The karrot-frontend nginx template hardcodes Docker's DNS resolver (127.0.0.11) which doesn't exist in Kubernetes. Added a ConfigMap to override the template, removing the Docker DNS resolver by using a direct proxy_pass with no nginx variable (which would force runtime resolution). Also adds a README with usage instructions. Documents lessons learned in ADDING-APPS-NOTES.md: - Note 24: nginx Docker DNS resolver doesn't work in Kubernetes; any nginx variable in proxy_pass (including $request_uri) forces runtime DNS resolution requiring a resolver directive - Note 25: ConfigMap changes don't restart pods; subPath mounts never auto-update; always follow with kubectl rollout restart - Note 26: includeSelectors mismatch affects every deployment in an app — check all endpoints, not just the web-facing one Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
91 lines
2.5 KiB
YAML
91 lines
2.5 KiB
YAML
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: karrot-frontend
|
|
namespace: {{ .namespace }}
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
component: frontend
|
|
template:
|
|
metadata:
|
|
labels:
|
|
component: frontend
|
|
spec:
|
|
securityContext:
|
|
runAsNonRoot: false
|
|
runAsUser: 0
|
|
runAsGroup: 0
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
containers:
|
|
- name: karrot-frontend
|
|
image: codeberg.org/karrot/karrot-frontend:v17.4.1
|
|
ports:
|
|
- name: http
|
|
containerPort: 8080
|
|
protocol: TCP
|
|
env:
|
|
- name: BACKEND
|
|
value: karrot-backend:8000
|
|
- name: FILE_UPLOAD_DIR
|
|
value: /app/uploads/
|
|
- name: FILE_UPLOAD_MAX_SIZE
|
|
value: 10m
|
|
resources:
|
|
limits:
|
|
cpu: 200m
|
|
ephemeral-storage: 256Mi
|
|
memory: 128Mi
|
|
requests:
|
|
cpu: 10m
|
|
ephemeral-storage: 50Mi
|
|
memory: 32Mi
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /
|
|
port: 8080
|
|
initialDelaySeconds: 10
|
|
timeoutSeconds: 3
|
|
periodSeconds: 15
|
|
failureThreshold: 6
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /
|
|
port: 8080
|
|
initialDelaySeconds: 5
|
|
timeoutSeconds: 3
|
|
periodSeconds: 10
|
|
failureThreshold: 3
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
readOnlyRootFilesystem: false
|
|
volumeMounts:
|
|
- name: karrot-uploads
|
|
mountPath: /app/uploads
|
|
readOnly: true
|
|
- name: nginx-cache
|
|
mountPath: /var/cache/nginx
|
|
- name: nginx-conf
|
|
mountPath: /etc/nginx/conf.d
|
|
- name: nginx-run
|
|
mountPath: /var/run
|
|
- name: nginx-template
|
|
mountPath: /etc/nginx/templates/default.conf.template
|
|
subPath: default.conf.template
|
|
volumes:
|
|
- name: karrot-uploads
|
|
persistentVolumeClaim:
|
|
claimName: karrot-uploads
|
|
- name: nginx-cache
|
|
emptyDir: {}
|
|
- name: nginx-conf
|
|
emptyDir: {}
|
|
- name: nginx-run
|
|
emptyDir: {}
|
|
- name: nginx-template
|
|
configMap:
|
|
name: karrot-nginx-template
|
|
restartPolicy: Always
|