- Transition to VMSS identity for flexvol - Update some environment variables for cloudzero dev - Overlay for applying migrations - Updates to disable CDN, which will not be available - Removes CronJob for resetting the database; don't need that in this cluster for now.
78 lines
2.3 KiB
YAML
78 lines
2.3 KiB
YAML
apiVersion: extensions/v1beta1
|
|
kind: Deployment
|
|
metadata:
|
|
name: atst
|
|
spec:
|
|
template:
|
|
spec:
|
|
volumes:
|
|
- name: nginx-secret
|
|
flexVolume:
|
|
options:
|
|
usepodidentity: "false"
|
|
usevmmanagedidentity: "true"
|
|
vmmanagedidentityclientid: $VMSS_CLIENT_ID
|
|
keyvaultname: "cz-jedidev-keyvault"
|
|
keyvaultobjectnames: "dhparam4096;ATATCERT;ATATCERT"
|
|
- name: flask-secret
|
|
flexVolume:
|
|
options:
|
|
usepodidentity: "false"
|
|
usevmmanagedidentity: "true"
|
|
vmmanagedidentityclientid: $VMSS_CLIENT_ID
|
|
keyvaultname: "cz-jedidev-keyvault"
|
|
keyvaultobjectnames: "AZURE-STORAGE-KEY;MAIL-PASSWORD;PGPASSWORD;REDIS-PASSWORD;SECRET-KEY"
|
|
---
|
|
apiVersion: extensions/v1beta1
|
|
kind: Deployment
|
|
metadata:
|
|
name: atst-worker
|
|
spec:
|
|
template:
|
|
spec:
|
|
volumes:
|
|
- name: flask-secret
|
|
flexVolume:
|
|
options:
|
|
usepodidentity: "false"
|
|
usevmmanagedidentity: "true"
|
|
vmmanagedidentityclientid: $VMSS_CLIENT_ID
|
|
keyvaultname: "cz-jedidev-keyvault"
|
|
keyvaultobjectnames: "AZURE-STORAGE-KEY;MAIL-PASSWORD;PGPASSWORD;REDIS-PASSWORD;SECRET-KEY"
|
|
---
|
|
apiVersion: extensions/v1beta1
|
|
kind: Deployment
|
|
metadata:
|
|
name: atst-beat
|
|
spec:
|
|
template:
|
|
spec:
|
|
volumes:
|
|
- name: flask-secret
|
|
flexVolume:
|
|
options:
|
|
usepodidentity: "false"
|
|
usevmmanagedidentity: "true"
|
|
vmmanagedidentityclientid: $VMSS_CLIENT_ID
|
|
keyvaultname: "cz-jedidev-keyvault"
|
|
keyvaultobjectnames: "AZURE-STORAGE-KEY;MAIL-PASSWORD;PGPASSWORD;REDIS-PASSWORD;SECRET-KEY"
|
|
---
|
|
apiVersion: batch/v1beta1
|
|
kind: CronJob
|
|
metadata:
|
|
name: crls
|
|
spec:
|
|
jobTemplate:
|
|
spec:
|
|
template:
|
|
spec:
|
|
volumes:
|
|
- name: flask-secret
|
|
flexVolume:
|
|
options:
|
|
usepodidentity: "false"
|
|
usevmmanagedidentity: "true"
|
|
vmmanagedidentityclientid: $VMSS_CLIENT_ID
|
|
keyvaultname: "cz-jedidev-keyvault"
|
|
keyvaultobjectnames: "AZURE-STORAGE-KEY;MAIL-PASSWORD;PGPASSWORD;REDIS-PASSWORD;SECRET-KEY"
|