跳转至

ExitVideo-Bot Helm Chart

Production-grade Helm v3 chart 替换 infra/k8s/ 静态 manifests。

优势

  • ✅ 参数化(--set)
  • ✅ 多环境支持(dev / staging / prod)
  • ✅ 一键升级 / 回滚
  • ✅ values 集中管理
  • ✅ Helm hooks(pre-install 等)

目录结构

helm/
├── Chart.yaml                 # Chart 元数据
├── values.yaml                # 默认配置
├── README.md                  # 本文件
└── templates/
    ├── _helpers.tpl           # Template 辅助函数
    ├── configmap-secret.yaml  # 配置
    ├── deployment-api.yaml    # API
    ├── deployment-worker-beat-webhook.yaml  # Worker / Beat / Webhook
    ├── service-ingress-pdb-hpa.yaml         # Service / Ingress / HPA / PDB
    └── servicemonitor-prometheusrule-network.yaml  # 监控 / 网络策略

安装

# 1. 添加 helm 仓库(如需要)
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo update

# 2. Lint 测试
helm lint ./infra/helm/

# 3. 试运行(dry-run + debug)
helm install exitvideo ./infra/helm/ \
  --namespace exitvideo-prod \
  --create-namespace \
  --dry-run --debug

# 4. 真实安装
helm install exitvideo ./infra/helm/ \
  --namespace exitvideo-prod \
  --create-namespace \
  --values values-prod.yaml

# 5. 升级
helm upgrade exitvideo ./infra/helm/ \
  -n exitvideo-prod \
  --values values-prod.yaml \
  --set api.replicaCount=10

# 6. 回滚
helm history exitvideo -n exitvideo-prod
helm rollback exitvideo 1 -n exitvideo-prod

# 7. 卸载
helm uninstall exitvideo -n exitvideo-prod

多环境 values 示例

values-prod.yaml

api:
  replicaCount: 3
  minReplicas: 3
  maxReplicas: 30
worker:
  replicaCount: 5

config:
  logLevel: "INFO"
  environment: "production"

secrets:
  jwtSecret: "<production-secret-64-chars>"
  stripeSecretKey: "sk_live_..."
  # ... 全量秘钥
  databaseUrl: "postgresql://app:xxx@prod-db.region.rds.amazonaws.com:5432/saas"
  redisUrl: "redis://prod-redis.region.cache.amazonaws.com:6379/0"

values-staging.yaml

api:
  replicaCount: 1
  worker:
    replicaCount: 2
config:
  logLevel: "DEBUG"
  environment: "staging"
  enableDailyBenchmark: "false"
secrets:
  stripeSecretKey: "sk_test_..."
  databaseUrl: "postgresql://app:xxx@staging-db:5432/saas"

values-dev.yaml

api:
  replicaCount: 1
worker:
  replicaCount: 1
config:
  logLevel: "DEBUG"
postgresql:
  enabled: true   # 内嵌 dev PG
redis:
  enabled: true   # 内嵌 dev Redis

验证清单

[ ] helm template exitvideo ./infra/helm/ > rendered.yaml
[ ] helm install --dry-run ...
[ ] kubectl -n exitvideo-prod get all
[ ] kubectl -n exitvideo-prod get ingress
[ ] kubectl -n exitvideo-prod get hpa
[ ] kubectl -n exitvideo-prod get prometheusrules
[ ] curl https://api.exitvideo.com/health

迁移自静态 manifests

如果已经从 infra/k8s/ 用 kubectl apply -f 部署过:

# 1. 导出当前 namespace 资源
kubectl get all -n exitvideo-prod -o yaml > current.yaml

# 2. helm install 之前先删除旧资源
kubectl delete deployment,service,configmap,secret -n exitvideo-prod -l app.kubernetes.io/part-of=exitvideo

# 3. 用 helm 接管
helm install exitvideo ./infra/helm/ -n exitvideo-prod

CI/CD 推荐集成

# .github/workflows/deploy.yml
- name: Helm Deploy
  run: |
    helm upgrade exitvideo ./infra/helm/ \
      --install \
      --namespace exitvideo-$ENV \
      --create-namespace \
      --values values-$ENV.yaml \
      --set image.tag=${{ github.sha }} \
      --wait \
      --timeout 10m

高级功能

1. Helm Hooks(数据库迁移)

# templates/job-migrate.yaml
apiVersion: batch/v1
kind: Job
metadata:
  name: {{ .Release.Name }}-migrate
  annotations:
    "helm.sh/hook": pre-upgrade
    "helm.sh/hook-weight": "-5"

2. ArgoCD / Flux 集成

# argocd-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: exitvideo
spec:
  source:
    repoURL: https://github.com/exitvideo/exitvideo-bot
    path: infra/helm
    targetRevision: HEAD

3. Horizontal Pod Autoscaler + Cluster Autoscaler

# aws cluster autoscaler
apiVersion: v1
kind: ConfigMap
metadata:
  name: cluster-autoscaler
data:
  min-size: "6"
  max-size: "30"

4. Pod Topology Constraints(多 AZ)

pod:
  topologySpreadConstraints:
    - maxSkew: 1
      topologyKey: topology.kubernetes.io/zone
      whenUnsatisfiable: ScheduleAnyway

安全建议

  1. 生产环境务必装 External Secrets Operator 或 Sealed Secrets,避免 secrets 直接用 Helm Values 明文存储
  2. Helm hooks 做数据库 migration + 数据备份
  3. 启用 sigstore / cosign 镜像签名验证
  4. 用 --render-subchart-notes 给运维人员生成部署说明
  5. 定期 helm diff 检查变更

故障排查

# 查看 chart 内所有资源
helm get manifest exitvideo -n exitvideo-prod

# 调试模板
helm template exitvideo ./infra/helm/ --debug 2>&1 | head -100

# 检查 values 合并结果
helm get values exitvideo -n exitvideo-prod

# 测试回滚
helm rollback --dry-run exitvideo 1 -n exitvideo-prod