k8s-and-chill/rendered/envs/production/ocis/deployment-ocdav.yaml
Felix Wolf 9f8714d767 fix(ocis): Add memory requests to prevent node overcommit
Sets default resource requests (64Mi memory, 10m CPU) for all oCIS
services, with 96Mi for heavier pods (proxy, nats, thumbnails). Without
requests, all pods were BestEffort and piled onto node 1.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 12:54:43 +02:00

114 lines
3.2 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
annotations:
a8r.io/repository: ssh://git@git.tr1ceracop.de:222/gitea_admin/k8s-and-chill.git
labels:
app.kubernetes.io/instance: ocis
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: ocis
app.kubernetes.io/version: 7.1.4
helm.sh/chart: ocis-0.7.0
name: ocdav
namespace: ocis
spec:
replicas: 1
selector:
matchLabels:
app: ocdav
strategy:
rollingUpdate:
maxSurge: 25%
maxUnavailable: 25%
type: RollingUpdate
template:
metadata:
labels:
app: ocdav
app.kubernetes.io/instance: ocis
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: ocis
app.kubernetes.io/version: 7.1.4
helm.sh/chart: ocis-0.7.0
spec:
containers:
- args:
- ocdav
- server
command:
- ocis
env:
- name: MICRO_REGISTRY
value: nats-js-kv
- name: MICRO_REGISTRY_ADDRESS
value: nats:9233
- name: OCIS_CORS_ALLOW_ORIGINS
value: https://drive.tr1ceracop.de
- name: OCDAV_LOG_COLOR
value: "false"
- name: OCDAV_LOG_LEVEL
value: info
- name: OCDAV_LOG_PRETTY
value: "false"
- name: OCDAV_TRACING_ENABLED
value: "false"
- name: OCDAV_TRACING_TYPE
value: jaeger
- name: OCDAV_TRACING_ENDPOINT
value: null
- name: OCDAV_TRACING_COLLECTOR
value: null
- name: OCDAV_DEBUG_PPROF
value: "false"
- name: OCDAV_HTTP_ADDR
value: 0.0.0.0:8080
- name: OCDAV_DEBUG_ADDR
value: 0.0.0.0:9163
- name: OCDAV_PUBLIC_URL
value: https://drive.tr1ceracop.de
- name: OCIS_EDITION
value: Community
- name: OCDAV_INSECURE
value: "false"
- name: OCDAV_JWT_SECRET
valueFrom:
secretKeyRef:
key: jwt-secret
name: jwt-secret
- name: OCDAV_MACHINE_AUTH_API_KEY
valueFrom:
secretKeyRef:
key: machine-auth-api-key
name: machine-auth-api-key
image: owncloud/ocis:7.1.4
imagePullPolicy: IfNotPresent
livenessProbe:
failureThreshold: 3
httpGet:
path: /healthz
port: metrics-debug
initialDelaySeconds: 60
periodSeconds: 20
timeoutSeconds: 10
name: ocdav
ports:
- containerPort: 8080
name: http
- containerPort: 9163
name: metrics-debug
resources:
requests:
cpu: 10m
memory: 64Mi
securityContext:
readOnlyRootFilesystem: true
runAsGroup: 1000
runAsNonRoot: true
runAsUser: 1000
volumeMounts: null
nodeSelector: {}
securityContext:
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
volumes: null