This commit is contained in:
2026-07-20 21:03:05 +02:00
parent dc60551e07
commit c3c85eef21
70 changed files with 8049 additions and 1 deletions
+175
View File
@@ -0,0 +1,175 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: ai-disclosure
labels:
app.kubernetes.io/name: ai-disclosure
spec:
replicas: 3
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 0
maxSurge: 1
selector:
matchLabels:
app.kubernetes.io/name: ai-disclosure
template:
metadata:
labels:
app.kubernetes.io/name: ai-disclosure
annotations:
prometheus.io/scrape: "true"
prometheus.io/port: "8080"
prometheus.io/path: /metrics
spec:
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: app
image: ghcr.io/REPLACE_ME/ai-disclosure-standard:1.6.1
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 8080
env:
- name: BASE_URL
value: https://ai.example.org
- name: PUBLIC_NAME
value: AI Usage Disclosure
- name: CONTACT_URL
value: https://b1tsblog.org/page/ai
- name: SALES_URL
value: https://b1tsblog.org/page/ai
- name: DEFAULT_LANGUAGE
value: de
- name: TRUST_PROXY
value: "true"
- name: LICENSE_TOKEN
valueFrom:
secretKeyRef:
name: ai-disclosure-license
key: token
optional: true
- name: LICENSE_MODE
value: offline
- name: LICENSE_SERVER_URL
value: ""
- name: LICENSE_INSTANCE_ID
valueFrom:
fieldRef:
fieldPath: metadata.uid
- name: LICENSE_CACHE_FILE
value: /data/license-lease.json
volumeMounts:
- name: license-cache
mountPath: /data
resources:
requests:
cpu: 25m
memory: 24Mi
limits:
cpu: 500m
memory: 128Mi
readinessProbe:
httpGet:
path: /readyz
port: http
initialDelaySeconds: 2
periodSeconds: 5
timeoutSeconds: 2
failureThreshold: 3
livenessProbe:
httpGet:
path: /healthz
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 2
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
volumes:
- name: license-cache
emptyDir: {}
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app.kubernetes.io/name: ai-disclosure
---
apiVersion: v1
kind: Service
metadata:
name: ai-disclosure
spec:
selector:
app.kubernetes.io/name: ai-disclosure
ports:
- name: http
port: 80
targetPort: http
---
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: ai-disclosure
spec:
minAvailable: 2
selector:
matchLabels:
app.kubernetes.io/name: ai-disclosure
---
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: ai-disclosure
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: ai-disclosure
minReplicas: 3
maxReplicas: 12
behavior:
scaleDown:
stabilizationWindowSeconds: 300
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 65
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: ai-disclosure
annotations:
nginx.ingress.kubernetes.io/proxy-read-timeout: "15"
nginx.ingress.kubernetes.io/proxy-send-timeout: "15"
nginx.ingress.kubernetes.io/limit-rps: "50"
spec:
ingressClassName: nginx
tls:
- hosts: [ai.example.org]
secretName: ai-disclosure-tls
rules:
- host: ai.example.org
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: ai-disclosure
port:
name: http
+81
View File
@@ -0,0 +1,81 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: universal-license-server
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: universal-license-server
template:
metadata:
labels:
app.kubernetes.io/name: universal-license-server
spec:
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- name: server
image: ghcr.io/REPLACE_ME/universal-license-server:1.5.0
ports:
- name: http
containerPort: 8091
env:
- name: LICENSE_SERVER_ADDRESS
value: :8091
- name: LICENSE_SERVER_DATA
value: /data/licenses.json
- name: LICENSE_TRUST_STORE_FILE
value: /config/trusted-keys.json
- name: LEASE_SIGNING_KEY_ID
value: lease-2026
- name: LEASE_SIGNING_PRIVATE_KEY
valueFrom:
secretKeyRef:
name: universal-license-secrets
key: lease-private-key
- name: LICENSE_SERVER_ADMIN_TOKEN
valueFrom:
secretKeyRef:
name: universal-license-secrets
key: admin-token
volumeMounts:
- name: data
mountPath: /data
- name: trust-store
mountPath: /config
readOnly: true
readinessProbe:
httpGet:
path: /healthz
port: http
livenessProbe:
httpGet:
path: /healthz
port: http
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
volumes:
- name: data
persistentVolumeClaim:
claimName: universal-license-data
- name: trust-store
configMap:
name: universal-license-trust-store
---
apiVersion: v1
kind: Service
metadata:
name: universal-license-server
spec:
selector:
app.kubernetes.io/name: universal-license-server
ports:
- name: http
port: 80
targetPort: http
+70
View File
@@ -0,0 +1,70 @@
version: "3.9"
services:
app:
image: ghcr.io/REPLACE_ME/ai-disclosure-standard:1.6.1
environment:
BASE_URL: https://ai.example.org
PUBLIC_NAME: AI Usage Disclosure
CONTACT_URL: https://b1tsblog.org/page/ai
SALES_URL: "${SALES_URL:-https://b1tsblog.org/page/ai}"
DEFAULT_LANGUAGE: de
TRUST_PROXY: "true"
LICENSE_TOKEN: "${LICENSE_TOKEN:-}"
LICENSE_MODE: "${LICENSE_MODE:-offline}"
LICENSE_SERVER_URL: "${LICENSE_SERVER_URL:-}"
LICENSE_INSTANCE_ID: "${LICENSE_INSTANCE_ID:-swarm}"
LICENSE_CACHE_FILE: /data/license-lease.json
ports:
- target: 8080
published: 8080
protocol: tcp
mode: ingress
networks:
- public
volumes:
- license-cache:/data
read_only: true
tmpfs:
- /tmp:size=16m,mode=1777
cap_drop:
- ALL
healthcheck:
test: ["CMD", "/ai-disclosure", "--healthcheck"]
interval: 15s
timeout: 3s
retries: 3
start_period: 5s
deploy:
mode: replicated
replicas: 3
endpoint_mode: vip
update_config:
parallelism: 1
delay: 5s
order: start-first
failure_action: rollback
rollback_config:
parallelism: 1
order: stop-first
restart_policy:
condition: on-failure
delay: 3s
max_attempts: 5
window: 30s
placement:
preferences:
- spread: node.labels.zone
resources:
reservations:
cpus: "0.05"
memory: 24M
limits:
cpus: "0.50"
memory: 128M
networks:
public:
driver: overlay
attachable: true
volumes:
license-cache: