♻️ emqx

This commit is contained in:
auricom
2022-09-14 10:53:37 +02:00
parent faf2621b75
commit 19fa708f8c
4 changed files with 51 additions and 21 deletions

View File

@@ -3,56 +3,55 @@ apiVersion: helm.toolkit.fluxcd.io/v2beta1
kind: HelmRelease
metadata:
name: emqx
namespace: home-automation
namespace: default
spec:
interval: 5m
interval: 15m
chart:
spec:
# renovate: registryUrl=https://repos.emqx.io/charts
chart: emqx
version: 5.0.3
sourceRef:
kind: HelmRepository
name: emqx-charts
namespace: flux-system
interval: 5m
install:
createNamespace: true
remediation:
retries: 5
upgrade:
remediation:
retries: 5
values:
image:
repository: public.ecr.aws/emqx/emqx
replicaCount: 3
recreatePods: true
emqxConfig:
EMQX_ALLOW_ANONYMOUS: "false"
EMQX_ADMIN_PASSWORD: "${SECRET_EMQX_ADMIN_PASSWORD}"
EMQX_AUTH__MNESIA__PASSWORD_HASH: plain
EMQX_AUTH__USER__1__USERNAME: "${SECRET_MQTT_USERNAME}"
EMQX_AUTH__USER__1__PASSWORD: "${SECRET_MQTT_PASSWORD}"
service:
annotations:
prometheus.io/probe: "true"
prometheus.io/protocol: tcp
type: LoadBalancer
externalIPs:
- ${CLUSTER_LB_EMQX}
externalTrafficPolicy: Local
ingress:
dashboard:
enabled: true
ingressClassName: nginx
path: /
hosts:
- &host "emqx.${SECRET_CLUSTER_DOMAIN}"
- &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
tls:
- hosts:
- *host
metrics:
enabled: false
persistence:
enabled: true
storageClass: ceph-block
size: 100Mi
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
@@ -62,13 +61,16 @@ spec:
matchExpressions:
- key: app.kubernetes.io/name
operator: In
values:
- emqx
values: ["emqx"]
topologyKey: kubernetes.io/hostname
resources:
requests:
cpu: 100m
memory: 150Mi
limits:
memory: 512Mi
valuesFrom:
- targetPath: emqxConfig.EMQX_DASHBOARD__DEFAULT_PASSWORD
kind: Secret
name: emqx-config
valuesKey: admin_password

View File

@@ -1,4 +1,5 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- secret.sops.yaml
- helm-release.yaml

View File

@@ -0,0 +1,28 @@
kind: Secret
apiVersion: v1
type: Opaque
metadata:
name: emqx-config
namespace: default
stringData:
admin_password: ENC[AES256_GCM,data:5CgeNci9Mr9bhHLG/cl9yajr02CInvng,iv:tzU2NnmprFiVfnxgXP8y+o2wgwooaWVpvq6+fKodLC8=,tag:MkDFv5wOn4B6yWUMfivQGA==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBvb3RQOTVNN0VzdElJSGRY
bytDQ045bnRMY2RGSmEvTE9jQkN4MTQrZUhnCnZ0TjF5ZTU2bWtJNzVGRXdqV0lP
RGtuaUVkZlluUjlsd0lvZ0ZuRE5ocEUKLS0tIGxsTjJpc0JEeUhxSjF6MU5mSlli
bXpSSjd3YU5hRXFKdnhVcTFKTzRqZzQKlFvt9rCRt+1EviAtZxaQVVwAEt300456
KDHW7U58DUO3TmzTG47/iLj7AxIgCQKUjgaU6FoiQ/DZLaVCloyWEA==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-09-14T08:51:36Z"
mac: ENC[AES256_GCM,data:cwjeMMjPMPF2J0cc14XcQANFnhF59445engaEJAufIi8CH6rNvqzW/7fx6KqRIgeRMoNVInd5izn+rQKAvpLCFjsntpjvihE9AOIEsxHYkZ7S6wxzDtffeEDMKPq9ybemkRkqUUWdIve2jZaFtsY5hndEmuWq+euvr4G3fqXeU4=,iv:ldP/x68he76ObwJ8dFuWL6+y87yTLsmkoABKFmmxVQY=,tag:COn18dD88/Oa7hYp8/bjdg==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3