apiVersion: apps/v1 kind: Deployment metadata: name: karrot-frontend namespace: {{ .namespace }} spec: replicas: 1 selector: matchLabels: component: frontend template: metadata: labels: component: frontend spec: securityContext: runAsNonRoot: true runAsUser: 101 runAsGroup: 101 seccompProfile: type: RuntimeDefault containers: - name: karrot-frontend image: codeberg.org/karrot/karrot-frontend:v17.4.1 ports: - name: http containerPort: 8080 protocol: TCP env: - name: BACKEND value: karrot-backend:8000 - name: FILE_UPLOAD_DIR value: /app/uploads/ - name: FILE_UPLOAD_MAX_SIZE value: 10m resources: limits: cpu: 200m ephemeral-storage: 256Mi memory: 128Mi requests: cpu: 10m ephemeral-storage: 50Mi memory: 32Mi livenessProbe: httpGet: path: / port: 8080 initialDelaySeconds: 10 timeoutSeconds: 3 periodSeconds: 15 failureThreshold: 6 readinessProbe: httpGet: path: / port: 8080 initialDelaySeconds: 5 timeoutSeconds: 3 periodSeconds: 10 failureThreshold: 3 securityContext: allowPrivilegeEscalation: false capabilities: drop: [ALL] readOnlyRootFilesystem: false volumeMounts: - name: karrot-uploads mountPath: /app/uploads readOnly: true - name: nginx-cache mountPath: /var/cache/nginx - name: nginx-conf mountPath: /etc/nginx/conf.d - name: nginx-run mountPath: /var/run volumes: - name: karrot-uploads persistentVolumeClaim: claimName: karrot-uploads - name: nginx-cache emptyDir: {} - name: nginx-conf emptyDir: {} - name: nginx-run emptyDir: {} restartPolicy: Always