|
| 1 | +{{- if and (not .Values.mini_runtime.useExternalKafka) .Values.mini_runtime.useSeparateKafkaDeployment }} |
| 2 | +apiVersion: apps/v1 |
| 3 | +kind: StatefulSet |
| 4 | +metadata: |
| 5 | + name: {{ include "akto.fullname" . }}-kafka |
| 6 | + labels: |
| 7 | + {{- include "akto.labels" . | nindent 4 }} |
| 8 | + app.kubernetes.io/component: kafka |
| 9 | +spec: |
| 10 | + serviceName: {{ include "akto.fullname" . }}-kafka-headless |
| 11 | + replicas: {{ .Values.mini_runtime.kafka1.replicas }} |
| 12 | + selector: |
| 13 | + matchLabels: |
| 14 | + app: {{ include "akto.fullname" . }}-kafka |
| 15 | + {{- include "akto.selectorLabels" . | nindent 6 }} |
| 16 | + template: |
| 17 | + metadata: |
| 18 | + labels: |
| 19 | + app: {{ include "akto.fullname" . }}-kafka |
| 20 | + {{- include "akto.selectorLabels" . | nindent 8 }} |
| 21 | + app.kubernetes.io/component: kafka |
| 22 | + spec: |
| 23 | + {{- with .Values.nodeSelector }} |
| 24 | + nodeSelector: |
| 25 | + {{- toYaml . | nindent 8 }} |
| 26 | + {{- end }} |
| 27 | + {{- with .Values.tolerations }} |
| 28 | + tolerations: |
| 29 | + {{- toYaml . | nindent 8 }} |
| 30 | + {{- end }} |
| 31 | + {{- with .Values.affinity }} |
| 32 | + affinity: |
| 33 | + {{- toYaml . | nindent 8 }} |
| 34 | + {{- end }} |
| 35 | + containers: |
| 36 | + - name: kafka |
| 37 | + image: {{ .Values.mini_runtime.kafka1.image.repository }}:{{ .Values.mini_runtime.kafka1.image.tag | default .Chart.AppVersion }} |
| 38 | + command: |
| 39 | + - bash |
| 40 | + - -c |
| 41 | + - | |
| 42 | + # Extract pod ordinal from hostname |
| 43 | + export POD_ORDINAL=${HOSTNAME##*-} |
| 44 | + export KAFKA_NODE_ID=${POD_ORDINAL} |
| 45 | + export KAFKA_BROKER_ID=${POD_ORDINAL} |
| 46 | +
|
| 47 | + # Build controller quorum voters list for KRaft |
| 48 | + QUORUM_VOTERS="" |
| 49 | + for i in $(seq 0 $(({{ .Values.mini_runtime.kafka1.replicas }} - 1))); do |
| 50 | + if [ -n "$QUORUM_VOTERS" ]; then |
| 51 | + QUORUM_VOTERS="${QUORUM_VOTERS}," |
| 52 | + fi |
| 53 | + QUORUM_VOTERS="${QUORUM_VOTERS}${i}@{{ include "akto.fullname" . }}-kafka-${i}.{{ include "akto.fullname" . }}-kafka-headless.${MY_POD_NAMESPACE}.svc.{{ .Values.kubernetesClusterDomain }}:9094" |
| 54 | + done |
| 55 | + export KAFKA_CONTROLLER_QUORUM_VOTERS=$QUORUM_VOTERS |
| 56 | +
|
| 57 | + echo "Starting Kafka with NODE_ID=${KAFKA_NODE_ID}" |
| 58 | + echo "Controller Quorum: ${KAFKA_CONTROLLER_QUORUM_VOTERS}" |
| 59 | +
|
| 60 | + # Start Kafka |
| 61 | + exec /etc/confluent/docker/run |
| 62 | + ports: |
| 63 | + - containerPort: 9092 |
| 64 | + name: kafka |
| 65 | + - containerPort: 9093 |
| 66 | + name: kafka-ssl |
| 67 | + - containerPort: 9094 |
| 68 | + name: controller |
| 69 | + - containerPort: 9999 |
| 70 | + name: jmx |
| 71 | + env: |
| 72 | + - name: MY_POD_NAME |
| 73 | + valueFrom: |
| 74 | + fieldRef: |
| 75 | + fieldPath: metadata.name |
| 76 | + - name: MY_POD_NAMESPACE |
| 77 | + valueFrom: |
| 78 | + fieldRef: |
| 79 | + fieldPath: metadata.namespace |
| 80 | + - name: HOSTNAME |
| 81 | + valueFrom: |
| 82 | + fieldRef: |
| 83 | + fieldPath: metadata.name |
| 84 | + - name: KAFKA_ADVERTISED_LISTENERS |
| 85 | + value: >- |
| 86 | + {{- if .Values.mini_runtime.kafka1.env.kafkaAdvertisedListeners }} |
| 87 | + {{ .Values.mini_runtime.kafka1.env.kafkaAdvertisedListeners }} |
| 88 | + {{- else if and .Values.mini_runtime.kafka1.useSasl .Values.mini_runtime.kafka1.useTls }} |
| 89 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST_SASL://$(MY_POD_NAME).{{ include "akto.fullname" . }}-kafka-headless.$(MY_POD_NAMESPACE).svc.{{ .Values.kubernetesClusterDomain }}:9093 |
| 90 | + {{- else if .Values.mini_runtime.kafka1.useSasl }} |
| 91 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST_SASL://$(MY_POD_NAME).{{ include "akto.fullname" . }}-kafka-headless.$(MY_POD_NAMESPACE).svc.{{ .Values.kubernetesClusterDomain }}:9092 |
| 92 | + {{- else if .Values.mini_runtime.kafka1.useTls }} |
| 93 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST://$(MY_POD_NAME).{{ include "akto.fullname" . }}-kafka-headless.$(MY_POD_NAMESPACE).svc.{{ .Values.kubernetesClusterDomain }}:9092,LISTENER_DOCKER_EXTERNAL_DIFFHOST_ENCRYPTED://$(MY_POD_NAME).{{ include "akto.fullname" . }}-kafka-headless.$(MY_POD_NAMESPACE).svc.{{ .Values.kubernetesClusterDomain }}:9093 |
| 94 | + {{- else }} |
| 95 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST://$(MY_POD_NAME).{{ include "akto.fullname" . }}-kafka-headless.$(MY_POD_NAMESPACE).svc.{{ .Values.kubernetesClusterDomain }}:9092 |
| 96 | + {{- end }} |
| 97 | + - name: KAFKA_CLEANUP_POLICY |
| 98 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaCleanupPolicy }} |
| 99 | + - name: KAFKA_CREATE_TOPICS |
| 100 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaCreateTopics }} |
| 101 | + - name: KAFKA_INTER_BROKER_LISTENER_NAME |
| 102 | + value: >- |
| 103 | + {{- if .Values.mini_runtime.kafka1.env.kafkaAdvertisedListeners }} |
| 104 | + {{ .Values.mini_runtime.kafka1.env.kafkaInterBrokerListenerName }} |
| 105 | + {{- else if .Values.mini_runtime.kafka1.useSasl }} |
| 106 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST_SASL |
| 107 | + {{- else if .Values.mini_runtime.kafka1.useTls }} |
| 108 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST |
| 109 | + {{- else }} |
| 110 | + LISTENER_DOCKER_EXTERNAL_DIFFHOST |
| 111 | + {{- end }} |
| 112 | + - name: KAFKA_LISTENER_SECURITY_PROTOCOL_MAP |
| 113 | + value: >- |
| 114 | + {{- if and .Values.mini_runtime.kafka1.useSasl .Values.mini_runtime.kafka1.useTls }} |
| 115 | + {{ .Values.mini_runtime.kafka1.env.kafkaListenerSecurityProtocolMapSaslTls }} |
| 116 | + {{- else if .Values.mini_runtime.kafka1.useSasl }} |
| 117 | + {{ .Values.mini_runtime.kafka1.env.kafkaListenerSecurityProtocolMapSasl }} |
| 118 | + {{- else if .Values.mini_runtime.kafka1.useTls }} |
| 119 | + {{ .Values.mini_runtime.kafka1.env.kafkaListenerSecurityProtocolMapSsl }} |
| 120 | + {{- else }} |
| 121 | + CONTROLLER:PLAINTEXT,LISTENER_DOCKER_EXTERNAL_DIFFHOST:PLAINTEXT |
| 122 | + {{- end }} |
| 123 | + - name: KAFKA_PROCESS_ROLES |
| 124 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaProcessRoles }} |
| 125 | + - name: KAFKA_CONTROLLER_LISTENER_NAMES |
| 126 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaControllerListenerNames }} |
| 127 | + - name: KAFKA_LISTENERS |
| 128 | + value: >- |
| 129 | + {{- if .Values.mini_runtime.kafka1.env.kafkaListeners }} |
| 130 | + {{ .Values.mini_runtime.kafka1.env.kafkaListeners }} |
| 131 | + {{- else if and .Values.mini_runtime.kafka1.useSasl .Values.mini_runtime.kafka1.useTls }} |
| 132 | + CONTROLLER://0.0.0.0:9094,LISTENER_DOCKER_EXTERNAL_DIFFHOST_SASL://0.0.0.0:9093 |
| 133 | + {{- else if .Values.mini_runtime.kafka1.useSasl }} |
| 134 | + CONTROLLER://0.0.0.0:9094,LISTENER_DOCKER_EXTERNAL_DIFFHOST_SASL://0.0.0.0:9092 |
| 135 | + {{- else if .Values.mini_runtime.kafka1.useTls }} |
| 136 | + CONTROLLER://0.0.0.0:9094,LISTENER_DOCKER_EXTERNAL_DIFFHOST_ENCRYPTED://0.0.0.0:9093 |
| 137 | + {{- else }} |
| 138 | + CONTROLLER://0.0.0.0:9094,LISTENER_DOCKER_EXTERNAL_DIFFHOST://0.0.0.0:9092 |
| 139 | + {{- end }} |
| 140 | + - name: KAFKA_LOG_CLEANER_ENABLE |
| 141 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaLogCleanerEnable }} |
| 142 | + - name: KAFKA_LOG_RETENTION_BYTES |
| 143 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaLogRetentionBytes }} |
| 144 | + - name: KAFKA_LOG_RETENTION_CHECK_INTERVAL_MS |
| 145 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaLogRetentionCheckIntervalMs }} |
| 146 | + - name: KAFKA_LOG_RETENTION_HOURS |
| 147 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaLogRetentionHours }} |
| 148 | + - name: KAFKA_LOG_SEGMENT_BYTES |
| 149 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaLogSegmentBytes }} |
| 150 | + - name: KAFKA_OFFSETS_TOPIC_REPLICATION_FACTOR |
| 151 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaOffsetsTopicReplicationFactor }} |
| 152 | + - name: KAFKA_TRANSACTION_STATE_LOG_MIN_ISR |
| 153 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaTransactionStateLogMinIsr }} |
| 154 | + - name: KAFKA_TRANSACTION_STATE_LOG_REPLICATION_FACTOR |
| 155 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaTransactionStateLogReplicationFactor }} |
| 156 | + - name: CLUSTER_ID |
| 157 | + value: {{ quote .Values.mini_runtime.kafka1.env.kafkaClusterId }} |
| 158 | + {{- if .Values.mini_runtime.kafka1.useTls }} |
| 159 | + - name: KAFKA_SSL_KEYSTORE_LOCATION |
| 160 | + value: {{ quote .Values.mini_runtime.kafka1.env.sslKeystoreLocation }} |
| 161 | + - name: KAFKA_SSL_KEYSTORE_PASSWORD |
| 162 | + value: {{ quote .Values.mini_runtime.kafka1.env.sslKeystorePassword }} |
| 163 | + - name: KAFKA_SSL_KEY_PASSWORD |
| 164 | + value: {{ quote .Values.mini_runtime.kafka1.env.sslKeyPassword }} |
| 165 | + - name: KAFKA_SSL_TRUSTSTORE_LOCATION |
| 166 | + value: {{ quote .Values.mini_runtime.kafka1.env.sslTruststoreLocation }} |
| 167 | + - name: KAFKA_SSL_TRUSTSTORE_PASSWORD |
| 168 | + value: {{ quote .Values.mini_runtime.kafka1.env.sslTruststorePassword }} |
| 169 | + {{- end }} |
| 170 | + {{- if .Values.mini_runtime.kafka1.useSasl }} |
| 171 | + - name: KAFKA_OPTS |
| 172 | + value: "-Djava.security.auth.login.config=/etc/kafka/config/kafka_server_jaas.conf" |
| 173 | + - name: KAFKA_SASL_ENABLED_MECHANISMS |
| 174 | + value: "PLAIN" |
| 175 | + - name: KAFKA_SASL_MECHANISM_INTER_BROKER_PROTOCOL |
| 176 | + value: "PLAIN" |
| 177 | + {{- end }} |
| 178 | + - name: KUBERNETES_CLUSTER_DOMAIN |
| 179 | + value: {{ quote .Values.kubernetesClusterDomain }} |
| 180 | + {{- if or .Values.mini_runtime.kafka1.useTls .Values.mini_runtime.kafka1.useSasl }} |
| 181 | + volumeMounts: |
| 182 | + {{- if .Values.mini_runtime.kafka1.useTls }} |
| 183 | + - name: kafka-certs |
| 184 | + mountPath: {{ quote .Values.mini_runtime.kafka1.env.sslBaseMountPath }} |
| 185 | + {{- end }} |
| 186 | + {{- if .Values.mini_runtime.kafka1.useSasl }} |
| 187 | + - name: kafka-jaas-config |
| 188 | + mountPath: /etc/kafka/config |
| 189 | + readOnly: true |
| 190 | + {{- end }} |
| 191 | + {{- end }} |
| 192 | + resources: {{- toYaml .Values.mini_runtime.kafka1.resources | nindent 10 }} |
| 193 | + restartPolicy: Always |
| 194 | + {{- if or .Values.mini_runtime.kafka1.useTls .Values.mini_runtime.kafka1.useSasl }} |
| 195 | + volumes: |
| 196 | + {{- if .Values.mini_runtime.kafka1.useTls }} |
| 197 | + - name: kafka-certs |
| 198 | + secret: |
| 199 | + secretName: {{ quote .Values.mini_runtime.kafka1.env.sslSecretName }} |
| 200 | + {{- end }} |
| 201 | + {{- if .Values.mini_runtime.kafka1.useSasl }} |
| 202 | + - name: kafka-jaas-config |
| 203 | + configMap: |
| 204 | + name: {{ include "akto.fullname" . }}-kafka-jaas-config |
| 205 | + {{- end }} |
| 206 | + {{- end }} |
| 207 | +{{- end }} |
0 commit comments