Prevent WebSocket disconnections during deployments by: 1. Rolling Update Strategy: - maxSurge: 1 (allow 1 extra pod during rollout) - maxUnavailable: 0 (keep all pods running) - minReadySeconds: 10 (wait before continuing rollout) 2. Graceful Shutdown: - terminationGracePeriodSeconds: 30 (allow Phoenix to drain connections) 3. PodDisruptionBudget: - minAvailable: 1 (ensure at least 1 pod always available) - Prevents all pods from being terminated simultaneously 4. Improved Health Checks: - Faster readiness probe (5s initial, 3s period) - More aggressive success/failure thresholds - New pods marked ready faster This ensures new pods are fully ready and serving traffic before old pods are terminated, maintaining WebSocket connections and preventing 'something went wrong' errors during deployments.
115 lines
3.3 KiB
YAML
115 lines
3.3 KiB
YAML
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: towerops
|
|
namespace: towerops
|
|
spec:
|
|
replicas: 2
|
|
strategy:
|
|
type: RollingUpdate
|
|
rollingUpdate:
|
|
maxSurge: 1 # Allow 1 extra pod during rollout
|
|
maxUnavailable: 0 # Keep all pods running during rollout
|
|
minReadySeconds: 10 # Wait 10s after pod is ready before continuing
|
|
selector:
|
|
matchLabels:
|
|
app: towerops
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: towerops
|
|
spec:
|
|
terminationGracePeriodSeconds: 30 # Allow 30s for graceful shutdown
|
|
imagePullSecrets:
|
|
- name: gitlab-registry
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 65534
|
|
fsGroup: 65534
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
containers:
|
|
- name: towerops
|
|
image: registry.gitlab.com/towerops/towerops:latest
|
|
imagePullPolicy: Always
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
runAsNonRoot: true
|
|
runAsUser: 65534
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
ports:
|
|
- containerPort: 4000
|
|
name: http
|
|
- containerPort: 4369
|
|
name: epmd
|
|
- containerPort: 9000
|
|
name: dist
|
|
env:
|
|
- name: POD_IP
|
|
valueFrom:
|
|
fieldRef:
|
|
fieldPath: status.podIP
|
|
- name: POD_NAME
|
|
valueFrom:
|
|
fieldRef:
|
|
fieldPath: metadata.name
|
|
- name: POD_NAMESPACE
|
|
valueFrom:
|
|
fieldRef:
|
|
fieldPath: metadata.namespace
|
|
- name: DEPLOY_TIMESTAMP
|
|
value: "1970-01-01T00:00:00Z" # Placeholder, updated by GitLab CI on deploy
|
|
- name: RELEASE_DISTRIBUTION
|
|
value: "name"
|
|
- name: RELEASE_NODE
|
|
value: "towerops@$(POD_IP)"
|
|
- name: PORT
|
|
value: "4000"
|
|
- name: PHX_HOST
|
|
value: "towerops.net"
|
|
- name: MIX_ENV
|
|
value: "prod"
|
|
- name: RELEASE_COOKIE
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: towerops-secrets
|
|
key: RELEASE_COOKIE
|
|
- name: SECRET_KEY_BASE
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: towerops-secrets
|
|
key: SECRET_KEY_BASE
|
|
envFrom:
|
|
- secretRef:
|
|
name: towerops-db
|
|
- secretRef:
|
|
name: towerops-aws
|
|
resources:
|
|
requests:
|
|
memory: "1Gi"
|
|
cpu: "100m"
|
|
limits:
|
|
memory: "2Gi"
|
|
cpu: "500m"
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /health
|
|
port: 4000
|
|
initialDelaySeconds: 30
|
|
periodSeconds: 10
|
|
timeoutSeconds: 3
|
|
failureThreshold: 3
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /health
|
|
port: 4000
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 3
|
|
timeoutSeconds: 2
|
|
successThreshold: 1
|
|
failureThreshold: 2
|