Until now the Secrets rendered by this chart were not configurable at all. Their labels were fixed
to the chart defaults, they could not carry annotations, and there was no way to hand in a Secret
that is managed outside of the chart - except for the GPG key, which had its own special case via
`signing.existingSecret`. Users who manage their secrets with an external operator (e.g. External
Secrets, Sealed Secrets) or who need annotations for tooling such as Reloader or Kyverno had no
option but to fork the chart.
A `secrets` section is introduced with one entry per Secret (config, gpg, init, inlineConfig,
metrics), each offering:
addSHASumAnnotation add a checksum annotation to the pod template (default: true)
existingSecret.enabled reference a Secret that is not managed by this chart
existingSecret.secretName name of that Secret
new.annotations annotations for the Secret created by the chart
new.labels additional labels for the Secret created by the chart
The `new` sub-key keeps the properties of a chart-managed Secret clearly separated from the
properties of a referenced one, so it is obvious which settings are ignored once `existingSecret` is
enabled. `secretName` rather than `name` mirrors the field the value ends up in, the `secretName` of
a pod volume.
The `gitea.secret.*.name` helpers resolve to the user-provided name when `existingSecret` is
enabled, which means the Deployment volumes and the ServiceMonitor credentials pick it up without
further changes. Enabling `existingSecret` without a name fails the render with a message naming the
full values path, because Helm would otherwise silently create a Secret under the referenced name and
overwrite it.
Only two of the five Secrets had a checksum annotation before, so changes to the init scripts, the
GPG key or the metrics token did not trigger a rollout. Annotations for all five are now rendered,
each gated by `addSHASumAnnotation` and skipped for Secrets the chart does not manage.
Two side effects had to be preserved when a Secret is no longer rendered:
- secret_config.yaml carries the HA assertions (RWX access mode, issue/repo indexer, mutually
exclusive PostgreSQL dependencies) inside its `assertions` field. They are extracted into
`gitea.config.assertions` and evaluated before the guard, otherwise providing an own config Secret
would silently disable chart-wide validation.
- secret_inlineConfig.yaml populates `.Values.gitea.config` as a side effect of
`gitea.inline_configuration`. Without evaluating it, even NOTES.txt fails on
`.Values.gitea.config.cache`. The include therefore runs independently of the guard as well.
`signing.existingSecret` keeps working; `secrets.gpg.existingSecret` takes precedence over it. The
error message raised for an enabled but unconfigured signing setup now lists all three options.
Test suites rendering the Deployment have to declare the Secret templates it checksums, hence the
added `templates:` entries. unittests/helm/deployment/extraInitContainers.yaml set `signing.enabled`
without a key or an existing Secret - a combination that fails a real `helm install` and only went
unnoticed because the Deployment never rendered secret_gpg.yaml before.
Co-authored-by: Copilot <copilot@github.com>
The names of the Secrets rendered by the chart were built inline in each template and, for two of
them, in ad-hoc chart-wide helpers. The same name therefore existed in several places (Deployment
volumes, ServiceMonitor credentials, the Secret templates themselves), which made every rename a
multi-file change and allowed the references to drift apart unnoticed - the Helm unit tests render
one template at a time and cannot detect a mismatching secretName.
All Secret names are now defined once in templates/gitea/_secrets.tpl:
gitea.secret.config.name -> <fullname>-config
gitea.secret.gpg.name -> <fullname>-gpg-key (or signing.existingSecret)
gitea.secret.init.name -> <fullname>-init
gitea.secret.inlineConfig.name -> <fullname>-inline-config
gitea.secret.metrics.name -> <fullname>-metrics
gitea.gpg-key-secret-name and gitea.metrics-secret-name are removed from _helpers.tpl accordingly.
A checksum/inlineConfig pod annotation is added as well. After the inline configuration had been
split out of secret_config.yaml, changes to it were no longer covered by any checksum annotation and
did not trigger a rollout of the Deployment.
Finally the metadata attributes of the Secret templates are sorted alphabetically as required by the
chart conventions.
BREAKING CHANGE: two Secrets are renamed. The config Secret changes from <fullname> to
<fullname>-config and the metrics Secret from <fullname>-metrics-secret to <fullname>-metrics. Helm
replaces both on upgrade; references to them from outside the chart have to be adjusted.
Co-authored-by: Copilot <copilot@github.com>
The files in templates/gitea/ used a mix of naming styles: lowercase concatenations
(poddisruptionbudget.yaml, serviceaccount.yaml, servicemonitor.yaml, pvc.yaml), camelCase
(httpService.yaml, sshService.yaml) and kind-suffixed names (gpg-secret.yaml, metrics-secret.yaml).
It was therefore not obvious from a file name which Kubernetes resource it renders, and the naming
contradicted the camelCase convention the Gateway API templates already follow.
Files are now named after the kind they render, with a lowercase suffix distinguishing several
resources of the same kind:
config.yaml -> secret_config.yaml + secret_inlineConfig.yaml
gpg-secret.yaml -> secret_gpg.yaml
init.yaml -> secret_init.yaml
metrics-secret.yaml -> secret_metrics.yaml
httpService.yaml -> service_http.yaml
sshService.yaml -> service_ssh.yaml
poddisruptionbudget.yaml -> podDisruptionBudget.yaml
pvc.yaml -> persistentVolumeClaim.yaml
serviceaccount.yaml -> serviceAccount.yaml
servicemonitor.yaml -> serviceMonitor.yaml
config.yaml rendered two Secrets from a single file, which forced every unit test to address them via
documentIndex. It is split so that each file renders exactly one resource.
The rendered manifests are unchanged; only file names and the references to them were touched. This
includes the checksum/config annotation in deployment.yaml and all helm unit test suites. The HA guard
assertions had to move from deployment.yaml to secret_config.yaml: Helm sorts templates in reverse
alphabetical order, so secret_config.yaml is now rendered before deployment.yaml and the fail() is
reported for that file directly instead of bubbling up through the include chain of the Deployment.
Users relying on the template paths (e.g. `helm template --show-only` or post-renderers) have to
adjust to the new file names.
Co-authored-by: Copilot <copilot@github.com>
The following patch intoduce the dictionaries pre and postExtraInitContainers.
The dictionaries can be used to specify further initContainers before and after
the gitea initializing process. For example:
```yaml
postExtraInitContainers:
- name: foo
image: docker.io/library/busybox:latest
preExtraInitContainers:
- name: bar
image: docker.io/library/busybox:latest
```