185 lines
10 KiB
YAML
185 lines
10 KiB
YAML
# =============================================================================
|
|
# P4.9 — a SPA, e com ela o roteamento interno de /bff e /api (P4.6).
|
|
#
|
|
# `teste5` e substituido ao provisionar.
|
|
#
|
|
# ── O QUE MUDOU EM RELACAO AO MOLDE ANTIGO ──────────────────────────────────
|
|
#
|
|
# O nginx desta imagem roteia `/bff` e `/api` por conta propria, a partir de
|
|
# `ATM_BFF_URL` e `ATM_API_URL`. Por isso o Ingress deste molde tem UMA rota — e
|
|
# nao uma linha por contexto, que era o que obrigava a editar o Ingress de todos
|
|
# os tenants a cada mudanca de topologia.
|
|
#
|
|
# O `/api` aponta para o `runtime-operacao` porque e ele quem recebe o webhook do
|
|
# provedor de pagamento em `/api/public/**`. Os outros caminhos de `/api` sao
|
|
# resolvidos pelo proprio nginx? NAO — e por isso esta linha e provisoria.
|
|
#
|
|
# **PENDENCIA CONHECIDA:** `/api/cadastro`, `/api/saude` e os demais precisam ir
|
|
# para runtimes DIFERENTES, e uma variavel so nao faz isso. O nginx precisa de
|
|
# uma regra por grupo de contexto. Esta no diario; ate resolver, use o Ingress
|
|
# para separar, como hoje.
|
|
# =============================================================================
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: frontend-spa
|
|
namespace: teste5-prod
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels: { app: frontend-spa }
|
|
template:
|
|
metadata:
|
|
labels: { app: frontend-spa, athleticmap.io/bff-aqui: "true" }
|
|
spec:
|
|
containers:
|
|
- name: frontend-spa
|
|
image: docker.io/library/frontend-spa:2.82-aviso-cobranca
|
|
imagePullPolicy: Never
|
|
ports: [{ containerPort: 80 }]
|
|
env:
|
|
- { name: ATM_KC_URL, value: "https://auth.athleticmap.com" }
|
|
- { name: ATM_REALM, value: "athleticmap-9" }
|
|
- { name: ATM_CLIENT, value: "spa" }
|
|
- { name: ATM_TENANT, value: "teste5" }
|
|
- { name: ATM_PLANO, value: "bronze" }
|
|
# P4.6 fechado 2026-09-26: o BFF e o SEGUNDO CONTAINER deste
|
|
# mesmo pod (ver abaixo, depois do frontend-spa) — nao tem
|
|
# Deployment proprio. `127.0.0.1` porque os dois containers
|
|
# de um pod compartilham a rede; nao precisa de Service nem
|
|
# de `resolver` (isso so vale para nome de Service, que exige
|
|
# DNS). O Service `servico-bff` continua existindo (o webhook
|
|
# do Garmin do escolinha aponta direto para ele, e o Prometheus
|
|
# tambem) — so o `selector` dele mudou, para o rotulo
|
|
# `athleticmap.io/bff-aqui` deste pod.
|
|
- { name: ATM_BFF_URL, value: "http://127.0.0.1:8083" }
|
|
|
|
# /api por GRUPO DE CONTEXTO, e nao um destino so.
|
|
#
|
|
# A versao anterior mandava TUDO para o `runtime-operacao`, porque e
|
|
# ele quem recebe o webhook do Asaas. Isso estava certo para quatro
|
|
# contextos e errado para os outros nove: `/api/cadastro` tem de ir
|
|
# para o core e `/api/saude` para o saude.
|
|
#
|
|
# O sintoma seria 404 do Spring, e nao 502 — o runtime responde, so
|
|
# nao conhece o caminho. Na tela, uma lista vazia.
|
|
#
|
|
# `ATM_API_URL` continua, e nao e redundante: e o destino do que nao
|
|
# pertence a grupo nenhum, hoje `/api/public/**`.
|
|
- { name: ATM_API_URL, value: "http://runtime-operacao.teste5-prod.svc.cluster.local" }
|
|
- { name: ATM_API_CORE_URL, value: "http://runtime-core.teste5-prod.svc.cluster.local" }
|
|
- { name: ATM_API_OPERACAO_URL, value: "http://runtime-operacao.teste5-prod.svc.cluster.local" }
|
|
- { name: ATM_API_SAUDE_URL, value: "http://runtime-saude.teste5-prod.svc.cluster.local" }
|
|
resources:
|
|
# 24 MiB medidos em 2026-09-18. 64Mi de request da folga de 2,5x.
|
|
requests: { cpu: 50m, memory: 64Mi }
|
|
limits: { cpu: 200m, memory: 128Mi }
|
|
volumeMounts:
|
|
- name: publico
|
|
mountPath: /usr/share/nginx/html/publico
|
|
readOnly: true
|
|
readinessProbe:
|
|
httpGet: { path: /, port: 80 }
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
- name: servico-bff
|
|
image: docker.io/library/servico-bff:2.0-conta-de-recebimento
|
|
imagePullPolicy: Never
|
|
ports: [{ containerPort: 8083 }]
|
|
env:
|
|
- { name: ATM_CONFIG_URL, value: "http://runtime-core" }
|
|
- { name: ATM_CADASTRO_URL, value: "http://runtime-core" }
|
|
- { name: ATM_ORGANIZACAO_URL, value: "http://runtime-core" }
|
|
- { name: ATM_DOCUMENTOS_URL, value: "http://runtime-core" }
|
|
- { name: ATM_AGENDA_URL, value: "http://runtime-core" }
|
|
- { name: ATM_PLANEJAMENTO_URL, value: "http://runtime-operacao" }
|
|
- { name: ATM_CAMPEONATO_URL, value: "http://runtime-operacao" }
|
|
- { name: ATM_ADMINISTRATIVO_URL, value: "http://runtime-operacao" }
|
|
- { name: ATM_FINANCEIRO_URL, value: "http://runtime-operacao" }
|
|
- { name: ATM_SAUDE_URL, value: "http://runtime-saude" }
|
|
- { name: ATM_NUTRICAO_URL, value: "http://runtime-saude" }
|
|
- { name: ATM_ASSISTENCIA_SOCIAL_URL, value: "http://runtime-saude" }
|
|
- { name: ATM_PEDAGOGICO_URL, value: "http://runtime-saude" }
|
|
- { name: ATM_JWK_SET_URI, value: "http://keycloak.plataforma-prod.svc:8080/realms/athleticmap-9/protocol/openid-connect/certs" }
|
|
- { name: ATM_ISSUER, value: "https://auth.athleticmap.com/realms/athleticmap-9" }
|
|
- { name: ATM_TENANT, value: "teste5" }
|
|
- { name: ATM_PLANO, value: "bronze" }
|
|
# `optional` porque o molde ainda NAO cria este Secret. Sem ele o
|
|
# selo de consentimento simplesmente nao e emitido — o BFF sobe e
|
|
# funciona (ver SeloDeConsentimento, que trata segredo vazio). No dia
|
|
# em que o Secret existir, isto passa a valer sozinho.
|
|
- name: ATM_CONSENTIMENTO_SEGREDO
|
|
valueFrom:
|
|
secretKeyRef: { name: consentimento-selo, key: segredo, optional: true }
|
|
resources:
|
|
requests: { cpu: 50m, memory: 256Mi }
|
|
limits: { cpu: 500m, memory: 512Mi }
|
|
readinessProbe:
|
|
httpGet: { path: /bff/health, port: 8083 }
|
|
initialDelaySeconds: 20
|
|
periodSeconds: 10
|
|
failureThreshold: 30
|
|
livenessProbe:
|
|
httpGet: { path: /actuator/health/liveness, port: 8083 }
|
|
initialDelaySeconds: 50
|
|
periodSeconds: 20
|
|
failureThreshold: 6
|
|
|
|
volumes:
|
|
- name: publico
|
|
projected:
|
|
sources:
|
|
- configMap:
|
|
name: frontend-publico-texto
|
|
items:
|
|
- { key: "_estilo.css", path: "_estilo.css" }
|
|
- { key: "consentimento.js", path: "consentimento.js" }
|
|
- { key: "fontes--fontes.css", path: "fontes/fontes.css" }
|
|
- { key: "lp-escolinhas.css", path: "lp-escolinhas.css" }
|
|
- { key: "lp-escolinhas.html", path: "lp-escolinhas.html" }
|
|
- { key: "lp-escolinhas.js", path: "lp-escolinhas.js" }
|
|
- { key: "minha-conta.css", path: "minha-conta.css" }
|
|
- { key: "minha-conta.html", path: "minha-conta.html" }
|
|
- { key: "minha-conta.js", path: "minha-conta.js" }
|
|
- { key: "painel.css", path: "painel.css" }
|
|
- { key: "painel.html", path: "painel.html" }
|
|
- { key: "painel.js", path: "painel.js" }
|
|
- { key: "planos-modulos.json", path: "planos-modulos.json" }
|
|
- { key: "preparando.html", path: "preparando.html" }
|
|
- { key: "preparando.js", path: "preparando.js" }
|
|
- { key: "privacidade.html", path: "privacidade.html" }
|
|
- { key: "termos.html", path: "termos.html" }
|
|
- configMap:
|
|
name: frontend-publico-binario
|
|
items:
|
|
- { key: "fontes--Barlow-400-latin-ext.woff2", path: "fontes/Barlow-400-latin-ext.woff2" }
|
|
- { key: "fontes--Barlow-400-latin.woff2", path: "fontes/Barlow-400-latin.woff2" }
|
|
- { key: "fontes--Barlow-500-latin-ext.woff2", path: "fontes/Barlow-500-latin-ext.woff2" }
|
|
- { key: "fontes--Barlow-500-latin.woff2", path: "fontes/Barlow-500-latin.woff2" }
|
|
- { key: "fontes--Barlow-600-latin-ext.woff2", path: "fontes/Barlow-600-latin-ext.woff2" }
|
|
- { key: "fontes--Barlow-600-latin.woff2", path: "fontes/Barlow-600-latin.woff2" }
|
|
- { key: "fontes--Barlow-700-latin-ext.woff2", path: "fontes/Barlow-700-latin-ext.woff2" }
|
|
- { key: "fontes--Barlow-700-latin.woff2", path: "fontes/Barlow-700-latin.woff2" }
|
|
- { key: "fontes--IBMPlexMono-500-latin-ext.woff2", path: "fontes/IBMPlexMono-500-latin-ext.woff2" }
|
|
- { key: "fontes--IBMPlexMono-500-latin.woff2", path: "fontes/IBMPlexMono-500-latin.woff2" }
|
|
- { key: "fontes--Poppins-500-latin-ext.woff2", path: "fontes/Poppins-500-latin-ext.woff2" }
|
|
- { key: "fontes--Poppins-500-latin.woff2", path: "fontes/Poppins-500-latin.woff2" }
|
|
- { key: "fontes--Poppins-600-latin-ext.woff2", path: "fontes/Poppins-600-latin-ext.woff2" }
|
|
- { key: "fontes--Poppins-600-latin.woff2", path: "fontes/Poppins-600-latin.woff2" }
|
|
- { key: "fontes--Poppins-700-latin-ext.woff2", path: "fontes/Poppins-700-latin-ext.woff2" }
|
|
- { key: "fontes--Poppins-700-latin.woff2", path: "fontes/Poppins-700-latin.woff2" }
|
|
- { key: "fontes--Poppins-800-latin-ext.woff2", path: "fontes/Poppins-800-latin-ext.woff2" }
|
|
- { key: "fontes--Poppins-800-latin.woff2", path: "fontes/Poppins-800-latin.woff2" }
|
|
- { key: "img--hero-escolinha.jpg", path: "img/hero-escolinha.jpg" }
|
|
- { key: "img--logo-athletic-map.png", path: "img/logo-athletic-map.png" }
|
|
- { key: "produto-dashboard.webp", path: "produto-dashboard.webp" }
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: frontend-spa
|
|
namespace: teste5-prod
|
|
spec:
|
|
selector: { app: frontend-spa }
|
|
ports: [{ port: 80, targetPort: 80 }]
|