feat(rackpeek): add internal-only rack visualization service

Compose and k8s manifests behind workstation/gigaforust internal hosts.
This commit is contained in:
forust committed 2026-09-26 00:00:49 +02:00
1 parent c536a16a2a
commit 16dd67c2c0
5 files changed
+158

No files matched your search

+34
View File
@@ -0,0 +1,34 @@
services:
rackpeek:
image: docker.io/aptacode/rackpeek:v2.1.0
container_name: rackpeek
restart: unless-stopped
ports:
- "127.0.0.1:8080:8080"
environment:
TZ: "Europe/Bratislava"
volumes:
- rackpeek-config:/app/config
networks:
- proxy
labels:
- "traefik.enable=true"
- "traefik.http.services.rackpeek.loadbalancer.server.port=8080"
# Local Router
- "traefik.http.routers.rackpeek-local.rule=Host(`rackpeek.workstation.internal`) || Host(`rack.workstation.internal`) || Host(`rackpeek.gigaforust.internal`) || Host(`rack.gigaforust.internal`)"
- "traefik.http.routers.rackpeek-local.entrypoints=websecure"
- "traefik.http.routers.rackpeek-local.tls=true"
healthcheck:
test: ["CMD-SHELL", "curl -fsS http://localhost:8080/health || exit 1"]
start_period: 15s
timeout: 5s
interval: 30s
retries: 3
volumes:
rackpeek-config:
networks:
proxy:
external: true
+15
View File
@@ -0,0 +1,15 @@
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: internal-wildcard-tls
namespace: rackpeek
spec:
secretName: internal-wildcard-tls
dnsNames:
- "*.workstation.internal"
- "*.gigaforust.internal"
- workstation.internal
- gigaforust.internal
issuerRef:
name: internal-ca
kind: ClusterIssuer
+16
View File
@@ -0,0 +1,16 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: rackpeek-local
namespace: rackpeek
spec:
entryPoints:
- websecure
routes:
- match: Host(`rackpeek.workstation.internal`) || Host(`rack.workstation.internal`) || Host(`rackpeek.gigaforust.internal`) || Host(`rack.gigaforust.internal`)
kind: Rule
services:
- name: rackpeek-service
port: 8080
tls:
secretName: internal-wildcard-tls
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: rackpeek
+89
View File
@@ -0,0 +1,89 @@
apiVersion: v1
kind: Service
metadata:
name: rackpeek-service
namespace: rackpeek
spec:
selector:
app: rackpeek
ports:
- name: http
port: 8080
targetPort: http
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: rackpeek-deployment
namespace: rackpeek
labels:
app: rackpeek
spec:
replicas: 1
selector:
matchLabels:
app: rackpeek
strategy:
type: Recreate
template:
metadata:
labels:
app: rackpeek
spec:
securityContext:
# Image runs as uid/gid 1654
fsGroup: 1654
containers:
- name: rackpeek
image: docker.io/aptacode/rackpeek:v2.1.0
ports:
- name: http
containerPort: 8080
env:
- name: RPK_YAML_DIR
value: "/app/config"
- name: TZ
value: "Europe/Bratislava"
volumeMounts:
- name: rackpeek-config
mountPath: /app/config
startupProbe:
httpGet:
path: /health
port: http
failureThreshold: 30
periodSeconds: 5
readinessProbe:
httpGet:
path: /health
port: http
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: http
initialDelaySeconds: 20
periodSeconds: 30
resources:
requests:
memory: "128Mi"
cpu: "100m"
limits:
memory: "512Mi"
cpu: "500m"
volumes:
- name: rackpeek-config
persistentVolumeClaim:
claimName: rackpeek-pvc
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: rackpeek-pvc
namespace: rackpeek
spec:
accessModes: ["ReadWriteOnce"]
storageClassName: local-path-retain
resources:
requests:
storage: 2Gi