Install (ArgoCD)
🚀Installation
Preliminary
1. Kubernetes is installed; if not, check 🔗link2. Helm is installed; if not, check 🔗link3. ArgoCD is installed; if not, check 🔗link- PostgreSQL is available in namespace
database, DNS resolvestoken.72602.space, and ingress-nginx with thelets-encryptClusterIssuer is ready.
1.prepare runtime Secrets
Details
kubectl get namespace application >/dev/null 2>&1 || \
kubectl create namespace application
set +x
read -rsp 'Sub2API admin password: ' ADMIN_PASSWORD; printf '\n'
read -rsp 'Sub2API PostgreSQL password: ' POSTGRES_PASSWORD; printf '\n'
read -rsp 'Sub2API Redis password: ' REDIS_PASSWORD; printf '\n'
JWT_SECRET="$(openssl rand -hex 32)"
TOTP_KEY="$(openssl rand -hex 32)"
test -n "$ADMIN_PASSWORD"
test -n "$POSTGRES_PASSWORD"
test -n "$REDIS_PASSWORD"
kubectl -n application create secret generic sub2api-auth \
--from-literal=admin-password="$ADMIN_PASSWORD" \
--from-literal=jwt-secret="$JWT_SECRET" \
--from-literal=totp-encryption-key="$TOTP_KEY" \
--dry-run=client -o yaml | kubectl apply -f -
kubectl -n application create secret generic sub2api-external-postgresql \
--from-literal=postgres-password="$POSTGRES_PASSWORD" \
--dry-run=client -o yaml | kubectl apply -f -
kubectl -n application create secret generic sub2api-redis \
--from-literal=redis-password="$REDIS_PASSWORD" \
--dry-run=client -o yaml | kubectl apply -f -
unset ADMIN_PASSWORD POSTGRES_PASSWORD REDIS_PASSWORD JWT_SECRET TOTP_KEY
kubectl -n application get secret \
sub2api-auth sub2api-external-postgresql sub2api-redisSecret values must stay outside Git, terminal output, and this handbook.
2.verify the GitOps source
The parent argocd/ops-docs Application reads
https://github.com/AaronYang0628/docs.git at path manifests. The canonical
child declaration is manifests/sub2api-argocd.yaml; it configures the OCI
chart source and must not be applied as an independent deployment route.
Details
git -C /home/aaron/Ops/docs fetch origin main
git -C /home/aaron/Ops/docs \
show origin/main:manifests/sub2api-argocd.yaml >/dev/null
kubectl -n argocd get application ops-docs \
-o jsonpath='{.spec.source.repoURL}{"\n"}{.spec.source.path}{"\n"}'Expected source values are https://github.com/AaronYang0628/docs.git and
manifests.
3.sync parent and child Applications
Details
argocd app get ops-docs --hard-refresh
argocd app sync ops-docs --revision main
argocd app wait ops-docs --sync --health --timeout 300
argocd app get sub2api --hard-refresh
argocd app sync sub2api
argocd app wait sub2api --sync --health --timeout 6004.verify release, storage, ingress, and API path
Details
kubectl -n argocd get application sub2api \
-o jsonpath='{.spec.source.repoURL}{"\n"}{.spec.source.chart}{" "}{.spec.source.targetRevision}{"\n"}'
kubectl -n application get deployment sub2api \
-o jsonpath='{range .spec.template.spec.containers[*]}{.name}{"="}{.image}{"\n"}{end}'
kubectl -n application rollout status deployment/sub2api --timeout=600s
kubectl -n application get pods,svc,ingress,pvc
kubectl -n application get certificate,certificaterequest,order,challenge
kubectl -n application get endpointslice \
-l kubernetes.io/service-name=sub2api
curl -fsS https://token.72602.space/health
curl -fsS https://token.72602.space/api/v1/settings/public
set +x
read -rsp 'Sub2API API token: ' SUB2API_API_TOKEN; printf '\n'
curl -fsS \
-H "Authorization: Bearer ${SUB2API_API_TOKEN}" \
https://token.72602.space/v1/models
read -rp 'Model ID for smoke generation: ' MODEL_ID
curl -fsS https://token.72602.space/v1/chat/completions \
-H "Authorization: Bearer ${SUB2API_API_TOKEN}" \
--json "{\"model\":\"${MODEL_ID}\",\"messages\":[{\"role\":\"user\",\"content\":\"Reply with OK.\"}],\"max_tokens\":8}"
unset SUB2API_API_TOKEN MODEL_IDExpected release values are chart 0.1.14 and application image
ghcr.io/wei-shaw/sub2api@sha256:4a9620931fbb966b04375c34fe3edd01b640e7e6fbbba02537a9a64d9555a59e.
The TLS certificate is Ready; the
sub2api-data PVC is 10Gi and the Redis PVC is 8Gi, both local-path
RWO.