♻️ emqx

This commit is contained in:
auricom
2022-09-14 10:53:37 +02:00
parent faf2621b75
commit 19fa708f8c
4 changed files with 51 additions and 21 deletions

View File

@@ -3,56 +3,55 @@ apiVersion: helm.toolkit.fluxcd.io/v2beta1
kind: HelmRelease
metadata:
name: emqx
namespace: home-automation
namespace: default
spec:
interval: 5m
interval: 15m
chart:
spec:
# renovate: registryUrl=https://repos.emqx.io/charts
chart: emqx
version: 5.0.3
sourceRef:
kind: HelmRepository
name: emqx-charts
namespace: flux-system
interval: 5m
install:
createNamespace: true
remediation:
retries: 5
upgrade:
remediation:
retries: 5
values:
image:
repository: public.ecr.aws/emqx/emqx
replicaCount: 3
recreatePods: true
emqxConfig:
EMQX_ALLOW_ANONYMOUS: "false"
EMQX_ADMIN_PASSWORD: "${SECRET_EMQX_ADMIN_PASSWORD}"
EMQX_AUTH__MNESIA__PASSWORD_HASH: plain
EMQX_AUTH__USER__1__USERNAME: "${SECRET_MQTT_USERNAME}"
EMQX_AUTH__USER__1__PASSWORD: "${SECRET_MQTT_PASSWORD}"
service:
annotations:
prometheus.io/probe: "true"
prometheus.io/protocol: tcp
type: LoadBalancer
externalIPs:
- ${CLUSTER_LB_EMQX}
externalTrafficPolicy: Local
ingress:
dashboard:
enabled: true
ingressClassName: nginx
path: /
hosts:
- &host "emqx.${SECRET_CLUSTER_DOMAIN}"
- &host "{{ .Release.Name }}.${SECRET_CLUSTER_DOMAIN}"
tls:
- hosts:
- *host
metrics:
enabled: false
persistence:
enabled: true
storageClass: ceph-block
size: 100Mi
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
@@ -62,13 +61,16 @@ spec:
matchExpressions:
- key: app.kubernetes.io/name
operator: In
values:
- emqx
values: ["emqx"]
topologyKey: kubernetes.io/hostname
resources:
requests:
cpu: 100m
memory: 150Mi
limits:
memory: 512Mi
valuesFrom:
- targetPath: emqxConfig.EMQX_DASHBOARD__DEFAULT_PASSWORD
kind: Secret
name: emqx-config
valuesKey: admin_password

View File

@@ -1,4 +1,5 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- secret.sops.yaml
- helm-release.yaml

View File

@@ -0,0 +1,28 @@
kind: Secret
apiVersion: v1
type: Opaque
metadata:
name: emqx-config
namespace: default
stringData:
admin_password: ENC[AES256_GCM,data:5CgeNci9Mr9bhHLG/cl9yajr02CInvng,iv:tzU2NnmprFiVfnxgXP8y+o2wgwooaWVpvq6+fKodLC8=,tag:MkDFv5wOn4B6yWUMfivQGA==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1hhurqwmfvl9m3vh3hk8urulfzcdsrep2ax2neazqt435yhpamu3qj20asg
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBvb3RQOTVNN0VzdElJSGRY
bytDQ045bnRMY2RGSmEvTE9jQkN4MTQrZUhnCnZ0TjF5ZTU2bWtJNzVGRXdqV0lP
RGtuaUVkZlluUjlsd0lvZ0ZuRE5ocEUKLS0tIGxsTjJpc0JEeUhxSjF6MU5mSlli
bXpSSjd3YU5hRXFKdnhVcTFKTzRqZzQKlFvt9rCRt+1EviAtZxaQVVwAEt300456
KDHW7U58DUO3TmzTG47/iLj7AxIgCQKUjgaU6FoiQ/DZLaVCloyWEA==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-09-14T08:51:36Z"
mac: ENC[AES256_GCM,data:cwjeMMjPMPF2J0cc14XcQANFnhF59445engaEJAufIi8CH6rNvqzW/7fx6KqRIgeRMoNVInd5izn+rQKAvpLCFjsntpjvihE9AOIEsxHYkZ7S6wxzDtffeEDMKPq9ybemkRkqUUWdIve2jZaFtsY5hndEmuWq+euvr4G3fqXeU4=,iv:ldP/x68he76ObwJ8dFuWL6+y87yTLsmkoABKFmmxVQY=,tag:COn18dD88/Oa7hYp8/bjdg==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3

View File

@@ -19,7 +19,6 @@ stringData:
SECRET_CLUSTER_OVH_CONSUMER_KEY: ENC[AES256_GCM,data:HwEaNSLEoON99KzgVLuDWxj8DPz1gz8tc3q/1hWJOvM=,iv:uTHCAT81Js9yQ/7iK90+elZzA0j6ia7AOWEufE1i/4k=,tag:D4tI50RyJz8o3n9hrrYz4Q==,type:str]
SECRET_EMAIL_DOMAIN: ENC[AES256_GCM,data:tggMEXyLi03dAorm,iv:tXHmWmm9wUIOyGXbHUagS0gl4cEW588XSvBIoNsADFw=,tag:69X+WZoj6CiI6mUJT01DzQ==,type:str]
SECRET_EMAIL_SMTP_USERNAME: ENC[AES256_GCM,data:U8UiC6SdBbX9JbpRglyXfofDzYf+LNY=,iv:BLqn6nWm+il2yxWBJgpjlLKp5/eVh8L9qSEfM9LzUEo=,tag:1+afhSVYeHTvzzBiTxP7Ew==,type:str]
SECRET_EMQX_ADMIN_PASSWORD: ENC[AES256_GCM,data:1TU2rUWjqHTX4a7P4L9cZSHUoO/OxrYS,iv:QUpEZs2nDNREOt915MSwMMVXAscC1rszIPRp4F/Slig=,tag:DN91F66rvha5TjMB/ZHGFQ==,type:str]
SECRET_GITEA_ADMIN_EMAIL: ENC[AES256_GCM,data:IJiZAgExGAUcYW1L8jW0m2zr+hZL,iv:T+T9AM5wYqNoWKlDVDpsmxf4gvYSsLHwSoxxFAZfiuU=,tag:QeL6xFPsgxgBjMb79zrWZw==,type:str]
SECRET_GITEA_ADMIN_PASSWORD: ENC[AES256_GCM,data:w1BcZzMeLqEMVFdX94c=,iv:bc4IaH9YXvRQTW38Rb1tySKx9/1npWtqI2DtS0y/p3w=,tag:X3hyHEhbGNJcYaH2yWMQNQ==,type:str]
SECRET_GITEA_API_TOKEN: ENC[AES256_GCM,data:Xsk9tJLyy6LaoGdIhIQ0rrbu4qREg5fKWJ0KDp7f4qPme7Q1Iha7YA==,iv:uHcaLAaQ/l737UMTzjX3okEAba7gxrowMDu/GO98FnM=,tag:4rKcU+z1sqnDcZoZ+9Zqxg==,type:str]
@@ -79,8 +78,8 @@ sops:
WG82VkdBMlNnRzBySFQzMk41cEtXSlEKBqOmq9UpO61C85+pj0ibdT31y4pmFsbm
pTi4N0vv81kcf4ilqBU5h1gudNCb42Q2iL0eGNR4e3JzH4iaNsvnEg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2022-09-13T22:56:56Z"
mac: ENC[AES256_GCM,data:lLQYL2TJ4KxZhviBd3Co2WGQPy09kyZF5a0oMR2QGud8JPqbSUzxNspu4n1cxJRuF7PAfsb3FWoeal/DmjTP06grqj1RNwSpNQfCBKb6bi1/9MONkA1PKUf1fzoZK+s8h8nTK0nknm6nMk/sSJg+Sgz/Zuy8rt/CuJgYEVVGb8w=,iv:VP5rnNNBZjGkTXOQfXcV8zLKcf9sjVwTJ+44K8Rmdgw=,tag:zukSR3nXrWiDlo67EKgsPg==,type:str]
lastmodified: "2022-09-14T08:46:49Z"
mac: ENC[AES256_GCM,data:V937qTqC7tg+sR7RbR1MSZCnXzfT1Xwzq0XTjJKh8rJEYHx8MHHgw70Tjz1aFfDGBvFn2Cokom27lTZTU+zsEwj6Mz+ulf8WNDlQpmScz24kwHHEPJAJExs1RmL2QiXn3G9YqCHXrJDEzPrbYQn2Kf4QtM1ED36UJrpxSufHTJg=,iv:rUfXzDTGOnpg7PA3Z3JGl3AW9s9vUDScTo970pPsEG8=,tag:C5CK17hIuIZbLJoiXbn/iA==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.7.3