CTP を Kubernetes にデプロイするには、以下で説明するプロセスに従ってください。
このバージョンでは、Kubernetes に複数の CTP サーバーをデプロイすることはサポートされていません。サポートは、Kubernetes クラスターで実行されている CTP の 1 つのインスタンスに限定されます。
前提条件
まず、CTP を実行するための名前空間を作成します。例:
kubectl create namespace parasoft-ctp-namespace
注意: 名前空間名 parasoft-ctp-namespace は、このドキュメント全体のコマンドおよびリソースの例で使用されています。名前空間に別の名前を使用している場合は、parasoft-ctp-namespace をすべて実際の名前空間名に変更してください。
CTP のライセンスが取得されると、たとえ同じ名前空間を再作成した場合でも、名前空間を削除するとマシンロック ライセンスが無効になります。
エクスポート ストレージ用の Persistent Volume と Persistent Volume Claim が必要です。約 10 GB のスペースをプロビジョニングする必要があり (これは必要に応じて増減できます)、ReadWriteOnce アクセス モードを推奨します。この領域は、CTP サーバーに使用されます。
デフォルトの Persistent Volume Claim 'ctp-exports-storage' は、CTP サーバーの yaml 定義を更新することでカスタマイズできます。以下に示すサンプルは、NFS Persistent Volume と Persistent Volume Claim を設定する構成です。例では NFS を使用していますが、これは必須ではありません。 ニーズに合った Persistent Volume タイプを使用してください。
警告: NFS の場合、エクスポートされたディレクトリには、コンテナを実行する Parasoft ユーザーと同じ UID および GID が必要です。たとえば、コマンド chown 1000:1000 <shared_path> を実行します。
# ==== Persistent Volume for Export Storage ====
apiVersion: v1
kind: PersistentVolume
metadata:
name: ctp-exports-storage
namespace: parasoft-ctp-namespace
spec:
capacity:
storage: 10Gi
volumeMode: Filesystem
accessModes:
- ReadWriteOnce
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs
nfs:
path: <path>
server: <ip_address>
---
# ==== PersistentVolumeClaim for CTP exports folder ====
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: ctp-exports-pvc
namespace: parasoft-ctp-namespace
spec:
accessModes:
- ReadWriteOnce
storageClassName: nfs
resources:
requests:
storage: 10Gi
volumeName: "ctp-exports-storage"
yaml ファイルを使用して、Persistent Volume と Persistent Volume Claim を作成します。
kubectl create -f ctp-pv.yaml
次に、CTP データベースを設定する必要があります。特に指定しない場合、CTP は /usr/local/parasoft/ctp/hsqldb ディレクトリにデフォルトの HyperSQL データベースを作成します。または、以下のシークレットを使用して db_config_xml 文字列を変更し、CTP が別のデータベースに接続するように設定することもできます。URL JDBC 文字列が MariaDB、MySQL、Oracle、または PostgreSQL, 用である場合は、CTP デプロイメント/ポッドを正しい JDBC アダプターで構成する必要があることに注意してください。URL JDBC 文字列が HyperSQL 用の場合は、CTP デプロイメント/ポッドの構成に関係なく起動するはずです。
apiVersion: v1
kind: Secret
metadata:
name: ctp-db-config-secret
namespace: parasoft-ctp-namespace
type: Opaque
stringData:
db_config_xml: |
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<db_config>
<connection>
<mode>JDBC_URL</mode>
<url>jdbc:mysql://mysql-service:3306/em</url>
<username>em</username>
<password>Kxj6+gSI/FcC8QJcg6UDyg==</password>
<type>MySQL</type>
</connection>
</db_config>
</configuration>
Persistent Volume と Persistent Volume Claim が必要です。約 50 GB のスペースをプロビジョニングする必要があり (これは必要に応じて増減できます)、ReadWriteOnce アクセス モードを推奨します。
以下の例のデフォルトの Persistent Volume Claim 名は、CTP サーバーの yaml 定義を更新することでカスタマイズできます。例では NFS を使用していますが、これは必須ではありません。 ニーズに合った Persistent Volume タイプを使用してください。外部データベースの場合、Persistent Volume および Persistent Volume Claim のマウントは、データベース自体ではなく、データベース JDBC アダプター用であることに注意してください。
組み込み HyperSQL データベースと外部データベースには、異なる yaml の例が含まれています。環境に適したものを使用してください。
警告: NFS の場合、エクスポートされたディレクトリには、コンテナを実行する Parasoft ユーザーと同じ UID および GID が必要です。たとえば、コマンド chown 1000:1000 <shared_path> を実行します。
HyperSQL (Embedded)
apiVersion: v1
kind: PersistentVolume
metadata:
name: ctp-hsqldb-storage
namespace: parasoft-ctp-namespace
spec:
capacity:
storage: 50Gi
volumeMode: Filesystem
accessModes:
- ReadWriteOnce
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs
nfs:
path: <path>
server: <ip_address>
---
# PersistentVolumeClaim for CTP HyperSQL DB
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: ctp-hsqldb-pvc
namespace: parasoft-ctp-namespace
spec:
accessModes:
- ReadWriteOnce
storageClassName: nfs
resources:
requests:
storage: 50Gi
外部データベース (MariaDB、MySQL、Oracle、またはPostgreSQL)
# ==== Persistent Volume for JDBC Adapter
apiVersion: v1
kind: PersistentVolume
metadata:
name: ctp-jdbcadapter-storage
namespace: parasoft-ctp-namespace
spec:
capacity:
storage: 1Gi
volumeMode: Filesystem
accessModes:
- ReadWriteOnce
persistentVolumeReclaimPolicy: Retain
storageClassName: nfs
nfs:
path: <path>
server: <ip_address>
---
# ==== PersistentVolumeClaim for JDBC Adapter ====
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: ctp-jdbcadapter-pvc
namespace: parasoft-ctp-namespace
spec:
accessModes:
- ReadWriteOnce
storageClassName: nfs
resources:
requests:
storage: 1Gi
volumeName: "ctp-jdbcadapter-storage"
yaml ファイルを使用して、Persistent Volume と Persistent Volume Claim を作成します。
kubectl create -f ctp-hsqldb.yaml
kubectl create -f ctp-jdbc.yaml
CTP の OIDC シークレットを設定できます。このステップはオプションです。
apiVersion: v1
kind: Secret
metadata:
name: ctp-oidc-secret
namespace: parasoft-ctp-namespace
type: Opaque
stringData:
oidc_json: |
{
"enabled": false,
"issuerUri": "your issuer uri",
"clientId": "your client id",
"clientSecret": your client secret",
"scopes": ["openid", "profile", "email"],
"claimMappings": {
"username": "preferred_username",
"firstName": "given_name",
"lastName": "family_name",
"email": "email"
},
"adminUsers": ["your admin user"]
}
次に、次のコマンドでシークレットを作成します。
kubectl create -f ctp-oidc-secret.yaml
また、サービス アカウントと必要な権限を作成する必要があります。
apiVersion: v1 kind: ServiceAccount metadata: name: parasoft-account namespace: parasoft-ctp-namespace automountServiceAccountToken: true --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: parasoft-read namespace: parasoft-ctp-namespace rules: - apiGroups: - "" resources: - "namespaces" - "pods" verbs: - get --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: parasoft-read-bind namespace: parasoft-ctp-namespace roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: parasoft-read subjects: - kind: ServiceAccount name: parasoft-account namespace: parasoft-ctp-namespace
yaml ファイルを使用して、サービス アカウントと必要な権限を作成します。
kubectl create -f parasoft-permissions.yaml
コンソールに以下のような出力が表示されるはずです。
serviceaccount/parasoft-account created role.rbac.authorization.k8s.io/parasoft-read created rolebinding.rbac.authorization.k8s.io/parasoft-read-bind created
CTP のデプロイ
前提条件が満たされたら、Kubernetes に CTP をデプロイできます。前の手順でカスタムの Persistent Volume Claim 名を使用した場合は、適切な volumeMounts:name フィールドと claimName フィールドを更新してカスタム名と一致させてください。使用しているデータベースのセクションのコメントを外します。
-env 指定子で ACCEPT_EULA 値を true に設定して、サーバーの EULA に同意する必要があります。さらに、匿名の使用状況データを Parasoft に送信して製品を改善することをオプトインするには、-env 指定子で USAGE_DATA 値を true に変更します。
注意: kind: Deployment はサポートされません。kind: Pod または kind: StatefulSet のいずれかを使用してください。これらはサポートされています。
apiVersion: v1
kind: Pod
metadata:
name: ctp-pod
namespace: parasoft-ctp-namespace
labels:
app: ctp
spec:
securityContext:
runAsNonRoot: true
serviceAccountName: parasoft-account
automountServiceAccountToken: true
containers:
- name: ctp
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
image: parasoft/ctp:latest
ports:
- name: http
containerPort: 8080
- name: https
containerPort: 8443
# Delete database.properties file to prevent overwriting of db_config.xml on pod startup
command: [ "/bin/bash", "-c" ]
args:
-
cd ctp/webapps/em/WEB-INF/classes/META-INF/spring/ &&
rm database.properties &&
cd /usr/local/parasoft &&
./entrypoint.sh
volumeMounts:
- name: ctp-exports-storage
mountPath: /usr/local/parasoft/exports
# === db_config.xml Secret Volume Mount ===
- name: "ctp-db-config-secret-volume"
mountPath: /usr/local/parasoft/ctp/webapps/em/config/db_config.xml
subPath: db_config.xml
readOnly: true
# - name: ctp-hsqldb-storage
# mountPath: /usr/local/parasoft/ctp/hsqldb
# === DB JDBC Adapter Volume Mount ===
# - name: ctp-jdbcadapter-storage
# mountPath: /usr/local/parasoft/ctp/webapps/em/WEB-INF/lib/<JAR_FILE>
# subPath: <JAR_FILE>
# === OIDC Secret Volume Mount ===
# - name: ctp-oidc-secret-volume
# mountPath: /usr/local/parasoft/ctp/webapps/em/config/oidc.json
# subPath: oidc.json
# readOnly: true
env:
# === USE BELOW TO CONFIGURE ENVIRONMENT VARIABLES ===
# Configures CTP to connect to license server at the specified base URL
- name: LICENSE_SERVER_URL
value: https://licenseserver:8443
# Configures CTP to use basic authentication when connecting to license server
- name: LICENSE_SERVER_AUTH_ENABLED
value: "false"
# Configures CTP to connect to license server as the specified user
# - name: LICENSE_SERVER_USERNAME
# value: admin
# Configures CTP to connect to license server with the specified password
# - name: LICENSE_SERVER_PASSWORD
# value: admin
# Set to true or false to opt-in or opt-out of sending anonymous usage data to Parasoft
- name: USAGE_DATA
value: "false"
# Accepts the End User License Agreement if set to true
- name: ACCEPT_EULA
value: "false"
- name: CATALINA_OPTS
value: "-Dparasoft.cloudvm=true
-Dparasoft.cloudvm.config=Kubernetes"
- name: PARASOFT_POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: PARASOFT_POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
# === PROBES ===
startupProbe:
httpGet:
path: /em/resources/favicon.ico
port: 8080
initialDelaySeconds: 30
periodSeconds: 30
timeoutSeconds: 30
failureThreshold: 3
livenessProbe:
httpGet:
path: /em/resources/favicon.ico
port: 8080
initialDelaySeconds: 30
periodSeconds: 30
timeoutSeconds: 30
readinessProbe:
httpGet:
path: /em/healthcheck
port: 8080
initialDelaySeconds: 30
periodSeconds: 30
timeoutSeconds: 30
volumes:
- name: ctp-exports-storage
persistentVolumeClaim:
claimName: ctp-exports-pvc
# === db_config.xml Secret Volume ===
- name: "ctp-db-config-secret-volume"
secret:
secretName: "ctp-db-config-secret"
optional: true
items:
- key: db_config_xml
path: db_config.xml
# - name: ctp-hsqldb-storage
# persistentVolumeClaim:
# claimName: ctp-hsqldb-pvc
# === SQL JDBC Adapter Volume ===
# - name: ctp-jdbcadapter-storage
# persistentVolumeClaim:
# claimName: ctp-jdbcadapter-pvc
# === OIDC Secret Volume ===
# - name: ctp-oidc-secret-volume
# secret:
# secretName: ctp-oidc-secret
# optional: true
# items:
# - key: oidc_json
# path: oidc.json
yaml ファイルを使用して、Kubernetes で CTP にアクセスするために使用できるサービスを作成します。
kubectl create -f ctp-pod.yaml
Kubernetes で CTP サーバーにアクセスするために使用できるサービスを作成します。以下に示す例では、ノード ポートを使用してこれを公開し、アプリケーションがアクセスするための安定したエンドポイントを提供します。
apiVersion: v1
kind: Service
metadata:
name: ctp-service
namespace: parasoft-ctp-namespace
spec:
selector:
app: ctp
type: NodePort
ports:
- name: http
protocol: TCP
port: 8080
targetPort: 8080
nodePort: 30000
- name: https
protocol: TCP
port: 8443
targetPort: 8443
nodePort: 30083
ボリューム マウントのセキュリティ ポリシー (オプション)
セキュリティ ポリシーで、アプリケーションがマウントされたボリュームにのみ書き込みを行うように指定されている場合は、以下の場所をマウントする必要があります。
/usr/local/parasoft/exports /usr/local/parasoft/ctp/hsqldb /usr/local/parasoft/ctp/logs /usr/local/parasoft/ctp/temp /usr/local/parasoft/ctp/webapps/em/apifiles /usr/local/parasoft/ctp/webapps/em/backups /usr/local/parasoft/ctp/webapps/em/license /usr/local/parasoft/ctp/work/Catalina/localhost/em