Skip to content

v0.4.2

Choose a tag to compare

@max3584 max3584 released this 08 Oct 15:13
6670826

追加

  • Kubernetes で動かせるようになりました(#136)。手順は docs/KUBERNETES.md。
    • コンテナイメージ ghcr.io/max3584/rproxy-ui:0.4.2(amd64・arm64、root でない利用者、ルートのファイルシステムは読むだけでよい)。
    • Helm chart oci://ghcr.io/max3584/charts/rproxy-ui:UI(既定 2 つ)・Service・PDB、任意で Ingress・HTTPRoute・NetworkPolicy。秘密は existingSecret で渡します。
    • DB は既定で外の MariaDB を使います。任意で公式の mariadb イメージを PVC つきで同梱でき(HA にはしません)、mysqldump のバックアップの CronJob も付けられます。
    • migration は Helm のフックの Job で当てます(db/migrate.mjs。2 回目や同時に流しても何もしません)。.deb でも手で使えます。
  • Kubernetes の rproxy を見られるようになりました:rproxy-gateway v0.4.3 が UI の namespace に書く一覧(Secret rproxy-ui-discovery)を読み、Gateway ごとの rproxy の Pod をノード・グループとして表示します。
    • 見るだけです。 変更・停止・送り直しなどは 409 readonly_node で断ります。管理者にだけ表示します。
    • 利用量は Pod ごとに集め、Gateway ごとにまとめます(終わる Pod の最後の 1 間隔は取りません)。
  • プローブ用の GET /api/healthz(サインイン不要、DB や rproxy には聞きません)。

変更

  • db/migrate.mjs は schema_migrations で当てた migration を覚えます。今の DB に初めて使うときは --baseline が要ります(db/README)。
  • .deb で入れた環境の動きは変わりません。

rproxy-api v0.3.5 以上で動きます。Kubernetes の rproxy を見るには rproxy-gateway v0.4.3 が要ります。


Added

  • Runs on Kubernetes (#136); see docs/en/KUBERNETES.md.
    • Container image ghcr.io/max3584/rproxy-ui:0.4.2 (amd64, arm64, non-root, works with a read-only root filesystem).
    • Helm chart oci://ghcr.io/max3584/charts/rproxy-ui: the UI (2 replicas by default), Service and PDB, with optional Ingress, HTTPRoute and NetworkPolicy. Secrets come through existingSecret.
    • An external MariaDB by default; optionally a bundled official mariadb image with a PVC (no HA), and a mysqldump backup CronJob.
    • Migrations run as a Helm hook Job (db/migrate.mjs; reruns and concurrent runs do nothing). Usable by hand with the .deb too.
  • Kubernetes rproxy in the UI: the UI reads the list rproxy-gateway v0.4.3 writes into its namespace (Secret rproxy-ui-discovery) and shows each Gateway's rproxy pods as nodes and a group.
    • Read-only. Changes, pause and resend get 409 readonly_node. Shown to admins only.
    • Usage is collected per pod and summed per Gateway (the last interval of a terminating pod is not captured).
  • GET /api/healthz for probes (no sign-in; does not ask the DB or rproxy).

Changed

  • db/migrate.mjs records applied migrations in schema_migrations; on an existing database, the first run needs --baseline (db/README).
  • .deb installs behave as before.

Works with rproxy-api v0.3.5 or later. Seeing Kubernetes rproxy needs rproxy-gateway v0.4.3.