feat(netbox): add enterprise-grade server documenting app w/ shared postgres
This commit is contained in:
1 parent
a4a4bb4cc5
commit
c536a16a2a
17 files changed
+772
-1
No files matched your search
@@ -0,0 +1,28 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: netbox-prod-tls
|
||||
namespace: netbox
|
||||
spec:
|
||||
secretName: netbox-prod-tls
|
||||
dnsNames:
|
||||
- netbox.forust.xyz
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
---
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: internal-wildcard-tls
|
||||
namespace: netbox
|
||||
spec:
|
||||
secretName: internal-wildcard-tls
|
||||
dnsNames:
|
||||
- "*.workstation.internal"
|
||||
- "*.gigaforust.internal"
|
||||
- workstation.internal
|
||||
- gigaforust.internal
|
||||
issuerRef:
|
||||
name: internal-ca
|
||||
kind: ClusterIssuer
|
||||
@@ -0,0 +1,21 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: netbox-config
|
||||
namespace: netbox
|
||||
data:
|
||||
DB_HOST: "postgres.database.svc.cluster.local"
|
||||
DB_PORT: "5432"
|
||||
DB_SSLMODE: "disable"
|
||||
REDIS_HOST: "netbox-valkey"
|
||||
REDIS_PORT: "6379"
|
||||
REDIS_DATABASE: "0"
|
||||
REDIS_CACHE_HOST: "netbox-valkey"
|
||||
REDIS_CACHE_PORT: "6379"
|
||||
REDIS_CACHE_DATABASE: "1"
|
||||
TIME_ZONE: "Europe/Bratislava"
|
||||
TZ: "Europe/Bratislava"
|
||||
GRANIAN_WORKERS: "2"
|
||||
ALLOWED_HOSTS: "netbox.forust.xyz,netbox.workstation.internal,netbox.gigaforust.internal"
|
||||
CSRF_TRUSTED_ORIGINS: "https://netbox.forust.xyz,https://netbox.workstation.internal,https://netbox.gigaforust.internal"
|
||||
SKIP_SUPERUSER: "false"
|
||||
@@ -0,0 +1,36 @@
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: netbox-prod
|
||||
namespace: netbox
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`netbox.forust.xyz`)
|
||||
kind: Rule
|
||||
middlewares:
|
||||
- name: crowdsec-bouncer
|
||||
namespace: crowdsec
|
||||
services:
|
||||
- name: netbox-service
|
||||
port: 8080
|
||||
tls:
|
||||
secretName: netbox-prod-tls
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRoute
|
||||
metadata:
|
||||
name: netbox-local
|
||||
namespace: netbox
|
||||
spec:
|
||||
entryPoints:
|
||||
- websecure
|
||||
routes:
|
||||
- match: Host(`netbox.workstation.internal`) || Host(`netbox.gigaforust.internal`)
|
||||
kind: Rule
|
||||
services:
|
||||
- name: netbox-service
|
||||
port: 8080
|
||||
tls:
|
||||
secretName: internal-wildcard-tls
|
||||
@@ -0,0 +1,4 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: netbox
|
||||
@@ -0,0 +1,204 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: netbox-service
|
||||
namespace: netbox
|
||||
spec:
|
||||
selector:
|
||||
app: netbox
|
||||
ports:
|
||||
- name: http
|
||||
port: 8080
|
||||
targetPort: http
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: netbox-deployment
|
||||
namespace: netbox
|
||||
labels:
|
||||
app: netbox
|
||||
spec:
|
||||
replicas: 1
|
||||
progressDeadlineSeconds: 300
|
||||
selector:
|
||||
matchLabels:
|
||||
app: netbox
|
||||
strategy:
|
||||
# ReadWriteOnce PVC
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: netbox
|
||||
spec:
|
||||
containers:
|
||||
- name: netbox
|
||||
image: docker.io/netboxcommunity/netbox:v4.7-5.1.1
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: 8080
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: netbox-config
|
||||
- secretRef:
|
||||
name: netbox-secrets
|
||||
volumeMounts:
|
||||
- name: netbox-config
|
||||
mountPath: /etc/netbox/config
|
||||
readOnly: true
|
||||
- name: netbox-media
|
||||
mountPath: /opt/netbox/netbox/media
|
||||
- name: netbox-reports
|
||||
mountPath: /opt/netbox/netbox/reports
|
||||
- name: netbox-scripts
|
||||
mountPath: /opt/netbox/netbox/scripts
|
||||
startupProbe:
|
||||
exec:
|
||||
command:
|
||||
- /opt/netbox/venv/bin/python
|
||||
- -c
|
||||
- >-
|
||||
exec /usr/bin/curl --fail --silent --show-error --max-time 4
|
||||
--header 'Host: netbox.forust.xyz'
|
||||
http://127.0.0.1:8080/login/ >/dev/null
|
||||
failureThreshold: 90
|
||||
periodSeconds: 10
|
||||
readinessProbe:
|
||||
exec:
|
||||
command:
|
||||
- /opt/netbox/venv/bin/python
|
||||
- -c
|
||||
- >-
|
||||
exec /usr/bin/curl --fail --silent --show-error --max-time 4
|
||||
--header 'Host: netbox.forust.xyz'
|
||||
http://127.0.0.1:8080/login/ >/dev/null
|
||||
periodSeconds: 10
|
||||
livenessProbe:
|
||||
exec:
|
||||
command:
|
||||
- /opt/netbox/venv/bin/python
|
||||
- -c
|
||||
- >-
|
||||
exec /usr/bin/curl --fail --silent --show-error --max-time 4
|
||||
--header 'Host: netbox.forust.xyz'
|
||||
http://127.0.0.1:8080/login/ >/dev/null
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 30
|
||||
resources:
|
||||
requests:
|
||||
cpu: "100m"
|
||||
memory: "512Mi"
|
||||
limits:
|
||||
cpu: "2"
|
||||
memory: "2Gi"
|
||||
volumes:
|
||||
- name: netbox-config
|
||||
configMap:
|
||||
name: netbox-settings
|
||||
- name: netbox-media
|
||||
persistentVolumeClaim:
|
||||
claimName: netbox-media-pvc
|
||||
- name: netbox-reports
|
||||
persistentVolumeClaim:
|
||||
claimName: netbox-reports-pvc
|
||||
- name: netbox-scripts
|
||||
persistentVolumeClaim:
|
||||
claimName: netbox-scripts-pvc
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: netbox-worker-deployment
|
||||
namespace: netbox
|
||||
labels:
|
||||
app: netbox-worker
|
||||
spec:
|
||||
replicas: 1
|
||||
progressDeadlineSeconds: 300
|
||||
selector:
|
||||
matchLabels:
|
||||
app: netbox-worker
|
||||
strategy:
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: netbox-worker
|
||||
spec:
|
||||
containers:
|
||||
- name: netbox-worker
|
||||
image: docker.io/netboxcommunity/netbox:v4.7-5.1.1
|
||||
command:
|
||||
- /opt/netbox/venv/bin/python
|
||||
- netbox/manage.py
|
||||
- rqworker
|
||||
workingDir: /opt/netbox
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: netbox-config
|
||||
- secretRef:
|
||||
name: netbox-secrets
|
||||
volumeMounts:
|
||||
- name: netbox-config
|
||||
mountPath: /etc/netbox/config
|
||||
readOnly: true
|
||||
- name: netbox-media
|
||||
mountPath: /opt/netbox/netbox/media
|
||||
- name: netbox-reports
|
||||
mountPath: /opt/netbox/netbox/reports
|
||||
- name: netbox-scripts
|
||||
mountPath: /opt/netbox/netbox/scripts
|
||||
resources:
|
||||
requests:
|
||||
cpu: "50m"
|
||||
memory: "256Mi"
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: "1Gi"
|
||||
volumes:
|
||||
- name: netbox-config
|
||||
configMap:
|
||||
name: netbox-settings
|
||||
- name: netbox-media
|
||||
persistentVolumeClaim:
|
||||
claimName: netbox-media-pvc
|
||||
- name: netbox-reports
|
||||
persistentVolumeClaim:
|
||||
claimName: netbox-reports-pvc
|
||||
- name: netbox-scripts
|
||||
persistentVolumeClaim:
|
||||
claimName: netbox-scripts-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: netbox-media-pvc
|
||||
namespace: netbox
|
||||
spec:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: netbox-reports-pvc
|
||||
namespace: netbox
|
||||
spec:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: netbox-scripts-pvc
|
||||
namespace: netbox
|
||||
spec:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: netbox-secrets
|
||||
namespace: netbox
|
||||
type: Opaque
|
||||
stringData:
|
||||
DB_NAME: "netbox"
|
||||
DB_USER: "netbox"
|
||||
DB_PASSWORD: "CHANGE_ME_POSTGRES_PASSWORD"
|
||||
REDIS_PASSWORD: "CHANGE_ME_VALKEY_PASSWORD"
|
||||
REDIS_CACHE_PASSWORD: "CHANGE_ME_VALKEY_PASSWORD"
|
||||
VALKEY_PASSWORD: "CHANGE_ME_VALKEY_PASSWORD"
|
||||
SECRET_KEY: "CHANGE_ME_DJANGO_SECRET_KEY"
|
||||
API_TOKEN_PEPPER_1: "CHANGE_ME_API_TOKEN_PEPPER"
|
||||
SUPERUSER_NAME: "admin"
|
||||
SUPERUSER_EMAIL: "admin@example.com"
|
||||
SUPERUSER_PASSWORD: "CHANGE_ME_SUPERUSER_PASSWORD"
|
||||
@@ -0,0 +1,56 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: netbox-settings
|
||||
namespace: netbox
|
||||
data:
|
||||
# Sync wit netbox/configuration/configuration.py (the Docker mounts that file).
|
||||
configuration.py: |
|
||||
import os
|
||||
|
||||
|
||||
def _csv(name, default=""):
|
||||
return [item.strip() for item in os.environ.get(name, default).split(",") if item.strip()]
|
||||
|
||||
|
||||
ALLOWED_HOSTS = _csv("ALLOWED_HOSTS", "localhost,127.0.0.1,[::1]")
|
||||
CSRF_TRUSTED_ORIGINS = _csv("CSRF_TRUSTED_ORIGINS")
|
||||
USE_X_FORWARDED_HOST = True
|
||||
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
|
||||
|
||||
DATABASES = {
|
||||
"default": {
|
||||
"NAME": os.environ["DB_NAME"],
|
||||
"USER": os.environ["DB_USER"],
|
||||
"PASSWORD": os.environ["DB_PASSWORD"],
|
||||
"HOST": os.environ["DB_HOST"],
|
||||
"PORT": os.environ.get("DB_PORT", "5432"),
|
||||
"OPTIONS": {"sslmode": os.environ.get("DB_SSLMODE", "disable")},
|
||||
"CONN_MAX_AGE": int(os.environ.get("DB_CONN_MAX_AGE", "300")),
|
||||
}
|
||||
}
|
||||
|
||||
REDIS = {
|
||||
"tasks": {
|
||||
"HOST": os.environ["REDIS_HOST"],
|
||||
"PORT": int(os.environ.get("REDIS_PORT", "6379")),
|
||||
"PASSWORD": os.environ["REDIS_PASSWORD"],
|
||||
"DATABASE": int(os.environ.get("REDIS_DATABASE", "0")),
|
||||
"SSL": False,
|
||||
},
|
||||
"caching": {
|
||||
"HOST": os.environ["REDIS_CACHE_HOST"],
|
||||
"PORT": int(os.environ.get("REDIS_CACHE_PORT", "6379")),
|
||||
"PASSWORD": os.environ["REDIS_CACHE_PASSWORD"],
|
||||
"DATABASE": int(os.environ.get("REDIS_CACHE_DATABASE", "1")),
|
||||
"SSL": False,
|
||||
},
|
||||
}
|
||||
|
||||
SECRET_KEY = os.environ["SECRET_KEY"]
|
||||
API_TOKEN_PEPPERS = {1: os.environ["API_TOKEN_PEPPER_1"]}
|
||||
TIME_ZONE = os.environ.get("TIME_ZONE", "UTC")
|
||||
MEDIA_ROOT = "/opt/netbox/netbox/media"
|
||||
REPORTS_ROOT = "/opt/netbox/netbox/reports"
|
||||
SCRIPTS_ROOT = "/opt/netbox/netbox/scripts"
|
||||
CENSUS_REPORTING_ENABLED = False
|
||||
@@ -0,0 +1,82 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: netbox-valkey
|
||||
namespace: netbox
|
||||
labels:
|
||||
app: netbox-valkey
|
||||
spec:
|
||||
clusterIP: None
|
||||
selector:
|
||||
app: netbox-valkey
|
||||
ports:
|
||||
- name: valkey
|
||||
port: 6379
|
||||
targetPort: valkey
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: netbox-valkey
|
||||
namespace: netbox
|
||||
labels:
|
||||
app: netbox-valkey
|
||||
spec:
|
||||
serviceName: netbox-valkey
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: netbox-valkey
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: netbox-valkey
|
||||
spec:
|
||||
containers:
|
||||
- name: valkey
|
||||
image: docker.io/valkey/valkey:9.1.2-alpine
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- valkey-server --appendonly yes --save 30 1 --loglevel warning --requirepass "$VALKEY_PASSWORD"
|
||||
env:
|
||||
- name: VALKEY_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: netbox-secrets
|
||||
key: VALKEY_PASSWORD
|
||||
ports:
|
||||
- name: valkey
|
||||
containerPort: 6379
|
||||
volumeMounts:
|
||||
- name: valkey-data
|
||||
mountPath: /data
|
||||
startupProbe:
|
||||
exec:
|
||||
command: ["sh", "-c", 'valkey-cli --pass "$VALKEY_PASSWORD" ping | grep -q PONG']
|
||||
failureThreshold: 20
|
||||
periodSeconds: 5
|
||||
readinessProbe:
|
||||
exec:
|
||||
command: ["sh", "-c", 'valkey-cli --pass "$VALKEY_PASSWORD" ping | grep -q PONG']
|
||||
periodSeconds: 10
|
||||
livenessProbe:
|
||||
exec:
|
||||
command: ["sh", "-c", 'valkey-cli --pass "$VALKEY_PASSWORD" ping | grep -q PONG']
|
||||
initialDelaySeconds: 20
|
||||
periodSeconds: 20
|
||||
resources:
|
||||
requests:
|
||||
cpu: "25m"
|
||||
memory: "64Mi"
|
||||
limits:
|
||||
cpu: "250m"
|
||||
memory: "256Mi"
|
||||
volumeClaimTemplates:
|
||||
- metadata:
|
||||
name: valkey-data
|
||||
spec:
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
Reference in new issue
Block a user