jump to content

Kubernetes

Step by step guide to the deployment of the platform on Kubernetes with Helm diagram, external PostgreSQL and S3 storage, input, monitoring and upgrades.

Show as Markdown

For production, connect the graph to an external PostgreSQL database and to an S3 compatible object storage space, which your team already operates and backups.

Use Kubernetes when your team has already established practices for entries, certificates, secrecy, monitoring and database operations.

  • Kubernetes 1.23 or newer
  • Helm 3.8 or newer
  • kubectl access to the target cluster
  • A PostgreSQL database accessible from the cluster
  • S3 sau S3 compatibil testat
  • An entry controller and a certificate
  • A SMTP relay if you want the platform to send emails

The database role must be able to create or use citext, pgcrypto, unaccent and pg_stat_statements extensions. On PostgreSQL 15 and later, make the platform’s role the scheme owner ___ZBT_I18N_RUNTIME_BLOCK_169__ before first start:

ALTER SCHEMA public OWNER TO probod;
GRANT ALL ON SCHEMA public TO probod;
  1. Choose and pin a chart version

    The chart is published at oci://artifact.probo.inc/probo/probo. Set the version you tested:

    Terminal window
    export PROBO_CHART_VERSION="0.0.0"
    helm show chart oci://artifact.probo.inc/probo/probo \
    --version "$PROBO_CHART_VERSION"

    Replace 0.0.0 with a available version of the chart.

  2. Generate application secrets

    Terminal window
    umask 077
    openssl rand -base64 32
    openssl rand -base64 32
    openssl rand -base64 32
    openssl rand -base64 32
    openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 \
    -out oauth2-signing-key.pem

    Record the four values generated separately as the encryption key, cookie secret, password pepper, and trusted token secret.

  3. Create non-secret values

    Save the following as values.yaml and replace the example host name and service details:

    replicaCount: 2
    haproxy-ingress:
    enabled: false
    ingress:
    enabled: true
    className: nginx
    annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
    hosts:
    - host: probo.example.com
    paths:
    - path: /
    pathType: Prefix
    tls:
    - secretName: probo-tls
    hosts:
    - probo.example.com
    probo:
    baseUrl: probo.example.com
    cors:
    allowedOrigins:
    - https://probo.example.com
    auth:
    disableSignup: true
    cookieDomain: probo.example.com
    trustAuth:
    cookieDomain: probo.example.com
    mailer:
    senderName: Probo
    senderEmail: no-reply@example.com
    smtp:
    addr: smtp.example.com:587
    tlsRequired: true
    postgresql:
    enabled: false
    host: postgres.example.internal
    port: 5432
    database: probod
    username: probod
    seaweedfs:
    enabled: false
    s3:
    region: eu-west-1
    bucket: probo-production
    endpoint: ""
    usePathStyle: false
    chrome:
    enabled: true
    resources:
    requests:
    cpu: 500m
    memory: 1Gi
    limits:
    cpu: 2
    memory: 4Gi

    If you intentionally want the graph to install HAProxy Ingress, enable haproxy-ingress and set ingress.className to haproxy.

  4. Create secret values

    Save the following as values-secrets.yaml, complete each locator and keep the file out of version control:

    probo:
    encryptionKey: "<base64 encryption key>"
    auth:
    cookieSecret: "<base64 cookie secret>"
    passwordPepper: "<base64 password pepper>"
    trustAuth:
    tokenSecret: "<base64 trust-token secret>"
    mailer:
    smtp:
    user: "<SMTP username>"
    password: "<SMTP password>"
    postgresql:
    password: "<database password>"
    s3:
    accessKeyId: "<S3 access key>"
    secretAccessKey: "<S3 secret key>"
    Terminal window
    chmod 600 values-secrets.yaml oauth2-signing-key.pem
  5. Reply and check the manifesto

    Terminal window
    helm template probo oci://artifact.probo.inc/probo/probo \
    --version "$PROBO_CHART_VERSION" \
    --namespace probo \
    --values values.yaml \
    --values values-secrets.yaml \
    --set-file probo.oauth2.signingKey=oauth2-signing-key.pem \
    > rendered.yaml

    Check the resource name, entry class, storage, security context and programming behavior. rendered.yaml contains secrets; safely delete it after review and do not commit it.

  6. Install the platform

    Terminal window
    kubectl create namespace probo
    helm install probo oci://artifact.probo.inc/probo/probo \
    --version "$PROBO_CHART_VERSION" \
    --namespace probo \
    --values values.yaml \
    --values values-secrets.yaml \
    --set-file probo.oauth2.signingKey=oauth2-signing-key.pem \
    --wait \
    --timeout 10m
  7. Verify the deployment

    Terminal window
    helm status probo --namespace probo
    kubectl get pods,service,ingress \
    --namespace probo \
    --selector app.kubernetes.io/instance=probo
    kubectl rollout status deployment/probo \
    --namespace probo \
    --timeout=10m
    kubectl logs deployment/probo \
    --namespace probo \
    --tail=100

    Once DNS and TLS are ready, check the public point:

    Terminal window
    curl --fail https://probo.example.com/

    Also test authentication, file uploading, PDF generation, and email delivery before inviting users.

Deactivate it when the cluster already has an input controller; otherwise, the installation may create an unexpected public load balancer.

The diagram directs the input to the back-office port of the platform. TLS configuration depends on your input controller and certificate system.

  • numai serviciile publice destinate primesc adrese externe;
  • HTTP redirects to HTTPS;
  • Configured host name matches probo.baseUrl;
  • probo.cors.allowedOrigins contains the full HTTPS source;
  • Cookies are targeted to the desired domain.

Do not claim high availability only by increasing the number replicaCount.

The assembly chart /data from emptyDir by default. Allowing persistence creates or assembles a single PVC, and the production example uses ReadWriteOnce. Multiple bridges programmed on different nodes may not be able to assemble this claim.

PostgreSQL and S3 remain the durable recording systems. Backup both services at a consistent recovery point and restoration testing regularly.

The default pool size is 100 connections per bridge platform. The replica account and running updates when setting PostgreSQL connection limits. For example, three current pods plus a growth bridge can substantially require more than 300 connections.

If your provider requires a custom CA, set postgresql.caBundle or mount a certificate and set postgresql.caBundlePath.

For AWSS3, leave s3.endpoint empty and s3.usePathStyle false. Other providers may require a custom endpoint and a path-style address.

Testing uploads, downloads, object metadata and deletions against the provider just before use in production. Azure Blob behind a S3 compatibility proxy has known limitations on metadata compatibility and should not be treated as an accepted equivalent without testing.

the platform exposes the metrics on the port 8081. If Prometheus Operator is installed, activate the graph ServiceMonitor:

metrics:
serviceMonitor:
enabled: true
interval: 30s

At least, warn about unavailable pods, reopening cycles, unsuccessful deployments, database and object storage errors, certificate expiry, and exhausted database connections.

Upgrade and rollback

“Upgrade and rollback”

Examine the platform and chart launch notes, back up PostgreSQL and S3 and test the target version in a non-production environment.

Terminal window
export PROBO_CHART_VERSION="0.0.0"
helm upgrade probo oci://artifact.probo.inc/probo/probo \
--version "$PROBO_CHART_VERSION" \
--namespace probo \
--values values.yaml \
--values values-secrets.yaml \
--set-file probo.oauth2.signingKey=oauth2-signing-key.pem \
--wait \
--timeout 10m

Database migrations run automatically when the platform starts. Follow both deployment and application logs:

Terminal window
kubectl rollout status deployment/probo --namespace probo --timeout=10m
kubectl logs deployment/probo --namespace probo --tail=200

If you need to return to the application version, first determine whether the database migration is back-compatible.

Terminal window
helm history probo --namespace probo
helm rollback probo REVISION --namespace probo --wait --timeout 10m
Terminal window
kubectl get pods --namespace probo
kubectl describe pod POD_NAME --namespace probo
kubectl logs POD_NAME --namespace probo --previous
kubectl get events --namespace probo --sort-by=.metadata.creationTimestamp

Common causes are invalid secret formats, a missing OAuth signature key, unavailable database extensions, database network policies, and an inaccessible S3 endpoint.

The ingress has no address

“The ingress has no address”
Terminal window
kubectl describe ingress probo-http --namespace probo
kubectl get ingressclass

Confirms that ingress.className names a controller installed and inspects the logs of that controller.

Terminal window
kubectl get pvc --namespace probo
kubectl describe pvc probo --namespace probo

Check volume access mode, storage class, availability area and bridge scheduling events. A single volume ReadWriteOnce is not a portable shared storage design for multi-noded replicas.

See the chart’s values.yaml şi a environment variable reference for additional configuration.

Ultima actualizare: