Files
athletic-map-deploy/tenants/teste5/95-frontend-spa.yaml
T

185 lines
10 KiB
YAML

# =============================================================================
# P4.9 — a SPA, e com ela o roteamento interno de /bff e /api (P4.6).
#
# `teste5` e substituido ao provisionar.
#
# ── O QUE MUDOU EM RELACAO AO MOLDE ANTIGO ──────────────────────────────────
#
# O nginx desta imagem roteia `/bff` e `/api` por conta propria, a partir de
# `ATM_BFF_URL` e `ATM_API_URL`. Por isso o Ingress deste molde tem UMA rota — e
# nao uma linha por contexto, que era o que obrigava a editar o Ingress de todos
# os tenants a cada mudanca de topologia.
#
# O `/api` aponta para o `runtime-operacao` porque e ele quem recebe o webhook do
# provedor de pagamento em `/api/public/**`. Os outros caminhos de `/api` sao
# resolvidos pelo proprio nginx? NAO — e por isso esta linha e provisoria.
#
# **PENDENCIA CONHECIDA:** `/api/cadastro`, `/api/saude` e os demais precisam ir
# para runtimes DIFERENTES, e uma variavel so nao faz isso. O nginx precisa de
# uma regra por grupo de contexto. Esta no diario; ate resolver, use o Ingress
# para separar, como hoje.
# =============================================================================
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontend-spa
namespace: teste5-prod
spec:
replicas: 1
selector:
matchLabels: { app: frontend-spa }
template:
metadata:
labels: { app: frontend-spa, athleticmap.io/bff-aqui: "true" }
spec:
containers:
- name: frontend-spa
image: docker.io/library/frontend-spa:2.82-aviso-cobranca
imagePullPolicy: Never
ports: [{ containerPort: 80 }]
env:
- { name: ATM_KC_URL, value: "https://auth.athleticmap.com" }
- { name: ATM_REALM, value: "athleticmap-9" }
- { name: ATM_CLIENT, value: "spa" }
- { name: ATM_TENANT, value: "teste5" }
- { name: ATM_PLANO, value: "bronze" }
# P4.6 fechado 2026-09-26: o BFF e o SEGUNDO CONTAINER deste
# mesmo pod (ver abaixo, depois do frontend-spa) — nao tem
# Deployment proprio. `127.0.0.1` porque os dois containers
# de um pod compartilham a rede; nao precisa de Service nem
# de `resolver` (isso so vale para nome de Service, que exige
# DNS). O Service `servico-bff` continua existindo (o webhook
# do Garmin do escolinha aponta direto para ele, e o Prometheus
# tambem) — so o `selector` dele mudou, para o rotulo
# `athleticmap.io/bff-aqui` deste pod.
- { name: ATM_BFF_URL, value: "http://127.0.0.1:8083" }
# /api por GRUPO DE CONTEXTO, e nao um destino so.
#
# A versao anterior mandava TUDO para o `runtime-operacao`, porque e
# ele quem recebe o webhook do Asaas. Isso estava certo para quatro
# contextos e errado para os outros nove: `/api/cadastro` tem de ir
# para o core e `/api/saude` para o saude.
#
# O sintoma seria 404 do Spring, e nao 502 — o runtime responde, so
# nao conhece o caminho. Na tela, uma lista vazia.
#
# `ATM_API_URL` continua, e nao e redundante: e o destino do que nao
# pertence a grupo nenhum, hoje `/api/public/**`.
- { name: ATM_API_URL, value: "http://runtime-operacao.teste5-prod.svc.cluster.local" }
- { name: ATM_API_CORE_URL, value: "http://runtime-core.teste5-prod.svc.cluster.local" }
- { name: ATM_API_OPERACAO_URL, value: "http://runtime-operacao.teste5-prod.svc.cluster.local" }
- { name: ATM_API_SAUDE_URL, value: "http://runtime-saude.teste5-prod.svc.cluster.local" }
resources:
# 24 MiB medidos em 2026-09-18. 64Mi de request da folga de 2,5x.
requests: { cpu: 50m, memory: 64Mi }
limits: { cpu: 200m, memory: 128Mi }
volumeMounts:
- name: publico
mountPath: /usr/share/nginx/html/publico
readOnly: true
readinessProbe:
httpGet: { path: /, port: 80 }
initialDelaySeconds: 5
periodSeconds: 10
- name: servico-bff
image: docker.io/library/servico-bff:2.0-conta-de-recebimento
imagePullPolicy: Never
ports: [{ containerPort: 8083 }]
env:
- { name: ATM_CONFIG_URL, value: "http://runtime-core" }
- { name: ATM_CADASTRO_URL, value: "http://runtime-core" }
- { name: ATM_ORGANIZACAO_URL, value: "http://runtime-core" }
- { name: ATM_DOCUMENTOS_URL, value: "http://runtime-core" }
- { name: ATM_AGENDA_URL, value: "http://runtime-core" }
- { name: ATM_PLANEJAMENTO_URL, value: "http://runtime-operacao" }
- { name: ATM_CAMPEONATO_URL, value: "http://runtime-operacao" }
- { name: ATM_ADMINISTRATIVO_URL, value: "http://runtime-operacao" }
- { name: ATM_FINANCEIRO_URL, value: "http://runtime-operacao" }
- { name: ATM_SAUDE_URL, value: "http://runtime-saude" }
- { name: ATM_NUTRICAO_URL, value: "http://runtime-saude" }
- { name: ATM_ASSISTENCIA_SOCIAL_URL, value: "http://runtime-saude" }
- { name: ATM_PEDAGOGICO_URL, value: "http://runtime-saude" }
- { name: ATM_JWK_SET_URI, value: "http://keycloak.plataforma-prod.svc:8080/realms/athleticmap-9/protocol/openid-connect/certs" }
- { name: ATM_ISSUER, value: "https://auth.athleticmap.com/realms/athleticmap-9" }
- { name: ATM_TENANT, value: "teste5" }
- { name: ATM_PLANO, value: "bronze" }
# `optional` porque o molde ainda NAO cria este Secret. Sem ele o
# selo de consentimento simplesmente nao e emitido — o BFF sobe e
# funciona (ver SeloDeConsentimento, que trata segredo vazio). No dia
# em que o Secret existir, isto passa a valer sozinho.
- name: ATM_CONSENTIMENTO_SEGREDO
valueFrom:
secretKeyRef: { name: consentimento-selo, key: segredo, optional: true }
resources:
requests: { cpu: 50m, memory: 256Mi }
limits: { cpu: 500m, memory: 512Mi }
readinessProbe:
httpGet: { path: /bff/health, port: 8083 }
initialDelaySeconds: 20
periodSeconds: 10
failureThreshold: 30
livenessProbe:
httpGet: { path: /actuator/health/liveness, port: 8083 }
initialDelaySeconds: 50
periodSeconds: 20
failureThreshold: 6
volumes:
- name: publico
projected:
sources:
- configMap:
name: frontend-publico-texto
items:
- { key: "_estilo.css", path: "_estilo.css" }
- { key: "consentimento.js", path: "consentimento.js" }
- { key: "fontes--fontes.css", path: "fontes/fontes.css" }
- { key: "lp-escolinhas.css", path: "lp-escolinhas.css" }
- { key: "lp-escolinhas.html", path: "lp-escolinhas.html" }
- { key: "lp-escolinhas.js", path: "lp-escolinhas.js" }
- { key: "minha-conta.css", path: "minha-conta.css" }
- { key: "minha-conta.html", path: "minha-conta.html" }
- { key: "minha-conta.js", path: "minha-conta.js" }
- { key: "painel.css", path: "painel.css" }
- { key: "painel.html", path: "painel.html" }
- { key: "painel.js", path: "painel.js" }
- { key: "planos-modulos.json", path: "planos-modulos.json" }
- { key: "preparando.html", path: "preparando.html" }
- { key: "preparando.js", path: "preparando.js" }
- { key: "privacidade.html", path: "privacidade.html" }
- { key: "termos.html", path: "termos.html" }
- configMap:
name: frontend-publico-binario
items:
- { key: "fontes--Barlow-400-latin-ext.woff2", path: "fontes/Barlow-400-latin-ext.woff2" }
- { key: "fontes--Barlow-400-latin.woff2", path: "fontes/Barlow-400-latin.woff2" }
- { key: "fontes--Barlow-500-latin-ext.woff2", path: "fontes/Barlow-500-latin-ext.woff2" }
- { key: "fontes--Barlow-500-latin.woff2", path: "fontes/Barlow-500-latin.woff2" }
- { key: "fontes--Barlow-600-latin-ext.woff2", path: "fontes/Barlow-600-latin-ext.woff2" }
- { key: "fontes--Barlow-600-latin.woff2", path: "fontes/Barlow-600-latin.woff2" }
- { key: "fontes--Barlow-700-latin-ext.woff2", path: "fontes/Barlow-700-latin-ext.woff2" }
- { key: "fontes--Barlow-700-latin.woff2", path: "fontes/Barlow-700-latin.woff2" }
- { key: "fontes--IBMPlexMono-500-latin-ext.woff2", path: "fontes/IBMPlexMono-500-latin-ext.woff2" }
- { key: "fontes--IBMPlexMono-500-latin.woff2", path: "fontes/IBMPlexMono-500-latin.woff2" }
- { key: "fontes--Poppins-500-latin-ext.woff2", path: "fontes/Poppins-500-latin-ext.woff2" }
- { key: "fontes--Poppins-500-latin.woff2", path: "fontes/Poppins-500-latin.woff2" }
- { key: "fontes--Poppins-600-latin-ext.woff2", path: "fontes/Poppins-600-latin-ext.woff2" }
- { key: "fontes--Poppins-600-latin.woff2", path: "fontes/Poppins-600-latin.woff2" }
- { key: "fontes--Poppins-700-latin-ext.woff2", path: "fontes/Poppins-700-latin-ext.woff2" }
- { key: "fontes--Poppins-700-latin.woff2", path: "fontes/Poppins-700-latin.woff2" }
- { key: "fontes--Poppins-800-latin-ext.woff2", path: "fontes/Poppins-800-latin-ext.woff2" }
- { key: "fontes--Poppins-800-latin.woff2", path: "fontes/Poppins-800-latin.woff2" }
- { key: "img--hero-escolinha.jpg", path: "img/hero-escolinha.jpg" }
- { key: "img--logo-athletic-map.png", path: "img/logo-athletic-map.png" }
- { key: "produto-dashboard.webp", path: "produto-dashboard.webp" }
---
apiVersion: v1
kind: Service
metadata:
name: frontend-spa
namespace: teste5-prod
spec:
selector: { app: frontend-spa }
ports: [{ port: 80, targetPort: 80 }]