Refactor labels.app.kubernetes.part-of

This commit is contained in:
erik 2022-11-01 15:37:29 +01:00
parent 2bc0168d14
commit 68d8323921
5 changed files with 39 additions and 20 deletions

View file

@ -12,15 +12,16 @@
(s/def ::issuer pred/letsencrypt-issuer?) (s/def ::issuer pred/letsencrypt-issuer?)
(s/def ::service-name string?) (s/def ::service-name string?)
(s/def ::app-name string?)
(s/def ::ingress-name string?) (s/def ::ingress-name string?)
(s/def ::cert-name string?) (s/def ::cert-name string?)
(s/def ::service-port pos-int?) (s/def ::service-port pos-int?)
(s/def ::fqdns (s/coll-of pred/fqdn-string?)) (s/def ::fqdns (s/coll-of pred/fqdn-string?))
(def ingress? (s/keys :req-un [::fqdns ::ingress-name ::service-name ::service-port] (def ingress? (s/keys :req-un [::fqdns ::app-name ::ingress-name ::service-name ::service-port]
:opt-un [::issuer ::cert-name])) :opt-un [::issuer ::cert-name]))
(def certificate? (s/keys :req-un [::fqdns ::cert-name] (def certificate? (s/keys :req-un [::fqdns ::app-name ::cert-name]
:opt-un [::issuer])) :opt-un [::issuer]))
#?(:cljs #?(:cljs
@ -32,6 +33,7 @@
"ingress/https-ingress.yaml" (rc/inline "ingress/https-ingress.yaml") "ingress/https-ingress.yaml" (rc/inline "ingress/https-ingress.yaml")
(throw (js/Error. "Undefined Resource!"))))) (throw (js/Error. "Undefined Resource!")))))
; TODO: Review jem 2022/10/26: generalize!
#?(:cljs #?(:cljs
(defmethod yaml/load-as-edn :ingress [resource-name] (defmethod yaml/load-as-edn :ingress [resource-name]
(yaml/from-string (yaml/load-resource resource-name)))) (yaml/from-string (yaml/load-resource resource-name))))
@ -48,32 +50,34 @@
(defn-spec generate-http-ingress pred/map-or-seq? (defn-spec generate-http-ingress pred/map-or-seq?
[config ingress?] [config ingress?]
(let [{:keys [ingress-name service-name service-port fqdns]} config] (let [{:keys [ingress-name service-name service-port fqdns app-name]} config]
(-> (->
(yaml/load-as-edn "ingress/http-ingress.yaml") (yaml/load-as-edn "ingress/http-ingress.yaml")
(assoc-in [:metadata :name] ingress-name) (assoc-in [:metadata :name] ingress-name)
(assoc-in [:metadata :labels :app.kubernetes.part-of] app-name)
(assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns))))) (assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns)))))
(defn-spec generate-https-ingress pred/map-or-seq? (defn-spec generate-https-ingress pred/map-or-seq?
[config ingress?] [config ingress?]
(let [{:keys [ingress-name cert-name service-name service-port fqdns]} config] (let [{:keys [ingress-name cert-name service-name service-port fqdns app-name]} config]
(-> (->
(yaml/load-as-edn "ingress/https-ingress.yaml") (yaml/load-as-edn "ingress/https-ingress.yaml")
(assoc-in [:metadata :name] ingress-name) (assoc-in [:metadata :name] ingress-name)
(assoc-in [:metadata :labels :app.kubernetes.part-of] app-name)
(assoc-in [:spec :tls 0 :secretName] cert-name) (assoc-in [:spec :tls 0 :secretName] cert-name)
(assoc-in [:spec :tls 0 :hosts] fqdns) (assoc-in [:spec :tls 0 :hosts] fqdns)
(assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns))))) (assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns)))))
(defn-spec generate-certificate pred/map-or-seq? (defn-spec generate-certificate pred/map-or-seq?
[config certificate?] [config certificate?]
(let [{:keys [cert-name issuer fqdns] (let [{:keys [cert-name issuer fqdns app-name]
:or {issuer "staging"}} config :or {issuer "staging"}} config
letsencrypt-issuer (name issuer)] letsencrypt-issuer (name issuer)]
(-> (->
(yaml/load-as-edn "ingress/certificate.yaml") (yaml/load-as-edn "ingress/certificate.yaml")
(assoc-in [:metadata :name] cert-name) (assoc-in [:metadata :name] cert-name)
(assoc-in [:metadata :labels :app.kubernetes.part-of] app-name)
(assoc-in [:spec :secretName] cert-name) (assoc-in [:spec :secretName] cert-name)
(assoc-in [:spec :commonName] (first fqdns)) (assoc-in [:spec :commonName] (first fqdns))
(assoc-in [:spec :dnsNames] fqdns) (assoc-in [:spec :dnsNames] fqdns)
(assoc-in [:spec :issuerRef :name] letsencrypt-issuer)))) (assoc-in [:spec :issuerRef :name] letsencrypt-issuer))))

View file

@ -2,6 +2,8 @@ apiVersion: cert-manager.io/v1
kind: Certificate kind: Certificate
metadata: metadata:
name: c4k-common-cert name: c4k-common-cert
labels:
app.kubernetes.part-of: c4k-common-app
namespace: default namespace: default
spec: spec:
secretName: c4k-common-cert secretName: c4k-common-cert

View file

@ -3,6 +3,8 @@ kind: Ingress
metadata: metadata:
name: c4k-common-http-ingress name: c4k-common-http-ingress
namespace: default namespace: default
labels:
app.kubernetes.part-of: c4k-common-app
annotations: annotations:
traefik.ingress.kubernetes.io/router.entrypoints: web traefik.ingress.kubernetes.io/router.entrypoints: web
traefik.ingress.kubernetes.io/router.middlewares: default-redirect-https@kubernetescrd traefik.ingress.kubernetes.io/router.middlewares: default-redirect-https@kubernetescrd
@ -13,7 +15,7 @@ spec:
paths: paths:
- pathType: Prefix - pathType: Prefix
path: "/" path: "/"
backend: backend: # TODO: Review jem 2022/10/26: wo backend as we should only do a redirect here ... ?
service: service:
name: SERVICE_NAME name: SERVICE_NAME
port: port:

View file

@ -3,6 +3,8 @@ kind: Ingress
metadata: metadata:
name: c4k-common-https-ingress name: c4k-common-https-ingress
namespace: default namespace: default
labels:
app.kubernetes.part-of: c4k-common-app
annotations: annotations:
traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.entrypoints: websecure
traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.tls: "true"

View file

@ -1,4 +1,4 @@
(ns dda.c4k-common.ingress-test (ns dda.c4k-common.ingress-cert-test
(:require (:require
#?(:clj [clojure.test :refer [deftest is are testing run-tests]] #?(:clj [clojure.test :refer [deftest is are testing run-tests]]
:cljs [cljs.test :refer-macros [deftest is are testing run-tests]]) :cljs [cljs.test :refer-macros [deftest is are testing run-tests]])
@ -28,11 +28,13 @@
:metadata :metadata
{:name "test-io-http-ingress", {:name "test-io-http-ingress",
:namespace "default", :namespace "default",
:labels {:app.kubernetes.part-of "c4k-common-app"},
:annotations :annotations
#:traefik.ingress.kubernetes.io{:router.entrypoints "web", #:traefik.ingress.kubernetes.io{:router.entrypoints "web",
:router.middlewares "default-redirect-https@kubernetescrd"}}} :router.middlewares "default-redirect-https@kubernetescrd"}}}
(dissoc (cut/generate-http-ingress (dissoc (cut/generate-http-ingress
{:issuer "prod" {:issuer "prod"
:app-name "c4k-common-app"
:service-name "myservice" :service-name "myservice"
:service-port 3000 :service-port 3000
:ingress-name "test-io-http-ingress" :ingress-name "test-io-http-ingress"
@ -53,6 +55,7 @@
(:spec (cut/generate-http-ingress (:spec (cut/generate-http-ingress
{:issuer "prod" {:issuer "prod"
:service-name "myservice" :service-name "myservice"
:app-name "c4k-common-app"
:service-port 3000 :service-port 3000
:ingress-name "test-io-http-ingress" :ingress-name "test-io-http-ingress"
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]}))))) :fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]})))))
@ -63,10 +66,12 @@
:metadata :metadata
{:name "test-io-https-ingress", {:name "test-io-https-ingress",
:namespace "default", :namespace "default",
:labels {:app.kubernetes.part-of "c4k-common-app"},
:annotations #:traefik.ingress.kubernetes.io{:router.entrypoints "websecure", :router.tls "true"}}} :annotations #:traefik.ingress.kubernetes.io{:router.entrypoints "websecure", :router.tls "true"}}}
(dissoc (cut/generate-https-ingress (dissoc (cut/generate-https-ingress
{:issuer "prod" {:issuer "prod"
:service-name "test-io-service" :service-name "test-io-service"
:app-name "c4k-common-app"
:service-port 80 :service-port 80
:ingress-name "test-io-https-ingress" :ingress-name "test-io-https-ingress"
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]}) :spec))) :fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]}) :spec)))
@ -88,6 +93,7 @@
:http :http
{:paths [{:pathType "Prefix", :path "/", :backend {:service {:name "test-io-service", :port {:number 80}}}}]}}]} {:paths [{:pathType "Prefix", :path "/", :backend {:service {:name "test-io-service", :port {:number 80}}}}]}}]}
(:spec (cut/generate-https-ingress {:issuer "prod" (:spec (cut/generate-https-ingress {:issuer "prod"
:app-name "c4k-common-app"
:service-name "test-io-service" :service-name "test-io-service"
:service-port 80 :service-port 80
:ingress-name "test-io-https-ingress" :ingress-name "test-io-https-ingress"
@ -97,7 +103,9 @@
(deftest should-generate-certificate (deftest should-generate-certificate
(is (= {:apiVersion "cert-manager.io/v1", (is (= {:apiVersion "cert-manager.io/v1",
:kind "Certificate", :kind "Certificate",
:metadata {:name "test-io-cert", :namespace "default"}, :metadata {:name "test-io-cert",
:namespace "default",
:labels {:app.kubernetes.part-of "c4k-common-app"}},
:spec :spec
{:secretName "test-io-cert", {:secretName "test-io-cert",
:commonName "test.de", :commonName "test.de",
@ -106,5 +114,6 @@
:dnsNames ["test.de" "test.org" "www.test.de" "www.test.org"], :dnsNames ["test.de" "test.org" "www.test.de" "www.test.org"],
:issuerRef {:name "prod", :kind "ClusterIssuer"}}} :issuerRef {:name "prod", :kind "ClusterIssuer"}}}
(cut/generate-certificate {:fqdns ["test.de" "test.org" "www.test.de" "www.test.org"] (cut/generate-certificate {:fqdns ["test.de" "test.org" "www.test.de" "www.test.org"]
:app-name "c4k-common-app"
:cert-name "test-io-cert" :cert-name "test-io-cert"
:issuer "prod"})))) :issuer "prod"}))))