Add k3s deployment scaffolding for dist/ on Vultr

Ships the static landing page to the existing k3s cluster at
65.20.110.165, served at www.apexturf.es (apexturf.es redirects to
it), using a self-hosted Gitea instance as the container registry.

- deploy/Dockerfile + nginx.conf: nginx:alpine image serving dist/
  (SPA-safe fallback, gzip, cache headers). Build-tested locally
  against the real dist/ output.
- deploy/k8s/apex-turf/: Namespace, Deployment, Service, and two
  Ingresses (www.apexturf.es + a Traefik Middleware redirect from
  the bare domain).
- deploy/k8s/cert-manager/: Let's Encrypt ClusterIssuers (prod +
  staging) for HTTP-01 via the cluster's bundled Traefik.
- deploy/k8s/gitea/: Helm values for a lightweight, SQLite-backed
  Gitea at git.apexturf.es with its container registry enabled.
- docs/DEPLOYMENT.md: full phased runbook with exact commands,
  troubleshooting, and a redeploy cheat sheet.
- docs/README.md: point at the new deploy/ tree and runbook.

Nothing here touches the remote cluster — these are local manifests
and docs for the user to apply themselves.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
albert
2026-08-24 20:38:03 +02:00
co-authored by Claude Sonnet 5
parent db45efcfd2
commit 661a7e060c
12 changed files with 493 additions and 1 deletions
+46
View File
@@ -0,0 +1,46 @@
# CHANGE ME: replace GITEA_OWNER with your Gitea username/org (see
# docs/DEPLOYMENT.md Phase 5) before applying, e.g.:
# sed -i '' 's/GITEA_OWNER/apexadmin/' deploy/k8s/apex-turf/deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: apex-turf-web
namespace: apex-turf
labels:
app: apex-turf-web
spec:
replicas: 2
selector:
matchLabels:
app: apex-turf-web
template:
metadata:
labels:
app: apex-turf-web
spec:
containers:
- name: web
image: git.apexturf.es/GITEA_OWNER/apex-turf-web:latest
ports:
- containerPort: 80
resources:
requests:
cpu: 25m
memory: 32Mi
limits:
cpu: 200m
memory: 64Mi
readinessProbe:
httpGet:
path: /
port: 80
initialDelaySeconds: 2
periodSeconds: 5
livenessProbe:
httpGet:
path: /
port: 80
initialDelaySeconds: 5
periodSeconds: 10
imagePullSecrets:
- name: gitea-registry
+26
View File
@@ -0,0 +1,26 @@
# Serves the site at https://www.apexturf.es (this is the canonical host —
# see redirect-ingress.yaml for the bare apexturf.es -> www redirect).
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: apex-turf-web
namespace: apex-turf
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
ingressClassName: traefik
tls:
- hosts:
- www.apexturf.es
secretName: apex-turf-web-tls
rules:
- host: www.apexturf.es
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: apex-turf-web
port:
number: 80
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: apex-turf
@@ -0,0 +1,42 @@
# Redirects bare https://apexturf.es/* -> https://www.apexturf.es/* (301).
# Needs cert-manager to issue a cert for the bare domain too (browsers hit
# TLS on apexturf.es *before* any HTTP-level redirect can happen), so this
# still requests its own certificate even though all traffic bounces onward.
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: redirect-to-www
namespace: apex-turf
spec:
redirectRegex:
regex: ^https?://apexturf\.es/(.*)
replacement: https://www.apexturf.es/${1}
permanent: true
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: apex-turf-redirect
namespace: apex-turf
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
traefik.ingress.kubernetes.io/router.middlewares: apex-turf-redirect-to-www@kubernetescrd
spec:
ingressClassName: traefik
tls:
- hosts:
- apexturf.es
secretName: apex-turf-root-tls
rules:
- host: apexturf.es
http:
paths:
# Backend is never actually reached — the middleware above redirects
# first — but Ingress requires a rule to attach the middleware to.
- path: /
pathType: Prefix
backend:
service:
name: apex-turf-web
port:
number: 80
+11
View File
@@ -0,0 +1,11 @@
apiVersion: v1
kind: Service
metadata:
name: apex-turf-web
namespace: apex-turf
spec:
selector:
app: apex-turf-web
ports:
- port: 80
targetPort: 80