diff --git a/helm/config/nginx/default.conf b/helm/config/nginx/default.conf deleted file mode 100644 index cb3a3dc..0000000 --- a/helm/config/nginx/default.conf +++ /dev/null @@ -1,102 +0,0 @@ -{{- $serviceName := printf "%s-service" (include "3d-extractable-management.fullname" .) -}} -{{- $opalaEnabled := .Values.nginx.authorization.enabled }} -{{- $accessControlMaxAge := default 1728000 .Values.nginx.nginx.maxAge }} - -split_clients "$otel_trace_id" $ratio_sampler { - {{ .Values.nginx.opentelemetry.ratio }}% on; - * off; -} - -upstream 3d-extractable-management-service { - server {{ $serviceName }}:{{ .Values.env.port }}; -} - -server { - listen {{ .Values.env.port }}; - # the domain name it will serve for - server_name 3d-extractable-management-service; - - proxy_request_buffering off; # upstream server can hanle large streaming uploads - proxy_http_version 1.1; # required to disable request buffering also for clients that send chunked encoding - client_max_body_size 0; # otherwise nginx imposes a size restriction; only upstream should decide that - - # max upload size, adjust to taste - # keepalive_timeout 500; - # proxy_connect_timeout 600; - # proxy_send_timeout 600; - # send_timeout 600; - # client_max_body_size 5000; - # client_header_timeout 600; - # client_body_timeout 600; - # client_header_buffer_size 5M; - # large_client_header_buffers 4 12288; # 12K - # fastcgi_read_timeout 300; - - # OpenShift route is configured to time out HTTP requests that are longer than 30 seconds: - # route.yaml -> annotations: -> haproxy.router.openshift.io/timeout: 30s - # The following value MUST be smaller to avoid unwanted behaviour (timeout with status code 200) - # Calculation: average (without cache) multiplied by "factor" which should correlates with response time while high load - proxy_read_timeout 60s; - - location /liveness { - access_log off; - return 200; - } - - location / { - {{ include "3d-extractable-management-nginx.otelTrace" . | nindent 8 }} - - if ($request_method = 'OPTIONS') { - add_header 'Access-Control-Allow-Origin' '*'; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE'; - # - # Custom headers and headers various browsers *should* be OK with but aren't - # - add_header 'Access-Control-Allow-Headers' 'DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization,x-api-key'; - # - # Tell client that this pre-flight info is valid for x days - # - add_header 'Access-Control-Max-Age' {{ $accessControlMaxAge }}; - add_header 'Content-Type' 'text/plain charset=UTF-8'; - add_header 'Content-Length' 0; - return 204; - } - - # Ensure CORS headers are present on all responses (including proxied/error responses) - add_header 'Access-Control-Allow-Origin' '*' always; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE' always; - add_header 'Access-Control-Allow-Headers' 'DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization,x-api-key' always; - add_header 'Access-Control-Max-Age' {{ $accessControlMaxAge }} always; - - proxy_hide_header Set-Cookie; # ensures the header will not be passed back to the client - proxy_ignore_headers Set-Cookie; # ensures that the header will not automatically disable caching within nginx - proxy_set_header Cookie ""; # ensures that a client cannot pass any prior cookies to the webapp and spoil your cache - - set $original_method $request_method; - set $original_args $args; - - {{- if $opalaEnabled }} - set $domain {{ .Values.nginx.authorization.domain }}; - auth_request /_validate_jwt; - - otel_span_attr opa.result $opa_result; - otel_span_attr opa.reason $opa_reason; - {{ end }} - - proxy_pass http://3d-extractable-management-service; - } - - {{- if $opalaEnabled }} - location = /_validate_jwt { - internal; - js_content auth.opaAuth; - } - - location = /opa { - internal; - - proxy_set_header Content-Type application/json; - proxy_pass {{ .Values.nginx.authorization.url }}; - } - {{ end }} -} diff --git a/helm/config/nginx/log_format.conf b/helm/config/nginx/log_format.conf deleted file mode 100644 index 7f7968a..0000000 --- a/helm/config/nginx/log_format.conf +++ /dev/null @@ -1,46 +0,0 @@ -map $msec $nanosec { - ~(.*)\.(.*) $1$2000000; -} - -log_format json escape=json -'{' - '"Timestamp":"$nanosec",' - '"Attributes":{' - '"mapcolonies.time_local":"$time_local",' - {{ if and (.Values.global.opalaEnabled) (.Values.nginx.authorization.enabled) }} - '"mapcolonies.http.auth.token.client_name":"$jwt_payload_sub",' - {{ end }} - '"http.request.method":"$request_method",' - '"http.request.header.referer":"$http_referer",' - '"http.request.body.size":"$content_length",' - '"http.response.body.size":"$body_bytes_sent",' - '"http.response.header.x_forwarded_for":"$proxy_add_x_forwarded_for",' - '"http.response.status_code":"$status",' - '"user_agent.original":"$http_user_agent",' - '"network.protocol":"$server_protocol",' - '"mapcolonies.request_time":"$request_time",' - '"mapcolonies.http.upstream_connect_time":"$upstream_connect_time",' - '"mapcolonies.http.upstream_response_time":"$upstream_response_time",' - '"mapcolonies.http.upstream_addr":"$upstream_addr",' - '"mapcolonies.http.upstream_status_code":"$upstream_status",' - '"mapcolonies.http.upstream_cache_status":"$upstream_cache_status",' - '"mapcolonies.server":"$hostname",' - '"server.address":"$host",' - '"server.port":"$server_port",' - '"client.address":"$remote_addr",' - '"client.port":"$remote_port",' - '"url.scheme":"$scheme",' - '"url.path":"$uri",' - '"url.full":"$request_uri"' - '},' - '"Resource":{' - '"service.name":"{{ .Values.image.repository }}",' - '"service.version":"{{ .Values.image.tag }}"' - '},' - '"TraceId":"$otel_trace_id",' ## this is a byte sequence (hex-encoded in JSON) - '"SpanId":"$otel_span_id",' - '"SeverityText":"INFO",' - '"SeverityNumber":"9",' - '"InstrumentationScope":"access.log",' - '"Body":"$request"' -'}'; diff --git a/helm/config/nginx/nginx.conf b/helm/config/nginx/nginx.conf deleted file mode 100644 index 6651bac..0000000 --- a/helm/config/nginx/nginx.conf +++ /dev/null @@ -1,41 +0,0 @@ -#user nginx; -load_module modules/ngx_http_js_module.so; -load_module modules/ngx_otel_module.so; -worker_processes 4; - -error_log /var/log/nginx/error.log warn; -pid /tmp/nginx.pid; - -events { - worker_connections 1024; -} - -http { - otel_service_name {{ .Values.nginx.opentelemetry.serviceName }}; - otel_exporter { - endpoint {{ .Values.nginx.opentelemetry.exporterHost }}:{{ .Values.nginx.opentelemetry.exporterPort }}; - } - - include /etc/nginx/mime.types; - default_type application/octet-stream; - - {{ if .Values.nginx.authorization.enabled }} - js_import auth from /etc/nginx/auth.js; - js_set $jwt_payload_sub auth.jwtPayloadSub; - - js_var $opa_result; - js_var $opa_reason; - {{ end }} - - include /etc/nginx/log_format.conf; - access_log /var/log/nginx/access.log json; - - sendfile on; - #tcp_nopush on; - - keepalive_timeout 65; - - #gzip on; - - include /etc/nginx/conf.d/*.conf; -} diff --git a/helm/templates/nginx/configmap.yaml b/helm/templates/nginx/configmap.yaml deleted file mode 100644 index 983b18f..0000000 --- a/helm/templates/nginx/configmap.yaml +++ /dev/null @@ -1,18 +0,0 @@ -{{- if .Values.nginx.enabled -}} -{{- $chartName := include "3d-extractable-management.name" . -}} -{{- $environment := include "3d-extractable-management.environment" . -}} -{{- $releaseName := .Release.Name -}} -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ .Release.Name }}-{{ $chartName }}-nginx-configmap - labels: - app: {{ $releaseName }}-{{ $chartName }} - component: nginx-configmap - environment: {{ $environment }} - release: {{ $releaseName }} -data: - log_format.conf: {{ tpl (.Files.Get "config/nginx/log_format.conf") . | quote }} - default.conf: {{ tpl (.Files.Get "config/nginx/default.conf") . | quote }} - nginx.conf: {{ tpl (.Files.Get "config/nginx/nginx.conf") . | quote }} -{{- end }} diff --git a/helm/values.yaml b/helm/values.yaml index ed67e14..3a7aede 100644 --- a/helm/values.yaml +++ b/helm/values.yaml @@ -130,6 +130,10 @@ resources: memory: 128Mi nginx: + mclabels: + partOf: extractable + owner: 3d + gisDomain: 3d nginx: maxAge: 1728000 enabled: true @@ -175,22 +179,6 @@ nginx: cpu: 100m memory: 128Mi - extraVolumes: - - name: nginx-config - configMap: - name: "{{ .Release.Name }}-3d-extractable-management-nginx-configmap" - - extraVolumeMounts: - - name: nginx-config - mountPath: "/etc/nginx/conf.d/default.conf" - subPath: default.conf - - name: nginx-config - mountPath: "/etc/nginx/nginx.conf" - subPath: nginx.conf - - name: nginx-config - mountPath: "/etc/nginx/log_format.conf" - subPath: log_format.conf - env: opentelemetry: serviceName: nginx