Add k3s deployment scaffolding for dist/ on Vultr
Ships the static landing page to the existing k3s cluster at 65.20.110.165, served at www.apexturf.es (apexturf.es redirects to it), using a self-hosted Gitea instance as the container registry. - deploy/Dockerfile + nginx.conf: nginx:alpine image serving dist/ (SPA-safe fallback, gzip, cache headers). Build-tested locally against the real dist/ output. - deploy/k8s/apex-turf/: Namespace, Deployment, Service, and two Ingresses (www.apexturf.es + a Traefik Middleware redirect from the bare domain). - deploy/k8s/cert-manager/: Let's Encrypt ClusterIssuers (prod + staging) for HTTP-01 via the cluster's bundled Traefik. - deploy/k8s/gitea/: Helm values for a lightweight, SQLite-backed Gitea at git.apexturf.es with its container registry enabled. - docs/DEPLOYMENT.md: full phased runbook with exact commands, troubleshooting, and a redeploy cheat sheet. - docs/README.md: point at the new deploy/ tree and runbook. Nothing here touches the remote cluster — these are local manifests and docs for the user to apply themselves. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
db45efcfd2
commit
661a7e060c
@@ -0,0 +1,46 @@
|
||||
# CHANGE ME: replace GITEA_OWNER with your Gitea username/org (see
|
||||
# docs/DEPLOYMENT.md Phase 5) before applying, e.g.:
|
||||
# sed -i '' 's/GITEA_OWNER/apexadmin/' deploy/k8s/apex-turf/deployment.yaml
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: apex-turf-web
|
||||
namespace: apex-turf
|
||||
labels:
|
||||
app: apex-turf-web
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: apex-turf-web
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: apex-turf-web
|
||||
spec:
|
||||
containers:
|
||||
- name: web
|
||||
image: git.apexturf.es/GITEA_OWNER/apex-turf-web:latest
|
||||
ports:
|
||||
- containerPort: 80
|
||||
resources:
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 64Mi
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /
|
||||
port: 80
|
||||
initialDelaySeconds: 2
|
||||
periodSeconds: 5
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /
|
||||
port: 80
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
imagePullSecrets:
|
||||
- name: gitea-registry
|
||||
@@ -0,0 +1,26 @@
|
||||
# Serves the site at https://www.apexturf.es (this is the canonical host —
|
||||
# see redirect-ingress.yaml for the bare apexturf.es -> www redirect).
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: apex-turf-web
|
||||
namespace: apex-turf
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
spec:
|
||||
ingressClassName: traefik
|
||||
tls:
|
||||
- hosts:
|
||||
- www.apexturf.es
|
||||
secretName: apex-turf-web-tls
|
||||
rules:
|
||||
- host: www.apexturf.es
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: apex-turf-web
|
||||
port:
|
||||
number: 80
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: apex-turf
|
||||
@@ -0,0 +1,42 @@
|
||||
# Redirects bare https://apexturf.es/* -> https://www.apexturf.es/* (301).
|
||||
# Needs cert-manager to issue a cert for the bare domain too (browsers hit
|
||||
# TLS on apexturf.es *before* any HTTP-level redirect can happen), so this
|
||||
# still requests its own certificate even though all traffic bounces onward.
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: Middleware
|
||||
metadata:
|
||||
name: redirect-to-www
|
||||
namespace: apex-turf
|
||||
spec:
|
||||
redirectRegex:
|
||||
regex: ^https?://apexturf\.es/(.*)
|
||||
replacement: https://www.apexturf.es/${1}
|
||||
permanent: true
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: apex-turf-redirect
|
||||
namespace: apex-turf
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
traefik.ingress.kubernetes.io/router.middlewares: apex-turf-redirect-to-www@kubernetescrd
|
||||
spec:
|
||||
ingressClassName: traefik
|
||||
tls:
|
||||
- hosts:
|
||||
- apexturf.es
|
||||
secretName: apex-turf-root-tls
|
||||
rules:
|
||||
- host: apexturf.es
|
||||
http:
|
||||
paths:
|
||||
# Backend is never actually reached — the middleware above redirects
|
||||
# first — but Ingress requires a rule to attach the middleware to.
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
backend:
|
||||
service:
|
||||
name: apex-turf-web
|
||||
port:
|
||||
number: 80
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: apex-turf-web
|
||||
namespace: apex-turf
|
||||
spec:
|
||||
selector:
|
||||
app: apex-turf-web
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
Reference in New Issue
Block a user