plane fix
This commit is contained in:
@@ -1,67 +1,109 @@
|
|||||||
apiVersion: argoproj.io/v1alpha1
|
apiVersion: argoproj.io/v1alpha1
|
||||||
kind: Application
|
kind: Application
|
||||||
metadata:
|
metadata:
|
||||||
name: seaweedfs
|
name: plane
|
||||||
finalizers:
|
finalizers:
|
||||||
- resources-finalizer.argocd.argoproj.io
|
- resources-finalizer.argocd.argoproj.io
|
||||||
spec:
|
spec:
|
||||||
|
# Health Check für Worker überspringen (temporär)
|
||||||
|
ignoreDifferences:
|
||||||
|
# PVCs - creationTimestamp und Status ignorieren
|
||||||
|
- group: ""
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
jsonPointers:
|
||||||
|
- /metadata/creationTimestamp
|
||||||
|
- /status
|
||||||
|
|
||||||
|
# StatefulSets - alle volumeClaimTemplates komplett ignorieren
|
||||||
|
- group: apps
|
||||||
|
kind: StatefulSet
|
||||||
|
jsonPointers:
|
||||||
|
- /spec/volumeClaimTemplates
|
||||||
|
- /status
|
||||||
|
- /spec/replicas
|
||||||
|
|
||||||
|
# Worker Deployment - Replica Status ignorieren
|
||||||
|
- group: apps
|
||||||
|
kind: Deployment
|
||||||
|
name: plane-worker-wl
|
||||||
|
jsonPointers:
|
||||||
|
- /status
|
||||||
|
|
||||||
project: default
|
project: default
|
||||||
source:
|
source:
|
||||||
repoURL: 'https://seaweedfs.github.io/seaweedfs/helm'
|
repoURL: 'https://helm.plane.so/'
|
||||||
chart: seaweedfs
|
chart: 'plane-ce'
|
||||||
targetRevision: 4.0.393
|
targetRevision: 1.3.1
|
||||||
helm:
|
helm:
|
||||||
values: |
|
values: |
|
||||||
master:
|
|
||||||
|
ingress:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
appHost: "plane.innovation-hub-niedersachsen.de"
|
||||||
|
ingressClass: "traefik"
|
||||||
|
ingress_annotations:
|
||||||
|
cert-manager.io/cluster-issuer: lets-encrypt-staging
|
||||||
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
||||||
|
|
||||||
|
ssl:
|
||||||
|
tls_secret_name: "plane-tls"
|
||||||
|
createIssuer: false
|
||||||
|
generateCerts: false
|
||||||
|
|
||||||
|
minio:
|
||||||
|
local_setup: false
|
||||||
|
|
||||||
|
env:
|
||||||
|
docstore_bucket: "plane-docstore"
|
||||||
|
doc_upload_size_limit: "5242880"
|
||||||
|
aws_access_key: "a0ccb47cc0994bf51ecd"
|
||||||
|
aws_secret_access_key: "0d54ee2f943f2a56b8cafc3afe9cb1e2f9fecac2"
|
||||||
|
aws_region: "eu-central-1"
|
||||||
|
aws_s3_endpoint_url: "https://sws3.innovation-hub-niedersachsen.de"
|
||||||
|
# Celery Worker Konfiguration - Reduziere Concurrency für Stabilität
|
||||||
|
CELERY_WORKER_CONCURRENCY: "4"
|
||||||
|
CELERY_WORKER_MAX_TASKS_PER_CHILD: "500"
|
||||||
|
CELERY_WORKER_MAX_MEMORY_PER_CHILD: "100000"
|
||||||
|
|
||||||
|
# Worker-spezifische Einstellungen
|
||||||
|
worker:
|
||||||
|
# Reduziere Replicas falls zu viele Workers laufen
|
||||||
replicas: 1
|
replicas: 1
|
||||||
|
# Celery Concurrency (Anzahl paralleler Worker-Prozesse)
|
||||||
volume:
|
concurrency: 4
|
||||||
enabled: true
|
resources:
|
||||||
replicas: 1
|
requests:
|
||||||
|
memory: "512Mi"
|
||||||
filer:
|
cpu: "200m"
|
||||||
enabled: true
|
limits:
|
||||||
replicas: 1
|
memory: "2Gi"
|
||||||
|
cpu: "1000m"
|
||||||
s3:
|
# Exec-basierte Probes für Celery Worker
|
||||||
enabled: true
|
readinessProbe:
|
||||||
replicas: 1
|
exec:
|
||||||
port: 8333
|
command:
|
||||||
httpsPort: 8433
|
- /bin/sh
|
||||||
enableAuth: true
|
- -c
|
||||||
existingConfigSecret: "admin-s3-secret"
|
- celery -A plane inspect ping -d celery@$HOSTNAME
|
||||||
ingress:
|
initialDelaySeconds: 30
|
||||||
enabled: true
|
periodSeconds: 30
|
||||||
className: "traefik"
|
timeoutSeconds: 10
|
||||||
host: "sws3.innovation-hub-niedersachsen.de"
|
failureThreshold: 3
|
||||||
# additional ingress annotations for the s3 endpoint
|
livenessProbe:
|
||||||
annotations:
|
exec:
|
||||||
kubernetes.io/ingress.class: "traefik"
|
command:
|
||||||
traefik.ingress.kubernetes.io/router.entrypoints: "websecure"
|
- /bin/sh
|
||||||
traefik.ingress.kubernetes.io/router.tls: "true"
|
- -c
|
||||||
cert-manager.io/cluster-issuer: "lets-encrypt"
|
- celery -A plane inspect ping -d celery@$HOSTNAME
|
||||||
# traefik.ingress.kubernetes.io/headers.customRequestHeaders: |
|
initialDelaySeconds: 60
|
||||||
# X-Forwarded-Proto = https
|
periodSeconds: 60
|
||||||
#traefik.ingress.kubernetes.io/headers.customResponseHeaders: |
|
timeoutSeconds: 10
|
||||||
# Access-Control-Allow-Origin: "*"
|
failureThreshold: 3
|
||||||
# Access-Control-Allow-Methods: "GET, OPTIONS, PUT, POST, DELETE"
|
|
||||||
# Access-Control-Allow-Headers: "DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range"
|
|
||||||
# Access-Control-Expose-Headers: "Content-Length,Content-Range"
|
|
||||||
# Referrer-Policy: no-referrer-when-downgrade
|
|
||||||
hosts:
|
|
||||||
- host: "sws3.innovation-hub-niedersachsen.de"
|
|
||||||
paths:
|
|
||||||
- path: /
|
|
||||||
pathType: Prefix
|
|
||||||
tls:
|
|
||||||
- secretName: "sws3.innovation-hub-niedersachsen.de-tls"
|
|
||||||
hosts:
|
|
||||||
- "sws3.innovation-hub-niedersachsen.de"
|
|
||||||
|
|
||||||
destination:
|
destination:
|
||||||
server: 'https://kubernetes.default.svc'
|
server: 'https://kubernetes.default.svc'
|
||||||
namespace: seaweedfs
|
namespace: plane
|
||||||
|
|
||||||
syncPolicy:
|
syncPolicy:
|
||||||
managedNamespaceMetadata:
|
managedNamespaceMetadata:
|
||||||
labels:
|
labels:
|
||||||
@@ -70,4 +112,7 @@ spec:
|
|||||||
selfHeal: true
|
selfHeal: true
|
||||||
prune: true
|
prune: true
|
||||||
syncOptions:
|
syncOptions:
|
||||||
- CreateNamespace=true
|
- CreateNamespace=true
|
||||||
|
- ServerSideApply=true
|
||||||
|
- PruneLast=true
|
||||||
|
- RespectIgnoreDifferences=true
|
||||||
Reference in New Issue
Block a user