345 lines
8.6 KiB
Plaintext
345 lines
8.6 KiB
Plaintext
data una struttura directory del progetto-A come da specifica che segue, creare i seguenti script in bash:
|
||
premessa: i file values.env contengono elenco coppie chiave/valore del tipo chiave1=valore1, ecc..
|
||
1) customize.sh: script che ha in input l'ambiente (dev,qa o prod) ed esegue la sostituzione nel file infrasructure.yaml della directory kubernetes dei tag del tipo <chiave1> con il relativo valore letto dal file values.env della directory corrispondente all'input fornito
|
||
1) build_container.sh : script che effettua la docker build di tutti i container presenti nella directory containers usando il nome della directory sotto containers come nome del container,nome della root directory come nome del repository e sha del commit come tag. lo script deve eseguire anche la push su un registry con precedente login con credenziali lette dal file properties.env
|
||
2) deploy.sh: script che effettua il deploy in kubernetes del file infrastructure.yaml contenuto nella directory kubernetes
|
||
|
||
struttura directory di progetto:
|
||
<dir> progetto-A
|
||
properties.env
|
||
build_src.sh
|
||
<dir> .gitea/
|
||
<dir> workflows
|
||
pipeline.yaml
|
||
<dir> containers
|
||
<dir> frontend
|
||
dockerfile
|
||
<dir> backend
|
||
dockerfile
|
||
<dir> env
|
||
<dir> dev
|
||
values.env
|
||
<dir> qa
|
||
values.env
|
||
<dir> prod
|
||
values.env
|
||
<dir> kubernetes
|
||
infrastructure.yaml
|
||
<dir> src
|
||
|
||
|
||
Provisioning:
|
||
env:
|
||
$organization= nome della società
|
||
$project=nome del progetto
|
||
|
||
|
||
1) Gitea: creazione Organization--> $organization(if not alreay exist)
|
||
2) Gitea: creazione progetto nome--> $project
|
||
3) Harbor: creazione project $project
|
||
4) X3 k8s creazione NAMSPACE,SA, ROLE, ROLEBINDING,KUBECONFIG per deploy su namespace (kube-provisioning.sh) per dev qa e prod
|
||
5) X3 Gitea: creazione secret KUBECONFIG_DEV, KUBECONFIG_QA e KUBECONFIG_PROD con kubeconfig generato da kube-provisioning.sh
|
||
6) harbor: creazione robot-user "git" con permessi full su repo del progetto ---> $registry_user, $registry_pass
|
||
7) harbor: creazione robot-user "k8spull" con permessi full su repo del progetto ---> $registry_user, $registry_pass
|
||
8) creazione secret e patch SA default
|
||
kubectl -n <$project> create secret docker-registry harbor-pull \
|
||
--docker-server=harbor.italiadatacenter.com \
|
||
--docker-username=robot\$<$project>+k8spull \
|
||
--docker-password=<robot usertoken> \
|
||
--docker-email=harbor@italiadatacenter.com
|
||
|
||
kubectl patch serviceaccount default -n athleteos-dev -p '{"imagePullSecrets":[{"name":"harbor-pull"}]}'
|
||
kubectl patch serviceaccount default -n <$project-qa> -p '{"imagePullSecrets":[{"name":"harbor-pull"}]}'
|
||
kubectl patch serviceaccount default -n <$project-prod> -p '{"imagePullSecrets":[{"name":"harbor-pull"}]}'
|
||
9) Gitea: creazione secret REGISTRY_USER -->$registry_user, REGISTRY_PASS -->$registry_pass
|
||
10)Gitea: poplazione repo con skeleton template
|
||
|
||
|
||
gitea-api-token
|
||
65fc5f07365bd3f89c5b9ddca3d2d2e7b3777a88
|
||
|
||
https://git.italiadatacenter.com/api/swagger
|
||
|
||
|
||
List Template
|
||
curl -X 'GET' \
|
||
'https://git.italiadatacenter.com/api/v1/repos/search?q=tmpl&topic=false&includeDesc=true&token=65fc5f07365bd3f89c5b9ddca3d2d2e7b3777a88' \
|
||
-H 'accept: application/json'
|
||
|
||
|
||
List repository:
|
||
curl -X 'GET' \
|
||
'https://git.italiadatacenter.com/api/v1/repos/search?token=65fc5f07365bd3f89c5b9ddca3d2d2e7b3777a88' \
|
||
-H 'accept: application/json'
|
||
|
||
|
||
Create repo from template:
|
||
curl -X 'POST' \
|
||
'https://git.italiadatacenter.com/api/v1/repos/STS_Lab/tmpl_nginx_node/generate?token=65fc5f07365bd3f89c5b9ddca3d2d2e7b3777a88' \
|
||
-H 'accept: application/json' \
|
||
-H 'Content-Type: application/json' \
|
||
-d '{
|
||
"avatar": true,
|
||
"default_branch": "string",
|
||
"description": "string",
|
||
"git_content": true,
|
||
"git_hooks": true,
|
||
"labels": true,
|
||
"name": "secondo",
|
||
"owner": "STS_Lab",
|
||
"private": true,
|
||
"protected_branch": true,
|
||
"topics": true,
|
||
"webhooks": true
|
||
}'
|
||
|
||
|
||
creazione din una applicazione backstage che permetta la creazione di un repo da template con questa api:
|
||
curl -X 'POST' \
|
||
'https://git.italiadatacenter.com/api/v1/repos/STS_Lab/tmpl_nginx_node/generate?token=65fc5f07365bd3f89c5b9ddca3d2d2e7b3777a88' \
|
||
-H 'accept: application/json' \
|
||
-H 'Content-Type: application/json' \
|
||
-d '{
|
||
"avatar": true,
|
||
"default_branch": "string",
|
||
"description": "string",
|
||
"git_content": true,
|
||
"git_hooks": true,
|
||
"labels": true,
|
||
"name": "secondo",
|
||
"owner": "STS_Lab",
|
||
"private": true,
|
||
"protected_branch": true,
|
||
"topics": true,
|
||
"webhooks": true
|
||
}'
|
||
|
||
la lista dei template disponbili è fornita dall'api:
|
||
curl -X 'GET' \
|
||
'https://git.italiadatacenter.com/api/v1/repos/search?q=tmpl&topic=false&includeDesc=true&token=65fc5f07365bd3f89c5b9ddca3d2d2e7b3777a88' \
|
||
-H 'accept: application/json'
|
||
|
||
l'utente deve poter creare un nuovo repo fornendo nome e template scelto dalla lista
|
||
|
||
---------------------------------
|
||
Harbor api:
|
||
https://harbor.italiadatacenter.com/devcenter-api-2.0
|
||
|
||
admin/KAYQE1QA7uwUZ8uI
|
||
|
||
|
||
|
||
Create project
|
||
curl -X 'POST' \
|
||
-u admin:KAYQE1QA7uwUZ8uI \
|
||
'https://harbor.italiadatacenter.com/api/v2.0/projects' \
|
||
-H 'accept: application/json' \
|
||
-H 'X-Resource-Name-In-Location: false' \
|
||
-H 'Content-Type: application/json' \
|
||
-d '{
|
||
"project_name": "secondo",
|
||
"public": false,
|
||
"metadata": {
|
||
"public": "false",
|
||
"enable_content_trust": "string",
|
||
"enable_content_trust_cosign": "string",
|
||
"prevent_vul": "string",
|
||
"severity": "string",
|
||
"auto_scan": "string",
|
||
"auto_sbom_generation": "string",
|
||
"reuse_sys_cve_allowlist": "string",
|
||
|
||
"proxy_speed_kb": "string",
|
||
"max_upstream_conn": "string"
|
||
},
|
||
"cve_allowlist": {
|
||
"id": 0,
|
||
"project_id": 0,
|
||
"expires_at": 0,
|
||
"items": [
|
||
{
|
||
"cve_id": "string"
|
||
}
|
||
],
|
||
"creation_time": "2026-03-21T17:12:18.108Z",
|
||
"update_time": "2026-03-21T17:12:18.108Z"
|
||
},
|
||
"storage_limit": 0
|
||
|
||
}'
|
||
|
||
|
||
creazionnr robot user
|
||
|
||
curl -X 'POST' \
|
||
-u admin:KAYQE1QA7uwUZ8uI \
|
||
'https://harbor.italiadatacenter.com/api/v2.0/robots' \
|
||
-H 'accept: application/json' \
|
||
-H 'Content-Type: application/json' \
|
||
-d '{
|
||
"name": "secondobot",
|
||
"description": "scondo bot",
|
||
"secret": "string",
|
||
"level": "system",
|
||
"disable": true,
|
||
"duration": -1,
|
||
"permissions": [
|
||
{
|
||
"kind": "project",
|
||
"namespace": "secondo",
|
||
"access": [
|
||
{
|
||
"action": "delete",
|
||
"resource": "repository"
|
||
},
|
||
{
|
||
"action": "list",
|
||
"resource": "repository"
|
||
},
|
||
{
|
||
"action": "push",
|
||
"resource": "repository"
|
||
},
|
||
{
|
||
"action": "read",
|
||
"resource": "repository"
|
||
},
|
||
{
|
||
"action": "update",
|
||
"resource": "repository"
|
||
},
|
||
{
|
||
"action": "pull",
|
||
"resource": "repository"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}'
|
||
|
||
|
||
|
||
{
|
||
"creation_time": "2026-03-21T18:24:57.665Z",
|
||
"expires_at": -1,
|
||
"id": 44,
|
||
"name": "robot$secondobot",
|
||
"secret": "YxlIfu6o73zsQnKkgaWMdSc6MEwftVzk"
|
||
}
|
||
|
||
|
||
|
||
|
||
|
||
####### template modulari#########################################################
|
||
|
||
|
||
# 🧠 🎯 Cos’è `git subtree` (in pratica)
|
||
|
||
👉 `subtree` ti permette di:
|
||
|
||
```text
|
||
includere un altro repository dentro una sottocartella
|
||
MANTENENDO la possibilità di aggiornarlo
|
||
```
|
||
|
||
👉 differenza chiave:
|
||
|
||
* il codice viene **copiato nel repo**
|
||
* ma mantiene un **legame logico con l’origine**
|
||
|
||
---
|
||
|
||
# 🔥 Perché è perfetto per template modulari
|
||
|
||
Scenario IDP:
|
||
|
||
```text
|
||
template-node
|
||
template-k8s
|
||
template-ci
|
||
```
|
||
|
||
👉 li vuoi combinare in:
|
||
|
||
```text
|
||
my-service/
|
||
app/
|
||
k8s/
|
||
ci/
|
||
```
|
||
|
||
👉 `subtree` fa ESATTAMENTE questo, in modo pulito
|
||
|
||
---
|
||
|
||
# 🏗️ Setup iniziale (step-by-step)
|
||
|
||
## 1️⃣ Aggiungi il repo template
|
||
|
||
```bash
|
||
git remote add template-node https://gitea/template-node.git
|
||
git fetch template-node
|
||
```
|
||
|
||
---
|
||
|
||
## 2️⃣ Importa il template
|
||
|
||
```bash
|
||
git subtree add \
|
||
--prefix=app \
|
||
template-node main \
|
||
--squash
|
||
```
|
||
|
||
---
|
||
|
||
### 🔍 Cosa succede
|
||
|
||
* copia contenuto in `app/`
|
||
* crea 1 commit (grazie a `--squash`)
|
||
* mantiene riferimento al repo remoto
|
||
|
||
---
|
||
|
||
# 🔄 Aggiornare il template
|
||
|
||
👉 quando il template evolve:
|
||
|
||
```bash
|
||
git subtree pull \
|
||
--prefix=app \
|
||
template-node main \
|
||
--squash
|
||
```
|
||
|
||
---
|
||
|
||
👉 risultato:
|
||
|
||
* aggiorna solo quella cartella
|
||
* merge automatico
|
||
|
||
---
|
||
|
||
# 🚀 Multi-template (use case IDP)
|
||
|
||
```bash
|
||
git subtree add --prefix=app template-node main --squash
|
||
git subtree add --prefix=k8s template-k8s main --squash
|
||
git subtree add --prefix=ci template-ci main --squash
|
||
```
|
||
|
||
---
|
||
|
||
👉 ottieni:
|
||
|
||
```text
|
||
repo finale:
|
||
app/
|
||
k8s/
|
||
ci/
|
||
```
|
||
|