-
Notifications
You must be signed in to change notification settings - Fork 0
/
kakera.yml
268 lines (250 loc) · 6.9 KB
/
kakera.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
---
kind: ConfigMap
apiVersion: v1
metadata:
name: kakera
labels:
app: kakera
data:
nginx.conf: |-
worker_processes auto;
daemon off;
error_log stderr info;
events {
worker_connections 1024;
multi_accept on;
}
http {
include /etc/nginx/mime.types;
default_type application/octet-stream;
sendfile on;
tcp_nopush on;
keepalive_timeout 65;
client_max_body_size 64M;
set_real_ip_from 0.0.0.0/0;
upstream kakera {
# Call the local instance, with no failure timeouts.
server 127.0.0.1:8000 fail_timeout=0;
# Fall back to calling another instance if the local one is dead.
server kakera.default.svc.cluster.local backup;
}
server {
listen 80 default_server;
server_name kazamatsuri.org new.kazamatsuri.org;
root /srv/www;
# Rewrite old WordPress URLs to their kakera equivalents
rewrite "^/[0-9]{4}/[0-9]{2}/[0-9]{2}/(.*)$" "/$1" permanent;
# Try to resolve real files in the www directory first, fall back to kakera
location / {
try_files $uri $uri/ @kakera;
error_page 403 = @kakera;
}
# Bypass kakera for media and static files
location /static {
expires 365d;
}
location /media {
expires 365d;
}
# Internal location for kakera
location @kakera {
proxy_pass http://kakera;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_redirect off;
}
# The real Podcast XML file is on Github Pages for easier publishing
location = /podcast.xml { return 302 http://podcast.kazamatsuri.org/feed.xml; }
# Podcast MP3s are now on S3
location ~ ^/podcast/?(.*)$ { return 302 https://kazamatsuri.s3.amazonaws.com/podcast/$1; }
# Redirects to the forum (thanks Youtube)
location ~ ^/go/t/(.*)$ { return 302 https://forum.kazamatsuri.org/t/$1; }
}
server {
listen 80;
server_name rokkenjima.org new.rokkenjima.org;
root /srv/www;
# Try to resolve real files in the www directory first, fall back to kakera
location / {
try_files $uri $uri/ @kakera;
error_page 403 = @kakera;
}
# Bypass kakera for media and static files
location /static {
expires 365d;
}
location /media {
expires 365d;
}
# Internal location for kakera
location @kakera {
proxy_pass http://kakera;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_redirect off;
}
# Redirects to the forum (thanks Youtube)
location ~ ^/go/t/(.*)$ { return 302 https://forum.rokkenjima.org/t/$1; }
}
}
---
kind: Service
apiVersion: v1
metadata:
name: kakera
labels:
app: kakera
spec:
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP
selector:
app: kakera
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: kakera-media
annotations:
volume.beta.kubernetes.io/storage-class: "slow"
spec:
accessModes:
- ReadWriteMany
resources:
requests:
storage: 1000Gi
---
kind: Deployment
apiVersion: extensions/v1beta1
metadata:
name: kakera
labels:
app: kakera
spec:
replicas: 2
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
template:
metadata:
labels:
app: kakera
spec:
containers:
- name: kakera
image: kazokuco/kakera
imagePullPolicy: Always
command: ["/bin/bash", "-c", "cp -R /srv/kakera/public/static/* /srv/www/static && ./manage.py migrate --noinput && ./docker_entrypoint.sh"]
env:
- name: SECRET_KEY
valueFrom:
secretKeyRef:
name: kakera
key: secret
- name: DB_ENGINE
value: django.db.backends.postgresql
- name: DB_HOST
value: postgresql.default.svc.cluster.local
- name: DB_PORT
value: "5432"
- name: DB_NAME
valueFrom:
secretKeyRef:
name: kakera
key: db.name
- name: DB_USER
valueFrom:
secretKeyRef:
name: kakera
key: db.username
- name: DB_PASSWORD
valueFrom:
secretKeyRef:
name: kakera
key: db.password
- name: REDIS_URL
value: redis://redis.default.svc.cluster.local:6379/0
- name: DEFAULT_FILE_STORAGE
value: storages.backends.s3boto3.S3Boto3Storage
- name: AWS_ACCESS_KEY_ID
valueFrom:
secretKeyRef:
name: kakera
key: aws.keyid
- name: AWS_SECRET_ACCESS_KEY
valueFrom:
secretKeyRef:
name: kakera
key: aws.key
- name: AWS_STORAGE_BUCKET_NAME
value: kakera
- name: AWS_S3_CUSTOM_DOMAIN
value: d31u62iyrzhln9.cloudfront.net
- name: CLOUDFLARE_EMAIL
valueFrom:
secretKeyRef:
name: cloudflare
key: email
- name: CLOUDFLARE_TOKEN
valueFrom:
secretKeyRef:
name: cloudflare
key: token
- name: GUNICORN_WORKERS
value: "8"
- name: GUNICORN_THREADS
value: "1"
readinessProbe:
httpGet:
path: /healthz/
port: gunicorn
httpHeaders:
- name: Accept
value: application/json
successThreshold: 6
ports:
- name: gunicorn
containerPort: 8000
protocol: TCP
volumeMounts:
- name: static
mountPath: /srv/www/static
- name: media
mountPath: /srv/kakera/public/media
- name: nginx
image: nginx:1
imagePullPolicy: Always
command: ["nginx", "-c", "/etc/config/nginx.conf"]
readinessProbe:
httpGet:
path: /healthz/
port: http
httpHeaders:
- name: Accept
value: application/json
ports:
- name: http
containerPort: 80
protocol: TCP
volumeMounts:
- name: config
mountPath: /etc/config
- name: static
mountPath: /srv/www/static
- name: media
mountPath: /srv/www/media
volumes:
- name: config
configMap:
name: kakera
- name: static
emptyDir: {}
- name: media
persistentVolumeClaim:
claimName: kakera-media