Serve preview URLs over Traefik+TLS, stabilize them, and speed up builds.
Ingress / preview URLs: - Default the app Ingress class and ACME HTTP-01 solver to Traefik (k3s default) via a new INGRESS_CLASS env, instead of hardcoding nginx — fixes 404s on clusters without ingress-nginx. - Only put public, real-TLD hosts (custom domain + preview) in the TLS block; the internal *.apps.cloudhost.local host no longer poisons the Let's Encrypt order, so certs actually issue. - Make the per-app preview number stable across redeploys so URLs stop breaking, and let PREVIEW_BASE_DOMAIN configure the base domain. Registry pulls: - Point the k3s registries.yaml mirror endpoint at the registry NodePort on loopback so node containerd never depends on cluster DNS (image pulls survive node restarts). Builds: - Pin the Kaniko image, use IfNotPresent pull policy, drop the dead build queue/processor, and retry transient Kubernetes API errors while polling build jobs. Logs & apps list: - fluent-bit reads log files from head so startup output reaches Elasticsearch. - Order joined deployments newest-first so the apps list shows the latest deployment status. Allocation: - Reserve in-flight (pending/building) capacity and stop globally degrading the cluster on a single allocation failure, so concurrent deploys don't starve or wrongly report "no healthy cluster". Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -43,6 +43,12 @@ BUILD_SERVICE_ACCOUNT=kaniko-builder
|
||||
|
||||
# Platform
|
||||
PLATFORM_DOMAIN=apps.cloudhost.local
|
||||
# Base domain for per-user preview URLs (<userId>-<7-digit>.<base-domain>).
|
||||
# Falls back to the root domain derived from FRONTEND_URL when unset.
|
||||
# PREVIEW_BASE_DOMAIN=3fase.ir
|
||||
# Ingress controller class for app Ingress + ACME HTTP-01 solver.
|
||||
# k3s default is Traefik; use "nginx" only on clusters running ingress-nginx.
|
||||
# INGRESS_CLASS=traefik
|
||||
UPLOAD_DIR=./uploads
|
||||
# PVC resize: use a dynamic StorageClass with allowVolumeExpansion (k3s: rancher.io/local-path)
|
||||
# k3s: use local-path and skip creating a custom class (set CREATE=false)
|
||||
|
||||
Reference in New Issue
Block a user