Serve preview URLs over Traefik+TLS, stabilize them, and speed up builds.
Ingress / preview URLs: - Default the app Ingress class and ACME HTTP-01 solver to Traefik (k3s default) via a new INGRESS_CLASS env, instead of hardcoding nginx — fixes 404s on clusters without ingress-nginx. - Only put public, real-TLD hosts (custom domain + preview) in the TLS block; the internal *.apps.cloudhost.local host no longer poisons the Let's Encrypt order, so certs actually issue. - Make the per-app preview number stable across redeploys so URLs stop breaking, and let PREVIEW_BASE_DOMAIN configure the base domain. Registry pulls: - Point the k3s registries.yaml mirror endpoint at the registry NodePort on loopback so node containerd never depends on cluster DNS (image pulls survive node restarts). Builds: - Pin the Kaniko image, use IfNotPresent pull policy, drop the dead build queue/processor, and retry transient Kubernetes API errors while polling build jobs. Logs & apps list: - fluent-bit reads log files from head so startup output reaches Elasticsearch. - Order joined deployments newest-first so the apps list shows the latest deployment status. Allocation: - Reserve in-flight (pending/building) capacity and stop globally degrading the cluster on a single allocation failure, so concurrent deploys don't starve or wrongly report "no healthy cluster". Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -28,6 +28,13 @@ function stripLeadingSubdomain(hostname: string): string {
|
||||
}
|
||||
|
||||
function resolvePreviewRootDomainFromEnv(): string {
|
||||
// Explicit override takes priority — the base domain used for preview URLs
|
||||
// (e.g. PREVIEW_BASE_DOMAIN=3fase.ir) must be configurable, never hardcoded.
|
||||
const explicit = process.env.PREVIEW_BASE_DOMAIN;
|
||||
if (explicit && explicit.trim()) {
|
||||
return explicit.trim().toLowerCase();
|
||||
}
|
||||
|
||||
const frontendUrl = process.env.FRONTEND_URL;
|
||||
if (frontendUrl) {
|
||||
try {
|
||||
@@ -108,6 +115,12 @@ export default () => ({
|
||||
platform: {
|
||||
domain: resolvePlatformDomainFromEnv(),
|
||||
previewRootDomain: resolvePreviewRootDomainFromEnv(),
|
||||
/**
|
||||
* Ingress controller class used for app Ingress objects and the ACME
|
||||
* HTTP-01 solver. k3s ships Traefik by default, so we default to "traefik".
|
||||
* Set INGRESS_CLASS=nginx for clusters running ingress-nginx instead.
|
||||
*/
|
||||
ingressClass: (process.env.INGRESS_CLASS || 'traefik').trim().toLowerCase(),
|
||||
uploadDir: process.env.UPLOAD_DIR || './uploads',
|
||||
/** StorageClass for new PVCs; must support allowVolumeExpansion for disk resize */
|
||||
storageClass: process.env.PLATFORM_STORAGE_CLASS || 'cloudhost-expandable',
|
||||
|
||||
Reference in New Issue
Block a user