Files
cat-shark 977a031393 Add shared Kubernetes configuration files
- Add k8s/configmap.yaml with shared environment variables
- Add k8s/lpt-secrets.yaml template (secrets not committed)
- Add k8s/regcred-secret.yaml template (managed by workflow)
- Add k8s/README.md with deployment instructions
- Remove incorrect deployment/service files from root k8s/

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-20 21:27:50 +08:00

3.8 KiB

Kubernetes Configuration for LPT Project

This directory contains the shared Kubernetes configuration files for the LPT (Learning Progress Tracker) project.

Files

ConfigMap

  • configmap.yaml - Shared environment variables for all services
    • LLM API configuration (URL, model, timeout)
    • Database connection string
    • Service URLs

Secrets (Templates)

  • lpt-secrets.yaml - Application secrets template

    • LLM API key
    • MySQL root password
    • ⚠️ DO NOT commit real secrets! Use the template to create secrets manually.
  • regcred-secret.yaml - Docker registry authentication template

    • Used for pulling images from private registry (192.168.123.199:5000)
    • ⚠️ Managed by Gitea Actions workflow - DO NOT commit real credentials!

Service-Specific Configurations

Each service has its own k8s/ directory with deployment and service configs:

  • lpt-fe/k8s/ - Frontend deployment (Nginx + Vue 3)
  • lpt-be/k8s/ - Backend deployment (Spring Boot)
  • lpt-ai/k8s/ - AI service deployment (Python FastAPI)

Deployment

Initial Setup

  1. Create namespace:

    kubectl create namespace lpt-dev
    
  2. Apply shared ConfigMap:

    kubectl apply -f k8s/configmap.yaml
    
  3. Create secrets (replace with actual values):

    # Application secrets
    kubectl create secret generic lpt-secrets \
      --from-literal=llm-api-key=<YOUR_LLM_API_KEY> \
      --from-literal=mysql-root-password=<YOUR_MYSQL_ROOT_PASSWORD> \
      --namespace=lpt-dev
    
    # Registry credentials (for manual creation, or use Gitea workflow)
    kubectl create secret docker-registry regcred \
      --docker-server=192.168.123.199:5000 \
      --docker-username=admin \
      --docker-password=<REGISTRY_PASSWORD> \
      --namespace=lpt-dev
    
  4. Deploy services:

    # Frontend
    kubectl apply -f lpt-fe/k8s/
    
    # Backend
    kubectl apply -f lpt-be/k8s/
    
    # AI Service
    kubectl apply -f lpt-ai/k8s/
    

CI/CD Workflow

The Gitea Actions workflows (.gitea/workflows/deploy.yml in each service) automatically:

  1. Build Docker images
  2. Push to private registry (192.168.123.199:5000)
  3. Create/update regcred secret with credentials from Gitea secrets
  4. Update deployment image tags

Required Gitea Secrets (per repository):

  • REGISTRY_USERNAME: Docker registry username (admin)
  • REGISTRY_PASSWORD: Docker registry password

Verification

Check deployment status:

kubectl get all -n lpt-dev
kubectl get configmap -n lpt-dev
kubectl get secret -n lpt-dev

View logs:

kubectl logs -f deployment/lpt-fe -n lpt-dev
kubectl logs -f deployment/lpt-be -n lpt-dev
kubectl logs -f deployment/lpt-ai -n lpt-dev

Architecture

┌─────────────────┐
│   lpt-fe:3000   │ (NodePort 30080)
│   Vue 3 + Nginx │
└────────┬────────┘
         │
         ▼
┌─────────────────┐
│   lpt-be:8080   │ (NodePort 30088)
│   Spring Boot   │
└────────┬────────┘
         │
         ├─────────► MySQL (external)
         │
         ▼
┌─────────────────┐
│  lpt-ai:5199    │ (ClusterIP)
│  FastAPI        │
└─────────────────┘
         │
         ▼
   LLM API (external)

Notes

  • Namespace: All resources use lpt-dev namespace
  • Registry: Private Docker registry at 192.168.123.199:5000
  • Image Pull: All deployments use imagePullSecrets: [name: regcred]
  • ConfigMap: Shared config is mounted as environment variables
  • Secrets: Sensitive data (API keys, passwords) stored in lpt-secrets