Merge pull request #1692 from P4sca1/k8s-shuffle-app-ports

feat(k8s): allow to change exposed app port
This commit is contained in:
Frikky
2025-05-18 22:49:05 +02:00
committed by GitHub
7 changed files with 52 additions and 17 deletions
+14 -3
View File
@@ -514,8 +514,20 @@ The password should be provided with the `SHUFFLE_OPENSEARCH_PASSWORD` env varia
### app Parameters ### app Parameters
| Name | Description | Value | | Name | Description | Value |
| ------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------- | | ------------------------------------------------- | ---------------------------------------------------------------------------------- | ------ |
| `app.serviceAccount.create` | Specifies whether a ServiceAccount should be created | `true` |
| `app.serviceAccount.name` | The name of the ServiceAccount to use. | `""` |
| `app.serviceAccount.annotations` | Additional Service Account annotations (evaluated as a template) | `{}` |
| `app.serviceAccount.automountServiceAccountToken` | Automount service account token for the app service account | `true` |
| `app.serviceAccount.imagePullSecrets` | Add image pull secrets to the app service account | `[]` |
| `app.rbac.create` | Specifies whether RBAC resources should be created | `true` |
| `app.networkPolicy.enabled` | Specifies whether a NetworkPolicy should be created | `true` |
| `app.networkPolicy.allowExternal` | Don't require server label for connections | `true` |
| `app.networkPolicy.allowExternalEgress` | Allow the pod to access any range of port and all destinations. | `true` |
| `app.networkPolicy.extraIngress` | Add extra ingress rules to the NetworkPolicy | `[]` |
| `app.networkPolicy.extraEgress` | Add extra ingress rules to the NetworkPolicy (ignored if allowExternalEgress=true) | `[]` |
| `app.exposedContainerPort` | The port that shuffle app containers will listen on for new requests. | `80` |
| `app.podSecurityContext.enabled` | Enable app pods' Security Context | `true` | | `app.podSecurityContext.enabled` | Enable app pods' Security Context | `true` |
| `app.podSecurityContext.fsGroupChangePolicy` | Set filesystem group change policy for app pods | `Always` | | `app.podSecurityContext.fsGroupChangePolicy` | Set filesystem group change policy for app pods | `Always` |
| `app.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface for app pods | `[]` | | `app.podSecurityContext.sysctls` | Set kernel settings using the sysctl interface for app pods | `[]` |
@@ -640,4 +652,3 @@ The password should be provided with the `SHUFFLE_OPENSEARCH_PASSWORD` env varia
### Other Parameters ### Other Parameters
@@ -88,6 +88,8 @@ spec:
value: "true" value: "true"
- name: SHUFFLE_WORKER_SERVICE_ACCOUNT_NAME - name: SHUFFLE_WORKER_SERVICE_ACCOUNT_NAME
value: {{ include "shuffle.worker.serviceAccount.name" . }} value: {{ include "shuffle.worker.serviceAccount.name" . }}
- name: SHUFFLE_APP_EXPOSED_PORT
value: {{ .Values.app.exposedContainerPort | quote }}
{{- if .Values.worker.podSecurityContext.enabled }} {{- if .Values.worker.podSecurityContext.enabled }}
- name: SHUFFLE_WORKER_POD_SECURITY_CONTEXT - name: SHUFFLE_WORKER_POD_SECURITY_CONTEXT
value: {{ omit .Values.worker.podSecurityContext "enabled" | mustToJson | quote }} value: {{ omit .Values.worker.podSecurityContext "enabled" | mustToJson | quote }}
@@ -54,17 +54,18 @@ spec:
{{- end }} {{- end }}
{{- end }} {{- end }}
ingress: ingress:
{{- if .Values.app.networkPolicy.allowExternal }} - ports:
- {} - port: {{ .Values.app.exposedContainerPort }}
{{- else }} protocol: TCP
# Allow access from workers. Apps will typicaly use port 80/TCP, but this is not enforced. {{- if not .Values.app.networkPolicy.allowExternal }}
- from: # Allow traffic from workers
from:
- namespaceSelector: - namespaceSelector:
matchLabels: matchLabels:
kubernetes.io/metadata.name: {{ .Release.Namespace }} kubernetes.io/metadata.name: {{ .Release.Namespace }}
podSelector: podSelector:
matchLabels: {{ include "shuffle.worker.matchLabels" . | nindent 14 }} matchLabels: {{ include "shuffle.worker.matchLabels" . | nindent 14 }}
{{- end }} {{- end }}
{{- if .Values.app.networkPolicy.extraIngress }} {{- if .Values.app.networkPolicy.extraIngress }}
{{- include "common.tplvalues.render" ( dict "value" .Values.app.networkPolicy.extraIngress "context" $ ) | nindent 4 }} {{- include "common.tplvalues.render" ( dict "value" .Values.app.networkPolicy.extraIngress "context" $ ) | nindent 4 }}
{{- end }} {{- end }}
@@ -2438,6 +2438,11 @@
"items": {} "items": {}
} }
} }
},
"exposedContainerPort": {
"type": "number",
"description": "The port that shuffle app containers will listen on for new requests. ",
"default": 80
} }
} }
}, },
@@ -1549,6 +1549,10 @@ app:
## ##
extraEgress: [] extraEgress: []
## @param app.exposedContainerPort The port that shuffle app containers will listen on for new requests.
##
exposedContainerPort: 80
## @section Traffic Exposure Parameters ## @section Traffic Exposure Parameters
## ##
+4
View File
@@ -1000,6 +1000,10 @@ func deployK8sWorker(image string, identifier string, env []string) error {
env = append(env, fmt.Sprintf("SHUFFLE_USE_GHCR_OVERRIDE_FOR_AUTODEPLOY=%s", os.Getenv("SHUFFLE_USE_GHCR_OVERRIDE_FOR_AUTODEPLOY"))) env = append(env, fmt.Sprintf("SHUFFLE_USE_GHCR_OVERRIDE_FOR_AUTODEPLOY=%s", os.Getenv("SHUFFLE_USE_GHCR_OVERRIDE_FOR_AUTODEPLOY")))
} }
if len(os.Getenv("SHUFFLE_APP_EXPOSED_PORT")) > 0 {
env = append(env, fmt.Sprintf("SHUFFLE_APP_EXPOSED_PORT=%s", os.Getenv("SHUFFLE_APP_EXPOSED_PORT")))
}
if len(appServiceAccountName) > 0 { if len(appServiceAccountName) > 0 {
env = append(env, fmt.Sprintf("SHUFFLE_APP_SERVICE_ACCOUNT_NAME=%s", appServiceAccountName)) env = append(env, fmt.Sprintf("SHUFFLE_APP_SERVICE_ACCOUNT_NAME=%s", appServiceAccountName))
} }
+16 -8
View File
@@ -404,6 +404,11 @@ func deployk8sApp(image string, identifier string, env []string) error {
kubernetesNamespace = "default" kubernetesNamespace = "default"
} }
deployport, err := strconv.Atoi(os.Getenv("SHUFFLE_APP_EXPOSED_PORT"))
if err != nil {
deployport = 80
}
envMap := make(map[string]string) envMap := make(map[string]string)
for _, envStr := range env { for _, envStr := range env {
parts := strings.SplitN(envStr, "=", 2) parts := strings.SplitN(envStr, "=", 2)
@@ -413,9 +418,7 @@ func deployk8sApp(image string, identifier string, env []string) error {
} }
// add to env // add to env
// fmt.Sprintf("SHUFFLE_APP_EXPOSED_PORT=%d", deployport), envMap["SHUFFLE_APP_EXPOSED_PORT"] = strconv.Itoa(deployport)
// fmt.Sprintf("SHUFFLE_SWARM_CONFIG=%s", os.Getenv("SHUFFLE_SWARM_CONFIG")),
envMap["SHUFFLE_APP_EXPOSED_PORT"] = "80"
envMap["SHUFFLE_SWARM_CONFIG"] = os.Getenv("SHUFFLE_SWARM_CONFIG") envMap["SHUFFLE_SWARM_CONFIG"] = os.Getenv("SHUFFLE_SWARM_CONFIG")
envMap["BASE_URL"] = "http://shuffle-workers:33333" envMap["BASE_URL"] = "http://shuffle-workers:33333"
@@ -623,9 +626,15 @@ func deployk8sApp(image string, identifier string, env []string) error {
Spec: corev1.PodSpec{ Spec: corev1.PodSpec{
Containers: []corev1.Container{ Containers: []corev1.Container{
{ {
Name: value, Name: value,
Image: image, Image: image,
Env: buildEnvVars(envMap), Env: buildEnvVars(envMap),
Ports: []corev1.ContainerPort{
{
Protocol: "TCP",
ContainerPort: int32(deployport),
},
},
SecurityContext: containerSecurityContext, SecurityContext: containerSecurityContext,
}, },
}, },
@@ -643,7 +652,6 @@ func deployk8sApp(image string, identifier string, env []string) error {
return err return err
} }
// kubectl expose deployment {podName} --type=NodePort --port=80 --target-port=80
service := &corev1.Service{ service := &corev1.Service{
ObjectMeta: metav1.ObjectMeta{ ObjectMeta: metav1.ObjectMeta{
Name: name, Name: name,
@@ -655,7 +663,7 @@ func deployk8sApp(image string, identifier string, env []string) error {
{ {
Protocol: "TCP", Protocol: "TCP",
Port: 80, Port: 80,
TargetPort: intstr.FromInt(80), TargetPort: intstr.FromInt(deployport),
}, },
}, },
Type: corev1.ServiceTypeNodePort, Type: corev1.ServiceTypeNodePort,