add k8s support and upload image to ghcr.io

This commit is contained in:
2026-07-16 19:06:33 +03:00
parent 36a1cdee1d
commit 4020fedf9a
7 changed files with 293 additions and 7 deletions
+96 -1
View File
@@ -42,10 +42,105 @@ cp .env.example .env
Fill `.env` and run:
```bash
export $(grep -v '^#' .env | xargs)
set -a
source .env
set +a
python bot.py
```
## Container image
The image contains only the application and Python dependencies. Runtime secrets
and the SQLite database are deliberately excluded.
Build and verify it locally:
```bash
docker build --pull -t tt-simple:dev .
docker run --rm --entrypoint sh tt-simple:dev -c \
'test ! -e /app/.env && test ! -e /app/stats.db && test -e /app/bot.py'
```
Run it with environment variables and persistent SQLite storage:
```bash
docker volume create tt-simple-data
docker run --rm \
--env-file .env \
--env DB_PATH=/data/stats.db \
--volume tt-simple-data:/data \
tt-simple:dev
```
### Publishing to GHCR
`.github/workflows/container.yml` publishes a multi-architecture image to:
```text
ghcr.io/kr0sh512/tt-simple
```
A push to `main` publishes `latest` and `sha-<commit>` tags. A Git tag such as
`v0.1.0` publishes the matching version tag:
```bash
git tag v0.1.0
git push origin main v0.1.0
```
### K3s deployment
Create the namespace first:
```bash
kubectl apply -f k8s/namespace.yaml
```
Create or update the application Secret from the local `.env` file. The Secret
is never stored in Git:
```bash
kubectl -n tt-simple create secret generic tt-simple-env \
--from-env-file=.env \
--dry-run=client -o yaml | kubectl apply -f -
```
For a private GHCR package, create a classic GitHub token with `read:packages`
and create the registry pull secret:
```bash
read -rsp "GHCR token: " GHCR_TOKEN
echo
kubectl -n tt-simple create secret docker-registry ghcr-creds \
--docker-server=ghcr.io \
--docker-username=kr0sh512 \
--docker-password="$GHCR_TOKEN" \
--dry-run=client -o yaml | kubectl apply -f -
unset GHCR_TOKEN
```
If the package is public, remove `imagePullSecrets` from
`k8s/tt-simple.yaml`. Deploy the PVC and bot after publishing the `v0.1.0`
image:
```bash
kubectl apply -f k8s/tt-simple.yaml
kubectl -n tt-simple rollout status deployment/tt-simple
kubectl -n tt-simple logs -f deployment/tt-simple
```
The manifest injects the Secret, mounts persistent storage at `/data`, and sets
`DB_PATH=/data/stats.db`. To use the shared non-Russian proxy, add this to the
local `.env` before updating `tt-simple-env`:
```dotenv
HTTP_PROXY=http://shared-http-proxy.proxy.svc.cluster.local:3128
```
The included namespace and pod labels satisfy the proxy `NetworkPolicy`.
## Notes
- Telegram Stars invoices use `currency="XTR"` and empty `provider_token`.
- Local SQLite database stores only payment statistics. User state is read from Marzban API.