This commit is contained in:
2025-10-25 08:43:42 +08:00
parent e5cd2700aa
commit d207146423
10 changed files with 687 additions and 10 deletions

242
script/cd.sh Normal file
View File

@@ -0,0 +1,242 @@
#!/bin/bash
# Continuous Deployment Script for Kubernetes
# This script deploys your application to a Kubernetes cluster
# =============================================================================
# Environment Variables (with default values)
# =============================================================================
# Kubernetes Configuration
KUBECONFIG_DATA="${KUBECONFIG_DATA:-}"
KUBERNETES_URL="${KUBERNETES_URL:-https://kubernetes.default.svc}"
KUBERNETES_NAMESPACE="${KUBERNETES_NAMESPACE:-default}"
KUBERNETES_INGRESS_HOST="${KUBERNETES_INGRESS_HOST:-blog-api.example.com}"
KUBERNETES_DEPLOYMENT_REPLICAS="${KUBERNETES_DEPLOYMENT_REPLICAS:-2}"
# Container Registry
CONTAINER_REGISTRY_URL="${CONTAINER_REGISTRY_URL:-127.0.0.1}"
CONTAINER_REGISTRY_USERNAME="${CONTAINER_REGISTRY_USERNAME:-username}"
CONTAINER_REGISTRY_NAMESPACE="${CONTAINER_REGISTRY_NAMESPACE:-username}"
CONTAINER_REGISTRY_PASSWORD="${CONTAINER_REGISTRY_PASSWORD:-password}"
CONTAINER_IMAGE_NAME="${CONTAINER_IMAGE_NAME:-blog}"
CONTAINER_IMAGE_TAG="${CONTAINER_IMAGE_TAG:-latest}"
# Application Configuration
DATABASE_DSN="${DATABASE_DSN:-postgres://postgres:password@localhost:5432/steam_union?sslmode=disable}"
JWT_SECRET="${JWT_SECRET:-your-secret-key-change-in-production}"
JWT_ISSUER="${JWT_ISSUER:-cialloo-authenticator}"
JWT_EXPIRES_IN="${JWT_EXPIRES_IN:-604800}"
S3_REGION="${S3_REGION:-us-east-1}"
S3_BUCKET="${S3_BUCKET:-your-bucket-name}"
S3_ACCESS_KEY_ID="${S3_ACCESS_KEY_ID:-your-access-key-id}"
S3_SECRET_ACCESS_KEY="${S3_SECRET_ACCESS_KEY:-your-secret-access-key}"
S3_ENDPOINT="${S3_ENDPOINT:-}"
S3_PRESIGNED_URL_EXPIRATION="${S3_PRESIGNED_URL_EXPIRATION:-3600}"
FORCE_RESTART="${FORCE_RESTART:-true}"
# =============================================================================
# Functions
# =============================================================================
# Print help message
print_help() {
echo "Usage: $0 [OPTIONS]"
echo ""
echo "Environment Variables:"
echo " KUBECONFIG_DATA Kubernetes config data (base64 encoded)"
echo " KUBERNETES_URL Kubernetes API URL (default: https://kubernetes.default.svc)"
echo " KUBERNETES_NAMESPACE Kubernetes namespace (default: default)"
echo " KUBERNETES_INGRESS_HOST Ingress host (default: blog-api.example.com)"
echo " KUBERNETES_DEPLOYMENT_REPLICAS Number of pod replicas (default: 2)"
echo " CONTAINER_REGISTRY_URL Container registry URL (default: 127.0.0.1)"
echo " CONTAINER_REGISTRY_USERNAME Registry username"
echo " CONTAINER_REGISTRY_PASSWORD Registry password"
echo " CONTAINER_IMAGE_NAME Image name (default: blog)"
echo " CONTAINER_IMAGE_TAG Image tag (default: latest)"
echo " DATABASE_DSN Database connection string"
echo " JWT_SECRET JWT secret key"
echo " JWT_ISSUER JWT issuer"
echo " JWT_EXPIRES_IN JWT expiration time in seconds"
echo " S3_REGION S3 region"
echo " S3_BUCKET S3 bucket name"
echo " S3_ACCESS_KEY_ID S3 access key ID"
echo " S3_SECRET_ACCESS_KEY S3 secret access key"
echo " S3_ENDPOINT S3 endpoint (optional)"
echo " S3_PRESIGNED_URL_EXPIRATION Presigned URL expiration in seconds"
echo " FORCE_RESTART Force rollout restart (default: true)"
echo ""
echo "Commands:"
echo " deploy Deploy application to Kubernetes"
echo " help Show this help message (default)"
}
# Setup kubectl configuration
setup_kubectl() {
echo "Setting up kubectl configuration..."
if [ -z "${KUBECONFIG_DATA}" ]; then
echo "✗ KUBECONFIG_DATA is not set"
return 1
fi
mkdir -p ~/.kube
echo "${KUBECONFIG_DATA}" | base64 -d > ~/.kube/config
chmod 600 ~/.kube/config
echo "✓ kubectl configured"
return 0
}
# Create namespace if it doesn't exist
create_namespace() {
echo "Checking namespace: ${KUBERNETES_NAMESPACE}"
kubectl get namespace "${KUBERNETES_NAMESPACE}" &> /dev/null
if [ $? -ne 0 ]; then
echo "Creating namespace: ${KUBERNETES_NAMESPACE}"
kubectl create namespace "${KUBERNETES_NAMESPACE}"
else
echo "✓ Namespace exists: ${KUBERNETES_NAMESPACE}"
fi
}
# Create image pull secret
create_image_pull_secret() {
echo "Creating image pull secret..."
kubectl create secret docker-registry regcred \
--docker-server="${CONTAINER_REGISTRY_URL}" \
--docker-username="${CONTAINER_REGISTRY_USERNAME}" \
--docker-password="${CONTAINER_REGISTRY_PASSWORD}" \
--namespace="${KUBERNETES_NAMESPACE}" \
--dry-run=client -o yaml | kubectl apply -f -
echo "✓ Image pull secret created/updated"
}
# Create or update application secrets
create_app_secrets() {
echo "Creating application secrets..."
kubectl create secret generic blog-secrets \
--from-literal=database-dsn="${DATABASE_DSN}" \
--from-literal=jwt-secret="${JWT_SECRET}" \
--from-literal=s3-access-key-id="${S3_ACCESS_KEY_ID}" \
--from-literal=s3-secret-access-key="${S3_SECRET_ACCESS_KEY}" \
--namespace="${KUBERNETES_NAMESPACE}" \
--dry-run=client -o yaml | kubectl apply -f -
echo "✓ Application secrets created/updated"
}
# Apply Kubernetes manifests
apply_manifests() {
echo "Applying Kubernetes manifests..."
# Substitute environment variables in manifests
export KUBERNETES_NAMESPACE
export KUBERNETES_INGRESS_HOST
export KUBERNETES_DEPLOYMENT_REPLICAS
export CONTAINER_REGISTRY_URL
export CONTAINER_REGISTRY_NAMESPACE
export CONTAINER_IMAGE_NAME
export CONTAINER_IMAGE_TAG
export JWT_ISSUER
export JWT_EXPIRES_IN
export S3_REGION
export S3_BUCKET
export S3_ENDPOINT
export S3_PRESIGNED_URL_EXPIRATION
# Apply namespace
envsubst < script/k8s/namespace.yaml | kubectl apply -f -
# Apply deployment
envsubst < script/k8s/deployment.yaml | kubectl apply -f -
# Apply service
envsubst < script/k8s/service.yaml | kubectl apply -f -
# Apply ingress
envsubst < script/k8s/ingress.yaml | kubectl apply -f -
echo "✓ Manifests applied"
}
# Wait for deployment to be ready
wait_for_deployment() {
echo "Waiting for deployment to be ready..."
kubectl rollout status deployment/blog \
--namespace="${KUBERNETES_NAMESPACE}" \
--timeout=300s
if [ $? -eq 0 ]; then
echo "✓ Deployment ready"
return 0
else
echo "✗ Deployment failed"
return 1
fi
}
# Force restart deployment
force_restart_deployment() {
if [ "${FORCE_RESTART}" = "true" ]; then
echo "Forcing deployment restart..."
kubectl rollout restart deployment/blog \
--namespace="${KUBERNETES_NAMESPACE}"
echo "✓ Deployment restarted"
fi
}
# Deploy application
deploy() {
echo "=========================================="
echo "Deploying Blog Application"
echo "=========================================="
echo "Namespace: ${KUBERNETES_NAMESPACE}"
echo "Image: ${CONTAINER_REGISTRY_URL}/${CONTAINER_REGISTRY_NAMESPACE}/${CONTAINER_IMAGE_NAME}:${CONTAINER_IMAGE_TAG}"
echo "Host: ${KUBERNETES_INGRESS_HOST}"
echo ""
setup_kubectl || return 1
create_namespace || return 1
create_image_pull_secret || return 1
create_app_secrets || return 1
apply_manifests || return 1
force_restart_deployment
wait_for_deployment || return 1
echo ""
echo "=========================================="
echo "✓ Deployment Successful"
echo "=========================================="
echo "Application URL: http://${KUBERNETES_INGRESS_HOST}"
echo ""
return 0
}
# =============================================================================
# Main Script
# =============================================================================
case "$1" in
deploy)
deploy
exit $?
;;
help|--help|-h|"")
print_help
exit 0
;;
*)
echo "Unknown option: $1"
echo ""
print_help
exit 1
;;
esac

121
script/ci.sh Normal file
View File

@@ -0,0 +1,121 @@
#!/bin/bash
# CI/CD Script for Docker Build and Push
# This script builds a Docker image and pushes it to a private container registry
# =============================================================================
# Environment Variables (with default values)
# =============================================================================
CONTAINER_REGISTRY_URL="${CONTAINER_REGISTRY_URL:-127.0.0.1}"
CONTAINER_REGISTRY_USERNAME="${CONTAINER_REGISTRY_USERNAME:-username}"
CONTAINER_REGISTRY_NAMESPACE="${CONTAINER_REGISTRY_NAMESPACE:-username}"
CONTAINER_REGISTRY_PASSWORD="${CONTAINER_REGISTRY_PASSWORD:-password}"
CONTAINER_IMAGE_NAME="${CONTAINER_IMAGE_NAME:-blog}"
CONTAINER_IMAGE_TAG="${CONTAINER_IMAGE_TAG:-latest}"
# =============================================================================
# Functions
# =============================================================================
# Print help message
print_help() {
echo "Usage: $0 [OPTIONS]"
echo ""
echo "Options:"
echo " build Build Docker image"
echo " push Push Docker image to registry"
echo " help Show this help message (default)"
echo ""
echo "Environment Variables:"
echo " CONTAINER_REGISTRY_URL Registry URL (default: 127.0.0.1)"
echo " CONTAINER_REGISTRY_USERNAME Registry username (default: username)"
echo " CONTAINER_REGISTRY_NAMESPACE Registry namespace (default: username)"
echo " CONTAINER_REGISTRY_PASSWORD Registry password (default: password)"
echo " CONTAINER_IMAGE_NAME Image name (default: blog)"
echo " CONTAINER_IMAGE_TAG Image tag (default: latest)"
}
# Build Docker image
build_image() {
FULL_IMAGE_NAME="${CONTAINER_REGISTRY_URL}/${CONTAINER_REGISTRY_NAMESPACE}/${CONTAINER_IMAGE_NAME}:${CONTAINER_IMAGE_TAG}"
echo "=========================================="
echo "Building Docker Image"
echo "=========================================="
echo "Image: ${FULL_IMAGE_NAME}"
echo ""
docker build -t "${FULL_IMAGE_NAME}" .
if [ $? -eq 0 ]; then
echo ""
echo "✓ Build successful: ${FULL_IMAGE_NAME}"
return 0
else
echo ""
echo "✗ Build failed"
return 1
fi
}
# Push Docker image to registry
push_image() {
FULL_IMAGE_NAME="${CONTAINER_REGISTRY_URL}/${CONTAINER_REGISTRY_NAMESPACE}/${CONTAINER_IMAGE_NAME}:${CONTAINER_IMAGE_TAG}"
echo "=========================================="
echo "Pushing Docker Image"
echo "=========================================="
echo "Registry: ${CONTAINER_REGISTRY_URL}"
echo "Image: ${FULL_IMAGE_NAME}"
echo ""
# Login to registry
echo "${CONTAINER_REGISTRY_PASSWORD}" | docker login "${CONTAINER_REGISTRY_URL}" \
--username "${CONTAINER_REGISTRY_USERNAME}" \
--password-stdin
if [ $? -ne 0 ]; then
echo "✗ Registry login failed"
return 1
fi
# Push image
docker push "${FULL_IMAGE_NAME}"
if [ $? -eq 0 ]; then
echo ""
echo "✓ Push successful: ${FULL_IMAGE_NAME}"
docker logout "${CONTAINER_REGISTRY_URL}"
return 0
else
echo ""
echo "✗ Push failed"
docker logout "${CONTAINER_REGISTRY_URL}"
return 1
fi
}
# =============================================================================
# Main Script
# =============================================================================
case "$1" in
build)
build_image
exit $?
;;
push)
push_image
exit $?
;;
help|--help|-h|"")
print_help
exit 0
;;
*)
echo "Unknown option: $1"
echo ""
print_help
exit 1
;;
esac

View File

@@ -0,0 +1,94 @@
# Kubernetes Deployment Configuration
apiVersion: apps/v1
kind: Deployment
metadata:
name: blog
namespace: ${KUBERNETES_NAMESPACE}
labels:
app: blog
spec:
replicas: ${KUBERNETES_DEPLOYMENT_REPLICAS}
selector:
matchLabels:
app: blog
template:
metadata:
labels:
app: blog
spec:
imagePullSecrets:
- name: regcred
containers:
- name: blog
image: ${CONTAINER_REGISTRY_URL}/${CONTAINER_REGISTRY_NAMESPACE}/${CONTAINER_IMAGE_NAME}:${CONTAINER_IMAGE_TAG}
imagePullPolicy: Always
ports:
- name: http
containerPort: 8888
protocol: TCP
readinessProbe:
httpGet:
path: /api/blog/ping
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
livenessProbe:
httpGet:
path: /api/blog/ping
port: http
initialDelaySeconds: 15
periodSeconds: 20
timeoutSeconds: 5
failureThreshold: 3
resources:
requests:
memory: "128Mi"
cpu: "200m"
limits:
memory: "512Mi"
cpu: "1000m"
env:
- name: TZ
value: "UTC"
- name: DATABASE_DSN
valueFrom:
secretKeyRef:
name: blog-secrets
key: database-dsn
- name: JWT_SECRET
valueFrom:
secretKeyRef:
name: blog-secrets
key: jwt-secret
- name: JWT_ISSUER
value: "${JWT_ISSUER}"
- name: JWT_EXPIRES_IN
value: "${JWT_EXPIRES_IN}"
- name: S3_REGION
value: "${S3_REGION}"
- name: S3_BUCKET
value: "${S3_BUCKET}"
- name: S3_ACCESS_KEY_ID
valueFrom:
secretKeyRef:
name: blog-secrets
key: s3-access-key-id
- name: S3_SECRET_ACCESS_KEY
valueFrom:
secretKeyRef:
name: blog-secrets
key: s3-secret-access-key
- name: S3_ENDPOINT
value: "${S3_ENDPOINT}"
- name: S3_PRESIGNED_URL_EXPIRATION
value: "${S3_PRESIGNED_URL_EXPIRATION}"

25
script/k8s/ingress.yaml Normal file
View File

@@ -0,0 +1,25 @@
# Kubernetes Ingress Configuration for Traefik
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: blog
namespace: ${KUBERNETES_NAMESPACE}
annotations:
traefik.ingress.kubernetes.io/router.entrypoints: web
labels:
app: blog
spec:
rules:
- host: ${KUBERNETES_INGRESS_HOST}
http:
paths:
- path: /api/blog
pathType: Prefix
backend:
service:
name: blog
port:
number: 8888

View File

@@ -0,0 +1,7 @@
# Kubernetes Namespace Configuration
apiVersion: v1
kind: Namespace
metadata:
name: ${KUBERNETES_NAMESPACE}
labels:
name: ${KUBERNETES_NAMESPACE}

19
script/k8s/service.yaml Normal file
View File

@@ -0,0 +1,19 @@
# Kubernetes Service Configuration
apiVersion: v1
kind: Service
metadata:
name: blog
namespace: ${KUBERNETES_NAMESPACE}
labels:
app: blog
spec:
type: ClusterIP
selector:
app: blog
ports:
- name: http
port: 8888
targetPort: http
protocol: TCP