{{/* Mutually exclusive with enterprise-api.yaml's Deployment+Service, gated the opposite way -- see that file's doc comment for why: "does a deployment run the tenant-isolated binary or not" should be a single values.yaml decision (enterprise.enabled), not two independently driftable ones. Both render a Service named {{ .Release.Name }}-api on port 8080, so every consumer (alerting's API_QUERY_URL, web's build args) needs zero conditional logic of its own. */}} {{- if not .Values.enterprise.enabled }} apiVersion: apps/v1 kind: Deployment metadata: name: {{ .Release.Name }}-api labels: {{- include "sentry.labels" . | nindent 4 }} {{- include "sentry.selectorLabels" (list $ "api") | nindent 4 }} spec: replicas: {{ .Values.api.replicas }} selector: matchLabels: {{- include "sentry.selectorLabels" (list $ "api") | nindent 6 }} template: metadata: labels: {{- include "sentry.selectorLabels" (list $ "api") | nindent 8 }} spec: initContainers: {{- include "sentry.waitForTCP" (list "clickhouse" (printf "%s-clickhouse" .Release.Name) "9000") | nindent 8 }} {{- include "sentry.waitForTCP" (list "postgres" (printf "%s-postgres" .Release.Name) "5432") | nindent 8 }} {{- include "sentry.waitForTCP" (list "search" (printf "%s-search" .Release.Name) "50052") | nindent 8 }} containers: - name: api image: "{{ .Values.api.image.repository }}:{{ .Values.api.image.tag }}" imagePullPolicy: {{ .Values.global.imagePullPolicy }} env: - name: CLICKHOUSE_ADDR value: "{{ .Release.Name }}-clickhouse:9000" - name: CLICKHOUSE_PASSWORD valueFrom: secretKeyRef: name: {{ .Release.Name }}-clickhouse key: password - name: SEARCH_GRPC_ADDR value: "{{ .Release.Name }}-search:50052" - name: POSTGRES_ADDR value: "{{ .Release.Name }}-postgres:5432" - name: POSTGRES_DATABASE value: sentry_metadata - name: POSTGRES_USERNAME value: sentry - name: POSTGRES_PASSWORD valueFrom: secretKeyRef: name: {{ .Release.Name }}-postgres key: password # No ENTERPRISE_AUTH_URL here -- this file only renders when # enterprise.enabled is false (see the top of this file), so # authz.RequireRole*/RequireRoleOrService stay a permanent # no-op for this Deployment. enterprise-api.yaml is where # that enforcement actually turns on. ports: - name: http containerPort: 8080 readinessProbe: exec: command: ["/api", "-healthcheck"] initialDelaySeconds: 5 periodSeconds: 5 resources: {{- toYaml .Values.api.resources | nindent 12 }} --- apiVersion: v1 kind: Service metadata: name: {{ .Release.Name }}-api labels: {{- include "sentry.labels" . | nindent 4 }} {{- include "sentry.selectorLabels" (list $ "api") | nindent 4 }} spec: selector: {{- include "sentry.selectorLabels" (list $ "api") | nindent 4 }} ports: - name: http port: 8080 {{- end }}