feat(deployment)!: move security contexts into the deployment dict
`podSecurityContext` and `containerSecurityContext` are both Deployment-scoped: the former is rendered into `spec.template.spec.securityContext`, the latter into the securityContext of the Gitea container and the chart-managed init containers. Keeping them at the top level hid that pod/container distinction behind a naming convention and separated them from the other pod- and container-scoped settings that already live under `deployment` and `deployment.gitea`. `podSecurityContext` therefore becomes `deployment.securityContext` and `containerSecurityContext` becomes `deployment.gitea.securityContext`, which makes the scope obvious from the values path alone and continues the consolidation started with `deployment.gitea.env`, `deployment.gitea.resources` and `deployment.gitea.image`. The template helpers keep their argument-based signatures, because `gitea.containerSecurityContext` is also used by the Helm test pod and is not bound to a single values path. Both removed keys are covered by the deprecation check so that a silently dropped security context cannot lead to containers unexpectedly running as root or without the configured capability set. BREAKING CHANGE: `podSecurityContext` and `containerSecurityContext` no longer exist. Use `deployment.securityContext` and `deployment.gitea.securityContext` instead. Installations that still set the old keys will fail to render unless `checkDeprecation` is set to `false`. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -1014,11 +1014,13 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
|||||||
| `deployment.gitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
| `deployment.gitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||||
| `deployment.gitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.gitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
| `deployment.gitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.gitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||||
| `deployment.gitea.resources` | Compute Resources required by Gitea container. Cannot be updated. | `nil` |
|
| `deployment.gitea.resources` | Compute Resources required by Gitea container. Cannot be updated. | `nil` |
|
||||||
|
| `deployment.gitea.securityContext` | Security context of the Gitea container and the chart-managed init containers. | `{}` |
|
||||||
| `deployment.nodeSelector` | NodeSelector for the deployment | `{}` |
|
| `deployment.nodeSelector` | NodeSelector for the deployment | `{}` |
|
||||||
| `deployment.priorityClassName` | priorityClassName for the deployment | `""` |
|
| `deployment.priorityClassName` | priorityClassName for the deployment | `""` |
|
||||||
| `deployment.replicas` | Number of replicas for the Gitea deployment. | `1` |
|
| `deployment.replicas` | Number of replicas for the Gitea deployment. | `1` |
|
||||||
| `deployment.resources` | Resources is the total amount of CPU and Memory resources required by all containers in the pod. | `{}` |
|
| `deployment.resources` | Resources is the total amount of CPU and Memory resources required by all containers in the pod. | `{}` |
|
||||||
| `deployment.schedulerName` | Use an alternate scheduler, e.g. "stork" | `""` |
|
| `deployment.schedulerName` | Use an alternate scheduler, e.g. "stork" | `""` |
|
||||||
|
| `deployment.securityContext` | Pod security context. On non-OpenShift clusters the chart defaults `fsGroup` to `1000` when this map is empty. | `{}` |
|
||||||
| `deployment.strategy.type` | Deployment strategy used to replace old pods, either `RollingUpdate` or `Recreate`. | `RollingUpdate` |
|
| `deployment.strategy.type` | Deployment strategy used to replace old pods, either `RollingUpdate` or `Recreate`. | `RollingUpdate` |
|
||||||
| `deployment.strategy.rollingUpdate.maxSurge` | Number or percentage of pods that may be created above the desired replica count. Only used with `RollingUpdate`. | `100%` |
|
| `deployment.strategy.rollingUpdate.maxSurge` | Number or percentage of pods that may be created above the desired replica count. Only used with `RollingUpdate`. | `100%` |
|
||||||
| `deployment.strategy.rollingUpdate.maxUnavailable` | Number or percentage of pods that may be unavailable during the update. Only used with `RollingUpdate`. | `0` |
|
| `deployment.strategy.rollingUpdate.maxUnavailable` | Number or percentage of pods that may be unavailable during the update. Only used with `RollingUpdate`. | `0` |
|
||||||
@@ -1083,14 +1085,12 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
|||||||
|
|
||||||
### Security
|
### Security
|
||||||
|
|
||||||
| Name | Description | Value |
|
| Name | Description | Value |
|
||||||
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ----- |
|
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ----- |
|
||||||
| `openshift.enabled` | Enable OpenShift compatibility defaults for chart-managed pods. Defaults to auto-detect based on the SecurityContextConstraints API. | `nil` |
|
| `openshift.enabled` | Enable OpenShift compatibility defaults for chart-managed pods. Defaults to auto-detect based on the SecurityContextConstraints API. | `nil` |
|
||||||
| `openshift.hostUsers` | Override the PodSpec hostUsers field for chart-managed pods. When unset, the field is omitted so the platform default is used. | `nil` |
|
| `openshift.hostUsers` | Override the PodSpec hostUsers field for chart-managed pods. When unset, the field is omitted so the platform default is used. | `nil` |
|
||||||
| `podSecurityContext` | Pod security context. On non-OpenShift clusters the chart defaults `fsGroup` to `1000` when this map is empty. | `{}` |
|
| `securityContext` | Run init and Gitea containers as a specific securityContext | `{}` |
|
||||||
| `containerSecurityContext` | Security context | `{}` |
|
| `podDisruptionBudget` | Pod disruption budget | `{}` |
|
||||||
| `securityContext` | Run init and Gitea containers as a specific securityContext | `{}` |
|
|
||||||
| `podDisruptionBudget` | Pod disruption budget | `{}` |
|
|
||||||
|
|
||||||
### Route
|
### Route
|
||||||
|
|
||||||
|
|||||||
@@ -104,13 +104,13 @@ Return the pod's hostUsers setting when OpenShift compatibility is enabled.
|
|||||||
{{/*
|
{{/*
|
||||||
Render pod securityContext. On non-OpenShift clusters an empty map defaults fsGroup to 1000.
|
Render pod securityContext. On non-OpenShift clusters an empty map defaults fsGroup to 1000.
|
||||||
*/}}
|
*/}}
|
||||||
{{- define "gitea.podSecurityContext" -}}
|
{{- define "gitea.deployment.securityContext" -}}
|
||||||
{{- $podSecurityContext := deepCopy .Values.podSecurityContext -}}
|
{{- $securityContext := deepCopy .Values.deployment.securityContext -}}
|
||||||
{{- if and (ne (include "gitea.openshift.enabled" . | trim) "true") (not (hasKey $podSecurityContext "fsGroup")) -}}
|
{{- if and (ne (include "gitea.openshift.enabled" . | trim) "true") (not (hasKey $securityContext "fsGroup")) -}}
|
||||||
{{- $_ := set $podSecurityContext "fsGroup" 1000 -}}
|
{{- $_ := set $securityContext "fsGroup" 1000 -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
{{- if gt (len $podSecurityContext) 0 -}}
|
{{- if gt (len $securityContext) 0 -}}
|
||||||
{{ toYaml $podSecurityContext }}
|
{{ toYaml $securityContext }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
@@ -150,7 +150,7 @@ These default to runAsUser 1000 outside OpenShift to preserve existing behavior.
|
|||||||
Render the runtime container securityContext while honoring the deprecated securityContext value.
|
Render the runtime container securityContext while honoring the deprecated securityContext value.
|
||||||
*/}}
|
*/}}
|
||||||
{{- define "gitea.runtimeContainerSecurityContext" -}}
|
{{- define "gitea.runtimeContainerSecurityContext" -}}
|
||||||
{{- $containerSecurityContext := deepCopy .Values.containerSecurityContext -}}
|
{{- $containerSecurityContext := deepCopy .Values.deployment.gitea.securityContext -}}
|
||||||
{{- if and (eq (len $containerSecurityContext) 0) .Values.securityContext -}}
|
{{- if and (eq (len $containerSecurityContext) 0) .Values.securityContext -}}
|
||||||
{{- $containerSecurityContext = deepCopy .Values.securityContext -}}
|
{{- $containerSecurityContext = deepCopy .Values.securityContext -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|||||||
@@ -62,9 +62,9 @@ spec:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
spec:
|
spec:
|
||||||
{{- $hostUsers := include "gitea.hostUsers" . | trim }}
|
{{- $hostUsers := include "gitea.hostUsers" . | trim }}
|
||||||
{{- $podSecurityContext := include "gitea.podSecurityContext" . | trim }}
|
{{- $securityContext := include "gitea.deployment.securityContext" . | trim }}
|
||||||
{{- $containerSecurityContext := include "gitea.containerSecurityContext" (list . (deepCopy .Values.containerSecurityContext)) | trim }}
|
{{- $containerSecurityContext := include "gitea.containerSecurityContext" (list . (deepCopy .Values.deployment.gitea.securityContext)) | trim }}
|
||||||
{{- $commandInitContainerSecurityContext := include "gitea.commandInitContainerSecurityContext" (list . (deepCopy .Values.containerSecurityContext)) | trim }}
|
{{- $commandInitContainerSecurityContext := include "gitea.commandInitContainerSecurityContext" (list . (deepCopy .Values.deployment.gitea.securityContext)) | trim }}
|
||||||
{{- $runtimeContainerSecurityContext := include "gitea.runtimeContainerSecurityContext" . | trim }}
|
{{- $runtimeContainerSecurityContext := include "gitea.runtimeContainerSecurityContext" . | trim }}
|
||||||
{{- if .Values.deployment.schedulerName }}
|
{{- if .Values.deployment.schedulerName }}
|
||||||
schedulerName: "{{ .Values.deployment.schedulerName }}"
|
schedulerName: "{{ .Values.deployment.schedulerName }}"
|
||||||
@@ -79,9 +79,9 @@ spec:
|
|||||||
hostUsers: {{ $hostUsers }}
|
hostUsers: {{ $hostUsers }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- include "gitea.images.pullSecrets" . | nindent 6 }}
|
{{- include "gitea.images.pullSecrets" . | nindent 6 }}
|
||||||
{{- if $podSecurityContext }}
|
{{- if $securityContext }}
|
||||||
securityContext:
|
securityContext:
|
||||||
{{- $podSecurityContext | nindent 8 }}
|
{{- $securityContext | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
initContainers:
|
initContainers:
|
||||||
{{- if .Values.preExtraInitContainers }}
|
{{- if .Values.preExtraInitContainers }}
|
||||||
|
|||||||
@@ -45,6 +45,11 @@
|
|||||||
{{- fail "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead." -}}
|
{{- fail "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead." -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/* CONTAINER SECURITY CONTEXT */}}
|
||||||
|
{{- if .Values.containerSecurityContext -}}
|
||||||
|
{{- fail "`containerSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.gitea.securityContext` instead." -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
{{/* DEPLOYMENT ENV */}}
|
{{/* DEPLOYMENT ENV */}}
|
||||||
{{- if .Values.deployment.env -}}
|
{{- if .Values.deployment.env -}}
|
||||||
{{- fail "`deployment.env` does no longer exist. Please refer to the changelog and configure `deployment.gitea.env` instead." -}}
|
{{- fail "`deployment.env` does no longer exist. Please refer to the changelog and configure `deployment.gitea.env` instead." -}}
|
||||||
@@ -65,6 +70,11 @@
|
|||||||
{{- fail "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead." -}}
|
{{- fail "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead." -}}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/* POD SECURITY CONTEXT */}}
|
||||||
|
{{- if .Values.podSecurityContext -}}
|
||||||
|
{{- fail "`podSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` instead." -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
{{/* RESOURCES */}}
|
{{/* RESOURCES */}}
|
||||||
{{- if .Values.resources -}}
|
{{- if .Values.resources -}}
|
||||||
{{- fail "`resources` does no longer exist. Please refer to the changelog and configure `deployment.gitea.resources` instead." -}}
|
{{- fail "`resources` does no longer exist. Please refer to the changelog and configure `deployment.gitea.resources` instead." -}}
|
||||||
|
|||||||
@@ -23,6 +23,13 @@ tests:
|
|||||||
asserts:
|
asserts:
|
||||||
- failedTemplate:
|
- failedTemplate:
|
||||||
errorMessage: "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead."
|
errorMessage: "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead."
|
||||||
|
- it: fails when the removed `containerSecurityContext` value is set
|
||||||
|
set:
|
||||||
|
containerSecurityContext:
|
||||||
|
runAsUser: 1000
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: "`containerSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.gitea.securityContext` instead."
|
||||||
- it: fails when the removed `deployment.env` value is set
|
- it: fails when the removed `deployment.env` value is set
|
||||||
set:
|
set:
|
||||||
deployment.env:
|
deployment.env:
|
||||||
@@ -52,6 +59,13 @@ tests:
|
|||||||
asserts:
|
asserts:
|
||||||
- failedTemplate:
|
- failedTemplate:
|
||||||
errorMessage: "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead."
|
errorMessage: "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead."
|
||||||
|
- it: fails when the removed `podSecurityContext` value is set
|
||||||
|
set:
|
||||||
|
podSecurityContext:
|
||||||
|
fsGroup: 1000
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: "`podSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` instead."
|
||||||
- it: fails when the removed `resources` value is set
|
- it: fails when the removed `resources` value is set
|
||||||
set:
|
set:
|
||||||
resources:
|
resources:
|
||||||
@@ -101,6 +115,8 @@ tests:
|
|||||||
checkDeprecation: false
|
checkDeprecation: false
|
||||||
affinity:
|
affinity:
|
||||||
nodeAffinity: {}
|
nodeAffinity: {}
|
||||||
|
containerSecurityContext:
|
||||||
|
runAsUser: 1000
|
||||||
deployment.env:
|
deployment.env:
|
||||||
- name: VARIABLE
|
- name: VARIABLE
|
||||||
value: my-value
|
value: my-value
|
||||||
@@ -109,6 +125,8 @@ tests:
|
|||||||
- 192.0.2.1
|
- 192.0.2.1
|
||||||
nodeSelector:
|
nodeSelector:
|
||||||
foo: bar
|
foo: bar
|
||||||
|
podSecurityContext:
|
||||||
|
fsGroup: 1000
|
||||||
priorityClassName: high-priority
|
priorityClassName: high-priority
|
||||||
replicaCount: 2
|
replicaCount: 2
|
||||||
resources:
|
resources:
|
||||||
|
|||||||
@@ -80,11 +80,13 @@ tests:
|
|||||||
openshift:
|
openshift:
|
||||||
enabled: true
|
enabled: true
|
||||||
hostUsers: true
|
hostUsers: true
|
||||||
podSecurityContext:
|
deployment:
|
||||||
fsGroup: 1000620000
|
securityContext:
|
||||||
containerSecurityContext:
|
fsGroup: 1000620000
|
||||||
runAsUser: 1000620000
|
gitea:
|
||||||
runAsGroup: 1000620000
|
securityContext:
|
||||||
|
runAsUser: 1000620000
|
||||||
|
runAsGroup: 1000620000
|
||||||
asserts:
|
asserts:
|
||||||
- equal:
|
- equal:
|
||||||
path: spec.template.spec.hostUsers
|
path: spec.template.spec.hostUsers
|
||||||
|
|||||||
+24
-24
@@ -101,6 +101,25 @@ deployment:
|
|||||||
# cpu: 100m
|
# cpu: 100m
|
||||||
# memory: 128Mi
|
# memory: 128Mi
|
||||||
|
|
||||||
|
## @param deployment.gitea.securityContext Security context of the Gitea container and the chart-managed init containers.
|
||||||
|
securityContext: {}
|
||||||
|
# allowPrivilegeEscalation: false
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# # Add the SYS_CHROOT capability for root and rootless images if you intend to
|
||||||
|
# # run pods on nodes that use the container runtime cri-o. Otherwise, you will
|
||||||
|
# # get an error message from the SSH server that it is not possible to read from
|
||||||
|
# # the repository.
|
||||||
|
# # https://gitea.com/gitea/helm-gitea/issues/161
|
||||||
|
# add:
|
||||||
|
# - SYS_CHROOT
|
||||||
|
# privileged: false
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsGroup: 1000
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
## @param deployment.nodeSelector NodeSelector for the deployment
|
## @param deployment.nodeSelector NodeSelector for the deployment
|
||||||
nodeSelector: {}
|
nodeSelector: {}
|
||||||
|
|
||||||
@@ -126,6 +145,9 @@ deployment:
|
|||||||
## @param deployment.schedulerName Use an alternate scheduler, e.g. "stork"
|
## @param deployment.schedulerName Use an alternate scheduler, e.g. "stork"
|
||||||
schedulerName: ""
|
schedulerName: ""
|
||||||
|
|
||||||
|
## @param deployment.securityContext Pod security context. On non-OpenShift clusters the chart defaults `fsGroup` to `1000` when this map is empty.
|
||||||
|
securityContext: {}
|
||||||
|
|
||||||
## @param deployment.strategy.type Deployment strategy used to replace old pods, either `RollingUpdate` or `Recreate`.
|
## @param deployment.strategy.type Deployment strategy used to replace old pods, either `RollingUpdate` or `Recreate`.
|
||||||
## @param deployment.strategy.rollingUpdate.maxSurge Number or percentage of pods that may be created above the desired replica count. Only used with `RollingUpdate`.
|
## @param deployment.strategy.rollingUpdate.maxSurge Number or percentage of pods that may be created above the desired replica count. Only used with `RollingUpdate`.
|
||||||
## @param deployment.strategy.rollingUpdate.maxUnavailable Number or percentage of pods that may be unavailable during the update. Only used with `RollingUpdate`.
|
## @param deployment.strategy.rollingUpdate.maxUnavailable Number or percentage of pods that may be unavailable during the update. Only used with `RollingUpdate`.
|
||||||
@@ -281,31 +303,9 @@ openshift:
|
|||||||
enabled: null
|
enabled: null
|
||||||
hostUsers: null
|
hostUsers: null
|
||||||
|
|
||||||
## @param podSecurityContext Pod security context. On non-OpenShift clusters the chart defaults `fsGroup` to `1000` when this map is empty.
|
|
||||||
podSecurityContext: {}
|
|
||||||
|
|
||||||
## @param containerSecurityContext Security context
|
|
||||||
containerSecurityContext: {}
|
|
||||||
# allowPrivilegeEscalation: false
|
|
||||||
# capabilities:
|
|
||||||
# drop:
|
|
||||||
# - ALL
|
|
||||||
# # Add the SYS_CHROOT capability for root and rootless images if you intend to
|
|
||||||
# # run pods on nodes that use the container runtime cri-o. Otherwise, you will
|
|
||||||
# # get an error message from the SSH server that it is not possible to read from
|
|
||||||
# # the repository.
|
|
||||||
# # https://gitea.com/gitea/helm-gitea/issues/161
|
|
||||||
# add:
|
|
||||||
# - SYS_CHROOT
|
|
||||||
# privileged: false
|
|
||||||
# readOnlyRootFilesystem: true
|
|
||||||
# runAsGroup: 1000
|
|
||||||
# runAsNonRoot: true
|
|
||||||
# runAsUser: 1000
|
|
||||||
|
|
||||||
## @deprecated The securityContext variable has been split two:
|
## @deprecated The securityContext variable has been split two:
|
||||||
## - containerSecurityContext
|
## - deployment.gitea.securityContext
|
||||||
## - podSecurityContext.
|
## - deployment.securityContext.
|
||||||
## @param securityContext Run init and Gitea containers as a specific securityContext
|
## @param securityContext Run init and Gitea containers as a specific securityContext
|
||||||
securityContext: {}
|
securityContext: {}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user