Subsections of Application
N8N
🚀Installation
Preliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link- Database postgresql has been installed, if not check 🔗link
1.prepare `n8n-middleware-credentials.yaml`
Details
kubectl get namespaces n8n > /dev/null 2>&1 || kubectl create namespace n8n
N8N_PASSWORD=$(kubectl -n database get secret postgresql-credentials -o jsonpath='{.data.password}' | base64 -d)
kubectl -n n8n create secret generic n8n-middleware-credential \
--from-literal=postgres-password="${N8N_PASSWORD}"2.prepare `deploy-n8n.yaml`
Details
kubectl -n argocd apply -f - <<EOF
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: n8n
spec:
project: default
source:
repoURL: https://community-charts.github.io/helm-charts
targetRevision: 1.16.36
helm:
releaseName: n8n
values: |
global:
security:
allowInsecureImages: true
image:
repository: n8nio/n8n
log:
level: info
encryptionKey: "ay-dev-n8n"
timezone: Asia/Shanghai
db:
type: postgresdb
externalPostgresql:
host: postgresql-hl.database.svc.cluster.local
port: 5432
username: "n8n"
database: "n8n"
existingSecret: "n8n-middleware-credential"
main:
count: 1
extraEnvVars:
"N8N_BLOCK_ENV_ACCESS_IN_NODE": "false"
"N8N_FILE_SYSTEM_ALLOWED_PATHS": "/home/node/.n8n-files"
"EXECUTIONS_TIMEOUT": "300"
"EXECUTIONS_TIMEOUT_MAX": "600"
"DB_POSTGRESDB_POOL_SIZE": "10"
"CACHE_ENABLED": "true"
"N8N_CONCURRENCY_PRODUCTION_LIMIT": "5"
"NODE_TLS_REJECT_UNAUTHORIZED": "0"
"N8N_SECURE_COOKIE": "false"
"WEBHOOK_URL": "https://webhook.n8n.dev.72602.online"
"QUEUE_BULL_REDIS_TIMEOUT_THRESHOLD": "60000"
"N8N_COMMUNITY_PACKAGES_ENABLED": "true"
"N8N_GIT_NODE_DISABLE_BARE_REPOS": "true"
"N8N_LICENSE_AUTO_RENEW_ENABLED": "true"
"N8N_LICENSE_RENEW_ON_INIT": "true"
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: "local-path"
size: 50Gi
volumes:
- name: downloads-volume
hostPath:
path: /home/aaron/Downloads
type: DirectoryOrCreate
volumeMounts:
- name: downloads-volume
mountPath: /home/node/.n8n-files
resources:
requests:
cpu: 1000m
memory: 1024Mi
limits:
cpu: 2000m
memory: 2048Mi
worker:
mode: queue
count: 2
waitMainNodeReady:
enabled: false
extraEnvVars:
"N8N_FILE_SYSTEM_ALLOWED_PATHS": "/home/node/.n8n-files"
"EXECUTIONS_TIMEOUT": "300"
"EXECUTIONS_TIMEOUT_MAX": "600"
"DB_POSTGRESDB_POOL_SIZE": "5"
"QUEUE_BULL_REDIS_TIMEOUT_THRESHOLD": "60000"
"N8N_COMMUNITY_PACKAGES_ENABLED": "true"
"N8N_GIT_NODE_DISABLE_BARE_REPOS": "true"
"N8N_LICENSE_AUTO_RENEW_ENABLED": "true"
"N8N_LICENSE_RENEW_ON_INIT": "true"
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: "local-path"
size: 50Gi
volumes:
- name: downloads-volume
hostPath:
path: /home/aaron/Downloads
type: DirectoryOrCreate
volumeMounts:
- name: downloads-volume
mountPath: /home/node/.n8n-files
resources:
requests:
cpu: 500m
memory: 1024Mi
limits:
cpu: 1000m
memory: 2048Mi
nodes:
builtin:
enabled: true
modules:
- crypto
- fs
external:
allowAll: true
packages:
- n8n-nodes-globals
npmRegistry:
enabled: true
url: http://mirrors.cloud.tencent.com/npm/
redis:
enabled: true
image:
registry: m.daocloud.io/docker.io
repository: bitnamilegacy/redis
master:
resourcesPreset: "small"
persistence:
enabled: true
accessMode: ReadWriteOnce
storageClass: "local-path"
size: 10Gi
ingress:
enabled: true
className: nginx
annotations:
kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: self-signed-ca-issuer
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
nginx.ingress.kubernetes.io/proxy-body-size: "50m"
nginx.ingress.kubernetes.io/upstream-keepalive-connections: "50"
nginx.ingress.kubernetes.io/upstream-keepalive-timeout: "60"
nginx.ingress.kubernetes.io/enable-cors: "true"
nginx.ingress.kubernetes.io/cors-allow-origin: "https://webhook.n8n.dev.72602.online:32443"
nginx.ingress.kubernetes.io/cors-allow-methods: "GET, POST, OPTIONS, PUT, DELETE"
nginx.ingress.kubernetes.io/cors-allow-headers: "DNT,X-CustomHeader,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Authorization"
nginx.ingress.kubernetes.io/cors-allow-credentials: "true"
hosts:
- host: n8n.dev.72602.online
paths:
- path: /
pathType: Prefix
- host: webhook.n8n.dev.72602.online
paths:
- path: /
pathType: Prefix
tls:
- hosts:
- n8n.dev.72602.online
- webhook.n8n.dev.72602.online
secretName: n8n.dev.72602.online-tls
webhook:
mode: queue
url: "https://webhook.n8n.dev.72602.online"
autoscaling:
enabled: false
waitMainNodeReady:
enabled: true
resources:
requests:
cpu: 200m
memory: 256Mi
limits:
cpu: 512m
memory: 512Mi
chart: n8n
destination:
server: https://kubernetes.default.svc
namespace: n8n
syncPolicy:
syncOptions:
- CreateNamespace=true
- ApplyOutOfSyncOnly=false
EOF3.sync by argocd
Details
argocd app sync argocd/n8nUsing AY ACR Image Mirror
Using DaoCloud Mirror
Preliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link- Database postgresql has been installed, if not check 🔗link
1.verify retained credentials and storage
Details
kubectl get namespace n8n
kubectl -n n8n get secret n8n-middleware-credential n8n-encryption-key-existing
kubectl -n n8n get pvcImportant
The live credentials and PVCs are retained state. Do not delete, recreate, or replace them when updating the Argo CD Application.
2.review and publish the canonical source `manifests/n8n-argocd.yaml`
The n8n Argo CD Application is parent-managed by argocd/ops-docs from the repository’s main branch and manifests path. n8n itself is manually synced after the parent Application has converged. The current chart is 1.24.42 and n8n is 2.40.5.
Details
git diff --check
git diff -- manifests/n8n-argocd.yaml
git status --short
git add manifests/n8n-argocd.yaml
git commit -m "fix(n8n): configure AI model requests"
git push origin main3.wait for parent convergence, then manually sync n8n
Details
argocd app get argocd/ops-docs --insecure --grpc-web
argocd app sync argocd/n8n --insecure --grpc-web
argocd app get argocd/n8n --insecure --grpc-web
kubectl -n n8n rollout status deployment/n8n --timeout=300sVerify parent argocd/ops-docs is synced before manually syncing argocd/n8n. Review the Application diff and confirm the existing credentials and PVCs remain unchanged.
4.verify
Details
argocd app get argocd/n8n --insecure --grpc-web
kubectl -n n8n rollout status deployment/n8n --timeout=300s
kubectl -n n8n get pods
curl -sS -o /dev/null -w '%{http_code}\n' https://n8n.72602.space/healthz
curl -sS -o /dev/null -w '%{http_code}\n' https://n8n.72602.space/healthz/readiness
curl -sS -o /dev/null -w '%{http_code}\n' https://n8n.72602.space/Confirm the Application is Synced and Healthy, the main Pod is Ready without restarts, and the health/readiness endpoints and public editor return HTTP 200.
🛎️FAQ
Wechat Markdown Editor
Official Documentation: https://github.com/doocs/md
🚀Installation
Preliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link1.prepare `deploy-wx-article-editor.yaml`
Details
kubectl -n argocd apply -f - <<'EOF'
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: wx-article-editor
namespace: argocd
spec:
project: default
source:
repoURL: https://bjw-s-labs.github.io/helm-charts
chart: app-template
targetRevision: 4.4.0
helm:
values: |
controllers:
main:
containers:
app:
image:
repository: m.daocloud.io/docker.io/doocs/md
tag: latest
pullPolicy: IfNotPresent
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
enabled: true
service:
app:
controller: main
ports:
http:
port: 80
ingress:
app:
enabled: true
className: nginx
annotations:
kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: self-signed-ca-issuer
hosts:
- host: md.dev.72602.online
paths:
- path: /
pathType: Prefix
service:
identifier: app
port: http
tls:
- secretName: md.dev.72602.online-tls
hosts:
- md.dev.72602.online
destination:
server: https://kubernetes.default.svc
namespace: application
syncPolicy:
syncOptions:
- CreateNamespace=true
- ServerSideApply=true
EOF2.sync by argocd
Details
argocd app sync argocd/wx-article-editorPreliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link1.prepare `deploy-wx-article-editor.yaml`
Details
kubectl -n argocd apply -f - <<'EOF'
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: wx-article-editor
namespace: argocd
spec:
project: default
source:
repoURL: https://bjw-s-labs.github.io/helm-charts
chart: app-template
targetRevision: 4.4.0
helm:
values: |
controllers:
main:
containers:
app:
image:
repository: m.daocloud.io/docker.io/doocs/md
tag: latest
pullPolicy: IfNotPresent
probes:
liveness:
enabled: true
readiness:
enabled: true
startup:
enabled: true
service:
app:
controller: main
ports:
http:
port: 80
ingress:
app:
enabled: true
className: nginx
annotations:
kubernetes.io/ingress.class: nginx
cert-manager.io/cluster-issuer: letsencrypt
hosts:
- host: md.72602.online
paths:
- path: /
pathType: Prefix
service:
identifier: app
port: http
tls:
- secretName: md.72602.online-tls
hosts:
- md.72602.online
destination:
server: https://kubernetes.default.svc
namespace: application
syncPolicy:
syncOptions:
- CreateNamespace=true
- ServerSideApply=true
EOF2.sync by argocd
Details
argocd app sync argocd/wx-article-editor1.run container
Details
docker run -d --name wx-article-editor -p 8080:80 doocs/md:latest2.access in browser
Details
open http://localhost:8080Verify
Details
kubectl -n application get pods
kubectl -n application get ingressIf deployed in ZJ environment, open https://md.dev.72602.online.
If deployed in 72602 environment, open https://md.72602.online.
🛎️FAQ
Charge Spot Quest
Overview
Charge Spot Quest is the 邻里互助·共享充电 UI + booking API. It is deployed via the 72602 ArgoCD GitOps pipeline using Helm chart charge-spot-quest (version 0.1.15) with in-cluster SQLite.
- ArgoCD Application:
argocd/charge-spot-quest(child ofargocd/ops-docs) - Namespace:
charge-spot - Service:
charge-spot-quest(port 8080) - Ingress:
charge.72602.space(TLS via cert-manager) - Database: SQLite PVC
charge-spot-quest-sqlite(1Gi,local-path)
- Install (ArgoCD)
Deploy Charge Spot Quest via 72602 GitOps ArgoCD
Subsections of Charge Spot Quest
Install (ArgoCD)
🚀Installation
Preliminary
1. Kubernetes is installed; if not, check 🔗link 2. Helm is installed; if not, check 🔗link 3. ArgoCD is installed; if not, check 🔗link1.prepare `charge` DNS A record
Details
# zone 72602.space, RR charge, type A, value 47.110.67.161, TTL 600
# create only when the matching enabled record is absent2.prepare `charge-spot-quest-argocd.yaml`
Details
git -C /home/aaron/Ops/docs fetch origin main
git -C /home/aaron/Ops/docs \
show origin/main:manifests/charge-spot-quest-argocd.yaml >/dev/null
argocd app get ops-docs --hard-refresh
argocd app sync ops-docs --revision main
argocd app wait ops-docs --sync --timeout 300
kubectl wait --for=jsonpath='{.status.phase}'=Active \
namespace/charge-spot --timeout=120sThe parent ops-docs Application reads the manifests path and creates the
child Application. The child creates namespace charge-spot through
CreateNamespace=true. SQLite is enabled; bundled and external PostgreSQL
stay off.
3.prepare `charge-spot-dingtalk`
Details
kubectl -n charge-spot create secret generic charge-spot-dingtalk \
--from-literal=webhook_url='https://oapi.dingtalk.com/robot/send?access_token=<replace-me>' \
--from-literal=sec_secret='SEC<replace-me>' \
--from-literal=revoke_secret="$(openssl rand -hex 32)"Create the Secret on the cluster only. GitOps values set dingtalk.enabled,
dingtalk.existingSecret=charge-spot-dingtalk, and
dingtalk.publicBaseUrl=https://charge.72602.space. Do not commit webhook,
SEC, or revoke tokens.
4.sync by argocd
Details
argocd app get charge-spot-quest --hard-refresh
argocd app sync charge-spot-quest
argocd app wait charge-spot-quest --sync --health --timeout 6005.verify
Details
kubectl -n argocd get application charge-spot-quest \
-o jsonpath='{.spec.source.repoURL}{"\n"}{.spec.source.path}{"\n"}{.spec.source.targetRevision}{"\n"}'
kubectl -n charge-spot get deployment charge-spot-quest \
-o jsonpath='{range .spec.template.spec.containers[*]}{.name}{"="}{.image}{"\n"}{end}'
kubectl -n charge-spot rollout status deployment/charge-spot-quest --timeout=600s
kubectl -n charge-spot get pods,svc,ingress,pvc
kubectl -n charge-spot get certificate
kubectl -n charge-spot get pods -l app.kubernetes.io/component=postgresql
kubectl -n charge-spot get secret charge-spot-dingtalk \
-o go-template='{{range $k,$v := .data}}{{$k}}{{"\n"}}{{end}}'
kubectl -n charge-spot get deployment charge-spot-quest \
-o jsonpath='{range .spec.template.spec.containers[0].env[*]}{.name}{"\n"}{end}'
curl -fsS https://charge.72602.space/health
curl -fsS https://charge.72602.space/readyz
curl -fsS -o /dev/null -w '%{content_type}\n' https://charge.72602.space/
curl -fsS https://charge.72602.space/api/spots >/dev/nullExpected release values: chart charge-spot-quest version 0.1.15 and image
ghcr.io/aaronyang0628/charge-spot-quest@sha256:31707edea46707434595c091cf6bdd4da0c6cb652f9831f8feccddda65ada1c2
(upstream did not publish a 0.1.15 GHCR tag; the digest pins the built
content, also available as sha-3efdcf1).
Ingress / returns text/html. PVC charge-spot-quest-sqlite is Bound at 1Gi. TLS certificate
charge.72602.space-tls should be Ready with expiry 2026-12-14T06:20:17Z.
📦Rollback Guidance
If a deployment must be reverted, create a reviewed Git revert for
manifests/charge-spot-quest-argocd.yaml, push it, and sync the parent
application. The SQLite PVC and TLS certificate are not deleted by
rollback.
cd /home/aaron/Ops/docs
git fetch origin main
git revert --no-edit 9a15bea
git push origin main
argocd app sync ops-docs --revision main
argocd app wait ops-docs --sync --health --timeout 300