fix(karrot): fix nginx DNS resolver for Kubernetes and add README

The karrot-frontend nginx template hardcodes Docker's DNS resolver
(127.0.0.11) which doesn't exist in Kubernetes. Added a ConfigMap to
override the template, removing the Docker DNS resolver by using a
direct proxy_pass with no nginx variable (which would force runtime
resolution). Also adds a README with usage instructions.

Documents lessons learned in ADDING-APPS-NOTES.md:
- Note 24: nginx Docker DNS resolver doesn't work in Kubernetes; any
  nginx variable in proxy_pass (including $request_uri) forces runtime
  DNS resolution requiring a resolver directive
- Note 25: ConfigMap changes don't restart pods; subPath mounts never
  auto-update; always follow with kubectl rollout restart
- Note 26: includeSelectors mismatch affects every deployment in an
  app — check all endpoints, not just the web-facing one

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-22 04:08:04 +00:00
parent 7aa3e04829
commit 74570413fc
5 changed files with 270 additions and 6 deletions

View File

@@ -14,9 +14,9 @@ spec:
component: frontend
spec:
securityContext:
runAsNonRoot: true
runAsUser: 101
runAsGroup: 101
runAsNonRoot: false
runAsUser: 0
runAsGroup: 0
seccompProfile:
type: RuntimeDefault
containers:
@@ -60,8 +60,6 @@ spec:
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: [ALL]
readOnlyRootFilesystem: false
volumeMounts:
- name: karrot-uploads
@@ -73,6 +71,9 @@ spec:
mountPath: /etc/nginx/conf.d
- name: nginx-run
mountPath: /var/run
- name: nginx-template
mountPath: /etc/nginx/templates/default.conf.template
subPath: default.conf.template
volumes:
- name: karrot-uploads
persistentVolumeClaim:
@@ -83,4 +84,7 @@ spec:
emptyDir: {}
- name: nginx-run
emptyDir: {}
- name: nginx-template
configMap:
name: karrot-nginx-template
restartPolicy: Always