++ add s3-proxy nginx service for vad

This commit is contained in:
Kochetkov S 2026-08-26 12:15:11 +03:00
parent d2df6afaa4
commit 8bbc158e49
6 changed files with 106 additions and 0 deletions

View File

@ -13,3 +13,4 @@ resources:
- ../../infrastructure/camunda/vad
- ../../infrastructure/zitadel/vad
- ../../infrastructure/istio-config/vad
- ../../infrastructure/s3-proxy/vad

View File

@ -0,0 +1,31 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: s3-proxy-nginx-conf
namespace: s3-proxy
data:
nginx.conf: |
worker_processes auto;
error_log /dev/stderr info;
events {
worker_connections 1024;
}
stream {
upstream minio_backend {
server 192.168.8.121:9000;
server 192.168.8.122:9000;
server 192.168.8.123:9000;
server 192.168.8.124:9000;
}
server {
listen 443 ssl;
ssl_certificate /vault/secrets/tls.crt;
ssl_certificate_key /vault/secrets/tls.key;
proxy_pass minio_backend;
proxy_connect_timeout 5s;
proxy_timeout 300s;
}
}

View File

@ -0,0 +1,56 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: s3-proxy
namespace: s3-proxy
spec:
replicas: 1
selector:
matchLabels:
app: s3-proxy
template:
metadata:
labels:
app: s3-proxy
annotations:
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "s3-proxy"
vault.hashicorp.com/auth-path: "auth/kubernetes"
vault.hashicorp.com/agent-inject-secret-tls.crt: "secrets/data/s3-proxy/tls"
vault.hashicorp.com/agent-inject-template-tls.crt: |
{{- with secret "secrets/data/s3-proxy/tls" -}}
{{ .Data.data.tls_crt }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-tls.key: "secrets/data/s3-proxy/tls"
vault.hashicorp.com/agent-inject-template-tls.key: |
{{- with secret "secrets/data/s3-proxy/tls" -}}
{{ .Data.data.tls_key }}
{{- end -}}
spec:
serviceAccountName: s3-proxy
hostNetwork: true
dnsPolicy: ClusterFirstWithHostNet
nodeSelector:
kubernetes.io/hostname: sarex-srv-generic-1
containers:
- name: nginx
image: nginx:1.25-alpine
volumeMounts:
- name: nginx-conf
mountPath: /etc/nginx/nginx.conf
subPath: nginx.conf
ports:
- name: s3-tls
containerPort: 443
hostPort: 443
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: nginx-conf
configMap:
name: s3-proxy-nginx-conf

View File

@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- serviceaccount.yaml
- configmap.yaml
- deployment.yaml

View File

@ -0,0 +1,6 @@
apiVersion: v1
kind: Namespace
metadata:
name: s3-proxy
labels:
istio-injection: disabled

View File

@ -0,0 +1,5 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: s3-proxy
namespace: s3-proxy