feat: add Gateway API support (#1073)
Add full Gateway API support for exposing Gitea via HTTPRoute, TCPRoute, BackendTLSPolicy, and ClientSettingsPolicy resources. New templates: - `httpRoute.yaml` — renders an HTTPRoute with configurable parentRefs, hostnames, and rules (defaults to PathPrefix `/`) - `tcpRoute.yaml` — renders a TCPRoute for SSH traffic - `backendTLSPolicy.yaml` — renders a BackendTLSPolicy for encrypted backend connections with required validation config - `clientSettingsPolicy.yaml` — renders an NGINX Gateway Fabric ClientSettingsPolicy to raise the request body size limit Infrastructure: - `gatewayAPI.enabled` global toggle gates all resources - Resources grouped under `gatewayAPI.core.*` and `gatewayAPI.nginx.*` - Helper templates extracted into dedicated `_*.tpl` files - Service name helpers (`gitea.service.http.name`, `gitea.service.ssh.name`) extracted into `_services.tpl`; service templates renamed to camelCase - `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` auto-resolve from `httpRoute.hostnames[0]`; `httpRoute.tls` switches to `https` Documentation: - New `docs/gateway-api.md` with topology examples, BackendTLSPolicy setup, sectionName guidance, SSH considerations, and NGINX body size limit configuration - `.github/copilot-instructions.md` with project conventions - README parameter table auto-generated via `make readme` Tests: - Helm unit tests for all four new resource templates - Config tests for hostname/TLS resolution from Gateway API values Co-authored-by: Todd Marimon <toddmarimon@gmail.com>
This commit is contained in:
committed by
Markus Pesch
parent
5005037dbf
commit
7747a001f7
@@ -0,0 +1,62 @@
|
|||||||
|
# Gitea Helm Chart — Copilot Instructions
|
||||||
|
|
||||||
|
## Project Overview
|
||||||
|
|
||||||
|
Kubernetes Helm chart for deploying [Gitea](https://gitea.com). Uses Go/Helm templating (`templates/`), YAML values (`values.yaml`), and includes sub-charts for PostgreSQL, PostgreSQL-HA, Valkey, and Valkey-cluster.
|
||||||
|
|
||||||
|
## Build & Test
|
||||||
|
|
||||||
|
```bash
|
||||||
|
make readme # Regenerate README.md parameter table + lint
|
||||||
|
make unittests-helm # Run Helm unit tests (helm-unittest plugin required)
|
||||||
|
make unittests-bash # Run bash/bats script tests (requires git submodule init)
|
||||||
|
make unittests # Both of the above
|
||||||
|
```
|
||||||
|
|
||||||
|
Always run `make readme` after changing `values.yaml` `@param` annotations.
|
||||||
|
Always run `make unittests-helm` after changing templates or unit tests.
|
||||||
|
|
||||||
|
## Conventions
|
||||||
|
|
||||||
|
### values.yaml
|
||||||
|
|
||||||
|
- Use `## @param path.to.key Description` annotations for every user-facing value. These drive the auto-generated README parameter table.
|
||||||
|
- Property ordering within a resource block: `enabled`, `annotations`, `labels` first, then type-specific fields.
|
||||||
|
- Top-level keys are sorted alphabetically within their section group.
|
||||||
|
- Use [Helm Values](https://docs.renovatebot.com/modules/manager/helm-values/#additional-information) pattern from renovatebot. Ensure that the attributes `registry`, `repository` and `tag` are available as part of the dict `image`. For example:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
image:
|
||||||
|
registry: docker.io
|
||||||
|
repository: library/busybox
|
||||||
|
tag: 0.1.0
|
||||||
|
```
|
||||||
|
|
||||||
|
### Templates
|
||||||
|
|
||||||
|
- Helm templates live in `templates/gitea/`. Helpers live in `templates/_helpers.tpl`.
|
||||||
|
- Use camelCase for all files and variables (e.g `httpRoute`, `backendTLSPolicy`, `gatewayAPI`, `statefulSet`).
|
||||||
|
- Use `include "gitea.fullname"` for naming resources.
|
||||||
|
- Use `fail` for required-value validation with clear error messages referencing the full values path.
|
||||||
|
- Ensure, that the attributes `annotations`, `labels`, `name` and `namespace` are alphabetically sorted.
|
||||||
|
- Render all attributes, even if they are empty, to prevent drift in Argo CD. For example, `labels` must be rendered, while `annotations` are defined as `yaml:"annotations,omitempty"`.
|
||||||
|
- Use plural for `*.tpl` files, because they may contain functions for multiple resources of the same kind (e.g. `_services.tpl` for `httpService.yaml` or `sshService.yaml`, `_backendTLSPolicies.tpl` for `backendTLSPolicy.yaml`).
|
||||||
|
|
||||||
|
### Unit Tests
|
||||||
|
|
||||||
|
- Helm unit tests live in `unittests/helm/` mirroring the template structure.
|
||||||
|
- Test files are YAML using the [helm-unittest](https://github.com/helm-unittest/helm-unittest) format.
|
||||||
|
- Each test must set all required values explicitly — do not rely on cross-test state.
|
||||||
|
- The `values.yaml` file must pass `yamllint`. The configuration is in `.yamllint`. Use `make yamllint` to run the linter.
|
||||||
|
|
||||||
|
### Commits & PRs
|
||||||
|
|
||||||
|
- Follow [Conventional Commits](https://www.conventionalcommits.org/en/v1.0.0/) for PR titles and commit messages (e.g. `feat:`, `fix:`, `refactor:`, `docs:`, `style:`).
|
||||||
|
- See `CONTRIBUTING.md` for full PR requirements.
|
||||||
|
- Explain in detail why a change is needed, not just what the change is. Include links to relevant issues, PRs, or external references.
|
||||||
|
- Add co-authors for any contributions that are not your own. Use the `Co-authored-by:` trailer in the commit message.
|
||||||
|
|
||||||
|
### Documentation
|
||||||
|
|
||||||
|
- `docs/` contains topic-specific guides (e.g. `gateway-api.md`, `ha-setup.md`).
|
||||||
|
- `README.md` parameter tables are auto-generated — never edit them manually.
|
||||||
@@ -43,6 +43,8 @@
|
|||||||
- [Security](#security)
|
- [Security](#security)
|
||||||
- [Service](#service)
|
- [Service](#service)
|
||||||
- [Ingress](#ingress)
|
- [Ingress](#ingress)
|
||||||
|
- [Route](#route)
|
||||||
|
- [Gateway API](#gateway-api)
|
||||||
- [deployment](#deployment)
|
- [deployment](#deployment)
|
||||||
- [ServiceAccount](#serviceaccount)
|
- [ServiceAccount](#serviceaccount)
|
||||||
- [Persistence](#persistence-1)
|
- [Persistence](#persistence-1)
|
||||||
@@ -311,6 +313,11 @@ route:
|
|||||||
|
|
||||||
When `route.host` is set, the chart uses it for `DOMAIN`, `SSH_DOMAIN`, and `ROOT_URL`. Setting `route.tls.termination` also switches the default `ROOT_URL` scheme to `https`.
|
When `route.host` is set, the chart uses it for `DOMAIN`, `SSH_DOMAIN`, and `ROOT_URL`. Setting `route.tls.termination` also switches the default `ROOT_URL` scheme to `https`.
|
||||||
|
|
||||||
|
#### Gateway API
|
||||||
|
|
||||||
|
The chart can also expose Gitea through Gateway API resources (`HTTPRoute`, `TCPRoute`, `BackendTLSPolicy`, and optionally `Gateway`).
|
||||||
|
See [docs/gateway-api.md](docs/gateway-api.md) for the full guide, including how routes interact with `ROOT_URL`/`DOMAIN` resolution and recommended topologies.
|
||||||
|
|
||||||
#### Session, Cache and Queue
|
#### Session, Cache and Queue
|
||||||
|
|
||||||
The session, cache and queue settings are set to use the built-in Valkey Cluster sub-chart dependency.
|
The session, cache and queue settings are set to use the built-in Valkey Cluster sub-chart dependency.
|
||||||
@@ -1075,6 +1082,36 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
|||||||
| `route.tls.caCertificate` | Route TLS CA certificate | `nil` |
|
| `route.tls.caCertificate` | Route TLS CA certificate | `nil` |
|
||||||
| `route.tls.destinationCACertificate` | Route destination CA certificate | `nil` |
|
| `route.tls.destinationCACertificate` | Route destination CA certificate | `nil` |
|
||||||
|
|
||||||
|
### Gateway API
|
||||||
|
|
||||||
|
| Name | Description | Value |
|
||||||
|
| --------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||||
|
| `gatewayAPI.enabled` | Enable deployment of Gateway API resources | `false` |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.enabled` | Render a BackendTLSPolicy resource for encrypted backend traffic | `false` |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.annotations` | Annotations applied to the BackendTLSPolicy | `{}` |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.labels` | Additional labels applied to the BackendTLSPolicy | `{}` |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.targetRefs` | Target references for the BackendTLSPolicy. Defaults to the HTTP service. | `[]` |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.validation` | Validation configuration (required when enabled). See `docs/gateway-api.md`. | `{}` |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.validation.caCertificateRefs` | CA certificate references for the BackendTLSPolicy validation. See `docs/gateway-api.md`. | |
|
||||||
|
| `gatewayAPI.core.backendTLSPolicy.validation.hostname` | Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the Gitea server certificate. See `docs/gateway-api.md`. | |
|
||||||
|
| `gatewayAPI.core.httpRoute.enabled` | Render an HTTPRoute resource | `false` |
|
||||||
|
| `gatewayAPI.core.httpRoute.annotations` | Annotations applied to the HTTPRoute | `{}` |
|
||||||
|
| `gatewayAPI.core.httpRoute.labels` | Additional labels applied to the HTTPRoute | `{}` |
|
||||||
|
| `gatewayAPI.core.httpRoute.tls` | When true, treat the upstream Gateway as terminating TLS so `ROOT_URL` uses `https`. | `false` |
|
||||||
|
| `gatewayAPI.core.httpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
|
||||||
|
| `gatewayAPI.core.httpRoute.hostnames` | List of hostnames for the HTTPRoute. | `[]` |
|
||||||
|
| `gatewayAPI.core.httpRoute.rules` | Custom routing rules. Defaults to a PathPrefix `/` rule targeting the HTTP service. | `[]` |
|
||||||
|
| `gatewayAPI.core.tcpRoute.enabled` | Render a TCPRoute resource (typically for SSH) | `false` |
|
||||||
|
| `gatewayAPI.core.tcpRoute.annotations` | Annotations applied to the TCPRoute | `{}` |
|
||||||
|
| `gatewayAPI.core.tcpRoute.labels` | Additional labels applied to the TCPRoute | `{}` |
|
||||||
|
| `gatewayAPI.core.tcpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
|
||||||
|
| `gatewayAPI.core.tcpRoute.rules` | Custom routing rules. Defaults to a rule targeting the SSH service. | `[]` |
|
||||||
|
| `gatewayAPI.nginx.clientSettingsPolicies.enabled` | Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit | `false` |
|
||||||
|
| `gatewayAPI.nginx.clientSettingsPolicies.annotations` | Annotations applied to the ClientSettingsPolicy | `{}` |
|
||||||
|
| `gatewayAPI.nginx.clientSettingsPolicies.labels` | Additional labels applied to the ClientSettingsPolicy | `{}` |
|
||||||
|
| `gatewayAPI.nginx.clientSettingsPolicies.targetRef` | Target reference for the ClientSettingsPolicy. Defaults to the chart's HTTPRoute. | `{}` |
|
||||||
|
| `gatewayAPI.nginx.clientSettingsPolicies.body` | Client body settings (required when enabled), e.g. `maxSize`. See `docs/gateway-api.md`. | `{}` |
|
||||||
|
|
||||||
### deployment
|
### deployment
|
||||||
|
|
||||||
| Name | Description | Value |
|
| Name | Description | Value |
|
||||||
|
|||||||
@@ -0,0 +1,267 @@
|
|||||||
|
# Gateway API
|
||||||
|
|
||||||
|
This chart can expose Gitea through [Kubernetes Gateway API](https://gateway-api.sigs.k8s.io/) resources
|
||||||
|
alongside (or instead of) the existing `Ingress` and OpenShift `Route` support. The following resources
|
||||||
|
are rendered:
|
||||||
|
|
||||||
|
- `HTTPRoute` — required for HTTP traffic
|
||||||
|
- `TCPRoute` — optional, typically for SSH (port 22)
|
||||||
|
- `BackendTLSPolicy` — optional, for encrypted backend traffic
|
||||||
|
- `ClientSettingsPolicy` — optional, **NGINX Gateway Fabric only**, to raise the client request body size limit
|
||||||
|
|
||||||
|
All resources are disabled by default. Enabling them requires Gateway API CRDs (and an implementation that supports them) to already be installed in the cluster.
|
||||||
|
|
||||||
|
The chart does **not** render a `Gateway` resource — provisioning and managing the Gateway is the responsibility of the cluster / platform administrator.
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
| Resource | API version | Status (as of writing) |
|
||||||
|
| ---------------------- | ------------------------------------ | ---------------------- |
|
||||||
|
| `HTTPRoute` | `gateway.networking.k8s.io/v1` | GA |
|
||||||
|
| `TCPRoute` | `gateway.networking.k8s.io/v1alpha2` | Experimental |
|
||||||
|
| `BackendTLSPolicy` | `gateway.networking.k8s.io/v1` | GA (v1.2+) |
|
||||||
|
| `ClientSettingsPolicy` | `gateway.nginx.org/v1alpha1` | NGINX Gateway Fabric |
|
||||||
|
|
||||||
|
## Common topology
|
||||||
|
|
||||||
|
Most users should attach to a pre-existing, shared `Gateway` managed by the cluster administrator:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gatewayAPI:
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
tls: true # the shared Gateway terminates TLS
|
||||||
|
hostnames:
|
||||||
|
- git.example.com
|
||||||
|
parentRefs:
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: shared-gateway
|
||||||
|
namespace: gateway-system
|
||||||
|
sectionName: https-gitea # pin to a specific listener (see below)
|
||||||
|
tcpRoute:
|
||||||
|
enabled: true
|
||||||
|
parentRefs:
|
||||||
|
- group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: shared-gateway
|
||||||
|
namespace: gateway-system
|
||||||
|
sectionName: ssh
|
||||||
|
```
|
||||||
|
|
||||||
|
With this configuration:
|
||||||
|
|
||||||
|
- `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` resolve to the first HTTPRoute hostname.
|
||||||
|
- Setting `gatewayAPI.core.httpRoute.tls: true` switches `ROOT_URL` to `https://`.
|
||||||
|
- The default HTTPRoute rule forwards `/` to the Gitea HTTP `Service`. The default TCPRoute rule forwards to the SSH `Service`.
|
||||||
|
- Custom `rules` and `hostnames` are rendered through `tpl`, so Helm template expressions work inside them.
|
||||||
|
|
||||||
|
### Why `sectionName` matters
|
||||||
|
|
||||||
|
Omitting `sectionName` attaches the route to **every** matching listener on the Gateway. On implementations
|
||||||
|
that use per-host HTTPS listeners (Envoy Gateway, Cilium Gateway), that means Gitea's HTTPRoute will try
|
||||||
|
to bind to every HTTPS listener — usually not what you want. Always pin to a named listener
|
||||||
|
(e.g. `https-gitea`, `ssh`) when the Gateway has more than one. The corresponding listener on the Gateway
|
||||||
|
side typically looks like:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
listeners:
|
||||||
|
- name: https-gitea
|
||||||
|
port: 443
|
||||||
|
protocol: HTTPS
|
||||||
|
hostname: git.example.com
|
||||||
|
tls:
|
||||||
|
certificateRefs:
|
||||||
|
- name: git-example-com-tls
|
||||||
|
allowedRoutes:
|
||||||
|
kinds:
|
||||||
|
- kind: HTTPRoute
|
||||||
|
namespaces:
|
||||||
|
from: Selector
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
kubernetes.io/metadata.name: gitea
|
||||||
|
- name: ssh
|
||||||
|
port: 22
|
||||||
|
protocol: TCP
|
||||||
|
allowedRoutes:
|
||||||
|
kinds:
|
||||||
|
- kind: TCPRoute
|
||||||
|
namespaces:
|
||||||
|
from: Selector
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
kubernetes.io/metadata.name: gitea
|
||||||
|
```
|
||||||
|
|
||||||
|
### Sharing a hostname between HTTP and SSH
|
||||||
|
|
||||||
|
HTTP (443) and SSH (22) are different ports, so a single hostname like `git.example.com` can serve both —
|
||||||
|
clients disambiguate by port. This is the recommended pattern: one DNS record, `ssh git@git.example.com`
|
||||||
|
and `https://git.example.com` both work, and `SSH_DOMAIN` / `DOMAIN` resolve to the same value with no
|
||||||
|
extra configuration.
|
||||||
|
|
||||||
|
If you want SSH on a **different** hostname (e.g. `gitea-ssh.example.com`), set it explicitly — the chart
|
||||||
|
cannot infer it from TCPRoute config because TCPRoutes don't carry hostnames:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gitea:
|
||||||
|
config:
|
||||||
|
server:
|
||||||
|
SSH_DOMAIN: gitea-ssh.example.com
|
||||||
|
```
|
||||||
|
|
||||||
|
## BackendTLSPolicy
|
||||||
|
|
||||||
|
Use this when the Gitea HTTP backend is terminating TLS itself (for example, when running Gitea with
|
||||||
|
`PROTOCOL=https`, or when fronting another HTTPS service from the same chart) and the Gateway needs to
|
||||||
|
verify the backend certificate before forwarding the request.
|
||||||
|
|
||||||
|
### Configuring Gitea to serve HTTPS directly
|
||||||
|
|
||||||
|
Gitea serves HTTPS via three `[server]` app.ini options
|
||||||
|
([cheat sheet](https://docs.gitea.com/administration/config-cheat-sheet#server-server)). Mount the
|
||||||
|
cert/key with `extraVolumes` + `extraContainerVolumeMounts` and point Gitea at them with absolute paths:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gitea:
|
||||||
|
config:
|
||||||
|
server:
|
||||||
|
PROTOCOL: https
|
||||||
|
CERT_FILE: /etc/gitea-tls/tls.crt
|
||||||
|
KEY_FILE: /etc/gitea-tls/tls.key
|
||||||
|
|
||||||
|
extraVolumes:
|
||||||
|
- name: gitea-tls
|
||||||
|
secret:
|
||||||
|
secretName: gitea-backend-tls # cert-manager-issued Secret, etc.
|
||||||
|
extraContainerVolumeMounts:
|
||||||
|
- name: gitea-tls
|
||||||
|
mountPath: /etc/gitea-tls
|
||||||
|
readOnly: true
|
||||||
|
```
|
||||||
|
|
||||||
|
- Relative `CERT_FILE`/`KEY_FILE` values resolve against Gitea's `CustomPath` (`/data/gitea` in the
|
||||||
|
official image); absolute paths are clearer.
|
||||||
|
- Both options are ignored when `gitea.config.server.ENABLE_ACME` is `true`.
|
||||||
|
- For chained certs, the server cert comes first, intermediates after.
|
||||||
|
- The Service still forwards raw TCP — no `service.http.*` changes needed. The pod's container port
|
||||||
|
(3000 by default) is now speaking HTTPS instead of HTTP.
|
||||||
|
|
||||||
|
### BackendTLSPolicy example
|
||||||
|
|
||||||
|
Verify the backend with a CA bundle stored in a `ConfigMap`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gatewayAPI:
|
||||||
|
core:
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: true
|
||||||
|
validation:
|
||||||
|
hostname: gitea.svc.cluster.local
|
||||||
|
caCertificateRefs:
|
||||||
|
- name: gitea-backend-ca
|
||||||
|
group: ""
|
||||||
|
kind: ConfigMap
|
||||||
|
```
|
||||||
|
|
||||||
|
This renders a single `BackendTLSPolicy` whose `targetRefs` defaults to the chart's HTTP `Service`
|
||||||
|
(`<fullname>-http`), and whose `validation` is passed through verbatim. `validation` is required by the
|
||||||
|
API; the template fails fast if omitted.
|
||||||
|
|
||||||
|
### System CA trust and explicit targetRefs
|
||||||
|
|
||||||
|
To trust the system CA store (Gateway API v1.1+) or target a different Service, use `wellKnownCACertificates`
|
||||||
|
and `targetRefs`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gatewayAPI:
|
||||||
|
core:
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: true
|
||||||
|
targetRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: gitea-sidecar
|
||||||
|
validation:
|
||||||
|
hostname: sidecar.gitea.svc.cluster.local
|
||||||
|
wellKnownCACertificates: System
|
||||||
|
```
|
||||||
|
|
||||||
|
Notes:
|
||||||
|
|
||||||
|
- `targetRefs[].kind` is almost always `Service`; `group: ""` is the core API group.
|
||||||
|
- `wellKnownCACertificates: System` requires Gateway API v1.1 and an implementation that supports it
|
||||||
|
(otherwise stick with `caCertificateRefs`).
|
||||||
|
- The corresponding HTTPRoute must reference the backend by the same `Service` (and, if used,
|
||||||
|
`sectionName`/`port`) — `BackendTLSPolicy` attaches to the Service-side reference, not to the route.
|
||||||
|
|
||||||
|
## Raising the request body size limit (NGINX Gateway Fabric)
|
||||||
|
|
||||||
|
NGINX defaults `client_max_body_size` to `1m`. Requests exceeding it are rejected with `413 Request
|
||||||
|
Entity Too Large`. This blocks uploading larger artifacts to Gitea's package/container registry (container
|
||||||
|
images, DEB/RPM packages, etc.). With the NGINX **Ingress** controller you raised this via the
|
||||||
|
`nginx.ingress.kubernetes.io/proxy-body-size` annotation — that annotation does **not** apply to Gateway
|
||||||
|
API. NGINX Gateway Fabric instead reads the limit from a
|
||||||
|
[`ClientSettingsPolicy`](https://docs.nginx.com/nginx-gateway-fabric/reference/api/) (`spec.body.maxSize`).
|
||||||
|
|
||||||
|
This is specific to **NGINX Gateway Fabric**. Other implementations (Envoy Gateway, Cilium, Istio, …) do
|
||||||
|
**not** impose a default request body size limit, so large uploads work without any extra configuration —
|
||||||
|
leave `gatewayAPI.nginx.clientSettingsPolicies` disabled.
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
body:
|
||||||
|
maxSize: 100m # bytes, or with a k / m / g suffix; 0 disables the limit
|
||||||
|
```
|
||||||
|
|
||||||
|
This renders a single `ClientSettingsPolicy` whose `targetRef` defaults to the chart's `HTTPRoute`
|
||||||
|
(`<fullname>`), so the limit applies to all traffic routed to Gitea. `body` is required when enabled; the
|
||||||
|
template fails fast if omitted. `spec.body` is passed through verbatim, so other fields (e.g. `timeout`)
|
||||||
|
are supported too.
|
||||||
|
|
||||||
|
To attach the policy elsewhere — for example the whole `Gateway` so the limit is inherited by every route —
|
||||||
|
override `targetRef`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
gatewayAPI:
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
targetRef:
|
||||||
|
group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: shared-gateway
|
||||||
|
body:
|
||||||
|
maxSize: 100m
|
||||||
|
```
|
||||||
|
|
||||||
|
Notes:
|
||||||
|
|
||||||
|
- `ClientSettingsPolicy` is an inherited policy: attaching it to a `Gateway` cascades to its routes, while
|
||||||
|
attaching it to an `HTTPRoute` scopes it to that route only.
|
||||||
|
- The policy must live in the same namespace as its `targetRef`.
|
||||||
|
- Gitea also enforces its own upload limits independently (`gitea.config` `[repository.upload]` and
|
||||||
|
`[packages]` sections) — raising the proxy limit alone is not always sufficient.
|
||||||
|
|
||||||
|
## Interaction with `ingress` and `route`
|
||||||
|
|
||||||
|
The three exposure mechanisms are independent and can coexist, but `ROOT_URL` / `DOMAIN` / `SSH_DOMAIN` resolution uses the first defined source in this order:
|
||||||
|
|
||||||
|
1. `route.host` (when `route.enabled`)
|
||||||
|
2. `httpRoute.hostnames[0]` (when `gatewayAPI.core.httpRoute.enabled`)
|
||||||
|
3. First `ingress.hosts[0].host`
|
||||||
|
4. The in-cluster Service DNS name
|
||||||
|
|
||||||
|
Likewise, `ROOT_URL` becomes `https://` if any of these terminate TLS: `route.tls.termination`, `ingress.tls`, or `gatewayAPI.core.httpRoute.tls`.
|
||||||
|
|
||||||
|
## SSH considerations
|
||||||
|
|
||||||
|
- `TCPRoute` is still experimental. Many production-grade implementations support it (Envoy Gateway, Istio, Kgateway, NGINX Gateway Fabric), but you should verify before relying on it.
|
||||||
|
- If your Gateway implementation does not support `TCPRoute`, keep using `service.ssh.type: LoadBalancer` (or `NodePort`) and only enable `httpRoute` for HTTP traffic.
|
||||||
|
- The default TCPRoute rule points at the Gitea SSH `Service` on `service.ssh.port` (typically 22), which itself proxies to `gitea.config.server.SSH_LISTEN_PORT` inside the pod.
|
||||||
@@ -247,6 +247,8 @@ app.kubernetes.io/instance: {{ .Release.Name }}
|
|||||||
{{- define "gitea.public_hostname" -}}
|
{{- define "gitea.public_hostname" -}}
|
||||||
{{- if and .Values.route.enabled .Values.route.host -}}
|
{{- if and .Values.route.enabled .Values.route.host -}}
|
||||||
{{ tpl .Values.route.host . }}
|
{{ tpl .Values.route.host . }}
|
||||||
|
{{- else if and .Values.gatewayAPI.enabled .Values.gatewayAPI.core.httpRoute.enabled (gt (len .Values.gatewayAPI.core.httpRoute.hostnames) 0) -}}
|
||||||
|
{{ tpl (index .Values.gatewayAPI.core.httpRoute.hostnames 0) $ }}
|
||||||
{{- else if gt (len .Values.ingress.hosts) 0 -}}
|
{{- else if gt (len .Values.ingress.hosts) 0 -}}
|
||||||
{{ tpl (index .Values.ingress.hosts 0).host $ }}
|
{{ tpl (index .Values.ingress.hosts 0).host $ }}
|
||||||
{{- else -}}
|
{{- else -}}
|
||||||
@@ -308,6 +310,8 @@ app.kubernetes.io/instance: {{ .Release.Name }}
|
|||||||
https
|
https
|
||||||
{{- else if and .Values.ingress.enabled (gt (len .Values.ingress.tls) 0) -}}
|
{{- else if and .Values.ingress.enabled (gt (len .Values.ingress.tls) 0) -}}
|
||||||
https
|
https
|
||||||
|
{{- else if and .Values.gatewayAPI.enabled .Values.gatewayAPI.core.httpRoute.enabled .Values.gatewayAPI.core.httpRoute.tls -}}
|
||||||
|
https
|
||||||
{{- else -}}
|
{{- else -}}
|
||||||
{{ .Values.gitea.config.server.PROTOCOL }}
|
{{ .Values.gitea.config.server.PROTOCOL }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/* annotations */}}
|
||||||
|
|
||||||
|
{{- define "gitea.backendTLSPolicy.annotations" -}}
|
||||||
|
{{- with .Values.gatewayAPI.core.backendTLSPolicy.annotations }}
|
||||||
|
{{- toYaml . -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* enabled */}}
|
||||||
|
|
||||||
|
{{- define "gitea.backendTLSPolicy.enabled" -}}
|
||||||
|
{{- if and .Values.gatewayAPI.enabled
|
||||||
|
.Values.gatewayAPI.core.backendTLSPolicy.enabled
|
||||||
|
-}}
|
||||||
|
true
|
||||||
|
{{- else -}}
|
||||||
|
false
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* labels */}}
|
||||||
|
|
||||||
|
{{- define "gitea.backendTLSPolicy.labels" -}}
|
||||||
|
{{ include "gitea.labels" . }}
|
||||||
|
{{- with .Values.gatewayAPI.core.backendTLSPolicy.labels }}
|
||||||
|
{{ toYaml . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/* annotations */}}
|
||||||
|
|
||||||
|
{{- define "gitea.clientSettingsPolicies.annotations" -}}
|
||||||
|
{{- with .Values.gatewayAPI.nginx.clientSettingsPolicies.annotations }}
|
||||||
|
{{- toYaml . -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* enabled */}}
|
||||||
|
|
||||||
|
{{- define "gitea.clientSettingsPolicies.enabled" -}}
|
||||||
|
{{- if and .Values.gatewayAPI.enabled
|
||||||
|
.Values.gatewayAPI.nginx.clientSettingsPolicies.enabled
|
||||||
|
-}}
|
||||||
|
true
|
||||||
|
{{- else -}}
|
||||||
|
false
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* labels */}}
|
||||||
|
|
||||||
|
{{- define "gitea.clientSettingsPolicies.labels" -}}
|
||||||
|
{{ include "gitea.labels" . }}
|
||||||
|
{{- with .Values.gatewayAPI.nginx.clientSettingsPolicies.labels }}
|
||||||
|
{{ toYaml . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/* annotations */}}
|
||||||
|
|
||||||
|
{{- define "gitea.httpRoute.annotations" -}}
|
||||||
|
{{- with .Values.gatewayAPI.core.httpRoute.annotations }}
|
||||||
|
{{- toYaml . -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* enabled */}}
|
||||||
|
|
||||||
|
{{- define "gitea.httpRoute.enabled" -}}
|
||||||
|
{{- if and .Values.gatewayAPI.enabled
|
||||||
|
.Values.gatewayAPI.core.httpRoute.enabled
|
||||||
|
-}}
|
||||||
|
true
|
||||||
|
{{- else -}}
|
||||||
|
false
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* labels */}}
|
||||||
|
|
||||||
|
{{- define "gitea.httpRoute.labels" -}}
|
||||||
|
{{ include "gitea.labels" . }}
|
||||||
|
{{- with .Values.gatewayAPI.core.httpRoute.labels }}
|
||||||
|
{{ toYaml . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/* names */}}
|
||||||
|
|
||||||
|
{{- define "gitea.service.http.name" -}}
|
||||||
|
{{ include "gitea.fullname" . }}-http
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "gitea.service.ssh.name" -}}
|
||||||
|
{{ include "gitea.fullname" . }}-ssh
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
|
||||||
|
{{/* annotations */}}
|
||||||
|
|
||||||
|
{{- define "gitea.tcpRoute.annotations" -}}
|
||||||
|
{{- with .Values.gatewayAPI.core.tcpRoute.annotations }}
|
||||||
|
{{- toYaml . -}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* enabled */}}
|
||||||
|
|
||||||
|
{{- define "gitea.tcpRoute.enabled" -}}
|
||||||
|
{{- if and .Values.gatewayAPI.enabled
|
||||||
|
.Values.gatewayAPI.core.tcpRoute.enabled
|
||||||
|
-}}
|
||||||
|
true
|
||||||
|
{{- else -}}
|
||||||
|
false
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/* labels */}}
|
||||||
|
|
||||||
|
{{- define "gitea.tcpRoute.labels" -}}
|
||||||
|
{{ include "gitea.labels" . }}
|
||||||
|
{{- with .Values.gatewayAPI.core.tcpRoute.labels }}
|
||||||
|
{{ toYaml . }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{- if eq (include "gitea.backendTLSPolicy.enabled" .) "true" -}}
|
||||||
|
{{- if not (keys .Values.gatewayAPI.core.backendTLSPolicy.validation) }}
|
||||||
|
{{- fail "gatewayAPI.core.backendTLSPolicy.validation is required" }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: BackendTLSPolicy
|
||||||
|
metadata:
|
||||||
|
{{- with (include "gitea.backendTLSPolicy.annotations" .) }}
|
||||||
|
annotations:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with (include "gitea.backendTLSPolicy.labels" .) }}
|
||||||
|
labels:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
name: {{ include "gitea.fullname" . }}
|
||||||
|
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
targetRefs:
|
||||||
|
{{- if .Values.gatewayAPI.core.backendTLSPolicy.targetRefs }}
|
||||||
|
{{- toYaml .Values.gatewayAPI.core.backendTLSPolicy.targetRefs | nindent 4 }}
|
||||||
|
{{- else }}
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: {{ include "gitea.service.http.name" . }}
|
||||||
|
{{- end }}
|
||||||
|
validation:
|
||||||
|
{{- toYaml .Values.gatewayAPI.core.backendTLSPolicy.validation | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{- if eq (include "gitea.clientSettingsPolicies.enabled" .) "true" -}}
|
||||||
|
{{- if not (keys .Values.gatewayAPI.nginx.clientSettingsPolicies.body) }}
|
||||||
|
{{- fail "gatewayAPI.nginx.clientSettingsPolicies.body is required" }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
apiVersion: gateway.nginx.org/v1alpha1
|
||||||
|
kind: ClientSettingsPolicy
|
||||||
|
metadata:
|
||||||
|
{{- with (include "gitea.clientSettingsPolicies.annotations" .) }}
|
||||||
|
annotations:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with (include "gitea.clientSettingsPolicies.labels" .) }}
|
||||||
|
labels:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
name: {{ include "gitea.fullname" . }}
|
||||||
|
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
targetRef:
|
||||||
|
{{- if .Values.gatewayAPI.nginx.clientSettingsPolicies.targetRef }}
|
||||||
|
{{- toYaml .Values.gatewayAPI.nginx.clientSettingsPolicies.targetRef | nindent 4 }}
|
||||||
|
{{- else }}
|
||||||
|
group: gateway.networking.k8s.io
|
||||||
|
kind: HTTPRoute
|
||||||
|
name: {{ include "gitea.fullname" . }}
|
||||||
|
{{- end }}
|
||||||
|
body:
|
||||||
|
{{- toYaml .Values.gatewayAPI.nginx.clientSettingsPolicies.body | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
{{- if eq (include "gitea.httpRoute.enabled" .) "true" -}}
|
||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1
|
||||||
|
kind: HTTPRoute
|
||||||
|
metadata:
|
||||||
|
{{- with (include "gitea.httpRoute.annotations" .) }}
|
||||||
|
annotations:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with (include "gitea.httpRoute.labels" .) }}
|
||||||
|
labels:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
name: {{ include "gitea.fullname" . }}
|
||||||
|
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
parentRefs:
|
||||||
|
{{- if .Values.gatewayAPI.core.httpRoute.parentRefs }}
|
||||||
|
{{- toYaml .Values.gatewayAPI.core.httpRoute.parentRefs | nindent 4 }}
|
||||||
|
{{- else }}
|
||||||
|
{{- fail "gatewayAPI.core.httpRoute.parentRefs is required" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.gatewayAPI.core.httpRoute.hostnames }}
|
||||||
|
hostnames:
|
||||||
|
{{- tpl (toYaml .) $ | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- if .Values.gatewayAPI.core.httpRoute.rules }}
|
||||||
|
{{- tpl (toYaml .Values.gatewayAPI.core.httpRoute.rules) $ | nindent 4 }}
|
||||||
|
{{- else }}
|
||||||
|
- matches:
|
||||||
|
- path:
|
||||||
|
type: PathPrefix
|
||||||
|
value: /
|
||||||
|
backendRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: {{ include "gitea.service.http.name" . }}
|
||||||
|
port: {{ .Values.service.http.port }}
|
||||||
|
weight: 1
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -1,15 +1,15 @@
|
|||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ include "gitea.fullname" . }}-http
|
annotations:
|
||||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
{{- toYaml .Values.service.http.annotations | nindent 4 }}
|
||||||
labels:
|
labels:
|
||||||
{{- include "gitea.labels" . | nindent 4 }}
|
{{- include "gitea.labels" . | nindent 4 }}
|
||||||
{{- if .Values.service.http.labels }}
|
{{- if .Values.service.http.labels }}
|
||||||
{{- toYaml .Values.service.http.labels | nindent 4 }}
|
{{- toYaml .Values.service.http.labels | nindent 4 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
annotations:
|
name: {{ include "gitea.service.http.name" . }}
|
||||||
{{- toYaml .Values.service.http.annotations | nindent 4 }}
|
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||||
spec:
|
spec:
|
||||||
type: {{ .Values.service.http.type }}
|
type: {{ .Values.service.http.type }}
|
||||||
{{- if eq .Values.service.http.type "LoadBalancer" }}
|
{{- if eq .Values.service.http.type "LoadBalancer" }}
|
||||||
@@ -36,7 +36,7 @@ spec:
|
|||||||
pathType: {{ default "Prefix" $.Values.ingress.pathType }}
|
pathType: {{ default "Prefix" $.Values.ingress.pathType }}
|
||||||
backend:
|
backend:
|
||||||
service:
|
service:
|
||||||
name: {{ $fullName }}-http
|
name: {{ include "gitea.service.http.name" $ }}
|
||||||
port:
|
port:
|
||||||
number: {{ $httpPort }}
|
number: {{ $httpPort }}
|
||||||
{{- else }}
|
{{- else }}
|
||||||
@@ -44,7 +44,7 @@ spec:
|
|||||||
pathType: {{ .pathType | default "Prefix" }}
|
pathType: {{ .pathType | default "Prefix" }}
|
||||||
backend:
|
backend:
|
||||||
service:
|
service:
|
||||||
name: {{ $fullName }}-http
|
name: {{ include "gitea.service.http.name" $ }}
|
||||||
port:
|
port:
|
||||||
number: {{ $httpPort }}
|
number: {{ $httpPort }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
@@ -54,7 +54,7 @@ spec:
|
|||||||
pathType: "Prefix"
|
pathType: "Prefix"
|
||||||
backend:
|
backend:
|
||||||
service:
|
service:
|
||||||
name: {{ $fullName }}-http
|
name: {{ include "gitea.service.http.name" $ }}
|
||||||
port:
|
port:
|
||||||
number: {{ $httpPort }}
|
number: {{ $httpPort }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ spec:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
to:
|
to:
|
||||||
kind: Service
|
kind: Service
|
||||||
name: {{ $fullName }}-http
|
name: {{ include "gitea.service.http.name" . }}
|
||||||
port:
|
port:
|
||||||
targetPort: http
|
targetPort: http
|
||||||
wildcardPolicy: {{ .Values.route.wildcardPolicy }}
|
wildcardPolicy: {{ .Values.route.wildcardPolicy }}
|
||||||
|
|||||||
@@ -1,15 +1,15 @@
|
|||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
name: {{ include "gitea.fullname" . }}-ssh
|
annotations:
|
||||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
{{- toYaml .Values.service.ssh.annotations | nindent 4 }}
|
||||||
labels:
|
labels:
|
||||||
{{- include "gitea.labels" . | nindent 4 }}
|
{{- include "gitea.labels" . | nindent 4 }}
|
||||||
{{- if .Values.service.ssh.labels }}
|
{{- if .Values.service.ssh.labels }}
|
||||||
{{- toYaml .Values.service.ssh.labels | nindent 4 }}
|
{{- toYaml .Values.service.ssh.labels | nindent 4 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
annotations:
|
name: {{ include "gitea.service.ssh.name" . }}
|
||||||
{{- toYaml .Values.service.ssh.annotations | nindent 4 }}
|
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||||
spec:
|
spec:
|
||||||
type: {{ .Values.service.ssh.type }}
|
type: {{ .Values.service.ssh.type }}
|
||||||
{{- if eq .Values.service.ssh.type "LoadBalancer" }}
|
{{- if eq .Values.service.ssh.type "LoadBalancer" }}
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
{{- if eq (include "gitea.tcpRoute.enabled" .) "true" -}}
|
||||||
|
---
|
||||||
|
apiVersion: gateway.networking.k8s.io/v1alpha2
|
||||||
|
kind: TCPRoute
|
||||||
|
metadata:
|
||||||
|
{{- with (include "gitea.tcpRoute.annotations" .) }}
|
||||||
|
annotations:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with (include "gitea.tcpRoute.labels" .) }}
|
||||||
|
labels:
|
||||||
|
{{- . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
name: {{ include "gitea.fullname" . }}
|
||||||
|
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||||
|
spec:
|
||||||
|
parentRefs:
|
||||||
|
{{- if .Values.gatewayAPI.core.tcpRoute.parentRefs }}
|
||||||
|
{{- toYaml .Values.gatewayAPI.core.tcpRoute.parentRefs | nindent 4 }}
|
||||||
|
{{- else }}
|
||||||
|
{{- fail "gatewayAPI.core.tcpRoute.parentRefs is required" }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- if .Values.gatewayAPI.core.tcpRoute.rules }}
|
||||||
|
{{- tpl (toYaml .Values.gatewayAPI.core.tcpRoute.rules) $ | nindent 4 }}
|
||||||
|
{{- else }}
|
||||||
|
- backendRefs:
|
||||||
|
- group: ""
|
||||||
|
kind: Service
|
||||||
|
name: {{ include "gitea.service.ssh.name" . }}
|
||||||
|
port: {{ .Values.service.ssh.port }}
|
||||||
|
weight: 1
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
@@ -22,6 +22,6 @@ spec:
|
|||||||
{{- $testContainerSecurityContext | nindent 8 }}
|
{{- $testContainerSecurityContext | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
command: ['wget']
|
command: ['wget']
|
||||||
args: ['{{ include "gitea.fullname" . }}-http:{{ .Values.service.http.port }}']
|
args: ['{{ include "gitea.service.http.name" . }}:{{ .Values.service.http.port }}']
|
||||||
restartPolicy: Never
|
restartPolicy: Never
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
@@ -103,3 +103,56 @@ tests:
|
|||||||
matchRegex:
|
matchRegex:
|
||||||
path: stringData.server
|
path: stringData.server
|
||||||
pattern: \nROOT_URL=https://route.example.com
|
pattern: \nROOT_URL=https://route.example.com
|
||||||
|
|
||||||
|
################################################
|
||||||
|
|
||||||
|
- it: "[HTTPRoute enabled] uses first hostname for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
||||||
|
template: templates/gitea/config.yaml
|
||||||
|
set:
|
||||||
|
ingress:
|
||||||
|
hosts: []
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
hostnames:
|
||||||
|
- gw.example.com
|
||||||
|
parentRefs:
|
||||||
|
- name: shared-gateway
|
||||||
|
asserts:
|
||||||
|
- documentIndex: 0
|
||||||
|
matchRegex:
|
||||||
|
path: stringData.server
|
||||||
|
pattern: \nDOMAIN=gw.example.com
|
||||||
|
- documentIndex: 0
|
||||||
|
matchRegex:
|
||||||
|
path: stringData.server
|
||||||
|
pattern: \nSSH_DOMAIN=gw.example.com
|
||||||
|
- documentIndex: 0
|
||||||
|
matchRegex:
|
||||||
|
path: stringData.server
|
||||||
|
pattern: \nROOT_URL=http://gw.example.com
|
||||||
|
|
||||||
|
################################################
|
||||||
|
|
||||||
|
- it: "[HTTPRoute tls] switches ROOT_URL to https"
|
||||||
|
template: templates/gitea/config.yaml
|
||||||
|
set:
|
||||||
|
ingress:
|
||||||
|
hosts: []
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
tls: true
|
||||||
|
hostnames:
|
||||||
|
- gw.example.com
|
||||||
|
parentRefs:
|
||||||
|
- name: shared-gateway
|
||||||
|
asserts:
|
||||||
|
- documentIndex: 0
|
||||||
|
matchRegex:
|
||||||
|
path: stringData.server
|
||||||
|
pattern: \nROOT_URL=https://gw.example.com
|
||||||
|
|||||||
@@ -1,13 +1,13 @@
|
|||||||
suite: ssh-svc / http-svc template (Services configuration)
|
suite: sshService / httpService template (Services configuration)
|
||||||
release:
|
release:
|
||||||
name: gitea-unittests
|
name: gitea-unittests
|
||||||
namespace: testing
|
namespace: testing
|
||||||
templates:
|
templates:
|
||||||
- templates/gitea/ssh-svc.yaml
|
- templates/gitea/sshService.yaml
|
||||||
- templates/gitea/http-svc.yaml
|
- templates/gitea/httpService.yaml
|
||||||
tests:
|
tests:
|
||||||
- it: supports adding custom labels to ssh-svc
|
- it: supports adding custom labels to sshService
|
||||||
template: templates/gitea/ssh-svc.yaml
|
template: templates/gitea/sshService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
ssh:
|
ssh:
|
||||||
@@ -19,7 +19,7 @@ tests:
|
|||||||
value: "testvalue"
|
value: "testvalue"
|
||||||
|
|
||||||
- it: keeps existing labels (ssh)
|
- it: keeps existing labels (ssh)
|
||||||
template: templates/gitea/ssh-svc.yaml
|
template: templates/gitea/sshService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
ssh:
|
ssh:
|
||||||
@@ -28,8 +28,8 @@ tests:
|
|||||||
- exists:
|
- exists:
|
||||||
path: metadata.labels["app"]
|
path: metadata.labels["app"]
|
||||||
|
|
||||||
- it: supports adding custom labels to http-svc
|
- it: supports adding custom labels to httpService
|
||||||
template: templates/gitea/http-svc.yaml
|
template: templates/gitea/httpService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
http:
|
http:
|
||||||
@@ -41,7 +41,7 @@ tests:
|
|||||||
value: "testvalue"
|
value: "testvalue"
|
||||||
|
|
||||||
- it: keeps existing labels (http)
|
- it: keeps existing labels (http)
|
||||||
template: templates/gitea/http-svc.yaml
|
template: templates/gitea/httpService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
http:
|
http:
|
||||||
@@ -51,7 +51,7 @@ tests:
|
|||||||
path: metadata.labels["app"]
|
path: metadata.labels["app"]
|
||||||
|
|
||||||
- it: render service.ssh.loadBalancerClass if set and type is LoadBalancer
|
- it: render service.ssh.loadBalancerClass if set and type is LoadBalancer
|
||||||
template: templates/gitea/ssh-svc.yaml
|
template: templates/gitea/sshService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
ssh:
|
ssh:
|
||||||
@@ -73,7 +73,7 @@ tests:
|
|||||||
value: ["1.2.3.4/32", "5.6.7.8/32"]
|
value: ["1.2.3.4/32", "5.6.7.8/32"]
|
||||||
|
|
||||||
- it: does not render when loadbalancer properties are set but type is not loadBalancerClass
|
- it: does not render when loadbalancer properties are set but type is not loadBalancerClass
|
||||||
template: templates/gitea/http-svc.yaml
|
template: templates/gitea/httpService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
http:
|
http:
|
||||||
@@ -92,7 +92,7 @@ tests:
|
|||||||
path: spec.loadBalancerSourceRanges
|
path: spec.loadBalancerSourceRanges
|
||||||
|
|
||||||
- it: does not render loadBalancerClass by default even when type is LoadBalancer
|
- it: does not render loadBalancerClass by default even when type is LoadBalancer
|
||||||
template: templates/gitea/http-svc.yaml
|
template: templates/gitea/httpService.yaml
|
||||||
set:
|
set:
|
||||||
service:
|
service:
|
||||||
http:
|
http:
|
||||||
@@ -107,8 +107,8 @@ tests:
|
|||||||
|
|
||||||
- it: both ssh and http services exist
|
- it: both ssh and http services exist
|
||||||
templates:
|
templates:
|
||||||
- templates/gitea/ssh-svc.yaml
|
- templates/gitea/sshService.yaml
|
||||||
- templates/gitea/http-svc.yaml
|
- templates/gitea/httpService.yaml
|
||||||
asserts:
|
asserts:
|
||||||
- matchRegex:
|
- matchRegex:
|
||||||
path: metadata.name
|
path: metadata.name
|
||||||
|
|||||||
@@ -0,0 +1,89 @@
|
|||||||
|
suite: Test Gateway API backendTLSPolicy.yaml
|
||||||
|
release:
|
||||||
|
name: gitea-unittests
|
||||||
|
namespace: testing
|
||||||
|
templates:
|
||||||
|
- templates/gitea/backendTLSPolicy.yaml
|
||||||
|
tests:
|
||||||
|
- it: should not render when gatewayAPI.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: false
|
||||||
|
core:
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: true
|
||||||
|
validation:
|
||||||
|
hostname: git.internal
|
||||||
|
caCertificateRefs:
|
||||||
|
- name: gitea-ca
|
||||||
|
group: ""
|
||||||
|
kind: ConfigMap
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should not render when backendTLSPolicy.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
gatewayAPI.core.backendTLSPolicy.enabled: false
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should render a BackendTLSPolicy targeting the http Service by default
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: true
|
||||||
|
validation:
|
||||||
|
hostname: git.internal
|
||||||
|
caCertificateRefs:
|
||||||
|
- name: gitea-ca
|
||||||
|
group: ""
|
||||||
|
kind: ConfigMap
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 1
|
||||||
|
- isKind:
|
||||||
|
of: BackendTLSPolicy
|
||||||
|
- equal:
|
||||||
|
path: apiVersion
|
||||||
|
value: gateway.networking.k8s.io/v1
|
||||||
|
- equal:
|
||||||
|
path: metadata.name
|
||||||
|
value: gitea-unittests
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRefs[0].name
|
||||||
|
value: gitea-unittests-http
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRefs[0].kind
|
||||||
|
value: Service
|
||||||
|
- equal:
|
||||||
|
path: spec.validation.hostname
|
||||||
|
value: git.internal
|
||||||
|
|
||||||
|
- it: should fail when validation is missing
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: true
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
|
||||||
|
|
||||||
|
- it: should fail when validation is an empty dict
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: true
|
||||||
|
validation: {}
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
|
||||||
@@ -0,0 +1,105 @@
|
|||||||
|
suite: Test Gateway API clientSettingsPolicy.yaml
|
||||||
|
release:
|
||||||
|
name: gitea-unittests
|
||||||
|
namespace: testing
|
||||||
|
templates:
|
||||||
|
- templates/gitea/clientSettingsPolicy.yaml
|
||||||
|
tests:
|
||||||
|
- it: should not render when gatewayAPI.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: false
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
body:
|
||||||
|
maxSize: 100m
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should not render when clientSettingsPolicies.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
gatewayAPI.nginx.clientSettingsPolicies.enabled: false
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should render a ClientSettingsPolicy targeting the HTTPRoute by default
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
body:
|
||||||
|
maxSize: 100m
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 1
|
||||||
|
- isKind:
|
||||||
|
of: ClientSettingsPolicy
|
||||||
|
- equal:
|
||||||
|
path: apiVersion
|
||||||
|
value: gateway.nginx.org/v1alpha1
|
||||||
|
- equal:
|
||||||
|
path: metadata.name
|
||||||
|
value: gitea-unittests
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRef.group
|
||||||
|
value: gateway.networking.k8s.io
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRef.kind
|
||||||
|
value: HTTPRoute
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRef.name
|
||||||
|
value: gitea-unittests
|
||||||
|
- equal:
|
||||||
|
path: spec.body.maxSize
|
||||||
|
value: 100m
|
||||||
|
|
||||||
|
- it: should honor a custom targetRef
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
targetRef:
|
||||||
|
group: gateway.networking.k8s.io
|
||||||
|
kind: Gateway
|
||||||
|
name: shared-gateway
|
||||||
|
body:
|
||||||
|
maxSize: 100m
|
||||||
|
asserts:
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRef.kind
|
||||||
|
value: Gateway
|
||||||
|
- equal:
|
||||||
|
path: spec.targetRef.name
|
||||||
|
value: shared-gateway
|
||||||
|
|
||||||
|
- it: should fail when body is missing
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: gatewayAPI.nginx.clientSettingsPolicies.body is required
|
||||||
|
|
||||||
|
- it: should fail when body is an empty dict
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
nginx:
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: true
|
||||||
|
body: {}
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: gatewayAPI.nginx.clientSettingsPolicies.body is required
|
||||||
@@ -0,0 +1,117 @@
|
|||||||
|
suite: Test Gateway API httpRoute.yaml
|
||||||
|
release:
|
||||||
|
name: gitea-unittests
|
||||||
|
namespace: testing
|
||||||
|
templates:
|
||||||
|
- templates/gitea/httpRoute.yaml
|
||||||
|
tests:
|
||||||
|
- it: should not render when gatewayAPI.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: false
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
hostnames:
|
||||||
|
- git.example.com
|
||||||
|
parentRefs:
|
||||||
|
- name: shared-gateway
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should not render when httpRoute.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
gatewayAPI.core.httpRoute.enabled: false
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should render a single HTTPRoute with default rule
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
annotations:
|
||||||
|
example.io/owner: gitea
|
||||||
|
hostnames:
|
||||||
|
- git.example.com
|
||||||
|
parentRefs:
|
||||||
|
- name: shared-gateway
|
||||||
|
namespace: gateway-system
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 1
|
||||||
|
- isKind:
|
||||||
|
of: HTTPRoute
|
||||||
|
- equal:
|
||||||
|
path: apiVersion
|
||||||
|
value: gateway.networking.k8s.io/v1
|
||||||
|
- equal:
|
||||||
|
path: metadata.name
|
||||||
|
value: gitea-unittests
|
||||||
|
- equal:
|
||||||
|
path: metadata.annotations["example.io/owner"]
|
||||||
|
value: gitea
|
||||||
|
- equal:
|
||||||
|
path: spec.parentRefs[0].name
|
||||||
|
value: shared-gateway
|
||||||
|
- equal:
|
||||||
|
path: spec.parentRefs[0].namespace
|
||||||
|
value: gateway-system
|
||||||
|
- equal:
|
||||||
|
path: spec.hostnames[0]
|
||||||
|
value: git.example.com
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].matches[0].path.value
|
||||||
|
value: /
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].group
|
||||||
|
value: ""
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].kind
|
||||||
|
value: Service
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].name
|
||||||
|
value: gitea-unittests-http
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].port
|
||||||
|
value: 3000
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].weight
|
||||||
|
value: 1
|
||||||
|
|
||||||
|
- it: should fail when parentRefs missing
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
hostnames:
|
||||||
|
- git.example.com
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: gatewayAPI.core.httpRoute.parentRefs is required
|
||||||
|
|
||||||
|
- it: hostname tpl rendering
|
||||||
|
set:
|
||||||
|
global:
|
||||||
|
giteaHostName: gitea.tpl.example.com
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
httpRoute:
|
||||||
|
enabled: true
|
||||||
|
hostnames:
|
||||||
|
- "{{ .Values.global.giteaHostName }}"
|
||||||
|
parentRefs:
|
||||||
|
- name: gw
|
||||||
|
asserts:
|
||||||
|
- equal:
|
||||||
|
path: spec.hostnames[0]
|
||||||
|
value: gitea.tpl.example.com
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
suite: Test Gateway API tcpRoute.yaml
|
||||||
|
release:
|
||||||
|
name: gitea-unittests
|
||||||
|
namespace: testing
|
||||||
|
templates:
|
||||||
|
- templates/gitea/tcpRoute.yaml
|
||||||
|
tests:
|
||||||
|
- it: should not render when gatewayAPI.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: false
|
||||||
|
core:
|
||||||
|
tcpRoute:
|
||||||
|
enabled: true
|
||||||
|
parentRefs:
|
||||||
|
- name: shared-gateway
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should not render when tcpRoute.enabled is false
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
gatewayAPI.core.tcpRoute.enabled: false
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 0
|
||||||
|
|
||||||
|
- it: should render a TCPRoute defaulting to the SSH service
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
tcpRoute:
|
||||||
|
enabled: true
|
||||||
|
parentRefs:
|
||||||
|
- name: shared-gateway
|
||||||
|
sectionName: ssh
|
||||||
|
asserts:
|
||||||
|
- hasDocuments:
|
||||||
|
count: 1
|
||||||
|
- isKind:
|
||||||
|
of: TCPRoute
|
||||||
|
- equal:
|
||||||
|
path: apiVersion
|
||||||
|
value: gateway.networking.k8s.io/v1alpha2
|
||||||
|
- equal:
|
||||||
|
path: metadata.name
|
||||||
|
value: gitea-unittests
|
||||||
|
- equal:
|
||||||
|
path: spec.parentRefs[0].sectionName
|
||||||
|
value: ssh
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].group
|
||||||
|
value: ""
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].kind
|
||||||
|
value: Service
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].name
|
||||||
|
value: gitea-unittests-ssh
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].port
|
||||||
|
value: 22
|
||||||
|
- equal:
|
||||||
|
path: spec.rules[0].backendRefs[0].weight
|
||||||
|
value: 1
|
||||||
|
|
||||||
|
- it: should fail when parentRefs missing
|
||||||
|
set:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
core:
|
||||||
|
tcpRoute:
|
||||||
|
enabled: true
|
||||||
|
asserts:
|
||||||
|
- failedTemplate:
|
||||||
|
errorMessage: gatewayAPI.core.tcpRoute.parentRefs is required
|
||||||
+93
-13
@@ -208,11 +208,94 @@ route:
|
|||||||
caCertificate:
|
caCertificate:
|
||||||
destinationCACertificate:
|
destinationCACertificate:
|
||||||
|
|
||||||
|
## @section Gateway API
|
||||||
|
## See docs/gateway-api.md for full guidance.
|
||||||
|
gatewayAPI:
|
||||||
|
## @param gatewayAPI.enabled Enable deployment of Gateway API resources
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
core:
|
||||||
|
## @param gatewayAPI.core.backendTLSPolicy.enabled Render a BackendTLSPolicy resource for encrypted backend traffic
|
||||||
|
## @param gatewayAPI.core.backendTLSPolicy.annotations Annotations applied to the BackendTLSPolicy
|
||||||
|
## @param gatewayAPI.core.backendTLSPolicy.labels Additional labels applied to the BackendTLSPolicy
|
||||||
|
## @param gatewayAPI.core.backendTLSPolicy.targetRefs Target references for the BackendTLSPolicy. Defaults to the HTTP service.
|
||||||
|
## @param gatewayAPI.core.backendTLSPolicy.validation Validation configuration (required when enabled). See `docs/gateway-api.md`.
|
||||||
|
## @extra gatewayAPI.core.backendTLSPolicy.validation.caCertificateRefs CA certificate references for the BackendTLSPolicy validation. See `docs/gateway-api.md`.
|
||||||
|
## @extra gatewayAPI.core.backendTLSPolicy.validation.hostname Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the gitea server certificate. See `docs/gateway-api.md`.
|
||||||
|
backendTLSPolicy:
|
||||||
|
enabled: false
|
||||||
|
annotations: {}
|
||||||
|
labels: {}
|
||||||
|
targetRefs: []
|
||||||
|
validation: {}
|
||||||
|
# caCertificateRefs:
|
||||||
|
# - name: gitea-ca
|
||||||
|
# group: ""
|
||||||
|
# kind: ConfigMap
|
||||||
|
# hostname: gitea-http
|
||||||
|
|
||||||
|
## @param gatewayAPI.core.httpRoute.enabled Render an HTTPRoute resource
|
||||||
|
## @param gatewayAPI.core.httpRoute.annotations Annotations applied to the HTTPRoute
|
||||||
|
## @param gatewayAPI.core.httpRoute.labels Additional labels applied to the HTTPRoute
|
||||||
|
## @param gatewayAPI.core.httpRoute.tls When true, treat the upstream Gateway as terminating TLS so `ROOT_URL` uses `https`.
|
||||||
|
## @param gatewayAPI.core.httpRoute.parentRefs Parent gateway references (required when enabled).
|
||||||
|
## @param gatewayAPI.core.httpRoute.hostnames List of hostnames for the HTTPRoute.
|
||||||
|
## @param gatewayAPI.core.httpRoute.rules Custom routing rules. Defaults to a PathPrefix `/` rule targeting the HTTP service.
|
||||||
|
httpRoute:
|
||||||
|
enabled: false
|
||||||
|
annotations: {}
|
||||||
|
labels: {}
|
||||||
|
tls: false
|
||||||
|
parentRefs: []
|
||||||
|
# - group: gateway.networking.k8s.io
|
||||||
|
# kind: Gateway
|
||||||
|
# name: shared-gateway
|
||||||
|
# namespace: gateway-system
|
||||||
|
# sectionName: http
|
||||||
|
hostnames: []
|
||||||
|
# - git.example.com
|
||||||
|
rules: []
|
||||||
|
|
||||||
|
|
||||||
|
## @param gatewayAPI.core.tcpRoute.enabled Render a TCPRoute resource (typically for SSH)
|
||||||
|
## @param gatewayAPI.core.tcpRoute.annotations Annotations applied to the TCPRoute
|
||||||
|
## @param gatewayAPI.core.tcpRoute.labels Additional labels applied to the TCPRoute
|
||||||
|
## @param gatewayAPI.core.tcpRoute.parentRefs Parent gateway references (required when enabled).
|
||||||
|
## @param gatewayAPI.core.tcpRoute.rules Custom routing rules. Defaults to a rule targeting the SSH service.
|
||||||
|
tcpRoute:
|
||||||
|
enabled: false
|
||||||
|
annotations: {}
|
||||||
|
labels: {}
|
||||||
|
parentRefs: []
|
||||||
|
# - group: gateway.networking.k8s.io
|
||||||
|
# kind: Gateway
|
||||||
|
# name: shared-gateway
|
||||||
|
# namespace: gateway-system
|
||||||
|
# sectionName: ssh
|
||||||
|
rules: []
|
||||||
|
|
||||||
|
|
||||||
|
## NGINX Gateway Fabric specific resources. Only relevant when the upstream
|
||||||
|
## Gateway is backed by NGINX Gateway Fabric (nginx.org). Other implementations
|
||||||
|
## (Envoy Gateway, Cilium, ...) do not impose a default request body size limit.
|
||||||
|
nginx:
|
||||||
|
## @param gatewayAPI.nginx.clientSettingsPolicies.enabled Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit
|
||||||
|
## @param gatewayAPI.nginx.clientSettingsPolicies.annotations Annotations applied to the ClientSettingsPolicy
|
||||||
|
## @param gatewayAPI.nginx.clientSettingsPolicies.labels Additional labels applied to the ClientSettingsPolicy
|
||||||
|
## @param gatewayAPI.nginx.clientSettingsPolicies.targetRef Target reference for the ClientSettingsPolicy. Defaults to the chart's HTTPRoute.
|
||||||
|
## @param gatewayAPI.nginx.clientSettingsPolicies.body Client body settings (required when enabled), e.g. `maxSize`. See `docs/gateway-api.md`.
|
||||||
|
clientSettingsPolicies:
|
||||||
|
enabled: false
|
||||||
|
annotations: {}
|
||||||
|
labels: {}
|
||||||
|
targetRef: {}
|
||||||
|
body: {}
|
||||||
|
# maxSize: 100m
|
||||||
|
|
||||||
## @section deployment
|
## @section deployment
|
||||||
#
|
#
|
||||||
## @param resources Kubernetes resources
|
## @param resources Kubernetes resources
|
||||||
resources:
|
resources: {}
|
||||||
{}
|
|
||||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
# choice for the user. This also increases chances charts run on environments with little
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
@@ -253,10 +336,9 @@ priorityClassName: ""
|
|||||||
## @param deployment.labels Labels for the deployment
|
## @param deployment.labels Labels for the deployment
|
||||||
## @param deployment.annotations Annotations for the Gitea deployment to be created
|
## @param deployment.annotations Annotations for the Gitea deployment to be created
|
||||||
deployment:
|
deployment:
|
||||||
env:
|
env: []
|
||||||
[]
|
# - name: VARIABLE
|
||||||
# - name: VARIABLE
|
# value: my-value
|
||||||
# value: my-value
|
|
||||||
terminationGracePeriodSeconds: 60
|
terminationGracePeriodSeconds: 60
|
||||||
labels: {}
|
labels: {}
|
||||||
annotations: {}
|
annotations: {}
|
||||||
@@ -423,8 +505,7 @@ gitea:
|
|||||||
tlsConfig: {}
|
tlsConfig: {}
|
||||||
|
|
||||||
## @param gitea.ldap LDAP configuration
|
## @param gitea.ldap LDAP configuration
|
||||||
ldap:
|
ldap: []
|
||||||
[]
|
|
||||||
# - name: "LDAP 1"
|
# - name: "LDAP 1"
|
||||||
# existingSecret:
|
# existingSecret:
|
||||||
# securityProtocol:
|
# securityProtocol:
|
||||||
@@ -441,8 +522,7 @@ gitea:
|
|||||||
|
|
||||||
# Either specify inline `key` and `secret` or refer to them via `existingSecret`
|
# Either specify inline `key` and `secret` or refer to them via `existingSecret`
|
||||||
## @param gitea.oauth OAuth configuration
|
## @param gitea.oauth OAuth configuration
|
||||||
oauth:
|
oauth: []
|
||||||
[]
|
|
||||||
# - name: 'OAuth 1'
|
# - name: 'OAuth 1'
|
||||||
# provider:
|
# provider:
|
||||||
# key:
|
# key:
|
||||||
@@ -659,9 +739,9 @@ valkey:
|
|||||||
repository: bitnamilegacy/redis-exporter
|
repository: bitnamilegacy/redis-exporter
|
||||||
|
|
||||||
primary:
|
primary:
|
||||||
## @param valkey.primary.persistence.enabled Enable persistence on Valkey replicas nodes using Persistent Volume Claims.
|
## @param valkey.primary.persistence.enabled Enable persistence on Valkey replicas nodes using Persistent Volume Claims.
|
||||||
## @param valkey.primary.persistence.storageClass Persistent Volume storage class.
|
## @param valkey.primary.persistence.storageClass Persistent Volume storage class.
|
||||||
## @param valkey.primary.persistence.size Persistent Volume size.
|
## @param valkey.primary.persistence.size Persistent Volume size.
|
||||||
persistence:
|
persistence:
|
||||||
enabled: true
|
enabled: true
|
||||||
storageClass: ""
|
storageClass: ""
|
||||||
|
|||||||
Reference in New Issue
Block a user