diff --git a/Tiltfile b/Tiltfile index 88f760a8..d3ff30a9 100644 --- a/Tiltfile +++ b/Tiltfile @@ -411,6 +411,10 @@ unitdb_labels = ["unitdb"] unitdb_links = [link("http://unitdb.{}".format(base_domain), "Rackover UnitDB")] proxy_local_service_if_set(service_name="faf-unitdb", service_chart="apps/faf-unitdb", service_namespace="faf-apps", service_labels=unitdb_labels, service_links=unitdb_links) +tournaments_labels = ["tournaments"] +tournaments_links = [link("http://tournaments.{}".format(base_domain), "FAF Tournaments")] +proxy_local_service_if_set(service_name="faf-tournaments", service_chart="apps/faf-tournaments", service_namespace="faf-apps", service_deps=["volumes"], service_labels=tournaments_labels, service_links=tournaments_links) + icebreaker_deps = ["faf-db-migrations", "ory-hydra"] + rabbitmq_setup_resources icebreaker_labels = ["api"] icebreaker_patch = {"HYDRA_URL": "http://ory-hydra:4444", "XIRSYS_ENABLED": "false", "XIRSYS_TURN_ENABLED": "false", "CLOUDFLARE_ENABLED": "false"} diff --git a/apps/faf-tournaments/Chart.yaml b/apps/faf-tournaments/Chart.yaml new file mode 100644 index 00000000..85f4bdc3 --- /dev/null +++ b/apps/faf-tournaments/Chart.yaml @@ -0,0 +1,8 @@ +apiVersion: v2 +name: faf-tournaments +version: 1.0.0 + +dependencies: + - name: infisical-secret + version: 1.0.0 + repository: file://../../common/infisical-secret diff --git a/apps/faf-tournaments/templates/config.yaml b/apps/faf-tournaments/templates/config.yaml new file mode 100644 index 00000000..bae52d49 --- /dev/null +++ b/apps/faf-tournaments/templates/config.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: faf-tournaments + labels: + app: faf-tournaments +data: + PORT: "8090" + DATA_DIR: "/data" + # The "FAF Tournaments" client in apps/ory-hydra. FAF login stays dormant + # until FAF_CLIENT_SECRET (Hydra's FAFTOURNEY_SECRET) is in the secret too; + # the site then falls back to name-only login. + FAF_CLIENT_ID: "f4d9a7e2-1c3b-4a8e-9f26-8b5e0d47c1a9" + FAF_HYDRA_HOST: "hydra.{{.Values.baseDomain}}" + FAF_API_HOST: "api.{{.Values.baseDomain}}" + FAF_REDIRECT_URI: "https://tournaments.{{.Values.baseDomain}}/auth/faf/callback" diff --git a/apps/faf-tournaments/templates/deployment.yaml b/apps/faf-tournaments/templates/deployment.yaml new file mode 100644 index 00000000..db7cc01e --- /dev/null +++ b/apps/faf-tournaments/templates/deployment.yaml @@ -0,0 +1,69 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: faf-tournaments + labels: + app: faf-tournaments + annotations: + reloader.stakater.com/auto: "true" + # Pushing to main in FAForever/faf-tournaments is the release: the image is + # republished as `latest`, and Keel rolls it out. Polled every two minutes + # rather than hourly, because tournaments run live and a fix cannot wait. + keel.sh/policy: force + keel.sh/matchTag: "true" + keel.sh/trigger: poll + keel.sh/pollSchedule: "@every 2m" +spec: + replicas: 1 + revisionHistoryLimit: 10 + # One db.json on one volume: the old pod has to be gone before the new one + # starts, or both would write the same file. + strategy: + type: Recreate + selector: + matchLabels: + app: faf-tournaments + template: + metadata: + labels: + app: faf-tournaments + spec: + # The image runs as the unprivileged `node` user (uid 1000), and a local + # volume keeps whatever owner its directory was created with. + initContainers: + - name: data-owner + image: busybox:1.37 + command: ["sh", "-c", "chown -R 1000:1000 /data"] + volumeMounts: + - name: data + mountPath: /data + containers: + - image: faforever/faf-tournaments:latest + imagePullPolicy: Always + name: faf-tournaments + envFrom: + - configMapRef: + name: faf-tournaments + - secretRef: + name: faf-tournaments + ports: + - containerPort: 8090 + livenessProbe: + httpGet: + path: /healthz + port: 8090 + initialDelaySeconds: 5 + periodSeconds: 30 + readinessProbe: + httpGet: + path: /healthz + port: 8090 + periodSeconds: 10 + volumeMounts: + - name: data + mountPath: /data + volumes: + - name: data + persistentVolumeClaim: + claimName: faf-tournaments-pvc + restartPolicy: Always diff --git a/apps/faf-tournaments/templates/ingress.yaml b/apps/faf-tournaments/templates/ingress.yaml new file mode 100644 index 00000000..de0a1c01 --- /dev/null +++ b/apps/faf-tournaments/templates/ingress.yaml @@ -0,0 +1,13 @@ +apiVersion: traefik.io/v1alpha1 +kind: IngressRoute +metadata: + name: faf-tournaments +spec: + entryPoints: + - websecure + routes: + - match: Host(`tournaments.{{.Values.baseDomain}}`) + kind: Rule + services: + - name: faf-tournaments + port: 8090 diff --git a/apps/faf-tournaments/templates/local-secret.yaml b/apps/faf-tournaments/templates/local-secret.yaml new file mode 100644 index 00000000..753306fe --- /dev/null +++ b/apps/faf-tournaments/templates/local-secret.yaml @@ -0,0 +1,10 @@ +{{- if not (index .Values "infisical-secret" "enabled") }} +apiVersion: v1 +kind: Secret +metadata: + name: {{ .Chart.Name }} +type: Opaque +stringData: + ADMIN_PASSWORD: "banana" + FAF_CLIENT_SECRET: "" +{{- end}} diff --git a/apps/faf-tournaments/templates/service.yaml b/apps/faf-tournaments/templates/service.yaml new file mode 100644 index 00000000..9bd16921 --- /dev/null +++ b/apps/faf-tournaments/templates/service.yaml @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: Service +metadata: + name: faf-tournaments + labels: + app: faf-tournaments +spec: + selector: + app: faf-tournaments + ports: + - port: 8090 + targetPort: 8090 diff --git a/apps/faf-tournaments/values-prod.yaml b/apps/faf-tournaments/values-prod.yaml new file mode 100644 index 00000000..e69de29b diff --git a/apps/faf-tournaments/values-test.yaml b/apps/faf-tournaments/values-test.yaml new file mode 100644 index 00000000..e69de29b diff --git a/apps/faf-tournaments/values.yaml b/apps/faf-tournaments/values.yaml new file mode 100644 index 00000000..c1356f2a --- /dev/null +++ b/apps/faf-tournaments/values.yaml @@ -0,0 +1,2 @@ +infisical-secret: + name: faf-tournaments diff --git a/apps/ory-hydra/values.yaml b/apps/ory-hydra/values.yaml index 95250e03..bffe2573 100644 --- a/apps/ory-hydra/values.yaml +++ b/apps/ory-hydra/values.yaml @@ -162,7 +162,7 @@ clients: key: FAFTOURNEY_SECRET grantType: "authorization_code,refresh_token" scope: "openid,offline,public_profile" - redirectUri: "https://tournaments.doodlepros.com/auth/faf/callback" + redirectUri: "https://tournaments.doodlepros.com/auth/faf/callback,https://tournaments.$BASE_DOMAIN/auth/faf/callback" logoUri: "https://tournaments.doodlepros.com/favicon.svg" clientUri: "https://tournaments.doodlepros.com" tokenEndpointAuthMethod: "client_secret_post" diff --git a/cluster/storage/values.yaml b/cluster/storage/values.yaml index 374e8dd4..029cad57 100644 --- a/cluster/storage/values.yaml +++ b/cluster/storage/values.yaml @@ -93,3 +93,8 @@ managedStorages: size: 1Gi pvc: namespace: faf-ops + - pv: + name: faf-tournaments + size: 5Gi + pvc: + namespace: faf-apps