mirror of
https://github.com/suitenumerique/docs.git
synced 2026-09-29 04:55:11 +02:00
Yhub has a s3 persistent plugin, since now we didn't use it but we wanto to give the possibility to use it optionnaly. To enable it set the YHUB_S3_PERSISTENCE environment value to true and configure it.
252 lines
8.1 KiB
Go Template
252 lines
8.1 KiB
Go Template
djangoSecretKey: &djangoSecretKey "lkjsdlfkjsldkfjslkdfjslkdjfslkdjf"
|
|
tag: &tag "{{ .Values.imageTag }}"
|
|
djangoSuperUserEmail: admin@example.com
|
|
djangoSuperUserPass: admin
|
|
aiApiKey: changeme
|
|
aiBaseUrl: changeme
|
|
oidc:
|
|
clientId: impress
|
|
clientSecret: ThisIsAnExampleKeyForDevPurposeOnly
|
|
|
|
image:
|
|
repository: lasuite/impress-backend
|
|
pullPolicy: Always
|
|
tag: *tag
|
|
|
|
backend:
|
|
replicas: 1
|
|
envVars:
|
|
CONVERSION_UPLOAD_ENABLED: True
|
|
DJANGO_CSRF_TRUSTED_ORIGINS: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
DJANGO_CONFIGURATION: Feature
|
|
DJANGO_ALLOWED_HOSTS: {{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
DJANGO_SERVER_TO_SERVER_API_TOKENS: secret-api-key
|
|
DJANGO_SECRET_KEY: *djangoSecretKey
|
|
DJANGO_SETTINGS_MODULE: impress.settings
|
|
DJANGO_SUPERUSER_PASSWORD: admin
|
|
DJANGO_EMAIL_BRAND_NAME: "La Suite Numérique"
|
|
DJANGO_EMAIL_HOST: "mailcatcher"
|
|
DJANGO_EMAIL_LOGO_IMG: https://{{ .Values.feature }}-docs.{{ .Values.domain }}/assets/logo-suite-numerique.png
|
|
DJANGO_EMAIL_PORT: 1025
|
|
DJANGO_EMAIL_URL_APP: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
DJANGO_EMAIL_USE_SSL: False
|
|
FRONTEND_SILENT_LOGIN_ENABLED: True
|
|
LOGGING_LEVEL_LOGGERS_ROOT: DEBUG
|
|
LOGGING_LEVEL_LOGGERS_APP: DEBUG
|
|
OIDC_USERINFO_SHORTNAME_FIELD: "first_name"
|
|
OIDC_USERINFO_FULLNAME_FIELDS: "name"
|
|
OIDC_OP_JWKS_ENDPOINT: https://{{ .Values.feature }}-docs-keycloak.{{ .Values.domain }}/realms/docs/protocol/openid-connect/certs
|
|
OIDC_OP_AUTHORIZATION_ENDPOINT: https://{{ .Values.feature }}-docs-keycloak.{{ .Values.domain }}/realms/docs/protocol/openid-connect/auth
|
|
OIDC_OP_TOKEN_ENDPOINT: https://{{ .Values.feature }}-docs-keycloak.{{ .Values.domain }}/realms/docs/protocol/openid-connect/token
|
|
OIDC_OP_USER_ENDPOINT: https://{{ .Values.feature }}-docs-keycloak.{{ .Values.domain }}/realms/docs/protocol/openid-connect/userinfo
|
|
OIDC_OP_LOGOUT_ENDPOINT: https://{{ .Values.feature }}-docs-keycloak.{{ .Values.domain }}/realms/docs/protocol/openid-connect/logout
|
|
OIDC_REDIRECT_ALLOWED_HOSTS: "{{ .Values.feature }}-docs.{{ .Values.domain }}"
|
|
OIDC_RP_CLIENT_ID: docs
|
|
OIDC_RP_CLIENT_SECRET: ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RP_SIGN_ALGO: RS256
|
|
OIDC_RP_SCOPES: "openid email profile"
|
|
LOGIN_REDIRECT_URL: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
LOGIN_REDIRECT_URL_FAILURE: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
LOGOUT_REDIRECT_URL: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
DB_HOST: dev-backend-postgres
|
|
DB_NAME:
|
|
secretKeyRef:
|
|
name: dev-backend-postgres
|
|
key: database
|
|
DB_USER:
|
|
secretKeyRef:
|
|
name: dev-backend-postgres
|
|
key: username
|
|
DB_PASSWORD:
|
|
secretKeyRef:
|
|
name: dev-backend-postgres
|
|
key: password
|
|
DB_PORT: 5432
|
|
REDIS_URL: redis://user:pass@dev-backend-redis:6379/1
|
|
DJANGO_CELERY_BROKER_URL: redis://user:pass@dev-backend-redis:6379/1
|
|
AWS_S3_ENDPOINT_URL: http://dev-backend-minio.{{ .Namespace }}.svc.cluster.local:9000
|
|
AWS_S3_ACCESS_KEY_ID: dinum
|
|
AWS_S3_SECRET_ACCESS_KEY: password
|
|
AWS_STORAGE_BUCKET_NAME: docs-media-storage
|
|
STORAGES_STATICFILES_BACKEND: servestatic.storage.CompressedManifestStaticFilesStorage
|
|
DOCSPEC_API_URL: http://impress-docs-docspec:4000/conversion
|
|
USER_RECONCILIATION_FORM_URL: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
# the collaboration server, reached in-cluster: the backend reads and
|
|
# writes document content there, and fetches its JWKS from the same host
|
|
YHUB_API_BASE_URL: http://impress-docs-yhub:443
|
|
Y_PROVIDER_API_BASE_URL: http://impress-docs-y-provider:443/api/
|
|
Y_PROVIDER_API_KEY: my-secret
|
|
CACHES_KEY_PREFIX: "{{ now | unixEpoch }}"
|
|
migrate:
|
|
command:
|
|
- "/bin/sh"
|
|
- "-c"
|
|
- |
|
|
attempt=0
|
|
until output=$(python manage.py check --database default 2>&1)
|
|
do
|
|
attempt=$((attempt + 1))
|
|
echo "Database check failed (attempt $attempt), retrying in 2s:"
|
|
echo "$output"
|
|
sleep 2
|
|
done
|
|
|
|
echo "Database is ready"
|
|
|
|
python manage.py migrate --no-input
|
|
restartPolicy: Never
|
|
|
|
command:
|
|
- "gunicorn"
|
|
- "-c"
|
|
- "/usr/local/etc/gunicorn/impress.py"
|
|
- "impress.wsgi:application"
|
|
- "--reload"
|
|
|
|
createsuperuser:
|
|
command:
|
|
- "/bin/sh"
|
|
- "-c"
|
|
- |
|
|
attempt=0
|
|
until output=$(python manage.py check --database default 2>&1)
|
|
do
|
|
attempt=$((attempt + 1))
|
|
echo "Database check failed (attempt $attempt), retrying in 2s:"
|
|
echo "$output"
|
|
sleep 2
|
|
done
|
|
|
|
echo "Database is ready"
|
|
python manage.py createsuperuser --email admin@example.com --password admin
|
|
restartPolicy: Never
|
|
|
|
# Extra volume mounts to manage our local custom CA and avoid to set ssl_verify: false
|
|
extraVolumeMounts: {}
|
|
|
|
# Extra volumes to manage our local custom CA and avoid to set ssl_verify: false
|
|
extraVolumes: {}
|
|
|
|
frontend:
|
|
envVars:
|
|
PORT: 8080
|
|
NEXT_PUBLIC_API_ORIGIN: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
|
|
replicas: 1
|
|
|
|
robotsTxt:
|
|
enabled: true
|
|
content: |
|
|
User-agent: *
|
|
Disallow: /
|
|
|
|
image:
|
|
repository: lasuite/impress-frontend
|
|
pullPolicy: Always
|
|
tag: *tag
|
|
|
|
yProvider:
|
|
replicas: 1
|
|
|
|
image:
|
|
repository: lasuite/impress-y-provider
|
|
pullPolicy: Always
|
|
tag: *tag
|
|
|
|
envVars:
|
|
COLLABORATION_BACKEND_BASE_URL: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
COLLABORATION_LOGGING: true
|
|
COLLABORATION_SERVER_ORIGIN: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
NODE_OPTIONS: "--max-old-space-size=1024"
|
|
|
|
# The keys the backend and the collaboration server sign the calls they make to
|
|
# each other with, generated on the cluster by a job into a secret both mount
|
|
# read-only.
|
|
jwtKeys:
|
|
enabled: true
|
|
|
|
yhub:
|
|
replicas: 3
|
|
|
|
worker:
|
|
enabled: true
|
|
replicas: 2
|
|
|
|
image:
|
|
repository: lasuite/impress-yhub
|
|
pullPolicy: Always
|
|
tag: *tag
|
|
|
|
envVars:
|
|
# its own logical database on the dev-backend postgres, created by the
|
|
# init-db job; redis /2, the backend cache and celery live in /1
|
|
POSTGRES: postgres://dinum:pass@dev-backend-postgres:5432/yhub
|
|
REDIS: redis://user:pass@dev-backend-redis:6379/2
|
|
REDIS_PREFIX: yhub
|
|
COLLABORATION_BACKEND_BASE_URL: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
COLLABORATION_SERVER_ORIGIN: https://{{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
NODE_OPTIONS: "--max-old-space-size=1024"
|
|
UWS_HTTP_MAX_HEADERS_SIZE: 32768
|
|
LOG_LEVEL: debug
|
|
YHUB_S3_PERSISTENCE: true
|
|
YHUB_S3_ENDPOINT_URL: http://dev-backend-minio.{{ .Namespace }}.svc.cluster.local:9000
|
|
YHUB_S3_ACCESS_KEY_ID: dinum
|
|
YHUB_S3_SECRET_ACCESS_KEY: password
|
|
YHUB_S3_BUCKET_NAME: docs-media-storage
|
|
|
|
|
|
docSpec:
|
|
enabled: true
|
|
replicas: 1
|
|
|
|
image:
|
|
repository: ghcr.io/docspec/api
|
|
pullPolicy: IfNotPresent
|
|
tag: "1.21.4"
|
|
|
|
probes:
|
|
liveness:
|
|
path: /health
|
|
readiness:
|
|
path: /health
|
|
|
|
ingress:
|
|
enabled: true
|
|
host: {{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
annotations:
|
|
nginx.ingress.kubernetes.io/proxy-body-size: 20m
|
|
cert-manager.io/cluster-issuer: letsencrypt
|
|
|
|
ingressCollaborationWS:
|
|
enabled: true
|
|
host: {{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
|
|
ingressCollaborationApi:
|
|
enabled: false
|
|
host: {{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
|
|
ingressAdmin:
|
|
enabled: true
|
|
host: {{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
|
|
posthog:
|
|
ingress:
|
|
enabled: false
|
|
|
|
ingressAssets:
|
|
enabled: false
|
|
|
|
ingressMedia:
|
|
enabled: true
|
|
host: {{ .Values.feature }}-docs.{{ .Values.domain }}
|
|
|
|
annotations:
|
|
nginx.ingress.kubernetes.io/auth-url: https://{{ .Values.feature }}-docs.{{ .Values.domain }}/api/v1.0/documents/media-auth/
|
|
nginx.ingress.kubernetes.io/auth-response-headers: "Authorization, X-Amz-Date, X-Amz-Content-SHA256"
|
|
nginx.ingress.kubernetes.io/upstream-vhost: dev-backend-minio.{{ .Namespace }}.svc.cluster.local:9000
|
|
nginx.ingress.kubernetes.io/rewrite-target: /docs-media-storage/$1
|
|
|
|
serviceMedia:
|
|
host: dev-backend-minio.{{ .Namespace }}.svc.cluster.local
|
|
port: 9000
|