apiVersion: apps/v1 kind: Deployment metadata: name: affine-worker labels: app.kubernetes.io/name: affine-worker app.kubernetes.io/instance: {{ .Release.Name }} app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} app.kubernetes.io/managed-by: {{ .Release.Service }} monitoring: enabled spec: replicas: {{ .Values.worker.replicaCount }} selector: matchLabels: app.kubernetes.io/name: affine-worker app.kubernetes.io/instance: {{ .Release.Name }} template: metadata: annotations: checksum/indexer-config: {{ include "affine.indexerConfig" . | sha256sum }} {{- with .Values.worker.podAnnotations }} {{- toYaml . | nindent 8 }} {{- end }} labels: app.kubernetes.io/name: affine-worker app.kubernetes.io/instance: {{ .Release.Name }} spec: serviceAccountName: {{ .Values.worker.serviceAccount.name }} securityContext: {{- toYaml .Values.worker.podSecurityContext | nindent 8 }} {{- with .Values.global.database.gcloud }} {{- if .enabled }} initContainers: - name: wait-for-cloud-sql-proxy image: busybox:1.36.1 imagePullPolicy: IfNotPresent command: - /bin/sh - -ec - | until wget -q -T 2 -O /dev/null "http://{{ $.Values.global.database.host }}:9801/startup"; do echo "waiting for cloud sql proxy to become ready" sleep 2 done {{- end }} {{- end }} containers: - name: worker image: "{{ .Values.worker.image.repository }}:{{ .Values.worker.image.tag | default .Values.graphql.image.tag | default .Chart.AppVersion }}" imagePullPolicy: IfNotPresent securityContext: {{- toYaml .Values.worker.securityContext | nindent 12 }} env: - name: AFFINE_PRIVATE_KEY valueFrom: secretKeyRef: name: "{{ .Values.global.secret.secretName }}" key: key - name: NODE_ENV value: "{{ .Values.worker.env }}" - name: NODE_OPTIONS value: "{{ .Values.worker.nodeOptions }}" - name: NO_COLOR value: "1" - name: DEPLOYMENT_TYPE value: "{{ .Values.global.deployment.type }}" - name: DEPLOYMENT_PLATFORM value: "{{ .Values.global.deployment.platform }}" - name: SERVER_FLAVOR value: "worker" - name: AFFINE_ENV value: "{{ .Release.Namespace }}" - name: DATABASE_PASSWORD valueFrom: secretKeyRef: name: pg-postgresql key: postgres-password - name: DATABASE_URL value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.host }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }} - name: REDIS_SERVER_ENABLED value: "true" - name: REDIS_SERVER_HOST value: "{{ .Values.global.redis.host }}" - name: REDIS_SERVER_PORT value: "{{ .Values.global.redis.port }}" - name: REDIS_SERVER_USER value: "{{ .Values.global.redis.username }}" - name: REDIS_SERVER_PASSWORD valueFrom: secretKeyRef: name: redis key: redis-password - name: REDIS_SERVER_DATABASE value: "{{ .Values.global.redis.database }}" - name: AFFINE_SERVER_PORT value: "{{ .Values.worker.app.port }}" - name: AFFINE_SERVER_HOST value: "{{ .Values.worker.app.host }}" - name: AFFINE_SERVER_HTTPS value: "{{ .Values.worker.app.https }}" ports: - name: http containerPort: {{ .Values.worker.app.port }} protocol: TCP livenessProbe: httpGet: path: /info port: http initialDelaySeconds: {{ default .Values.worker.probe.initialDelaySeconds .Values.worker.probe.liveness.initialDelaySeconds }} timeoutSeconds: {{ default .Values.worker.probe.timeoutSeconds .Values.worker.probe.liveness.timeoutSeconds }} periodSeconds: {{ default .Values.worker.probe.periodSeconds .Values.worker.probe.liveness.periodSeconds }} failureThreshold: {{ default .Values.worker.probe.failureThreshold .Values.worker.probe.liveness.failureThreshold }} successThreshold: {{ default .Values.worker.probe.successThreshold .Values.worker.probe.liveness.successThreshold }} readinessProbe: httpGet: path: /info port: http initialDelaySeconds: {{ default .Values.worker.probe.initialDelaySeconds .Values.worker.probe.readiness.initialDelaySeconds }} timeoutSeconds: {{ default .Values.worker.probe.timeoutSeconds .Values.worker.probe.readiness.timeoutSeconds }} periodSeconds: {{ default .Values.worker.probe.periodSeconds .Values.worker.probe.readiness.periodSeconds }} failureThreshold: {{ default .Values.worker.probe.failureThreshold .Values.worker.probe.readiness.failureThreshold }} successThreshold: {{ default .Values.worker.probe.successThreshold .Values.worker.probe.readiness.successThreshold }} resources: {{- toYaml .Values.worker.resources | nindent 12 }} volumeMounts: - name: indexer-config mountPath: /app/config.json subPath: config.json readOnly: true - name: tmp mountPath: /tmp volumes: - name: indexer-config secret: secretName: indexer - name: tmp emptyDir: {} {{- with .Values.worker.nodeSelector }} nodeSelector: {{- toYaml . | nindent 8 }} {{- end }} {{- with .Values.worker.affinity }} affinity: {{- toYaml . | nindent 8 }} {{- end }} {{- with .Values.worker.tolerations }} tolerations: {{- toYaml . | nindent 8 }} {{- end }}