ExitVideo-Bot Helm Chart¶
Production-grade Helm v3 chart 替换
infra/k8s/静态 manifests。
优势¶
- ✅ 参数化(
--set) - ✅ 多环境支持(dev / staging / prod)
- ✅ 一键升级 / 回滚
- ✅ values 集中管理
- ✅ Helm hooks(pre-install 等)
目录结构¶
helm/
├── Chart.yaml # Chart 元数据
├── values.yaml # 默认配置
├── README.md # 本文件
└── templates/
├── _helpers.tpl # Template 辅助函数
├── configmap-secret.yaml # 配置
├── deployment-api.yaml # API
├── deployment-worker-beat-webhook.yaml # Worker / Beat / Webhook
├── service-ingress-pdb-hpa.yaml # Service / Ingress / HPA / PDB
└── servicemonitor-prometheusrule-network.yaml # 监控 / 网络策略
安装¶
# 1. 添加 helm 仓库(如需要)
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo update
# 2. Lint 测试
helm lint ./infra/helm/
# 3. 试运行(dry-run + debug)
helm install exitvideo ./infra/helm/ \
--namespace exitvideo-prod \
--create-namespace \
--dry-run --debug
# 4. 真实安装
helm install exitvideo ./infra/helm/ \
--namespace exitvideo-prod \
--create-namespace \
--values values-prod.yaml
# 5. 升级
helm upgrade exitvideo ./infra/helm/ \
-n exitvideo-prod \
--values values-prod.yaml \
--set api.replicaCount=10
# 6. 回滚
helm history exitvideo -n exitvideo-prod
helm rollback exitvideo 1 -n exitvideo-prod
# 7. 卸载
helm uninstall exitvideo -n exitvideo-prod
多环境 values 示例¶
values-prod.yaml¶
api:
replicaCount: 3
minReplicas: 3
maxReplicas: 30
worker:
replicaCount: 5
config:
logLevel: "INFO"
environment: "production"
secrets:
jwtSecret: "<production-secret-64-chars>"
stripeSecretKey: "sk_live_..."
# ... 全量秘钥
databaseUrl: "postgresql://app:xxx@prod-db.region.rds.amazonaws.com:5432/saas"
redisUrl: "redis://prod-redis.region.cache.amazonaws.com:6379/0"
values-staging.yaml¶
api:
replicaCount: 1
worker:
replicaCount: 2
config:
logLevel: "DEBUG"
environment: "staging"
enableDailyBenchmark: "false"
secrets:
stripeSecretKey: "sk_test_..."
databaseUrl: "postgresql://app:xxx@staging-db:5432/saas"
values-dev.yaml¶
api:
replicaCount: 1
worker:
replicaCount: 1
config:
logLevel: "DEBUG"
postgresql:
enabled: true # 内嵌 dev PG
redis:
enabled: true # 内嵌 dev Redis
验证清单¶
[ ] helm template exitvideo ./infra/helm/ > rendered.yaml
[ ] helm install --dry-run ...
[ ] kubectl -n exitvideo-prod get all
[ ] kubectl -n exitvideo-prod get ingress
[ ] kubectl -n exitvideo-prod get hpa
[ ] kubectl -n exitvideo-prod get prometheusrules
[ ] curl https://api.exitvideo.com/health
迁移自静态 manifests¶
如果已经从 infra/k8s/ 用 kubectl apply -f 部署过:
# 1. 导出当前 namespace 资源
kubectl get all -n exitvideo-prod -o yaml > current.yaml
# 2. helm install 之前先删除旧资源
kubectl delete deployment,service,configmap,secret -n exitvideo-prod -l app.kubernetes.io/part-of=exitvideo
# 3. 用 helm 接管
helm install exitvideo ./infra/helm/ -n exitvideo-prod
CI/CD 推荐集成¶
# .github/workflows/deploy.yml
- name: Helm Deploy
run: |
helm upgrade exitvideo ./infra/helm/ \
--install \
--namespace exitvideo-$ENV \
--create-namespace \
--values values-$ENV.yaml \
--set image.tag=${{ github.sha }} \
--wait \
--timeout 10m
高级功能¶
1. Helm Hooks(数据库迁移)¶
# templates/job-migrate.yaml
apiVersion: batch/v1
kind: Job
metadata:
name: {{ .Release.Name }}-migrate
annotations:
"helm.sh/hook": pre-upgrade
"helm.sh/hook-weight": "-5"
2. ArgoCD / Flux 集成¶
# argocd-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: exitvideo
spec:
source:
repoURL: https://github.com/exitvideo/exitvideo-bot
path: infra/helm
targetRevision: HEAD
3. Horizontal Pod Autoscaler + Cluster Autoscaler¶
# aws cluster autoscaler
apiVersion: v1
kind: ConfigMap
metadata:
name: cluster-autoscaler
data:
min-size: "6"
max-size: "30"
4. Pod Topology Constraints(多 AZ)¶
pod:
topologySpreadConstraints:
- maxSkew: 1
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: ScheduleAnyway
安全建议¶
- 生产环境务必装 External Secrets Operator 或 Sealed Secrets,避免
secrets直接用 Helm Values 明文存储 - Helm hooks 做数据库 migration + 数据备份
- 启用 sigstore / cosign 镜像签名验证
- 用
--render-subchart-notes给运维人员生成部署说明 - 定期
helm diff检查变更
故障排查¶
# 查看 chart 内所有资源
helm get manifest exitvideo -n exitvideo-prod
# 调试模板
helm template exitvideo ./infra/helm/ --debug 2>&1 | head -100
# 检查 values 合并结果
helm get values exitvideo -n exitvideo-prod
# 测试回滚
helm rollback --dry-run exitvideo 1 -n exitvideo-prod