I really appreciate the kubernetes tutorial <https...
# orm-help
y
I really appreciate the kubernetes tutorial https://www.prisma.io/tutorials/deploy-prisma-to-kubernetes-ct13/. Only thing that troubles me (so far...) as a Kubernetes newbie is how to inject secrets / env vars into teh PRISMA_CONFIG part of the configMap i.e. :
Copy code
apiVersion: v1
kind: ConfigMap
metadata:
  name: prisma-configmap
  namespace: prisma
  labels:
    stage: production
    name: prisma
    app: prisma
data:
  PRISMA_CONFIG: |
    port: 4466
    # uncomment the next line and provide the env var PRISMA_MANAGEMENT_API_SECRET=my-secret to activate cluster security
    # managementApiSecret: my-secret
    databases:
      default:
        connector: mysql
        host: database
        port: 3306
        user: root
        password: prisma
        migrations: true
i.e. if I had a secret or an env var e.g. in .env file describing my db password how do I then inject that into the configMAP?
h
Hi i am also a k8s newbie but as of my understanding of configmaps I guess they are just like env files which contains your secrets and see no point of mapping I maybe totally wrong
BTW totally unrelated but do you know any good resource to learn k8s I am just following the docs for now
y
i follow the docs as well πŸ™‚ My question is more in line with how to represent the PRISMA_CONFIG with k8s secrets e.g. something like
Copy code
PRISMA_CONFIG: |
    port: DB_PORT
      valueFrom:
        secretKeyRef:
          name: onlaw
          key: DB_PORT
...which does not work because PRISMA_CONFIG is a yaml scalar block where this is not supported as far as I understand
h
I guess there are some predefined env that prisma reads when PRISMA_CONFIG is not present
I know the PRISMA_MANAGEMENT_API_SECRET is one
so maybe we can use the env property and read the value from the config map using th valueFrom property. Need to do a bit more research on that
y
I hope you are right. Currently my plan is to inject secrets as environment vars in the deployment and then us ${} notation in the configmap for PRISMA_CONFIG πŸ™‚ If my kids stay a sleep I report back in a few minutes πŸ™‚
nothing is working... I want to use the .env file only to keep it in one place
h
I guess you need to write a bash script or something now
I have seen people doing that
Cc @divyendu I have seen him working with some cloud stuff maybe he can help
y
would be great. I am building a stack with prisma and yoga server. So I would prefer to keep all settings in one place, preferably in the .env file. I manage to creat secrets and/or configmaps from the .env file using
--from-env-file
but I cannot figure out how to use em in the PRISMA_CONFIG yaml scalar block
m
Hee, I used terraform to inject the variables. The container definition looks like this:
Copy code
resource "aws_ecs_task_definition" "prod-prisma" {
  family = "prod-prisma"

  container_definitions = <<DEFINITION
[
  {
    "name": "prisma-prod",
    "cpu": 256,
    "memory": 512,
    "environment": [{
      "name": "PRISMA_CONFIG",
      "value": "managementApiSecret: ${var.prod-PRISMA_MANAGEMENT_API_SECRET}\nport: 4466\ndatabases:\n  default:\n    connector: postgres\n    migrations: true\n    host: ${var.prod-PRISMA_DB_HOST}\n    port: 5432\n    user: ${var.prod-PRISMA_DB_USERNAME}\n    password: ${var.prod-PRISMA_DB_PASSWORD}"
    }],
    "essential": true,
    "image": "<http://registry.hub.docker.com/prismagraphql/prisma:1.16|registry.hub.docker.com/prismagraphql/prisma:1.16>",
    "dockerLabels": {
      "STAGE": "prod"
    },
    "portMappings": [
      {
        "hostPort": 4466,
        "protocol": "tcp",
        "containerPort": 4466
      }
    ],
    "logConfiguration": {
      "logDriver": "awslogs",
      "options": {
        "awslogs-group": "/ecs/prisma-prod",
        "awslogs-region": "us-east-1",
        "awslogs-stream-prefix": "ecs"
      }
    }
  }
]
DEFINITION
}
the indentation in the PRISMA_CONFIG is important, it took me a long time before I had the right ones.
Not sure if this helps your kubernetes config though, but it might give you some hints as the "encoding" of that PRISMA_CONFIG yaml should have
So I think you can represent the PRISMA_CONFIG as a string in your env config, which in turn is read as yaml by the prisma server.
y
@Michiel Westerbeek I am not sure it helps πŸ™‚ I posted a new message just now πŸ™‚
... and then again, what does the var. prefix men in your ${} ? To my understanding it is prisma doing string replacement or what?
m
Hee, it’s terraform doing string replacement. Prisma doesn’t do variables at all, it should have the real values in the env variable. (I’ll read your other message)
y
oh so the reason why string replacement works in e.g. databases -> default->user when using docker-compose is that docker does the string replacement i suppose?
h
Terraform is a separate service from hashicorp I guess. @yolen did you tried exploring some of predefined env varibales
m
I think so yeah, try to not see the PRISMA_CONFIG as the same yaml as your kubernetes config. So in the configmap, see it as a string
y
...which makes it difficult to build the PRISMA_CONFIG env var with injected env vars
m
I don't know kubernetes config, but probably there is a way to append variables in a string?
y
I see it as a string but i need to inject other env vars (or secrets or configmap entries) into the PRISMA_CONFIG env var string excatly as you do using terraform
As far as I understand you cannot do that in standard yaml.
m
In the example you just posted it's still "data: PRISMA_CONFIG: | port: penis managementApiSecret: ${PRISMA_MANAGEMENT_API_SECRET}horse databases:"
not PRISMA_CONFIG: ""
y
... only if k8s supports somethign special like docker does
@Harshit I cloned the prisma repo but i could not find the underlying env vars as you suggested
m
and from my understanding you don't want to put secrets in the configmap.yml right?
h
@yolen I have seen the cli suggesting me to define management secret
y
you are right but at some stages if you store the e.g. prisma_secret in a k8s secret you need to add it to the PRISMA_CONFIG string unless there are other ways as @Harshit suggests
h
Probably if this is adds reading some default from env can help
But still DB would be tough that way
y
exactly
m
mm yeah, for my case I don't store the secrets in a special way, they're just variables that get replaced. If you would want that, that's more difficult I guess
h
But not everyone uses terraform
y
So what "we" need is to replace PRISMA_CONFIG with environment variables such as DB_DEFAULT_CONNECTOR etc
h
I guess that way we can use config maps
y
yes πŸ™‚
m
Yeah, more clear env vars would be better than PRISMA_CONFIG. I saw a discussion about it somewhere on the forum
this one
h
Now only Kelsey Hightower can help us πŸ˜‚πŸ˜‚
This is going too far
m
yaml is probably more "flexible", but it makes things more difficult
y
I still do not understand why it works for me when m,y ports are obviously wrong? Did i unintentionally use names for my env vars that are the same as undocumented ones used by prisma? e.g. I define PRISMA_HOST_PORT
h
πŸ˜‚
Will helm solve this
Cause I use the official Prisma chart which is really good at handling this type of stuff
I guess you should use helm @yolen
y
I actuallytrie to run with helm but I paused it because I could not see any real benefit πŸ™‚ and I was worried about tiller to be installed etc.
... but perhaps I shopuold go back to helm
h
Ya that would be good I guess
You can use the
{{ }}
y
thanks for the link. I looked at thishttps://github.com/akoenig/helm-prisma
h
Ya always look helm chart repo before sending
y
i go helmy then
at least I can use the legacy env vars πŸ™‚ they work for me. I have now spend a hole day not being able to insert env vars into PRISMA_CONFIG. I even downloaded the official helm prisma chart which gave me the same problems 😞 I give up and hard code the stuff into my code or use the legacy env vars
Copy code
val port           = sys.env.getOrElse("PORT", "4466").toInt
      val secret         = sys.env.getOrElse("PRISMA_MANAGEMENT_API_JWT_SECRET", "")
      val legacySecret   = sys.env.getOrElse("CLUSTER_PUBLIC_KEY", "")
      val clusterAddress = sys.env.getOrElse("CLUSTER_ADDRESS", "")
      val rabbitUri      = sys.env.getOrElse("RABBITMQ_URI", "")
      val dbHost         = sys.env.getOrElse("SQL_CLIENT_HOST", sys.error("Env var SQL_CLIENT_HOST required but not found"))
      val dbPort         = sys.env.getOrElse("SQL_CLIENT_PORT", "3306").toInt
      val dbUser         = sys.env.getOrElse("SQL_CLIENT_USER", sys.error("Env var SQL_CLIENT_USER required but not found"))
      val dbPass         = sys.env.getOrElse("SQL_CLIENT_PASSWORD", sys.error("Env var SQL_CLIENT_PASSWORD required but not found"))
      val dbConn         = sys.env.getOrElse("SQL_INTERNAL_CONNECTION_LIMIT", "1")
      val database       = sys.env.getOrElse("SQL_INTERNAL_DATABASE", "graphcool") // Legacy always ran on 'graphcool'
      val mgmtApiEnabled = sys.env.getOrElse("CLUSTER_API_ENABLED", "1") match {