values.readiness.periodSeconds }}
75           env:
76             - name: MSB_PROTO
77               value: "{{ .Values.global.config.msbprotocol }}"
78             - name: SSL_ENABLED
79               value: "{{ .Values.global.config.ssl_enabled }}"
80             - name: MSB_ADDR
81               value: "{{ .Values.global.config.msbServiceName }}:{{ .Values.global.config.msbPort }}"
82             - name: MYSQL_ADDR
83               value: "{{ .Values.config.mariadbService }}:{{ .Values.config.mariadbPort }}"
84             - name: REDIS_ADDR
85               value: "{{ .Values.global.config.redisServiceName }}:{{ .Values.global.config.redisPort }}"
86             - name: MYSQL_ROOT_USER
87               value: "{{ .Values.global.config.mariadb_admin }}"
88             - name: MYSQL_ROOT_PASSWORD
89               {{- include "common.secret.envFromSecret" (dict "global" . "uid" "db-root-pass" "key" "password") | indent 14}}
90
91           volumeMounts:
92           - name: {{ include "common.fullname" . }}-localtime
93             mountPath: /etc/localtime
94             readOnly: true
95           - name: {{ include "common.fullname" . }}-logs
96             mountPath: /var/log/onap
97           - name: {{ include "common.fullname" . }}-logconfig
98             mountPath: /opt/vfc/gvnfm-vnfres/config/log.yml
99             subPath: log.yml
100           resources:
101 {{ include "common.resources" . | indent 12 }}
102         {{- if .Values.nodeSelector }}
103         nodeSelector:
104 {{ toYaml .Values.nodeSelector | indent 10 }}
105         {{- end -}}
106         {{- if .Values.affinity }}
107         affinity:
108 {{ toYaml .Values.affinity | indent 10 }}
109         {{- end }}
110
111         # side car containers
112         - name: {{ include "common.name" . }}-filebeat-onap
113           image: "{{ .Values.global.loggingRepository }}/{{ .Values.global.loggingImage }}"
114           imagePullPolicy: {{ .Values.global.pullPolicy | default .Values.pullPolicy }}
115           volumeMounts:
116           - name: {{ include "common.fullname" . }}-filebeat-conf
117             mountPath: /usr/share/filebeat/filebeat.yml
118             subPath: filebeat.yml
119           - name: {{ include "common.fullname" . }}-logs
120             mountPath: /var/log/onap
121           - name: {{ include "common.fullname" . }}-data-filebeat
122             mountPath: /usr/share/filebeat/data
123
124       volumes:
125         - name: {{ include "common.fullname" . }}-localtime
126           hostPath:
127             path: /etc/localtime
128         - name:  {{ include "common.fullname" . }}-logs
129           emptyDir: {}
130         - name: {{ include "common.fullname" . }}-logconfig
131           configMap:
132             name : {{ include "common.fullname" . }}-logging-configmap
133
134         - name: {{ include "common.fullname" . }}-filebeat-conf
135           configMap:
136             name: {{ include "common.release" . }}-vfc-filebeat-configmap
137         - name: {{ include "common.fullname" . }}-data-filebeat
138           emptyDir: {}
139       imagePullSecrets:
140       - name: "{{ include "common.namespace" . }}-docker-registry-key"