mastodon.yaml 62 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053
  1. ---
  2. # Source: mastodon/charts/minio/templates/serviceaccount.yaml
  3. apiVersion: v1
  4. kind: ServiceAccount
  5. metadata:
  6. name: mastodon-minio
  7. namespace: "mastodon"
  8. labels:
  9. app.kubernetes.io/name: minio
  10. helm.sh/chart: minio-12.0.0
  11. app.kubernetes.io/instance: mastodon
  12. app.kubernetes.io/managed-by: Helm
  13. automountServiceAccountToken: true
  14. secrets:
  15. - name: mastodon-minio
  16. ---
  17. # Source: mastodon/charts/redis/templates/serviceaccount.yaml
  18. apiVersion: v1
  19. kind: ServiceAccount
  20. automountServiceAccountToken: true
  21. metadata:
  22. name: mastodon-redis
  23. namespace: "mastodon"
  24. labels:
  25. app.kubernetes.io/name: redis
  26. helm.sh/chart: redis-17.4.3
  27. app.kubernetes.io/instance: mastodon
  28. app.kubernetes.io/managed-by: Helm
  29. ---
  30. # Source: mastodon/templates/service-account.yaml
  31. apiVersion: v1
  32. kind: ServiceAccount
  33. metadata:
  34. name: mastodon
  35. namespace: "mastodon"
  36. labels:
  37. app.kubernetes.io/name: mastodon
  38. helm.sh/chart: mastodon-1.0.1
  39. app.kubernetes.io/instance: mastodon
  40. app.kubernetes.io/managed-by: Helm
  41. app.kubernetes.io/part-of: mastodon
  42. automountServiceAccountToken: true
  43. ---
  44. # Source: mastodon/charts/minio/templates/secrets.yaml
  45. apiVersion: v1
  46. kind: Secret
  47. metadata:
  48. name: mastodon-minio
  49. namespace: "mastodon"
  50. labels:
  51. app.kubernetes.io/name: minio
  52. helm.sh/chart: minio-12.0.0
  53. app.kubernetes.io/instance: mastodon
  54. app.kubernetes.io/managed-by: Helm
  55. type: Opaque
  56. data:
  57. root-user: "YWRtaW4="
  58. root-password: "eEdlaHhqOHV5Zw=="
  59. key.json: ""
  60. ---
  61. # Source: mastodon/charts/postgresql/templates/secrets.yaml
  62. apiVersion: v1
  63. kind: Secret
  64. metadata:
  65. name: mastodon-postgresql
  66. namespace: "mastodon"
  67. labels:
  68. app.kubernetes.io/name: postgresql
  69. helm.sh/chart: postgresql-12.1.9
  70. app.kubernetes.io/instance: mastodon
  71. app.kubernetes.io/managed-by: Helm
  72. type: Opaque
  73. data:
  74. postgres-password: "NU04SUJUTVliRA=="
  75. password: "aFdZaWNOUHlvTA=="
  76. # We don't auto-generate LDAP password when it's not provided as we do for other passwords
  77. ---
  78. # Source: mastodon/charts/redis/templates/secret.yaml
  79. apiVersion: v1
  80. kind: Secret
  81. metadata:
  82. name: mastodon-redis
  83. namespace: "mastodon"
  84. labels:
  85. app.kubernetes.io/name: redis
  86. helm.sh/chart: redis-17.4.3
  87. app.kubernetes.io/instance: mastodon
  88. app.kubernetes.io/managed-by: Helm
  89. type: Opaque
  90. data:
  91. redis-password: "RlVCU09tRVJqVg=="
  92. ---
  93. # Source: mastodon/templates/default-secret.yaml
  94. apiVersion: v1
  95. kind: Secret
  96. metadata:
  97. name: mastodon-default
  98. namespace: "mastodon"
  99. labels:
  100. app.kubernetes.io/name: mastodon
  101. helm.sh/chart: mastodon-1.0.1
  102. app.kubernetes.io/instance: mastodon
  103. app.kubernetes.io/managed-by: Helm
  104. app.kubernetes.io/part-of: mastodon
  105. data:
  106. MASTODON_ADMIN_PASSWORD: "Mk9yRFZWUEx0dw=="
  107. SECRET_KEY_BASE: "RElKYjJETFlWYg=="
  108. OTP_SECRET: "eUZoU1pTclAyRg=="
  109. ---
  110. # Source: mastodon/charts/minio/templates/provisioning-configmap.yaml
  111. apiVersion: v1
  112. kind: ConfigMap
  113. metadata:
  114. name: mastodon-minio-provisioning
  115. namespace: "mastodon"
  116. labels:
  117. app.kubernetes.io/name: minio
  118. helm.sh/chart: minio-12.0.0
  119. app.kubernetes.io/instance: mastodon
  120. app.kubernetes.io/managed-by: Helm
  121. app.kubernetes.io/component: minio-provisioning
  122. data:
  123. ---
  124. # Source: mastodon/charts/redis/templates/configmap.yaml
  125. apiVersion: v1
  126. kind: ConfigMap
  127. metadata:
  128. name: mastodon-redis-configuration
  129. namespace: "mastodon"
  130. labels:
  131. app.kubernetes.io/name: redis
  132. helm.sh/chart: redis-17.4.3
  133. app.kubernetes.io/instance: mastodon
  134. app.kubernetes.io/managed-by: Helm
  135. data:
  136. redis.conf: |-
  137. # User-supplied common configuration:
  138. # Enable AOF https://redis.io/topics/persistence#append-only-file
  139. appendonly yes
  140. # Disable RDB persistence, AOF persistence already enabled.
  141. save ""
  142. # End of common configuration
  143. master.conf: |-
  144. dir /data
  145. # User-supplied master configuration:
  146. rename-command FLUSHDB ""
  147. rename-command FLUSHALL ""
  148. # End of master configuration
  149. replica.conf: |-
  150. dir /data
  151. # User-supplied replica configuration:
  152. rename-command FLUSHDB ""
  153. rename-command FLUSHALL ""
  154. # End of replica configuration
  155. ---
  156. # Source: mastodon/charts/redis/templates/health-configmap.yaml
  157. apiVersion: v1
  158. kind: ConfigMap
  159. metadata:
  160. name: mastodon-redis-health
  161. namespace: "mastodon"
  162. labels:
  163. app.kubernetes.io/name: redis
  164. helm.sh/chart: redis-17.4.3
  165. app.kubernetes.io/instance: mastodon
  166. app.kubernetes.io/managed-by: Helm
  167. data:
  168. ping_readiness_local.sh: |-
  169. #!/bin/bash
  170. [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")"
  171. [[ -n "$REDIS_PASSWORD" ]] && export REDISCLI_AUTH="$REDIS_PASSWORD"
  172. response=$(
  173. timeout -s 3 $1 \
  174. redis-cli \
  175. -h localhost \
  176. -p $REDIS_PORT \
  177. ping
  178. )
  179. if [ "$?" -eq "124" ]; then
  180. echo "Timed out"
  181. exit 1
  182. fi
  183. if [ "$response" != "PONG" ]; then
  184. echo "$response"
  185. exit 1
  186. fi
  187. ping_liveness_local.sh: |-
  188. #!/bin/bash
  189. [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")"
  190. [[ -n "$REDIS_PASSWORD" ]] && export REDISCLI_AUTH="$REDIS_PASSWORD"
  191. response=$(
  192. timeout -s 3 $1 \
  193. redis-cli \
  194. -h localhost \
  195. -p $REDIS_PORT \
  196. ping
  197. )
  198. if [ "$?" -eq "124" ]; then
  199. echo "Timed out"
  200. exit 1
  201. fi
  202. responseFirstWord=$(echo $response | head -n1 | awk '{print $1;}')
  203. if [ "$response" != "PONG" ] && [ "$responseFirstWord" != "LOADING" ] && [ "$responseFirstWord" != "MASTERDOWN" ]; then
  204. echo "$response"
  205. exit 1
  206. fi
  207. ping_readiness_master.sh: |-
  208. #!/bin/bash
  209. [[ -f $REDIS_MASTER_PASSWORD_FILE ]] && export REDIS_MASTER_PASSWORD="$(< "${REDIS_MASTER_PASSWORD_FILE}")"
  210. [[ -n "$REDIS_MASTER_PASSWORD" ]] && export REDISCLI_AUTH="$REDIS_MASTER_PASSWORD"
  211. response=$(
  212. timeout -s 3 $1 \
  213. redis-cli \
  214. -h $REDIS_MASTER_HOST \
  215. -p $REDIS_MASTER_PORT_NUMBER \
  216. ping
  217. )
  218. if [ "$?" -eq "124" ]; then
  219. echo "Timed out"
  220. exit 1
  221. fi
  222. if [ "$response" != "PONG" ]; then
  223. echo "$response"
  224. exit 1
  225. fi
  226. ping_liveness_master.sh: |-
  227. #!/bin/bash
  228. [[ -f $REDIS_MASTER_PASSWORD_FILE ]] && export REDIS_MASTER_PASSWORD="$(< "${REDIS_MASTER_PASSWORD_FILE}")"
  229. [[ -n "$REDIS_MASTER_PASSWORD" ]] && export REDISCLI_AUTH="$REDIS_MASTER_PASSWORD"
  230. response=$(
  231. timeout -s 3 $1 \
  232. redis-cli \
  233. -h $REDIS_MASTER_HOST \
  234. -p $REDIS_MASTER_PORT_NUMBER \
  235. ping
  236. )
  237. if [ "$?" -eq "124" ]; then
  238. echo "Timed out"
  239. exit 1
  240. fi
  241. responseFirstWord=$(echo $response | head -n1 | awk '{print $1;}')
  242. if [ "$response" != "PONG" ] && [ "$responseFirstWord" != "LOADING" ]; then
  243. echo "$response"
  244. exit 1
  245. fi
  246. ping_readiness_local_and_master.sh: |-
  247. script_dir="$(dirname "$0")"
  248. exit_status=0
  249. "$script_dir/ping_readiness_local.sh" $1 || exit_status=$?
  250. "$script_dir/ping_readiness_master.sh" $1 || exit_status=$?
  251. exit $exit_status
  252. ping_liveness_local_and_master.sh: |-
  253. script_dir="$(dirname "$0")"
  254. exit_status=0
  255. "$script_dir/ping_liveness_local.sh" $1 || exit_status=$?
  256. "$script_dir/ping_liveness_master.sh" $1 || exit_status=$?
  257. exit $exit_status
  258. ---
  259. # Source: mastodon/charts/redis/templates/scripts-configmap.yaml
  260. apiVersion: v1
  261. kind: ConfigMap
  262. metadata:
  263. name: mastodon-redis-scripts
  264. namespace: "mastodon"
  265. labels:
  266. app.kubernetes.io/name: redis
  267. helm.sh/chart: redis-17.4.3
  268. app.kubernetes.io/instance: mastodon
  269. app.kubernetes.io/managed-by: Helm
  270. data:
  271. start-master.sh: |
  272. #!/bin/bash
  273. [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")"
  274. if [[ -f /opt/bitnami/redis/mounted-etc/master.conf ]];then
  275. cp /opt/bitnami/redis/mounted-etc/master.conf /opt/bitnami/redis/etc/master.conf
  276. fi
  277. if [[ -f /opt/bitnami/redis/mounted-etc/redis.conf ]];then
  278. cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf
  279. fi
  280. ARGS=("--port" "${REDIS_PORT}")
  281. ARGS+=("--requirepass" "${REDIS_PASSWORD}")
  282. ARGS+=("--masterauth" "${REDIS_PASSWORD}")
  283. ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf")
  284. ARGS+=("--include" "/opt/bitnami/redis/etc/master.conf")
  285. exec redis-server "${ARGS[@]}"
  286. ---
  287. # Source: mastodon/templates/apache-configmap.yaml
  288. apiVersion: v1
  289. kind: ConfigMap
  290. metadata:
  291. name: mastodon-apache-mastodon-vhost
  292. namespace: "mastodon"
  293. labels:
  294. app.kubernetes.io/name: mastodon
  295. helm.sh/chart: mastodon-1.0.1
  296. app.kubernetes.io/instance: mastodon
  297. app.kubernetes.io/managed-by: Helm
  298. app.kubernetes.io/part-of: mastodon
  299. data:
  300. mastodon-vhost.conf: |-
  301. <VirtualHost VirtualHost 127.0.0.1:8080 _default_:8080>
  302. ServerName
  303. ServerAlias *
  304. <Location "/">
  305. ProxyPass http://mastodon-web:80/
  306. ProxyPassReverse
  307. Order allow,deny
  308. Allow from all
  309. </Location>
  310. <Location "/api/v1/streaming">
  311. # Streaming uses normal API calls and websockets. We used this configuration
  312. # based on https://stackoverflow.com/questions/27526281/websockets-and-apache-proxy-how-to-configure-mod-proxy-wstunnel
  313. RewriteEngine On
  314. RewriteCond %{HTTP:Upgrade} =websocket [NC]
  315. RewriteRule /api/(.*) ws://mastodon-streaming:80/api/$1 [P,L]
  316. RewriteCond %{HTTP:Upgrade} !=websocket [NC]
  317. RewriteRule /api/(.*) http://mastodon-streaming:80/api/$1 [P,L]
  318. ProxyPassReverse
  319. Order allow,deny
  320. Allow from all
  321. </Location>
  322. <Location "/s3storage">
  323. ProxyPass http://mastodon-minio:80/s3storage/
  324. ProxyPassReverse
  325. Order allow,deny
  326. Allow from all
  327. </Location>
  328. </VirtualHost>
  329. ---
  330. # Source: mastodon/templates/default-configmap.yaml
  331. apiVersion: v1
  332. kind: ConfigMap
  333. metadata:
  334. name: mastodon-default
  335. namespace: "mastodon"
  336. labels:
  337. app.kubernetes.io/name: mastodon
  338. helm.sh/chart: mastodon-1.0.1
  339. app.kubernetes.io/instance: mastodon
  340. app.kubernetes.io/managed-by: Helm
  341. app.kubernetes.io/part-of: mastodon
  342. data:
  343. MASTODON_ADMIN_USERNAME: "user"
  344. MASTODON_ADMIN_EMAIL: "user@changeme.com"
  345. DB_HOST: "mastodon-postgresql"
  346. DB_PORT: "5432"
  347. DB_NAME: "bitnami_mastodon"
  348. DB_USER: "bn_mastodon"
  349. ES_ENABLED: "true"
  350. ES_HOST: "mastodon-elasticsearch"
  351. ES_PORT: "9200"
  352. WEB_DOMAIN: ""
  353. STREAMING_API_BASE_URL: "ws://"
  354. REDIS_HOST: "mastodon-redis-master"
  355. REDIS_PORT: "6379"
  356. S3_ENABLED: "true"
  357. S3_BUCKET: "s3storage"
  358. S3_ENDPOINT: "http://mastodon-minio"
  359. S3_HOSTNAME: "mastodon-minio"
  360. S3_REGION: "us-east-1"
  361. S3_ALIAS_HOST: "/s3storage"
  362. S3_PROTOCOL: "http"
  363. ---
  364. # Source: mastodon/templates/init-job/init-job-configmap.yaml
  365. apiVersion: v1
  366. kind: ConfigMap
  367. metadata:
  368. name: mastodon-init-scripts
  369. namespace: "mastodon"
  370. labels:
  371. app.kubernetes.io/name: mastodon
  372. helm.sh/chart: mastodon-1.0.1
  373. app.kubernetes.io/instance: mastodon
  374. app.kubernetes.io/managed-by: Helm
  375. app.kubernetes.io/part-of: mastodon
  376. data:
  377. # All these operations require access to PostgreSQL (including Elasticsearch migration) and Redis. In order to avoid
  378. # potential race conditions we include them in the same script.
  379. migrate-and-create-admin.sh: |-
  380. #!/bin/bash
  381. set -o errexit
  382. set -o nounset
  383. set -o pipefail
  384. # Load libraries
  385. . /opt/bitnami/scripts/liblog.sh
  386. . /opt/bitnami/scripts/libos.sh
  387. . /opt/bitnami/scripts/libvalidations.sh
  388. . /opt/bitnami/scripts/libmastodon.sh
  389. # Load Mastodon environment variables
  390. . /opt/bitnami/scripts/mastodon-env.sh
  391. info "Migrating database"
  392. psql_connection_string="postgresql://${MASTODON_DATABASE_USERNAME}:${MASTODON_DATABASE_PASSWORD}@${MASTODON_DATABASE_HOST}:${MASTODON_DATABASE_PORT_NUMBER}/${MASTODON_DATABASE_NAME}"
  393. mastodon_wait_for_postgresql_connection "$psql_connection_string"
  394. mastodon_rake_execute db:migrate
  395. elasticsearch_connection_string="http://${MASTODON_ELASTICSEARCH_HOST}:${MASTODON_ELASTICSEARCH_PORT_NUMBER}"
  396. mastodon_wait_for_elasticsearch_connection "$elasticsearch_connection_string"
  397. info "Migrating Elasticsearch"
  398. mastodon_rake_execute chewy:upgrade
  399. mastodon_ensure_admin_user_exists
  400. precompile-assets.sh: |-
  401. #!/bin/bash
  402. set -o errexit
  403. set -o nounset
  404. set -o pipefail
  405. # Load libraries
  406. . /opt/bitnami/scripts/liblog.sh
  407. . /opt/bitnami/scripts/libos.sh
  408. . /opt/bitnami/scripts/libvalidations.sh
  409. . /opt/bitnami/scripts/libmastodon.sh
  410. # Load Mastodon environment variables
  411. . /opt/bitnami/scripts/mastodon-env.sh
  412. mastodon_wait_for_s3_connection "$MASTODON_S3_HOSTNAME" "$MASTODON_S3_PORT_NUMBER"
  413. info "Precompiling assets"
  414. mastodon_rake_execute assets:precompile
  415. ---
  416. # Source: mastodon/charts/minio/templates/pvc.yaml
  417. kind: PersistentVolumeClaim
  418. apiVersion: v1
  419. metadata:
  420. name: mastodon-minio
  421. namespace: "mastodon"
  422. labels:
  423. app.kubernetes.io/name: minio
  424. helm.sh/chart: minio-12.0.0
  425. app.kubernetes.io/instance: mastodon
  426. app.kubernetes.io/managed-by: Helm
  427. spec:
  428. accessModes:
  429. - "ReadWriteOnce"
  430. resources:
  431. requests:
  432. storage: "8Gi"
  433. ---
  434. # Source: mastodon/charts/apache/templates/svc.yaml
  435. apiVersion: v1
  436. kind: Service
  437. metadata:
  438. name: mastodon-apache
  439. namespace: "mastodon"
  440. labels:
  441. app.kubernetes.io/name: apache
  442. helm.sh/chart: apache-9.2.11
  443. app.kubernetes.io/instance: mastodon
  444. app.kubernetes.io/managed-by: Helm
  445. spec:
  446. type: LoadBalancer
  447. externalTrafficPolicy: "Cluster"
  448. loadBalancerSourceRanges: []
  449. sessionAffinity: None
  450. ports:
  451. - name: http
  452. port: 80
  453. targetPort: http
  454. - name: https
  455. port: 443
  456. targetPort: https
  457. selector:
  458. app.kubernetes.io/name: apache
  459. app.kubernetes.io/instance: mastodon
  460. ---
  461. # Source: mastodon/charts/elasticsearch/templates/coordinating/svc-headless.yaml
  462. apiVersion: v1
  463. kind: Service
  464. metadata:
  465. name: mastodon-elasticsearch-coordinating-hl
  466. namespace: "mastodon"
  467. labels:
  468. app.kubernetes.io/name: elasticsearch
  469. helm.sh/chart: elasticsearch-19.5.8
  470. app.kubernetes.io/instance: mastodon
  471. app.kubernetes.io/managed-by: Helm
  472. app.kubernetes.io/component: coordinating-only
  473. spec:
  474. type: ClusterIP
  475. publishNotReadyAddresses: true
  476. ports:
  477. - name: tcp-rest-api
  478. port: 9200
  479. targetPort: rest-api
  480. - name: tcp-transport
  481. port: 9300
  482. targetPort: transport
  483. selector:
  484. app.kubernetes.io/name: elasticsearch
  485. app.kubernetes.io/instance: mastodon
  486. app.kubernetes.io/component: coordinating-only
  487. ---
  488. # Source: mastodon/charts/elasticsearch/templates/data/svc-headless.yaml
  489. apiVersion: v1
  490. kind: Service
  491. metadata:
  492. name: mastodon-elasticsearch-data-hl
  493. namespace: "mastodon"
  494. labels:
  495. app.kubernetes.io/name: elasticsearch
  496. helm.sh/chart: elasticsearch-19.5.8
  497. app.kubernetes.io/instance: mastodon
  498. app.kubernetes.io/managed-by: Helm
  499. app.kubernetes.io/component: data
  500. spec:
  501. type: ClusterIP
  502. publishNotReadyAddresses: true
  503. ports:
  504. - name: tcp-rest-api
  505. port: 9200
  506. targetPort: rest-api
  507. - name: tcp-transport
  508. port: 9300
  509. targetPort: transport
  510. selector:
  511. app.kubernetes.io/name: elasticsearch
  512. app.kubernetes.io/instance: mastodon
  513. app.kubernetes.io/component: data
  514. ---
  515. # Source: mastodon/charts/elasticsearch/templates/ingest/svc-headless.yaml
  516. apiVersion: v1
  517. kind: Service
  518. metadata:
  519. name: mastodon-elasticsearch-ingest-hl
  520. namespace: "mastodon"
  521. labels:
  522. app.kubernetes.io/name: elasticsearch
  523. helm.sh/chart: elasticsearch-19.5.8
  524. app.kubernetes.io/instance: mastodon
  525. app.kubernetes.io/managed-by: Helm
  526. app.kubernetes.io/component: ingest
  527. spec:
  528. type: ClusterIP
  529. publishNotReadyAddresses: true
  530. ports:
  531. - name: tcp-rest-api
  532. port: 9200
  533. targetPort: rest-api
  534. - name: tcp-transport
  535. port: 9300
  536. targetPort: transport
  537. selector:
  538. app.kubernetes.io/name: elasticsearch
  539. app.kubernetes.io/instance: mastodon
  540. app.kubernetes.io/component: ingest
  541. ---
  542. # Source: mastodon/charts/elasticsearch/templates/master/svc-headless.yaml
  543. apiVersion: v1
  544. kind: Service
  545. metadata:
  546. name: mastodon-elasticsearch-master-hl
  547. namespace: "mastodon"
  548. labels:
  549. app.kubernetes.io/name: elasticsearch
  550. helm.sh/chart: elasticsearch-19.5.8
  551. app.kubernetes.io/instance: mastodon
  552. app.kubernetes.io/managed-by: Helm
  553. app.kubernetes.io/component: master
  554. spec:
  555. type: ClusterIP
  556. publishNotReadyAddresses: true
  557. ports:
  558. - name: tcp-rest-api
  559. port: 9200
  560. targetPort: rest-api
  561. - name: tcp-transport
  562. port: 9300
  563. targetPort: transport
  564. selector:
  565. app.kubernetes.io/name: elasticsearch
  566. app.kubernetes.io/instance: mastodon
  567. app.kubernetes.io/component: master
  568. ---
  569. # Source: mastodon/charts/elasticsearch/templates/service.yaml
  570. apiVersion: v1
  571. kind: Service
  572. metadata:
  573. name: mastodon-elasticsearch
  574. namespace: "mastodon"
  575. labels:
  576. app.kubernetes.io/name: elasticsearch
  577. helm.sh/chart: elasticsearch-19.5.8
  578. app.kubernetes.io/instance: mastodon
  579. app.kubernetes.io/managed-by: Helm
  580. app.kubernetes.io/component: coordinating-only
  581. annotations:
  582. spec:
  583. type: ClusterIP
  584. sessionAffinity: None
  585. ports:
  586. - name: tcp-rest-api
  587. port: 9200
  588. targetPort: rest-api
  589. nodePort: null
  590. - name: tcp-transport
  591. port: 9300
  592. nodePort: null
  593. selector:
  594. app.kubernetes.io/name: elasticsearch
  595. app.kubernetes.io/instance: mastodon
  596. app.kubernetes.io/component: coordinating-only
  597. ---
  598. # Source: mastodon/charts/minio/templates/service.yaml
  599. apiVersion: v1
  600. kind: Service
  601. metadata:
  602. name: mastodon-minio
  603. namespace: "mastodon"
  604. labels:
  605. app.kubernetes.io/name: minio
  606. helm.sh/chart: minio-12.0.0
  607. app.kubernetes.io/instance: mastodon
  608. app.kubernetes.io/managed-by: Helm
  609. spec:
  610. type: ClusterIP
  611. ports:
  612. - name: minio-api
  613. port: 80
  614. targetPort: minio-api
  615. nodePort: null
  616. - name: minio-console
  617. port: 9001
  618. targetPort: minio-console
  619. nodePort: null
  620. selector:
  621. app.kubernetes.io/name: minio
  622. app.kubernetes.io/instance: mastodon
  623. ---
  624. # Source: mastodon/charts/postgresql/templates/primary/svc-headless.yaml
  625. apiVersion: v1
  626. kind: Service
  627. metadata:
  628. name: mastodon-postgresql-hl
  629. namespace: "mastodon"
  630. labels:
  631. app.kubernetes.io/name: postgresql
  632. helm.sh/chart: postgresql-12.1.9
  633. app.kubernetes.io/instance: mastodon
  634. app.kubernetes.io/managed-by: Helm
  635. app.kubernetes.io/component: primary
  636. # Use this annotation in addition to the actual publishNotReadyAddresses
  637. # field below because the annotation will stop being respected soon but the
  638. # field is broken in some versions of Kubernetes:
  639. # https://github.com/kubernetes/kubernetes/issues/58662
  640. service.alpha.kubernetes.io/tolerate-unready-endpoints: "true"
  641. spec:
  642. type: ClusterIP
  643. clusterIP: None
  644. # We want all pods in the StatefulSet to have their addresses published for
  645. # the sake of the other Postgresql pods even before they're ready, since they
  646. # have to be able to talk to each other in order to become ready.
  647. publishNotReadyAddresses: true
  648. ports:
  649. - name: tcp-postgresql
  650. port: 5432
  651. targetPort: tcp-postgresql
  652. selector:
  653. app.kubernetes.io/name: postgresql
  654. app.kubernetes.io/instance: mastodon
  655. app.kubernetes.io/component: primary
  656. ---
  657. # Source: mastodon/charts/postgresql/templates/primary/svc.yaml
  658. apiVersion: v1
  659. kind: Service
  660. metadata:
  661. name: mastodon-postgresql
  662. namespace: "mastodon"
  663. labels:
  664. app.kubernetes.io/name: postgresql
  665. helm.sh/chart: postgresql-12.1.9
  666. app.kubernetes.io/instance: mastodon
  667. app.kubernetes.io/managed-by: Helm
  668. app.kubernetes.io/component: primary
  669. annotations:
  670. spec:
  671. type: ClusterIP
  672. sessionAffinity: None
  673. ports:
  674. - name: tcp-postgresql
  675. port: 5432
  676. targetPort: tcp-postgresql
  677. nodePort: null
  678. selector:
  679. app.kubernetes.io/name: postgresql
  680. app.kubernetes.io/instance: mastodon
  681. app.kubernetes.io/component: primary
  682. ---
  683. # Source: mastodon/charts/redis/templates/headless-svc.yaml
  684. apiVersion: v1
  685. kind: Service
  686. metadata:
  687. name: mastodon-redis-headless
  688. namespace: "mastodon"
  689. labels:
  690. app.kubernetes.io/name: redis
  691. helm.sh/chart: redis-17.4.3
  692. app.kubernetes.io/instance: mastodon
  693. app.kubernetes.io/managed-by: Helm
  694. annotations:
  695. spec:
  696. type: ClusterIP
  697. clusterIP: None
  698. ports:
  699. - name: tcp-redis
  700. port: 6379
  701. targetPort: redis
  702. selector:
  703. app.kubernetes.io/name: redis
  704. app.kubernetes.io/instance: mastodon
  705. ---
  706. # Source: mastodon/charts/redis/templates/master/service.yaml
  707. apiVersion: v1
  708. kind: Service
  709. metadata:
  710. name: mastodon-redis-master
  711. namespace: "mastodon"
  712. labels:
  713. app.kubernetes.io/name: redis
  714. helm.sh/chart: redis-17.4.3
  715. app.kubernetes.io/instance: mastodon
  716. app.kubernetes.io/managed-by: Helm
  717. app.kubernetes.io/component: master
  718. spec:
  719. type: ClusterIP
  720. sessionAffinity: None
  721. ports:
  722. - name: tcp-redis
  723. port: 6379
  724. targetPort: redis
  725. nodePort: null
  726. selector:
  727. app.kubernetes.io/name: redis
  728. app.kubernetes.io/instance: mastodon
  729. app.kubernetes.io/component: master
  730. ---
  731. # Source: mastodon/templates/streaming/service.yaml
  732. apiVersion: v1
  733. kind: Service
  734. metadata:
  735. name: mastodon-streaming
  736. namespace: "mastodon"
  737. labels:
  738. app.kubernetes.io/name: mastodon
  739. helm.sh/chart: mastodon-1.0.1
  740. app.kubernetes.io/instance: mastodon
  741. app.kubernetes.io/managed-by: Helm
  742. app.kubernetes.io/part-of: mastodon
  743. app.kubernetes.io/component: streaming
  744. spec:
  745. type: ClusterIP
  746. sessionAffinity: None
  747. ports:
  748. - name: http
  749. port: 80
  750. targetPort: http
  751. protocol: TCP
  752. nodePort: null
  753. selector:
  754. app.kubernetes.io/name: mastodon
  755. app.kubernetes.io/instance: mastodon
  756. app.kubernetes.io/component: streaming
  757. ---
  758. # Source: mastodon/templates/web/service.yaml
  759. apiVersion: v1
  760. kind: Service
  761. metadata:
  762. name: mastodon-web
  763. namespace: "mastodon"
  764. labels:
  765. app.kubernetes.io/name: mastodon
  766. helm.sh/chart: mastodon-1.0.1
  767. app.kubernetes.io/instance: mastodon
  768. app.kubernetes.io/managed-by: Helm
  769. app.kubernetes.io/part-of: mastodon
  770. app.kubernetes.io/component: web
  771. spec:
  772. type: ClusterIP
  773. sessionAffinity: None
  774. ports:
  775. - name: http
  776. port: 80
  777. protocol: TCP
  778. targetPort: http
  779. nodePort: null
  780. selector:
  781. app.kubernetes.io/name: mastodon
  782. app.kubernetes.io/instance: mastodon
  783. app.kubernetes.io/component: web
  784. ---
  785. # Source: mastodon/charts/apache/templates/deployment.yaml
  786. apiVersion: apps/v1
  787. kind: Deployment
  788. metadata:
  789. name: mastodon-apache
  790. namespace: "mastodon"
  791. labels:
  792. app.kubernetes.io/name: apache
  793. helm.sh/chart: apache-9.2.11
  794. app.kubernetes.io/instance: mastodon
  795. app.kubernetes.io/managed-by: Helm
  796. spec:
  797. selector:
  798. matchLabels:
  799. app.kubernetes.io/name: apache
  800. app.kubernetes.io/instance: mastodon
  801. replicas: 1
  802. strategy:
  803. type: RollingUpdate
  804. template:
  805. metadata:
  806. labels:
  807. app.kubernetes.io/name: apache
  808. helm.sh/chart: apache-9.2.11
  809. app.kubernetes.io/instance: mastodon
  810. app.kubernetes.io/managed-by: Helm
  811. spec:
  812. # yamllint disable rule:indentation
  813. hostAliases:
  814. - hostnames:
  815. - status.localhost
  816. ip: 127.0.0.1
  817. # yamllint enable rule:indentation
  818. priorityClassName: ""
  819. affinity:
  820. podAffinity:
  821. podAntiAffinity:
  822. preferredDuringSchedulingIgnoredDuringExecution:
  823. - podAffinityTerm:
  824. labelSelector:
  825. matchLabels:
  826. app.kubernetes.io/name: apache
  827. app.kubernetes.io/instance: mastodon
  828. topologyKey: kubernetes.io/hostname
  829. weight: 1
  830. nodeAffinity:
  831. securityContext:
  832. fsGroup: 1001
  833. containers:
  834. - name: apache
  835. image: docker.io/bitnami/apache:2.4.55-debian-11-r0
  836. imagePullPolicy: "IfNotPresent"
  837. securityContext:
  838. runAsNonRoot: true
  839. runAsUser: 1001
  840. env:
  841. - name: BITNAMI_DEBUG
  842. value: "false"
  843. - name: APACHE_HTTP_PORT_NUMBER
  844. value: "8080"
  845. - name: APACHE_HTTPS_PORT_NUMBER
  846. value: "8443"
  847. envFrom:
  848. ports:
  849. - name: http
  850. containerPort: 8080
  851. - name: https
  852. containerPort: 8443
  853. livenessProbe:
  854. httpGet:
  855. path: /api/v1/streaming/health
  856. port: http
  857. initialDelaySeconds: 180
  858. periodSeconds: 20
  859. timeoutSeconds: 5
  860. successThreshold: 1
  861. failureThreshold: 6
  862. readinessProbe:
  863. httpGet:
  864. path: /api/v1/streaming/health
  865. port: http
  866. initialDelaySeconds: 30
  867. periodSeconds: 10
  868. timeoutSeconds: 5
  869. successThreshold: 1
  870. failureThreshold: 6
  871. resources:
  872. limits: {}
  873. requests: {}
  874. volumeMounts:
  875. - name: vhosts
  876. mountPath: /vhosts
  877. volumes:
  878. - name: vhosts
  879. configMap:
  880. name: mastodon-apache-mastodon-vhost
  881. ---
  882. # Source: mastodon/charts/minio/templates/standalone/deployment.yaml
  883. apiVersion: apps/v1
  884. kind: Deployment
  885. metadata:
  886. name: mastodon-minio
  887. namespace: "mastodon"
  888. labels:
  889. app.kubernetes.io/name: minio
  890. helm.sh/chart: minio-12.0.0
  891. app.kubernetes.io/instance: mastodon
  892. app.kubernetes.io/managed-by: Helm
  893. spec:
  894. selector:
  895. matchLabels:
  896. app.kubernetes.io/name: minio
  897. app.kubernetes.io/instance: mastodon
  898. strategy:
  899. type: Recreate
  900. template:
  901. metadata:
  902. labels:
  903. app.kubernetes.io/name: minio
  904. helm.sh/chart: minio-12.0.0
  905. app.kubernetes.io/instance: mastodon
  906. app.kubernetes.io/managed-by: Helm
  907. annotations:
  908. checksum/credentials-secret: fda36e188bbd8e646a63850dfb0280dec380936aa1d6b927b773a2e70fed8c2e
  909. spec:
  910. serviceAccountName: mastodon-minio
  911. affinity:
  912. podAffinity:
  913. podAntiAffinity:
  914. preferredDuringSchedulingIgnoredDuringExecution:
  915. - podAffinityTerm:
  916. labelSelector:
  917. matchLabels:
  918. app.kubernetes.io/name: minio
  919. app.kubernetes.io/instance: mastodon
  920. topologyKey: kubernetes.io/hostname
  921. weight: 1
  922. nodeAffinity:
  923. securityContext:
  924. fsGroup: 1001
  925. containers:
  926. - name: minio
  927. image: docker.io/bitnami/minio:2023.1.12-debian-11-r0
  928. imagePullPolicy: "IfNotPresent"
  929. securityContext:
  930. runAsNonRoot: true
  931. runAsUser: 1001
  932. env:
  933. - name: BITNAMI_DEBUG
  934. value: "false"
  935. - name: MINIO_SCHEME
  936. value: "http"
  937. - name: MINIO_FORCE_NEW_KEYS
  938. value: "no"
  939. - name: MINIO_ROOT_USER
  940. valueFrom:
  941. secretKeyRef:
  942. name: mastodon-minio
  943. key: root-user
  944. - name: MINIO_ROOT_PASSWORD
  945. valueFrom:
  946. secretKeyRef:
  947. name: mastodon-minio
  948. key: root-password
  949. - name: MINIO_DEFAULT_BUCKETS
  950. value: s3storage
  951. - name: MINIO_BROWSER
  952. value: "on"
  953. - name: MINIO_PROMETHEUS_AUTH_TYPE
  954. value: "public"
  955. - name: MINIO_CONSOLE_PORT_NUMBER
  956. value: "9001"
  957. envFrom:
  958. ports:
  959. - name: minio-api
  960. containerPort: 9000
  961. protocol: TCP
  962. - name: minio-console
  963. containerPort: 9001
  964. protocol: TCP
  965. livenessProbe:
  966. httpGet:
  967. path: /minio/health/live
  968. port: minio-api
  969. scheme: "HTTP"
  970. initialDelaySeconds: 5
  971. periodSeconds: 5
  972. timeoutSeconds: 5
  973. successThreshold: 1
  974. failureThreshold: 5
  975. readinessProbe:
  976. tcpSocket:
  977. port: minio-api
  978. initialDelaySeconds: 5
  979. periodSeconds: 5
  980. timeoutSeconds: 1
  981. successThreshold: 1
  982. failureThreshold: 5
  983. resources:
  984. limits: {}
  985. requests: {}
  986. volumeMounts:
  987. - name: data
  988. mountPath: /data
  989. volumes:
  990. - name: data
  991. persistentVolumeClaim:
  992. claimName: mastodon-minio
  993. ---
  994. # Source: mastodon/charts/elasticsearch/templates/coordinating/statefulset.yaml
  995. apiVersion: apps/v1
  996. kind: StatefulSet
  997. metadata:
  998. name: mastodon-elasticsearch-coordinating
  999. namespace: "mastodon"
  1000. labels:
  1001. app.kubernetes.io/name: elasticsearch
  1002. helm.sh/chart: elasticsearch-19.5.8
  1003. app.kubernetes.io/instance: mastodon
  1004. app.kubernetes.io/managed-by: Helm
  1005. app.kubernetes.io/component: coordinating-only
  1006. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1007. app: coordinating-only
  1008. spec:
  1009. replicas: 1
  1010. selector:
  1011. matchLabels:
  1012. app.kubernetes.io/name: elasticsearch
  1013. app.kubernetes.io/instance: mastodon
  1014. app.kubernetes.io/component: coordinating-only
  1015. updateStrategy:
  1016. type: RollingUpdate
  1017. serviceName: mastodon-elasticsearch-coordinating-hl
  1018. podManagementPolicy: Parallel
  1019. template:
  1020. metadata:
  1021. labels:
  1022. app.kubernetes.io/name: elasticsearch
  1023. helm.sh/chart: elasticsearch-19.5.8
  1024. app.kubernetes.io/instance: mastodon
  1025. app.kubernetes.io/managed-by: Helm
  1026. app.kubernetes.io/component: coordinating-only
  1027. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1028. app: coordinating-only
  1029. annotations:
  1030. spec:
  1031. serviceAccountName: default
  1032. affinity:
  1033. podAffinity:
  1034. podAntiAffinity:
  1035. nodeAffinity:
  1036. securityContext:
  1037. fsGroup: 1001
  1038. initContainers:
  1039. ## Image that performs the sysctl operation to modify Kernel settings (needed sometimes to avoid boot errors)
  1040. - name: sysctl
  1041. image: docker.io/bitnami/bitnami-shell:11-debian-11-r70
  1042. imagePullPolicy: "IfNotPresent"
  1043. command:
  1044. - /bin/bash
  1045. - -ec
  1046. - |
  1047. CURRENT=`sysctl -n vm.max_map_count`;
  1048. DESIRED="262144";
  1049. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1050. sysctl -w vm.max_map_count=262144;
  1051. fi;
  1052. CURRENT=`sysctl -n fs.file-max`;
  1053. DESIRED="65536";
  1054. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1055. sysctl -w fs.file-max=65536;
  1056. fi;
  1057. securityContext:
  1058. privileged: true
  1059. runAsUser: 0
  1060. resources:
  1061. limits: {}
  1062. requests: {}
  1063. containers:
  1064. - name: elasticsearch
  1065. image: docker.io/bitnami/elasticsearch:8.6.0-debian-11-r0
  1066. imagePullPolicy: "IfNotPresent"
  1067. securityContext:
  1068. runAsNonRoot: true
  1069. runAsUser: 1001
  1070. env:
  1071. - name: MY_POD_NAME
  1072. valueFrom:
  1073. fieldRef:
  1074. fieldPath: metadata.name
  1075. - name: BITNAMI_DEBUG
  1076. value: "false"
  1077. - name: ELASTICSEARCH_CLUSTER_NAME
  1078. value: "elastic"
  1079. - name: ELASTICSEARCH_IS_DEDICATED_NODE
  1080. value: "yes"
  1081. - name: ELASTICSEARCH_NODE_ROLES
  1082. value: ""
  1083. - name: ELASTICSEARCH_TRANSPORT_PORT_NUMBER
  1084. value: "9300"
  1085. - name: ELASTICSEARCH_HTTP_PORT_NUMBER
  1086. value: "9200"
  1087. - name: ELASTICSEARCH_CLUSTER_HOSTS
  1088. value: "mastodon-elasticsearch-master-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-coordinating-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-data-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-ingest-hl.mastodon.svc.cluster.local,"
  1089. - name: ELASTICSEARCH_TOTAL_NODES
  1090. value: "2"
  1091. - name: ELASTICSEARCH_CLUSTER_MASTER_HOSTS
  1092. value: mastodon-elasticsearch-master-0
  1093. - name: ELASTICSEARCH_MINIMUM_MASTER_NODES
  1094. value: "1"
  1095. - name: ELASTICSEARCH_ADVERTISED_HOSTNAME
  1096. value: "$(MY_POD_NAME).mastodon-elasticsearch-coordinating-hl.mastodon.svc.cluster.local"
  1097. - name: ELASTICSEARCH_HEAP_SIZE
  1098. value: "128m"
  1099. ports:
  1100. - name: rest-api
  1101. containerPort: 9200
  1102. - name: transport
  1103. containerPort: 9300
  1104. livenessProbe:
  1105. failureThreshold: 5
  1106. initialDelaySeconds: 90
  1107. periodSeconds: 10
  1108. successThreshold: 1
  1109. timeoutSeconds: 5
  1110. exec:
  1111. command:
  1112. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1113. readinessProbe:
  1114. failureThreshold: 5
  1115. initialDelaySeconds: 90
  1116. periodSeconds: 10
  1117. successThreshold: 1
  1118. timeoutSeconds: 5
  1119. exec:
  1120. command:
  1121. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1122. resources:
  1123. limits: {}
  1124. requests:
  1125. cpu: 25m
  1126. memory: 256Mi
  1127. volumeMounts:
  1128. - name: data
  1129. mountPath: /bitnami/elasticsearch/data
  1130. volumes:
  1131. - name: "data"
  1132. emptyDir: {}
  1133. ---
  1134. # Source: mastodon/charts/elasticsearch/templates/data/statefulset.yaml
  1135. apiVersion: apps/v1
  1136. kind: StatefulSet
  1137. metadata:
  1138. name: mastodon-elasticsearch-data
  1139. namespace: "mastodon"
  1140. labels:
  1141. app.kubernetes.io/name: elasticsearch
  1142. helm.sh/chart: elasticsearch-19.5.8
  1143. app.kubernetes.io/instance: mastodon
  1144. app.kubernetes.io/managed-by: Helm
  1145. app.kubernetes.io/component: data
  1146. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1147. app: data
  1148. spec:
  1149. replicas: 1
  1150. podManagementPolicy: Parallel
  1151. selector:
  1152. matchLabels:
  1153. app.kubernetes.io/name: elasticsearch
  1154. app.kubernetes.io/instance: mastodon
  1155. app.kubernetes.io/component: data
  1156. serviceName: mastodon-elasticsearch-data-hl
  1157. updateStrategy:
  1158. type: RollingUpdate
  1159. template:
  1160. metadata:
  1161. labels:
  1162. app.kubernetes.io/name: elasticsearch
  1163. helm.sh/chart: elasticsearch-19.5.8
  1164. app.kubernetes.io/instance: mastodon
  1165. app.kubernetes.io/managed-by: Helm
  1166. app.kubernetes.io/component: data
  1167. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1168. app: data
  1169. annotations:
  1170. spec:
  1171. serviceAccountName: default
  1172. affinity:
  1173. podAffinity:
  1174. podAntiAffinity:
  1175. nodeAffinity:
  1176. securityContext:
  1177. fsGroup: 1001
  1178. initContainers:
  1179. ## Image that performs the sysctl operation to modify Kernel settings (needed sometimes to avoid boot errors)
  1180. - name: sysctl
  1181. image: docker.io/bitnami/bitnami-shell:11-debian-11-r70
  1182. imagePullPolicy: "IfNotPresent"
  1183. command:
  1184. - /bin/bash
  1185. - -ec
  1186. - |
  1187. CURRENT=`sysctl -n vm.max_map_count`;
  1188. DESIRED="262144";
  1189. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1190. sysctl -w vm.max_map_count=262144;
  1191. fi;
  1192. CURRENT=`sysctl -n fs.file-max`;
  1193. DESIRED="65536";
  1194. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1195. sysctl -w fs.file-max=65536;
  1196. fi;
  1197. securityContext:
  1198. privileged: true
  1199. runAsUser: 0
  1200. resources:
  1201. limits: {}
  1202. requests: {}
  1203. containers:
  1204. - name: elasticsearch
  1205. image: docker.io/bitnami/elasticsearch:8.6.0-debian-11-r0
  1206. imagePullPolicy: "IfNotPresent"
  1207. securityContext:
  1208. runAsNonRoot: true
  1209. runAsUser: 1001
  1210. env:
  1211. - name: BITNAMI_DEBUG
  1212. value: "false"
  1213. - name: MY_POD_NAME
  1214. valueFrom:
  1215. fieldRef:
  1216. fieldPath: metadata.name
  1217. - name: ELASTICSEARCH_IS_DEDICATED_NODE
  1218. value: "yes"
  1219. - name: ELASTICSEARCH_NODE_ROLES
  1220. value: "data"
  1221. - name: ELASTICSEARCH_TRANSPORT_PORT_NUMBER
  1222. value: "9300"
  1223. - name: ELASTICSEARCH_HTTP_PORT_NUMBER
  1224. value: "9200"
  1225. - name: ELASTICSEARCH_CLUSTER_NAME
  1226. value: "elastic"
  1227. - name: ELASTICSEARCH_CLUSTER_HOSTS
  1228. value: "mastodon-elasticsearch-master-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-coordinating-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-data-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-ingest-hl.mastodon.svc.cluster.local,"
  1229. - name: ELASTICSEARCH_TOTAL_NODES
  1230. value: "2"
  1231. - name: ELASTICSEARCH_CLUSTER_MASTER_HOSTS
  1232. value: mastodon-elasticsearch-master-0
  1233. - name: ELASTICSEARCH_MINIMUM_MASTER_NODES
  1234. value: "1"
  1235. - name: ELASTICSEARCH_ADVERTISED_HOSTNAME
  1236. value: "$(MY_POD_NAME).mastodon-elasticsearch-data-hl.mastodon.svc.cluster.local"
  1237. - name: ELASTICSEARCH_HEAP_SIZE
  1238. value: "1024m"
  1239. ports:
  1240. - name: rest-api
  1241. containerPort: 9200
  1242. - name: transport
  1243. containerPort: 9300
  1244. livenessProbe:
  1245. failureThreshold: 5
  1246. initialDelaySeconds: 90
  1247. periodSeconds: 10
  1248. successThreshold: 1
  1249. timeoutSeconds: 5
  1250. exec:
  1251. command:
  1252. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1253. readinessProbe:
  1254. failureThreshold: 5
  1255. initialDelaySeconds: 90
  1256. periodSeconds: 10
  1257. successThreshold: 1
  1258. timeoutSeconds: 5
  1259. exec:
  1260. command:
  1261. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1262. resources:
  1263. limits: {}
  1264. requests:
  1265. cpu: 25m
  1266. memory: 2048Mi
  1267. volumeMounts:
  1268. - name: data
  1269. mountPath: /bitnami/elasticsearch/data
  1270. volumes:
  1271. volumeClaimTemplates:
  1272. - metadata:
  1273. name: "data"
  1274. annotations:
  1275. spec:
  1276. accessModes:
  1277. - "ReadWriteOnce"
  1278. resources:
  1279. requests:
  1280. storage: "8Gi"
  1281. ---
  1282. # Source: mastodon/charts/elasticsearch/templates/ingest/statefulset.yaml
  1283. apiVersion: apps/v1
  1284. kind: StatefulSet
  1285. metadata:
  1286. name: mastodon-elasticsearch-ingest
  1287. namespace: "mastodon"
  1288. labels:
  1289. app.kubernetes.io/name: elasticsearch
  1290. helm.sh/chart: elasticsearch-19.5.8
  1291. app.kubernetes.io/instance: mastodon
  1292. app.kubernetes.io/managed-by: Helm
  1293. app.kubernetes.io/component: ingest
  1294. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1295. app: ingest
  1296. spec:
  1297. replicas: 1
  1298. podManagementPolicy: Parallel
  1299. selector:
  1300. matchLabels:
  1301. app.kubernetes.io/name: elasticsearch
  1302. app.kubernetes.io/instance: mastodon
  1303. app.kubernetes.io/component: ingest
  1304. serviceName: mastodon-elasticsearch-ingest-hl
  1305. updateStrategy:
  1306. type: RollingUpdate
  1307. template:
  1308. metadata:
  1309. labels:
  1310. app.kubernetes.io/name: elasticsearch
  1311. helm.sh/chart: elasticsearch-19.5.8
  1312. app.kubernetes.io/instance: mastodon
  1313. app.kubernetes.io/managed-by: Helm
  1314. app.kubernetes.io/component: ingest
  1315. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1316. app: ingest
  1317. annotations:
  1318. spec:
  1319. serviceAccountName: default
  1320. affinity:
  1321. podAffinity:
  1322. podAntiAffinity:
  1323. nodeAffinity:
  1324. securityContext:
  1325. fsGroup: 1001
  1326. initContainers:
  1327. ## Image that performs the sysctl operation to modify Kernel settings (needed sometimes to avoid boot errors)
  1328. - name: sysctl
  1329. image: docker.io/bitnami/bitnami-shell:11-debian-11-r70
  1330. imagePullPolicy: "IfNotPresent"
  1331. command:
  1332. - /bin/bash
  1333. - -ec
  1334. - |
  1335. CURRENT=`sysctl -n vm.max_map_count`;
  1336. DESIRED="262144";
  1337. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1338. sysctl -w vm.max_map_count=262144;
  1339. fi;
  1340. CURRENT=`sysctl -n fs.file-max`;
  1341. DESIRED="65536";
  1342. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1343. sysctl -w fs.file-max=65536;
  1344. fi;
  1345. securityContext:
  1346. privileged: true
  1347. runAsUser: 0
  1348. resources:
  1349. limits: {}
  1350. requests: {}
  1351. containers:
  1352. - name: elasticsearch
  1353. image: docker.io/bitnami/elasticsearch:8.6.0-debian-11-r0
  1354. imagePullPolicy: "IfNotPresent"
  1355. securityContext:
  1356. runAsNonRoot: true
  1357. runAsUser: 1001
  1358. env:
  1359. - name: BITNAMI_DEBUG
  1360. value: "false"
  1361. - name: MY_POD_NAME
  1362. valueFrom:
  1363. fieldRef:
  1364. fieldPath: metadata.name
  1365. - name: ELASTICSEARCH_IS_DEDICATED_NODE
  1366. value: "yes"
  1367. - name: ELASTICSEARCH_NODE_ROLES
  1368. value: "ingest"
  1369. - name: ELASTICSEARCH_TRANSPORT_PORT_NUMBER
  1370. value: "9300"
  1371. - name: ELASTICSEARCH_HTTP_PORT_NUMBER
  1372. value: "9200"
  1373. - name: ELASTICSEARCH_CLUSTER_NAME
  1374. value: "elastic"
  1375. - name: ELASTICSEARCH_CLUSTER_HOSTS
  1376. value: "mastodon-elasticsearch-master-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-coordinating-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-data-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-ingest-hl.mastodon.svc.cluster.local,"
  1377. - name: ELASTICSEARCH_TOTAL_NODES
  1378. value: "2"
  1379. - name: ELASTICSEARCH_CLUSTER_MASTER_HOSTS
  1380. value: mastodon-elasticsearch-master-0
  1381. - name: ELASTICSEARCH_MINIMUM_MASTER_NODES
  1382. value: "1"
  1383. - name: ELASTICSEARCH_ADVERTISED_HOSTNAME
  1384. value: "$(MY_POD_NAME).mastodon-elasticsearch-ingest-hl.mastodon.svc.cluster.local"
  1385. - name: ELASTICSEARCH_HEAP_SIZE
  1386. value: "128m"
  1387. ports:
  1388. - name: rest-api
  1389. containerPort: 9200
  1390. - name: transport
  1391. containerPort: 9300
  1392. livenessProbe:
  1393. failureThreshold: 5
  1394. initialDelaySeconds: 90
  1395. periodSeconds: 10
  1396. successThreshold: 1
  1397. timeoutSeconds: 5
  1398. exec:
  1399. command:
  1400. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1401. readinessProbe:
  1402. failureThreshold: 5
  1403. initialDelaySeconds: 90
  1404. periodSeconds: 10
  1405. successThreshold: 1
  1406. timeoutSeconds: 5
  1407. exec:
  1408. command:
  1409. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1410. resources:
  1411. limits: {}
  1412. requests:
  1413. cpu: 25m
  1414. memory: 256Mi
  1415. volumeMounts:
  1416. - name: data
  1417. mountPath: /bitnami/elasticsearch/data
  1418. volumes:
  1419. - name: "data"
  1420. emptyDir: {}
  1421. ---
  1422. # Source: mastodon/charts/elasticsearch/templates/master/statefulset.yaml
  1423. apiVersion: apps/v1
  1424. kind: StatefulSet
  1425. metadata:
  1426. name: mastodon-elasticsearch-master
  1427. namespace: "mastodon"
  1428. labels:
  1429. app.kubernetes.io/name: elasticsearch
  1430. helm.sh/chart: elasticsearch-19.5.8
  1431. app.kubernetes.io/instance: mastodon
  1432. app.kubernetes.io/managed-by: Helm
  1433. app.kubernetes.io/component: master
  1434. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1435. app: master
  1436. spec:
  1437. replicas: 1
  1438. podManagementPolicy: Parallel
  1439. selector:
  1440. matchLabels:
  1441. app.kubernetes.io/name: elasticsearch
  1442. app.kubernetes.io/instance: mastodon
  1443. app.kubernetes.io/component: master
  1444. serviceName: mastodon-elasticsearch-master-hl
  1445. updateStrategy:
  1446. type: RollingUpdate
  1447. template:
  1448. metadata:
  1449. labels:
  1450. app.kubernetes.io/name: elasticsearch
  1451. helm.sh/chart: elasticsearch-19.5.8
  1452. app.kubernetes.io/instance: mastodon
  1453. app.kubernetes.io/managed-by: Helm
  1454. app.kubernetes.io/component: master
  1455. ## Istio Labels: https://istio.io/docs/ops/deployment/requirements/
  1456. app: master
  1457. annotations:
  1458. spec:
  1459. serviceAccountName: default
  1460. affinity:
  1461. podAffinity:
  1462. podAntiAffinity:
  1463. nodeAffinity:
  1464. securityContext:
  1465. fsGroup: 1001
  1466. initContainers:
  1467. ## Image that performs the sysctl operation to modify Kernel settings (needed sometimes to avoid boot errors)
  1468. - name: sysctl
  1469. image: docker.io/bitnami/bitnami-shell:11-debian-11-r70
  1470. imagePullPolicy: "IfNotPresent"
  1471. command:
  1472. - /bin/bash
  1473. - -ec
  1474. - |
  1475. CURRENT=`sysctl -n vm.max_map_count`;
  1476. DESIRED="262144";
  1477. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1478. sysctl -w vm.max_map_count=262144;
  1479. fi;
  1480. CURRENT=`sysctl -n fs.file-max`;
  1481. DESIRED="65536";
  1482. if [ "$DESIRED" -gt "$CURRENT" ]; then
  1483. sysctl -w fs.file-max=65536;
  1484. fi;
  1485. securityContext:
  1486. privileged: true
  1487. runAsUser: 0
  1488. resources:
  1489. limits: {}
  1490. requests: {}
  1491. containers:
  1492. - name: elasticsearch
  1493. image: docker.io/bitnami/elasticsearch:8.6.0-debian-11-r0
  1494. imagePullPolicy: "IfNotPresent"
  1495. securityContext:
  1496. runAsNonRoot: true
  1497. runAsUser: 1001
  1498. env:
  1499. - name: BITNAMI_DEBUG
  1500. value: "false"
  1501. - name: MY_POD_NAME
  1502. valueFrom:
  1503. fieldRef:
  1504. fieldPath: metadata.name
  1505. - name: ELASTICSEARCH_IS_DEDICATED_NODE
  1506. value: "yes"
  1507. - name: ELASTICSEARCH_NODE_ROLES
  1508. value: "master"
  1509. - name: ELASTICSEARCH_TRANSPORT_PORT_NUMBER
  1510. value: "9300"
  1511. - name: ELASTICSEARCH_HTTP_PORT_NUMBER
  1512. value: "9200"
  1513. - name: ELASTICSEARCH_CLUSTER_NAME
  1514. value: "elastic"
  1515. - name: ELASTICSEARCH_CLUSTER_HOSTS
  1516. value: "mastodon-elasticsearch-master-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-coordinating-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-data-hl.mastodon.svc.cluster.local,mastodon-elasticsearch-ingest-hl.mastodon.svc.cluster.local,"
  1517. - name: ELASTICSEARCH_TOTAL_NODES
  1518. value: "2"
  1519. - name: ELASTICSEARCH_CLUSTER_MASTER_HOSTS
  1520. value: mastodon-elasticsearch-master-0
  1521. - name: ELASTICSEARCH_MINIMUM_MASTER_NODES
  1522. value: "1"
  1523. - name: ELASTICSEARCH_ADVERTISED_HOSTNAME
  1524. value: "$(MY_POD_NAME).mastodon-elasticsearch-master-hl.mastodon.svc.cluster.local"
  1525. - name: ELASTICSEARCH_HEAP_SIZE
  1526. value: "128m"
  1527. ports:
  1528. - name: rest-api
  1529. containerPort: 9200
  1530. - name: transport
  1531. containerPort: 9300
  1532. livenessProbe:
  1533. failureThreshold: 5
  1534. initialDelaySeconds: 90
  1535. periodSeconds: 10
  1536. successThreshold: 1
  1537. timeoutSeconds: 5
  1538. exec:
  1539. command:
  1540. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1541. readinessProbe:
  1542. failureThreshold: 5
  1543. initialDelaySeconds: 90
  1544. periodSeconds: 10
  1545. successThreshold: 1
  1546. timeoutSeconds: 5
  1547. exec:
  1548. command:
  1549. - /opt/bitnami/scripts/elasticsearch/healthcheck.sh
  1550. resources:
  1551. limits: {}
  1552. requests:
  1553. cpu: 25m
  1554. memory: 256Mi
  1555. volumeMounts:
  1556. - name: data
  1557. mountPath: /bitnami/elasticsearch/data
  1558. volumes:
  1559. volumeClaimTemplates:
  1560. - metadata:
  1561. name: "data"
  1562. annotations:
  1563. spec:
  1564. accessModes:
  1565. - "ReadWriteOnce"
  1566. resources:
  1567. requests:
  1568. storage: "8Gi"
  1569. ---
  1570. # Source: mastodon/charts/postgresql/templates/primary/statefulset.yaml
  1571. apiVersion: apps/v1
  1572. kind: StatefulSet
  1573. metadata:
  1574. name: mastodon-postgresql
  1575. namespace: "mastodon"
  1576. labels:
  1577. app.kubernetes.io/name: postgresql
  1578. helm.sh/chart: postgresql-12.1.9
  1579. app.kubernetes.io/instance: mastodon
  1580. app.kubernetes.io/managed-by: Helm
  1581. app.kubernetes.io/component: primary
  1582. annotations:
  1583. spec:
  1584. replicas: 1
  1585. serviceName: mastodon-postgresql-hl
  1586. updateStrategy:
  1587. rollingUpdate: {}
  1588. type: RollingUpdate
  1589. selector:
  1590. matchLabels:
  1591. app.kubernetes.io/name: postgresql
  1592. app.kubernetes.io/instance: mastodon
  1593. app.kubernetes.io/component: primary
  1594. template:
  1595. metadata:
  1596. name: mastodon-postgresql
  1597. labels:
  1598. app.kubernetes.io/name: postgresql
  1599. helm.sh/chart: postgresql-12.1.9
  1600. app.kubernetes.io/instance: mastodon
  1601. app.kubernetes.io/managed-by: Helm
  1602. app.kubernetes.io/component: primary
  1603. annotations:
  1604. spec:
  1605. serviceAccountName: default
  1606. affinity:
  1607. podAffinity:
  1608. podAntiAffinity:
  1609. preferredDuringSchedulingIgnoredDuringExecution:
  1610. - podAffinityTerm:
  1611. labelSelector:
  1612. matchLabels:
  1613. app.kubernetes.io/name: postgresql
  1614. app.kubernetes.io/instance: mastodon
  1615. app.kubernetes.io/component: primary
  1616. topologyKey: kubernetes.io/hostname
  1617. weight: 1
  1618. nodeAffinity:
  1619. securityContext:
  1620. fsGroup: 1001
  1621. hostNetwork: false
  1622. hostIPC: false
  1623. initContainers:
  1624. containers:
  1625. - name: postgresql
  1626. image: docker.io/bitnami/postgresql:15.1.0-debian-11-r20
  1627. imagePullPolicy: "IfNotPresent"
  1628. securityContext:
  1629. runAsUser: 1001
  1630. env:
  1631. - name: BITNAMI_DEBUG
  1632. value: "false"
  1633. - name: POSTGRESQL_PORT_NUMBER
  1634. value: "5432"
  1635. - name: POSTGRESQL_VOLUME_DIR
  1636. value: "/bitnami/postgresql"
  1637. - name: PGDATA
  1638. value: "/bitnami/postgresql/data"
  1639. # Authentication
  1640. - name: POSTGRES_USER
  1641. value: "bn_mastodon"
  1642. - name: POSTGRES_POSTGRES_PASSWORD
  1643. valueFrom:
  1644. secretKeyRef:
  1645. name: mastodon-postgresql
  1646. key: postgres-password
  1647. - name: POSTGRES_PASSWORD
  1648. valueFrom:
  1649. secretKeyRef:
  1650. name: mastodon-postgresql
  1651. key: password
  1652. - name: POSTGRES_DB
  1653. value: "bitnami_mastodon"
  1654. # Replication
  1655. # Initdb
  1656. # Standby
  1657. # LDAP
  1658. - name: POSTGRESQL_ENABLE_LDAP
  1659. value: "no"
  1660. # TLS
  1661. - name: POSTGRESQL_ENABLE_TLS
  1662. value: "no"
  1663. # Audit
  1664. - name: POSTGRESQL_LOG_HOSTNAME
  1665. value: "false"
  1666. - name: POSTGRESQL_LOG_CONNECTIONS
  1667. value: "false"
  1668. - name: POSTGRESQL_LOG_DISCONNECTIONS
  1669. value: "false"
  1670. - name: POSTGRESQL_PGAUDIT_LOG_CATALOG
  1671. value: "off"
  1672. # Others
  1673. - name: POSTGRESQL_CLIENT_MIN_MESSAGES
  1674. value: "error"
  1675. - name: POSTGRESQL_SHARED_PRELOAD_LIBRARIES
  1676. value: "pgaudit"
  1677. ports:
  1678. - name: tcp-postgresql
  1679. containerPort: 5432
  1680. livenessProbe:
  1681. failureThreshold: 6
  1682. initialDelaySeconds: 30
  1683. periodSeconds: 10
  1684. successThreshold: 1
  1685. timeoutSeconds: 5
  1686. exec:
  1687. command:
  1688. - /bin/sh
  1689. - -c
  1690. - exec pg_isready -U "bn_mastodon" -d "dbname=bitnami_mastodon" -h 127.0.0.1 -p 5432
  1691. readinessProbe:
  1692. failureThreshold: 6
  1693. initialDelaySeconds: 5
  1694. periodSeconds: 10
  1695. successThreshold: 1
  1696. timeoutSeconds: 5
  1697. exec:
  1698. command:
  1699. - /bin/sh
  1700. - -c
  1701. - -e
  1702. - |
  1703. exec pg_isready -U "bn_mastodon" -d "dbname=bitnami_mastodon" -h 127.0.0.1 -p 5432
  1704. [ -f /opt/bitnami/postgresql/tmp/.initialized ] || [ -f /bitnami/postgresql/.initialized ]
  1705. resources:
  1706. limits: {}
  1707. requests:
  1708. cpu: 250m
  1709. memory: 256Mi
  1710. volumeMounts:
  1711. - name: dshm
  1712. mountPath: /dev/shm
  1713. - name: data
  1714. mountPath: /bitnami/postgresql
  1715. volumes:
  1716. - name: dshm
  1717. emptyDir:
  1718. medium: Memory
  1719. volumeClaimTemplates:
  1720. - metadata:
  1721. name: data
  1722. spec:
  1723. accessModes:
  1724. - "ReadWriteOnce"
  1725. resources:
  1726. requests:
  1727. storage: "8Gi"
  1728. ---
  1729. # Source: mastodon/charts/redis/templates/master/application.yaml
  1730. apiVersion: apps/v1
  1731. kind: StatefulSet
  1732. metadata:
  1733. name: mastodon-redis-master
  1734. namespace: "mastodon"
  1735. labels:
  1736. app.kubernetes.io/name: redis
  1737. helm.sh/chart: redis-17.4.3
  1738. app.kubernetes.io/instance: mastodon
  1739. app.kubernetes.io/managed-by: Helm
  1740. app.kubernetes.io/component: master
  1741. spec:
  1742. replicas: 1
  1743. selector:
  1744. matchLabels:
  1745. app.kubernetes.io/name: redis
  1746. app.kubernetes.io/instance: mastodon
  1747. app.kubernetes.io/component: master
  1748. serviceName: mastodon-redis-headless
  1749. updateStrategy:
  1750. type: RollingUpdate
  1751. template:
  1752. metadata:
  1753. labels:
  1754. app.kubernetes.io/name: redis
  1755. helm.sh/chart: redis-17.4.3
  1756. app.kubernetes.io/instance: mastodon
  1757. app.kubernetes.io/managed-by: Helm
  1758. app.kubernetes.io/component: master
  1759. annotations:
  1760. checksum/configmap: 2f15040384162155f37c5089d1a10352963784fb168a605b339e88c8642e7001
  1761. checksum/health: 0b8c4cf2e9643861c68f5ce94dc34b6497ef911db5da1c59f51d5f172a4b98dd
  1762. checksum/scripts: aaa87d91cbed3dc312c3e5b1dab72400a783834667c43a4d19bba0b89be86c63
  1763. checksum/secret: a6419e12b36d05bc7c2ce11860928be0c5a2a41ea37358fe1979106d70ea686f
  1764. spec:
  1765. securityContext:
  1766. fsGroup: 1001
  1767. serviceAccountName: mastodon-redis
  1768. affinity:
  1769. podAffinity:
  1770. podAntiAffinity:
  1771. preferredDuringSchedulingIgnoredDuringExecution:
  1772. - podAffinityTerm:
  1773. labelSelector:
  1774. matchLabels:
  1775. app.kubernetes.io/name: redis
  1776. app.kubernetes.io/instance: mastodon
  1777. app.kubernetes.io/component: master
  1778. topologyKey: kubernetes.io/hostname
  1779. weight: 1
  1780. nodeAffinity:
  1781. terminationGracePeriodSeconds: 30
  1782. containers:
  1783. - name: redis
  1784. image: docker.io/bitnami/redis:7.0.8-debian-11-r0
  1785. imagePullPolicy: "IfNotPresent"
  1786. securityContext:
  1787. runAsUser: 1001
  1788. command:
  1789. - /bin/bash
  1790. args:
  1791. - -c
  1792. - /opt/bitnami/scripts/start-scripts/start-master.sh
  1793. env:
  1794. - name: BITNAMI_DEBUG
  1795. value: "false"
  1796. - name: REDIS_REPLICATION_MODE
  1797. value: master
  1798. - name: ALLOW_EMPTY_PASSWORD
  1799. value: "no"
  1800. - name: REDIS_PASSWORD
  1801. valueFrom:
  1802. secretKeyRef:
  1803. name: mastodon-redis
  1804. key: redis-password
  1805. - name: REDIS_TLS_ENABLED
  1806. value: "no"
  1807. - name: REDIS_PORT
  1808. value: "6379"
  1809. ports:
  1810. - name: redis
  1811. containerPort: 6379
  1812. livenessProbe:
  1813. initialDelaySeconds: 20
  1814. periodSeconds: 5
  1815. # One second longer than command timeout should prevent generation of zombie processes.
  1816. timeoutSeconds: 6
  1817. successThreshold: 1
  1818. failureThreshold: 5
  1819. exec:
  1820. command:
  1821. - sh
  1822. - -c
  1823. - /health/ping_liveness_local.sh 5
  1824. readinessProbe:
  1825. initialDelaySeconds: 20
  1826. periodSeconds: 5
  1827. timeoutSeconds: 2
  1828. successThreshold: 1
  1829. failureThreshold: 5
  1830. exec:
  1831. command:
  1832. - sh
  1833. - -c
  1834. - /health/ping_readiness_local.sh 1
  1835. resources:
  1836. limits: {}
  1837. requests: {}
  1838. volumeMounts:
  1839. - name: start-scripts
  1840. mountPath: /opt/bitnami/scripts/start-scripts
  1841. - name: health
  1842. mountPath: /health
  1843. - name: redis-data
  1844. mountPath: /data
  1845. - name: config
  1846. mountPath: /opt/bitnami/redis/mounted-etc
  1847. - name: redis-tmp-conf
  1848. mountPath: /opt/bitnami/redis/etc/
  1849. - name: tmp
  1850. mountPath: /tmp
  1851. volumes:
  1852. - name: start-scripts
  1853. configMap:
  1854. name: mastodon-redis-scripts
  1855. defaultMode: 0755
  1856. - name: health
  1857. configMap:
  1858. name: mastodon-redis-health
  1859. defaultMode: 0755
  1860. - name: config
  1861. configMap:
  1862. name: mastodon-redis-configuration
  1863. - name: redis-tmp-conf
  1864. emptyDir: {}
  1865. - name: tmp
  1866. emptyDir: {}
  1867. volumeClaimTemplates:
  1868. - metadata:
  1869. name: redis-data
  1870. labels:
  1871. app.kubernetes.io/name: redis
  1872. app.kubernetes.io/instance: mastodon
  1873. app.kubernetes.io/component: master
  1874. spec:
  1875. accessModes:
  1876. - "ReadWriteOnce"
  1877. resources:
  1878. requests:
  1879. storage: "8Gi"
  1880. ---
  1881. # Source: mastodon/charts/minio/templates/provisioning-job.yaml
  1882. apiVersion: batch/v1
  1883. kind: Job
  1884. metadata:
  1885. name: mastodon-minio-provisioning
  1886. namespace: "mastodon"
  1887. labels:
  1888. app.kubernetes.io/name: minio
  1889. helm.sh/chart: minio-12.0.0
  1890. app.kubernetes.io/instance: mastodon
  1891. app.kubernetes.io/managed-by: Helm
  1892. app.kubernetes.io/component: minio-provisioning
  1893. annotations:
  1894. helm.sh/hook: post-install,post-upgrade
  1895. helm.sh/hook-delete-policy: before-hook-creation
  1896. spec:
  1897. parallelism: 1
  1898. template:
  1899. metadata:
  1900. labels:
  1901. app.kubernetes.io/managed-by: Helm
  1902. helm.sh/chart: minio-12.0.0
  1903. app.kubernetes.io/component: minio-provisioning
  1904. spec:
  1905. restartPolicy: OnFailure
  1906. terminationGracePeriodSeconds: 0
  1907. securityContext:
  1908. fsGroup: 1001
  1909. serviceAccountName: mastodon-minio
  1910. initContainers:
  1911. - name: wait-for-available-minio
  1912. image: docker.io/bitnami/minio:2023.1.12-debian-11-r0
  1913. imagePullPolicy: "IfNotPresent"
  1914. securityContext:
  1915. runAsNonRoot: true
  1916. runAsUser: 1001
  1917. command:
  1918. - /bin/bash
  1919. - -c
  1920. - >-
  1921. set -e;
  1922. echo "Waiting for Minio";
  1923. wait-for-port \
  1924. --host=mastodon-minio \
  1925. --state=inuse \
  1926. --timeout=120 \
  1927. 80;
  1928. echo "Minio is available";
  1929. resources:
  1930. limits: {}
  1931. requests: {}
  1932. containers:
  1933. - name: minio
  1934. image: docker.io/bitnami/minio:2023.1.12-debian-11-r0
  1935. imagePullPolicy: "IfNotPresent"
  1936. securityContext:
  1937. runAsNonRoot: true
  1938. runAsUser: 1001
  1939. command:
  1940. - /bin/bash
  1941. - -c
  1942. - >-
  1943. set -e;
  1944. echo "Start Minio provisioning";
  1945. function addPolicy() {
  1946. local tmp=$(mc admin $1 info provisioning $2 | sed -n -e 's/^Policy.*: \(.*\)$/\1/p');
  1947. IFS=',' read -r -a CURRENT_POLICIES <<< "$tmp";
  1948. if [[ ! "${CURRENT_POLICIES[*]}" =~ "$3" ]]; then
  1949. mc admin policy update provisioning $3 $1=$2;
  1950. fi;
  1951. };
  1952. function addUsersFromFile() {
  1953. local username=$(grep -oP '^username=\K.+' $1);
  1954. local password=$(grep -oP '^password=\K.+' $1);
  1955. local disabled=$(grep -oP '^disabled=\K.+' $1);
  1956. local policies_list=$(grep -oP '^policies=\K.+' $1);
  1957. local set_policies=$(grep -oP '^setPolicies=\K.+' $1);
  1958. mc admin user add provisioning "${username}" "${password}";
  1959. if [ "${set_policies}" == "true" ]; then
  1960. mc admin policy set provisioning "${policies_list}" user="${username}";
  1961. else
  1962. IFS=',' read -r -a POLICIES <<< "${policies_list}";
  1963. for policy in "${POLICIES[@]}"; do
  1964. addPolicy user "${username}" "${policy}";
  1965. done
  1966. fi;
  1967. local user_status="enable";
  1968. if [[ "${disabled}" != "" && "${disabled,,}" == "true" ]]; then
  1969. user_status="disable";
  1970. fi;
  1971. mc admin user "${user_status}" provisioning "${username}";
  1972. };
  1973. mc alias set provisioning $MINIO_SCHEME://mastodon-minio:80 $MINIO_ROOT_USER $MINIO_ROOT_PASSWORD;
  1974. mc admin service restart provisioning;
  1975. mc anonymous set download provisioning/s3storage;
  1976. echo "End Minio provisioning";
  1977. env:
  1978. - name: MINIO_SCHEME
  1979. value: "http"
  1980. - name: MINIO_ROOT_USER
  1981. valueFrom:
  1982. secretKeyRef:
  1983. name: mastodon-minio
  1984. key: root-user
  1985. - name: MINIO_ROOT_PASSWORD
  1986. valueFrom:
  1987. secretKeyRef:
  1988. name: mastodon-minio
  1989. key: root-password
  1990. envFrom:
  1991. resources:
  1992. limits: {}
  1993. requests: {}
  1994. volumeMounts:
  1995. - name: minio-provisioning
  1996. mountPath: /etc/ilm
  1997. volumes:
  1998. - name: minio-provisioning
  1999. configMap:
  2000. name: mastodon-minio-provisioning