Compare commits

..

10 Commits

14 changed files with 352 additions and 119 deletions
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-7d2d
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-7d2d-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-7d2d.khalisio.com`)
kind: Rule
services:
- name: wings-7d2d-api
port: 8081
@@ -4,11 +4,10 @@ metadata:
name: wings-ark-sa name: wings-ark-sa
namespace: game-servers namespace: game-servers
labels: labels:
app.kubernetes.io/name: wings app: wings-ark-sa
app.kubernetes.io/component: game-server
app.kubernetes.io/part-of: pelican
game: ark-sa game: ark-sa
spec: spec:
replicas: 1
strategy: strategy:
type: Recreate type: Recreate
selector: selector:
@@ -22,98 +21,101 @@ spec:
spec: spec:
nodeSelector: nodeSelector:
kubernetes.io/arch: amd64 kubernetes.io/arch: amd64
serviceAccountName: wings-ark-sa affinity:
podAntiAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
- labelSelector:
matchExpressions:
- key: game
operator: In
values: [ark-sa]
topologyKey: "kubernetes.io/hostname"
volumes:
- name: wings-config
secret:
secretName: wings-ark-sa-config
- name: game-data
persistentVolumeClaim:
claimName: wings-ark-sa-data
- name: docker-socket
emptyDir: {}
- name: autostart-token
secret:
secretName: pelican-autostart-key
containers: containers:
- name: wings - name: dind
image: ghcr.io/pelican-dev/wings:latest image: docker:dind
env: args:
- name: DOCKER_HOST - "--storage-driver=vfs"
value: tcp://localhost:2375 - "--iptables=false"
- name: WINGS_UID securityContext:
value: "1000" privileged: true
- name: WINGS_GID
value: "1000"
- name: WINGS_PORT
value: "8081"
- name: WINGS_API_SFTP_PORT
value: "2023"
- name: WINGS_SERVER_UUID
value: "3fd0b08d-7393-4d0f-b11c-bad5e1d1f771"
envFrom:
- secretRef:
name: wings-ark-sa-config
volumeMounts: volumeMounts:
- name: docker-socket - name: docker-socket
mountPath: /var/run/docker.sock mountPath: /var/run/docker.sock
- name: wings-data
mountPath: /var/lib/wings
- name: server-data
mountPath: /mnt/server
readinessProbe:
httpGet:
path: /ready
port: 8081
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 8081
initialDelaySeconds: 15
periodSeconds: 30
- name: dind
image: docker:24-dind
securityContext:
privileged: true
env: env:
- name: DOCKER_TLS_CERTDIR - name: DOCKER_TLS_CERTDIR
value: "" value: ""
volumeMounts: resources:
- name: docker-socket requests:
mountPath: /var/run cpu: "500m"
- name: dind-storage memory: "512Mi"
mountPath: /var/lib/docker limits:
readinessProbe: cpu: "1"
exec: memory: "1Gi"
command: - name: wings
- sh image: ghcr.io/pelican-dev/wings:latest
- -c command:
- '[ -S /var/run/docker.sock ]' - /bin/sh
initialDelaySeconds: 5 - -c
periodSeconds: 5 - |
- name: game-autostart export DOCKER_HOST=tcp://localhost:2375
image: curlimages/curl:latest exec wings
env: envFrom:
- name: PELICAN_API_KEY - secretRef:
valueFrom: name: wings-ark-sa-config
secretKeyRef: env:
name: pelican-autostart-key - name: DOCKER_HOST
key: api_key value: tcp://localhost:2375
- name: SERVER_UUID - name: WATCHDOG_ENABLED
value: "3fd0b08d-7393-4d0f-b11c-bad5e1d1f771" value: "true"
volumeMounts:
- name: wings-config
mountPath: /etc/pterodactyl
readOnly: true
- name: game-data
mountPath: /mnt/server
- name: docker-socket
mountPath: /var/run/docker.sock
resources:
requests:
cpu: "2"
memory: "4Gi"
limits:
cpu: "4"
memory: "8Gi"
- name: game-autostart
image: curlimages/curl:latest
command: command:
- /bin/sh - /bin/sh
- -c - -c
- | - |
echo "Waiting for Wings API to be ready..."
while ! curl -sf http://localhost:8081/ready; do
sleep 2
done
echo "Wings ready. Starting game server..."
while true; do while true; do
sleep 60 sleep 60
echo "Checking game server status..." curl -sf -X POST "https://pelican.khalisio.com/api/client/servers/3fd0b08d-7393-4d0f-b11c-bad5e1d1f771/power" \
-H "Authorization: Bearer $(cat /etc/secrets/autostart/api_key)" \
-H "Content-Type: application/json" \
-d '{"signal":"start"}' > /dev/null 2>&1 || true
done done
volumeMounts: volumeMounts:
- name: server-data - name: autostart-token
mountPath: /mnt/server mountPath: /etc/secrets/autostart
volumes: readOnly: true
- name: docker-socket resources:
emptyDir: {} requests:
- name: dind-storage cpu: "50m"
emptyDir: {} memory: "64Mi"
- name: wings-data limits:
emptyDir: {} cpu: "100m"
- name: server-data memory: "128Mi"
persistentVolumeClaim: restartPolicy: Always
claimName: wings-ark-sa-data
@@ -6,17 +6,21 @@ metadata:
spec: spec:
refreshInterval: 1h refreshInterval: 1h
secretStoreRef: secretStoreRef:
name: vault-secret-store name: vault
kind: ClusterSecretStore kind: ClusterSecretStore
target: target:
name: wings-ark-sa-config name: wings-ark-sa-config
creationPolicy: Owner creationPolicy: Owner
data: data:
- secretKey: config - secretKey: WINGS_UUID
remoteRef: remoteRef:
key: Talos Cluster/wings/ark-sa key: wings/ark-sa
property: config property: uuid
- secretKey: api_key - secretKey: WINGS_TOKEN
remoteRef: remoteRef:
key: Talos Cluster/wings/ark-sa key: wings/ark-sa
property: api_key property: token
- secretKey: LOCALE
remoteRef:
key: wings/ark-sa
property: locale
@@ -1,7 +1,7 @@
apiVersion: traefik.containo.us/v1alpha1 apiVersion: traefik.io/v1alpha1
kind: IngressRoute kind: IngressRoute
metadata: metadata:
name: wings-ark-sa-api name: wings-ark-sa
namespace: game-servers namespace: game-servers
spec: spec:
entryPoints: entryPoints:
@@ -1,7 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: game-servers
labels:
app.kubernetes.io/name: game-servers
app.kubernetes.io/managed-by: orion
@@ -4,8 +4,7 @@ metadata:
name: wings-ark-sa-api name: wings-ark-sa-api
namespace: game-servers namespace: game-servers
spec: spec:
selector: type: ClusterIP
app: wings-ark-sa
ports: ports:
- name: api - name: api
port: 8081 port: 8081
@@ -15,3 +14,5 @@ spec:
port: 2023 port: 2023
targetPort: 2023 targetPort: 2023
protocol: TCP protocol: TCP
selector:
app: wings-ark-sa
@@ -4,26 +4,22 @@ metadata:
name: wings-ark-sa-game name: wings-ark-sa-game
namespace: game-servers namespace: game-servers
annotations: annotations:
metallb.universe.tf/address-pool: default metallb.universe.tf/address-pool: default-lb-pool
spec: spec:
type: LoadBalancer type: LoadBalancer
loadBalancerIP: 10.4.4.200 loadBalancerIP: 10.4.4.200
ports:
- name: ark-game
port: 7777
protocol: UDP
targetPort: 7777
- name: ark-query
port: 27015
protocol: UDP
targetPort: 27015
- name: ark-tcp
port: 27016
protocol: TCP
targetPort: 27016
selector: selector:
app: wings-ark-sa app: wings-ark-sa
ports:
- name: game-udp-1
port: 7777
targetPort: 7777
protocol: UDP
- name: game-udp-2
port: 7778
targetPort: 7778
protocol: UDP
- name: game-tcp
port: 27015
targetPort: 27015
protocol: TCP
- name: game-tcp-2
port: 27016
targetPort: 27016
protocol: TCP
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-enshrouded
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-enshrouded-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-enshrouded.khalisio.com`)
kind: Rule
services:
- name: wings-enshrouded-api
port: 8081
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-moria
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-moria-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-moria.khalisio.com`)
kind: Rule
services:
- name: wings-moria-api
port: 8081
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-palworld
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-palworld-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-palworld.khalisio.com`)
kind: Rule
services:
- name: wings-palworld-api
port: 8081
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-satisfactory
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-satisfactory-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-satisfactory.khalisio.com`)
kind: Rule
services:
- name: wings-satisfactory-api
port: 8081
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-sotf
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-sotf-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-sotf.khalisio.com`)
kind: Rule
services:
- name: wings-sotf-api
port: 8081
@@ -0,0 +1,118 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: wings-valheim
namespace: game-servers
labels:
app.kubernetes.io/name: wings
app.kubernetes.io/component: game-server
app.kubernetes.io/part-of: pelican
game: valheim
spec:
strategy:
type: Recreate
selector:
matchLabels:
app: wings-valheim
template:
metadata:
labels:
app: wings-valheim
game: valheim
spec:
nodeSelector:
kubernetes.io/arch: amd64
containers:
- name: wings
image: ghcr.io/pelican-dev/wings:latest
env:
- name: DOCKER_HOST
value: tcp://localhost:2375
- name: WINGS_UID
value: "1000"
- name: WINGS_GID
value: "1000"
- name: WINGS_PORT
value: "8081"
- name: WINGS_API_SFTP_PORT
value: "2023"
- name: WINGS_SERVER_UUID
value: "9d09e83d-00c3-4404-07c0522a6c25"
envFrom:
- secretRef:
name: wings-valheim-config
volumeMounts:
- name: docker-socket
mountPath: /var/run/docker.sock
- name: wings-data
mountPath: /var/lib/wings
- name: server-data
mountPath: /mnt/server
readinessProbe:
httpGet:
path: /ready
port: 8081
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 8081
initialDelaySeconds: 15
periodSeconds: 30
- name: dind
image: docker:24-dind
securityContext:
privileged: true
env:
- name: DOCKER_TLS_CERTDIR
value: ""
volumeMounts:
- name: docker-socket
mountPath: /var/run
- name: dind-storage
mountPath: /var/lib/docker
readinessProbe:
exec:
command:
- sh
- -c
- '[ -S /var/run/docker.sock ]'
initialDelaySeconds: 5
periodSeconds: 5
- name: game-autostart
image: curlimages/curl:latest
env:
- name: PELICAN_API_KEY
valueFrom:
secretKeyRef:
name: pelican-autostart-key
key: api_key
- name: SERVER_UUID
value: "9d09e83d-00c3-4404-07c0522a6c25"
command:
- /bin/sh
- -c
- |
echo "Waiting for Wings API to be ready..."
while ! curl -sf http://localhost:8081/ready; do
sleep 2
done
echo "Wings ready. Starting game server..."
while true; do
sleep 60
echo "Checking game server status..."
done
volumeMounts:
- name: server-data
mountPath: /mnt/server
volumes:
- name: docker-socket
emptyDir: {}
- name: dind-storage
emptyDir: {}
- name: wings-data
emptyDir: {}
- name: server-data
persistentVolumeClaim:
claimName: wings-valheim-data
@@ -0,0 +1,17 @@
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: wings-valheim
namespace: game-servers
spec:
entryPoints:
- websecure
tls:
secretName: wings-valheim-tls
certResolver: letsencrypt
routes:
- match: Host(`wings-valheim.khalisio.com`)
kind: Rule
services:
- name: wings-valheim-api
port: 8081