Feature: add HARP/ExApps support
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 35/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Tranquilla
- Stack tecnologico
- docker, helm, kubernetes
- Ambito
- devops, infrastructure
Direzione di ricerca
Non sono indicati file o test. Inizia esaminando i template service e ingress di Helm esistenti e la configurazione Kubernetes del chart, quindi confronta il StatefulSet proposto e la Docker rootless/socket exposure tra le configurazioni supportate. Il lavoro è completato quando ExApps può essere distribuito con una configurazione service e ingress funzionante, senza dipendere da un manifest specifico del cluster.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description of the change
I tried to add a StatefulSet with HARP to run exapps on kubernetes.
My tests were successful.
StatefulSet code:
apiVersion: v1
kind: ConfigMap
metadata:
name: docker-daemon-config
data:
daemon.json: |
{
"memory": "512m"
}
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
labels:
app: clouduvet
name: clouduvet-harp
spec:
serviceName: harp
replicas: 1
selector:
matchLabels:
app: clouduvet
template:
metadata:
labels:
app: clouduvet
spec:
volumes:
- name: docker-config
configMap:
name: docker-daemon-config
restartPolicy: Always
securityContext:
fsGroup: 1000
containers:
- name: appapi-harp
image: ghcr.io/nextcloud/nextcloud-appapi-harp:release
imagePullPolicy: Always
env:
- name: DOCKER_HOST
value: unix:///run/user/1000/docker.sock
- name: HP_SHARED_KEY
valueFrom:
secretKeyRef:
name: harp-shared-key
key: shared-key
- name: NC_INSTANCE_URL
value: "http://nextcloud.nextcloud.svc.cluster.local"
resources:
requests:
cpu: "250m"
memory: "512Mi"
limits:
cpu: "250m"
memory: "512Mi"
#securityContext:
# privileged: true
#---
#apiVersion: v1
#kind: Pod
#metadata:
# name: appapi-harp
# labels:
# app: appapi-harp
#spec:
# restartPolicy: Always
# hostNetwork: false
# containers:
# - name: appapi-harp
# image: ghcr.io/nextcloud/nextcloud-appapi-harp:release
# imagePullPolicy: IfNotPresent
# env:
# - name: HP_SHARED_KEY
# valueFrom:
# secretKeyRef:
# name: harp-shared-key
# key: shared-key
# - name: NC_INSTANCE_URL
# value: "http://nextcloud.nextcloud.svc.cluster.local"
# ports:
# - containerPort: 8780
# - containerPort: 8782
# volumeMounts:
# - name: docker-sock
# mountPath: /var/run/docker.sock
# - name: certs
# mountPath: /certs
# volumes:
# - name: docker-sock
# hostPath:
# path: /var/run/docker.sock
# type: Socket
# - name: certs
# hostPath:
# path: /absolute/path/to/certs # Change to absolute path on host
# type: Directory
It allowed me to expose a docker rootless using harp. I put that here mostly so others may be able to reference it, feel free to use it :)
You also need to change the service and the ingress.
Benefits
ExApps support.
Possible drawbacks
The StatefulState approach is losely based on what I've done for gitlab runners on my cluster, it might not be the best approach.
I cannot guarantee that the manifest I provided can be used across every clusters.
Additional information
I am willing to create a pull request for this change. However, I'd appreciate some guidance on how to expose the docker socket of the host node in a manner that is compatible with a maximum of setups.
- Lingua principale
- Go Template
- Stelle
- 536
- Fork
- 316
- Merge medio
- 4g 16h
- PR unite (30g)
- 2
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di nextcloud/helm
-
No native support for REDIS_USER enviroment varForse già presa @jholmes802 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Failed to inspect imageAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is setForse già presa @JanWelker l’ha presa 17 giorni fa. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 78/100
-
External Redis not working: redis-session.ini: Permission deniedForse già presa @antoinetran l’ha presa 21 giorni fa. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
Tutte le issue di nextcloud/helm
Issue simili
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
FinanceFlash/unvibecode#203 ·
I maintainer di solito rispondono entro 1 giorno
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 testForse già presa @yurnov l’ha presa oggi. Apertaneeds_triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 91/100
ansible-collections/kubernetes.core#1275 ·
I maintainer di solito rispondono entro 1 giorno
-
bug milestone-qa
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
lognorman20/monaco#3995 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
gnosis/gnosis_vpn#540 ·
I maintainer di solito rispondono entro 1 giorno