diff --git a/README.MD b/README.MD index 336f2dcf..1a8e6440 100644 --- a/README.MD +++ b/README.MD @@ -73,6 +73,8 @@ This repository aims to provide a ready-to-go [Tilt](https://docs.tilt.dev/) set * [helm](https://helm.sh/docs/intro/install/) must be installed to generate the k8s from the helm charts in the gitops repo * For Windows users: * A bash program. By default git bash is used with an assumed installation directory of C:/Program Files/Git +* System Resource Usage + * For local development containers takee about 4GB with docker desktop on windows full k8s used 11GB ## Startup Services In the root directory of the repository run `tilt up`. This will start all the faf services in the correct order. The status of each service can be viewed in the tilt UI by visiting . This is the control server for tilt where you can restart services or disable them for substitution by services you would like to run from source code as you actively develop them. diff --git a/Tiltfile b/Tiltfile index 25bb1e3a..88f760a8 100644 --- a/Tiltfile +++ b/Tiltfile @@ -28,23 +28,16 @@ if os.name == "nt": if not os.path.exists(windows_bash_path): fail("Windows users need to supply a valid path to a bash executable") + data_absolute_path = "//data/" + data_relative_path if k8s_context() == "docker-desktop": hostname = cfg.get("hostname", "host.docker.internal") - drive, path_without_drive = os.getcwd().split(":") - data_absolute_path = os.path.join("//run/desktop/mnt/host/", drive, path_without_drive, data_relative_path).replace("\\","/").lower() - use_named_volumes = ["mariadb"] elif k8s_context() == "minikube" or k8s_context() == "kind-kind": hostname = cfg.get("hostname", "") - data_absolute_path = "//data/" + data_relative_path - use_named_volumes = [] - else: - fail("Cannot determine how to mount for windows host") else: faf_data_dir = cfg.get("faf-data-dir", "~/.faforever") hostname = cfg.get("hostname", "") data_absolute_path = os.path.join(os.getcwd(), data_relative_path) - use_named_volumes = [] host_details = ["hostIP="+host_ip, "hostname="+hostname] @@ -169,15 +162,12 @@ def helm_with_build_cache(chart, namespace="", values=[], set=[], specifier = "" return encode_yaml_stream(objects) -def to_hostpath_storage(yaml, use_named_volumes): +def to_hostpath_storage(yaml): objects = decode_yaml_stream(yaml) for object in objects: if object["kind"] == "PersistentVolume": object["spec"].pop("nodeAffinity", None) localpath_spec = object["spec"].pop("local", {"path": ""}) - if os.path.basename(localpath_spec["path"]) in use_named_volumes: - volume_name = os.path.basename(localpath_spec["path"]) - localpath_spec["path"] = volume_name object["spec"]["hostPath"] = localpath_spec object["spec"]["hostPath"]["type"] = "DirectoryOrCreate" @@ -267,7 +257,7 @@ if not is_ci: k8s_resource(workload="release-name-reloader", new_name="reloader", objects=["release-name-reloader:serviceaccount", "release-name-reloader-metadata-role:role", "release-name-reloader-role:clusterrole", "release-name-reloader-metadata-role-binding:rolebinding", "release-name-reloader-role-binding:clusterrolebinding"], resource_deps=["namespaces"], labels=["core"]) storage_yaml = helm_with_build_cache("cluster/storage", values=["config/local.yaml"], set=["dataPath="+data_absolute_path]) -storage_yaml = to_hostpath_storage(storage_yaml, use_named_volumes=use_named_volumes) +storage_yaml = to_hostpath_storage(storage_yaml) k8s_yaml(storage_yaml) volume_identifiers = [] @@ -316,7 +306,7 @@ k8s_resource(workload="mariadb", objects=["mariadb:configmap", "mariadb:secret", mariadb_setup_resources = [] for object in decode_yaml_stream(mariadb_init_user_yaml): mariadb_setup_resources.append(object["metadata"]["name"]) - k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "mariadb", "faf-api-config", "faf-user-service-config", "faf-lobby-server-config", "faf-replay-server-config", "faf-policy-server-config", "faf-league-service-config", "wordpress-config", "ergochat-config"], labels=["database"]) + k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "mariadb", "faf-api-config", "faf-user-service-config", "faf-lobby-server-config", "faf-replay-server-config", "faf-policy-server-config", "faf-league-service-config", "wordpress-config", "ergochat-config", "faf-icebreaker-config"], labels=["database"]) mongodb_yaml = helm_with_build_cache("infra/mongodb", namespace="faf-infra", values=["config/local.yaml"]) mongodb_init_user_yaml, mongodb_resource_yaml = filter_yaml(mongodb_yaml, {"app": "mongodb-sync-db-user"}) @@ -337,7 +327,7 @@ k8s_resource(workload="rabbitmq", objects=["rabbitmq:configmap", "rabbitmq:secre rabbitmq_setup_resources = [] for object in decode_yaml_stream(rabbitmq_init_user_yaml): rabbitmq_setup_resources.append(object["metadata"]["name"]) - k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "rabbitmq", "faf-api-config", "faf-icebreaker-config", "faf-lobby-server-config", "debezium-config", "faf-league-service-config"], labels=["rabbitmq"]) + k8s_resource(workload=object["metadata"]["name"], resource_deps=["init-apps", "rabbitmq", "faf-api-config", "faf-icebreaker-config", "faf-lobby-server-config", "debezium-config", "faf-league-service-config", "faf-user-service-config"], labels=["rabbitmq"]) k8s_yaml(cronjob_to_job(helm_with_build_cache("apps/faf-db-migrations", namespace="faf-apps", values=["config/local.yaml"]))) k8s_resource(workload="faf-db-migrations", objects=["faf-db-migrations:secret"], resource_deps=mariadb_setup_resources, labels=["database"]) diff --git a/apps/faf-user-service/mail/account-deletion-confirmation.html b/apps/faf-user-service/mail/account-deletion-confirmation.html new file mode 100644 index 00000000..a514466c --- /dev/null +++ b/apps/faf-user-service/mail/account-deletion-confirmation.html @@ -0,0 +1,491 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Confirm your FAF account deletion
+ +
+ + + + +
+
+ + + + + + +
+ + +
+ + + + + + + + + + + + + + + + + + + + + +
+ +
 
+ +
+ + + + + + + +
+ + FAF Logo + +
+ +
+ +
Forged Alliance Forever
+ +
+ +
 
+ +
+ +
+ + +
+
+
+ + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + + + + + + + + + +
+ +

Confirm your account deletion

+ +

Dear {{`{{username}}`}},

+ +

+ We received a request to permanently delete your FAForever account. + Click the button below to confirm this request. +

+ +

+ Once confirmed, your account will be deleted or anonymized in accordance + with our account deletion process. This action cannot be undone. +

+ +
+ + + + + + + +
+ + Confirm account deletion + +
+ +
+ +

Thanks,

+

-- The FAForever team

+ +
+ +
+ + +
+ +
+ + + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

+ If you did not request this deletion, you can safely ignore this email. + Your account will remain unchanged unless you confirm the request. +

+ +
+ +
+ + +
+ +
+ + + + + + + + + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

+ If the button above does not work, open this URL manually in your browser: + {{`{{confirmationUrl}}`}} +

+ +
+ +
+ + +
+ +
+ + + + + +
+ + + + \ No newline at end of file diff --git a/apps/faf-user-service/mail/account-deletion-notification.html b/apps/faf-user-service/mail/account-deletion-notification.html new file mode 100644 index 00000000..d2a86a13 --- /dev/null +++ b/apps/faf-user-service/mail/account-deletion-notification.html @@ -0,0 +1,400 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Your FAF account has been deleted
+ +
+ + + + +
+
+ + + + + + +
+ + +
+ + + + + + + + + + + + + + + + + + + + + +
+ +
 
+ +
+ + + + + + + +
+ + FAF Logo + +
+ +
+ +
Forged Alliance Forever
+ +
+ +
 
+ +
+ +
+ + +
+
+
+ + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

Your account has been deleted

+ +

Dear {{`{{username}}`}},

+ +

+ Your FAForever account deletion request has now been completed. +

+ +

+ Your personal account data has been deleted or anonymized in accordance + with our account deletion process. +

+ +

Thanks,

+

-- The FAForever team

+ +
+ +
+ + +
+ +
+ + + + + +
+ + + + + + + +
+ + +
+ + + + + + + + + +
+ +

+ If you did not request this account deletion, please contact the FAForever team immediately. +

+ +
+ +
+ + +
+ +
+ + + + + + + + + + + +
+ + + + \ No newline at end of file diff --git a/apps/faf-user-service/templates/config-files.yaml b/apps/faf-user-service/templates/config-files.yaml index 1bf82ef3..e4bc1cb4 100644 --- a/apps/faf-user-service/templates/config-files.yaml +++ b/apps/faf-user-service/templates/config-files.yaml @@ -7,6 +7,10 @@ metadata: data: "account-activation.html": |- {{ tpl (.Files.Get "mail/account-activation.html") . | indent 4 }} + "account-deletion-confirmation.html": |- +{{ tpl (.Files.Get "mail/account-deletion-confirmation.html") . | indent 4 }} + "account-deletion-notification.html": |- +{{ tpl (.Files.Get "mail/account-deletion-notification.html") . | indent 4 }} "password-reset.html": |- {{ tpl (.Files.Get "mail/password-reset.html") . | indent 4 }} "welcome-to-faf.html": |- diff --git a/apps/faf-user-service/templates/config.yaml b/apps/faf-user-service/templates/config.yaml index 914f43da..86d6b3ed 100644 --- a/apps/faf-user-service/templates/config.yaml +++ b/apps/faf-user-service/templates/config.yaml @@ -25,4 +25,10 @@ data: LOBBY_URL: "wss://ws.{{.Values.baseDomain}}" IRC_TOKEN_TTL: "86400" REPLAY_URL: "wss://replay-ws.{{.Values.baseDomain}}" - ALTCHA_ENABLED: "true" \ No newline at end of file + ALTCHA_ENABLED: "true" + RABBITMQ_USER: "faf-user-service" + RABBITMQ_PORT: "5672" + RABBITMQ_HOST: "rabbitmq" + NODEBB_READ_API_URL: https://forum.{{.Values.baseDomain}}/api + NODEBB_WRITE_API_URL: https://forum.{{.Values.baseDomain}}/api/v3 + WIKIJS_GRAPHQL_URL: https://wiki.{{.Values.baseDomain}}/graphql diff --git a/apps/faf-user-service/templates/local-secret.yaml b/apps/faf-user-service/templates/local-secret.yaml index f31836fd..bf615074 100644 --- a/apps/faf-user-service/templates/local-secret.yaml +++ b/apps/faf-user-service/templates/local-secret.yaml @@ -12,4 +12,5 @@ stringData: LOBBY_SECRET: "banana" REPLAY_SECRET: "banana" ALTCHA_HMAC_KEY: "bananabananabananabanana" + RABBITMQ_PASSWORD: "banana" {{- end}} diff --git a/apps/rabbitmq/templates/config.yaml b/apps/rabbitmq/templates/config.yaml index dec705fc..af3e16d9 100644 --- a/apps/rabbitmq/templates/config.yaml +++ b/apps/rabbitmq/templates/config.yaml @@ -6,7 +6,7 @@ metadata: app: rabbitmq data: ADMIN_USER: "faf-admin" - "enabled_plugins": "[rabbitmq_management,rabbitmq_prometheus]." + "enabled_plugins": "[rabbitmq_management,rabbitmq_prometheus,rabbitmq_shovel,rabbitmq_shovel_management]." "rabbitmq_conf": |- default_user = $(ADMIN_USER) default_pass = $(ADMIN_PASSWORD) diff --git a/apps/rabbitmq/templates/statefulset.yaml b/apps/rabbitmq/templates/statefulset.yaml index 802ec2e3..30a0d00c 100644 --- a/apps/rabbitmq/templates/statefulset.yaml +++ b/apps/rabbitmq/templates/statefulset.yaml @@ -32,7 +32,7 @@ spec: protocol: TCP startupProbe: exec: - command: ["rabbitmq-diagnostics", "-q", "ping"] + command: ["rabbitmq-diagnostics", "-q", "check_running"] initialDelaySeconds: 15 timeoutSeconds: 15 periodSeconds: 5 diff --git a/apps/rabbitmq/values.yaml b/apps/rabbitmq/values.yaml index 82b9d710..5dc17484 100644 --- a/apps/rabbitmq/values.yaml +++ b/apps/rabbitmq/values.yaml @@ -26,3 +26,7 @@ users: secretRef: faf-icebreaker usernameKey: RABBITMQ_USER passwordKey: RABBITMQ_PASSWORD + - configMapRef: faf-user-service + secretRef: faf-user-service + usernameKey: RABBITMQ_USER + passwordKey: RABBITMQ_PASSWORD diff --git a/ops/infisical/Chart.yaml b/ops/infisical/Chart.yaml index 555cb02c..7955fccb 100644 --- a/ops/infisical/Chart.yaml +++ b/ops/infisical/Chart.yaml @@ -3,5 +3,5 @@ name: infisical version: 1.0.0 dependencies: - name: secrets-operator - version: 0.10.29 + version: 0.11.11 repository: https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/