Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
85 changes: 85 additions & 0 deletions .github/workflows/teste-infra.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
name: teste-infra

on:
pull_request:
branches: [main]
paths:
- "apps/**"
- "argocd/**"
- "infra/aws/**"
- ".github/workflows/teste-infra.yml"
push:
branches: [main]
paths:
- "apps/**"
- "argocd/**"
- "infra/aws/**"
- ".github/workflows/teste-infra.yml"

permissions:
contents: read

jobs:
validar-kustomize:
runs-on: ubuntu-latest

steps:
- name: baixar codigo
uses: actions/checkout@v4

- name: instalar kubectl
uses: azure/setup-kubectl@v4

- name: renderizar manifests
run: kubectl kustomize apps > manifests-rendered.yaml

- name: validar schemas k8s
uses: docker://ghcr.io/yannh/kubeconform:v0.6.7
with:
entrypoint: /kubeconform
args: -strict -summary -skip InfisicalSecret /github/workspace/manifests-rendered.yaml

validar-terraform:
runs-on: ubuntu-latest

steps:
- name: baixar codigo
uses: actions/checkout@v4

- name: instalar terraform
uses: hashicorp/setup-terraform@v4
with:
terraform_version: 1.13.3

- name: verificar formatacao
run: terraform -chdir=infra/aws fmt -check

- name: inicializar sem backend
run: terraform -chdir=infra/aws init -backend=false -input=false

- name: validar terraform
run: terraform -chdir=infra/aws validate

validar-argocd:
runs-on: ubuntu-latest

steps:
- name: baixar codigo
uses: actions/checkout@v4

- name: validar estrutura da application
uses: mikefarah/yq@v4.52.1
with:
cmd: >-
yq -e '
.apiVersion == "argoproj.io/v1alpha1" and
.kind == "Application" and
.metadata.namespace == "argocd" and
.spec.source.repoURL == "https://github.com/AppActa/acta-platform.git" and
.spec.source.targetRevision == "main" and
.spec.source.path == "apps" and
.spec.destination.server == "https://kubernetes.default.svc" and
.spec.destination.namespace == "acta-prod" and
.spec.syncPolicy.automated.prune == true and
.spec.syncPolicy.automated.selfHeal == true
' argocd/prod.yaml
7 changes: 7 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
*.env
local/*.env
testes/
*.terraform
*.tfstate
terraform.tfvars
.aws/
46 changes: 46 additions & 0 deletions apps/config/pg-api-secrets.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret

metadata:
name: acta-pg-api-secrets

spec:
hostAPI: https://app.infisical.com/api

syncConfig:
resyncInterval: 60s
instantUpdates: false

authentication:
universalAuth:
credentialsRef:
secretName: infisical-universal-auth
secretNamespace: acta-prod
secretsScope:
projectId: 051dcf5e-00ed-4d46-8b36-baad0a621f5d
envSlug: prod
secretsPath: /pg-api
recursive: false

managedKubeSecretReferences:
- secretName: acta-pg-api-env
secretNamespace: acta-prod
creationPolicy: Owner

template:
includeAllSecrets: false
data:
DB_URL: "{{ .DB_URL.Value }}"
DB_USER: "{{ .DB_USER.Value }}"
DB_PASSWORD: "{{ .DB_PASSWORD.Value }}"
FIREBASE_PROJECT_ID: "{{ .FIREBASE_PROJECT_ID.Value }}"
CORS_ALLOWED_ORIGINS: "{{ .CORS_ALLOWED_ORIGINS.Value }}"

- secretName: firebase-admin
secretNamespace: acta-prod
creationPolicy: Owner

template:
includeAllSecrets: false
data:
service-account.json: "{{ .FIREBASE_SERVICE_ACCOUNT_JSON.Value }}"
8 changes: 8 additions & 0 deletions apps/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization

namespace: acta-prod

resources:
- pg-api.yaml
- config/pg-api-secrets.yaml
109 changes: 109 additions & 0 deletions apps/pg-api.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,109 @@
apiVersion: apps/v1
kind: Deployment

metadata:
name: acta-pg-api
annotations:
# reinicia os pods quando o infisical atualizar os secrets
secrets.infisical.com/auto-reload: "true"
labels:
app.kubernetes.io/name: acta-pg-api
app.kubernetes.io/part-of: acta

spec:
replicas: 3
revisionHistoryLimit: 3

selector:
matchLabels:
app.kubernetes.io/name: acta-pg-api

template:
metadata:
labels:
app.kubernetes.io/name: acta-pg-api
app.kubernetes.io/part-of: acta

spec:
containers:
- name: acta-pg-api
image: ghcr.io/appacta/acta-pg-api@sha256:760a2c439bc64494e69342166338a0f934b72354ee0a352444a596bbd6e6427d
imagePullPolicy: IfNotPresent

ports:
- name: http
containerPort: 8080
protocol: TCP

envFrom:
- secretRef:
name: acta-pg-api-env

env:
- name: GOOGLE_APPLICATION_CREDENTIALS
value: /var/run/secrets/firebase/service-account.json

# monta o json do firebase como arquivo somente leitura
volumeMounts:
- name: firebase-admin
mountPath: /var/run/secrets/firebase
readOnly: true

startupProbe:
tcpSocket:
port: http
periodSeconds: 5
failureThreshold: 60

readinessProbe:
httpGet:
path: /api/v1/health
port: http
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3

# verifica se o processo continua aceitando conexoes na porta
livenessProbe:
tcpSocket:
port: http
periodSeconds: 20
timeoutSeconds: 5
failureThreshold: 3

resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi

volumes:
- name: firebase-admin
secret:
secretName: firebase-admin
items:
- key: service-account.json
path: service-account.json
---
apiVersion: v1
kind: Service

metadata:
name: acta-pg-api
labels:
app.kubernetes.io/name: acta-pg-api
app.kubernetes.io/part-of: acta

spec:
type: ClusterIP

selector:
app.kubernetes.io/name: acta-pg-api

ports:
- name: http
port: 8080
targetPort: http
protocol: TCP
23 changes: 23 additions & 0 deletions argocd/prod.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
apiVersion: argoproj.io/v1alpha1
kind: Application

metadata:
name: acta-prod
namespace: argocd

spec:
project: default

source:
repoURL: https://github.com/AppActa/acta-platform.git
targetRevision: main
path: apps

destination:
server: https://kubernetes.default.svc
namespace: acta-prod

syncPolicy:
automated:
prune: true
selfHeal: true
Loading
Loading