Refactor labels.app.kubernetes.part-of
This commit is contained in:
parent
2bc0168d14
commit
68d8323921
5 changed files with 39 additions and 20 deletions
|
@ -12,15 +12,16 @@
|
||||||
|
|
||||||
(s/def ::issuer pred/letsencrypt-issuer?)
|
(s/def ::issuer pred/letsencrypt-issuer?)
|
||||||
(s/def ::service-name string?)
|
(s/def ::service-name string?)
|
||||||
|
(s/def ::app-name string?)
|
||||||
(s/def ::ingress-name string?)
|
(s/def ::ingress-name string?)
|
||||||
(s/def ::cert-name string?)
|
(s/def ::cert-name string?)
|
||||||
(s/def ::service-port pos-int?)
|
(s/def ::service-port pos-int?)
|
||||||
(s/def ::fqdns (s/coll-of pred/fqdn-string?))
|
(s/def ::fqdns (s/coll-of pred/fqdn-string?))
|
||||||
|
|
||||||
(def ingress? (s/keys :req-un [::fqdns ::ingress-name ::service-name ::service-port]
|
(def ingress? (s/keys :req-un [::fqdns ::app-name ::ingress-name ::service-name ::service-port]
|
||||||
:opt-un [::issuer ::cert-name]))
|
:opt-un [::issuer ::cert-name]))
|
||||||
|
|
||||||
(def certificate? (s/keys :req-un [::fqdns ::cert-name]
|
(def certificate? (s/keys :req-un [::fqdns ::app-name ::cert-name]
|
||||||
:opt-un [::issuer]))
|
:opt-un [::issuer]))
|
||||||
|
|
||||||
#?(:cljs
|
#?(:cljs
|
||||||
|
@ -32,48 +33,51 @@
|
||||||
"ingress/https-ingress.yaml" (rc/inline "ingress/https-ingress.yaml")
|
"ingress/https-ingress.yaml" (rc/inline "ingress/https-ingress.yaml")
|
||||||
(throw (js/Error. "Undefined Resource!")))))
|
(throw (js/Error. "Undefined Resource!")))))
|
||||||
|
|
||||||
|
; TODO: Review jem 2022/10/26: generalize!
|
||||||
#?(:cljs
|
#?(:cljs
|
||||||
(defmethod yaml/load-as-edn :ingress [resource-name]
|
(defmethod yaml/load-as-edn :ingress [resource-name]
|
||||||
(yaml/from-string (yaml/load-resource resource-name))))
|
(yaml/from-string (yaml/load-resource resource-name))))
|
||||||
|
|
||||||
(defn-spec generate-host-rule pred/map-or-seq?
|
(defn-spec generate-host-rule pred/map-or-seq?
|
||||||
[service-name ::service-name
|
[service-name ::service-name
|
||||||
service-port ::service-port
|
service-port ::service-port
|
||||||
fqdn pred/fqdn-string?]
|
fqdn pred/fqdn-string?]
|
||||||
(->
|
(->
|
||||||
(yaml/load-as-edn "ingress/host-rule.yaml")
|
(yaml/load-as-edn "ingress/host-rule.yaml")
|
||||||
(cm/replace-all-matching-values-by-new-value "FQDN" fqdn)
|
(cm/replace-all-matching-values-by-new-value "FQDN" fqdn)
|
||||||
(cm/replace-all-matching-values-by-new-value "SERVICE_PORT" service-port)
|
(cm/replace-all-matching-values-by-new-value "SERVICE_PORT" service-port)
|
||||||
(cm/replace-all-matching-values-by-new-value "SERVICE_NAME" service-name)))
|
(cm/replace-all-matching-values-by-new-value "SERVICE_NAME" service-name)))
|
||||||
|
|
||||||
(defn-spec generate-http-ingress pred/map-or-seq?
|
(defn-spec generate-http-ingress pred/map-or-seq?
|
||||||
[config ingress?]
|
[config ingress?]
|
||||||
(let [{:keys [ingress-name service-name service-port fqdns]} config]
|
(let [{:keys [ingress-name service-name service-port fqdns app-name]} config]
|
||||||
(->
|
(->
|
||||||
(yaml/load-as-edn "ingress/http-ingress.yaml")
|
(yaml/load-as-edn "ingress/http-ingress.yaml")
|
||||||
(assoc-in [:metadata :name] ingress-name)
|
(assoc-in [:metadata :name] ingress-name)
|
||||||
|
(assoc-in [:metadata :labels :app.kubernetes.part-of] app-name)
|
||||||
(assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns)))))
|
(assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns)))))
|
||||||
|
|
||||||
(defn-spec generate-https-ingress pred/map-or-seq?
|
(defn-spec generate-https-ingress pred/map-or-seq?
|
||||||
[config ingress?]
|
[config ingress?]
|
||||||
(let [{:keys [ingress-name cert-name service-name service-port fqdns]} config]
|
(let [{:keys [ingress-name cert-name service-name service-port fqdns app-name]} config]
|
||||||
(->
|
(->
|
||||||
(yaml/load-as-edn "ingress/https-ingress.yaml")
|
(yaml/load-as-edn "ingress/https-ingress.yaml")
|
||||||
(assoc-in [:metadata :name] ingress-name)
|
(assoc-in [:metadata :name] ingress-name)
|
||||||
|
(assoc-in [:metadata :labels :app.kubernetes.part-of] app-name)
|
||||||
(assoc-in [:spec :tls 0 :secretName] cert-name)
|
(assoc-in [:spec :tls 0 :secretName] cert-name)
|
||||||
(assoc-in [:spec :tls 0 :hosts] fqdns)
|
(assoc-in [:spec :tls 0 :hosts] fqdns)
|
||||||
(assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns)))))
|
(assoc-in [:spec :rules] (mapv (partial generate-host-rule service-name service-port) fqdns)))))
|
||||||
|
|
||||||
(defn-spec generate-certificate pred/map-or-seq?
|
(defn-spec generate-certificate pred/map-or-seq?
|
||||||
[config certificate?]
|
[config certificate?]
|
||||||
(let [{:keys [cert-name issuer fqdns]
|
(let [{:keys [cert-name issuer fqdns app-name]
|
||||||
:or {issuer "staging"}} config
|
:or {issuer "staging"}} config
|
||||||
letsencrypt-issuer (name issuer)]
|
letsencrypt-issuer (name issuer)]
|
||||||
(->
|
(->
|
||||||
(yaml/load-as-edn "ingress/certificate.yaml")
|
(yaml/load-as-edn "ingress/certificate.yaml")
|
||||||
(assoc-in [:metadata :name] cert-name)
|
(assoc-in [:metadata :name] cert-name)
|
||||||
|
(assoc-in [:metadata :labels :app.kubernetes.part-of] app-name)
|
||||||
(assoc-in [:spec :secretName] cert-name)
|
(assoc-in [:spec :secretName] cert-name)
|
||||||
(assoc-in [:spec :commonName] (first fqdns))
|
(assoc-in [:spec :commonName] (first fqdns))
|
||||||
(assoc-in [:spec :dnsNames] fqdns)
|
(assoc-in [:spec :dnsNames] fqdns)
|
||||||
(assoc-in [:spec :issuerRef :name] letsencrypt-issuer))))
|
(assoc-in [:spec :issuerRef :name] letsencrypt-issuer))))
|
||||||
|
|
|
@ -2,6 +2,8 @@ apiVersion: cert-manager.io/v1
|
||||||
kind: Certificate
|
kind: Certificate
|
||||||
metadata:
|
metadata:
|
||||||
name: c4k-common-cert
|
name: c4k-common-cert
|
||||||
|
labels:
|
||||||
|
app.kubernetes.part-of: c4k-common-app
|
||||||
namespace: default
|
namespace: default
|
||||||
spec:
|
spec:
|
||||||
secretName: c4k-common-cert
|
secretName: c4k-common-cert
|
||||||
|
|
|
@ -3,6 +3,8 @@ kind: Ingress
|
||||||
metadata:
|
metadata:
|
||||||
name: c4k-common-http-ingress
|
name: c4k-common-http-ingress
|
||||||
namespace: default
|
namespace: default
|
||||||
|
labels:
|
||||||
|
app.kubernetes.part-of: c4k-common-app
|
||||||
annotations:
|
annotations:
|
||||||
traefik.ingress.kubernetes.io/router.entrypoints: web
|
traefik.ingress.kubernetes.io/router.entrypoints: web
|
||||||
traefik.ingress.kubernetes.io/router.middlewares: default-redirect-https@kubernetescrd
|
traefik.ingress.kubernetes.io/router.middlewares: default-redirect-https@kubernetescrd
|
||||||
|
@ -13,7 +15,7 @@ spec:
|
||||||
paths:
|
paths:
|
||||||
- pathType: Prefix
|
- pathType: Prefix
|
||||||
path: "/"
|
path: "/"
|
||||||
backend:
|
backend: # TODO: Review jem 2022/10/26: wo backend as we should only do a redirect here ... ?
|
||||||
service:
|
service:
|
||||||
name: SERVICE_NAME
|
name: SERVICE_NAME
|
||||||
port:
|
port:
|
||||||
|
|
|
@ -3,6 +3,8 @@ kind: Ingress
|
||||||
metadata:
|
metadata:
|
||||||
name: c4k-common-https-ingress
|
name: c4k-common-https-ingress
|
||||||
namespace: default
|
namespace: default
|
||||||
|
labels:
|
||||||
|
app.kubernetes.part-of: c4k-common-app
|
||||||
annotations:
|
annotations:
|
||||||
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
||||||
traefik.ingress.kubernetes.io/router.tls: "true"
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
||||||
|
|
|
@ -1,4 +1,4 @@
|
||||||
(ns dda.c4k-common.ingress-test
|
(ns dda.c4k-common.ingress-cert-test
|
||||||
(:require
|
(:require
|
||||||
#?(:clj [clojure.test :refer [deftest is are testing run-tests]]
|
#?(:clj [clojure.test :refer [deftest is are testing run-tests]]
|
||||||
:cljs [cljs.test :refer-macros [deftest is are testing run-tests]])
|
:cljs [cljs.test :refer-macros [deftest is are testing run-tests]])
|
||||||
|
@ -28,11 +28,13 @@
|
||||||
:metadata
|
:metadata
|
||||||
{:name "test-io-http-ingress",
|
{:name "test-io-http-ingress",
|
||||||
:namespace "default",
|
:namespace "default",
|
||||||
|
:labels {:app.kubernetes.part-of "c4k-common-app"},
|
||||||
:annotations
|
:annotations
|
||||||
#:traefik.ingress.kubernetes.io{:router.entrypoints "web",
|
#:traefik.ingress.kubernetes.io{:router.entrypoints "web",
|
||||||
:router.middlewares "default-redirect-https@kubernetescrd"}}}
|
:router.middlewares "default-redirect-https@kubernetescrd"}}}
|
||||||
(dissoc (cut/generate-http-ingress
|
(dissoc (cut/generate-http-ingress
|
||||||
{:issuer "prod"
|
{:issuer "prod"
|
||||||
|
:app-name "c4k-common-app"
|
||||||
:service-name "myservice"
|
:service-name "myservice"
|
||||||
:service-port 3000
|
:service-port 3000
|
||||||
:ingress-name "test-io-http-ingress"
|
:ingress-name "test-io-http-ingress"
|
||||||
|
@ -53,6 +55,7 @@
|
||||||
(:spec (cut/generate-http-ingress
|
(:spec (cut/generate-http-ingress
|
||||||
{:issuer "prod"
|
{:issuer "prod"
|
||||||
:service-name "myservice"
|
:service-name "myservice"
|
||||||
|
:app-name "c4k-common-app"
|
||||||
:service-port 3000
|
:service-port 3000
|
||||||
:ingress-name "test-io-http-ingress"
|
:ingress-name "test-io-http-ingress"
|
||||||
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]})))))
|
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]})))))
|
||||||
|
@ -63,10 +66,12 @@
|
||||||
:metadata
|
:metadata
|
||||||
{:name "test-io-https-ingress",
|
{:name "test-io-https-ingress",
|
||||||
:namespace "default",
|
:namespace "default",
|
||||||
|
:labels {:app.kubernetes.part-of "c4k-common-app"},
|
||||||
:annotations #:traefik.ingress.kubernetes.io{:router.entrypoints "websecure", :router.tls "true"}}}
|
:annotations #:traefik.ingress.kubernetes.io{:router.entrypoints "websecure", :router.tls "true"}}}
|
||||||
(dissoc (cut/generate-https-ingress
|
(dissoc (cut/generate-https-ingress
|
||||||
{:issuer "prod"
|
{:issuer "prod"
|
||||||
:service-name "test-io-service"
|
:service-name "test-io-service"
|
||||||
|
:app-name "c4k-common-app"
|
||||||
:service-port 80
|
:service-port 80
|
||||||
:ingress-name "test-io-https-ingress"
|
:ingress-name "test-io-https-ingress"
|
||||||
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]}) :spec)))
|
:fqdns ["test.de" "www.test.de" "test-it.de" "www.test-it.de"]}) :spec)))
|
||||||
|
@ -88,6 +93,7 @@
|
||||||
:http
|
:http
|
||||||
{:paths [{:pathType "Prefix", :path "/", :backend {:service {:name "test-io-service", :port {:number 80}}}}]}}]}
|
{:paths [{:pathType "Prefix", :path "/", :backend {:service {:name "test-io-service", :port {:number 80}}}}]}}]}
|
||||||
(:spec (cut/generate-https-ingress {:issuer "prod"
|
(:spec (cut/generate-https-ingress {:issuer "prod"
|
||||||
|
:app-name "c4k-common-app"
|
||||||
:service-name "test-io-service"
|
:service-name "test-io-service"
|
||||||
:service-port 80
|
:service-port 80
|
||||||
:ingress-name "test-io-https-ingress"
|
:ingress-name "test-io-https-ingress"
|
||||||
|
@ -97,7 +103,9 @@
|
||||||
(deftest should-generate-certificate
|
(deftest should-generate-certificate
|
||||||
(is (= {:apiVersion "cert-manager.io/v1",
|
(is (= {:apiVersion "cert-manager.io/v1",
|
||||||
:kind "Certificate",
|
:kind "Certificate",
|
||||||
:metadata {:name "test-io-cert", :namespace "default"},
|
:metadata {:name "test-io-cert",
|
||||||
|
:namespace "default",
|
||||||
|
:labels {:app.kubernetes.part-of "c4k-common-app"}},
|
||||||
:spec
|
:spec
|
||||||
{:secretName "test-io-cert",
|
{:secretName "test-io-cert",
|
||||||
:commonName "test.de",
|
:commonName "test.de",
|
||||||
|
@ -105,6 +113,7 @@
|
||||||
:renewBefore "360h",
|
:renewBefore "360h",
|
||||||
:dnsNames ["test.de" "test.org" "www.test.de" "www.test.org"],
|
:dnsNames ["test.de" "test.org" "www.test.de" "www.test.org"],
|
||||||
:issuerRef {:name "prod", :kind "ClusterIssuer"}}}
|
:issuerRef {:name "prod", :kind "ClusterIssuer"}}}
|
||||||
(cut/generate-certificate {:fqdns ["test.de" "test.org" "www.test.de" "www.test.org"]
|
(cut/generate-certificate {:fqdns ["test.de" "test.org" "www.test.de" "www.test.org"]
|
||||||
:cert-name "test-io-cert"
|
:app-name "c4k-common-app"
|
||||||
:issuer "prod"}))))
|
:cert-name "test-io-cert"
|
||||||
|
:issuer "prod"}))))
|
Loading…
Reference in a new issue