Compare commits

...
10 Commits
Author SHA1 Message Date
volker.raschek ccea2082c3 fix(ci): add xterm
changelog / changelog (push) Successful in 20s
Bash / bash-unittest (push) Successful in 29s
Helm / helm-unittest (push) Successful in 1m12s
Helm / helm-lint (push) Successful in 10s
2026-09-14 20:59:24 +02:00
volker.raschek 4016c5396d fix(ci): add bash unittests
changelog / changelog (push) Successful in 17s
Bash / bash-unittest (push) Failing after 23s
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 1m11s
2026-09-14 20:57:01 +02:00
volker.raschekandCopilot d35177ec71 chore(renovate): migrate the configuration to plain JSON
Helm / helm-lint (push) Successful in 17s
changelog / changelog (push) Successful in 20s
Helm / helm-unittest (push) Successful in 1m9s
The JSON5 syntax was not used for anything that JSON cannot express. The only comment-looking entry was already a
`description` field, which renovate evaluates itself and which therefore survives the conversion. Plain JSON is the
better default here, because it needs no dedicated parser in editors and tooling.

The converted configuration was verified against the JSON5 parser to be structurally identical to its predecessor.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:42:40 +02:00
volker.raschekandCopilot e97f3b3bba fix(ci): resolve the helm dependencies with dependency update
changelog / changelog (push) Successful in 16s
Helm / helm-lint (push) Successful in 16s
Helm / helm-unittest (push) Successful in 31s
`helm dependency build` only downloads charts from repositories that are already registered in the local repository
cache. On a fresh runner that cache is empty, so the classic repository of the valkey dependency could not be resolved:
"no repository definition for https://valkey.io/valkey-helm. Please add the missing repos via 'helm repo add'". The two
bitnami dependencies were unaffected, because OCI references do not need a repository entry.

`helm dependency update` resolves the repository URLs straight from `Chart.yaml` and therefore needs no additional
`helm repo add` step. Repeating the URL in the workflow would only invite drift, since renovate updates `Chart.yaml`
alone. All three dependencies are pinned to exact versions, so the resolution result is identical to `Chart.lock`.

This corrects 0102563, which introduced the `dependency build` step.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:38:05 +02:00
volker.raschekandCopilot 70a033d519 chore(make): add a clean target
Helm / helm-lint (push) Failing after 12s
changelog / changelog (push) Successful in 16s
Helm / helm-unittest (push) Failing after 22s
Removes the artifacts that are produced by the other targets and ignored by git, so a broken state can be reset without
remembering which directories are generated. `helm dependency build` populates `charts`, the readme generator installs
`node_modules` and packaging leaves the chart archive and its signature behind.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:33:19 +02:00
volker.raschekandCopilot 010256397a fix(ci): build the helm dependencies before linting and testing
The `charts` directory is ignored by git, so a fresh checkout does not contain the postgresql, postgresql-ha and valkey
sub-charts. Locally the workflow appeared to work because `make helm/dependency-update` had populated the directory at
some earlier point.

Without the sub-charts every suite that asserts on a dependency template failed with "document index 0 is out of range"
and "template gitea/charts/postgresql/templates/primary/svc.yaml not exists or not selected in test suite". `helm lint`
was affected for the same reason.

`helm dependency build` is used instead of `helm dependency update`, because `Chart.lock` is committed and the pinned
versions should be resolved reproducibly rather than refreshed on every run.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:32:37 +02:00
volker.raschekandCopilot 552fe8c56e refactor(templates): move the templates out of the gitea subdirectory
Helm / helm-lint (push) Successful in 9s
changelog / changelog (push) Successful in 29s
Helm / helm-unittest (push) Failing after 21s
Markdown linter / markdown-lint (push) Successful in 17s
Markdown linter / markdown-link-checker (push) Successful in 56s
The `templates/gitea` subdirectory did not group anything meaningful, since every template of this chart belongs to
Gitea. It only duplicated the chart name in every path and forced the unit tests to spell out
`templates/gitea/<name>.yaml`, while `_helpers.tpl` and `NOTES.txt` already lived directly in `templates`.

All templates now live in `templates`, which matches the layout of the bundled sub-charts and the Helm defaults.

The checksum helper in `templates/_secrets.tpl` built its include path from `$root.Template.BasePath` and therefore
carried the subdirectory in a `printf` format string instead of a literal path. Without adjusting it the chart failed to
render with "no template gitea/templates/gitea/secret_config.yaml associated with template gotpl".

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:28:17 +02:00
volker.raschekandCopilot 0a237ba2c1 refactor(serviceAccount)!: group the values into existingServiceAccount and new
Helm / helm-lint (push) Successful in 13s
changelog / changelog (push) Successful in 20s
Helm / helm-unittest (push) Failing after 40s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 32s
The previous notation mixed two concerns in a single flat dict: `create`/`name` decided whether the chart manages the
ServiceAccount or only references an externally provided one, while the remaining keys only ever applied to a
chart-managed ServiceAccount. That made `name` ambiguous, because it either renamed the generated object or pointed to a
foreign one, and it forced the deployment to guard the reference with `or .Values.serviceAccount.create
.Values.serviceAccount.name`.

The values are now grouped the same way as `persistence`, which was restructured in dfe087c. `serviceAccount.enabled`
controls whether the pod uses a ServiceAccount at all, `serviceAccount.existingServiceAccount` references an externally
managed object and `serviceAccount.new` holds the properties of the object created by the chart. The templates follow
the established helper layout in `templates/gitea/_serviceAccounts.tpl`.

Two latent bugs are fixed along the way. The annotation helper was defined as `gitea.secret.admin.annotations`, so the
`gitea.serviceAccount.annotations` include in the template never resolved. And the duplicated name helper
`gitea.serviceAccountName` in `templates/_helpers.tpl` is removed in favour of `gitea.serviceAccount.name`.

BREAKING CHANGE:
- `serviceAccount.create` does no longer exist. Use `serviceAccount.enabled` instead. The default changed from `false`
  to `true`, so a ServiceAccount is now created unless it is explicitly disabled.
- `serviceAccount.name` does no longer exist. Use `serviceAccount.existingServiceAccount.enabled` together with
  `serviceAccount.existingServiceAccount.existingServiceAccountName` to reference an externally managed ServiceAccount.
- `serviceAccount.annotations`, `serviceAccount.labels`, `serviceAccount.automountServiceAccountToken` and
  `serviceAccount.imagePullSecrets` moved below `serviceAccount.new`.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 19:15:58 +02:00
volker.raschekandCopilot dfe087c0c1 refactor(persistence)!: group the values into existingPersistentVolumeClaim and new
Helm / helm-lint (push) Successful in 13s
changelog / changelog (push) Successful in 22s
Helm / helm-unittest (push) Failing after 45s
Markdown linter / markdown-link-checker (push) Successful in 44s
Markdown linter / markdown-lint (push) Successful in 36s
The flat `persistence` dict mixed three concerns: whether persistence is used at all, whether the chart creates the
PersistentVolumeClaim, and how that claim is shaped. The pairs `create`/`claimName` and `enabled`/`mount` were only
meaningful in certain combinations, so an invalid configuration such as `create=true` together with a foreign
`claimName` was silently accepted. The same split into an `existingX`/`new` pair is already used for the Secrets, so
this aligns persistence with the rest of the chart.

`persistence.enabled` now only decides whether a volume is used at all. `persistence.existingPersistentVolumeClaim`
points at a claim managed outside of the chart, and everything under `persistence.new` describes the claim the chart
creates itself. Rendering and naming move into `templates/gitea/_persistentVolumeClaims.tpl` so the Deployment and the
PersistentVolumeClaim derive the claim name from a single helper instead of repeating the value lookups.

Support for `global.storageClass` is dropped. It was a chart-wide override that silently applied to the Gitea claim and
was evaluated through `tpl`, which made the effective storage class hard to predict. The storage class is now set
explicitly via `persistence.new.storageClassName`, which also matches the field name in the PersistentVolumeClaim spec.

BREAKING CHANGE: The `persistence` values were restructured and `global.storageClass` was removed.

- `persistence.create` and `persistence.mount` are gone. Set `persistence.enabled` to use a volume and
  `persistence.existingPersistentVolumeClaim.enabled` to reuse a claim that is not managed by the chart.
- `persistence.claimName` moves to `persistence.existingPersistentVolumeClaim.persistentVolumeClaimName`. A claim
  created by the chart is now named after `gitea.fullname` instead of the default `gitea-shared-storage`.
- `persistence.accessModes`, `annotations`, `labels`, `size` and `subPath` move into `persistence.new`.
- `persistence.volumeName` becomes `persistence.new.persistentVolumeName`.
- `persistence.storageClass` and `global.storageClass` become `persistence.new.storageClassName`.
- `persistence.enabled` now defaults to `false`.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 15:38:06 +02:00
volker.raschekandCopilot 761921faed test(ingress): align assertions with the release name and namespace
The suite header was changed to the release `gitea-unittests` in the namespace `testing`, but the assertions still
expected the previous `gitea-unittest` and `gitea-debug`. That made four cases fail on the rendered resource name, the
`app.kubernetes.io/instance` label and the backend Service name.

Renovate comments had additionally been copied into the expected `app.kubernetes.io/version` and `version` label values.
They only matched by accident, because YAML strips the trailing comment from an unquoted scalar. Removing them keeps the
assertions honest about what is actually compared.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 15:24:55 +02:00
98 changed files with 843 additions and 794 deletions
+23
View File
@@ -0,0 +1,23 @@
name: Bash
on:
pull_request:
types: [ "opened", "reopened", "synchronize" ]
push:
branches:
- '**'
tags-ignore:
- '**'
workflow_dispatch: {}
jobs:
bash-unittest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
submodules: true
- env:
TERM: xterm
name: Run bash unittests
run: make bash/unittest
+4
View File
@@ -18,6 +18,8 @@ jobs:
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with:
version: v4.3.0 # renovate: datasource=github-releases depName=helm/helm
- name: Update helm dependencies
run: helm dependency update
- name: Lint helm files
run: |
helm lint --values values.yaml .
@@ -33,5 +35,7 @@ jobs:
HELM_UNITTEST_VERSION: v1.0.0 #renovate: datasource=github-releases depName=helm-unittest/helm-unittest
name: Install helm-unittest
run: helm plugin install --verify=false --version "${HELM_UNITTEST_VERSION}" https://github.com/helm-unittest/helm-unittest
- name: Update helm dependencies
run: helm dependency update
- name: Execute helm unittests
run: helm unittest --strict --file 'unittests/**/*.yaml' .
+1 -1
View File
@@ -34,7 +34,7 @@ image:
### Templates
- Helm templates live in `templates/gitea/`. Helpers live in `templates/_helpers.tpl`.
- Helm templates live in `templates/`. Helpers live in `templates/_helpers.tpl`.
- Use camelCase for all files and variables (e.g `httpRoute`, `backendTLSPolicy`, `gatewayAPI`, `statefulSet`).
- Use `include "gitea.fullname"` for naming resources.
- Use `fail` for required-value validation with clear error messages referencing the full values path.
+1 -1
View File
@@ -36,6 +36,6 @@ unittests/
.prettierignore
.yamllint
CODEOWNERS
renovate.json5
renovate.json
.commitlintrc.json
.gitsv/
+1 -2
View File
@@ -4,8 +4,7 @@
"/unittests/**/*.yaml"
],
"https://docs.renovatebot.com/renovate-schema.json":[
"renovate.json",
"renovate.json5"
"renovate.json"
]
},
"yaml.schemaStore.enable": true,
+13
View File
@@ -1,5 +1,11 @@
SHELL := /usr/bin/env bash -O globstar
# CLEAN
# ==============================================================================
PHONY+=clean
clean:
-rm -rf charts *.tar.gz *.tar.gz.sig node_modules
# MISSING DOT
# ==============================================================================
PHONY+=missing-dot
@@ -35,6 +41,13 @@ PHONY+=helm/unittest
helm/unittest:
helm unittest --strict --file 'unittests/helm/**/*.yaml' --file 'unittests/helm/values-conflicting-checks.yaml' ./
# BASH PREPARE
# ==============================================================================
PHONY+=bash/prepare
bash/prepare:
git submodule init
git submodule update
# BASH UNITTESTS
# ==============================================================================
PHONY+=bash/unittest
+26 -27
View File
@@ -267,7 +267,7 @@ If `.Values.deployment.gitea.image.rootless: true`, then the following will occu
- `$HOME` becomes `/data/gitea/git`
[see deployment.yaml](./templates/gitea/deployment.yaml) template inside (init-)container "env" declarations
[see deployment.yaml](./templates/deployment.yaml) template inside (init-)container "env" declarations
- `START_SSH_SERVER: true` (Unless explicity overwritten by `gitea.config.server.START_SSH_SERVER`)
@@ -279,7 +279,7 @@ If `.Values.deployment.gitea.image.rootless: true`, then the following will occu
- `SSH_LOG_LEVEL` environment variable is not injected into the container
[see deployment.yaml](./templates/gitea/deployment.yaml) template inside container "env" declarations
[see deployment.yaml](./templates/deployment.yaml) template inside container "env" declarations
#### OpenShift Compatibility
@@ -1023,7 +1023,6 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
| ------------------------- | -------------------------------------------------------------------------- | ----- |
| `global.imageRegistry` | global image registry override. | `""` |
| `global.imagePullSecrets` | global image pull secrets override; can be extended by `imagePullSecrets`. | `[]` |
| `global.storageClass` | global storage class override. | `""` |
| `global.hostAliases` | global hostAliases which will be added to the pod's hosts files. | `[]` |
### deployment
@@ -1276,33 +1275,33 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
### ServiceAccount
| Name | Description | Value |
| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `serviceAccount.create` | Enable the creation of a ServiceAccount. | `false` |
| `serviceAccount.name` | Name of the created ServiceAccount, defaults to release name. Can also link to an externally provided ServiceAccount that should be used. | `""` |
| `serviceAccount.automountServiceAccountToken` | Enable/disable auto mounting of the service account token. | `false` |
| `serviceAccount.imagePullSecrets` | Image pull secrets, available to the ServiceAccount. | `[]` |
| `serviceAccount.annotations` | Custom annotations for the ServiceAccount. | `{}` |
| `serviceAccount.labels` | Custom labels for the ServiceAccount. | `{}` |
| Name | Description | Value |
| ------------------------------------------------------------------ | ---------------------------------------------------------- | ------- |
| `serviceAccount.enabled` | Assign the pod to use the ServiceAccount. | `true` |
| `serviceAccount.existingServiceAccount.enabled` | Enable using an existing ServiceAccount. | `false` |
| `serviceAccount.existingServiceAccount.existingServiceAccountName` | Name of the existing ServiceAccount to use. | `""` |
| `serviceAccount.new.annotations` | Custom annotations for the ServiceAccount. | `{}` |
| `serviceAccount.new.labels` | Custom labels for the ServiceAccount. | `{}` |
| `serviceAccount.new.automountServiceAccountToken` | Enable/disable auto mounting of the service account token. | `false` |
| `serviceAccount.new.imagePullSecrets` | Image pull secrets, available to the ServiceAccount. | `[]` |
### Persistence
| Name | Description | Value |
| ------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ---------------------- |
| `persistence.enabled` | Enable persistent storage. | `true` |
| `persistence.create` | Whether to create the persistentVolumeClaim for shared storage. | `true` |
| `persistence.mount` | Whether the persistentVolumeClaim should be mounted (even if not created). | `true` |
| `persistence.claimName` | Use an existing claim to store repository information. | `gitea-shared-storage` |
| `persistence.size` | Size for persistence to store repo information. | `10Gi` |
| `persistence.accessModes` | AccessMode for persistence. | `["ReadWriteOnce"]` |
| `persistence.labels` | Labels for the persistence volume claim to be created. | `{}` |
| `persistence.annotations.helm.sh/resource-policy` | Resource policy for the persistence volume claim. | `keep` |
| `persistence.storageClass` | Name of the storage class to use. | `nil` |
| `persistence.subPath` | Subdirectory of the volume to mount at. | `nil` |
| `persistence.volumeName` | Name of persistent volume in PVC. | `""` |
| `extraContainers` | Additional sidecar containers to run in the pod. | `[]` |
| `extraInitVolumeMounts` | Mounts that are only mapped into the init-containers. Can be used for additional preconfiguration. | `[]` |
| `extraVolumeMounts` | **DEPRECATED** Additional volume mounts for init containers and the Gitea main container. | `[]` |
| Name | Description | Value |
| --------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ------------------- |
| `persistence.enabled` | Enable persistent storage. | `false` |
| `persistence.existingPersistentVolumeClaim.enabled` | Enable using an existing persistent volume claim. | `false` |
| `persistence.existingPersistentVolumeClaim.persistentVolumeClaimName` | Name of the existing persistent volume claim to use. | `""` |
| `persistence.new.annotations.helm.sh/resource-policy` | Resource policy for the new persistent volume claim. | `keep` |
| `persistence.new.labels` | Labels for the new persistent volume claim. | `{}` |
| `persistence.new.accessModes` | AccessMode for the new persistent volume claim. | `["ReadWriteOnce"]` |
| `persistence.new.persistentVolumeName` | Name of the persistent volume for the new persistent volume claim. | `""` |
| `persistence.new.size` | Size for the new persistent volume claim. | `10Gi` |
| `persistence.new.storageClassName` | Name of the storage class to use for the new persistent volume claim. | `""` |
| `persistence.new.subPath` | Subdirectory of the volume to mount at for the new persistent volume claim. | `""` |
| `extraContainers` | Additional sidecar containers to run in the pod. | `[]` |
| `extraInitVolumeMounts` | Mounts that are only mapped into the init-containers. Can be used for additional preconfiguration. | `[]` |
| `extraVolumeMounts` | **DEPRECATED** Additional volume mounts for init containers and the Gitea main container. | `[]` |
### Init
+136
View File
@@ -0,0 +1,136 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"gitea>gitea/renovate-config",
"helpers:pinGitHubActionDigests",
":automergeMinor",
"schedule:automergeDaily",
"schedule:weekends"
],
"labels": [
"kind/dependency"
],
"digest": {
"automerge": true
},
"automergeStrategy": "squash",
"git-submodules": {
"enabled": true
},
"customManagers": [
{
"description": "Gitea-version of https://docs.renovatebot.com/presets-regexManagers/#regexmanagersgithubactionsversions",
"customType": "regex",
"managerFilePatterns": [
"/.gitea/workflows/.+\\.ya?ml$/"
],
"matchStrings": [
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?_VERSION\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s"
]
},
{
"description": "Detect helm-unittest yaml schema file",
"customType": "regex",
"managerFilePatterns": [
"/.vscode/settings\\.json$/"
],
"matchStrings": [
"https:\\/\\/raw\\.githubusercontent\\.com\\/(?<depName>[^\\s]+?)\\/(?<currentValue>v[0-9.]+?)\\/schema\\/helm-testsuite\\.json"
],
"datasourceTemplate": "github-releases"
},
{
"description": "Automatically detect new Gitea releases",
"customType": "regex",
"datasourceTemplate": "github-releases",
"depNameTemplate": "gitea/gitea",
"extractVersionTemplate": "^v(?<version>.*)$",
"managerFilePatterns": [
"/(^|/)Chart\\.ya?ml$/"
],
"matchStrings": [
"^appVersion:\\s+[\"']?(?<currentVersion>\\S+)[\"']?$"
]
}
],
"lockFileMaintenance": {
"enabled": true,
"commitMessageAction": "update",
"commitMessageTopic": "lockfiles",
"schedule": [
"at any time"
]
},
"packageRules": [
{
"groupName": "subcharts (minor & patch)",
"matchManagers": [
"helmv3"
],
"matchUpdateTypes": [
"minor",
"patch",
"digest"
]
},
{
"groupName": "bats testing framework",
"matchManagers": [
"git-submodules"
],
"matchUpdateTypes": [
"minor",
"patch",
"digest"
]
},
{
"groupName": "workflow dependencies (minor & patch)",
"matchManagers": [
"github-actions",
"npm",
"custom.regex"
],
"matchUpdateTypes": [
"minor",
"patch",
"digest"
],
"matchFileNames": [
"!Chart.yaml"
]
},
{
"description": "Update README.md on changes in values.yaml",
"matchManagers": [
"helm-values"
],
"postUpgradeTasks": {
"commands": [
"install-tool node",
"make readme"
],
"fileFilters": [
"README.md"
],
"executionMode": "update"
}
},
{
"description": "Override changelog url for Helm image, to have release notes in our PRs",
"matchDepNames": [
"alpine/helm"
],
"changelogUrl": "https://github.com/helm/helm"
},
{
"description": "Bump Gitea as fast as possible - not only on weekends",
"matchDepNames": [
"go-gitea/gitea"
],
"schedule": [
"at any time"
]
}
]
}
-136
View File
@@ -1,136 +0,0 @@
{
$schema: "https://docs.renovatebot.com/renovate-schema.json",
extends: [
"gitea>gitea/renovate-config",
"helpers:pinGitHubActionDigests",
":automergeMinor",
"schedule:automergeDaily",
"schedule:weekends",
],
labels: [
"kind/dependency",
],
digest: {
automerge: true,
},
automergeStrategy: "squash",
"git-submodules": {
enabled: true,
},
customManagers: [
{
description: "Gitea-version of https://docs.renovatebot.com/presets-regexManagers/#regexmanagersgithubactionsversions",
customType: "regex",
managerFilePatterns: [
"/.gitea/workflows/.+\\.ya?ml$/",
],
matchStrings: [
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?_VERSION\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s",
],
},
{
description: "Detect helm-unittest yaml schema file",
customType: "regex",
managerFilePatterns: [
"/.vscode/settings\\.json$/",
],
matchStrings: [
"https:\\/\\/raw\\.githubusercontent\\.com\\/(?<depName>[^\\s]+?)\\/(?<currentValue>v[0-9.]+?)\\/schema\\/helm-testsuite\\.json",
],
datasourceTemplate: "github-releases",
},
{
description: "Automatically detect new Gitea releases",
customType: "regex",
datasourceTemplate: "github-releases",
depNameTemplate: "gitea/gitea",
extractVersionTemplate: "^v(?<version>.*)$",
managerFilePatterns: [
"/(^|/)Chart\\.ya?ml$/",
],
matchStrings: [
"^appVersion:\\s+[\"']?(?<currentVersion>\\S+)[\"']?$",
],
},
],
lockFileMaintenance: {
"enabled": true,
"commitMessageAction": "update",
"commitMessageTopic": "lockfiles",
schedule: [
"at any time",
]
},
packageRules: [
{
groupName: "subcharts (minor & patch)",
matchManagers: [
"helmv3",
],
matchUpdateTypes: [
"minor",
"patch",
"digest",
],
},
{
groupName: "bats testing framework",
matchManagers: [
"git-submodules",
],
matchUpdateTypes: [
"minor",
"patch",
"digest",
],
},
{
groupName: "workflow dependencies (minor & patch)",
matchManagers: [
"github-actions",
"npm",
"custom.regex",
],
matchUpdateTypes: [
"minor",
"patch",
"digest",
],
matchFileNames: [
"!Chart.yaml",
],
},
{
description: "Update README.md on changes in values.yaml",
matchManagers: [
"helm-values",
],
postUpgradeTasks: {
commands: [
"install-tool node",
"make readme",
],
fileFilters: [
"README.md",
],
executionMode: "update",
},
},
{
description: "Override changelog url for Helm image, to have release notes in our PRs",
matchDepNames: [
"alpine/helm",
],
changelogUrl: "https://github.com/helm/helm",
},
{
description: "Bump Gitea as fast as possible - not only on weekends",
matchDepNames: [
"go-gitea/gitea",
],
schedule: [
"at any time",
],
},
],
}
-15
View File
@@ -154,17 +154,6 @@ These default to runAsUser 1000 outside OpenShift to preserve existing behavior.
{{- include "gitea.containerSecurityContext" (list $root $containerSecurityContext) -}}
{{- end -}}
{{/*
Storage Class
*/}}
{{- define "gitea.persistence.storageClass" -}}
{{- $storageClass := (tpl ( default "" .Values.persistence.storageClass) .) | default (tpl ( default "" .Values.global.storageClass) .) }}
{{- if $storageClass }}
storageClassName: {{ $storageClass | quote }}
{{- end }}
{{- end -}}
{{/*
Common labels
*/}}
@@ -504,10 +493,6 @@ https
{{- end -}}
{{- end -}}
{{- define "gitea.serviceAccountName" -}}
{{ .Values.serviceAccount.name | default (include "gitea.fullname" .) }}
{{- end -}}
{{- define "ingress.annotations" -}}
{{- if .Values.ingress.annotations }}
annotations:
@@ -40,8 +40,8 @@
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
{{- with $config.volumeMounts }}
@@ -105,8 +105,8 @@
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
- name: inline-config-sources
mountPath: /env-to-ini-mounts/inlines/
@@ -168,8 +168,8 @@
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
- name: gpg-private-key
mountPath: /raw
@@ -292,8 +292,8 @@
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
{{- with $config.volumeMounts }}
+38
View File
@@ -0,0 +1,38 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.persistentVolumeClaim.annotations" -}}
{{- with .Values.persistence.new.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.persistentVolumeClaim.enabled" -}}
{{- if and .Values.persistence.enabled (not .Values.persistence.existingPersistentVolumeClaim.enabled) -}}
true
{{- else -}}
false
{{- end }}
{{- end }}
{{/* labels */}}
{{- define "gitea.persistentVolumeClaim.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.persistence.new.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
{{/* name */}}
{{- define "gitea.persistentVolumeClaim.name" -}}
{{- if .Values.persistence.existingPersistentVolumeClaim.enabled -}}
{{ required "persistence.existingPersistentVolumeClaim.persistentVolumeClaimName is required when persistence.existingPersistentVolumeClaim.enabled is true" .Values.persistence.existingPersistentVolumeClaim.persistentVolumeClaimName }}
{{- else -}}
{{ include "gitea.fullname" . }}
{{- end }}
{{- end }}
@@ -54,7 +54,7 @@ Arguments: (list $root $key)
{{- $name := include (printf "gitea.secret.%s.name" $key) $root -}}
{{- lookup "v1" "Secret" $namespace $name | toYaml | sha256sum -}}
{{- else -}}
{{- include (printf "%s/gitea/secret_%s.yaml" $root.Template.BasePath $key) $root | sha256sum -}}
{{- include (printf "%s/secret_%s.yaml" $root.Template.BasePath $key) $root | sha256sum -}}
{{- end -}}
{{- end }}
+38
View File
@@ -0,0 +1,38 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.serviceAccount.annotations" -}}
{{- with .Values.serviceAccount.new.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.serviceAccount.enabled" -}}
{{- if and .Values.serviceAccount.enabled (not .Values.serviceAccount.existingServiceAccount.enabled) -}}
true
{{- else -}}
false
{{- end }}
{{- end }}
{{/* labels */}}
{{- define "gitea.serviceAccount.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.serviceAccount.new.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
{{/* name */}}
{{- define "gitea.serviceAccount.name" -}}
{{- if .Values.serviceAccount.existingServiceAccount.enabled -}}
{{ required "serviceAccount.existingServiceAccount.existingServiceAccountName is required when serviceAccount.existingServiceAccount.enabled is true" .Values.serviceAccount.existingServiceAccount.existingServiceAccountName }}
{{- else -}}
{{ include "gitea.fullname" . }}
{{- end }}
{{- end }}
@@ -42,8 +42,8 @@ spec:
{{- if .Values.deployment.schedulerName }}
schedulerName: "{{ .Values.deployment.schedulerName }}"
{{- end }}
{{- if (or .Values.serviceAccount.create .Values.serviceAccount.name) }}
serviceAccountName: {{ include "gitea.serviceAccountName" . }}
{{- if .Values.serviceAccount.enabled }}
serviceAccountName: {{ include "gitea.serviceAccount.name" . }}
{{- end }}
{{- if .Values.deployment.priorityClassName }}
priorityClassName: "{{ .Values.deployment.priorityClassName }}"
@@ -145,8 +145,8 @@ spec:
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
{{- include "gitea.container-additional-mounts" . | nindent 12 }}
{{- if .Values.extraContainers }}
@@ -211,12 +211,10 @@ spec:
defaultMode: 0100
{{- end }}
{{- if .Values.persistence.enabled }}
{{- if .Values.persistence.mount }}
- name: data
persistentVolumeClaim:
claimName: {{ .Values.persistence.claimName }}
{{- end }}
{{- else if not .Values.persistence.enabled }}
claimName: {{ include "gitea.persistentVolumeClaim.name" . }}
{{- else }}
- name: data
emptyDir: {}
{{- end }}
@@ -1,26 +0,0 @@
{{- if and .Values.persistence.enabled .Values.persistence.create }}
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: {{ .Values.persistence.claimName }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
annotations:
{{ .Values.persistence.annotations | toYaml | indent 4}}
labels:
{{ .Values.persistence.labels | toYaml | indent 4}}
spec:
accessModes:
{{- if gt (.Values.deployment.replicas | int) 1 }}
- ReadWriteMany
{{- else }}
{{- .Values.persistence.accessModes | toYaml | nindent 4 }}
{{- end }}
volumeMode: Filesystem
{{- include "gitea.persistence.storageClass" . | nindent 2 }}
{{- with .Values.persistence.volumeName }}
volumeName: {{ . }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.size }}
{{- end }}
-21
View File
@@ -1,21 +0,0 @@
{{- if .Values.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "gitea.serviceAccountName" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
labels:
{{- include "gitea.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.labels }}
{{- . | toYaml | nindent 4 }}
{{- end }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- . | toYaml | nindent 4 }}
{{- end }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
{{- with .Values.serviceAccount.imagePullSecrets }}
imagePullSecrets:
{{- . | toYaml | nindent 2 }}
{{- end }}
{{- end }}
+33
View File
@@ -0,0 +1,33 @@
{{- if eq (include "gitea.persistentVolumeClaim.enabled" .) "true" }}
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
{{- with (include "gitea.persistentVolumeClaim.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.persistentVolumeClaim.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.persistentVolumeClaim.name" . }}
namespace: {{ .Release.Namespace }}
spec:
accessModes:
{{- if gt (.Values.deployment.replicas | int) 1 }}
- ReadWriteMany
{{- else }}
{{- .Values.persistence.new.accessModes | toYaml | nindent 4 }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.new.size }}
{{- with .Values.persistence.new.storageClassName }}
storageClassName: {{ . }}
{{- end }}
volumeMode: Filesystem
{{- with .Values.persistence.new.persistentVolumeName }}
volumeName: {{ . }}
{{- end }}
{{- end }}
@@ -37,8 +37,8 @@ stringData:
{{- end }}
{{- end }}
{{- if eq (first .Values.persistence.accessModes) "ReadWriteOnce" -}}
{{- fail "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany." -}}
{{- if eq (first .Values.persistence.new.accessModes) "ReadWriteOnce" -}}
{{- fail "When using multiple replicas, a RWX file system is required and persistence.new.accessModes[0] must be set to ReadWriteMany." -}}
{{- end }}
{{- if .Values.gitea.config.indexer -}}
{{- if eq .Values.gitea.config.indexer.ISSUE_INDEXER_TYPE "bleve" -}}
+21
View File
@@ -0,0 +1,21 @@
{{- if eq (include "gitea.serviceAccount.enabled" .) "true" }}
---
apiVersion: v1
kind: ServiceAccount
metadata:
{{- with (include "gitea.serviceAccount.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.serviceAccount.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.serviceAccount.name" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
automountServiceAccountToken: {{ .Values.serviceAccount.new.automountServiceAccountToken }}
{{- with .Values.serviceAccount.new.imagePullSecrets }}
imagePullSecrets:
{{- . | toYaml | nindent 2 }}
{{- end }}
{{- end }}
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_admin.yaml
- templates/secret_admin.yaml
tests:
- it: skips rendering when the admin user is disabled
set:
+3 -3
View File
@@ -3,17 +3,17 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_inlineConfig.yaml
- templates/secret_inlineConfig.yaml
tests:
- it: "actions are enabled by default (based on vanilla Gitea behavior)"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
notExists:
path: stringData.actions
- it: "actions can be disabled via inline config"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea.config.actions.ENABLED: false
asserts:
+3 -3
View File
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "cache is configured correctly for valkey"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: true
@@ -17,7 +17,7 @@ tests:
HOST=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- it: "cache is configured correctly for 'memory' when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -30,7 +30,7 @@ tests:
HOST=
- it: "cache can be customized when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -3,11 +3,11 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
tests:
- it: uses `gitea config edit-ini` to write app.ini from environment variables
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: metrics token is set
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
@@ -18,7 +18,7 @@ tests:
ENABLED=true
TOKEN=somepassword
- it: metrics token is empty
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
@@ -31,7 +31,7 @@ tests:
value: |-
ENABLED=true
- it: metrics token is nil
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
@@ -44,7 +44,7 @@ tests:
value: |-
ENABLED=true
- it: does not configures a token if metrics are disabled
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
+3 -3
View File
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "queue is configured correctly for valkey"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: true
@@ -17,7 +17,7 @@ tests:
TYPE=redis
- it: "queue is configured correctly for 'levelDB' when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -30,7 +30,7 @@ tests:
TYPE=level
- it: "queue can be customized when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "[default values] uses ingress host for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -22,7 +22,7 @@ tests:
################################################
- it: "[no ingress hosts] uses gitea http service for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
ingress:
hosts: []
@@ -43,7 +43,7 @@ tests:
################################################
- it: "[provided via values] uses that for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea.config.server.DOMAIN: provided.example.com
ingress:
@@ -69,7 +69,7 @@ tests:
################################################
- it: "[route enabled] uses route host for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
route:
enabled: true
@@ -91,7 +91,7 @@ tests:
################################################
- it: "[route tls termination] uses https for ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
route:
enabled: true
@@ -107,7 +107,7 @@ tests:
################################################
- it: "[HTTPRoute enabled] uses first hostname for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
ingress:
hosts: []
@@ -137,7 +137,7 @@ tests:
################################################
- it: "[HTTPRoute tls] switches ROOT_URL to https"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
ingress:
hosts: []
+3 -3
View File
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "session is configured correctly for valkey"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: true
@@ -17,7 +17,7 @@ tests:
PROVIDER_CONFIG=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- it: "session is configured correctly for 'memory' when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -30,7 +30,7 @@ tests:
PROVIDER_CONFIG=
- it: "session can be customized when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -106,7 +106,7 @@ tests:
name: gitea-unittests-postgresql-ha-pgpool
namespace: testing
- it: "[gitea] connects to pgpool service"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -115,14 +115,14 @@ tests:
- it: "[gitea] connects to pgpool service with custom cluster domain"
set:
clusterDomain: my-special-cluster.local
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
path: stringData.database
pattern: HOST=gitea-unittests-postgresql-ha-pgpool.testing.svc.my-special-cluster.local:1234
- it: "[gitea] connects to configured database"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -65,7 +65,7 @@ tests:
name: gitea-unittests-postgresql
namespace: testing
- it: "[gitea] connects to postgresql service"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -74,14 +74,14 @@ tests:
- it: "[gitea] connects to postgresql service with custom cluster domain"
set:
clusterDomain: my-special-cluster.local
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
path: stringData.database
pattern: HOST=gitea-unittests-postgresql.testing.svc.my-special-cluster.local:1234
- it: "[gitea] connects to configured database"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -35,7 +35,7 @@ tests:
targetPort: tcp
protocol: TCP
- it: "[gitea] waits for valkey to be up and running"
template: templates/gitea/secret_init.yaml
template: templates/secret_init.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -44,7 +44,7 @@ tests:
- it: "[gitea] waits for valkey to be up and running with custom cluster domain"
set:
clusterDomain: my-special-cluster.local
template: templates/gitea/secret_init.yaml
template: templates/secret_init.yaml
asserts:
- documentIndex: 0
matchRegex:
+21 -18
View File
@@ -3,22 +3,23 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: fails with multiple replicas and "GIT_GC_REPOS" enabled
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
persistence:
accessModes:
- ReadWriteMany
new:
accessModes:
- ReadWriteMany
gitea:
config:
cron:
@@ -28,21 +29,22 @@ tests:
- failedTemplate:
errorMessage: "Invoking the garbage collector via CRON is not yet supported when running with multiple replicas. Please set 'gitea.config.cron.GIT_GC_REPOS.enabled = false'."
- it: fails with multiple replicas and RWX file system not set
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
asserts:
- failedTemplate:
errorMessage: "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany."
errorMessage: "When using multiple replicas, a RWX file system is required and persistence.new.accessModes[0] must be set to ReadWriteMany."
- it: fails with multiple replicas and bleve issue indexer
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
persistence:
accessModes:
- ReadWriteMany
new:
accessModes:
- ReadWriteMany
gitea:
config:
indexer:
@@ -51,13 +53,14 @@ tests:
- failedTemplate:
errorMessage: "When using multiple replicas, the issue indexer (gitea.config.indexer.ISSUE_INDEXER_TYPE) must be set to a HA-ready provider such as 'meilisearch', 'elasticsearch' or 'db' (if the DB is HA-ready)."
- it: fails with multiple replicas and bleve repo indexer
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
persistence:
accessModes:
- ReadWriteMany
new:
accessModes:
- ReadWriteMany
gitea:
config:
indexer:
+11 -11
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: reads the admin credentials from the generated secret
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- contains:
path: spec.template.spec.initContainers[2].env
@@ -45,7 +45,7 @@ tests:
value: keepUpdated
- it: reads the admin credentials from the configured keys of an existing secret
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.existingSecret.enabled: true
secrets.admin.existingSecret.secretName: custom-admin-secret
@@ -79,7 +79,7 @@ tests:
name: custom-admin-secret
- it: omits the admin environment when the admin user is disabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.enabled: false
asserts:
@@ -95,7 +95,7 @@ tests:
any: true
- it: fails on an unsupported password mode
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.passwordMode: unsupported
asserts:
+39 -39
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: renders a deployment
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- hasDocuments:
count: 1
@@ -21,14 +21,14 @@ tests:
apiVersion: apps/v1
name: gitea-unittests
- it: renders no deployment when disabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.enabled: false
asserts:
- hasDocuments:
count: 0
- it: deployment labels are set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.labels:
hello: world
@@ -46,7 +46,7 @@ tests:
content:
hello: world
- it: deployment labels are not in selector matchLabels
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.labels:
custom-label: custom-value
@@ -58,7 +58,7 @@ tests:
app.kubernetes.io/name: gitea
app.kubernetes.io/instance: gitea-unittests
- it: deployment labels are always rendered
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- isSubset:
path: metadata.labels
@@ -68,12 +68,12 @@ tests:
app.kubernetes.io/instance: gitea-unittests
app.kubernetes.io/managed-by: Helm
- it: deployment annotations are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: metadata.annotations
- it: deployment annotations are set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.annotations:
hello: world
@@ -86,7 +86,7 @@ tests:
asserts:
- notExists:
path: spec.template.spec.nodeSelector
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: nodeSelector is defined
set:
deployment.nodeSelector:
@@ -98,14 +98,14 @@ tests:
content:
foo: bar
bar: foo
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: affinity is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.affinity
- it: affinity is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.affinity:
nodeAffinity:
@@ -129,12 +129,12 @@ tests:
values:
- linux
- it: dnsConfig is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.dnsConfig
- it: dnsConfig is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.dnsConfig:
nameservers:
@@ -152,12 +152,12 @@ tests:
- name: ndots
value: "2"
- it: priorityClassName is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.priorityClassName
- it: priorityClassName is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.priorityClassName: high-priority
asserts:
@@ -165,12 +165,12 @@ tests:
path: spec.template.spec.priorityClassName
value: high-priority
- it: schedulerName is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.schedulerName
- it: schedulerName is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.schedulerName: stork
asserts:
@@ -178,7 +178,7 @@ tests:
path: spec.template.spec.schedulerName
value: stork
- it: strategy defaults to a rolling update
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.strategy
@@ -188,7 +188,7 @@ tests:
maxUnavailable: 0
maxSurge: 100%
- it: strategy omits rollingUpdate for other strategy types
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.strategy.type: Recreate
asserts:
@@ -197,12 +197,12 @@ tests:
value:
type: Recreate
- it: tolerations are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.tolerations
- it: tolerations are defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.tolerations:
- key: database/type
@@ -218,12 +218,12 @@ tests:
value: postgres
effect: NoSchedule
- it: topologySpreadConstraints are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.topologySpreadConstraints
- it: topologySpreadConstraints are defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.topologySpreadConstraints:
- topologyKey: kubernetes.io/hostname
@@ -244,7 +244,7 @@ tests:
app.kubernetes.io/instance: gitea-unittests
- it: "injects TMP_EXISTING_ENVS_FILE as environment variable to 'init-app-ini' init container"
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- contains:
path: spec.template.spec.initContainers[1].env
@@ -252,7 +252,7 @@ tests:
name: TMP_EXISTING_ENVS_FILE
value: /tmp/existing-envs
- it: "injects ENV_TO_INI_MOUNT_POINT as environment variable to 'init-app-ini' init container"
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- contains:
path: spec.template.spec.initContainers[1].env
@@ -260,7 +260,7 @@ tests:
name: ENV_TO_INI_MOUNT_POINT
value: /env-to-ini-mounts
- it: "deployment.gitea.env is injected into all init containers and the gitea container"
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.env:
- name: VARIABLE
@@ -287,7 +287,7 @@ tests:
name: VARIABLE
value: my-value
- it: CPU resources are defined as well as GOMAXPROCS
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.resources:
limits:
@@ -315,7 +315,7 @@ tests:
cpu: 100ms
memory: 100Mi
- it: container resources default to an empty map and GOMAXPROCS is omitted
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.containers[0].resources
@@ -329,12 +329,12 @@ tests:
divisor: "1"
resource: limits.cpu
- it: pod level resources are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.resources
- it: pod level resources are defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.resources:
limits:
@@ -354,7 +354,7 @@ tests:
cpu: 250m
memory: 256Mi
- it: Init containers have correct volumeMount path
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
initContainersScriptsVolumeMountPath: "/custom/init/path"
asserts:
@@ -365,7 +365,7 @@ tests:
path: spec.template.spec.initContainers[*].volumeMounts[?(@.name=="config")].mountPath
value: "/custom/init/path"
- it: Init containers have correct volumeMount path if there is no override
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.initContainers[*].volumeMounts[?(@.name=="init")].mountPath
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: omits the checksum annotations by default
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.enabled: true
secrets.config.enabled: true
@@ -38,7 +38,7 @@ tests:
path: spec.template.metadata.annotations["checksum/metrics"]
- it: adds a checksum annotation for every Secret when addSHASumAnnotation is enabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.addSHASumAnnotation: true
secrets.admin.enabled: true
@@ -75,7 +75,7 @@ tests:
path: spec.template.metadata.annotations["checksum/metrics"]
- it: omits the checksum annotation of a single disabled Secret only
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.addSHASumAnnotation: false
secrets.admin.enabled: true
@@ -112,7 +112,7 @@ tests:
path: spec.template.metadata.annotations["checksum/metrics"]
- it: adds the checksum of Secrets provided by the user
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.enabled: true
secrets.admin.addSHASumAnnotation: true
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: Renders a deployment
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- hasDocuments:
count: 1
@@ -21,7 +21,7 @@ tests:
apiVersion: apps/v1
name: gitea-unittests
- it: Deployment with empty additionalConfigFromEnvs
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.additionalConfigFromEnvs: []
asserts:
@@ -49,7 +49,7 @@ tests:
- name: ENV_TO_INI_MOUNT_POINT
value: /env-to-ini-mounts
- it: Deployment with standard additionalConfigFromEnvs
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.additionalConfigFromEnvs: [{name: GITEA_database_HOST, value: my-db:123}, {name: GITEA_database_USER, value: my-user}]
asserts:
@@ -81,7 +81,7 @@ tests:
- name: GITEA_database_USER
value: my-user
- it: Deployment with templated additionalConfigFromEnvs
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.misc.host: my-db-host:321
gitea.misc.user: my-db-user
@@ -115,7 +115,7 @@ tests:
- name: GITEA_database_USER
value: my-db-user
- it: Deployment with additionalConfigFromEnvs templated secret name
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.misc.existingSecret: my-db-secret
gitea.additionalConfigFromEnvs[0]:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deprecation.yaml
- templates/deprecation.yaml
tests:
- it: renders nothing with the default values
asserts:
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: uses direct execution when extraEnvSourceFile is not set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.initContainers[1].command
@@ -26,7 +26,7 @@ tests:
path: spec.template.spec.initContainers[2].args
- it: sources env file in init-app-ini when extraEnvSourceFile is set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
extraEnvSourceFile: /vault/secrets/gitea
@@ -42,7 +42,7 @@ tests:
pattern: config_environment\.sh
- it: sources env file in configure-gitea when extraEnvSourceFile is set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
extraEnvSourceFile: /vault/secrets/gitea
@@ -58,7 +58,7 @@ tests:
pattern: configure_gitea\.sh
- it: sources env file in configure-gpg when extraEnvSourceFile is set with signing enabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -77,7 +77,7 @@ tests:
pattern: configure_gpg_environment\.sh
- it: includes file existence check in source command
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
extraEnvSourceFile: /vault/secrets/gitea
@@ -3,23 +3,23 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: Render the deployment (default)
asserts:
- hasDocuments:
count: 1
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- lengthEqual:
path: spec.template.spec.initContainers
count: 3
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: Render the deployment (signing)
set:
@@ -29,11 +29,11 @@ tests:
asserts:
- hasDocuments:
count: 1
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- lengthEqual:
path: spec.template.spec.initContainers
count: 4
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: Render the deployment (extraInitContainers)
set:
@@ -54,22 +54,22 @@ tests:
asserts:
- hasDocuments:
count: 1
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- lengthEqual:
path: spec.template.spec.initContainers
count: 6
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- equal:
path: spec.template.spec.initContainers[0].name
value: bar
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- equal:
path: spec.template.spec.initContainers[5].name
value: foo
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: renders the chart-managed init containers in the configured order
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- link: "initConfigureGitea"
@@ -83,7 +83,7 @@ tests:
value: init-directories
- it: fails when an init container entry sets both container and link
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- link: "initDirectories"
@@ -95,7 +95,7 @@ tests:
errorMessage: "deployment.initContainers[0]: `container` and `link` are mutually exclusive"
- it: fails when an init container entry sets neither container nor link
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- name: foo
@@ -104,7 +104,7 @@ tests:
errorMessage: "deployment.initContainers[0]: either `container` or `link` must be set"
- it: fails when an init container links to an unknown configuration
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- link: "initSomething"
@@ -6,22 +6,22 @@ chart:
# Override appVersion to be consistent with used digest :)
appVersion: 1.19.3
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: default values
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3-rootless"
- it: tag override
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.tag: "1.19.4"
asserts:
@@ -29,7 +29,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.4-rootless"
- it: root-based image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: false
asserts:
@@ -37,7 +37,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3"
- it: scoped registry
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.registry: "example.com"
asserts:
@@ -45,7 +45,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "example.com/gitea:1.19.3-rootless"
- it: global registry
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
global.imageRegistry: "global.example.com"
asserts:
@@ -53,7 +53,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "global.example.com/gitea:1.19.3-rootless"
- it: digest for rootless image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment:
gitea:
@@ -65,7 +65,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3-rootless@sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
- it: image fullOverride (does not append rootless)
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment:
gitea:
@@ -82,7 +82,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3"
- it: digest for root-based image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment:
gitea:
@@ -94,7 +94,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3@sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
- it: digest and global registry
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
global.imageRegistry: "global.example.com"
deployment.gitea.image.digest: "sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
@@ -103,7 +103,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "global.example.com/gitea:1.19.3-rootless@sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
- it: correctly renders floating tag references
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
# use non-quoted values on purpose. See: https://gitea.com/gitea/helm-gitea/issues/631
deployment.gitea.image.tag: 1.21
@@ -124,7 +124,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.21-rootless"
- it: init containers use their own image configuration
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initDirectories.image.registry: "init.example.com"
deployment.initDirectories.image.tag: "1.19.4"
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: appends the per-container env
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initDirectories.env:
- name: INIT_DIRECTORIES
@@ -38,7 +38,7 @@ tests:
value: "1"
- it: renders the per-container envFrom
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initAppIni.envFrom:
- secretRef:
@@ -53,7 +53,7 @@ tests:
name: special-secret
- it: appends the per-container volumeMounts
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initConfigureGitea.volumeMounts:
- name: my-configmap-volume
@@ -74,7 +74,7 @@ tests:
readOnly: true
- it: overrides the resources of a single init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initDirectories.resources:
requests:
@@ -94,7 +94,7 @@ tests:
memory: 128Mi
- it: overrides the security context of a single init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.securityContext:
runAsUser: 1000
@@ -109,7 +109,7 @@ tests:
value: 1000
- it: renders the envFrom of the gitea container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.envFrom:
- configMapRef:
@@ -122,7 +122,7 @@ tests:
name: special-config
- it: omits envFrom when unset
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].envFrom
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_inlineConfig.yaml
- templates/secret_inlineConfig.yaml
tests:
- it: inline config stringData.server using TPL
set:
+11 -11
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: renders openshift-compatible defaults for chart-managed containers
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift.enabled: true
asserts:
@@ -62,7 +62,7 @@ tests:
type: RuntimeDefault
- it: does not force runAsUser 1000 for command init containers on OpenShift
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift.enabled: true
secrets.gpg.enabled: true
@@ -75,7 +75,7 @@ tests:
path: spec.template.spec.initContainers[3].securityContext.runAsUser
- it: preserves explicit pod and container security context overrides on OpenShift
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift:
enabled: true
@@ -103,7 +103,7 @@ tests:
value: 1000620000
- it: renders an explicit hostUsers=false override on OpenShift
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift:
enabled: true
+17 -17
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: renders default liveness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].livenessProbe.enabled
@@ -27,7 +27,7 @@ tests:
port: http
timeoutSeconds: 1
- it: renders default readiness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].readinessProbe.enabled
@@ -42,12 +42,12 @@ tests:
port: http
timeoutSeconds: 1
- it: does not render a default startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].startupProbe
- it: allows enabling a startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.startupProbe.enabled: true
asserts:
@@ -65,7 +65,7 @@ tests:
timeoutSeconds: 1
- it: allows overwriting the default port of the liveness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
livenessProbe:
@@ -79,7 +79,7 @@ tests:
port: my-port
- it: allows overwriting the default port of the readiness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
readinessProbe:
@@ -93,7 +93,7 @@ tests:
port: my-port
- it: allows overwriting the default port of the startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
startupProbe:
@@ -108,7 +108,7 @@ tests:
port: my-port
- it: allows using a non-default method as liveness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
livenessProbe:
@@ -136,7 +136,7 @@ tests:
timeoutSeconds: 13372
- it: allows using a non-default method as readiness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
readinessProbe:
@@ -164,7 +164,7 @@ tests:
timeoutSeconds: 13372
- it: allows using a non-default method as startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
startupProbe:
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: supports adding a sidecar container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
extraContainers:
- name: sidecar-bob
+11 -11
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: skips gpg init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notContains:
path: spec.template.spec.initContainers
@@ -20,7 +20,7 @@ tests:
content:
name: configure-gpg
- it: skips gpg env in `init-directories` init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: false
asserts:
@@ -29,14 +29,14 @@ tests:
content:
name: GNUPGHOME
- it: skips gpg env in runtime container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notContains:
path: spec.template.spec.containers[0].env
content:
name: GNUPGHOME
- it: skips gpg volume spec
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notContains:
path: spec.template.spec.volumes
+13 -13
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: adds gpg init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -49,7 +49,7 @@ tests:
mountPath: /raw
readOnly: true
- it: adds gpg env in `init-directories` init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -64,7 +64,7 @@ tests:
name: custom-gpg-secret
key: gpgHome
- it: adds gpg env in runtime container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -79,7 +79,7 @@ tests:
name: custom-gpg-secret
key: gpgHome
- it: reads the gpg home from the configured key of an existing secret
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -95,7 +95,7 @@ tests:
name: custom-gpg-secret
key: custom-gpg-home
- it: adds gpg volume spec
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.new.privateKey: "gpg-key-placeholder"
@@ -111,7 +111,7 @@ tests:
path: private.asc
defaultMode: 0100
- it: supports gpg volume spec with external reference
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: supports defining SSH log level for root based image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: false
asserts:
@@ -22,7 +22,7 @@ tests:
name: SSH_LOG_LEVEL
value: "INFO"
- it: supports overriding SSH log level
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: false
gitea.ssh.logLevel: "DEBUG"
@@ -33,7 +33,7 @@ tests:
name: SSH_LOG_LEVEL
value: "DEBUG"
- it: supports overriding SSH log level (even when image.fullOverride set)
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.19.3
deployment.gitea.image.rootless: false
@@ -45,7 +45,7 @@ tests:
name: SSH_LOG_LEVEL
value: "DEBUG"
- it: skips SSH_LOG_LEVEL for rootless image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: true
gitea.ssh.logLevel: "DEBUG" # explicitly defining a non-standard level here
@@ -56,7 +56,7 @@ tests:
content:
name: SSH_LOG_LEVEL
- it: skips SSH_LOG_LEVEL for rootless image (even when image.fullOverride set)
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.19.3
deployment.gitea.image.rootless: true
@@ -1,39 +1,17 @@
# File: tests/gitea-storageclass-tests.yaml
suite: storage class configuration tests
chart:
appVersion: 1.27.3
release:
name: gitea-storageclass-tests
name: gitea-unittests
namespace: testing
suite: Storage class configuration tests
templates:
- templates/gitea/persistentVolumeClaim.yaml
- templates/persistentVolumeClaim.yaml
tests:
- it: should set storageClassName when persistence.storageClass is defined
template: templates/gitea/persistentVolumeClaim.yaml
- it: Set storageClassName when persistence.new.storageClassName is defined
set:
persistence.storageClass: "my-storage-class"
asserts:
- equal:
path: "spec.storageClassName"
value: "my-storage-class"
- it: should set global.storageClass when persistence.storageClass is not defined
template: templates/gitea/persistentVolumeClaim.yaml
set:
global.storageClass: "default-storage-class"
persistence.enabled: true
persistence.new.storageClassName: my-storage-class
asserts:
- equal:
path: spec.storageClassName
value: "default-storage-class"
- it: should set storageClassName when persistence.storageClass is defined and global.storageClass is defined
template: templates/gitea/persistentVolumeClaim.yaml
set:
global.storageClass: "default-storage-class"
persistence.storageClass: "my-storage-class"
asserts:
- equal:
path: spec.storageClassName
value: "my-storage-class"
value: my-storage-class
@@ -3,11 +3,11 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/service_ssh.yaml
- templates/gitea/service_http.yaml
- templates/service_ssh.yaml
- templates/service_http.yaml
tests:
- it: supports adding custom labels to sshService
template: templates/gitea/service_ssh.yaml
template: templates/service_ssh.yaml
set:
service:
ssh:
@@ -19,7 +19,7 @@ tests:
value: "testvalue"
- it: keeps existing labels (ssh)
template: templates/gitea/service_ssh.yaml
template: templates/service_ssh.yaml
set:
service:
ssh:
@@ -29,7 +29,7 @@ tests:
path: metadata.labels["app"]
- it: supports adding custom labels to httpService
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -41,7 +41,7 @@ tests:
value: "testvalue"
- it: keeps existing labels (http)
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -51,7 +51,7 @@ tests:
path: metadata.labels["app"]
- it: render service.ssh.loadBalancerClass if set and type is LoadBalancer
template: templates/gitea/service_ssh.yaml
template: templates/service_ssh.yaml
set:
service:
ssh:
@@ -73,7 +73,7 @@ tests:
value: ["1.2.3.4/32", "5.6.7.8/32"]
- it: does not render when loadbalancer properties are set but type is not loadBalancerClass
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -92,7 +92,7 @@ tests:
path: spec.loadBalancerSourceRanges
- it: does not render loadBalancerClass by default even when type is LoadBalancer
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -107,8 +107,8 @@ tests:
- it: both ssh and http services exist
templates:
- templates/gitea/service_ssh.yaml
- templates/gitea/service_http.yaml
- templates/service_ssh.yaml
- templates/service_http.yaml
asserts:
- matchRegex:
path: metadata.name
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/backendTLSPolicy.yaml
- templates/backendTLSPolicy.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/clientSettingsPolicy.yaml
- templates/clientSettingsPolicy.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/httpRoute.yaml
- templates/httpRoute.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/tcpRoute.yaml
- templates/tcpRoute.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_gpg.yaml
- templates/secret_gpg.yaml
tests:
- it: renders nothing
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_gpg.yaml
- templates/secret_gpg.yaml
tests:
- it: fails rendering when nothing is configured
set:
+13 -13
View File
@@ -1,11 +1,11 @@
suite: Test ingress.yaml
chart:
appVersion: 1.27.3
release:
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
suite: Test ingress.yaml
templates:
- templates/gitea/ingress.yaml
- templates/ingress.yaml
tests:
- it: Skip ingress if ingress is disabled
set:
@@ -41,15 +41,15 @@ tests:
- containsDocument:
kind: Ingress
apiVersion: networking.k8s.io/v1
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
- notExists:
path: metadata.annotations
- isSubset:
path: metadata.labels
content:
app: gitea
app.kubernetes.io/instance: gitea-unittest
app.kubernetes.io/instance: gitea-unittests
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: gitea
app.kubernetes.io/version: 1.27.3
@@ -66,7 +66,7 @@ tests:
paths:
- backend:
service:
name: gitea-unittest-http
name: gitea-unittests-http
port:
number: 3000
path: /
@@ -101,8 +101,8 @@ tests:
- containsDocument:
kind: Ingress
apiVersion: networking.k8s.io/v1
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
- contains:
path: spec.rules
content:
@@ -111,7 +111,7 @@ tests:
paths:
- backend:
service:
name: gitea-unittest-http
name: gitea-unittests-http
port:
number: 32000
path: /
@@ -131,8 +131,8 @@ tests:
- containsDocument:
kind: Ingress
apiVersion: networking.k8s.io/v1
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
- isSubset:
path: metadata.annotations
content:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_init.yaml
- templates/secret_init.yaml
tests:
- it: renders a secret
asserts:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_init.yaml
- templates/secret_init.yaml
tests:
- it: runs gpg in batch mode
set:
@@ -63,7 +63,7 @@ tests:
chown -v 1000:1000 "${GNUPGHOME}"
fi
- it: it does not chown /data even when image.fullOverride is set
template: templates/gitea/secret_init.yaml
template: templates/secret_init.yaml
set:
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.20.5
asserts:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_init.yaml
- templates/secret_init.yaml
tests:
- it: runs gpg in batch mode
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_metrics.yaml
- templates/secret_metrics.yaml
tests:
- it: renders nothing if monitoring disabled and gitea.metrics.token empty
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_metrics.yaml
- templates/secret_metrics.yaml
tests:
- it: renders nothing if monitoring enabled and gitea.metrics.token empty
set:
@@ -0,0 +1,29 @@
chart:
appVersion: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
release:
name: gitea-unittests
namespace: testing
suite: PVC template
templates:
- templates/persistentVolumeClaim.yaml
tests:
- it: Skip persistentVolumeClaim if persistentVolumeClaim is disabled
set:
persistence.enabled: false
asserts:
- hasDocuments:
count: 0
- it: Render persistentVolumeClaim with default values
set:
persistence.enabled: true
persistence.new.storageClassName: "my-storage-class"
asserts:
- containsDocument:
apiVersion: v1
kind: PersistentVolumeClaim
name: gitea-unittests
namespace: testing
- equal:
path: spec.storageClassName
value: "my-storage-class"
-19
View File
@@ -1,19 +0,0 @@
suite: PVC template
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/persistentVolumeClaim.yaml
tests:
- it: Storage Class using TPL
set:
global.persistence.storageClass: "storage-class"
persistence.enabled: true
persistence.create: true
persistence.storageClass: "{{ .Values.global.persistence.storageClass }}"
asserts:
- isKind:
of: PersistentVolumeClaim
- equal:
path: spec.storageClassName
value: "storage-class"
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/route.yaml
- templates/route.yaml
tests:
- it: should create route when route.enabled is true
set:
@@ -0,0 +1,102 @@
chart:
appVersion: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
release:
name: gitea-unittests
namespace: testing
suite: ServiceAccount template
templates:
- templates/serviceAccount.yaml
tests:
- it: Render the ServiceAccount by default
asserts:
- hasDocuments:
count: 1
- containsDocument:
kind: ServiceAccount
apiVersion: v1
name: gitea-unittests
namespace: testing
- notExists:
path: metadata.annotations
- equal:
path: metadata.labels
value:
app: gitea
app.kubernetes.io/instance: gitea-unittests
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: gitea
app.kubernetes.io/version: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
helm.sh/chart: gitea-0.0.0
version: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
- equal:
path: automountServiceAccountToken
value: false
- notExists:
path: imagePullSecrets
- it: Skip rendering when serviceAccount.enabled is false
set:
serviceAccount:
enabled: false
asserts:
- hasDocuments:
count: 0
- it: Skip rendering when an existing ServiceAccount is used
set:
serviceAccount:
existingServiceAccount:
enabled: true
existingServiceAccountName: externally-existing-serviceaccount
asserts:
- hasDocuments:
count: 0
- it: Add custom labels when serviceAccount.new.labels is defined
set:
serviceAccount:
new:
labels:
custom: label
asserts:
- equal:
path: metadata.labels.custom
value: label
- it: Add custom annotations when serviceAccount.new.annotations is defined
set:
serviceAccount:
new:
annotations:
myCustom: annotation
asserts:
- equal:
path: metadata.annotations.myCustom
value: annotation
- it: Mount the token when serviceAccount.new.automountServiceAccountToken is true
set:
serviceAccount:
new:
automountServiceAccountToken: true
asserts:
- equal:
path: automountServiceAccountToken
value: true
- it: Reference image pull secrets when serviceAccount.new.imagePullSecrets is defined
set:
serviceAccount:
new:
imagePullSecrets:
- name: testing-image-pull-secret
- name: another-pull-secret
asserts:
- contains:
path: imagePullSecrets
content:
name: testing-image-pull-secret
- contains:
path: imagePullSecrets
content:
name: another-pull-secret
-82
View File
@@ -1,82 +0,0 @@
suite: ServiceAccount template (basic)
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceAccount.yaml
tests:
- it: skips rendering by default
asserts:
- hasDocuments:
count: 0
- it: renders default ServiceAccount object with serviceAccount.create=true
set:
serviceAccount.create: true
asserts:
- hasDocuments:
count: 1
- containsDocument:
kind: ServiceAccount
apiVersion: v1
name: gitea-unittests
- equal:
path: automountServiceAccountToken
value: false
- notExists:
path: imagePullSecrets
- notExists:
path: metadata.annotations
- it: allows for adding custom labels
set:
serviceAccount:
create: true
labels:
custom: label
asserts:
- equal:
path: metadata.labels.custom
value: label
- it: allows for adding custom annotations
set:
serviceAccount:
create: true
annotations:
myCustom: annotation
asserts:
- equal:
path: metadata.annotations.myCustom
value: annotation
- it: allows to override the generated name
set:
serviceAccount:
create: true
name: provided-serviceaccount-name
asserts:
- equal:
path: metadata.name
value: provided-serviceaccount-name
- it: allows to mount the token
set:
serviceAccount:
create: true
automountServiceAccountToken: true
asserts:
- equal:
path: automountServiceAccountToken
value: true
- it: allows to reference image pull secrets
set:
serviceAccount:
create: true
imagePullSecrets:
- name: testing-image-pull-secret
- name: another-pull-secret
asserts:
- contains:
path: imagePullSecrets
content:
name: testing-image-pull-secret
- contains:
path: imagePullSecrets
content:
name: another-pull-secret
@@ -1,37 +0,0 @@
suite: ServiceAccount template (reference)
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceAccount.yaml
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
tests:
- it: does not modify the deployment by default
template: templates/gitea/deployment.yaml
asserts:
- notExists:
path: spec.serviceAccountName
- it: adds the reference to the deployment with serviceAccount.create=true
template: templates/gitea/deployment.yaml
set:
serviceAccount.create: true
asserts:
- equal:
path: spec.template.spec.serviceAccountName
value: gitea-unittests
- it: allows referencing an externally created ServiceAccount to the deployment
template: templates/gitea/deployment.yaml
set:
serviceAccount:
create: false # explicitly set to define rendering behavior
name: "externally-existing-serviceaccount"
asserts:
- equal:
path: spec.template.spec.serviceAccountName
value: externally-existing-serviceaccount
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceMonitor.yaml
- templates/serviceMonitor.yaml
tests:
- it: skips rendering by default
asserts:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceMonitor.yaml
- templates/serviceMonitor.yaml
tests:
- it: renders nothing if gitea.metrics.serviceMonitor disabled and gitea.metrics.token empty
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceMonitor.yaml
- templates/serviceMonitor.yaml
tests:
- it: renders unsecure ServiceMonitor if gitea.metrics.token nil
set:
@@ -1,34 +0,0 @@
suite: test connection template
release:
name: gitea-unittests
namespace: testing
templates:
- templates/tests/test-http-connection.yaml
tests:
- it: renders openshift-compatible defaults for the test pod
set:
openshift.enabled: true
asserts:
- notExists:
path: spec.hostUsers
- equal:
path: spec.containers[0].securityContext
value:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
- it: renders an explicit hostUsers=false override for the test pod
set:
openshift:
enabled: true
deployment:
hostUsers: false
asserts:
- equal:
path: spec.hostUsers
value: false
+45 -40
View File
@@ -5,7 +5,6 @@
#
## @param global.imageRegistry global image registry override.
## @param global.imagePullSecrets global image pull secrets override; can be extended by `imagePullSecrets`.
## @param global.storageClass global storage class override.
## @param global.hostAliases global hostAliases which will be added to the pod's hosts files.
global:
imageRegistry: ""
@@ -14,7 +13,6 @@ global:
## - myRegistryKeySecretName
##
imagePullSecrets: []
storageClass: ""
hostAliases: []
# - ip: 192.168.137.2
# hostnames:
@@ -84,7 +82,6 @@ deployment:
image:
registry: "docker.gitea.com"
repository: gitea
# Overrides the image tag whose default is the chart appVersion.
tag: ""
digest: ""
pullPolicy: IfNotPresent
@@ -871,47 +868,55 @@ service:
## @section ServiceAccount
## @param serviceAccount.create Enable the creation of a ServiceAccount.
## @param serviceAccount.name Name of the created ServiceAccount, defaults to release name. Can also link to an externally provided ServiceAccount that should be used.
## @param serviceAccount.automountServiceAccountToken Enable/disable auto mounting of the service account token.
## @param serviceAccount.imagePullSecrets Image pull secrets, available to the ServiceAccount.
## @param serviceAccount.annotations Custom annotations for the ServiceAccount.
## @param serviceAccount.labels Custom labels for the ServiceAccount.
serviceAccount:
create: false
name: ""
automountServiceAccountToken: false
imagePullSecrets: []
# - name: private-registry-access
annotations: {}
labels: {}
## @param serviceAccount.enabled Assign the pod to use the ServiceAccount.
enabled: true
## @param serviceAccount.existingServiceAccount.enabled Enable using an existing ServiceAccount.
## @param serviceAccount.existingServiceAccount.existingServiceAccountName Name of the existing ServiceAccount to use.
existingServiceAccount:
enabled: false
existingServiceAccountName: ""
## @param serviceAccount.new.annotations Custom annotations for the ServiceAccount.
## @param serviceAccount.new.labels Custom labels for the ServiceAccount.
## @param serviceAccount.new.automountServiceAccountToken Enable/disable auto mounting of the service account token.
## @param serviceAccount.new.imagePullSecrets Image pull secrets, available to the ServiceAccount.
new:
annotations: {}
labels: {}
automountServiceAccountToken: false
imagePullSecrets: []
# - name: private-registry-access
## @section Persistence
## @param persistence.enabled Enable persistent storage.
## @param persistence.create Whether to create the persistentVolumeClaim for shared storage.
## @param persistence.mount Whether the persistentVolumeClaim should be mounted (even if not created).
## @param persistence.claimName Use an existing claim to store repository information.
## @param persistence.size Size for persistence to store repo information.
## @param persistence.accessModes AccessMode for persistence.
## @param persistence.labels Labels for the persistence volume claim to be created.
## @param persistence.annotations.helm.sh/resource-policy Resource policy for the persistence volume claim.
## @param persistence.storageClass Name of the storage class to use.
## @param persistence.subPath Subdirectory of the volume to mount at.
## @param persistence.volumeName Name of persistent volume in PVC.
persistence:
enabled: true
create: true
mount: true
claimName: gitea-shared-storage
size: 10Gi
accessModes:
- ReadWriteOnce
labels: {}
storageClass:
subPath:
volumeName: ""
annotations:
helm.sh/resource-policy: keep
## @param persistence.enabled Enable persistent storage.
enabled: false
## @param persistence.existingPersistentVolumeClaim.enabled Enable using an existing persistent volume claim.
## @param persistence.existingPersistentVolumeClaim.persistentVolumeClaimName Name of the existing persistent volume claim to use.
existingPersistentVolumeClaim:
enabled: false
persistentVolumeClaimName: ""
## @param persistence.new.annotations.helm.sh/resource-policy Resource policy for the new persistent volume claim.
## @param persistence.new.labels Labels for the new persistent volume claim.
## @param persistence.new.accessModes AccessMode for the new persistent volume claim.
## @param persistence.new.persistentVolumeName Name of the persistent volume for the new persistent volume claim.
## @param persistence.new.size Size for the new persistent volume claim.
## @param persistence.new.storageClassName Name of the storage class to use for the new persistent volume claim.
## @param persistence.new.subPath Subdirectory of the volume to mount at for the new persistent volume claim.
new:
annotations:
helm.sh/resource-policy: keep
labels: {}
accessModes:
- ReadWriteOnce
persistentVolumeName: ""
size: 10Gi
storageClassName: ""
subPath: ""
## @param extraContainers Additional sidecar containers to run in the pod.
extraContainers: []