The per-site `x402_instance` module created one Deployment + Service + PDB per protected host (9 in total, 9×64Mi). Every pod was running the exact same logic with the same config — the only thing that varied was the upstream URL, which we don't even need since the gateway can return 200 to "allow" and Traefik handles the upstream itself. Refactor to the same pattern as `ai-bot-block`: * single deployment + service in `traefik` namespace, 2 replicas, HA * Traefik `Middleware` CRD `x402` (forwardAuth → x402-gateway:8080/auth) * each consumer ingress just appends `traefik-x402@kubernetescrd` to its middleware chain via `extra_middlewares` x402-gateway gains a `MODE=forwardauth` env var that returns 200 (allow) or 402 (with x402 PaymentRequiredResponse body) instead of reverse- proxying. Image: ghcr ... f4804d62. Pod count: 9 → 2 (78% memory saved). All 9 sites verified still serving the Anubis challenge to plain curl with identical TTFB. DRY_RUN until `var.x402_wallet_address` is set on the traefik stack. Removes `modules/kubernetes/x402_instance/` (dead code now).
165 lines
4.7 KiB
HCL
165 lines
4.7 KiB
HCL
variable "tls_secret_name" {
|
|
type = string
|
|
sensitive = true
|
|
}
|
|
|
|
|
|
module "tls_secret" {
|
|
source = "../../modules/kubernetes/setup_tls_secret"
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
tls_secret_name = var.tls_secret_name
|
|
}
|
|
|
|
resource "kubernetes_namespace" "homepage" {
|
|
metadata {
|
|
name = "homepage"
|
|
labels = {
|
|
"istio-injection" : "disabled"
|
|
tier = local.tiers.aux
|
|
}
|
|
}
|
|
lifecycle {
|
|
# KYVERNO_LIFECYCLE_V1: goldilocks-vpa-auto-mode ClusterPolicy stamps this label on every namespace
|
|
ignore_changes = [metadata[0].labels["goldilocks.fairwinds.com/vpa-update-mode"]]
|
|
}
|
|
}
|
|
|
|
resource "helm_release" "homepage" {
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
create_namespace = false
|
|
name = "homepage"
|
|
atomic = true
|
|
|
|
repository = "http://jameswynn.github.io/helm-charts"
|
|
chart = "homepage"
|
|
|
|
values = [file("${path.module}/values.yaml")]
|
|
}
|
|
|
|
# --- Caching proxy: nginx in front of Homepage for stale-while-revalidate on /api/ ---
|
|
|
|
resource "kubernetes_config_map" "cache_proxy" {
|
|
metadata {
|
|
name = "homepage-cache-config"
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
}
|
|
data = {
|
|
"default.conf" = <<-EOT
|
|
proxy_cache_path /tmp/cache levels=1:2 keys_zone=hp:10m max_size=500m inactive=24h;
|
|
|
|
server {
|
|
listen 80;
|
|
resolver kube-dns.kube-system.svc.cluster.local valid=5s;
|
|
set $upstream http://homepage.homepage.svc.cluster.local:3000;
|
|
|
|
location /api/ {
|
|
proxy_pass $upstream;
|
|
proxy_cache hp;
|
|
proxy_cache_valid 200 24h;
|
|
proxy_cache_use_stale updating error timeout;
|
|
proxy_cache_background_update on;
|
|
proxy_cache_lock on;
|
|
proxy_cache_key "$request_uri";
|
|
proxy_set_header Host $host;
|
|
proxy_next_upstream error timeout http_500 http_502 http_503;
|
|
proxy_next_upstream_tries 3;
|
|
add_header X-Cache-Status $upstream_cache_status;
|
|
}
|
|
|
|
location / {
|
|
proxy_pass $upstream;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_buffering off;
|
|
}
|
|
}
|
|
EOT
|
|
}
|
|
}
|
|
|
|
resource "kubernetes_deployment" "cache_proxy" {
|
|
metadata {
|
|
name = "homepage-cache"
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
}
|
|
spec {
|
|
replicas = 1
|
|
selector {
|
|
match_labels = { app = "homepage-cache" }
|
|
}
|
|
template {
|
|
metadata {
|
|
labels = { app = "homepage-cache" }
|
|
}
|
|
spec {
|
|
container {
|
|
name = "nginx"
|
|
image = "nginx:alpine"
|
|
port {
|
|
container_port = 80
|
|
}
|
|
resources {
|
|
requests = { cpu = "10m", memory = "64Mi" }
|
|
limits = { memory = "64Mi" }
|
|
}
|
|
volume_mount {
|
|
name = "config"
|
|
mount_path = "/etc/nginx/conf.d"
|
|
}
|
|
}
|
|
volume {
|
|
name = "config"
|
|
config_map {
|
|
name = kubernetes_config_map.cache_proxy.metadata[0].name
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
lifecycle {
|
|
# KYVERNO_LIFECYCLE_V1: Kyverno admission webhook mutates dns_config with ndots=2
|
|
ignore_changes = [spec[0].template[0].spec[0].dns_config]
|
|
}
|
|
}
|
|
|
|
resource "kubernetes_service" "cache_proxy" {
|
|
metadata {
|
|
name = "homepage-cache"
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
}
|
|
spec {
|
|
selector = { app = "homepage-cache" }
|
|
port {
|
|
port = 80
|
|
target_port = 80
|
|
}
|
|
}
|
|
}
|
|
|
|
module "anubis" {
|
|
source = "../../modules/kubernetes/anubis_instance"
|
|
name = "homepage"
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
target_url = "http://${kubernetes_service.cache_proxy.metadata[0].name}.${kubernetes_namespace.homepage.metadata[0].name}.svc.cluster.local"
|
|
}
|
|
|
|
module "ingress" {
|
|
source = "../../modules/kubernetes/ingress_factory"
|
|
namespace = kubernetes_namespace.homepage.metadata[0].name
|
|
name = "homepage"
|
|
host = "home"
|
|
dns_type = "proxied"
|
|
service_name = module.anubis.service_name
|
|
port = module.anubis.service_port
|
|
extra_middlewares = ["traefik-x402@kubernetescrd"]
|
|
tls_secret_name = var.tls_secret_name
|
|
anti_ai_scraping = false
|
|
extra_annotations = {
|
|
"gethomepage.dev/enabled" = "true"
|
|
"gethomepage.dev/name" = "Homepage"
|
|
"gethomepage.dev/description" = "Service dashboard"
|
|
"gethomepage.dev/group" = "Core Platform"
|
|
"gethomepage.dev/icon" = "homepage.png"
|
|
}
|
|
}
|