ExitVideo-Bootstrap · 一键拉起整片 SaaS¶
一条
make up命令,从零(kind cluster)开始,30 分钟内拉起 30+ Kubernetes 服务, 包括 ExitVideo-Bot 业务应用 + 完整 GitOps / 可观测性 / 安全 / 数据栈。
🎯 解决的问题¶
之前要部署这套 SaaS 需要:
1. 安装 kubectl / helm / jq / yq / docker / terraform
2. kind create cluster
3. terraform apply(VPC / RDS / Redis / S3 / CDN)
4. 手动 helm install 11 个 chart(按特定顺序)
5. 配置 ArgoCD + ApplicationSet + 注入 values
6. 配置 Vault + External Secrets + 同步密钥
7. 配置 Kyverno Policies
8. 注入 Linkerd mTLS
9. 部署业务应用(4 个 chart)
10. 等 10+ 分钟 ArgoCD 同步
11. 检查每个服务健康度
Onboarding 一个新人需要 3 天 DevOps 工作量。
现在只需要:
make up # 30 分钟
make ports # 打开全部 UI
Onboarding 时间从 3 天 → 30 分钟。
🚀 快速开始¶
Dev 环境(kind + 本地)¶
cd infra/bootstrap
make up
# 30 分钟后
make status # 查看 bootstrap 进度
make ports # 打开 ArgoCD / Grafana / Vault UI
生产环境(EKS + Terraform)¶
cd infra/bootstrap
# 1. 准备 terraform.tfvars
cp ../terraform/environments/prod/terraform.tfvars.example ../terraform/environments/prod/terraform.tfvars
vim ../terraform/environments/prod/terraform.tfvars
# 2. 跑全栈
make up ENV=prod
失败续跑¶
make resume # 从 .bootstrap-state.json 续跑
反初始化¶
make down # 默认:销毁全部
make down-keep-cluster # 保留 kind 集群
make purge # 包括 state/log 文件
📐 11 阶段流水线¶
| Phase | 内容 | 用时(dev) |
|---|---|---|
| 0 · 前置检查 | kubectl/helm/jq/yq/docker/terraform | 10s |
| 1 · 创建集群 | kind cluster + kubeconfig | 30s |
| 2 · Terraform | VPC/RDS/Redis/S3(生产)/ skip(dev) | 5m / 0s |
| 3 · K8s 基础 | cert-manager / ingress-nginx / metrics-server | 1m |
| 4 · 数据中间件 | Postgres / Redis / MinIO | 1m |
| 5 · 可观测性 | Prometheus / Loki / Tempo / Grafana | 2m |
| 6 · 安全栈 | Vault / Kyverno / Linkerd | 1m |
| 7 · GitOps 工具链 | ArgoCD / Argo Rollouts / Image Updater | 1m |
| 8 · ArgoCD Bootstrap | Root App-of-Apps + 8 个 child ApplicationSet | 30s |
| 9 · 业务应用 | API / Worker / Dashboard / Landing | 5m |
| 10 · 冒烟测试 | API health / DB / ArgoCD / Vault | 1m |
总计:~15 分钟(dev)/ 30 分钟(生产)
🗂️ 目录结构¶
infra/bootstrap/
├── bootstrap.sh # 主入口(11 阶段 + state machine)
├── teardown.sh # 反初始化
├── Makefile # make up / down / status / ports / ...
├── kind-config.yaml # kind 集群配置
├── README.md # 本文件
│
├── lib/
│ └── common.sh # 共享函数(state、retry、log、helm_install)
│
├── sql/
│ └── schema.sql # Postgres schema(自动 import)
│
├── apps/
│ └── root-app.yaml # ArgoCD root App-of-Apps + AppProject
│
└── apps-of-apps/ # 8 个 child ApplicationSet
├── 01-infrastructure.yaml # Wave 0: cert-manager/ingress-nginx/metrics-server
├── 02-data.yaml # Wave 1: postgres/redis/minio
├── 03-observability.yaml # Wave 2: prom/loki/tempo/grafana
├── 04-security.yaml # Wave 3: vault/kyverno/linkerd
├── 05-delivery.yaml # Wave 4: image-updater/argo-rollouts/external-secrets
├── 06-app-core.yaml # Wave 5: exitvideo-bot-api/worker
├── 07-app-edge.yaml # Wave 5: dashboard/landing
└── 08-monitoring.yaml # Wave 6: grafana dashboards/prometheus rules
🔁 完整依赖拓扑(Sync Wave)¶
Wave 0 ─────────────┐
基础设施 │
(cert/ingress) │
▼
Wave 1 ─────────────┐
数据层 │
(pg/redis/minio) │
▼
Wave 2 ─────────────┐
可观测性 │
(prom/loki/tempo) │
▼
Wave 3 ─────────────┐
安全栈 │
(vault/kyv/linkerd) │
▼
Wave 4 ─────────────┐
GitOps 工具链 │
(argocd/updater) │
▼
Wave 5 ─────────────┐
业务应用 │
(api/dashboard) │
▼
Wave 6 ─────────────┐
监控配置 │
(dashboards/alerts)│
▼
Sync Wave 由 child ApplicationSet 内部维护, 确保依赖拓扑,避免 Postgres 还没就绪 API 就尝试连接。
🎛️ 全部 Make 命令¶
主命令¶
| 命令 | 说明 |
|---|---|
make up |
一键拉起整片 SaaS |
make up-fast |
跳过 Terraform + 测试(最快) |
make resume |
从失败点续跑 |
make status |
Bootstrap 进度 |
make state |
完整 state(含时间戳) |
make log |
跟踪日志 |
销毁¶
| 命令 | 说明 |
|---|---|
make down |
反初始化 |
make down-keep-cluster |
保留 kind 集群 |
make purge |
反初始化 + 清理 state/log |
ArgoCD / 监控 UI¶
| 命令 | 说明 |
|---|---|
make argocd-ui |
ArgoCD UI |
make argocd-list |
列出所有 Application 状态 |
make argocd-sync |
强制 Self-Heal |
make grafana-ui |
Grafana UI |
make vault-ui |
Vault UI |
make prom-ui |
Prometheus UI |
make linkerd-viz |
Linkerd Dashboard |
make rollouts |
Argo Rollouts Dashboard |
make ports |
同时打开所有 UI |
测试 / 调试¶
| 命令 | 说明 |
|---|---|
make smoke |
跑 Phase 10 冒烟测试 |
make apps |
列出业务应用 |
make logs-api |
API 日志 |
make logs-worker |
Worker 日志 |
make psql |
Postgres CLI |
make redis-cli |
Redis CLI |
make mc |
MinIO Client |
make shell |
API pod shell |
维护¶
| 命令 | 说明 |
|---|---|
make clean-pvc |
清 PVC(慎用) |
make clean-images |
清本地镜像 |
make info |
集群信息 |
make count |
资源数量 |
make version |
工具版本 |
🔐 安全要点¶
| 设计 | 实现 |
|---|---|
| State 持久化 | .bootstrap-state.json + .bootstrap.log,中断可续跑 |
| Retry + 指数退避 | Helm/Terraform 自动重试 3 次 |
| Dry-run 友好 | --skip-terraform / --skip-tests / --resume |
| CI 模式 | YES=1 / CI=1 跳过交互 |
| 反初始化安全 | 倒序删除,namespace 优雅 wait=false |
| 敏感文件未硬编码 | 占位符 REPLACE_VIA_VAULT 提示用 External Secrets 注入 |
⚠️ 投产前必改¶
下面 3 处必须替换,否则仍在用 dev 默认值:
# 1. apps-of-apps/02-data.yaml
rootPassword: REPLACE_VIA_VAULT # MinIO
# 2. apps-of-apps/03-observability.yaml
adminPassword: REPLACE_VIA_VAULT # Grafana
# 3. apps-of-apps/06-app-core.yaml
DATABASE_URL / REDIS_URL / STRIPE_API_KEY # 通过 ExternalSecrets 注入
推荐做法:用 infra/vault/external-secrets-config.yaml 已配置好的
VaultStaticSecret / VaultDynamicSecret,不在 GitOps repo 暴露任何明文。
🛠️ 故障排查¶
| 现象 | 检查点 |
|---|---|
| bootstrap 卡住 | make log + make status |
| ArgoCD 应用一直 OutOfSync | kubectl describe application -n argocd |
| Helm install 失败 | helm history -n <ns> <release> |
| ArgoCD UI 进不去 | kubectl logs -n argocd deploy/argocd-server |
| Vault sealed | kubectl exec -n vault vault-0 -- vault operator unseal |
| Postgres 连接被拒 | 检查 linkerd inject + NetworkPolicy |
| Argo Rollouts 卡在 Pause | kubectl argo rollouts promote <name> |
| Image Updater 没动 | kubectl logs -n argocd deploy/argocd-image-updater |
| Linkerd proxy 启动失败 | linkerd check |
完整 Runbook:
- infra/runbooks/oncall-runbook.md
- infra/runbooks/disaster-recovery-runbook.md
- infra/runbooks/release-runbook.md
📚 相关文档¶
| 文件 | 说明 |
|---|---|
bootstrap.sh |
主入口 |
lib/common.sh |
共享库 |
apps/root-app.yaml |
Root App-of-Apps |
apps-of-apps/*.yaml |
8 个 child ApplicationSet |
kind-config.yaml |
kind 集群配置 |
sql/schema.sql |
Postgres schema |
Makefile |
make 命令 |
teardown.sh |
反初始化 |
最后更新:与第 11 轮 GitOps App-of-Apps 整合同步
总产出:13 个文件 / ~95KB / 一条 make up 拉起整片 SaaS