databunker
This commit is contained in:
42
infra/base/databunker/databunker.yaml
Normal file
42
infra/base/databunker/databunker.yaml
Normal file
@@ -0,0 +1,42 @@
|
|||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: databunker
|
||||||
|
namespace: argocd
|
||||||
|
annotations:
|
||||||
|
argocd.argoproj.io/sync-wave: "1"
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: databunker
|
||||||
|
app.kubernetes.io/part-of: identity
|
||||||
|
app.kubernetes.io/managed-by: argocd
|
||||||
|
finalizers:
|
||||||
|
- resources-finalizer.argocd.argoproj.io
|
||||||
|
spec:
|
||||||
|
project: default
|
||||||
|
|
||||||
|
sources:
|
||||||
|
- repoURL: https://securitybunker.github.io/databunkerpro-setup
|
||||||
|
chart: databunkerpro/databunkerpro
|
||||||
|
targetRevision: "0.1.0"
|
||||||
|
helm:
|
||||||
|
releaseName: databunkerpro
|
||||||
|
valueFiles:
|
||||||
|
- $values/infra/values/base/databunker-values.yaml
|
||||||
|
|
||||||
|
- repoURL: ssh://git@git.forteapps.net:2222/Forte/launchpad.git
|
||||||
|
targetRevision: HEAD
|
||||||
|
ref: values
|
||||||
|
|
||||||
|
destination:
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
namespace: databunker
|
||||||
|
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
|
allowEmpty: false
|
||||||
|
syncOptions:
|
||||||
|
- CreateNamespace=true
|
||||||
|
- Validate=true
|
||||||
|
- ServerSideApply=true
|
||||||
4
infra/base/databunker/kustomization.yaml
Normal file
4
infra/base/databunker/kustomization.yaml
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- databunker.yaml
|
||||||
@@ -20,3 +20,4 @@ resources:
|
|||||||
- tempo
|
- tempo
|
||||||
- grafana-dashboards
|
- grafana-dashboards
|
||||||
- karpor
|
- karpor
|
||||||
|
- databunker
|
||||||
|
|||||||
@@ -5,3 +5,12 @@ resources:
|
|||||||
|
|
||||||
# No patches needed — base already has "upc-dev" paths
|
# No patches needed — base already has "upc-dev" paths
|
||||||
# upc-dev is the default/base cluster
|
# upc-dev is the default/base cluster
|
||||||
|
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
kind: Application
|
||||||
|
name: databunker
|
||||||
|
patch: |
|
||||||
|
- op: add
|
||||||
|
path: /spec/sources/0/helm/valueFiles/-
|
||||||
|
value: $values/infra/values/upc-dev/databunker-values.yaml
|
||||||
|
|||||||
34
infra/values/base/databunker-values.yaml
Normal file
34
infra/values/base/databunker-values.yaml
Normal file
@@ -0,0 +1,34 @@
|
|||||||
|
# Default values for databunkerpro
|
||||||
|
image:
|
||||||
|
tag: 1.0.0
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: false # Set to true to enable ingress
|
||||||
|
className: traefik
|
||||||
|
# Set host to enable ingress
|
||||||
|
host: databunker.example.com
|
||||||
|
annotations:
|
||||||
|
kubernetes.io/ingress.class: traefik
|
||||||
|
cert-manager.io/cluster-issuer: "letsencrypt-prod" # or your cluster issuer
|
||||||
|
traefik.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
traefik.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
traefik.ingress.kubernetes.io/ssl-passthrough: "false"
|
||||||
|
# Security headers
|
||||||
|
traefik.ingress.kubernetes.io/configuration-snippet: |
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Frame-Options DENY always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header X-XSS-Protection "1; mode=block" always;
|
||||||
|
# TLS configuration
|
||||||
|
tls:
|
||||||
|
enabled: true # Set to true to enable TLS
|
||||||
|
secretName: "databunker-tls" # Name of the secret containing TLS certificate
|
||||||
|
|
||||||
|
resources:
|
||||||
|
# Uncomment and adjust these values based on your requirements
|
||||||
|
# requests:
|
||||||
|
# memory: "512Mi"
|
||||||
|
# cpu: "250m"
|
||||||
|
# limits:
|
||||||
|
# memory: "1Gi"
|
||||||
|
# cpu: "500m"
|
||||||
3
infra/values/upc-dev/databunker-values.yaml
Normal file
3
infra/values/upc-dev/databunker-values.yaml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
host: databunker.forteapps.net
|
||||||
Reference in New Issue
Block a user