From 977a031393f9eb0094300737ccc7ed8aeebd4ae3 Mon Sep 17 00:00:00 2001 From: cat-shark <1716967236@qq.com> Date: Mon, 20 Jul 2026 21:27:50 +0800 Subject: [PATCH] Add shared Kubernetes configuration files - Add k8s/configmap.yaml with shared environment variables - Add k8s/lpt-secrets.yaml template (secrets not committed) - Add k8s/regcred-secret.yaml template (managed by workflow) - Add k8s/README.md with deployment instructions - Remove incorrect deployment/service files from root k8s/ Co-Authored-By: Claude Opus 4.8 --- k8s/README.md | 131 ++++++++++++++++++++++++++++++++++++++++ k8s/configmap.yaml | 15 +++++ k8s/deployment.yaml | 62 ------------------- k8s/lpt-secrets.yaml | 33 ++++++++++ k8s/regcred-secret.yaml | 26 ++++++++ k8s/service.yaml | 15 ----- 6 files changed, 205 insertions(+), 77 deletions(-) create mode 100644 k8s/README.md create mode 100644 k8s/configmap.yaml delete mode 100644 k8s/deployment.yaml create mode 100644 k8s/lpt-secrets.yaml create mode 100644 k8s/regcred-secret.yaml delete mode 100644 k8s/service.yaml diff --git a/k8s/README.md b/k8s/README.md new file mode 100644 index 0000000..29abbe7 --- /dev/null +++ b/k8s/README.md @@ -0,0 +1,131 @@ +# Kubernetes Configuration for LPT Project + +This directory contains the shared Kubernetes configuration files for the LPT (Learning Progress Tracker) project. + +## Files + +### ConfigMap +- **`configmap.yaml`** - Shared environment variables for all services + - LLM API configuration (URL, model, timeout) + - Database connection string + - Service URLs + +### Secrets (Templates) +- **`lpt-secrets.yaml`** - Application secrets template + - LLM API key + - MySQL root password + - **⚠️ DO NOT commit real secrets!** Use the template to create secrets manually. + +- **`regcred-secret.yaml`** - Docker registry authentication template + - Used for pulling images from private registry (192.168.123.199:5000) + - **⚠️ Managed by Gitea Actions workflow** - DO NOT commit real credentials! + +### Service-Specific Configurations +Each service has its own `k8s/` directory with deployment and service configs: +- **`lpt-fe/k8s/`** - Frontend deployment (Nginx + Vue 3) +- **`lpt-be/k8s/`** - Backend deployment (Spring Boot) +- **`lpt-ai/k8s/`** - AI service deployment (Python FastAPI) + +## Deployment + +### Initial Setup + +1. **Create namespace**: + ```bash + kubectl create namespace lpt-dev + ``` + +2. **Apply shared ConfigMap**: + ```bash + kubectl apply -f k8s/configmap.yaml + ``` + +3. **Create secrets** (replace with actual values): + ```bash + # Application secrets + kubectl create secret generic lpt-secrets \ + --from-literal=llm-api-key= \ + --from-literal=mysql-root-password= \ + --namespace=lpt-dev + + # Registry credentials (for manual creation, or use Gitea workflow) + kubectl create secret docker-registry regcred \ + --docker-server=192.168.123.199:5000 \ + --docker-username=admin \ + --docker-password= \ + --namespace=lpt-dev + ``` + +4. **Deploy services**: + ```bash + # Frontend + kubectl apply -f lpt-fe/k8s/ + + # Backend + kubectl apply -f lpt-be/k8s/ + + # AI Service + kubectl apply -f lpt-ai/k8s/ + ``` + +### CI/CD Workflow + +The Gitea Actions workflows (`.gitea/workflows/deploy.yml` in each service) automatically: +1. Build Docker images +2. Push to private registry (192.168.123.199:5000) +3. Create/update `regcred` secret with credentials from Gitea secrets +4. Update deployment image tags + +**Required Gitea Secrets** (per repository): +- `REGISTRY_USERNAME`: Docker registry username (admin) +- `REGISTRY_PASSWORD`: Docker registry password + +## Verification + +Check deployment status: +```bash +kubectl get all -n lpt-dev +kubectl get configmap -n lpt-dev +kubectl get secret -n lpt-dev +``` + +View logs: +```bash +kubectl logs -f deployment/lpt-fe -n lpt-dev +kubectl logs -f deployment/lpt-be -n lpt-dev +kubectl logs -f deployment/lpt-ai -n lpt-dev +``` + +## Architecture + +``` +┌─────────────────┐ +│ lpt-fe:3000 │ (NodePort 30080) +│ Vue 3 + Nginx │ +└────────┬────────┘ + │ + ▼ +┌─────────────────┐ +│ lpt-be:8080 │ (NodePort 30088) +│ Spring Boot │ +└────────┬────────┘ + │ + ├─────────► MySQL (external) + │ + ▼ +┌─────────────────┐ +│ lpt-ai:5199 │ (ClusterIP) +│ FastAPI │ +└─────────────────┘ + │ + ▼ + LLM API (external) +``` + +## Notes + +- **Namespace**: All resources use `lpt-dev` namespace +- **Registry**: Private Docker registry at `192.168.123.199:5000` +- **Image Pull**: All deployments use `imagePullSecrets: [name: regcred]` +- **ConfigMap**: Shared config is mounted as environment variables +- **Secrets**: Sensitive data (API keys, passwords) stored in `lpt-secrets` diff --git a/k8s/configmap.yaml b/k8s/configmap.yaml new file mode 100644 index 0000000..53dc155 --- /dev/null +++ b/k8s/configmap.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: lpt-config + namespace: lpt-dev +data: + # LPT AI Service + LLM_API_URL: https://api.siliconflow.cn/v1/chat/completions + LLM_MODEL: Qwen/Qwen2.5-32B-Instruct + LLM_TIMEOUT_MS: "60000" + LPT_AI-SERVICE_URL: http://lpt-ai:5199 + PORT: "5199" + + # Spring Boot Database + SPRING_DATASOURCE_URL: jdbc:mysql://mysql:3306/learning_progress_tracker?allowPublicKeyRetrieval=true&characterEncoding=utf-8&useSSL=false&serverTimezone=GMT%2B8 diff --git a/k8s/deployment.yaml b/k8s/deployment.yaml deleted file mode 100644 index b5ffeff..0000000 --- a/k8s/deployment.yaml +++ /dev/null @@ -1,62 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: lpt-ai - namespace: lpt-dev - labels: - app: lpt-ai -spec: - replicas: 1 - selector: - matchLabels: - app: lpt-ai - strategy: - type: RollingUpdate - rollingUpdate: - maxSurge: 25% - maxUnavailable: 25% - template: - metadata: - labels: - app: lpt-ai - spec: - imagePullSecrets: - - name: regcred - containers: - - name: lpt-ai - image: 192.168.123.199:5000/lpt-ai:dev - imagePullPolicy: IfNotPresent - ports: - - containerPort: 5199 - env: - - name: LLM_API_KEY - valueFrom: - secretKeyRef: - name: lpt-secrets - key: llm-api-key - envFrom: - - configMapRef: - name: lpt-config - resources: - requests: - cpu: 100m - memory: 128Mi - limits: - cpu: 500m - memory: 256Mi - livenessProbe: - httpGet: - path: /health - port: 5199 - initialDelaySeconds: 10 - periodSeconds: 15 - timeoutSeconds: 5 - failureThreshold: 3 - readinessProbe: - httpGet: - path: /health - port: 5199 - initialDelaySeconds: 5 - periodSeconds: 5 - timeoutSeconds: 3 - failureThreshold: 3 diff --git a/k8s/lpt-secrets.yaml b/k8s/lpt-secrets.yaml new file mode 100644 index 0000000..c65a92e --- /dev/null +++ b/k8s/lpt-secrets.yaml @@ -0,0 +1,33 @@ +# LPT Application Secrets +# +# This file is a TEMPLATE - DO NOT commit real secrets to git! +# +# To create this secret: +# kubectl create secret generic lpt-secrets \ +# --from-literal=llm-api-key= \ +# --from-literal=mysql-root-password= \ +# --namespace=lpt-dev +# +# Or use kubectl apply with stringData: +# kubectl apply -f - < + # mysql-root-password: diff --git a/k8s/regcred-secret.yaml b/k8s/regcred-secret.yaml new file mode 100644 index 0000000..45c8bfb --- /dev/null +++ b/k8s/regcred-secret.yaml @@ -0,0 +1,26 @@ +# Docker Registry Secret for pulling images from private registry +# +# This file is a TEMPLATE - the actual secret is managed by Gitea Actions workflow +# and should NOT be committed with real credentials. +# +# To create this secret manually: +# kubectl create secret docker-registry regcred \ +# --docker-server=192.168.123.199:5000 \ +# --docker-username=admin \ +# --docker-password= \ +# --namespace=lpt-dev +# +# Or use the workflow which reads from Gitea secrets: +# - REGISTRY_USERNAME +# - REGISTRY_PASSWORD + +apiVersion: v1 +kind: Secret +metadata: + name: regcred + namespace: lpt-dev +type: kubernetes.io/dockerconfigjson +data: + # .dockerconfigjson: + # This is generated by the workflow - DO NOT commit real values here + .dockerconfigjson: "" diff --git a/k8s/service.yaml b/k8s/service.yaml deleted file mode 100644 index fbd01c6..0000000 --- a/k8s/service.yaml +++ /dev/null @@ -1,15 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: lpt-ai - namespace: lpt-dev - labels: - app: lpt-ai -spec: - type: ClusterIP - selector: - app: lpt-ai - ports: - - port: 5199 - targetPort: 5199 - protocol: TCP