feat: externalize appsettings to K8s Secret — config persists independently of image rebuilds
Build and Deploy to Production / build-and-deploy (push) Has been cancelled

- Add cms-config.yaml (K8s Secret) for staging and production
- Mount appsettings.{Environment}.json from Secret into /app/
- Update CI/CD pipelines to apply Secret before Deployment
- Remove redundant env vars (Kestrel, FileStorage) — now in config file
This commit is contained in:
masoodafar-web
2026-02-23 21:58:05 +03:30
parent 540a2ce4fc
commit f4e24f7449
5 changed files with 183 additions and 10 deletions
+54
View File
@@ -0,0 +1,54 @@
---
# CMS Application Configuration Secret (Production)
# This Secret stores appsettings.Production.json externally in K8s
# so configuration persists independently of Docker image rebuilds.
#
# To edit config without redeploying:
# kubectl edit secret cms-appsettings
# kubectl rollout restart deployment/cms
#
apiVersion: v1
kind: Secret
metadata:
name: cms-appsettings
namespace: default
labels:
app: cms
environment: production
type: Opaque
stringData:
appsettings.Production.json: |
{
"ZarinPal": {
"MerchantId": "4225d555-5fa9-4df0-9b61-1ce152cbbba8",
"UseSandbox": false
},
"CmsBaseUrl": "https://cms.kbs1.ir",
"FrontOfficeBaseUrl": "https://kbs1.ir",
"ConnectionStrings": {
"DefaultConnection": "Server=mssql-svc;Database=KBS;User Id=sa;Password=YourStrong@Passw0rd;TrustServerCertificate=True;"
},
"SeedWorkers": {
"MagicWalletCycleSeed": {
"Enabled": true
}
},
"FileStorage": {
"UploadPath": "/app/Uploads"
},
"Kestrel": {
"EndpointDefaults": {
"Protocols": "Http2"
}
},
"Seq": {
"ServerUrl": "http://seq-svc:5341",
"ApiKey": "oxpvpUzU1pZxMS4s3Fqq"
},
"Logging": {
"LogLevel": {
"Default": "Warning",
"Microsoft.AspNetCore": "Warning"
}
}
}
+7 -4
View File
@@ -45,13 +45,13 @@ spec:
value: "Production"
- name: ASPNETCORE_URLS
value: "http://+:8080"
- name: Kestrel__EndpointDefaults__Protocols
value: "Http1AndHttp2"
- name: FileStorage__UploadPath
value: "/app/Uploads"
volumeMounts:
- name: cms-uploads
mountPath: /app/Uploads
- name: cms-config
mountPath: /app/appsettings.Production.json
subPath: appsettings.Production.json
readOnly: true
resources:
requests:
memory: "512Mi"
@@ -79,6 +79,9 @@ spec:
- name: cms-uploads
persistentVolumeClaim:
claimName: cms-uploads-pvc
- name: cms-config
secret:
secretName: cms-appsettings
---
# CMS Service (Production)