forked from Iankulani/warbunny
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathk8s-deployment.yaml
More file actions
142 lines (142 loc) · 3.69 KB
/
Copy pathk8s-deployment.yaml
File metadata and controls
142 lines (142 loc) · 3.69 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# WARBUNNY Kubernetes Deployment
apiVersion: apps/v1
kind: Deployment
metadata:
name: warbunny
namespace: security
labels:
app: warbunny
version: v2.0.0
tier: backend
spec:
replicas: 2
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 1
maxUnavailable: 0
selector:
matchLabels:
app: warbunny
template:
metadata:
labels:
app: warbunny
version: v2.0.0
annotations:
prometheus.io/scrape: "true"
prometheus.io/port: "5000"
spec:
serviceAccountName: warbunny
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
containers:
- name: warbunny
image: warbunny:2.0.0
imagePullPolicy: Always
ports:
- containerPort: 5000
name: web
protocol: TCP
- containerPort: 8080
name: phishing
protocol: TCP
env:
- name: WARBUNNY_ENV
valueFrom:
configMapKeyRef:
name: warbunny-config
key: environment
- name: DB_HOST
valueFrom:
configMapKeyRef:
name: warbunny-config
key: db_host
- name: DB_PASSWORD
valueFrom:
secretKeyRef:
name: warbunny-secret
key: db_password
- name: DISCORD_TOKEN
valueFrom:
secretKeyRef:
name: warbunny-secret
key: discord_token
optional: true
- name: SLACK_TOKEN
valueFrom:
secretKeyRef:
name: warbunny-secret
key: slack_token
optional: true
- name: TELEGRAM_TOKEN
valueFrom:
secretKeyRef:
name: warbunny-secret
key: telegram_token
optional: true
securityContext:
capabilities:
add:
- NET_ADMIN
- NET_RAW
resources:
requests:
memory: "256Mi"
cpu: "250m"
limits:
memory: "1Gi"
cpu: "1000m"
livenessProbe:
httpGet:
path: /health
port: 5000
initialDelaySeconds: 60
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /ready
port: 5000
initialDelaySeconds: 30
periodSeconds: 5
timeoutSeconds: 3
failureThreshold: 3
volumeMounts:
- name: config
mountPath: /opt/warbunny/.warbunny
- name: logs
mountPath: /var/log/warbunny
- name: reports
mountPath: /opt/warbunny/warbunny_reports
volumes:
- name: config
persistentVolumeClaim:
claimName: warbunny-config-pvc
- name: logs
persistentVolumeClaim:
claimName: warbunny-logs-pvc
- name: reports
persistentVolumeClaim:
claimName: warbunny-reports-pvc
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchExpressions:
- key: app
operator: In
values:
- warbunny
topologyKey: kubernetes.io/hostname
tolerations:
- key: "security"
operator: "Equal"
value: "true"
effect: "NoSchedule"