Kubernetes
Step by step guide to the deployment of the platform on Kubernetes with Helm diagram, external PostgreSQL and S3 storage, input, monitoring and upgrades.
For production, connect the graph to an external PostgreSQL database and to an S3 compatible object storage space, which your team already operates and backups.
Use Kubernetes when your team has already established practices for entries, certificates, secrecy, monitoring and database operations.
Requirements
Section titled ‘Requirements’- Kubernetes 1.23 or newer
- Helm 3.8 or newer
kubectlaccess to the target cluster- A PostgreSQL database accessible from the cluster
- S3 sau S3 compatibil testat
- An entry controller and a certificate
- A SMTP relay if you want the platform to send emails
The database role must be able to create or use citext, pgcrypto, unaccent and pg_stat_statements extensions. On PostgreSQL 15 and later, make the platform’s role the scheme owner ___ZBT_I18N_RUNTIME_BLOCK_169__ before first start:
ALTER SCHEMA public OWNER TO probod;GRANT ALL ON SCHEMA public TO probod;Prepare the deployment
Section entitled “Prepare the deployment”-
Choose and pin a chart version
The chart is published at
oci://artifact.probo.inc/probo/probo. Set the version you tested:Terminal window export PROBO_CHART_VERSION="0.0.0"helm show chart oci://artifact.probo.inc/probo/probo \--version "$PROBO_CHART_VERSION"Replace
0.0.0with a available version of the chart. -
Generate application secrets
Terminal window umask 077openssl rand -base64 32openssl rand -base64 32openssl rand -base64 32openssl rand -base64 32openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 \-out oauth2-signing-key.pemRecord the four values generated separately as the encryption key, cookie secret, password pepper, and trusted token secret.
-
Create non-secret values
Save the following as
values.yamland replace the example host name and service details:replicaCount: 2haproxy-ingress:enabled: falseingress:enabled: trueclassName: nginxannotations:cert-manager.io/cluster-issuer: letsencrypt-prodhosts:- host: probo.example.compaths:- path: /pathType: Prefixtls:- secretName: probo-tlshosts:- probo.example.comprobo:baseUrl: probo.example.comcors:allowedOrigins:- https://probo.example.comauth:disableSignup: truecookieDomain: probo.example.comtrustAuth:cookieDomain: probo.example.commailer:senderName: ProbosenderEmail: no-reply@example.comsmtp:addr: smtp.example.com:587tlsRequired: truepostgresql:enabled: falsehost: postgres.example.internalport: 5432database: probodusername: probodseaweedfs:enabled: falses3:region: eu-west-1bucket: probo-productionendpoint: ""usePathStyle: falsechrome:enabled: trueresources:requests:cpu: 500mmemory: 1Gilimits:cpu: 2memory: 4GiIf you intentionally want the graph to install HAProxy Ingress, enable
haproxy-ingressand setingress.classNametohaproxy. -
Create secret values
Save the following as
values-secrets.yaml, complete each locator and keep the file out of version control:probo:encryptionKey: "<base64 encryption key>"auth:cookieSecret: "<base64 cookie secret>"passwordPepper: "<base64 password pepper>"trustAuth:tokenSecret: "<base64 trust-token secret>"mailer:smtp:user: "<SMTP username>"password: "<SMTP password>"postgresql:password: "<database password>"s3:accessKeyId: "<S3 access key>"secretAccessKey: "<S3 secret key>"Terminal window chmod 600 values-secrets.yaml oauth2-signing-key.pem -
Reply and check the manifesto
Terminal window helm template probo oci://artifact.probo.inc/probo/probo \--version "$PROBO_CHART_VERSION" \--namespace probo \--values values.yaml \--values values-secrets.yaml \--set-file probo.oauth2.signingKey=oauth2-signing-key.pem \> rendered.yamlCheck the resource name, entry class, storage, security context and programming behavior.
rendered.yamlcontains secrets; safely delete it after review and do not commit it. -
Install the platform
Terminal window kubectl create namespace probohelm install probo oci://artifact.probo.inc/probo/probo \--version "$PROBO_CHART_VERSION" \--namespace probo \--values values.yaml \--values values-secrets.yaml \--set-file probo.oauth2.signingKey=oauth2-signing-key.pem \--wait \--timeout 10m -
Verify the deployment
Terminal window helm status probo --namespace probokubectl get pods,service,ingress \--namespace probo \--selector app.kubernetes.io/instance=probokubectl rollout status deployment/probo \--namespace probo \--timeout=10mkubectl logs deployment/probo \--namespace probo \--tail=100Once DNS and TLS are ready, check the public point:
Terminal window curl --fail https://probo.example.com/Also test authentication, file uploading, PDF generation, and email delivery before inviting users.
Production decisions
Section entitled “Production decisions”Ingress and TLS
Section entitled “Ingress andTLS”Deactivate it when the cluster already has an input controller; otherwise, the installation may create an unexpected public load balancer.
The diagram directs the input to the back-office port of the platform. TLS configuration depends on your input controller and certificate system.
- numai serviciile publice destinate primesc adrese externe;
- HTTP redirects to HTTPS;
- Configured host name matches
probo.baseUrl; probo.cors.allowedOriginscontains the full HTTPS source;- Cookies are targeted to the desired domain.
Replicas and local storage
Section “Replicas and local storage”Do not claim high availability only by increasing the number replicaCount.
The assembly chart /data from emptyDir by default. Allowing persistence creates or assembles a single PVC, and the production example uses ReadWriteOnce. Multiple bridges programmed on different nodes may not be able to assemble this claim.
PostgreSQL and S3 remain the durable recording systems. Backup both services at a consistent recovery point and restoration testing regularly.
Database connections
Section entitled “Database connections”The default pool size is 100 connections per bridge platform. The replica account and running updates when setting PostgreSQL connection limits. For example, three current pods plus a growth bridge can substantially require more than 300 connections.
If your provider requires a custom CA, set postgresql.caBundle or mount a certificate and set postgresql.caBundlePath.
S3 compatibility
Section entitled “S3 compatibility”For AWSS3, leave s3.endpoint empty and s3.usePathStyle false. Other providers may require a custom endpoint and a path-style address.
Testing uploads, downloads, object metadata and deletions against the provider just before use in production. Azure Blob behind a S3 compatibility proxy has known limitations on metadata compatibility and should not be treated as an accepted equivalent without testing.
Monitoring
Section “Monitoring”the platform exposes the metrics on the port 8081. If Prometheus Operator is installed, activate the graph ServiceMonitor:
metrics: serviceMonitor: enabled: true interval: 30sAt least, warn about unavailable pods, reopening cycles, unsuccessful deployments, database and object storage errors, certificate expiry, and exhausted database connections.
Upgrade and rollback
“Upgrade and rollback”Examine the platform and chart launch notes, back up PostgreSQL and S3 and test the target version in a non-production environment.
export PROBO_CHART_VERSION="0.0.0"
helm upgrade probo oci://artifact.probo.inc/probo/probo \ --version "$PROBO_CHART_VERSION" \ --namespace probo \ --values values.yaml \ --values values-secrets.yaml \ --set-file probo.oauth2.signingKey=oauth2-signing-key.pem \ --wait \ --timeout 10mDatabase migrations run automatically when the platform starts. Follow both deployment and application logs:
kubectl rollout status deployment/probo --namespace probo --timeout=10mkubectl logs deployment/probo --namespace probo --tail=200If you need to return to the application version, first determine whether the database migration is back-compatible.
helm history probo --namespace probohelm rollback probo REVISION --namespace probo --wait --timeout 10mTroubleshooting
Section “Troubleshooting”Pods do not start
Section titled “Pods do not start”kubectl get pods --namespace probokubectl describe pod POD_NAME --namespace probokubectl logs POD_NAME --namespace probo --previouskubectl get events --namespace probo --sort-by=.metadata.creationTimestampCommon causes are invalid secret formats, a missing OAuth signature key, unavailable database extensions, database network policies, and an inaccessible S3 endpoint.
The ingress has no address
“The ingress has no address”kubectl describe ingress probo-http --namespace probokubectl get ingressclassConfirms that ingress.className names a controller installed and inspects the logs of that controller.
A rollout cannot mount /data
Section entitled “A rollout cannot mount/data”kubectl get pvc --namespace probokubectl describe pvc probo --namespace proboCheck volume access mode, storage class, availability area and bridge scheduling events. A single volume ReadWriteOnce is not a portable shared storage design for multi-noded replicas.
See the chart’s values.yaml şi a environment variable reference for additional configuration.