# Kubernetes Configuration for LPT Project This directory contains the shared Kubernetes configuration files for the LPT (Learning Progress Tracker) project. ## Files ### ConfigMap - **`configmap.yaml`** - Shared environment variables for all services - LLM API configuration (URL, model, timeout) - Database connection string - Service URLs ### Secrets (Templates) - **`lpt-secrets.yaml`** - Application secrets template - LLM API key - MySQL root password - **⚠️ DO NOT commit real secrets!** Use the template to create secrets manually. - **`regcred-secret.yaml`** - Docker registry authentication template - Used for pulling images from private registry (192.168.123.199:5000) - **⚠️ Managed by Gitea Actions workflow** - DO NOT commit real credentials! ### Service-Specific Configurations Each service has its own `k8s/` directory with deployment and service configs: - **`lpt-fe/k8s/`** - Frontend deployment (Nginx + Vue 3) - **`lpt-be/k8s/`** - Backend deployment (Spring Boot) - **`lpt-ai/k8s/`** - AI service deployment (Python FastAPI) ## Deployment ### Initial Setup 1. **Create namespace**: ```bash kubectl create namespace lpt-dev ``` 2. **Apply shared ConfigMap**: ```bash kubectl apply -f k8s/configmap.yaml ``` 3. **Create secrets** (replace with actual values): ```bash # Application secrets kubectl create secret generic lpt-secrets \ --from-literal=llm-api-key= \ --from-literal=mysql-root-password= \ --namespace=lpt-dev # Registry credentials (for manual creation, or use Gitea workflow) kubectl create secret docker-registry regcred \ --docker-server=192.168.123.199:5000 \ --docker-username=admin \ --docker-password= \ --namespace=lpt-dev ``` 4. **Deploy services**: ```bash # Frontend kubectl apply -f lpt-fe/k8s/ # Backend kubectl apply -f lpt-be/k8s/ # AI Service kubectl apply -f lpt-ai/k8s/ ``` ### CI/CD Workflow The Gitea Actions workflows (`.gitea/workflows/deploy.yml` in each service) automatically: 1. Build Docker images 2. Push to private registry (192.168.123.199:5000) 3. Create/update `regcred` secret with credentials from Gitea secrets 4. Update deployment image tags **Required Gitea Secrets** (per repository): - `REGISTRY_USERNAME`: Docker registry username (admin) - `REGISTRY_PASSWORD`: Docker registry password ## Verification Check deployment status: ```bash kubectl get all -n lpt-dev kubectl get configmap -n lpt-dev kubectl get secret -n lpt-dev ``` View logs: ```bash kubectl logs -f deployment/lpt-fe -n lpt-dev kubectl logs -f deployment/lpt-be -n lpt-dev kubectl logs -f deployment/lpt-ai -n lpt-dev ``` ## Architecture ``` ┌─────────────────┐ │ lpt-fe:3000 │ (NodePort 30080) │ Vue 3 + Nginx │ └────────┬────────┘ │ ▼ ┌─────────────────┐ │ lpt-be:8080 │ (NodePort 30088) │ Spring Boot │ └────────┬────────┘ │ ├─────────► MySQL (external) │ ▼ ┌─────────────────┐ │ lpt-ai:5199 │ (ClusterIP) │ FastAPI │ └─────────────────┘ │ ▼ LLM API (external) ``` ## Notes - **Namespace**: All resources use `lpt-dev` namespace - **Registry**: Private Docker registry at `192.168.123.199:5000` - **Image Pull**: All deployments use `imagePullSecrets: [name: regcred]` - **ConfigMap**: Shared config is mounted as environment variables - **Secrets**: Sensitive data (API keys, passwords) stored in `lpt-secrets`