Skip to content

Commit

Permalink
Added Switcher Resolver API
Browse files Browse the repository at this point in the history
  • Loading branch information
petruki committed Nov 26, 2023
1 parent ad4cdfa commit 9262210
Show file tree
Hide file tree
Showing 10 changed files with 280 additions and 10 deletions.
35 changes: 29 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

# Switcher API Helm Charts

Deploy Switcher API and Switcher Management using `switcherapi/switcher-api` Helm Charts.
Deploy Switcher API using `switcherapi/switcher-api` Helm Charts.

## Usage

Expand Down Expand Up @@ -58,18 +58,18 @@ helm uninstall switcherapi --namespace switcherapi
| `api.env.resourceSecret` | API Swagger (user: admin) | `admin` |
| `api.env.switcherApiLogger` | API log | true |
| `api.env.historyActivated` | API Change Log record | true |
| `api.env.metricsActivated` | API Metrics record | true |
| `api.env.metricsActivated` | (*) API Metrics record | true |
| `api.env.permissionCacheActivated` | API Permission Cache | true |
| `api.env.googleSkipAuth` | Skip Google ReCaptcha validation | true |
| `api.env.metricsMaxPage` | Metrics: max logs per page | 50 |
| `api.env.strategyMaxOperation` | Strategy: max operation entries | 100 |
| `api.env.relayBypassHttps` | Relay: Bypass HTTPS validation | false |
| `api.env.relayBypassVerification` | Relay: Bypass Verification | false |
| `api.env.regexMaxTimeout` | Regex Validator: max timeout in ms | 3000 |
| `api.env.regexMaxBlacklist` | Regex Validator: max blacklist entries | 50 |
| `api.env.maxRequestPerMinute` | API max Request per minute | 0 (unlimited) |
| `api.env.regexMaxTimeout` | (*) Regex Validator: max timeout in ms | 3000 |
| `api.env.regexMaxBlacklist` | (*) Regex Validator: max blacklist entries | 50 |
| `api.env.maxRequestPerMinute` | (*) API max Request per minute | 0 (unlimited) |
| `api.env.jwtAdminTokenRenewInterval` | User token renew interval | `5m` |
| `api.env.jwtClientTokenExpTime` | Component token renew interval | `5m` |
| `api.env.jwtClientTokenExpTime` | (*) Component token renew interval | `5m` |
| `api.env.mongoUri` | API Database URI | < see values.yml > |
| `api.env.bitbucketClientId` | Bitbucket Client Id | `` |
| `api.env.bitbucketClientSecret` | Bitbucket Client Secret | `` |
Expand All @@ -78,6 +78,29 @@ helm uninstall switcherapi --namespace switcherapi
| `api.env.googleRecaptchaSecret` | Google ReCaptcha Secret | `` |
| `api.env.switcherSlackJwtSecret` | Switcher Slack Secret | `` |

(*) - Depracated parameters will be removed in future versions. Those are now managed by the Resolver API.

### Resolver API parameters

| Name | Description | Value |
| ------------------------------- | ---------------------------------------------- | ---------------------- |
| `resolver.image.tag` | Switcher Resolver Image tag | `latest` |
| `resolver.service.port` | API Service port | 3001 |

| Name | Description | Value |
| ------------------------------------------ | --------------------------------------------- | --------------------- |
| `resolver.env.sslSecretName` | API SSL Secret Name (enable HTTPS) | `` |
| `resolver.env.resourceSecret` | API Swagger (user: admin) | `admin` |
| `resolver.env.switcherApiLogger` | API log | true |
| `resolver.env.metricsActivated` | API Metrics record | true |
| `resolver.env.relayBypassHttps` | Relay: Bypass HTTPS validation | false |
| `resolver.env.relayBypassVerification` | Relay: Bypass Verification | false |
| `resolver.env.regexMaxTimeout` | Regex Validator: max timeout in ms | 3000 |
| `resolver.env.regexMaxBlacklist` | Regex Validator: max blacklist entries | 50 |
| `resolver.env.maxRequestPerMinute` | API max Request per minute | 0 (unlimited) |
| `resolver.env.jwtClientTokenExpTime` | Component token renew interval | `5m` |
| `resolver.env.mongoUri` | API Database URI | < see values.yml > |

### Management parameters

| Name | Description | Value |
Expand Down
2 changes: 1 addition & 1 deletion charts/switcher-api/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,5 +9,5 @@ maintainers:
url: https://github.com/petruki

type: application
version: 1.1.1
version: 1.2.0
appVersion: "latest"
13 changes: 11 additions & 2 deletions charts/switcher-api/templates/NOTES.txt
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
Looks good! To access Switcher API, follow the 3 steps below:
Looks good! To get started, you need to run the following commands:

1. Port-forward UI and API services:

kubectl -n {{ .Release.Namespace }} port-forward svc/switcher-api {{ .Values.api.port }}:{{ .Values.api.service.port }} & \
kubectl -n {{ .Release.Namespace }} port-forward svc/switcher-resolver {{ .Values.resolver.port }}:{{ .Values.resolver.service.port }} & \
{{- if .Values.api.env.sslSecretName }}
kubectl -n {{ .Release.Namespace }} port-forward svc/switcher-management {{ .Values.management.service.port }}:{{ .Values.management.service.portTls }} &
{{- else }}
Expand All @@ -17,4 +18,12 @@ Looks good! To access Switcher API, follow the 3 steps below:
http://localhost:{{ .Values.management.service.port }}
{{- end }}

3. Happy Switcher!
3. Access Resolver API (use one of the Client SDKs):

{{- if .Values.api.env.sslSecretName }}
https://localhost:{{ .Values.resolver.service.port }}
{{- else }}
http://localhost:{{ .Values.resolver.service.port }}
{{- end }}

Happy Switcher!
52 changes: 52 additions & 0 deletions charts/switcher-api/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,58 @@ app.kubernetes.io/name: {{ include "switcher-api.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

{{/*
Expand the name of the chart.
*/}}
{{- define "switcher-resolver.name" -}}
{{- default .Chart.Name .Values.resolver.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}

{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
*/}}
{{- define "switcher-resolver.fullname" -}}
{{- if .Values.resolver.fullnameOverride }}
{{- .Values.resolver.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.resolver.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}

{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "switcher-resolver.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}

{{/*
Common labels
*/}}
{{- define "switcher-resolver.labels" -}}
helm.sh/chart: {{ include "switcher-resolver.chart" . }}
{{ include "switcher-resolver.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}

{{/*
Selector labels
*/}}
{{- define "switcher-resolver.selectorLabels" -}}
app.kubernetes.io/name: {{ include "switcher-resolver.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

{{/*
Expand the name of the chart.
*/}}
Expand Down
2 changes: 1 addition & 1 deletion charts/switcher-api/templates/api/configmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ data:
RELAY_BYPASS_HTTPS: {{ .Values.api.env.relayBypassHttps | quote }}
RELAY_BYPASS_VERIFICATION: {{ .Values.api.env.relayBypassVerification | quote }}
REGEX_MAX_TIMEOUT: {{ default 3000 .Values.api.env.regexMaxTimeout | quote }}
REGEX_MAX_BLACLIST: {{ default 50 .Values.api.env.regexMaxBlacklist | quote }}
REGEX_MAX_BLACKLIST: {{ default 50 .Values.api.env.regexMaxBlacklist | quote }}
MAX_REQUEST_PER_MINUTE: {{ default 0 .Values.api.env.maxRequestPerMinute | quote }}
JWT_ADMIN_TOKEN_RENEW_INTERVAL: {{ default "5m" .Values.api.env.jwtAdminTokenRenewInterval | quote }}
JWT_CLIENT_TOKEN_EXP_TIME: {{ default "5m" .Values.api.env.jwtClientTokenExpTime | quote }}
Expand Down
23 changes: 23 additions & 0 deletions charts/switcher-api/templates/resolver/configmap.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
apiVersion: v1
kind: ConfigMap
metadata:
namespace: {{ .Release.Namespace }}
name: switcher-resolver
labels:
{{- include "switcher-resolver.labels" . | nindent 4 }}
data:
# SSL settings
{{- if .Values.resolver.env.sslSecretName }}
SSL_CERT: "/etc/certs/tls.crt"
SSL_KEY: "/etc/certs/tls.key"
{{- end -}}

# Global settings
SWITCHER_API_LOGGER: {{ .Values.resolver.env.switcherApiLogger | quote }}
METRICS_ACTIVATED: {{ .Values.resolver.env.metricsActivated | quote }}
RELAY_BYPASS_HTTPS: {{ .Values.resolver.env.relayBypassHttps | quote }}
RELAY_BYPASS_VERIFICATION: {{ .Values.resolver.env.relayBypassVerification | quote }}
REGEX_MAX_TIMEOUT: {{ default 3000 .Values.resolver.env.regexMaxTimeout | quote }}
REGEX_MAX_BLACKLIST: {{ default 50 .Values.resolver.env.regexMaxBlacklist | quote }}
MAX_REQUEST_PER_MINUTE: {{ default 0 .Values.resolver.env.maxRequestPerMinute | quote }}
JWT_CLIENT_TOKEN_EXP_TIME: {{ default "5m" .Values.resolver.env.jwtClientTokenExpTime | quote }}
79 changes: 79 additions & 0 deletions charts/switcher-api/templates/resolver/deployment.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
apiVersion: apps/v1
kind: Deployment
metadata:
namespace: {{ .Release.Namespace }}
name: switcher-resolver
labels:
{{- include "switcher-resolver.labels" . | nindent 4 }}
spec:
{{- if not .Values.resolver.autoscaling.enabled }}
replicas: {{ .Values.resolver.replicaCount }}
{{- end }}
selector:
matchLabels:
{{- include "switcher-resolver.selectorLabels" . | nindent 6 }}
template:
metadata:
{{- with .Values.resolver.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
labels:
{{- include "switcher-resolver.selectorLabels" . | nindent 8 }}
spec:
{{- with .Values.resolver.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if .Values.resolver.env.sslSecretName }}
volumes:
- name: secret-tls
secret:
secretName: {{ .Values.resolver.env.sslSecretName }}
{{- end }}
containers:
- name: {{ .Chart.Name }}
securityContext:
{{- toYaml .Values.resolver.securityContext | nindent 12 }}
image: "{{ .Values.resolver.image.repository }}:{{ .Values.resolver.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.resolver.image.pullPolicy }}
ports:
- name: http
containerPort: {{ .Values.resolver.port }}
protocol: TCP
readinessProbe:
httpGet:
path: /check
port: http
{{- if .Values.resolver.env.sslSecretName }}
scheme: HTTPS
{{- else }}
scheme: HTTP
{{- end }}
resources:
{{- toYaml .Values.resolver.resources | nindent 12 }}
env:
- name: PORT
value: "{{ .Values.resolver.port }}"
envFrom:
{{- with .Values.resolver.envFrom }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if .Values.resolver.env.sslSecretName }}
volumeMounts:
- name: secret-tls
mountPath: /etc/certs
readOnly: true
{{- end }}
{{- with .Values.resolver.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.resolver.affinity }}
affinity:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.resolver.tolerations }}
tolerations:
{{- toYaml . | nindent 8 }}
{{- end }}
12 changes: 12 additions & 0 deletions charts/switcher-api/templates/resolver/secret.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
apiVersion: v1
kind: Secret
metadata:
namespace: {{ .Release.Namespace }}
name: switcher-resolver
labels:
{{- include "switcher-resolver.labels" . | nindent 4 }}
type: Opaque
data:
JWT_SECRET: {{ randAlphaNum 16 | b64enc | quote }}
MONGODB_URI: {{ .Values.resolver.env.mongoUri | b64enc | quote }}
RESOURCE_SECRET: {{ default "admin" .Values.resolver.env.resourceSecret | b64enc | quote }}
16 changes: 16 additions & 0 deletions charts/switcher-api/templates/resolver/service.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
apiVersion: v1
kind: Service
metadata:
namespace: {{ .Release.Namespace }}
name: switcher-resolver
labels:
{{- include "switcher-resolver.labels" . | nindent 4 }}
spec:
type: {{ .Values.resolver.service.type }}
ports:
- port: {{ .Values.resolver.service.port }}
targetPort: http
protocol: TCP
name: http
selector:
{{- include "switcher-resolver.selectorLabels" . | nindent 4 }}
56 changes: 56 additions & 0 deletions charts/switcher-api/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,62 @@ api:
tolerations: []
affinity: {}

resolver:
replicaCount: 1
port: 3001

env:
mongoUri: mongodb://db-mongodb.switcherapi.svc.cluster.local:27017/switcher-api
switcherApiLogger: true
metricsActivated: true

# Enable SSL (tls.crt and tls.key)
sslSecretName: ""

image:
repository: trackerforce/switcher-resolver-node
pullPolicy: IfNotPresent
tag: "latest"

envFrom:
- configMapRef:
name: switcher-resolver
- secretRef:
name: switcher-resolver

imagePullSecrets: []
nameOverride: "switcher-resolver"
fullnameOverride: ""

podAnnotations: {}

service:
type: ClusterIP
port: 3001

resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi

autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80

nodeSelector: {}
tolerations: []
affinity: {}

management:
replicaCount: 1
port: 80
Expand Down

0 comments on commit 9262210

Please sign in to comment.