Serve preview URLs over Traefik+TLS, stabilize them, and speed up builds.

Ingress / preview URLs:
- Default the app Ingress class and ACME HTTP-01 solver to Traefik
  (k3s default) via a new INGRESS_CLASS env, instead of hardcoding nginx —
  fixes 404s on clusters without ingress-nginx.
- Only put public, real-TLD hosts (custom domain + preview) in the TLS
  block; the internal *.apps.cloudhost.local host no longer poisons the
  Let's Encrypt order, so certs actually issue.
- Make the per-app preview number stable across redeploys so URLs stop
  breaking, and let PREVIEW_BASE_DOMAIN configure the base domain.

Registry pulls:
- Point the k3s registries.yaml mirror endpoint at the registry NodePort on
  loopback so node containerd never depends on cluster DNS (image pulls
  survive node restarts).

Builds:
- Pin the Kaniko image, use IfNotPresent pull policy, drop the dead build
  queue/processor, and retry transient Kubernetes API errors while polling
  build jobs.

Logs & apps list:
- fluent-bit reads log files from head so startup output reaches
  Elasticsearch.
- Order joined deployments newest-first so the apps list shows the latest
  deployment status.

Allocation:
- Reserve in-flight (pending/building) capacity and stop globally degrading
  the cluster on a single allocation failure, so concurrent deploys don't
  starve or wrongly report "no healthy cluster".

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
keyhan
2026-06-02 15:44:08 +03:30
parent 786689e0fd
commit 4301277b48
13 changed files with 244 additions and 109 deletions
@@ -26,7 +26,9 @@ spec:
containers:
- name: {{ $name }}
image: {{ .Values.app.image | quote }}
imagePullPolicy: Always
# Image tags are unique per build (name:timestamp) and immutable —
# IfNotPresent avoids re-pulling on every restart/scale-up.
imagePullPolicy: IfNotPresent
{{- if include "cloudhost-app.loggingWrapEnabled" . }}
command: ["sh", "-c"]
args:
@@ -26,6 +26,10 @@ data:
Refresh_Interval 5
Mem_Buf_Limit 5MB
Skip_Long_Lines On
# Read the whole file (incl. startup output written before fluent-bit
# attached) instead of only new lines — otherwise an idle app that
# logged only at boot would ship nothing to Elasticsearch.
Read_from_Head On
[FILTER]
Name record_modifier
@@ -3,6 +3,13 @@
{{- $ns := include "cloudhost-app.namespace" . -}}
{{- $host := printf "%s.%s" (default $name .Values.ingress.subdomain) .Values.ingress.domain -}}
{{- $previewHost := .Values.ingress.previewHost | default "" -}}
{{- $className := .Values.ingress.className | default "traefik" -}}
{{- /* Only public, real-TLD hosts (custom domain + preview) can get a managed cert.
The internal *.apps.cloudhost.local host is not a valid public suffix and would
make Let's Encrypt reject the whole order. */ -}}
{{- $tlsHosts := list -}}
{{- if .Values.ingress.customDomain }}{{- $tlsHosts = append $tlsHosts .Values.ingress.customDomain -}}{{- end -}}
{{- if $previewHost }}{{- $tlsHosts = append $tlsHosts $previewHost -}}{{- end -}}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
@@ -10,10 +17,12 @@ metadata:
namespace: {{ $ns }}
labels:
{{- include "cloudhost-app.labels" . | nindent 4 }}
{{- if gt (len $tlsHosts) 0 }}
annotations:
cert-manager.io/cluster-issuer: {{ .Values.ingress.clusterIssuer | quote }}
{{- end }}
spec:
ingressClassName: nginx
ingressClassName: {{ $className }}
rules:
- host: {{ $host }}
http:
@@ -49,14 +58,12 @@ spec:
port:
number: 80
{{- end }}
{{- if gt (len $tlsHosts) 0 }}
tls:
- hosts:
- {{ $host }}
{{- if .Values.ingress.customDomain }}
- {{ .Values.ingress.customDomain }}
{{- end }}
{{- if $previewHost }}
- {{ $previewHost }}
{{- range $tlsHosts }}
- {{ . }}
{{- end }}
secretName: {{ $name }}-tls
{{- end }}
{{- end }}