Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions doi/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,32 @@ docker run --rm -it doi:latest /bin/bash
docker run --rm --user tomcat:tomcat --volume=/path/to/external/config:/config:ro --name doi doi:latest
```

## Kubernetes deployment

A Helm chart for deploying the DOI service is provided in `doi/helm` from the
repository root. Start with `doi/helm/examples/values.example.yaml`, provide
the environment-specific registry, service, VOSpace, and DataCite settings,
and create the referenced credential and certificate Secrets out of band.

Validate the chart before installation:

```
helm lint doi/helm \
--set application.config.accountPrefix=10.5072
helm template doi doi/helm \
--namespace doi \
--set application.config.accountPrefix=10.5072
```

Install it with environment-specific values:

```
helm upgrade --install doi doi/helm \
--namespace doi \
--create-namespace \
--values <your-values.yaml>
```

## running it with alternative settings
```
docker run --rm --user tomcat:tomcat --volume=/path/to/external/config:/config:ro --name doi-alt doi:latest
Expand Down
7 changes: 7 additions & 0 deletions doi/helm/.helmignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Patterns to ignore when building packages.
.DS_Store
.git/
.gitignore
.helmignore
*.swp
*.tmp
13 changes: 13 additions & 0 deletions doi/helm/Chart.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
apiVersion: v2
name: doi
description: "A Helm chart to install the Digital Object Identifier service"

maintainers:
- name: Canadian Astronomy Data Centre
email: cadc@nrc-cnrc.gc.ca

type: application

version: 0.1.0

appVersion: "1.2.0"
94 changes: 94 additions & 0 deletions doi/helm/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
# doi

Digital Object Identifier service Helm chart.

This chart deploys the CADC DOI Tomcat service. Non-secret configuration is rendered into a ConfigMap under `/config`; DataCite credentials and the required `doiadmin.pem` and `cadcproxy.pem` files are read from Kubernetes Secrets and merged into the runtime config by an init container. An optional `RsaSignaturePub.key` can also be projected from a Secret for browser cookie validation.

## Required Secrets

Create a Secret for DataCite credentials:

```shell
kubectl create secret generic doi-datacite \
--from-literal=username='<username>' \
--from-literal=password='<password>'
```

Create a Secret for service certificates:

```shell
kubectl create secret generic doi-certs \
--from-file=doiadmin.pem=./doiadmin.pem \
--from-file=cadcproxy.pem=./cadcproxy.pem
```

Create the optional Secret containing the cookie-signature public key:

```shell
kubectl create secret generic doi-cookie-signature-public-key \
--from-file=RsaSignaturePub.key=./RsaSignaturePub.key
```

Set:

```yaml
application:
datacite:
auth:
existingSecret: doi-datacite
certificates:
existingSecret: doi-certs
cookieSignaturePublicKey:
existingSecret:
name: doi-cookie-signature-public-key
path: RsaSignaturePub.key
```

## Example Values

Start from `examples/values.example.yaml` and replace the example hostnames, registry IDs, VOSpace URI, DataCite account prefix, and Secret names.

## Test the Chart

Render and lint the chart with non-secret placeholder Secret names:

```shell
helm lint doi/helm \
--set application.datacite.auth.existingSecret=doi-datacite \
--set application.certificates.existingSecret=doi-certs \
--set application.config.accountPrefix=10.5072

helm template doi doi/helm \
--namespace doi \
--set application.datacite.auth.existingSecret=doi-datacite \
--set application.certificates.existingSecret=doi-certs \
--set application.config.accountPrefix=10.5072
```

Dry-run against a cluster:

```shell
helm upgrade --install doi doi/helm \
--namespace doi \
--create-namespace \
--values doi/helm/examples/values.example.yaml \
--dry-run
```

Install after replacing the example values and creating the required Secrets:

```shell
helm upgrade --install doi doi/helm \
--namespace doi \
--create-namespace \
--values <your-values.yaml>
```

Check the workload:

```shell
kubectl -n doi get pods
kubectl -n doi logs deploy/doi-tomcat
kubectl -n doi port-forward svc/doi-tomcat-svc 18080:8080
curl http://localhost:18080/doi/availability
```
3 changes: 3 additions & 0 deletions doi/helm/config/cadc-log.properties
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{{- range $val := .Values.application.loggingGroups }}
group = {{ $val }}
{{- end }}
21 changes: 21 additions & 0 deletions doi/helm/config/cadc-registry.properties
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
#
# local authority map
#
{{- with .Values.application.gmsID }}
ivo://ivoa.net/std/GMS#search-1.0 = {{ . }}
ivo://ivoa.net/std/GMS#search-0.1 = {{ . }}
ivo://ivoa.net/std/GMS#users-1.0 = {{ . }}
ivo://ivoa.net/std/UMS#users-0.1 = {{ . }}
ivo://ivoa.net/std/UMS#users-1.0 = {{ . }}
ivo://ivoa.net/sso#tls-with-password = {{ . }}
{{- end }}
{{- with .Values.application.oidcURI }}
ivo://ivoa.net/sso#OAuth = {{ . }}
ivo://ivoa.net/sso#OpenID = {{ . }}
{{- end }}

{{- $raw := .Values.application.registryURL -}}
{{- $urls := ternary (list $raw) $raw (kindIs "string" $raw) -}}
{{- range $urls }}
ca.nrc.cadc.reg.client.RegistryClient.baseURL = {{ . }}
{{- end }}
10 changes: 10 additions & 0 deletions doi/helm/config/catalina.properties
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
tomcat.connector.connectionTimeout=180000
tomcat.connector.keepAliveTimeout=180000
tomcat.connector.secure=true
tomcat.connector.scheme=https
tomcat.connector.proxyName={{ include "doi.hostname" . }}
tomcat.connector.proxyPort=443
ca.nrc.cadc.auth.PrincipalExtractor.enableClientCertHeader=true
ca.nrc.cadc.util.Log4jInit.messageOnly=true
# (default: ca.nrc.cadc.auth.NoOpIdentityManager)
ca.nrc.cadc.auth.IdentityManager={{ .Values.application.identityManagerClass }}
19 changes: 19 additions & 0 deletions doi/helm/config/doi.properties
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
ca.nrc.cadc.doi.vospaceParentUri = {{ .Values.application.config.vospaceParentUri | required ".Values.application.config.vospaceParentUri is required" }}
ca.nrc.cadc.doi.metaDataPrefix = {{ .Values.application.config.metaDataPrefix | required ".Values.application.config.metaDataPrefix is required" }}
ca.nrc.cadc.doi.groupPrefix = {{ .Values.application.config.groupPrefix | required ".Values.application.config.groupPrefix is required" }}
ca.nrc.cadc.doi.landingUrl = {{ .Values.application.config.landingUrl | required ".Values.application.config.landingUrl is required" }}
ca.nrc.cadc.doi.datacite.mdsUrl = {{ .Values.application.config.mdsUrl | required ".Values.application.config.mdsUrl is required" }}
ca.nrc.cadc.doi.datacite.accountPrefix = {{ .Values.application.config.accountPrefix | required ".Values.application.config.accountPrefix is required" }}
{{- with .Values.application.config.doiIdentifierPrefix }}
ca.nrc.cadc.doi.doiIdentifierPrefix = {{ . }}
{{- end }}
{{- with .Values.application.config.publisherGroupURI }}
ca.nrc.cadc.doi.publisherGroupURI = {{ . }}
{{- end }}
{{- with .Values.application.config.selfPublish }}
ca.nrc.cadc.doi.selfPublish = {{ . }}
{{- end }}
{{- if .Values.application.config.randomTestID }}
ca.nrc.cadc.doi.randomTestID = true
{{- end }}
# ca.nrc.cadc.doi.datacite.username and ca.nrc.cadc.doi.datacite.password are appended at pod startup from Secret {{ include "doi.dataciteAuthSecretName" . }}.
3 changes: 3 additions & 0 deletions doi/helm/config/war-rename.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{{- if and .Values.application.applicationName (ne .Values.application.applicationName "doi") }}
mv doi.war {{ .Values.application.applicationName }}.war
{{- end }}
58 changes: 58 additions & 0 deletions doi/helm/examples/values.example.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# Example values for deploying the DOI service.
#
# Copy this file and replace the example values with your environment-specific
# hostnames, registry IDs, VOSpace URI, DataCite account, and Secret names.

image:
repository: bucket.canfar.net/doi
tag: "1.2.0"

imagePullSecrets:
- name: bucket-registry-auth

application:
registryURL: https://doi.example.org/reg
gmsID: ivo://example.org/gms
oidcURI: https://iam.example.org/

config:
vospaceParentUri: vos://example.org~arc/doi
metaDataPrefix: doi
groupPrefix: doi
landingUrl: https://doi.example.org/doi
mdsUrl: https://mds.datacite.org
accountPrefix: "10.5072"

datacite:
auth:
existingSecret: doi-datacite

certificates:
existingSecret: doi-certs

cookieSignaturePublicKey:
existingSecret:
name: doi-cookie-signature-public-key
path: RsaSignaturePub.key

ingress:
enabled: true
className: traefik
hosts:
- host: doi.example.org
paths:
- path: /doi
pathType: Prefix

httpRoute:
enabled: false
parentRefs:
- name: gateway
sectionName: http
hostnames:
- doi.example.org
rules:
- matches:
- path:
type: PathPrefix
value: /doi
13 changes: 13 additions & 0 deletions doi/helm/templates/NOTES.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
'{{ .Chart.Name }}' installed successfully. You can monitor it in the {{ .Release.Namespace }} Namespace:

kubectl -n {{ .Release.Namespace }} get pods

Your release is named {{ .Release.Name }}.

The DOI service expects DataCite credentials from Secret {{ include "doi.dataciteAuthSecretName" . }}
and PEM certificates from Secret {{ include "doi.certificateSecretName" . }}.

To learn more about the release, try:

$ helm -n {{ .Release.Namespace }} status {{ .Release.Name }}
$ helm -n {{ .Release.Namespace }} get all {{ .Release.Name }}
78 changes: 78 additions & 0 deletions doi/helm/templates/_helpers.tpl
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
{{/*
Expand the name of the chart.
*/}}
{{- define "doi.name" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}

{{/*
Create chart name and version as used by the chart label.
*/}}
{{- define "doi.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}

{{/*
Selector labels
*/}}
{{- define "doi.selectorLabels" -}}
app.kubernetes.io/name: {{ include "doi.name" . }}
app.kubernetes.io/instance: {{ .Release.Name }}
{{- end }}

{{/*
Common labels
*/}}
{{- define "doi.labels" -}}
helm.sh/chart: {{ include "doi.chart" . }}
{{ include "doi.selectorLabels" . }}
{{- if .Chart.AppVersion }}
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
{{- end }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- end }}

{{/*
Use the Gateway API hostname when HTTPRoute is enabled; otherwise use the
first configured Ingress hostname. DOI needs this to construct external URLs.
*/}}
{{- define "doi.hostname" -}}
{{- if .Values.httpRoute.enabled -}}
{{- $hostnames := .Values.httpRoute.hostnames | default (list) -}}
{{- if eq (len $hostnames) 0 -}}
{{- fail "httpRoute.hostnames must contain at least one hostname when httpRoute.enabled is true" -}}
{{- end -}}
{{- index $hostnames 0 -}}
{{- else -}}
{{- $hosts := .Values.ingress.hosts | default (list) -}}
{{- if eq (len $hosts) 0 -}}
{{- fail "ingress.hosts must contain at least one hostname when httpRoute is disabled" -}}
{{- end -}}
{{- index (index $hosts 0) "host" -}}
{{- end -}}
{{- end }}

{{/*
Create the name of the service account to use.
*/}}
{{- define "doi.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (printf "%s-service-account" .Release.Name) .Values.serviceAccount.name }}
{{- else }}
{{- default "default" .Values.serviceAccount.name }}
{{- end }}
{{- end }}

{{/*
DataCite credential Secret name.
*/}}
{{- define "doi.dataciteAuthSecretName" -}}
{{- required "application.datacite.auth.existingSecret is required" .Values.application.datacite.auth.existingSecret -}}
{{- end -}}

{{/*
PEM certificate Secret name.
*/}}
{{- define "doi.certificateSecretName" -}}
{{- required "application.certificates.existingSecret is required" .Values.application.certificates.existingSecret -}}
{{- end -}}
9 changes: 9 additions & 0 deletions doi/helm/templates/configmap.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ .Release.Name }}-config
namespace: {{ .Release.Namespace }}
labels:
{{- include "doi.labels" . | nindent 4 }}
data:
{{ tpl (.Files.Glob "config/*").AsConfig . | indent 2 }}
Loading
Loading