Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 1 | // ONLYOFFICE document server. |
| 2 | // JWT secret needs to be generated as follows per environment: |
| 3 | // kubectl -n onlyoffice-prod create secret generic documentserver-jwt --from-literal=jwt=$(pwgen 32 1) |
| 4 | |
Radek Pietruszewski | f584431 | 2023-10-27 22:41:18 +0200 | [diff] [blame] | 5 | local kube = import "../../kube/hscloud.libsonnet"; |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 6 | local policies = import "../../kube/policies.libsonnet"; |
| 7 | |
| 8 | { |
| 9 | onlyoffice:: { |
radex | c995c21 | 2023-11-24 12:01:49 +0100 | [diff] [blame] | 10 | local top = self, |
| 11 | local cfg = top.cfg, |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 12 | cfg:: { |
| 13 | namespace: error "cfg.namespace must be set", |
Piotr Dobrowolski | 4978706 | 2022-02-09 21:30:16 +0100 | [diff] [blame] | 14 | image: "onlyoffice/documentserver:7.0.0.132", |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 15 | storageClassName: "waw-hdd-redundant-3", |
| 16 | domain: error "cfg.domain must be set", |
| 17 | }, |
| 18 | |
radex | 1439fde | 2023-11-24 12:22:22 +0100 | [diff] [blame] | 19 | secretRefs:: { |
| 20 | jwt: { secretKeyRef: { name: "documentserver-jwt", key: "jwt", } }, |
| 21 | }, |
| 22 | |
radex | 99ed6a7 | 2023-11-24 11:42:55 +0100 | [diff] [blame] | 23 | local ns = kube.Namespace(cfg.namespace), |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 24 | |
radex | 99ed6a7 | 2023-11-24 11:42:55 +0100 | [diff] [blame] | 25 | pvc: ns.Contain(kube.PersistentVolumeClaim("documentserver")) { |
radex | 36964dc | 2023-11-24 11:19:46 +0100 | [diff] [blame] | 26 | storage:: "10Gi", |
| 27 | storageClass:: cfg.storageClassName, |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 28 | }, |
| 29 | |
radex | 99ed6a7 | 2023-11-24 11:42:55 +0100 | [diff] [blame] | 30 | deploy: ns.Contain(kube.Deployment("documentserver")) { |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 31 | spec+: { |
| 32 | template+: { |
| 33 | spec+: { |
| 34 | containers_: { |
| 35 | documentserver: kube.Container("default") { |
| 36 | image: cfg.image, |
| 37 | resources: { |
| 38 | requests: { memory: "4G", cpu: "100m" }, |
| 39 | limits: { memory: "8G", cpu: "2" }, |
| 40 | }, |
| 41 | env_: { |
| 42 | JWT_ENABLED: "true", |
radex | 1439fde | 2023-11-24 12:22:22 +0100 | [diff] [blame] | 43 | JWT_SECRET: top.secretRefs.jwt, |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 44 | }, |
| 45 | ports_: { |
| 46 | http: { containerPort: 80 }, |
| 47 | }, |
| 48 | local make(sp, p) = { name: "data", mountPath: p, subPath: sp }, |
| 49 | volumeMounts: [ |
| 50 | // Per upstream Dockerfile: |
Radek Pietruszewski | f584431 | 2023-10-27 22:41:18 +0200 | [diff] [blame] | 51 | // VOLUME /var/log/$COMPANY_NAME /var/lib/$COMPANY_NAME |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 52 | // /var/www/$COMPANY_NAME/Data /var/lib/postgresql |
| 53 | // /var/lib/rabbitmq /var/lib/redis |
| 54 | // /usr/share/fonts/truetype/custom |
| 55 | make("log", "/var/log/onlyoffice"), |
| 56 | make("www-data", "/var/www/onlyoffice/Data"), |
| 57 | make("postgres", "/var/lib/postgresql"), |
| 58 | make("rabbit", "/var/lib/rabbitmq"), |
| 59 | make("redis", "/var/lib/redis"), |
| 60 | make("fonts", "/usr/share/fonts/truetype/custom"), |
| 61 | ], |
| 62 | }, |
| 63 | }, |
| 64 | volumes_: { |
radex | c995c21 | 2023-11-24 12:01:49 +0100 | [diff] [blame] | 65 | data: kube.PersistentVolumeClaimVolume(top.pvc), |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 66 | }, |
| 67 | }, |
| 68 | }, |
| 69 | }, |
| 70 | }, |
| 71 | |
radex | 99ed6a7 | 2023-11-24 11:42:55 +0100 | [diff] [blame] | 72 | svc: ns.Contain(kube.Service("documentserver")) { |
radex | c995c21 | 2023-11-24 12:01:49 +0100 | [diff] [blame] | 73 | target:: top.deploy, |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 74 | }, |
Radek Pietruszewski | f584431 | 2023-10-27 22:41:18 +0200 | [diff] [blame] | 75 | |
radex | 99ed6a7 | 2023-11-24 11:42:55 +0100 | [diff] [blame] | 76 | ingress: ns.Contain(kube.SimpleIngress("office")) { |
Radek Pietruszewski | f584431 | 2023-10-27 22:41:18 +0200 | [diff] [blame] | 77 | hosts:: [cfg.domain], |
radex | c995c21 | 2023-11-24 12:01:49 +0100 | [diff] [blame] | 78 | target_service:: top.svc, |
Serge Bazanski | 06b61d4 | 2020-09-15 18:21:35 +0000 | [diff] [blame] | 79 | }, |
| 80 | |
| 81 | // Needed because the documentserver runs its own supervisor, and: |
| 82 | // - rabbitmq wants to mkdir in /run, which starts out with the wrong permissions |
| 83 | // - nginx wants to bind to port 80 |
| 84 | insecure: policies.AllowNamespaceInsecure(cfg.namespace), |
| 85 | }, |
| 86 | |
| 87 | prod: self.onlyoffice { |
| 88 | cfg+: { |
| 89 | namespace: "onlyoffice-prod", |
| 90 | domain: "office.hackerspace.pl", |
| 91 | }, |
| 92 | }, |
| 93 | } |