🎉 Major enhancement: Full migration from shell script deployment to Kustomize ## New Features ### Kustomize Infrastructure - ✅ Complete base resources for all Kubernetes manifests - ✅ Development overlay with optimized dev settings - ✅ Production overlay with enterprise-grade security and performance - ✅ ConfigMap and Secret generation from environment variables - ✅ Image tag and replica management per environment ### Environment Variable Integration - ✅ Multi-source environment loading (~/.env, .env.dev, .env.prod, .env.local) - ✅ Static configuration generation from environment variables - ✅ Dynamic runtime environment variable injection - ✅ Comprehensive variable documentation and examples - ✅ Secrets template generation for secure credential management ### Enhanced Makefile - ✅ 20+ new Kustomize-specific deployment targets - ✅ Environment-aware configuration generation commands - ✅ Validation, dry-run, and debugging capabilities - ✅ Backward compatibility with legacy shell script deployment ### New Scripts & Tools - ✅ scripts/generate-config.sh - Environment variable to Kustomize config generator - ✅ scripts/deploy-with-env.sh - Runtime environment variable deployment tool - ✅ Comprehensive help and usage documentation ### Documentation - ✅ k8s-kustomize/README.md - Complete Kustomize deployment guide - ✅ docs/ENVIRONMENT_VARIABLES.md - Environment variable integration guide - ✅ KUSTOMIZE_MIGRATION.md - Migration summary and next steps ## Benefits - 🚀 Simplified deployment: make deploy-dev vs complex shell scripts - 🔒 Environment isolation: Clear dev/staging/prod separation - 🔧 GitOps ready: Works seamlessly with ArgoCD, Flux - ✅ Better validation: Built-in YAML validation catches errors early - 📈 Standard approach: Industry-standard Kubernetes deployment method - 🛡️ Enhanced security: Production security contexts, network policies, TLS ## Usage Examples [34mGenerating development configuration...[0m [0;34m[INFO][0m Kustomize Config Generator [0;34m[INFO][0m Environment: dev [0;34m[INFO][0m Loading environment variables... [1;33m[WARNING][0m File not found: /home/will/.env [0;34m[INFO][0m Loading: /home/will/Code/meds/.env [1;33m[WARNING][0m File not found: /home/will/Code/meds/.env.dev [1;33m[WARNING][0m File not found: /home/will/Code/meds/.env.local [0;34m[INFO][0m Generating base config.env... [0;32m[SUCCESS][0m Generated: /home/will/Code/meds/k8s-kustomize/base/config.env [0;34m[INFO][0m Generating environment-specific config for: dev [0;32m[SUCCESS][0m Generated development config: /home/will/Code/meds/k8s-kustomize/overlays/dev/config.env [0;34m[INFO][0m Validating generated configuration... [0;32m[SUCCESS][0m Configuration validation passed! [0;32m[SUCCESS][0m Configuration generation completed! [0;34m[INFO][0m Next steps: 1. Review generated files in k8s-kustomize/ 2. Update any environment-specific values 3. Create secrets.env files for sensitive data 4. Test with: make kustomize-dry-run-dev [34mDeploying to Kubernetes with Kustomize (dev)...[0m [34mDeploying to production with environment variables...[0m [0;34m[INFO][0m Kustomize Deployment with Environment Variables [0;34m[INFO][0m Environment: prod [0;34m[INFO][0m Action: apply [0;34m[INFO][0m Validating prerequisites... [0;32m[SUCCESS][0m Prerequisites validated [0;34m[INFO][0m Loading environment variables for: prod [0;34m[INFO][0m Loading: /home/will/Code/meds/.env [0;32m[SUCCESS][0m Environment loaded: prod [0;34m[INFO][0m Key variables: APP_NAME: rxminder NODE_ENV: production IMAGE_TAG: latest NAMESPACE: rxminder-prod INGRESS_HOST: rxminder.192.168.153.243.nip.io [0;34m[INFO][0m Generating dynamic configuration... [34mValidating Kustomize configuration (dev)...[0m configmap/rxminder-config-4229dg76t6 created (dry run) secret/couchdb-secret-7ck2cc96g5 created (dry run) service/rxminder-couchdb-service created (dry run) service/rxminder-frontend-service created (dry run) persistentvolumeclaim/rxminder-couchdb-pvc created (dry run) deployment.apps/rxminder-frontend created (dry run) statefulset.apps/rxminder-couchdb created (dry run) horizontalpodautoscaler.autoscaling/rxminder-frontend-hpa created (dry run) job.batch/rxminder-db-seed created (dry run) ingress.networking.k8s.io/rxminder-ingress created (dry run) networkpolicy.networking.k8s.io/rxminder-database-policy created (dry run) networkpolicy.networking.k8s.io/rxminder-frontend-policy created (dry run) [34mValidating Kustomize configuration (prod)...[0m configmap/rxminder-config-2979gkcf9c created (dry run) secret/couchdb-secret-6k9794bgg2 created (dry run) service/rxminder-couchdb-service created (dry run) service/rxminder-frontend-service created (dry run) persistentvolumeclaim/rxminder-couchdb-pvc created (dry run) deployment.apps/rxminder-frontend created (dry run) statefulset.apps/rxminder-couchdb created (dry run) horizontalpodautoscaler.autoscaling/rxminder-frontend-hpa created (dry run) job.batch/rxminder-db-seed created (dry run) ingress.networking.k8s.io/rxminder-ingress created (dry run) networkpolicy.networking.k8s.io/rxminder-database-policy created (dry run) networkpolicy.networking.k8s.io/rxminder-frontend-policy created (dry run) [32mKustomize validation completed![0m [34mDry run Kustomize deployment (dev)...[0m apiVersion: v1 items: - apiVersion: v1 data: APP_NAME: rxminder APP_VERSION: 1.0.0 CACHE_TTL: "1800" CERT_MANAGER_ISSUER: letsencrypt-prod CORS_ORIGIN: '*' COUCHDB_DATABASE_NAME: meds_app DB_HOST: rxminder-couchdb-service DB_PORT: "5984" DEBUG: "true" DEV_MODE: "false" ENABLE_CORS: "true" ENABLE_METRICS: "false" ENABLE_MONITORING: "false" ENABLE_TRACING: "false" HEALTH_CHECK_INTERVAL: "30" HOT_RELOAD: "false" IMAGE_REPOSITORY: will/rxminder INGRESS_CLASS: nginx LOG_FORMAT: json LOG_LEVEL: debug LOG_TIMESTAMP: "true" MAX_CONNECTIONS: "100" METRICS_PORT: "9090" NODE_ENV: development REACT_APP_API_URL: http://rxminder-couchdb-service:5984 READINESS_CHECK_TIMEOUT: "5" REGISTRY_URL: gitea-http.taildb3494.ts.net REQUEST_TIMEOUT: "30000" kind: ConfigMap metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"v1","data":{"APP_NAME":"rxminder","APP_VERSION":"1.0.0","CACHE_TTL":"1800","CERT_MANAGER_ISSUER":"letsencrypt-prod","CORS_ORIGIN":"*","COUCHDB_DATABASE_NAME":"meds_app","DB_HOST":"rxminder-couchdb-service","DB_PORT":"5984","DEBUG":"true","DEV_MODE":"false","ENABLE_CORS":"true","ENABLE_METRICS":"false","ENABLE_MONITORING":"false","ENABLE_TRACING":"false","HEALTH_CHECK_INTERVAL":"30","HOT_RELOAD":"false","IMAGE_REPOSITORY":"will/rxminder","INGRESS_CLASS":"nginx","LOG_FORMAT":"json","LOG_LEVEL":"debug","LOG_TIMESTAMP":"true","MAX_CONNECTIONS":"100","METRICS_PORT":"9090","NODE_ENV":"development","REACT_APP_API_URL":"http://rxminder-couchdb-service:5984","READINESS_CHECK_TIMEOUT":"5","REGISTRY_URL":"gitea-http.taildb3494.ts.net","REQUEST_TIMEOUT":"30000"},"kind":"ConfigMap","metadata":{"annotations":{},"labels":{"app":"rxminder","environment":"dev","version":"v1.0.0"},"name":"rxminder-config-4229dg76t6","namespace":"rxminder-dev"}} labels: app: rxminder environment: dev version: v1.0.0 name: rxminder-config-4229dg76t6 namespace: rxminder-dev - apiVersion: v1 data: password: ZGV2cGFzczEyMw== username: YWRtaW4= kind: Secret metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"v1","data":{"password":"ZGV2cGFzczEyMw==","username":"YWRtaW4="},"kind":"Secret","metadata":{"annotations":{},"labels":{"app":"rxminder","environment":"dev","version":"v1.0.0"},"name":"couchdb-secret-7ck2cc96g5","namespace":"rxminder-dev"},"type":"Opaque"} labels: app: rxminder environment: dev version: v1.0.0 name: couchdb-secret-7ck2cc96g5 namespace: rxminder-dev type: Opaque - apiVersion: v1 kind: Service metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"v1","kind":"Service","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"database","environment":"dev","version":"v1.0.0"},"name":"rxminder-couchdb-service","namespace":"rxminder-dev"},"spec":{"ports":[{"name":"couchdb","port":5984,"protocol":"TCP","targetPort":5984}],"selector":{"app":"rxminder","component":"database"},"type":"ClusterIP"}} labels: app: rxminder component: database environment: dev version: v1.0.0 name: rxminder-couchdb-service namespace: rxminder-dev spec: ports: - name: couchdb port: 5984 protocol: TCP targetPort: 5984 selector: app: rxminder component: database type: ClusterIP - apiVersion: v1 kind: Service metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"v1","kind":"Service","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"frontend","environment":"dev","version":"v1.0.0"},"name":"rxminder-frontend-service","namespace":"rxminder-dev"},"spec":{"ports":[{"name":"http","port":80,"protocol":"TCP","targetPort":80}],"selector":{"app":"rxminder","component":"frontend"},"type":"ClusterIP"}} labels: app: rxminder component: frontend environment: dev version: v1.0.0 name: rxminder-frontend-service namespace: rxminder-dev spec: ports: - name: http port: 80 protocol: TCP targetPort: 80 selector: app: rxminder component: frontend type: ClusterIP - apiVersion: v1 kind: PersistentVolumeClaim metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"v1","kind":"PersistentVolumeClaim","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"database","environment":"dev","version":"v1.0.0"},"name":"rxminder-couchdb-pvc","namespace":"rxminder-dev"},"spec":{"accessModes":["ReadWriteOnce"],"resources":{"requests":{"storage":"1Gi"}},"storageClassName":"standard"}} labels: app: rxminder component: database environment: dev version: v1.0.0 name: rxminder-couchdb-pvc namespace: rxminder-dev spec: accessModes: - ReadWriteOnce resources: requests: storage: 1Gi storageClassName: standard - apiVersion: apps/v1 kind: Deployment metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"apps/v1","kind":"Deployment","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"frontend","environment":"dev","version":"v1.0.0"},"name":"rxminder-frontend","namespace":"rxminder-dev"},"spec":{"replicas":1,"selector":{"matchLabels":{"component":"frontend"}},"template":{"metadata":{"labels":{"component":"frontend"}},"spec":{"containers":[{"env":[{"name":"NODE_ENV","value":"development"},{"name":"LOG_LEVEL","value":"debug"}],"envFrom":[{"configMapRef":{"name":"rxminder-config-4229dg76t6"}}],"image":"gitea-http.taildb3494.ts.net/will/rxminder:dev","livenessProbe":{"httpGet":{"path":"/","port":80},"initialDelaySeconds":30,"periodSeconds":30},"name":"frontend","ports":[{"containerPort":80}],"readinessProbe":{"httpGet":{"path":"/","port":80},"initialDelaySeconds":5,"periodSeconds":5},"resources":{"limits":{"cpu":"40m","memory":"32Mi"},"requests":{"cpu":"20m","memory":"16Mi"}}}],"imagePullSecrets":[{"name":"rxminder-registry-secret"}]}}}} labels: app: rxminder component: frontend environment: dev version: v1.0.0 name: rxminder-frontend namespace: rxminder-dev spec: replicas: 1 selector: matchLabels: component: frontend template: metadata: labels: component: frontend spec: containers: - env: - name: NODE_ENV value: development - name: LOG_LEVEL value: debug envFrom: - configMapRef: name: rxminder-config-4229dg76t6 image: gitea-http.taildb3494.ts.net/will/rxminder:dev livenessProbe: httpGet: path: / port: 80 initialDelaySeconds: 30 periodSeconds: 30 name: frontend ports: - containerPort: 80 readinessProbe: httpGet: path: / port: 80 initialDelaySeconds: 5 periodSeconds: 5 resources: limits: cpu: 40m memory: 32Mi requests: cpu: 20m memory: 16Mi imagePullSecrets: - name: rxminder-registry-secret - apiVersion: apps/v1 kind: StatefulSet metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"apps/v1","kind":"StatefulSet","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"database","environment":"dev","version":"v1.0.0"},"name":"rxminder-couchdb","namespace":"rxminder-dev"},"spec":{"replicas":1,"selector":{"matchLabels":{"app":"rxminder","component":"database"}},"serviceName":"rxminder-couchdb-service","template":{"metadata":{"labels":{"app":"rxminder","component":"database"}},"spec":{"containers":[{"env":[{"name":"COUCHDB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"couchdb-secret-7ck2cc96g5"}}},{"name":"COUCHDB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"couchdb-secret-7ck2cc96g5"}}}],"image":"couchdb:3.3.2","livenessProbe":{"httpGet":{"path":"/_up","port":5984},"initialDelaySeconds":60,"periodSeconds":30},"name":"couchdb","ports":[{"containerPort":5984}],"readinessProbe":{"httpGet":{"path":"/_up","port":5984},"initialDelaySeconds":10,"periodSeconds":5},"resources":{"limits":{"cpu":"60m","memory":"128Mi"},"requests":{"cpu":"30m","memory":"64Mi"}},"volumeMounts":[{"mountPath":"/opt/couchdb/data","name":"couchdb-data"}]}]}},"volumeClaimTemplates":[{"metadata":{"labels":{"app":"rxminder","component":"database"},"name":"couchdb-data"},"spec":{"accessModes":["ReadWriteOnce"],"resources":{"requests":{"storage":"1Gi"}},"storageClassName":"standard"}}]}} labels: app: rxminder component: database environment: dev version: v1.0.0 name: rxminder-couchdb namespace: rxminder-dev spec: replicas: 1 selector: matchLabels: app: rxminder component: database serviceName: rxminder-couchdb-service template: metadata: labels: app: rxminder component: database spec: containers: - env: - name: COUCHDB_USER valueFrom: secretKeyRef: key: username name: couchdb-secret-7ck2cc96g5 - name: COUCHDB_PASSWORD valueFrom: secretKeyRef: key: password name: couchdb-secret-7ck2cc96g5 image: couchdb:3.3.2 livenessProbe: httpGet: path: /_up port: 5984 initialDelaySeconds: 60 periodSeconds: 30 name: couchdb ports: - containerPort: 5984 readinessProbe: httpGet: path: /_up port: 5984 initialDelaySeconds: 10 periodSeconds: 5 resources: limits: cpu: 60m memory: 128Mi requests: cpu: 30m memory: 64Mi volumeMounts: - mountPath: /opt/couchdb/data name: couchdb-data volumeClaimTemplates: - metadata: labels: app: rxminder component: database name: couchdb-data spec: accessModes: - ReadWriteOnce resources: requests: storage: 1Gi storageClassName: standard - apiVersion: autoscaling/v2 kind: HorizontalPodAutoscaler metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"autoscaling/v2","kind":"HorizontalPodAutoscaler","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"frontend","environment":"dev","version":"v1.0.0"},"name":"rxminder-frontend-hpa","namespace":"rxminder-dev"},"spec":{"maxReplicas":3,"metrics":[{"resource":{"name":"cpu","target":{"averageUtilization":50,"type":"Utilization"}},"type":"Resource"}],"minReplicas":1,"scaleTargetRef":{"apiVersion":"apps/v1","kind":"Deployment","name":"rxminder-frontend"}}} labels: app: rxminder component: frontend environment: dev version: v1.0.0 name: rxminder-frontend-hpa namespace: rxminder-dev spec: maxReplicas: 3 metrics: - resource: name: cpu target: averageUtilization: 50 type: Utilization type: Resource minReplicas: 1 scaleTargetRef: apiVersion: apps/v1 kind: Deployment name: rxminder-frontend - apiVersion: batch/v1 kind: Job metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"batch/v1","kind":"Job","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"database","environment":"dev","version":"v1.0.0"},"name":"rxminder-db-seed","namespace":"rxminder-dev"},"spec":{"backoffLimit":4,"template":{"metadata":{"labels":{"app":"rxminder","component":"database"}},"spec":{"containers":[{"args":["# Wait for CouchDB to be ready\necho \"Waiting for CouchDB to be ready...\"\nuntil curl -f http://couchdb-service:5984/_up 2\u003e/dev/null; do\n sleep 2\ndone\n\n# Create databases\necho \"Creating databases...\"\ncurl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app\n\n# Create default admin user\necho \"Creating default admin user...\"\ncurl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/_users/org.couchdb.user:$COUCHDB_USER \\\n -H \"Content-Type: application/json\" \\\n -d \"{\n \\\"name\\\": \\\"$COUCHDB_USER\\\",\n \\\"password\\\": \\\"$COUCHDB_PASSWORD\\\",\n \\\"roles\\\": [\\\"admin\\\"],\n \\\"type\\\": \\\"user\\\"\n }\"\n\n# Create design documents for views\necho \"Creating design documents...\"\ncurl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app/_design/medications \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"views\": {\n \"by_name\": {\n \"map\": \"function(doc) { if (doc.type === \\\"medication\\\") emit(doc.name, doc); }\"\n },\n \"by_user\": {\n \"map\": \"function(doc) { if (doc.type === \\\"medication\\\") emit(doc.userId, doc); }\"\n }\n }\n }'\n\ncurl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app/_design/reminders \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"views\": {\n \"by_medication\": {\n \"map\": \"function(doc) { if (doc.type === \\\"reminder\\\") emit(doc.medicationId, doc); }\"\n },\n \"by_user\": {\n \"map\": \"function(doc) { if (doc.type === \\\"reminder\\\") emit(doc.userId, doc); }\"\n }\n }\n }'\n\n# Create a sample user document for reference\n # Create design document for authentication users\n curl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app/_design/auth \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"views\": {\n \"by_username\": {\n \"map\": \"function(doc) { if (doc.type === \\\"user\\\" \u0026\u0026 doc.username) emit(doc.username, doc); }\"\n },\n \"by_email\": {\n \"map\": \"function(doc) { if (doc.type === \\\"user\\\" \u0026\u0026 doc.email) emit(doc.email, doc); }\"\n }\n }\n }'\necho \"Creating sample user document...\"\ncurl -X POST http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"type\": \"user\",\n \"name\": \"sample_user\",\n \"email\": \"user@example.com\",\n \"createdAt\": \"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'\"\n }'\n\necho \"Database seeding completed with default admin user\"\n"],"command":["/bin/sh","-c"],"env":[{"name":"COUCHDB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"couchdb-secret-7ck2cc96g5"}}},{"name":"COUCHDB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"couchdb-secret-7ck2cc96g5"}}}],"image":"couchdb:3.3.2","name":"db-seeder"}],"restartPolicy":"Never"}}}} labels: app: rxminder component: database environment: dev version: v1.0.0 name: rxminder-db-seed namespace: rxminder-dev spec: backoffLimit: 4 template: metadata: labels: app: rxminder component: database spec: containers: - args: - | # Wait for CouchDB to be ready echo "Waiting for CouchDB to be ready..." until curl -f http://couchdb-service:5984/_up 2>/dev/null; do sleep 2 done # Create databases echo "Creating databases..." curl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app # Create default admin user echo "Creating default admin user..." curl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/_users/org.couchdb.user:$COUCHDB_USER \ -H "Content-Type: application/json" \ -d "{ \"name\": \"$COUCHDB_USER\", \"password\": \"$COUCHDB_PASSWORD\", \"roles\": [\"admin\"], \"type\": \"user\" }" # Create design documents for views echo "Creating design documents..." curl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app/_design/medications \ -H "Content-Type: application/json" \ -d '{ "views": { "by_name": { "map": "function(doc) { if (doc.type === \"medication\") emit(doc.name, doc); }" }, "by_user": { "map": "function(doc) { if (doc.type === \"medication\") emit(doc.userId, doc); }" } } }' curl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app/_design/reminders \ -H "Content-Type: application/json" \ -d '{ "views": { "by_medication": { "map": "function(doc) { if (doc.type === \"reminder\") emit(doc.medicationId, doc); }" }, "by_user": { "map": "function(doc) { if (doc.type === \"reminder\") emit(doc.userId, doc); }" } } }' # Create a sample user document for reference # Create design document for authentication users curl -X PUT http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app/_design/auth \ -H "Content-Type: application/json" \ -d '{ "views": { "by_username": { "map": "function(doc) { if (doc.type === \"user\" && doc.username) emit(doc.username, doc); }" }, "by_email": { "map": "function(doc) { if (doc.type === \"user\" && doc.email) emit(doc.email, doc); }" } } }' echo "Creating sample user document..." curl -X POST http://$COUCHDB_USER:$COUCHDB_PASSWORD@couchdb-service:5984/meds_app \ -H "Content-Type: application/json" \ -d '{ "type": "user", "name": "sample_user", "email": "user@example.com", "createdAt": "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'" }' echo "Database seeding completed with default admin user" command: - /bin/sh - -c env: - name: COUCHDB_USER valueFrom: secretKeyRef: key: username name: couchdb-secret-7ck2cc96g5 - name: COUCHDB_PASSWORD valueFrom: secretKeyRef: key: password name: couchdb-secret-7ck2cc96g5 image: couchdb:3.3.2 name: db-seeder restartPolicy: Never - apiVersion: networking.k8s.io/v1 kind: Ingress metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"networking.k8s.io/v1","kind":"Ingress","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"frontend","environment":"dev","version":"v1.0.0"},"name":"rxminder-ingress","namespace":"rxminder-dev"},"spec":{"ingressClassName":"nginx","rules":[{"host":"rxminder-dev.local","http":{"paths":[{"backend":{"service":{"name":"rxminder-frontend-service","port":{"number":80}}},"path":"/","pathType":"Prefix"}]}}]}} labels: app: rxminder component: frontend environment: dev version: v1.0.0 name: rxminder-ingress namespace: rxminder-dev spec: ingressClassName: nginx rules: - host: rxminder-dev.local http: paths: - backend: service: name: rxminder-frontend-service port: number: 80 path: / pathType: Prefix - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"networking.k8s.io/v1","kind":"NetworkPolicy","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"database","environment":"dev","version":"v1.0.0"},"name":"rxminder-database-policy","namespace":"rxminder-dev"},"spec":{"egress":[{"ports":[{"port":5984,"protocol":"TCP"}],"to":[{"podSelector":{"matchLabels":{"component":"database"}}}]}],"ingress":[{"from":[{"podSelector":{"matchLabels":{"component":"frontend"}}}],"ports":[{"port":5984,"protocol":"TCP"}]}],"podSelector":{"matchLabels":{"component":"database"}},"policyTypes":["Ingress","Egress"]}} labels: app: rxminder component: database environment: dev version: v1.0.0 name: rxminder-database-policy namespace: rxminder-dev spec: egress: - ports: - port: 5984 protocol: TCP to: - podSelector: matchLabels: component: database ingress: - from: - podSelector: matchLabels: component: frontend ports: - port: 5984 protocol: TCP podSelector: matchLabels: component: database policyTypes: - Ingress - Egress - apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: annotations: kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"networking.k8s.io/v1","kind":"NetworkPolicy","metadata":{"annotations":{},"labels":{"app":"rxminder","component":"frontend","environment":"dev","version":"v1.0.0"},"name":"rxminder-frontend-policy","namespace":"rxminder-dev"},"spec":{"egress":[{"ports":[{"port":5984,"protocol":"TCP"}],"to":[{"podSelector":{"matchLabels":{"component":"database"}}}]},{"ports":[{"port":80,"protocol":"TCP"}],"to":[{"podSelector":{"matchLabels":{"component":"frontend"}}}]}],"ingress":[{"from":[{"podSelector":{"matchLabels":{"component":"frontend"}}}],"ports":[{"port":80,"protocol":"TCP"}]}],"podSelector":{"matchLabels":{"component":"frontend"}},"policyTypes":["Ingress","Egress"]}} labels: app: rxminder component: frontend environment: dev version: v1.0.0 name: rxminder-frontend-policy namespace: rxminder-dev spec: egress: - ports: - port: 5984 protocol: TCP to: - podSelector: matchLabels: component: database - ports: - port: 80 protocol: TCP to: - podSelector: matchLabels: component: frontend ingress: - from: - podSelector: matchLabels: component: frontend ports: - port: 80 protocol: TCP podSelector: matchLabels: component: frontend policyTypes: - Ingress - Egress kind: List metadata: {} ## Migration Path - Legacy shell scripts remain available for backward compatibility - Gradual migration: dev → staging → production - Zero-downtime deployment capability Co-authored-by: Assistant <assistant@anthropic.com>
475 lines
12 KiB
Bash
Executable File
475 lines
12 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
# generate-config.sh
|
|
# Generates config.env files for Kustomize from environment variables
|
|
# Usage: ./scripts/generate-config.sh [environment]
|
|
# Example: ./scripts/generate-config.sh dev
|
|
|
|
set -euo pipefail
|
|
|
|
# Default environment
|
|
ENVIRONMENT=${1:-dev}
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
PROJECT_ROOT="$(dirname "$SCRIPT_DIR")"
|
|
|
|
# Color codes for output
|
|
RED='\033[0;31m'
|
|
GREEN='\033[0;32m'
|
|
YELLOW='\033[1;33m'
|
|
BLUE='\033[0;34m'
|
|
NC='\033[0m' # No Color
|
|
|
|
# Function to print colored output
|
|
print_status() {
|
|
echo -e "${BLUE}[INFO]${NC} $1"
|
|
}
|
|
|
|
print_success() {
|
|
echo -e "${GREEN}[SUCCESS]${NC} $1"
|
|
}
|
|
|
|
print_warning() {
|
|
echo -e "${YELLOW}[WARNING]${NC} $1"
|
|
}
|
|
|
|
print_error() {
|
|
echo -e "${RED}[ERROR]${NC} $1"
|
|
}
|
|
|
|
# Load environment variables from various sources
|
|
load_env_files() {
|
|
local env_files=(
|
|
"$HOME/.env"
|
|
"$PROJECT_ROOT/.env"
|
|
"$PROJECT_ROOT/.env.$ENVIRONMENT"
|
|
"$PROJECT_ROOT/.env.local"
|
|
)
|
|
|
|
print_status "Loading environment variables..."
|
|
|
|
for env_file in "${env_files[@]}"; do
|
|
if [[ -f "$env_file" ]]; then
|
|
print_status "Loading: $env_file"
|
|
# Source the file in a subshell to avoid polluting current environment
|
|
set -a
|
|
source "$env_file"
|
|
set +a
|
|
else
|
|
print_warning "File not found: $env_file"
|
|
fi
|
|
done
|
|
}
|
|
|
|
# Generate config.env for base configuration
|
|
generate_base_config() {
|
|
local config_file="$PROJECT_ROOT/k8s-kustomize/base/config.env"
|
|
local temp_file=$(mktemp)
|
|
|
|
print_status "Generating base config.env..."
|
|
|
|
cat > "$temp_file" << EOF
|
|
# Base configuration for rxminder application
|
|
# Generated automatically from environment variables
|
|
# Generated on: $(date)
|
|
# Environment: $ENVIRONMENT
|
|
|
|
# Application Environment
|
|
NODE_ENV=${NODE_ENV:-production}
|
|
LOG_LEVEL=${LOG_LEVEL:-info}
|
|
|
|
# API Configuration
|
|
REACT_APP_API_URL=${REACT_APP_API_URL:-http://rxminder-couchdb-service:5984}
|
|
|
|
# Feature Flags
|
|
ENABLE_MONITORING=${ENABLE_MONITORING:-false}
|
|
DEBUG=${DEBUG:-false}
|
|
|
|
# Cache Configuration
|
|
CACHE_TTL=${CACHE_TTL:-1800}
|
|
|
|
# Database Configuration
|
|
DB_HOST=${DB_HOST:-rxminder-couchdb-service}
|
|
DB_PORT=${DB_PORT:-5984}
|
|
COUCHDB_DATABASE_NAME=${COUCHDB_DATABASE_NAME:-meds_app}
|
|
|
|
# Security Configuration
|
|
ENABLE_CORS=${ENABLE_CORS:-true}
|
|
CORS_ORIGIN=${CORS_ORIGIN:-*}
|
|
|
|
# Performance Configuration
|
|
REQUEST_TIMEOUT=${REQUEST_TIMEOUT:-30000}
|
|
MAX_CONNECTIONS=${MAX_CONNECTIONS:-100}
|
|
|
|
# Logging Configuration
|
|
LOG_FORMAT=${LOG_FORMAT:-json}
|
|
LOG_TIMESTAMP=${LOG_TIMESTAMP:-true}
|
|
|
|
# Health Check Configuration
|
|
HEALTH_CHECK_INTERVAL=${HEALTH_CHECK_INTERVAL:-30}
|
|
READINESS_CHECK_TIMEOUT=${READINESS_CHECK_TIMEOUT:-5}
|
|
|
|
# Application Metadata
|
|
APP_NAME=${APP_NAME:-rxminder}
|
|
APP_VERSION=${APP_VERSION:-1.0.0}
|
|
|
|
# Container Registry
|
|
REGISTRY_URL=${REGISTRY_URL:-gitea-http.taildb3494.ts.net}
|
|
IMAGE_REPOSITORY=${IMAGE_REPOSITORY:-will/rxminder}
|
|
|
|
# Ingress Configuration
|
|
INGRESS_CLASS=${INGRESS_CLASS:-nginx}
|
|
CERT_MANAGER_ISSUER=${CERT_MANAGER_ISSUER:-letsencrypt-prod}
|
|
|
|
# Monitoring and Observability
|
|
ENABLE_METRICS=${ENABLE_METRICS:-false}
|
|
METRICS_PORT=${METRICS_PORT:-9090}
|
|
ENABLE_TRACING=${ENABLE_TRACING:-false}
|
|
|
|
# Development specific (will be overridden in overlays)
|
|
DEV_MODE=${DEV_MODE:-false}
|
|
HOT_RELOAD=${HOT_RELOAD:-false}
|
|
EOF
|
|
|
|
# Move temp file to final location
|
|
mv "$temp_file" "$config_file"
|
|
print_success "Generated: $config_file"
|
|
}
|
|
|
|
# Generate environment-specific config
|
|
generate_environment_config() {
|
|
local overlay_dir="$PROJECT_ROOT/k8s-kustomize/overlays/$ENVIRONMENT"
|
|
local env_config_file="$overlay_dir/config.env"
|
|
|
|
if [[ ! -d "$overlay_dir" ]]; then
|
|
print_error "Environment overlay directory not found: $overlay_dir"
|
|
return 1
|
|
fi
|
|
|
|
print_status "Generating environment-specific config for: $ENVIRONMENT"
|
|
|
|
case "$ENVIRONMENT" in
|
|
"dev"|"development")
|
|
generate_dev_config "$env_config_file"
|
|
;;
|
|
"prod"|"production")
|
|
generate_prod_config "$env_config_file"
|
|
;;
|
|
"staging")
|
|
generate_staging_config "$env_config_file"
|
|
;;
|
|
*)
|
|
print_warning "Unknown environment: $ENVIRONMENT. Generating generic config."
|
|
generate_generic_config "$env_config_file"
|
|
;;
|
|
esac
|
|
}
|
|
|
|
# Generate development-specific configuration
|
|
generate_dev_config() {
|
|
local config_file="$1"
|
|
local temp_file=$(mktemp)
|
|
|
|
cat > "$temp_file" << EOF
|
|
# Development environment configuration
|
|
# Generated on: $(date)
|
|
|
|
NODE_ENV=development
|
|
LOG_LEVEL=debug
|
|
DEBUG=true
|
|
ENABLE_MONITORING=false
|
|
DEV_MODE=true
|
|
HOT_RELOAD=true
|
|
|
|
# Development URLs (override if needed)
|
|
REACT_APP_API_URL=${DEV_API_URL:-http://rxminder-couchdb-service:5984}
|
|
CORS_ORIGIN=${DEV_CORS_ORIGIN:-*}
|
|
|
|
# Development domain
|
|
INGRESS_HOST=${DEV_INGRESS_HOST:-rxminder-dev.local}
|
|
|
|
# Relaxed timeouts for debugging
|
|
REQUEST_TIMEOUT=60000
|
|
HEALTH_CHECK_INTERVAL=60
|
|
|
|
# Development image tag
|
|
IMAGE_TAG=${DEV_IMAGE_TAG:-dev}
|
|
EOF
|
|
|
|
mv "$temp_file" "$config_file"
|
|
print_success "Generated development config: $config_file"
|
|
}
|
|
|
|
# Generate production-specific configuration
|
|
generate_prod_config() {
|
|
local config_file="$1"
|
|
local temp_file=$(mktemp)
|
|
|
|
cat > "$temp_file" << EOF
|
|
# Production environment configuration
|
|
# Generated on: $(date)
|
|
|
|
NODE_ENV=production
|
|
LOG_LEVEL=${PROD_LOG_LEVEL:-warn}
|
|
DEBUG=false
|
|
ENABLE_MONITORING=true
|
|
DEV_MODE=false
|
|
|
|
# Production URLs
|
|
REACT_APP_API_URL=${PROD_API_URL:-http://rxminder-couchdb-service:5984}
|
|
CORS_ORIGIN=${PROD_CORS_ORIGIN:-https://rxminder.yourdomain.com}
|
|
|
|
# Production domain
|
|
INGRESS_HOST=${PROD_INGRESS_HOST:-rxminder.yourdomain.com}
|
|
|
|
# Production performance settings
|
|
CACHE_TTL=3600
|
|
REQUEST_TIMEOUT=30000
|
|
MAX_CONNECTIONS=200
|
|
|
|
# Production monitoring
|
|
ENABLE_METRICS=true
|
|
ENABLE_TRACING=true
|
|
|
|
# Production image tag
|
|
IMAGE_TAG=${PROD_IMAGE_TAG:-v1.0.0}
|
|
|
|
# Security settings
|
|
ENABLE_SECURITY_HEADERS=true
|
|
ENABLE_RATE_LIMITING=true
|
|
EOF
|
|
|
|
mv "$temp_file" "$config_file"
|
|
print_success "Generated production config: $config_file"
|
|
}
|
|
|
|
# Generate staging-specific configuration
|
|
generate_staging_config() {
|
|
local config_file="$1"
|
|
local temp_file=$(mktemp)
|
|
|
|
cat > "$temp_file" << EOF
|
|
# Staging environment configuration
|
|
# Generated on: $(date)
|
|
|
|
NODE_ENV=staging
|
|
LOG_LEVEL=${STAGING_LOG_LEVEL:-info}
|
|
DEBUG=false
|
|
ENABLE_MONITORING=true
|
|
DEV_MODE=false
|
|
|
|
# Staging URLs
|
|
REACT_APP_API_URL=${STAGING_API_URL:-http://rxminder-couchdb-service:5984}
|
|
CORS_ORIGIN=${STAGING_CORS_ORIGIN:-https://staging.rxminder.yourdomain.com}
|
|
|
|
# Staging domain
|
|
INGRESS_HOST=${STAGING_INGRESS_HOST:-staging.rxminder.yourdomain.com}
|
|
|
|
# Staging image tag
|
|
IMAGE_TAG=${STAGING_IMAGE_TAG:-staging}
|
|
|
|
# Enable monitoring but with relaxed settings
|
|
ENABLE_METRICS=true
|
|
ENABLE_TRACING=false
|
|
EOF
|
|
|
|
mv "$temp_file" "$config_file"
|
|
print_success "Generated staging config: $config_file"
|
|
}
|
|
|
|
# Generate generic environment configuration
|
|
generate_generic_config() {
|
|
local config_file="$1"
|
|
local temp_file=$(mktemp)
|
|
|
|
cat > "$temp_file" << EOF
|
|
# Generic environment configuration for: $ENVIRONMENT
|
|
# Generated on: $(date)
|
|
|
|
NODE_ENV=${ENVIRONMENT}
|
|
LOG_LEVEL=${LOG_LEVEL:-info}
|
|
DEBUG=${DEBUG:-false}
|
|
|
|
# Image tag for this environment
|
|
IMAGE_TAG=${ENVIRONMENT}
|
|
EOF
|
|
|
|
mv "$temp_file" "$config_file"
|
|
print_success "Generated generic config: $config_file"
|
|
}
|
|
|
|
# Generate secrets template (not actual secrets)
|
|
generate_secrets_template() {
|
|
local secrets_file="$PROJECT_ROOT/k8s-kustomize/overlays/$ENVIRONMENT/secrets.env.template"
|
|
local temp_file=$(mktemp)
|
|
|
|
print_status "Generating secrets template..."
|
|
|
|
cat > "$temp_file" << EOF
|
|
# Secrets template for $ENVIRONMENT environment
|
|
# Copy this to secrets.env and fill in actual values
|
|
# DO NOT commit secrets.env to version control
|
|
|
|
# Database credentials
|
|
COUCHDB_USERNAME=${COUCHDB_USERNAME:-admin}
|
|
COUCHDB_PASSWORD=CHANGE_ME_IN_${ENVIRONMENT^^}
|
|
|
|
# Registry credentials (if using private registry)
|
|
REGISTRY_USERNAME=${REGISTRY_USERNAME:-}
|
|
REGISTRY_PASSWORD=CHANGE_ME
|
|
REGISTRY_EMAIL=${REGISTRY_EMAIL:-}
|
|
|
|
# TLS/SSL certificates (base64 encoded)
|
|
TLS_CERT=CHANGE_ME
|
|
TLS_KEY=CHANGE_ME
|
|
|
|
# API keys and tokens
|
|
API_SECRET_KEY=CHANGE_ME
|
|
JWT_SECRET=CHANGE_ME
|
|
|
|
# External service credentials
|
|
MONITORING_API_KEY=CHANGE_ME
|
|
SMTP_PASSWORD=CHANGE_ME
|
|
EOF
|
|
|
|
mv "$temp_file" "$secrets_file"
|
|
print_success "Generated secrets template: $secrets_file"
|
|
print_warning "Remember to create actual secrets.env file and add it to .gitignore!"
|
|
}
|
|
|
|
# Validate generated configuration
|
|
validate_config() {
|
|
local config_file="$PROJECT_ROOT/k8s-kustomize/base/config.env"
|
|
|
|
print_status "Validating generated configuration..."
|
|
|
|
if [[ ! -f "$config_file" ]]; then
|
|
print_error "Config file not found: $config_file"
|
|
return 1
|
|
fi
|
|
|
|
# Check for required variables
|
|
local required_vars=("APP_NAME" "NODE_ENV" "REACT_APP_API_URL")
|
|
local missing_vars=()
|
|
|
|
for var in "${required_vars[@]}"; do
|
|
if ! grep -q "^${var}=" "$config_file"; then
|
|
missing_vars+=("$var")
|
|
fi
|
|
done
|
|
|
|
if [[ ${#missing_vars[@]} -gt 0 ]]; then
|
|
print_error "Missing required variables: ${missing_vars[*]}"
|
|
return 1
|
|
fi
|
|
|
|
print_success "Configuration validation passed!"
|
|
}
|
|
|
|
# Display usage information
|
|
show_usage() {
|
|
cat << EOF
|
|
Usage: $0 [environment] [options]
|
|
|
|
ENVIRONMENTS:
|
|
dev, development Generate development configuration
|
|
prod, production Generate production configuration
|
|
staging Generate staging configuration
|
|
<custom> Generate configuration for custom environment
|
|
|
|
OPTIONS:
|
|
-h, --help Show this help message
|
|
-v, --validate Only validate existing configuration
|
|
--secrets Generate secrets template
|
|
--dry-run Show what would be generated without writing files
|
|
|
|
EXAMPLES:
|
|
$0 dev Generate development configuration
|
|
$0 prod --secrets Generate production config and secrets template
|
|
$0 --validate Validate existing configuration
|
|
|
|
ENVIRONMENT VARIABLES:
|
|
The script will load variables from:
|
|
- ~/.env (global user environment)
|
|
- ./.env (project environment)
|
|
- ./.env.\$ENVIRONMENT (environment-specific)
|
|
- ./.env.local (local overrides)
|
|
|
|
EOF
|
|
}
|
|
|
|
# Main execution
|
|
main() {
|
|
local validate_only=false
|
|
local generate_secrets=false
|
|
local dry_run=false
|
|
|
|
# Parse command line arguments
|
|
while [[ $# -gt 0 ]]; do
|
|
case $1 in
|
|
-h|--help)
|
|
show_usage
|
|
exit 0
|
|
;;
|
|
-v|--validate)
|
|
validate_only=true
|
|
shift
|
|
;;
|
|
--secrets)
|
|
generate_secrets=true
|
|
shift
|
|
;;
|
|
--dry-run)
|
|
dry_run=true
|
|
shift
|
|
;;
|
|
-*)
|
|
print_error "Unknown option: $1"
|
|
show_usage
|
|
exit 1
|
|
;;
|
|
*)
|
|
ENVIRONMENT="$1"
|
|
shift
|
|
;;
|
|
esac
|
|
done
|
|
|
|
print_status "Kustomize Config Generator"
|
|
print_status "Environment: $ENVIRONMENT"
|
|
|
|
if [[ "$validate_only" == "true" ]]; then
|
|
validate_config
|
|
exit $?
|
|
fi
|
|
|
|
if [[ "$dry_run" == "true" ]]; then
|
|
print_status "DRY RUN MODE - No files will be written"
|
|
# Set dry run flag for other functions to check
|
|
export DRY_RUN=true
|
|
fi
|
|
|
|
# Load environment variables
|
|
load_env_files
|
|
|
|
# Generate configurations
|
|
generate_base_config
|
|
generate_environment_config
|
|
|
|
if [[ "$generate_secrets" == "true" ]]; then
|
|
generate_secrets_template
|
|
fi
|
|
|
|
# Validate generated configuration
|
|
validate_config
|
|
|
|
print_success "Configuration generation completed!"
|
|
print_status "Next steps:"
|
|
echo " 1. Review generated files in k8s-kustomize/"
|
|
echo " 2. Update any environment-specific values"
|
|
echo " 3. Create secrets.env files for sensitive data"
|
|
echo " 4. Test with: make kustomize-dry-run-$ENVIRONMENT"
|
|
}
|
|
|
|
# Run main function with all arguments
|
|
main "$@"
|