# The Next server. It holds no secrets and never opens a database connection: it renders # and proxies /api to the api Service. apiVersion: apps/v1 kind: Deployment metadata: name: impuestos-web namespace: impuestos labels: { app: impuestos, component: web } spec: replicas: 2 selector: matchLabels: { app: impuestos, component: web } template: metadata: labels: { app: impuestos, component: web } spec: terminationGracePeriodSeconds: 30 containers: - name: web image: ghcr.io/example/impuestos-web:latest ports: - name: http containerPort: 3000 envFrom: - configMapRef: { name: impuestos-web-config } livenessProbe: httpGet: { path: /healthz, port: http } initialDelaySeconds: 5 periodSeconds: 10 readinessProbe: httpGet: { path: /healthz, port: http } initialDelaySeconds: 2 periodSeconds: 5 resources: requests: { cpu: 100m, memory: 256Mi } limits: { memory: 512Mi } volumeMounts: - name: tmp mountPath: /tmp # Next writes its own cache under the app directory at runtime. - name: next-cache mountPath: /app/apps/web/.next/cache securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: { drop: ['ALL'] } volumes: - name: tmp emptyDir: {} - name: next-cache emptyDir: {} --- apiVersion: v1 kind: Service metadata: name: impuestos-web namespace: impuestos spec: type: ClusterIP selector: { app: impuestos, component: web } ports: - name: http port: 3000 targetPort: http