111 lines
3.9 KiB
YAML
111 lines
3.9 KiB
YAML
# infrastructure/traefik/deployment.yaml
|
|
apiVersion: v1
|
|
items:
|
|
- apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: traefik
|
|
namespace: traefik
|
|
spec:
|
|
progressDeadlineSeconds: 600
|
|
replicas: 2
|
|
revisionHistoryLimit: 10
|
|
selector:
|
|
matchLabels:
|
|
app: traefik
|
|
strategy:
|
|
rollingUpdate:
|
|
maxSurge: 1
|
|
maxUnavailable: 0
|
|
type: RollingUpdate
|
|
template:
|
|
metadata:
|
|
annotations:
|
|
descheduler.alpha.kubernetes.io/evict: "false"
|
|
kubectl.kubernetes.io/restartedAt: "2025-02-12T05:57:48-06:00"
|
|
creationTimestamp: null
|
|
labels:
|
|
app: traefik
|
|
app.kubernetes.io/instance: traefik-kube-system
|
|
app.kubernetes.io/name: traefik
|
|
spec:
|
|
containers:
|
|
- args:
|
|
- --providers.kubernetesIngress=true
|
|
- --providers.kubernetescrd=true
|
|
- --entrypoints.web.address=:80
|
|
- --entrypoints.websecure.address=:443
|
|
- --api.dashboard=true
|
|
- --metrics.prometheus=true
|
|
- --metrics.prometheus.addEntryPointsLabels=true
|
|
- --metrics.prometheus.addRoutersLabels=true
|
|
- --metrics.prometheus.addServicesLabels=true
|
|
- --entrypoints.web.transport.respondingTimeouts.readTimeout=0s
|
|
- --entrypoints.web.transport.respondingTimeouts.writeTimeout=0s
|
|
- --entrypoints.web.transport.respondingTimeouts.idleTimeout=0s
|
|
- --entrypoints.websecure.transport.respondingTimeouts.readTimeout=0s
|
|
- --entrypoints.websecure.transport.respondingTimeouts.writeTimeout=0s
|
|
- --entrypoints.websecure.transport.respondingTimeouts.idleTimeout=0s
|
|
- --ping=true
|
|
- --ping.entrypoint=health
|
|
- --entrypoints.health.address=:8082
|
|
- --entrypoints.web.transport.lifecycle.requestacceptgracetimeout=10s
|
|
- --entrypoints.web.transport.lifecycle.gracetimeout=300s
|
|
- --entrypoints.websecure.transport.lifecycle.requestacceptgracetimeout=10s
|
|
- --entrypoints.websecure.transport.lifecycle.gracetimeout=300s
|
|
- --entrypoints.metrics.address=:9100
|
|
- --metrics.prometheus.entryPoint=metrics
|
|
image: traefik:v3.3.3@sha256:19884a9d0b922b321c9cff54cbfe43f3169893041b8dd4ea6100677afaddce46
|
|
imagePullPolicy: IfNotPresent
|
|
name: traefik
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 512Mi
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /ping
|
|
port: health
|
|
periodSeconds: 5
|
|
timeoutSeconds: 3
|
|
failureThreshold: 3
|
|
ports:
|
|
- containerPort: 8082
|
|
name: health
|
|
protocol: TCP
|
|
- containerPort: 80
|
|
name: web
|
|
protocol: TCP
|
|
- containerPort: 443
|
|
name: websecure
|
|
protocol: TCP
|
|
- containerPort: 8080
|
|
name: admin
|
|
protocol: TCP
|
|
- containerPort: 9100
|
|
name: metrics
|
|
protocol: TCP
|
|
terminationMessagePath: /dev/termination-log
|
|
terminationMessagePolicy: File
|
|
dnsPolicy: ClusterFirst
|
|
# Stable NVMe hosts keep ingress away from CI and storage-worker I/O.
|
|
nodeSelector:
|
|
node-role.kubernetes.io/control-plane: "true"
|
|
affinity:
|
|
podAntiAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
- labelSelector:
|
|
matchLabels:
|
|
app: traefik
|
|
topologyKey: kubernetes.io/hostname
|
|
restartPolicy: Always
|
|
schedulerName: default-scheduler
|
|
serviceAccount: atlas-traefik-ingress-controller
|
|
serviceAccountName: atlas-traefik-ingress-controller
|
|
terminationGracePeriodSeconds: 330
|
|
kind: List
|
|
metadata: {}
|