diff --git a/apps/codimd/manifests/03-codimd-db-deployment.yaml b/apps/codimd/manifests/03-codimd-db-deployment.yaml index 2e21f45..1e0e100 100644 --- a/apps/codimd/manifests/03-codimd-db-deployment.yaml +++ b/apps/codimd/manifests/03-codimd-db-deployment.yaml @@ -17,6 +17,13 @@ spec: containers: - name: postgres image: postgres:17-alpine + resources: + requests: + memory: "128Mi" + cpu: "100m" + limits: + memory: "512Mi" + cpu: "500m" env: - name: POSTGRES_USER value: "codimd" @@ -29,6 +36,27 @@ spec: key: POSTGRES_PASSWORD - name: PGDATA value: "/var/lib/postgresql/data/pgdata" + # Health check + livenessProbe: + exec: + command: + - sh + - -c + - pg_isready -d "$POSTGRES_DB" -U "$POSTGRES_USER" + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 + readinessProbe: + exec: + command: + - sh + - -c + - pg_isready -d "$POSTGRES_DB" -U "$POSTGRES_USER" + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 volumeMounts: - mountPath: "/var/lib/postgresql/data" name: db-data diff --git a/apps/codimd/manifests/05-codimd-app-deployment.yaml b/apps/codimd/manifests/05-codimd-app-deployment.yaml index 9fb8a4c..dc07525 100644 --- a/apps/codimd/manifests/05-codimd-app-deployment.yaml +++ b/apps/codimd/manifests/05-codimd-app-deployment.yaml @@ -5,7 +5,7 @@ metadata: spec: replicas: 1 strategy: - type: Recreate + type: Recreate selector: matchLabels: app: codimd @@ -14,12 +14,16 @@ spec: labels: app: codimd spec: - securityContext: # <-- 這裡開始 - runAsUser: 0 - fsGroup: 0 # <-- 結束 containers: - name: codimd - image: hackmdio/hackmd:latest + image: hackmdio/hackmd:2.5.3-alpine + resources: + requests: + memory: "256Mi" + cpu: "100m" + limits: + memory: "512Mi" + cpu: "500m" env: - name: CMD_DB_URL valueFrom: @@ -34,6 +38,23 @@ spec: value: "true" - name: CMD_CSP_ENABLE value: "false" + # Health check (CodiMD has /healthz endpoint) + livenessProbe: + httpGet: + path: /healthz + port: 3000 + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 + readinessProbe: + httpGet: + path: /healthz + port: 3000 + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 volumeMounts: - mountPath: "/home/hackmd/app/public/uploads" name: upload-data diff --git a/apps/vaultwarden/manifests/vaultwarden-deployment.yaml b/apps/vaultwarden/manifests/vaultwarden-deployment.yaml index c41a999..6a5aad8 100644 --- a/apps/vaultwarden/manifests/vaultwarden-deployment.yaml +++ b/apps/vaultwarden/manifests/vaultwarden-deployment.yaml @@ -16,8 +16,11 @@ spec: spec: containers: - name: vaultwarden - image: vaultwarden/server:latest + image: vaultwarden/server:1.32.7-alpine resources: + requests: + memory: "128Mi" + cpu: "100m" limits: memory: "512Mi" cpu: "500m" @@ -29,7 +32,27 @@ spec: - name: DOMAIN value: "https://vaultwarden.lotimmy.com" - name: ADMIN_TOKEN - value: "$$argon2id$$v=19$$m=65540,t=3,p=4$$EVIbGzNlkQUK5b0r7aMgKoUWV98aqrpPevU+8Bbv0EE$$JB51q0ih0LGmw6rp7ZVBgT+PNnCepy+bNYyaChD+VMc" + valueFrom: + secretKeyRef: + name: vaultwarden-secret + key: ADMIN_TOKEN + # Health check + livenessProbe: + httpGet: + path: /alive + port: 80 + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 + readinessProbe: + httpGet: + path: /alive + port: 80 + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 volumeMounts: - mountPath: "/data" name: data-vol diff --git a/apps/vaultwarden/manifests/vaultwarden-secret.yaml b/apps/vaultwarden/manifests/vaultwarden-secret.yaml new file mode 100644 index 0000000..4d773f9 --- /dev/null +++ b/apps/vaultwarden/manifests/vaultwarden-secret.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +kind: Secret +metadata: + name: vaultwarden-secret +type: Opaque +stringData: + ADMIN_TOKEN: "$argon2id$v=19$m=65540,t=3,p=4$EVIbGzNlkQUK5b0r7aMgKoUWV98aqrpPevU+8Bbv0EE$JB51q0ih0LGmw6rp7ZVBgT+PNnCepy+bNYyaChD+VMc"