feat: add Gateway API support (#1073)

Add full Gateway API support for exposing Gitea via HTTPRoute, TCPRoute, BackendTLSPolicy, and ClientSettingsPolicy resources.

New templates:
- `httpRoute.yaml` — renders an HTTPRoute with configurable
  parentRefs, hostnames, and rules (defaults to PathPrefix `/`)
- `tcpRoute.yaml` — renders a TCPRoute for SSH traffic
- `backendTLSPolicy.yaml` — renders a BackendTLSPolicy for
  encrypted backend connections with required validation config
- `clientSettingsPolicy.yaml` — renders an NGINX Gateway Fabric
  ClientSettingsPolicy to raise the request body size limit

Infrastructure:
- `gatewayAPI.enabled` global toggle gates all resources
- Resources grouped under `gatewayAPI.core.*` and `gatewayAPI.nginx.*`
- Helper templates extracted into dedicated `_*.tpl` files
- Service name helpers (`gitea.service.http.name`, `gitea.service.ssh.name`)
  extracted into `_services.tpl`; service templates renamed to camelCase
- `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` auto-resolve from
  `httpRoute.hostnames[0]`; `httpRoute.tls` switches to `https`

Documentation:
- New `docs/gateway-api.md` with topology examples, BackendTLSPolicy
  setup, sectionName guidance, SSH considerations, and NGINX body
  size limit configuration
- `.github/copilot-instructions.md` with project conventions
- README parameter table auto-generated via `make readme`

Tests:
- Helm unit tests for all four new resource templates
- Config tests for hostname/TLS resolution from Gateway API values

Co-authored-by: Todd Marimon <toddmarimon@gmail.com>
This commit is contained in:
Todd Marimon
2026-07-19 16:25:28 +00:00
committed by Markus Pesch
parent 5005037dbf
commit 7747a001f7
25 changed files with 1200 additions and 40 deletions
+62
View File
@@ -0,0 +1,62 @@
# Gitea Helm Chart — Copilot Instructions
## Project Overview
Kubernetes Helm chart for deploying [Gitea](https://gitea.com). Uses Go/Helm templating (`templates/`), YAML values (`values.yaml`), and includes sub-charts for PostgreSQL, PostgreSQL-HA, Valkey, and Valkey-cluster.
## Build & Test
```bash
make readme # Regenerate README.md parameter table + lint
make unittests-helm # Run Helm unit tests (helm-unittest plugin required)
make unittests-bash # Run bash/bats script tests (requires git submodule init)
make unittests # Both of the above
```
Always run `make readme` after changing `values.yaml` `@param` annotations.
Always run `make unittests-helm` after changing templates or unit tests.
## Conventions
### values.yaml
- Use `## @param path.to.key Description` annotations for every user-facing value. These drive the auto-generated README parameter table.
- Property ordering within a resource block: `enabled`, `annotations`, `labels` first, then type-specific fields.
- Top-level keys are sorted alphabetically within their section group.
- Use [Helm Values](https://docs.renovatebot.com/modules/manager/helm-values/#additional-information) pattern from renovatebot. Ensure that the attributes `registry`, `repository` and `tag` are available as part of the dict `image`. For example:
```yaml
image:
registry: docker.io
repository: library/busybox
tag: 0.1.0
```
### Templates
- Helm templates live in `templates/gitea/`. Helpers live in `templates/_helpers.tpl`.
- Use camelCase for all files and variables (e.g `httpRoute`, `backendTLSPolicy`, `gatewayAPI`, `statefulSet`).
- Use `include "gitea.fullname"` for naming resources.
- Use `fail` for required-value validation with clear error messages referencing the full values path.
- Ensure, that the attributes `annotations`, `labels`, `name` and `namespace` are alphabetically sorted.
- Render all attributes, even if they are empty, to prevent drift in Argo CD. For example, `labels` must be rendered, while `annotations` are defined as `yaml:"annotations,omitempty"`.
- Use plural for `*.tpl` files, because they may contain functions for multiple resources of the same kind (e.g. `_services.tpl` for `httpService.yaml` or `sshService.yaml`, `_backendTLSPolicies.tpl` for `backendTLSPolicy.yaml`).
### Unit Tests
- Helm unit tests live in `unittests/helm/` mirroring the template structure.
- Test files are YAML using the [helm-unittest](https://github.com/helm-unittest/helm-unittest) format.
- Each test must set all required values explicitly — do not rely on cross-test state.
- The `values.yaml` file must pass `yamllint`. The configuration is in `.yamllint`. Use `make yamllint` to run the linter.
### Commits & PRs
- Follow [Conventional Commits](https://www.conventionalcommits.org/en/v1.0.0/) for PR titles and commit messages (e.g. `feat:`, `fix:`, `refactor:`, `docs:`, `style:`).
- See `CONTRIBUTING.md` for full PR requirements.
- Explain in detail why a change is needed, not just what the change is. Include links to relevant issues, PRs, or external references.
- Add co-authors for any contributions that are not your own. Use the `Co-authored-by:` trailer in the commit message.
### Documentation
- `docs/` contains topic-specific guides (e.g. `gateway-api.md`, `ha-setup.md`).
- `README.md` parameter tables are auto-generated — never edit them manually.
+37
View File
@@ -43,6 +43,8 @@
- [Security](#security)
- [Service](#service)
- [Ingress](#ingress)
- [Route](#route)
- [Gateway API](#gateway-api)
- [deployment](#deployment)
- [ServiceAccount](#serviceaccount)
- [Persistence](#persistence-1)
@@ -311,6 +313,11 @@ route:
When `route.host` is set, the chart uses it for `DOMAIN`, `SSH_DOMAIN`, and `ROOT_URL`. Setting `route.tls.termination` also switches the default `ROOT_URL` scheme to `https`.
#### Gateway API
The chart can also expose Gitea through Gateway API resources (`HTTPRoute`, `TCPRoute`, `BackendTLSPolicy`, and optionally `Gateway`).
See [docs/gateway-api.md](docs/gateway-api.md) for the full guide, including how routes interact with `ROOT_URL`/`DOMAIN` resolution and recommended topologies.
#### Session, Cache and Queue
The session, cache and queue settings are set to use the built-in Valkey Cluster sub-chart dependency.
@@ -1075,6 +1082,36 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
| `route.tls.caCertificate` | Route TLS CA certificate | `nil` |
| `route.tls.destinationCACertificate` | Route destination CA certificate | `nil` |
### Gateway API
| Name | Description | Value |
| --------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `gatewayAPI.enabled` | Enable deployment of Gateway API resources | `false` |
| `gatewayAPI.core.backendTLSPolicy.enabled` | Render a BackendTLSPolicy resource for encrypted backend traffic | `false` |
| `gatewayAPI.core.backendTLSPolicy.annotations` | Annotations applied to the BackendTLSPolicy | `{}` |
| `gatewayAPI.core.backendTLSPolicy.labels` | Additional labels applied to the BackendTLSPolicy | `{}` |
| `gatewayAPI.core.backendTLSPolicy.targetRefs` | Target references for the BackendTLSPolicy. Defaults to the HTTP service. | `[]` |
| `gatewayAPI.core.backendTLSPolicy.validation` | Validation configuration (required when enabled). See `docs/gateway-api.md`. | `{}` |
| `gatewayAPI.core.backendTLSPolicy.validation.caCertificateRefs` | CA certificate references for the BackendTLSPolicy validation. See `docs/gateway-api.md`. | |
| `gatewayAPI.core.backendTLSPolicy.validation.hostname` | Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the Gitea server certificate. See `docs/gateway-api.md`. | |
| `gatewayAPI.core.httpRoute.enabled` | Render an HTTPRoute resource | `false` |
| `gatewayAPI.core.httpRoute.annotations` | Annotations applied to the HTTPRoute | `{}` |
| `gatewayAPI.core.httpRoute.labels` | Additional labels applied to the HTTPRoute | `{}` |
| `gatewayAPI.core.httpRoute.tls` | When true, treat the upstream Gateway as terminating TLS so `ROOT_URL` uses `https`. | `false` |
| `gatewayAPI.core.httpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
| `gatewayAPI.core.httpRoute.hostnames` | List of hostnames for the HTTPRoute. | `[]` |
| `gatewayAPI.core.httpRoute.rules` | Custom routing rules. Defaults to a PathPrefix `/` rule targeting the HTTP service. | `[]` |
| `gatewayAPI.core.tcpRoute.enabled` | Render a TCPRoute resource (typically for SSH) | `false` |
| `gatewayAPI.core.tcpRoute.annotations` | Annotations applied to the TCPRoute | `{}` |
| `gatewayAPI.core.tcpRoute.labels` | Additional labels applied to the TCPRoute | `{}` |
| `gatewayAPI.core.tcpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
| `gatewayAPI.core.tcpRoute.rules` | Custom routing rules. Defaults to a rule targeting the SSH service. | `[]` |
| `gatewayAPI.nginx.clientSettingsPolicies.enabled` | Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit | `false` |
| `gatewayAPI.nginx.clientSettingsPolicies.annotations` | Annotations applied to the ClientSettingsPolicy | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.labels` | Additional labels applied to the ClientSettingsPolicy | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.targetRef` | Target reference for the ClientSettingsPolicy. Defaults to the chart's HTTPRoute. | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.body` | Client body settings (required when enabled), e.g. `maxSize`. See `docs/gateway-api.md`. | `{}` |
### deployment
| Name | Description | Value |
+267
View File
@@ -0,0 +1,267 @@
# Gateway API
This chart can expose Gitea through [Kubernetes Gateway API](https://gateway-api.sigs.k8s.io/) resources
alongside (or instead of) the existing `Ingress` and OpenShift `Route` support. The following resources
are rendered:
- `HTTPRoute` — required for HTTP traffic
- `TCPRoute` — optional, typically for SSH (port 22)
- `BackendTLSPolicy` — optional, for encrypted backend traffic
- `ClientSettingsPolicy` — optional, **NGINX Gateway Fabric only**, to raise the client request body size limit
All resources are disabled by default. Enabling them requires Gateway API CRDs (and an implementation that supports them) to already be installed in the cluster.
The chart does **not** render a `Gateway` resource — provisioning and managing the Gateway is the responsibility of the cluster / platform administrator.
## Prerequisites
| Resource | API version | Status (as of writing) |
| ---------------------- | ------------------------------------ | ---------------------- |
| `HTTPRoute` | `gateway.networking.k8s.io/v1` | GA |
| `TCPRoute` | `gateway.networking.k8s.io/v1alpha2` | Experimental |
| `BackendTLSPolicy` | `gateway.networking.k8s.io/v1` | GA (v1.2+) |
| `ClientSettingsPolicy` | `gateway.nginx.org/v1alpha1` | NGINX Gateway Fabric |
## Common topology
Most users should attach to a pre-existing, shared `Gateway` managed by the cluster administrator:
```yaml
gatewayAPI:
core:
httpRoute:
enabled: true
tls: true # the shared Gateway terminates TLS
hostnames:
- git.example.com
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: shared-gateway
namespace: gateway-system
sectionName: https-gitea # pin to a specific listener (see below)
tcpRoute:
enabled: true
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: shared-gateway
namespace: gateway-system
sectionName: ssh
```
With this configuration:
- `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` resolve to the first HTTPRoute hostname.
- Setting `gatewayAPI.core.httpRoute.tls: true` switches `ROOT_URL` to `https://`.
- The default HTTPRoute rule forwards `/` to the Gitea HTTP `Service`. The default TCPRoute rule forwards to the SSH `Service`.
- Custom `rules` and `hostnames` are rendered through `tpl`, so Helm template expressions work inside them.
### Why `sectionName` matters
Omitting `sectionName` attaches the route to **every** matching listener on the Gateway. On implementations
that use per-host HTTPS listeners (Envoy Gateway, Cilium Gateway), that means Gitea's HTTPRoute will try
to bind to every HTTPS listener — usually not what you want. Always pin to a named listener
(e.g. `https-gitea`, `ssh`) when the Gateway has more than one. The corresponding listener on the Gateway
side typically looks like:
```yaml
listeners:
- name: https-gitea
port: 443
protocol: HTTPS
hostname: git.example.com
tls:
certificateRefs:
- name: git-example-com-tls
allowedRoutes:
kinds:
- kind: HTTPRoute
namespaces:
from: Selector
selector:
matchLabels:
kubernetes.io/metadata.name: gitea
- name: ssh
port: 22
protocol: TCP
allowedRoutes:
kinds:
- kind: TCPRoute
namespaces:
from: Selector
selector:
matchLabels:
kubernetes.io/metadata.name: gitea
```
### Sharing a hostname between HTTP and SSH
HTTP (443) and SSH (22) are different ports, so a single hostname like `git.example.com` can serve both —
clients disambiguate by port. This is the recommended pattern: one DNS record, `ssh git@git.example.com`
and `https://git.example.com` both work, and `SSH_DOMAIN` / `DOMAIN` resolve to the same value with no
extra configuration.
If you want SSH on a **different** hostname (e.g. `gitea-ssh.example.com`), set it explicitly — the chart
cannot infer it from TCPRoute config because TCPRoutes don't carry hostnames:
```yaml
gitea:
config:
server:
SSH_DOMAIN: gitea-ssh.example.com
```
## BackendTLSPolicy
Use this when the Gitea HTTP backend is terminating TLS itself (for example, when running Gitea with
`PROTOCOL=https`, or when fronting another HTTPS service from the same chart) and the Gateway needs to
verify the backend certificate before forwarding the request.
### Configuring Gitea to serve HTTPS directly
Gitea serves HTTPS via three `[server]` app.ini options
([cheat sheet](https://docs.gitea.com/administration/config-cheat-sheet#server-server)). Mount the
cert/key with `extraVolumes` + `extraContainerVolumeMounts` and point Gitea at them with absolute paths:
```yaml
gitea:
config:
server:
PROTOCOL: https
CERT_FILE: /etc/gitea-tls/tls.crt
KEY_FILE: /etc/gitea-tls/tls.key
extraVolumes:
- name: gitea-tls
secret:
secretName: gitea-backend-tls # cert-manager-issued Secret, etc.
extraContainerVolumeMounts:
- name: gitea-tls
mountPath: /etc/gitea-tls
readOnly: true
```
- Relative `CERT_FILE`/`KEY_FILE` values resolve against Gitea's `CustomPath` (`/data/gitea` in the
official image); absolute paths are clearer.
- Both options are ignored when `gitea.config.server.ENABLE_ACME` is `true`.
- For chained certs, the server cert comes first, intermediates after.
- The Service still forwards raw TCP — no `service.http.*` changes needed. The pod's container port
(3000 by default) is now speaking HTTPS instead of HTTP.
### BackendTLSPolicy example
Verify the backend with a CA bundle stored in a `ConfigMap`:
```yaml
gatewayAPI:
core:
backendTLSPolicy:
enabled: true
validation:
hostname: gitea.svc.cluster.local
caCertificateRefs:
- name: gitea-backend-ca
group: ""
kind: ConfigMap
```
This renders a single `BackendTLSPolicy` whose `targetRefs` defaults to the chart's HTTP `Service`
(`<fullname>-http`), and whose `validation` is passed through verbatim. `validation` is required by the
API; the template fails fast if omitted.
### System CA trust and explicit targetRefs
To trust the system CA store (Gateway API v1.1+) or target a different Service, use `wellKnownCACertificates`
and `targetRefs`:
```yaml
gatewayAPI:
core:
backendTLSPolicy:
enabled: true
targetRefs:
- group: ""
kind: Service
name: gitea-sidecar
validation:
hostname: sidecar.gitea.svc.cluster.local
wellKnownCACertificates: System
```
Notes:
- `targetRefs[].kind` is almost always `Service`; `group: ""` is the core API group.
- `wellKnownCACertificates: System` requires Gateway API v1.1 and an implementation that supports it
(otherwise stick with `caCertificateRefs`).
- The corresponding HTTPRoute must reference the backend by the same `Service` (and, if used,
`sectionName`/`port`) — `BackendTLSPolicy` attaches to the Service-side reference, not to the route.
## Raising the request body size limit (NGINX Gateway Fabric)
NGINX defaults `client_max_body_size` to `1m`. Requests exceeding it are rejected with `413 Request
Entity Too Large`. This blocks uploading larger artifacts to Gitea's package/container registry (container
images, DEB/RPM packages, etc.). With the NGINX **Ingress** controller you raised this via the
`nginx.ingress.kubernetes.io/proxy-body-size` annotation — that annotation does **not** apply to Gateway
API. NGINX Gateway Fabric instead reads the limit from a
[`ClientSettingsPolicy`](https://docs.nginx.com/nginx-gateway-fabric/reference/api/) (`spec.body.maxSize`).
This is specific to **NGINX Gateway Fabric**. Other implementations (Envoy Gateway, Cilium, Istio, …) do
**not** impose a default request body size limit, so large uploads work without any extra configuration —
leave `gatewayAPI.nginx.clientSettingsPolicies` disabled.
```yaml
gatewayAPI:
enabled: true
nginx:
clientSettingsPolicies:
enabled: true
body:
maxSize: 100m # bytes, or with a k / m / g suffix; 0 disables the limit
```
This renders a single `ClientSettingsPolicy` whose `targetRef` defaults to the chart's `HTTPRoute`
(`<fullname>`), so the limit applies to all traffic routed to Gitea. `body` is required when enabled; the
template fails fast if omitted. `spec.body` is passed through verbatim, so other fields (e.g. `timeout`)
are supported too.
To attach the policy elsewhere — for example the whole `Gateway` so the limit is inherited by every route —
override `targetRef`:
```yaml
gatewayAPI:
nginx:
clientSettingsPolicies:
enabled: true
targetRef:
group: gateway.networking.k8s.io
kind: Gateway
name: shared-gateway
body:
maxSize: 100m
```
Notes:
- `ClientSettingsPolicy` is an inherited policy: attaching it to a `Gateway` cascades to its routes, while
attaching it to an `HTTPRoute` scopes it to that route only.
- The policy must live in the same namespace as its `targetRef`.
- Gitea also enforces its own upload limits independently (`gitea.config` `[repository.upload]` and
`[packages]` sections) — raising the proxy limit alone is not always sufficient.
## Interaction with `ingress` and `route`
The three exposure mechanisms are independent and can coexist, but `ROOT_URL` / `DOMAIN` / `SSH_DOMAIN` resolution uses the first defined source in this order:
1. `route.host` (when `route.enabled`)
2. `httpRoute.hostnames[0]` (when `gatewayAPI.core.httpRoute.enabled`)
3. First `ingress.hosts[0].host`
4. The in-cluster Service DNS name
Likewise, `ROOT_URL` becomes `https://` if any of these terminate TLS: `route.tls.termination`, `ingress.tls`, or `gatewayAPI.core.httpRoute.tls`.
## SSH considerations
- `TCPRoute` is still experimental. Many production-grade implementations support it (Envoy Gateway, Istio, Kgateway, NGINX Gateway Fabric), but you should verify before relying on it.
- If your Gateway implementation does not support `TCPRoute`, keep using `service.ssh.type: LoadBalancer` (or `NodePort`) and only enable `httpRoute` for HTTP traffic.
- The default TCPRoute rule points at the Gitea SSH `Service` on `service.ssh.port` (typically 22), which itself proxies to `gitea.config.server.SSH_LISTEN_PORT` inside the pod.
+4
View File
@@ -247,6 +247,8 @@ app.kubernetes.io/instance: {{ .Release.Name }}
{{- define "gitea.public_hostname" -}}
{{- if and .Values.route.enabled .Values.route.host -}}
{{ tpl .Values.route.host . }}
{{- else if and .Values.gatewayAPI.enabled .Values.gatewayAPI.core.httpRoute.enabled (gt (len .Values.gatewayAPI.core.httpRoute.hostnames) 0) -}}
{{ tpl (index .Values.gatewayAPI.core.httpRoute.hostnames 0) $ }}
{{- else if gt (len .Values.ingress.hosts) 0 -}}
{{ tpl (index .Values.ingress.hosts 0).host $ }}
{{- else -}}
@@ -308,6 +310,8 @@ app.kubernetes.io/instance: {{ .Release.Name }}
https
{{- else if and .Values.ingress.enabled (gt (len .Values.ingress.tls) 0) -}}
https
{{- else if and .Values.gatewayAPI.enabled .Values.gatewayAPI.core.httpRoute.enabled .Values.gatewayAPI.core.httpRoute.tls -}}
https
{{- else -}}
{{ .Values.gitea.config.server.PROTOCOL }}
{{- end -}}
+30
View File
@@ -0,0 +1,30 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.backendTLSPolicy.annotations" -}}
{{- with .Values.gatewayAPI.core.backendTLSPolicy.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.backendTLSPolicy.enabled" -}}
{{- if and .Values.gatewayAPI.enabled
.Values.gatewayAPI.core.backendTLSPolicy.enabled
-}}
true
{{- else -}}
false
{{- end -}}
{{- end }}
{{/* labels */}}
{{- define "gitea.backendTLSPolicy.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.gatewayAPI.core.backendTLSPolicy.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
@@ -0,0 +1,30 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.clientSettingsPolicies.annotations" -}}
{{- with .Values.gatewayAPI.nginx.clientSettingsPolicies.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.clientSettingsPolicies.enabled" -}}
{{- if and .Values.gatewayAPI.enabled
.Values.gatewayAPI.nginx.clientSettingsPolicies.enabled
-}}
true
{{- else -}}
false
{{- end -}}
{{- end }}
{{/* labels */}}
{{- define "gitea.clientSettingsPolicies.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.gatewayAPI.nginx.clientSettingsPolicies.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
+30
View File
@@ -0,0 +1,30 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.httpRoute.annotations" -}}
{{- with .Values.gatewayAPI.core.httpRoute.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.httpRoute.enabled" -}}
{{- if and .Values.gatewayAPI.enabled
.Values.gatewayAPI.core.httpRoute.enabled
-}}
true
{{- else -}}
false
{{- end -}}
{{- end }}
{{/* labels */}}
{{- define "gitea.httpRoute.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.gatewayAPI.core.httpRoute.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
+11
View File
@@ -0,0 +1,11 @@
{{/* vim: set filetype=mustache: */}}
{{/* names */}}
{{- define "gitea.service.http.name" -}}
{{ include "gitea.fullname" . }}-http
{{- end }}
{{- define "gitea.service.ssh.name" -}}
{{ include "gitea.fullname" . }}-ssh
{{- end }}
+30
View File
@@ -0,0 +1,30 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.tcpRoute.annotations" -}}
{{- with .Values.gatewayAPI.core.tcpRoute.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.tcpRoute.enabled" -}}
{{- if and .Values.gatewayAPI.enabled
.Values.gatewayAPI.core.tcpRoute.enabled
-}}
true
{{- else -}}
false
{{- end -}}
{{- end }}
{{/* labels */}}
{{- define "gitea.tcpRoute.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.gatewayAPI.core.tcpRoute.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
+30
View File
@@ -0,0 +1,30 @@
{{- if eq (include "gitea.backendTLSPolicy.enabled" .) "true" -}}
{{- if not (keys .Values.gatewayAPI.core.backendTLSPolicy.validation) }}
{{- fail "gatewayAPI.core.backendTLSPolicy.validation is required" }}
{{- end }}
---
apiVersion: gateway.networking.k8s.io/v1
kind: BackendTLSPolicy
metadata:
{{- with (include "gitea.backendTLSPolicy.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.backendTLSPolicy.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.fullname" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
spec:
targetRefs:
{{- if .Values.gatewayAPI.core.backendTLSPolicy.targetRefs }}
{{- toYaml .Values.gatewayAPI.core.backendTLSPolicy.targetRefs | nindent 4 }}
{{- else }}
- group: ""
kind: Service
name: {{ include "gitea.service.http.name" . }}
{{- end }}
validation:
{{- toYaml .Values.gatewayAPI.core.backendTLSPolicy.validation | nindent 4 }}
{{- end }}
+30
View File
@@ -0,0 +1,30 @@
{{- if eq (include "gitea.clientSettingsPolicies.enabled" .) "true" -}}
{{- if not (keys .Values.gatewayAPI.nginx.clientSettingsPolicies.body) }}
{{- fail "gatewayAPI.nginx.clientSettingsPolicies.body is required" }}
{{- end }}
---
apiVersion: gateway.nginx.org/v1alpha1
kind: ClientSettingsPolicy
metadata:
{{- with (include "gitea.clientSettingsPolicies.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.clientSettingsPolicies.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.fullname" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
spec:
targetRef:
{{- if .Values.gatewayAPI.nginx.clientSettingsPolicies.targetRef }}
{{- toYaml .Values.gatewayAPI.nginx.clientSettingsPolicies.targetRef | nindent 4 }}
{{- else }}
group: gateway.networking.k8s.io
kind: HTTPRoute
name: {{ include "gitea.fullname" . }}
{{- end }}
body:
{{- toYaml .Values.gatewayAPI.nginx.clientSettingsPolicies.body | nindent 4 }}
{{- end }}
+42
View File
@@ -0,0 +1,42 @@
{{- if eq (include "gitea.httpRoute.enabled" .) "true" -}}
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
{{- with (include "gitea.httpRoute.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.httpRoute.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.fullname" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
spec:
parentRefs:
{{- if .Values.gatewayAPI.core.httpRoute.parentRefs }}
{{- toYaml .Values.gatewayAPI.core.httpRoute.parentRefs | nindent 4 }}
{{- else }}
{{- fail "gatewayAPI.core.httpRoute.parentRefs is required" }}
{{- end }}
{{- with .Values.gatewayAPI.core.httpRoute.hostnames }}
hostnames:
{{- tpl (toYaml .) $ | nindent 4 }}
{{- end }}
rules:
{{- if .Values.gatewayAPI.core.httpRoute.rules }}
{{- tpl (toYaml .Values.gatewayAPI.core.httpRoute.rules) $ | nindent 4 }}
{{- else }}
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- group: ""
kind: Service
name: {{ include "gitea.service.http.name" . }}
port: {{ .Values.service.http.port }}
weight: 1
{{- end }}
{{- end }}
@@ -1,15 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "gitea.fullname" . }}-http
namespace: {{ .Values.namespace | default .Release.Namespace }}
annotations:
{{- toYaml .Values.service.http.annotations | nindent 4 }}
labels:
{{- include "gitea.labels" . | nindent 4 }}
{{- if .Values.service.http.labels }}
{{- toYaml .Values.service.http.labels | nindent 4 }}
{{- end }}
annotations:
{{- toYaml .Values.service.http.annotations | nindent 4 }}
name: {{ include "gitea.service.http.name" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
spec:
type: {{ .Values.service.http.type }}
{{- if eq .Values.service.http.type "LoadBalancer" }}
+3 -3
View File
@@ -36,7 +36,7 @@ spec:
pathType: {{ default "Prefix" $.Values.ingress.pathType }}
backend:
service:
name: {{ $fullName }}-http
name: {{ include "gitea.service.http.name" $ }}
port:
number: {{ $httpPort }}
{{- else }}
@@ -44,7 +44,7 @@ spec:
pathType: {{ .pathType | default "Prefix" }}
backend:
service:
name: {{ $fullName }}-http
name: {{ include "gitea.service.http.name" $ }}
port:
number: {{ $httpPort }}
{{- end }}
@@ -54,7 +54,7 @@ spec:
pathType: "Prefix"
backend:
service:
name: {{ $fullName }}-http
name: {{ include "gitea.service.http.name" $ }}
port:
number: {{ $httpPort }}
{{- end }}
+1 -1
View File
@@ -20,7 +20,7 @@ spec:
{{- end }}
to:
kind: Service
name: {{ $fullName }}-http
name: {{ include "gitea.service.http.name" . }}
port:
targetPort: http
wildcardPolicy: {{ .Values.route.wildcardPolicy }}
@@ -1,15 +1,15 @@
apiVersion: v1
kind: Service
metadata:
name: {{ include "gitea.fullname" . }}-ssh
namespace: {{ .Values.namespace | default .Release.Namespace }}
annotations:
{{- toYaml .Values.service.ssh.annotations | nindent 4 }}
labels:
{{- include "gitea.labels" . | nindent 4 }}
{{- if .Values.service.ssh.labels }}
{{- toYaml .Values.service.ssh.labels | nindent 4 }}
{{- end }}
annotations:
{{- toYaml .Values.service.ssh.annotations | nindent 4 }}
name: {{ include "gitea.service.ssh.name" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
spec:
type: {{ .Values.service.ssh.type }}
{{- if eq .Values.service.ssh.type "LoadBalancer" }}
+34
View File
@@ -0,0 +1,34 @@
{{- if eq (include "gitea.tcpRoute.enabled" .) "true" -}}
---
apiVersion: gateway.networking.k8s.io/v1alpha2
kind: TCPRoute
metadata:
{{- with (include "gitea.tcpRoute.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.tcpRoute.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.fullname" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
spec:
parentRefs:
{{- if .Values.gatewayAPI.core.tcpRoute.parentRefs }}
{{- toYaml .Values.gatewayAPI.core.tcpRoute.parentRefs | nindent 4 }}
{{- else }}
{{- fail "gatewayAPI.core.tcpRoute.parentRefs is required" }}
{{- end }}
rules:
{{- if .Values.gatewayAPI.core.tcpRoute.rules }}
{{- tpl (toYaml .Values.gatewayAPI.core.tcpRoute.rules) $ | nindent 4 }}
{{- else }}
- backendRefs:
- group: ""
kind: Service
name: {{ include "gitea.service.ssh.name" . }}
port: {{ .Values.service.ssh.port }}
weight: 1
{{- end }}
{{- end }}
+1 -1
View File
@@ -22,6 +22,6 @@ spec:
{{- $testContainerSecurityContext | nindent 8 }}
{{- end }}
command: ['wget']
args: ['{{ include "gitea.fullname" . }}-http:{{ .Values.service.http.port }}']
args: ['{{ include "gitea.service.http.name" . }}:{{ .Values.service.http.port }}']
restartPolicy: Never
{{- end }}
@@ -103,3 +103,56 @@ tests:
matchRegex:
path: stringData.server
pattern: \nROOT_URL=https://route.example.com
################################################
- it: "[HTTPRoute enabled] uses first hostname for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/config.yaml
set:
ingress:
hosts: []
gatewayAPI:
enabled: true
core:
httpRoute:
enabled: true
hostnames:
- gw.example.com
parentRefs:
- name: shared-gateway
asserts:
- documentIndex: 0
matchRegex:
path: stringData.server
pattern: \nDOMAIN=gw.example.com
- documentIndex: 0
matchRegex:
path: stringData.server
pattern: \nSSH_DOMAIN=gw.example.com
- documentIndex: 0
matchRegex:
path: stringData.server
pattern: \nROOT_URL=http://gw.example.com
################################################
- it: "[HTTPRoute tls] switches ROOT_URL to https"
template: templates/gitea/config.yaml
set:
ingress:
hosts: []
gatewayAPI:
enabled: true
core:
httpRoute:
enabled: true
tls: true
hostnames:
- gw.example.com
parentRefs:
- name: shared-gateway
asserts:
- documentIndex: 0
matchRegex:
path: stringData.server
pattern: \nROOT_URL=https://gw.example.com
@@ -1,13 +1,13 @@
suite: ssh-svc / http-svc template (Services configuration)
suite: sshService / httpService template (Services configuration)
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/ssh-svc.yaml
- templates/gitea/http-svc.yaml
- templates/gitea/sshService.yaml
- templates/gitea/httpService.yaml
tests:
- it: supports adding custom labels to ssh-svc
template: templates/gitea/ssh-svc.yaml
- it: supports adding custom labels to sshService
template: templates/gitea/sshService.yaml
set:
service:
ssh:
@@ -19,7 +19,7 @@ tests:
value: "testvalue"
- it: keeps existing labels (ssh)
template: templates/gitea/ssh-svc.yaml
template: templates/gitea/sshService.yaml
set:
service:
ssh:
@@ -28,8 +28,8 @@ tests:
- exists:
path: metadata.labels["app"]
- it: supports adding custom labels to http-svc
template: templates/gitea/http-svc.yaml
- it: supports adding custom labels to httpService
template: templates/gitea/httpService.yaml
set:
service:
http:
@@ -41,7 +41,7 @@ tests:
value: "testvalue"
- it: keeps existing labels (http)
template: templates/gitea/http-svc.yaml
template: templates/gitea/httpService.yaml
set:
service:
http:
@@ -51,7 +51,7 @@ tests:
path: metadata.labels["app"]
- it: render service.ssh.loadBalancerClass if set and type is LoadBalancer
template: templates/gitea/ssh-svc.yaml
template: templates/gitea/sshService.yaml
set:
service:
ssh:
@@ -73,7 +73,7 @@ tests:
value: ["1.2.3.4/32", "5.6.7.8/32"]
- it: does not render when loadbalancer properties are set but type is not loadBalancerClass
template: templates/gitea/http-svc.yaml
template: templates/gitea/httpService.yaml
set:
service:
http:
@@ -92,7 +92,7 @@ tests:
path: spec.loadBalancerSourceRanges
- it: does not render loadBalancerClass by default even when type is LoadBalancer
template: templates/gitea/http-svc.yaml
template: templates/gitea/httpService.yaml
set:
service:
http:
@@ -107,8 +107,8 @@ tests:
- it: both ssh and http services exist
templates:
- templates/gitea/ssh-svc.yaml
- templates/gitea/http-svc.yaml
- templates/gitea/sshService.yaml
- templates/gitea/httpService.yaml
asserts:
- matchRegex:
path: metadata.name
@@ -0,0 +1,89 @@
suite: Test Gateway API backendTLSPolicy.yaml
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/backendTLSPolicy.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
gatewayAPI:
enabled: false
core:
backendTLSPolicy:
enabled: true
validation:
hostname: git.internal
caCertificateRefs:
- name: gitea-ca
group: ""
kind: ConfigMap
asserts:
- hasDocuments:
count: 0
- it: should not render when backendTLSPolicy.enabled is false
set:
gatewayAPI:
enabled: true
gatewayAPI.core.backendTLSPolicy.enabled: false
asserts:
- hasDocuments:
count: 0
- it: should render a BackendTLSPolicy targeting the http Service by default
set:
gatewayAPI:
enabled: true
core:
backendTLSPolicy:
enabled: true
validation:
hostname: git.internal
caCertificateRefs:
- name: gitea-ca
group: ""
kind: ConfigMap
asserts:
- hasDocuments:
count: 1
- isKind:
of: BackendTLSPolicy
- equal:
path: apiVersion
value: gateway.networking.k8s.io/v1
- equal:
path: metadata.name
value: gitea-unittests
- equal:
path: spec.targetRefs[0].name
value: gitea-unittests-http
- equal:
path: spec.targetRefs[0].kind
value: Service
- equal:
path: spec.validation.hostname
value: git.internal
- it: should fail when validation is missing
set:
gatewayAPI:
enabled: true
core:
backendTLSPolicy:
enabled: true
asserts:
- failedTemplate:
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
- it: should fail when validation is an empty dict
set:
gatewayAPI:
enabled: true
core:
backendTLSPolicy:
enabled: true
validation: {}
asserts:
- failedTemplate:
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
@@ -0,0 +1,105 @@
suite: Test Gateway API clientSettingsPolicy.yaml
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/clientSettingsPolicy.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
gatewayAPI:
enabled: false
nginx:
clientSettingsPolicies:
enabled: true
body:
maxSize: 100m
asserts:
- hasDocuments:
count: 0
- it: should not render when clientSettingsPolicies.enabled is false
set:
gatewayAPI:
enabled: true
gatewayAPI.nginx.clientSettingsPolicies.enabled: false
asserts:
- hasDocuments:
count: 0
- it: should render a ClientSettingsPolicy targeting the HTTPRoute by default
set:
gatewayAPI:
enabled: true
nginx:
clientSettingsPolicies:
enabled: true
body:
maxSize: 100m
asserts:
- hasDocuments:
count: 1
- isKind:
of: ClientSettingsPolicy
- equal:
path: apiVersion
value: gateway.nginx.org/v1alpha1
- equal:
path: metadata.name
value: gitea-unittests
- equal:
path: spec.targetRef.group
value: gateway.networking.k8s.io
- equal:
path: spec.targetRef.kind
value: HTTPRoute
- equal:
path: spec.targetRef.name
value: gitea-unittests
- equal:
path: spec.body.maxSize
value: 100m
- it: should honor a custom targetRef
set:
gatewayAPI:
enabled: true
nginx:
clientSettingsPolicies:
enabled: true
targetRef:
group: gateway.networking.k8s.io
kind: Gateway
name: shared-gateway
body:
maxSize: 100m
asserts:
- equal:
path: spec.targetRef.kind
value: Gateway
- equal:
path: spec.targetRef.name
value: shared-gateway
- it: should fail when body is missing
set:
gatewayAPI:
enabled: true
nginx:
clientSettingsPolicies:
enabled: true
asserts:
- failedTemplate:
errorMessage: gatewayAPI.nginx.clientSettingsPolicies.body is required
- it: should fail when body is an empty dict
set:
gatewayAPI:
enabled: true
nginx:
clientSettingsPolicies:
enabled: true
body: {}
asserts:
- failedTemplate:
errorMessage: gatewayAPI.nginx.clientSettingsPolicies.body is required
+117
View File
@@ -0,0 +1,117 @@
suite: Test Gateway API httpRoute.yaml
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/httpRoute.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
gatewayAPI:
enabled: false
core:
httpRoute:
enabled: true
hostnames:
- git.example.com
parentRefs:
- name: shared-gateway
asserts:
- hasDocuments:
count: 0
- it: should not render when httpRoute.enabled is false
set:
gatewayAPI:
enabled: true
gatewayAPI.core.httpRoute.enabled: false
asserts:
- hasDocuments:
count: 0
- it: should render a single HTTPRoute with default rule
set:
gatewayAPI:
enabled: true
core:
httpRoute:
enabled: true
annotations:
example.io/owner: gitea
hostnames:
- git.example.com
parentRefs:
- name: shared-gateway
namespace: gateway-system
asserts:
- hasDocuments:
count: 1
- isKind:
of: HTTPRoute
- equal:
path: apiVersion
value: gateway.networking.k8s.io/v1
- equal:
path: metadata.name
value: gitea-unittests
- equal:
path: metadata.annotations["example.io/owner"]
value: gitea
- equal:
path: spec.parentRefs[0].name
value: shared-gateway
- equal:
path: spec.parentRefs[0].namespace
value: gateway-system
- equal:
path: spec.hostnames[0]
value: git.example.com
- equal:
path: spec.rules[0].matches[0].path.value
value: /
- equal:
path: spec.rules[0].backendRefs[0].group
value: ""
- equal:
path: spec.rules[0].backendRefs[0].kind
value: Service
- equal:
path: spec.rules[0].backendRefs[0].name
value: gitea-unittests-http
- equal:
path: spec.rules[0].backendRefs[0].port
value: 3000
- equal:
path: spec.rules[0].backendRefs[0].weight
value: 1
- it: should fail when parentRefs missing
set:
gatewayAPI:
enabled: true
core:
httpRoute:
enabled: true
hostnames:
- git.example.com
asserts:
- failedTemplate:
errorMessage: gatewayAPI.core.httpRoute.parentRefs is required
- it: hostname tpl rendering
set:
global:
giteaHostName: gitea.tpl.example.com
gatewayAPI:
enabled: true
core:
httpRoute:
enabled: true
hostnames:
- "{{ .Values.global.giteaHostName }}"
parentRefs:
- name: gw
asserts:
- equal:
path: spec.hostnames[0]
value: gitea.tpl.example.com
+79
View File
@@ -0,0 +1,79 @@
suite: Test Gateway API tcpRoute.yaml
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/tcpRoute.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
gatewayAPI:
enabled: false
core:
tcpRoute:
enabled: true
parentRefs:
- name: shared-gateway
asserts:
- hasDocuments:
count: 0
- it: should not render when tcpRoute.enabled is false
set:
gatewayAPI:
enabled: true
gatewayAPI.core.tcpRoute.enabled: false
asserts:
- hasDocuments:
count: 0
- it: should render a TCPRoute defaulting to the SSH service
set:
gatewayAPI:
enabled: true
core:
tcpRoute:
enabled: true
parentRefs:
- name: shared-gateway
sectionName: ssh
asserts:
- hasDocuments:
count: 1
- isKind:
of: TCPRoute
- equal:
path: apiVersion
value: gateway.networking.k8s.io/v1alpha2
- equal:
path: metadata.name
value: gitea-unittests
- equal:
path: spec.parentRefs[0].sectionName
value: ssh
- equal:
path: spec.rules[0].backendRefs[0].group
value: ""
- equal:
path: spec.rules[0].backendRefs[0].kind
value: Service
- equal:
path: spec.rules[0].backendRefs[0].name
value: gitea-unittests-ssh
- equal:
path: spec.rules[0].backendRefs[0].port
value: 22
- equal:
path: spec.rules[0].backendRefs[0].weight
value: 1
- it: should fail when parentRefs missing
set:
gatewayAPI:
enabled: true
core:
tcpRoute:
enabled: true
asserts:
- failedTemplate:
errorMessage: gatewayAPI.core.tcpRoute.parentRefs is required
+93 -13
View File
@@ -208,11 +208,94 @@ route:
caCertificate:
destinationCACertificate:
## @section Gateway API
## See docs/gateway-api.md for full guidance.
gatewayAPI:
## @param gatewayAPI.enabled Enable deployment of Gateway API resources
enabled: false
core:
## @param gatewayAPI.core.backendTLSPolicy.enabled Render a BackendTLSPolicy resource for encrypted backend traffic
## @param gatewayAPI.core.backendTLSPolicy.annotations Annotations applied to the BackendTLSPolicy
## @param gatewayAPI.core.backendTLSPolicy.labels Additional labels applied to the BackendTLSPolicy
## @param gatewayAPI.core.backendTLSPolicy.targetRefs Target references for the BackendTLSPolicy. Defaults to the HTTP service.
## @param gatewayAPI.core.backendTLSPolicy.validation Validation configuration (required when enabled). See `docs/gateway-api.md`.
## @extra gatewayAPI.core.backendTLSPolicy.validation.caCertificateRefs CA certificate references for the BackendTLSPolicy validation. See `docs/gateway-api.md`.
## @extra gatewayAPI.core.backendTLSPolicy.validation.hostname Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the gitea server certificate. See `docs/gateway-api.md`.
backendTLSPolicy:
enabled: false
annotations: {}
labels: {}
targetRefs: []
validation: {}
# caCertificateRefs:
# - name: gitea-ca
# group: ""
# kind: ConfigMap
# hostname: gitea-http
## @param gatewayAPI.core.httpRoute.enabled Render an HTTPRoute resource
## @param gatewayAPI.core.httpRoute.annotations Annotations applied to the HTTPRoute
## @param gatewayAPI.core.httpRoute.labels Additional labels applied to the HTTPRoute
## @param gatewayAPI.core.httpRoute.tls When true, treat the upstream Gateway as terminating TLS so `ROOT_URL` uses `https`.
## @param gatewayAPI.core.httpRoute.parentRefs Parent gateway references (required when enabled).
## @param gatewayAPI.core.httpRoute.hostnames List of hostnames for the HTTPRoute.
## @param gatewayAPI.core.httpRoute.rules Custom routing rules. Defaults to a PathPrefix `/` rule targeting the HTTP service.
httpRoute:
enabled: false
annotations: {}
labels: {}
tls: false
parentRefs: []
# - group: gateway.networking.k8s.io
# kind: Gateway
# name: shared-gateway
# namespace: gateway-system
# sectionName: http
hostnames: []
# - git.example.com
rules: []
## @param gatewayAPI.core.tcpRoute.enabled Render a TCPRoute resource (typically for SSH)
## @param gatewayAPI.core.tcpRoute.annotations Annotations applied to the TCPRoute
## @param gatewayAPI.core.tcpRoute.labels Additional labels applied to the TCPRoute
## @param gatewayAPI.core.tcpRoute.parentRefs Parent gateway references (required when enabled).
## @param gatewayAPI.core.tcpRoute.rules Custom routing rules. Defaults to a rule targeting the SSH service.
tcpRoute:
enabled: false
annotations: {}
labels: {}
parentRefs: []
# - group: gateway.networking.k8s.io
# kind: Gateway
# name: shared-gateway
# namespace: gateway-system
# sectionName: ssh
rules: []
## NGINX Gateway Fabric specific resources. Only relevant when the upstream
## Gateway is backed by NGINX Gateway Fabric (nginx.org). Other implementations
## (Envoy Gateway, Cilium, ...) do not impose a default request body size limit.
nginx:
## @param gatewayAPI.nginx.clientSettingsPolicies.enabled Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit
## @param gatewayAPI.nginx.clientSettingsPolicies.annotations Annotations applied to the ClientSettingsPolicy
## @param gatewayAPI.nginx.clientSettingsPolicies.labels Additional labels applied to the ClientSettingsPolicy
## @param gatewayAPI.nginx.clientSettingsPolicies.targetRef Target reference for the ClientSettingsPolicy. Defaults to the chart's HTTPRoute.
## @param gatewayAPI.nginx.clientSettingsPolicies.body Client body settings (required when enabled), e.g. `maxSize`. See `docs/gateway-api.md`.
clientSettingsPolicies:
enabled: false
annotations: {}
labels: {}
targetRef: {}
body: {}
# maxSize: 100m
## @section deployment
#
## @param resources Kubernetes resources
resources:
{}
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
@@ -253,10 +336,9 @@ priorityClassName: ""
## @param deployment.labels Labels for the deployment
## @param deployment.annotations Annotations for the Gitea deployment to be created
deployment:
env:
[]
# - name: VARIABLE
# value: my-value
env: []
# - name: VARIABLE
# value: my-value
terminationGracePeriodSeconds: 60
labels: {}
annotations: {}
@@ -423,8 +505,7 @@ gitea:
tlsConfig: {}
## @param gitea.ldap LDAP configuration
ldap:
[]
ldap: []
# - name: "LDAP 1"
# existingSecret:
# securityProtocol:
@@ -441,8 +522,7 @@ gitea:
# Either specify inline `key` and `secret` or refer to them via `existingSecret`
## @param gitea.oauth OAuth configuration
oauth:
[]
oauth: []
# - name: 'OAuth 1'
# provider:
# key:
@@ -659,9 +739,9 @@ valkey:
repository: bitnamilegacy/redis-exporter
primary:
## @param valkey.primary.persistence.enabled Enable persistence on Valkey replicas nodes using Persistent Volume Claims.
## @param valkey.primary.persistence.storageClass Persistent Volume storage class.
## @param valkey.primary.persistence.size Persistent Volume size.
## @param valkey.primary.persistence.enabled Enable persistence on Valkey replicas nodes using Persistent Volume Claims.
## @param valkey.primary.persistence.storageClass Persistent Volume storage class.
## @param valkey.primary.persistence.size Persistent Volume size.
persistence:
enabled: true
storageClass: ""