mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Auto import kubernetes template in Helm charts (#3550)
This commit is contained in:
+10
-8
@@ -1,14 +1,16 @@
|
||||
---
|
||||
name: Develop multiple services in Kubernetes
|
||||
name: Develop in Kubernetes
|
||||
description: Get started with Kubernetes development.
|
||||
tags: [cloud, kubernetes]
|
||||
---
|
||||
|
||||
# Getting started
|
||||
|
||||
This template creates a pod running the `codercom/enterprise-base:ubuntu` image.
|
||||
|
||||
## RBAC
|
||||
|
||||
The Coder provisioner requires permission to administer pods to use this template. The template
|
||||
The Coder provisioner requires permission to administer pods to use this template. The template
|
||||
creates workspaces in a single Kubernetes namespace, using the `workspaces_namespace` parameter set
|
||||
while creating the template.
|
||||
|
||||
@@ -20,15 +22,15 @@ kind: Role
|
||||
metadata:
|
||||
name: coder
|
||||
rules:
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["*"]
|
||||
- apiGroups: [""]
|
||||
resources: ["pods"]
|
||||
verbs: ["*"]
|
||||
```
|
||||
|
||||
## Authentication
|
||||
|
||||
This template can authenticate using in-cluster authentication, or using a kubeconfig local to the
|
||||
Coder host. For additional authentication options, consult the [Kubernetes provider
|
||||
Coder host. For additional authentication options, consult the [Kubernetes provider
|
||||
documentation](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs).
|
||||
|
||||
### kubeconfig on Coder host
|
||||
@@ -46,8 +48,8 @@ you can use in-cluster authentication.
|
||||
To use this authentication, set the parameter `use_kubeconfig` to false.
|
||||
|
||||
The Terraform provisioner will automatically use the service account associated with the pod to
|
||||
authenticate to Kubernetes. Be sure to bind a [role with appropriate permission](#rbac) to the
|
||||
service account. For example, assuming the Coder host runs in the same namespace as you intend
|
||||
authenticate to Kubernetes. Be sure to bind a [role with appropriate permission](#rbac) to the
|
||||
service account. For example, assuming the Coder host runs in the same namespace as you intend
|
||||
to create workspaces:
|
||||
|
||||
```yaml
|
||||
@@ -25,17 +25,21 @@ variable "use_kubeconfig" {
|
||||
EOF
|
||||
}
|
||||
|
||||
variable "coder_namespace" {
|
||||
variable "namespace" {
|
||||
type = string
|
||||
sensitive = true
|
||||
description = "The namespace to create workspaces in (must exist prior to creating workspaces)"
|
||||
default = "coder-namespace"
|
||||
default = "coder-workspaces"
|
||||
}
|
||||
|
||||
variable "disk_size" {
|
||||
type = number
|
||||
description = "Disk size (__ GB)"
|
||||
variable "home_disk_size" {
|
||||
type = number
|
||||
description = "How large would you like your home volume to be (in GB)?"
|
||||
default = 10
|
||||
validation {
|
||||
condition = var.home_disk_size >= 1
|
||||
error_message = "Value must be greater than or equal to 1."
|
||||
}
|
||||
}
|
||||
|
||||
provider "kubernetes" {
|
||||
@@ -46,8 +50,8 @@ provider "kubernetes" {
|
||||
data "coder_workspace" "me" {}
|
||||
|
||||
resource "coder_agent" "main" {
|
||||
os = "linux"
|
||||
arch = "amd64"
|
||||
os = "linux"
|
||||
arch = "amd64"
|
||||
startup_script = <<EOT
|
||||
#!/bin/bash
|
||||
|
||||
@@ -66,11 +70,26 @@ resource "coder_app" "code-server" {
|
||||
relative_path = true
|
||||
}
|
||||
|
||||
resource "kubernetes_persistent_volume_claim" "home" {
|
||||
metadata {
|
||||
name = "coder-${data.coder_workspace.me.owner}-${data.coder_workspace.me.name}-home"
|
||||
namespace = var.namespace
|
||||
}
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
resources {
|
||||
requests = {
|
||||
storage = "${var.home_disk_size}Gi"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "kubernetes_pod" "main" {
|
||||
count = data.coder_workspace.me.start_count
|
||||
metadata {
|
||||
name = "coder-${data.coder_workspace.me.owner}-${data.coder_workspace.me.name}"
|
||||
namespace = var.coder_namespace
|
||||
namespace = var.namespace
|
||||
}
|
||||
spec {
|
||||
security_context {
|
||||
@@ -90,28 +109,16 @@ resource "kubernetes_pod" "main" {
|
||||
}
|
||||
volume_mount {
|
||||
mount_path = "/home/coder"
|
||||
name = "home-directory"
|
||||
name = "home"
|
||||
read_only = false
|
||||
}
|
||||
}
|
||||
volume {
|
||||
name = "home-directory"
|
||||
persistent_volume_claim {
|
||||
claim_name = kubernetes_persistent_volume_claim.home-directory.metadata.0.name
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "kubernetes_persistent_volume_claim" "home-directory" {
|
||||
metadata {
|
||||
name = "home-coder-java-${data.coder_workspace.me.owner}-${data.coder_workspace.me.name}"
|
||||
namespace = var.coder_namespace
|
||||
}
|
||||
spec {
|
||||
access_modes = ["ReadWriteOnce"]
|
||||
resources {
|
||||
requests = {
|
||||
storage = "${var.disk_size}Gi"
|
||||
volume {
|
||||
name = "home"
|
||||
persistent_volume_claim {
|
||||
claim_name = kubernetes_persistent_volume_claim.home.metadata.0.name
|
||||
read_only = false
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user