Compare commits

..
17 Commits
Author SHA1 Message Date
volker.raschek ccea2082c3 fix(ci): add xterm
changelog / changelog (push) Successful in 20s
Bash / bash-unittest (push) Successful in 29s
Helm / helm-unittest (push) Successful in 1m12s
Helm / helm-lint (push) Successful in 10s
2026-09-14 20:59:24 +02:00
volker.raschek 4016c5396d fix(ci): add bash unittests
changelog / changelog (push) Successful in 17s
Bash / bash-unittest (push) Failing after 23s
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 1m11s
2026-09-14 20:57:01 +02:00
volker.raschekandCopilot d35177ec71 chore(renovate): migrate the configuration to plain JSON
Helm / helm-lint (push) Successful in 17s
changelog / changelog (push) Successful in 20s
Helm / helm-unittest (push) Successful in 1m9s
The JSON5 syntax was not used for anything that JSON cannot express. The only comment-looking entry was already a
`description` field, which renovate evaluates itself and which therefore survives the conversion. Plain JSON is the
better default here, because it needs no dedicated parser in editors and tooling.

The converted configuration was verified against the JSON5 parser to be structurally identical to its predecessor.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:42:40 +02:00
volker.raschekandCopilot e97f3b3bba fix(ci): resolve the helm dependencies with dependency update
changelog / changelog (push) Successful in 16s
Helm / helm-lint (push) Successful in 16s
Helm / helm-unittest (push) Successful in 31s
`helm dependency build` only downloads charts from repositories that are already registered in the local repository
cache. On a fresh runner that cache is empty, so the classic repository of the valkey dependency could not be resolved:
"no repository definition for https://valkey.io/valkey-helm. Please add the missing repos via 'helm repo add'". The two
bitnami dependencies were unaffected, because OCI references do not need a repository entry.

`helm dependency update` resolves the repository URLs straight from `Chart.yaml` and therefore needs no additional
`helm repo add` step. Repeating the URL in the workflow would only invite drift, since renovate updates `Chart.yaml`
alone. All three dependencies are pinned to exact versions, so the resolution result is identical to `Chart.lock`.

This corrects 0102563, which introduced the `dependency build` step.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:38:05 +02:00
volker.raschekandCopilot 70a033d519 chore(make): add a clean target
Helm / helm-lint (push) Failing after 12s
changelog / changelog (push) Successful in 16s
Helm / helm-unittest (push) Failing after 22s
Removes the artifacts that are produced by the other targets and ignored by git, so a broken state can be reset without
remembering which directories are generated. `helm dependency build` populates `charts`, the readme generator installs
`node_modules` and packaging leaves the chart archive and its signature behind.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:33:19 +02:00
volker.raschekandCopilot 010256397a fix(ci): build the helm dependencies before linting and testing
The `charts` directory is ignored by git, so a fresh checkout does not contain the postgresql, postgresql-ha and valkey
sub-charts. Locally the workflow appeared to work because `make helm/dependency-update` had populated the directory at
some earlier point.

Without the sub-charts every suite that asserts on a dependency template failed with "document index 0 is out of range"
and "template gitea/charts/postgresql/templates/primary/svc.yaml not exists or not selected in test suite". `helm lint`
was affected for the same reason.

`helm dependency build` is used instead of `helm dependency update`, because `Chart.lock` is committed and the pinned
versions should be resolved reproducibly rather than refreshed on every run.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:32:37 +02:00
volker.raschekandCopilot 552fe8c56e refactor(templates): move the templates out of the gitea subdirectory
Helm / helm-lint (push) Successful in 9s
changelog / changelog (push) Successful in 29s
Helm / helm-unittest (push) Failing after 21s
Markdown linter / markdown-lint (push) Successful in 17s
Markdown linter / markdown-link-checker (push) Successful in 56s
The `templates/gitea` subdirectory did not group anything meaningful, since every template of this chart belongs to
Gitea. It only duplicated the chart name in every path and forced the unit tests to spell out
`templates/gitea/<name>.yaml`, while `_helpers.tpl` and `NOTES.txt` already lived directly in `templates`.

All templates now live in `templates`, which matches the layout of the bundled sub-charts and the Helm defaults.

The checksum helper in `templates/_secrets.tpl` built its include path from `$root.Template.BasePath` and therefore
carried the subdirectory in a `printf` format string instead of a literal path. Without adjusting it the chart failed to
render with "no template gitea/templates/gitea/secret_config.yaml associated with template gotpl".

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 20:28:17 +02:00
volker.raschekandCopilot 0a237ba2c1 refactor(serviceAccount)!: group the values into existingServiceAccount and new
Helm / helm-lint (push) Successful in 13s
changelog / changelog (push) Successful in 20s
Helm / helm-unittest (push) Failing after 40s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 32s
The previous notation mixed two concerns in a single flat dict: `create`/`name` decided whether the chart manages the
ServiceAccount or only references an externally provided one, while the remaining keys only ever applied to a
chart-managed ServiceAccount. That made `name` ambiguous, because it either renamed the generated object or pointed to a
foreign one, and it forced the deployment to guard the reference with `or .Values.serviceAccount.create
.Values.serviceAccount.name`.

The values are now grouped the same way as `persistence`, which was restructured in dfe087c. `serviceAccount.enabled`
controls whether the pod uses a ServiceAccount at all, `serviceAccount.existingServiceAccount` references an externally
managed object and `serviceAccount.new` holds the properties of the object created by the chart. The templates follow
the established helper layout in `templates/gitea/_serviceAccounts.tpl`.

Two latent bugs are fixed along the way. The annotation helper was defined as `gitea.secret.admin.annotations`, so the
`gitea.serviceAccount.annotations` include in the template never resolved. And the duplicated name helper
`gitea.serviceAccountName` in `templates/_helpers.tpl` is removed in favour of `gitea.serviceAccount.name`.

BREAKING CHANGE:
- `serviceAccount.create` does no longer exist. Use `serviceAccount.enabled` instead. The default changed from `false`
  to `true`, so a ServiceAccount is now created unless it is explicitly disabled.
- `serviceAccount.name` does no longer exist. Use `serviceAccount.existingServiceAccount.enabled` together with
  `serviceAccount.existingServiceAccount.existingServiceAccountName` to reference an externally managed ServiceAccount.
- `serviceAccount.annotations`, `serviceAccount.labels`, `serviceAccount.automountServiceAccountToken` and
  `serviceAccount.imagePullSecrets` moved below `serviceAccount.new`.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 19:15:58 +02:00
volker.raschekandCopilot dfe087c0c1 refactor(persistence)!: group the values into existingPersistentVolumeClaim and new
Helm / helm-lint (push) Successful in 13s
changelog / changelog (push) Successful in 22s
Helm / helm-unittest (push) Failing after 45s
Markdown linter / markdown-link-checker (push) Successful in 44s
Markdown linter / markdown-lint (push) Successful in 36s
The flat `persistence` dict mixed three concerns: whether persistence is used at all, whether the chart creates the
PersistentVolumeClaim, and how that claim is shaped. The pairs `create`/`claimName` and `enabled`/`mount` were only
meaningful in certain combinations, so an invalid configuration such as `create=true` together with a foreign
`claimName` was silently accepted. The same split into an `existingX`/`new` pair is already used for the Secrets, so
this aligns persistence with the rest of the chart.

`persistence.enabled` now only decides whether a volume is used at all. `persistence.existingPersistentVolumeClaim`
points at a claim managed outside of the chart, and everything under `persistence.new` describes the claim the chart
creates itself. Rendering and naming move into `templates/gitea/_persistentVolumeClaims.tpl` so the Deployment and the
PersistentVolumeClaim derive the claim name from a single helper instead of repeating the value lookups.

Support for `global.storageClass` is dropped. It was a chart-wide override that silently applied to the Gitea claim and
was evaluated through `tpl`, which made the effective storage class hard to predict. The storage class is now set
explicitly via `persistence.new.storageClassName`, which also matches the field name in the PersistentVolumeClaim spec.

BREAKING CHANGE: The `persistence` values were restructured and `global.storageClass` was removed.

- `persistence.create` and `persistence.mount` are gone. Set `persistence.enabled` to use a volume and
  `persistence.existingPersistentVolumeClaim.enabled` to reuse a claim that is not managed by the chart.
- `persistence.claimName` moves to `persistence.existingPersistentVolumeClaim.persistentVolumeClaimName`. A claim
  created by the chart is now named after `gitea.fullname` instead of the default `gitea-shared-storage`.
- `persistence.accessModes`, `annotations`, `labels`, `size` and `subPath` move into `persistence.new`.
- `persistence.volumeName` becomes `persistence.new.persistentVolumeName`.
- `persistence.storageClass` and `global.storageClass` become `persistence.new.storageClassName`.
- `persistence.enabled` now defaults to `false`.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 15:38:06 +02:00
volker.raschekandCopilot 761921faed test(ingress): align assertions with the release name and namespace
The suite header was changed to the release `gitea-unittests` in the namespace `testing`, but the assertions still
expected the previous `gitea-unittest` and `gitea-debug`. That made four cases fail on the rendered resource name, the
`app.kubernetes.io/instance` label and the backend Service name.

Renovate comments had additionally been copied into the expected `app.kubernetes.io/version` and `version` label values.
They only matched by accident, because YAML strips the trailing comment from an unquoted scalar. Removing them keeps the
assertions honest about what is actually compared.

Co-authored-by: Copilot <copilot@github.com>
2026-09-14 15:24:55 +02:00
volker.raschek 69b546d1cd fix(ci): update commit lint
changelog / changelog (push) Successful in 15s
Helm / helm-lint (push) Successful in 7s
Helm / helm-unittest (push) Failing after 19s
2026-09-13 23:12:40 +02:00
volker.raschek b2af7400b5 fix(ci): update helm linters
changelog / changelog (push) Successful in 15s
Helm / helm-lint (push) Successful in 7s
Helm / helm-unittest (push) Failing after 21s
2026-09-13 23:10:32 +02:00
volker.raschek 0e15d3bd74 fix(ci): add markdown linters 2026-09-13 23:09:37 +02:00
volker.raschekandCopilot 3fb036befe docs(values): end all @param descriptions with a dot
changelog / changelog (push) Successful in 16s
check-and-test / check-and-test (push) Failing after 3h14m22s
The `missing-dot` Makefile target enforces that every `## @param` and `## @skip` annotation ends with a dot, so that the
generated README parameter table reads consistently. 211 annotations violated that rule and made the check fail.

For the `*.image.fullOverride` parameters the dot was moved outside of the bold markup so that the sentence ends with a
dot instead of `**`.

README.md was regenerated via `make readme`.

Co-authored-by: Copilot <copilot@github.com>
2026-09-13 23:02:48 +02:00
volker.raschekandCopilot 05bdc2b521 docs(copilot): align build & test commands with the Makefile
The Makefile targets were renamed to a `<group>/<action>` scheme and a `missing-dot` target was added, but the Copilot
instructions still referenced the old `unittests-*` targets and a non-existent `unittests` target. Contributors and
agents following these instructions therefore ran commands that no longer exist.

Also correct the yamllint configuration file name to `.yamllint.yaml`.

Co-authored-by: Copilot <copilot@github.com>
2026-09-13 23:02:48 +02:00
volker.raschek c510e06609 fix(Makefile): update targets and add link checker 2026-09-13 22:51:05 +02:00
volker.raschek dee7e1f0f6 fix(copilot): adapt file name pattern 2026-09-13 22:00:39 +02:00
105 changed files with 2350 additions and 1335 deletions
+23
View File
@@ -0,0 +1,23 @@
name: Bash
on:
pull_request:
types: [ "opened", "reopened", "synchronize" ]
push:
branches:
- '**'
tags-ignore:
- '**'
workflow_dispatch: {}
jobs:
bash-unittest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
submodules: true
- env:
TERM: xterm
name: Run bash unittests
run: make bash/unittest
@@ -1,19 +1,16 @@
name: commitlint
name: Commit Linter
on:
pull_request:
branches:
- "*"
types:
- opened
- edited
branches: [ "*" ]
types: [ "opened", "edited" ]
jobs:
check-and-test:
runs-on: ubuntu-latest
container: docker.io/commitlint/commitlint:21.2.1
steps:
- uses: actions/checkout@v7.0.0
- name: check PR title
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Verify PR title
run: |
echo "${{ gitea.event.pull_request.title }}" | commitlint --config .commitlintrc.json
+41
View File
@@ -0,0 +1,41 @@
name: Helm
on:
pull_request:
types: [ "opened", "reopened", "synchronize" ]
push:
branches:
- '**'
tags-ignore:
- '**'
workflow_dispatch: {}
jobs:
helm-lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with:
version: v4.3.0 # renovate: datasource=github-releases depName=helm/helm
- name: Update helm dependencies
run: helm dependency update
- name: Lint helm files
run: |
helm lint --values values.yaml .
helm-unittest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with:
version: v4.3.0 # renovate: datasource=github-releases depName=helm/helm
- env:
HELM_UNITTEST_VERSION: v1.0.0 #renovate: datasource=github-releases depName=helm-unittest/helm-unittest
name: Install helm-unittest
run: helm plugin install --verify=false --version "${HELM_UNITTEST_VERSION}" https://github.com/helm-unittest/helm-unittest
- name: Update helm dependencies
run: helm dependency update
- name: Execute helm unittests
run: helm unittest --strict --file 'unittests/**/*.yaml' .
+44
View File
@@ -0,0 +1,44 @@
name: Markdown linter
on:
pull_request:
paths: [ "**/*.md" ]
types: [ "opened", "reopened", "synchronize" ]
push:
branches:
- '**'
paths: [ "**/*.md" ]
tags-ignore:
- '**'
workflow_dispatch: {}
jobs:
markdown-link-checker:
container:
image: docker.io/library/node:26.8.2-alpine
runs-on: ubuntu-latest
steps:
- name: Install tooling
run: |
apk update
apk add git npm
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Verify links in markdown files
run: |
npm install
npm run readme:link
markdown-lint:
container:
image: docker.io/library/node:26.8.2-alpine
runs-on: ubuntu-latest
steps:
- name: Install tooling
run: |
apk update
apk add git
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
- name: Lint markdown files
run: |
npm install
npm run readme:lint
-50
View File
@@ -1,50 +0,0 @@
name: check-and-test
on:
pull_request:
branches:
- "*"
push:
branches:
- main
env:
# renovate: datasource=github-releases depName=helm-unittest/helm-unittest
HELM_UNITTEST_VERSION: "v1.1.1"
jobs:
check-and-test:
runs-on: ubuntu-latest
container: docker.io/alpine/helm:4.2.3
steps:
- name: install tools
run: |
apk update
apk add --update bash make nodejs npm yamllint ncurses
- uses: actions/checkout@v7.0.0
- name: define helm repositories
run: |
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo add valkey https://valkey.io/valkey-helm
helm repo update
- name: install chart dependencies
run: helm dependency build
- name: lint
run: helm lint .
- name: template
run: helm template --debug gitea-helm .
- name: prepare unit test environment
run: |
helm plugin install --verify=false --version ${{ env.HELM_UNITTEST_VERSION }} https://github.com/helm-unittest/helm-unittest
git submodule update --init --recursive
- name: unit tests
env:
TERM: xterm
run: |
make unittests
- name: verify readme
run: |
make readme
git diff --exit-code --name-only README.md
- name: yaml lint
uses: https://github.com/ibiqlik/action-yamllint@v3
+8 -7
View File
@@ -7,14 +7,14 @@ Kubernetes Helm chart for deploying [Gitea](https://gitea.com). Uses Go/Helm tem
## Build & Test
```bash
make readme # Regenerate README.md parameter table + lint
make unittests-helm # Run Helm unit tests (helm-unittest plugin required)
make unittests-bash # Run bash/bats script tests (requires git submodule init)
make unittests # Both of the above
make missing-dot # Check if the @param annotations are missing a trailing dot.
make readme # Regenerate README.md parameter table + lint + link checker
make helm/unittest # Run Helm unit tests (helm-unittest plugin required)
make bash/unittest # Run bash/bats script tests (requires git submodule init)
```
Always run `make readme` after changing `values.yaml` `@param` annotations.
Always run `make unittests-helm` after changing templates or unit tests.
Always run `make helm/unittest` after changing templates or unit tests.
## Conventions
@@ -34,7 +34,7 @@ image:
### Templates
- Helm templates live in `templates/gitea/`. Helpers live in `templates/_helpers.tpl`.
- Helm templates live in `templates/`. Helpers live in `templates/_helpers.tpl`.
- Use camelCase for all files and variables (e.g `httpRoute`, `backendTLSPolicy`, `gatewayAPI`, `statefulSet`).
- Use `include "gitea.fullname"` for naming resources.
- Use `fail` for required-value validation with clear error messages referencing the full values path.
@@ -42,13 +42,14 @@ image:
- Render all attributes, even if they are empty, to prevent drift in Argo CD. For example, `labels` must be rendered, while `annotations` are defined as `yaml:"annotations,omitempty"`.
- Use plural for `*.tpl` files, because they may contain functions for multiple resources of the same kind (e.g. `_services.tpl` for `httpService.yaml` or `sshService.yaml`, `_backendTLSPolicies.tpl` for `backendTLSPolicy.yaml`).
- Use as prefix of YAML files the resource kind (e.g., `deployment.yaml` for `Deployment` resources). If there are multiple resources of the same kind, use a descriptive suffix (e.g., `deployment_metrics.yaml` for a `Deployment` related to metrics).
- Short names like `pvc` for Persistent Volume Claims or `svc` for Services are not allowed in file names or key names.
### Unit Tests
- Helm unit tests live in `unittests/helm/` mirroring the template structure.
- Test files are YAML using the [helm-unittest](https://github.com/helm-unittest/helm-unittest) format.
- Each test must set all required values explicitly — do not rely on cross-test state.
- The `values.yaml` file must pass `yamllint`. The configuration is in `.yamllint`. Use `make yamllint` to run the linter.
- The `values.yaml` file must pass `yamllint`. The configuration is in `.yamllint.yaml`. Use `make yamllint` to run the linter.
- The title of the unit test should clearly describe the scenario being tested. As title must be use a short sentence starting with a capital letter and ending without a period.
- Each unit test must explicitly set a custom namespace and release name, rather than relying on defaults.
+1 -1
View File
@@ -36,6 +36,6 @@ unittests/
.prettierignore
.yamllint
CODEOWNERS
renovate.json5
renovate.json
.commitlintrc.json
.gitsv/
+1 -2
View File
@@ -4,8 +4,7 @@
"/unittests/**/*.yaml"
],
"https://docs.renovatebot.com/renovate-schema.json":[
"renovate.json",
"renovate.json5"
"renovate.json"
]
},
"yaml.schemaStore.enable": true,
+10 -9
View File
@@ -1,20 +1,21 @@
---
extends: default
ignore: |
charts
.yamllint
node_modules
templates
unittests/bash
rules:
truthy:
allowed-values: ['true', 'false']
check-keys: False
level: error
line-length: disable
document-start: disable
comments:
min-spaces-from-content: 1
braces:
max-spaces-inside: 2
comments:
min-spaces-from-content: 1
comments-indentation: disable
document-start: disable
line-length: disable
truthy:
allowed-values: ['true', 'false']
check-keys: false
level: error
+5 -6
View File
@@ -37,15 +37,14 @@ For local development and testing of pull requests, the following workflow can
be used:
1. Install `minikube` and `helm`.
1. Start a `minikube` cluster via `minikube start`.
1. From the `gitea/helm-gitea` directory execute the following command.
2. Start a `minikube` cluster via `minikube start`.
3. From the `gitea/helm-gitea` directory execute the following command.
This will install the dependencies listed in `Chart.yml` and deploy the current state of the helm chart found locally.
If you want to test a branch, make sure to switch to the respective branch first.
`helm install --dependency-update gitea . -f values.yaml`.
1. Gitea is now deployed in `minikube`.
To access it, it's port needs to be forwarded first from `minikube` to localhost first via `kubectl --namespace
default port-forward svc/gitea-http 3000:3000`.
Now Gitea is accessible at [http://localhost:3000](http://localhost:3000).
4. Gitea is now deployed in `minikube`. To access it, it's port needs to be forwarded first from `minikube` to localhost
first via `kubectl --namespace default port-forward svc/gitea-http 3000:3000`. Now Gitea is accessible at
`localhost:3000`.
### Unit tests
+57 -19
View File
@@ -1,29 +1,67 @@
SHELL := /usr/bin/env bash -O globstar
.PHONY: prepare-environment
prepare-environment:
npm install
# CLEAN
# ==============================================================================
PHONY+=clean
clean:
-rm -rf charts *.tar.gz *.tar.gz.sig node_modules
.PHONY: readme
readme: prepare-environment
npm run readme:parameters
npm run readme:lint
# MISSING DOT
# ==============================================================================
PHONY+=missing-dot
missing-dot:
grep --perl-regexp '## @(param|skip).*[^.]$$' values.yaml
.PHONY: unittests
unittests: unittests-helm unittests-bash
# README
# ==============================================================================
PHONY+=readme
readme: readme/link readme/lint readme/parameters
.PHONY: unittests-helm
unittests-helm:
helm unittest --strict -f 'unittests/helm/**/*.yaml' -f 'unittests/helm/values-conflicting-checks.yaml' ./
PHONY+=readme/link
readme/link:
npm install && npm run readme:link
.PHONY: unittests-bash
unittests-bash:
./unittests/bash/bats/bin/bats --pretty ./unittests/bash/tests/**/*.bats
PHONY+=readme/lint
readme/lint:
npm install && npm run readme:lint
.PHONY: update-helm-dependencies
update-helm-dependencies:
PHONY+=readme/parameters
readme/parameters:
npm install && npm run readme:parameters
# HELM DEPENDENCIES
# ==============================================================================
PHONY+=helm/dependency-update
helm/dependency-update:
helm dependency update
.PHONY: yamllint
# HELM UNITTESTS
# ==============================================================================
PHONY+=helm/unittest
helm/unittest:
helm unittest --strict --file 'unittests/helm/**/*.yaml' --file 'unittests/helm/values-conflicting-checks.yaml' ./
# BASH PREPARE
# ==============================================================================
PHONY+=bash/prepare
bash/prepare:
git submodule init
git submodule update
# BASH UNITTESTS
# ==============================================================================
PHONY+=bash/unittest
bash/unittest:
./unittests/bash/bats/bin/bats --pretty ./unittests/bash/tests/**/*.bats
# YAML LINT
# ==============================================================================
PHONY+=yamllint
yamllint:
yamllint -c .yamllint .
yamllint -c .yamllint.yaml .
# PHONY
# ==============================================================================
# Declare the contents of the PHONY variable as phony. We keep that information
# in a variable so we can use it in if_changed.
.PHONY: ${PHONY}
+264 -263
View File
@@ -15,9 +15,10 @@
- [Server defaults](#server-defaults)
- [Metrics defaults](#metrics-defaults)
- [Rootless Defaults](#rootless-defaults)
- [OpenShift Compatibility](#openshift-compatibility)
- [Gateway API](#gateway-api)
- [Session, Cache and Queue](#session-cache-and-queue)
- [Single-Pod Configurations](#single-pod-configurations)
- [Additional _app.ini_ settings](#additional-appini-settings)
- [User defined environment variables in app.ini](#user-defined-environment-variables-in-appini)
- [External Database](#external-database)
- [Ports and external url](#ports-and-external-url)
@@ -33,13 +34,14 @@
- [Metrics and profiling](#metrics-and-profiling)
- [Secure Metrics Endpoint](#secure-metrics-endpoint)
- [Pod annotations](#pod-annotations)
- [Secret checksum annotations](#secret-checksum-annotations)
- [TLS certificate rotation](#tls-certificate-rotation)
- [Themes](#themes)
- [Renovate](#renovate)
- [Parameters](#parameters)
- [Global](#global)
- [deployment](#deployment)
- [Gateway API](#gateway-api)
- [Gateway API](#gateway-api-1)
- [Ingress](#ingress)
- [Network](#network)
- [Image](#image)
@@ -265,7 +267,7 @@ If `.Values.deployment.gitea.image.rootless: true`, then the following will occu
- `$HOME` becomes `/data/gitea/git`
[see deployment.yaml](./templates/gitea/deployment.yaml) template inside (init-)container "env" declarations
[see deployment.yaml](./templates/deployment.yaml) template inside (init-)container "env" declarations
- `START_SSH_SERVER: true` (Unless explicity overwritten by `gitea.config.server.START_SSH_SERVER`)
@@ -277,7 +279,7 @@ If `.Values.deployment.gitea.image.rootless: true`, then the following will occu
- `SSH_LOG_LEVEL` environment variable is not injected into the container
[see deployment.yaml](./templates/gitea/deployment.yaml) template inside container "env" declarations
[see deployment.yaml](./templates/deployment.yaml) template inside container "env" declarations
#### OpenShift Compatibility
@@ -483,7 +485,7 @@ Priority (highest to lowest) for defining app.ini variables:
### External Database
Any external database listed in [https://docs.gitea.com/installation/database-prep](https://docs.gitea.com/installation/database-prep) can be used instead of the built-in PostgreSQL.
Any external database listed in [https://docs.gitea.com/installation/database-prep/](https://docs.gitea.com/installation/database-prep/) can be used instead of the built-in PostgreSQL.
In fact, it is **highly recommended** to use an external database to ensure a stable Gitea installation longterm.
If an external database is used, no matter which type, make sure to set `postgresql.enabled` to `false` to disable the use of the built-in PostgreSQL.
@@ -1017,31 +1019,30 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
### Global
| Name | Description | Value |
| ------------------------- | ------------------------------------------------------------------------- | ----- |
| `global.imageRegistry` | global image registry override | `""` |
| `global.imagePullSecrets` | global image pull secrets override; can be extended by `imagePullSecrets` | `[]` |
| `global.storageClass` | global storage class override | `""` |
| `global.hostAliases` | global hostAliases which will be added to the pod's hosts files | `[]` |
| Name | Description | Value |
| ------------------------- | -------------------------------------------------------------------------- | ----- |
| `global.imageRegistry` | global image registry override. | `""` |
| `global.imagePullSecrets` | global image pull secrets override; can be extended by `imagePullSecrets`. | `[]` |
| `global.hostAliases` | global hostAliases which will be added to the pod's hosts files. | `[]` |
### deployment
| Name | Description | Value |
| -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |
| `deployment.enabled` | Enable the deployment of Gitea. | `true` |
| `deployment.annotations` | Annotations for the Gitea deployment to be created | `{}` |
| `deployment.labels` | Labels for the deployment | `{}` |
| `deployment.annotations` | Annotations for the Gitea deployment to be created. | `{}` |
| `deployment.labels` | Labels for the deployment. | `{}` |
| `deployment.affinity` | Affinity for the deployment. | `{}` |
| `deployment.dnsConfig` | dnsConfig of the Gitea deployment. | `{}` |
| `deployment.gitea.env` | Additional environment variables to pass to the Gitea container. | `[]` |
| `deployment.gitea.envFrom` | List of environment variables mounted from configMaps or secrets for the Gitea container. | `[]` |
| `deployment.gitea.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
| `deployment.gitea.image.repository` | Image to start for this pod | `gitea` |
| `deployment.gitea.env` | Additional environment variables to pass to the gitea container. | `[]` |
| `deployment.gitea.envFrom` | List of environment variables mounted from configMaps or secrets for the gitea container. | `[]` |
| `deployment.gitea.image.registry` | image registry, e.g. gcr.io,docker.io. | `docker.gitea.com` |
| `deployment.gitea.image.repository` | Image to start for this pod. | `gitea` |
| `deployment.gitea.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
| `deployment.gitea.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `deployment.gitea.image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `deployment.gitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
| `deployment.gitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.gitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
| `deployment.gitea.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`. | `""` |
| `deployment.gitea.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.gitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher. | `true` |
| `deployment.gitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.gitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults)**. | `""` |
| `deployment.gitea.resources` | Compute Resources required by Gitea container. Cannot be updated. | `nil` |
| `deployment.gitea.securityContext` | Security context of the Gitea container. Used as fallback for the chart-managed init containers. | `{}` |
| `deployment.gitea.volumeMounts` | Additional volume mounts. | `[]` |
@@ -1049,109 +1050,109 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
| `deployment.initContainers` | List of initContainers. The order is important. First init container in the list will be executed first. The link refers to the corresponding init container configuration. | `[]` |
| `deployment.initDirectories.env` | Additional environment variables to pass to the init container. | `[]` |
| `deployment.initDirectories.envFrom` | List of environment variables mounted from configMaps or secrets for the initDirectories container. | `[]` |
| `deployment.initDirectories.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
| `deployment.initDirectories.image.repository` | Image to start for this pod | `gitea` |
| `deployment.initDirectories.image.registry` | image registry, e.g. gcr.io,docker.io. | `docker.gitea.com` |
| `deployment.initDirectories.image.repository` | Image to start for this pod. | `gitea` |
| `deployment.initDirectories.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
| `deployment.initDirectories.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `deployment.initDirectories.image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `deployment.initDirectories.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
| `deployment.initDirectories.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initDirectories.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
| `deployment.initDirectories.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`. | `""` |
| `deployment.initDirectories.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.initDirectories.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher. | `true` |
| `deployment.initDirectories.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initDirectories.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults)**. | `""` |
| `deployment.initDirectories.resources` | Compute Resources required by the initDirectories container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
| `deployment.initDirectories.securityContext` | Security context of the initDirectories container. Defaults to `deployment.gitea.securityContext`. | `{}` |
| `deployment.initDirectories.volumeMounts` | Additional volume mounts. | `[]` |
| `deployment.initAppIni.env` | Additional environment variables to pass to the init container. | `[]` |
| `deployment.initAppIni.envFrom` | List of environment variables mounted from configMaps or secrets for the initAppIni container. | `[]` |
| `deployment.initAppIni.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
| `deployment.initAppIni.image.repository` | Image to start for this pod | `gitea` |
| `deployment.initAppIni.image.registry` | image registry, e.g. gcr.io,docker.io. | `docker.gitea.com` |
| `deployment.initAppIni.image.repository` | Image to start for this pod. | `gitea` |
| `deployment.initAppIni.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
| `deployment.initAppIni.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `deployment.initAppIni.image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `deployment.initAppIni.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
| `deployment.initAppIni.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initAppIni.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
| `deployment.initAppIni.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`. | `""` |
| `deployment.initAppIni.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.initAppIni.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher. | `true` |
| `deployment.initAppIni.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initAppIni.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults)**. | `""` |
| `deployment.initAppIni.resources` | Compute Resources required by the initAppIni container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
| `deployment.initAppIni.securityContext` | Security context of the initAppIni container. Defaults to `deployment.gitea.securityContext`. | `{}` |
| `deployment.initAppIni.volumeMounts` | Additional volume mounts. | `[]` |
| `deployment.initConfigureGPG.env` | Additional environment variables to pass to the init container. | `[]` |
| `deployment.initConfigureGPG.envFrom` | List of environment variables mounted from configMaps or secrets for the initConfigureGPG container. | `[]` |
| `deployment.initConfigureGPG.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
| `deployment.initConfigureGPG.image.repository` | Image to start for this pod | `gitea` |
| `deployment.initConfigureGPG.image.registry` | image registry, e.g. gcr.io,docker.io. | `docker.gitea.com` |
| `deployment.initConfigureGPG.image.repository` | Image to start for this pod. | `gitea` |
| `deployment.initConfigureGPG.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
| `deployment.initConfigureGPG.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `deployment.initConfigureGPG.image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `deployment.initConfigureGPG.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
| `deployment.initConfigureGPG.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initConfigureGPG.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
| `deployment.initConfigureGPG.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`. | `""` |
| `deployment.initConfigureGPG.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.initConfigureGPG.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher. | `true` |
| `deployment.initConfigureGPG.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initConfigureGPG.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults)**. | `""` |
| `deployment.initConfigureGPG.resources` | Compute Resources required by the initConfigureGPG container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
| `deployment.initConfigureGPG.securityContext` | Security context of the initConfigureGPG container. Defaults to `deployment.gitea.securityContext`. | `{}` |
| `deployment.initConfigureGPG.volumeMounts` | Additional volume mounts. | `[]` |
| `deployment.initConfigureGitea.env` | Additional environment variables to pass to the init container. | `[]` |
| `deployment.initConfigureGitea.envFrom` | List of environment variables mounted from configMaps or secrets for the initConfigureGitea container. | `[]` |
| `deployment.initConfigureGitea.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
| `deployment.initConfigureGitea.image.repository` | Image to start for this pod | `gitea` |
| `deployment.initConfigureGitea.image.registry` | image registry, e.g. gcr.io,docker.io. | `docker.gitea.com` |
| `deployment.initConfigureGitea.image.repository` | Image to start for this pod. | `gitea` |
| `deployment.initConfigureGitea.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
| `deployment.initConfigureGitea.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `deployment.initConfigureGitea.image.pullPolicy` | Image pull policy | `IfNotPresent` |
| `deployment.initConfigureGitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
| `deployment.initConfigureGitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initConfigureGitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
| `deployment.initConfigureGitea.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`. | `""` |
| `deployment.initConfigureGitea.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.initConfigureGitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher. | `true` |
| `deployment.initConfigureGitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initConfigureGitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults)**. | `""` |
| `deployment.initConfigureGitea.resources` | Compute Resources required by the initConfigureGitea container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
| `deployment.initConfigureGitea.securityContext` | Security context of the initConfigureGitea container. Defaults to `deployment.gitea.securityContext`. | `{}` |
| `deployment.initConfigureGitea.volumeMounts` | Additional volume mounts. | `[]` |
| `deployment.nodeSelector` | NodeSelector for the deployment | `{}` |
| `deployment.priorityClassName` | priorityClassName for the deployment | `""` |
| `deployment.nodeSelector` | NodeSelector for the deployment. | `{}` |
| `deployment.priorityClassName` | priorityClassName for the deployment. | `""` |
| `deployment.replicas` | Number of replicas for the Gitea deployment. | `1` |
| `deployment.resources` | Resources is the total amount of CPU and Memory resources required by all containers in the pod. | `{}` |
| `deployment.schedulerName` | Use an alternate scheduler, e.g. "stork" | `""` |
| `deployment.schedulerName` | Use an alternate scheduler, e.g. "stork". | `""` |
| `deployment.securityContext` | Pod security context. On non-OpenShift clusters the chart defaults `fsGroup` to `1000` when this map is empty. | `{}` |
| `deployment.strategy.type` | Deployment strategy used to replace old pods, either `RollingUpdate` or `Recreate`. | `RollingUpdate` |
| `deployment.strategy.rollingUpdate.maxSurge` | Number or percentage of pods that may be created above the desired replica count. Only used with `RollingUpdate`. | `100%` |
| `deployment.strategy.rollingUpdate.maxUnavailable` | Number or percentage of pods that may be unavailable during the update. Only used with `RollingUpdate`. | `0` |
| `deployment.terminationGracePeriodSeconds` | How long to wait until forcefully kill the pod | `60` |
| `deployment.terminationGracePeriodSeconds` | How long to wait until forcefully kill the pod. | `60` |
| `deployment.tolerations` | Tolerations of the Gitea deployment. | `[]` |
| `deployment.topologySpreadConstraints` | TopologySpreadConstraints for the deployment | `[]` |
| `deployment.topologySpreadConstraints` | TopologySpreadConstraints for the deployment. | `[]` |
| `deployment.volumes` | Additional volumes to mount into the pods of the Gitea deployment. | `[]` |
### Gateway API
| Name | Description | Value |
| --------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `gatewayAPI.enabled` | Enable deployment of Gateway API resources | `false` |
| `gatewayAPI.core.backendTLSPolicy.enabled` | Render a BackendTLSPolicy resource for encrypted backend traffic | `false` |
| `gatewayAPI.core.backendTLSPolicy.annotations` | Annotations applied to the BackendTLSPolicy | `{}` |
| `gatewayAPI.core.backendTLSPolicy.labels` | Additional labels applied to the BackendTLSPolicy | `{}` |
| `gatewayAPI.enabled` | Enable deployment of Gateway API resources. | `false` |
| `gatewayAPI.core.backendTLSPolicy.enabled` | Render a BackendTLSPolicy resource for encrypted backend traffic. | `false` |
| `gatewayAPI.core.backendTLSPolicy.annotations` | Annotations applied to the BackendTLSPolicy. | `{}` |
| `gatewayAPI.core.backendTLSPolicy.labels` | Additional labels applied to the BackendTLSPolicy. | `{}` |
| `gatewayAPI.core.backendTLSPolicy.targetRefs` | Target references for the BackendTLSPolicy. Defaults to the HTTP service. | `[]` |
| `gatewayAPI.core.backendTLSPolicy.validation` | Validation configuration (required when enabled). See `docs/gateway-api.md`. | `{}` |
| `gatewayAPI.core.backendTLSPolicy.validation.caCertificateRefs` | CA certificate references for the BackendTLSPolicy validation. See `docs/gateway-api.md`. | |
| `gatewayAPI.core.backendTLSPolicy.validation.hostname` | Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the Gitea server certificate. See `docs/gateway-api.md`. | |
| `gatewayAPI.core.httpRoute.enabled` | Render an HTTPRoute resource | `false` |
| `gatewayAPI.core.httpRoute.annotations` | Annotations applied to the HTTPRoute | `{}` |
| `gatewayAPI.core.httpRoute.labels` | Additional labels applied to the HTTPRoute | `{}` |
| `gatewayAPI.core.backendTLSPolicy.validation.hostname` | Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the gitea server certificate. See `docs/gateway-api.md`. | |
| `gatewayAPI.core.httpRoute.enabled` | Render an HTTPRoute resource. | `false` |
| `gatewayAPI.core.httpRoute.annotations` | Annotations applied to the HTTPRoute. | `{}` |
| `gatewayAPI.core.httpRoute.labels` | Additional labels applied to the HTTPRoute. | `{}` |
| `gatewayAPI.core.httpRoute.tls` | When true, treat the upstream Gateway as terminating TLS so `ROOT_URL` uses `https`. | `false` |
| `gatewayAPI.core.httpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
| `gatewayAPI.core.httpRoute.hostnames` | List of hostnames for the HTTPRoute. | `[]` |
| `gatewayAPI.core.httpRoute.rules` | Custom routing rules. Defaults to a PathPrefix `/` rule targeting the HTTP service. | `[]` |
| `gatewayAPI.core.tcpRoute.enabled` | Render a TCPRoute resource (typically for SSH) | `false` |
| `gatewayAPI.core.tcpRoute.annotations` | Annotations applied to the TCPRoute | `{}` |
| `gatewayAPI.core.tcpRoute.labels` | Additional labels applied to the TCPRoute | `{}` |
| `gatewayAPI.core.tcpRoute.enabled` | Render a TCPRoute resource (typically for SSH). | `false` |
| `gatewayAPI.core.tcpRoute.annotations` | Annotations applied to the TCPRoute. | `{}` |
| `gatewayAPI.core.tcpRoute.labels` | Additional labels applied to the TCPRoute. | `{}` |
| `gatewayAPI.core.tcpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
| `gatewayAPI.core.tcpRoute.rules` | Custom routing rules. Defaults to a rule targeting the SSH service. | `[]` |
| `gatewayAPI.nginx.clientSettingsPolicies.enabled` | Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit | `false` |
| `gatewayAPI.nginx.clientSettingsPolicies.annotations` | Annotations applied to the ClientSettingsPolicy | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.labels` | Additional labels applied to the ClientSettingsPolicy | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.enabled` | Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit. | `false` |
| `gatewayAPI.nginx.clientSettingsPolicies.annotations` | Annotations applied to the ClientSettingsPolicy. | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.labels` | Additional labels applied to the ClientSettingsPolicy. | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.targetRef` | Target reference for the ClientSettingsPolicy. Defaults to the chart's HTTPRoute. | `{}` |
| `gatewayAPI.nginx.clientSettingsPolicies.body` | Client body settings (required when enabled), e.g. `maxSize`. See `docs/gateway-api.md`. | `{}` |
### Ingress
| Name | Description | Value |
| -------------------------------- | ---------------------------------------------------------------------------------------------- | ----------------- |
| `ingress.enabled` | Enable ingress | `false` |
| `ingress.annotations` | Additional annotations. | `{}` |
| `ingress.labels` | Additional labels. | `{}` |
| `ingress.className` | DEPRECATED: Ingress class name. | `nginx` |
| `ingress.pathType` | Ingress Path Type | `Prefix` |
| `ingress.hosts[0].host` | Default Ingress host | `git.example.com` |
| `ingress.hosts[0].paths[0].path` | Default Ingress path | `/` |
| `ingress.tls` | Ingress tls settings | `[]` |
| `namespace` | An explicit namespace to deploy Gitea into. Defaults to the release namespace if not specified | `""` |
| Name | Description | Value |
| -------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------- |
| `ingress.enabled` | Enable ingress. | `false` |
| `ingress.annotations` | Additional annotations. | `{}` |
| `ingress.labels` | Additional labels. | `{}` |
| `ingress.className` | DEPRECATED: Ingress class name. | `nginx` |
| `ingress.pathType` | Ingress Path Type. | `Prefix` |
| `ingress.hosts[0].host` | Default Ingress host. | `git.example.com` |
| `ingress.hosts[0].paths[0].path` | Default Ingress path. | `/` |
| `ingress.tls` | Ingress tls settings. | `[]` |
| `namespace` | An explicit namespace to deploy gitea into. Defaults to the release namespace if not specified. | `""` |
### Network
@@ -1161,162 +1162,162 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
### Image
| Name | Description | Value |
| ------------------ | ----------------------------------- | ----- |
| `imagePullSecrets` | Secret to use for pulling the image | `[]` |
| Name | Description | Value |
| ------------------ | ------------------------------------ | ----- |
| `imagePullSecrets` | Secret to use for pulling the image. | `[]` |
### Security
| Name | Description | Value |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ----- |
| `openshift.enabled` | Enable OpenShift compatibility defaults for chart-managed pods. Defaults to auto-detect based on the SecurityContextConstraints API. | `nil` |
| `podDisruptionBudget` | Pod disruption budget | `{}` |
| `podDisruptionBudget` | Pod disruption budget. | `{}` |
### Route
| Name | Description | Value |
| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ------- |
| `route.enabled` | Enable OpenShift Route | `false` |
| `route.annotations` | Route annotations | `{}` |
| `route.enabled` | Enable OpenShift Route. | `false` |
| `route.annotations` | Route annotations. | `{}` |
| `route.host` | Route host. When unset, OpenShift may generate one and Gitea URL defaults fall back to ingress/service values. | `""` |
| `route.path` | Route path | `""` |
| `route.wildcardPolicy` | Route wildcard policy | `None` |
| `route.tls.termination` | Route TLS termination type | `nil` |
| `route.tls.insecureEdgeTerminationPolicy` | Route insecure edge termination policy | `nil` |
| `route.tls.key` | Route TLS key | `nil` |
| `route.tls.certificate` | Route TLS certificate | `nil` |
| `route.tls.caCertificate` | Route TLS CA certificate | `nil` |
| `route.tls.destinationCACertificate` | Route destination CA certificate | `nil` |
| `route.path` | Route path. | `""` |
| `route.wildcardPolicy` | Route wildcard policy. | `None` |
| `route.tls.termination` | Route TLS termination type. | `nil` |
| `route.tls.insecureEdgeTerminationPolicy` | Route insecure edge termination policy. | `nil` |
| `route.tls.key` | Route TLS key. | `nil` |
| `route.tls.certificate` | Route TLS certificate. | `nil` |
| `route.tls.caCertificate` | Route TLS CA certificate. | `nil` |
| `route.tls.destinationCACertificate` | Route destination CA certificate. | `nil` |
### Secrets
| Name | Description | Value |
| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| `secrets.admin.enabled` | Create and keep the Gitea admin user in sync | `true` |
| `secrets.admin.enabled` | Create and keep the Gitea admin user in sync. | `true` |
| `secrets.admin.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the admin Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
| `secrets.admin.passwordMode` | Mode for how to set/update the admin user password. Options are: initialOnlyNoReset, initialOnlyRequireReset, and keepUpdated | `keepUpdated` |
| `secrets.admin.existingSecret.enabled` | Use an already existing Secret instead of creating the admin Secret | `false` |
| `secrets.admin.existingSecret.secretName` | Name of the already existing admin Secret | `""` |
| `secrets.admin.existingSecret.emailKey` | Key of the email address in the existing admin Secret | `email` |
| `secrets.admin.existingSecret.passwordKey` | Key of the password in the existing admin Secret | `password` |
| `secrets.admin.existingSecret.usernameKey` | Key of the username in the existing admin Secret | `username` |
| `secrets.admin.new.annotations` | Annotations for the admin Secret | `{}` |
| `secrets.admin.new.labels` | Labels for the admin Secret | `{}` |
| `secrets.admin.new.email` | Email of the Gitea admin user | `gitea@local.domain` |
| `secrets.admin.passwordMode` | Mode for how to set/update the admin user password. Options are: initialOnlyNoReset, initialOnlyRequireReset, and keepUpdated. | `keepUpdated` |
| `secrets.admin.existingSecret.enabled` | Use an already existing Secret instead of creating the admin Secret. | `false` |
| `secrets.admin.existingSecret.secretName` | Name of the already existing admin Secret. | `""` |
| `secrets.admin.existingSecret.emailKey` | Key of the email address in the existing admin Secret. | `email` |
| `secrets.admin.existingSecret.passwordKey` | Key of the password in the existing admin Secret. | `password` |
| `secrets.admin.existingSecret.usernameKey` | Key of the username in the existing admin Secret. | `username` |
| `secrets.admin.new.annotations` | Annotations for the admin Secret. | `{}` |
| `secrets.admin.new.labels` | Labels for the admin Secret. | `{}` |
| `secrets.admin.new.email` | Email of the Gitea admin user. | `gitea@local.domain` |
| `secrets.admin.new.password` | Password of the Gitea admin user. | `r8sA8CPHD9!bt6d` |
| `secrets.admin.new.username` | Username of the Gitea admin user | `gitea_admin` |
| `secrets.admin.new.username` | Username of the Gitea admin user. | `gitea_admin` |
| `secrets.config.enabled` | Enable mounting of the config Secret. | `true` |
| `secrets.config.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the config Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
| `secrets.config.existingSecret.enabled` | Use an already existing Secret instead of creating the config Secret | `false` |
| `secrets.config.existingSecret.secretName` | Name of the already existing config Secret | `""` |
| `secrets.config.new.annotations` | Annotations for the config Secret | `{}` |
| `secrets.config.new.labels` | Labels for the config Secret | `{}` |
| `secrets.gpg.enabled` | Enable mounting of a GPG key to sign Git commits. | `false` |
| `secrets.config.existingSecret.enabled` | Use an already existing Secret instead of creating the config Secret. | `false` |
| `secrets.config.existingSecret.secretName` | Name of the already existing config Secret. | `""` |
| `secrets.config.new.annotations` | Annotations for the config Secret. | `{}` |
| `secrets.config.new.labels` | Labels for the config Secret. | `{}` |
| `secrets.gpg.enabled` | Enable mounting of a GPG key to sign git commits. | `false` |
| `secrets.gpg.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the GPG key Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
| `secrets.gpg.existingSecret.enabled` | Use an already existing Secret instead of creating the GPG key Secret | `false` |
| `secrets.gpg.existingSecret.secretName` | Name of the already existing GPG key Secret | `""` |
| `secrets.gpg.existingSecret.gpgHomeKey` | Key of the GPG home directory in the existing GPG key Secret | `gpgHome` |
| `secrets.gpg.existingSecret.enabled` | Use an already existing Secret instead of creating the GPG key Secret. | `false` |
| `secrets.gpg.existingSecret.secretName` | Name of the already existing GPG key Secret. | `""` |
| `secrets.gpg.existingSecret.gpgHomeKey` | Key of the GPG home directory in the existing GPG key Secret. | `gpgHome` |
| `secrets.gpg.existingSecret.privateKeyKey` | Key of the private key in the existing GPG key Secret. | `privateKey` |
| `secrets.gpg.new.annotations` | Annotations for the GPG key Secret | `{}` |
| `secrets.gpg.new.labels` | Labels for the GPG key Secret | `{}` |
| `secrets.gpg.new.annotations` | Annotations for the GPG key Secret. | `{}` |
| `secrets.gpg.new.labels` | Labels for the GPG key Secret. | `{}` |
| `secrets.gpg.new.gpgHome` | Path to the GPG home directory. | `/data/git/.gnupg` |
| `secrets.gpg.new.privateKey` | Content of the private GPG key in armored format. | `""` |
| `secrets.init.enabled` | Enable mounting of the init Secret. | `true` |
| `secrets.init.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the init Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
| `secrets.init.existingSecret.enabled` | Use an already existing Secret instead of creating the init Secret | `false` |
| `secrets.init.existingSecret.secretName` | Name of the already existing init Secret | `""` |
| `secrets.init.new.annotations` | Annotations for the init Secret | `{}` |
| `secrets.init.new.labels` | Labels for the init Secret | `{}` |
| `secrets.init.existingSecret.enabled` | Use an already existing Secret instead of creating the init Secret. | `false` |
| `secrets.init.existingSecret.secretName` | Name of the already existing init Secret. | `""` |
| `secrets.init.new.annotations` | Annotations for the init Secret. | `{}` |
| `secrets.init.new.labels` | Labels for the init Secret. | `{}` |
| `secrets.inlineConfig.enabled` | Enable mounting of the inline configuration Secret. | `true` |
| `secrets.inlineConfig.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the inline configuration Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
| `secrets.inlineConfig.existingSecret.enabled` | Use an already existing Secret instead of creating the inline configuration Secret | `false` |
| `secrets.inlineConfig.existingSecret.secretName` | Name of the already existing inline configuration Secret | `""` |
| `secrets.inlineConfig.new.annotations` | Annotations for the inline configuration Secret | `{}` |
| `secrets.inlineConfig.new.labels` | Labels for the inline configuration Secret | `{}` |
| `secrets.inlineConfig.existingSecret.enabled` | Use an already existing Secret instead of creating the inline configuration Secret. | `false` |
| `secrets.inlineConfig.existingSecret.secretName` | Name of the already existing inline configuration Secret. | `""` |
| `secrets.inlineConfig.new.annotations` | Annotations for the inline configuration Secret. | `{}` |
| `secrets.inlineConfig.new.labels` | Labels for the inline configuration Secret. | `{}` |
| `secrets.metrics.enabled` | Enable mounting of the metrics Secret. | `true` |
| `secrets.metrics.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the metrics Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
| `secrets.metrics.existingSecret.enabled` | Use an already existing Secret instead of creating the metrics Secret | `false` |
| `secrets.metrics.existingSecret.secretName` | Name of the already existing metrics Secret | `""` |
| `secrets.metrics.new.annotations` | Annotations for the metrics Secret | `{}` |
| `secrets.metrics.new.labels` | Labels for the metrics Secret | `{}` |
| `secrets.metrics.existingSecret.enabled` | Use an already existing Secret instead of creating the metrics Secret. | `false` |
| `secrets.metrics.existingSecret.secretName` | Name of the already existing metrics Secret. | `""` |
| `secrets.metrics.new.annotations` | Annotations for the metrics Secret. | `{}` |
| `secrets.metrics.new.labels` | Labels for the metrics Secret. | `{}` |
### Service
| Name | Description | Value |
| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- |
| `service.http.type` | Kubernetes service type for web traffic | `ClusterIP` |
| `service.http.port` | Port number for web traffic | `3000` |
| `service.http.clusterIP` | ClusterIP setting for http autosetup for deployment is None | `None` |
| `service.http.loadBalancerIP` | LoadBalancer IP setting | `nil` |
| `service.http.nodePort` | NodePort for http service | `nil` |
| `service.http.externalTrafficPolicy` | If `service.http.type` is `NodePort` or `LoadBalancer`, set this to `Local` to enable source IP preservation | `nil` |
| `service.http.externalIPs` | External IPs for service | `nil` |
| `service.http.ipFamilyPolicy` | HTTP service dual-stack policy | `nil` |
| `service.http.type` | Kubernetes service type for web traffic. | `ClusterIP` |
| `service.http.port` | Port number for web traffic. | `3000` |
| `service.http.clusterIP` | ClusterIP setting for http autosetup for deployment is None. | `None` |
| `service.http.loadBalancerIP` | LoadBalancer IP setting. | `nil` |
| `service.http.nodePort` | NodePort for http service. | `nil` |
| `service.http.externalTrafficPolicy` | If `service.http.type` is `NodePort` or `LoadBalancer`, set this to `Local` to enable source IP preservation. | `nil` |
| `service.http.externalIPs` | External IPs for service. | `nil` |
| `service.http.ipFamilyPolicy` | HTTP service dual-stack policy. | `nil` |
| `service.http.ipFamilies` | HTTP service dual-stack familiy selection,for dual-stack parameters see official kubernetes [dual-stack concept documentation](https://kubernetes.io/docs/concepts/services-networking/dual-stack/). | `nil` |
| `service.http.loadBalancerSourceRanges` | Source range filter for http loadbalancer | `[]` |
| `service.http.annotations` | HTTP service annotations | `{}` |
| `service.http.labels` | HTTP service additional labels | `{}` |
| `service.http.loadBalancerClass` | Loadbalancer class | `nil` |
| `service.ssh.type` | Kubernetes service type for ssh traffic | `ClusterIP` |
| `service.ssh.port` | Port number for ssh traffic | `22` |
| `service.ssh.clusterIP` | ClusterIP setting for ssh autosetup for deployment is None | `None` |
| `service.ssh.loadBalancerIP` | LoadBalancer IP setting | `nil` |
| `service.ssh.nodePort` | NodePort for ssh service | `nil` |
| `service.ssh.externalTrafficPolicy` | If `service.ssh.type` is `NodePort` or `LoadBalancer`, set this to `Local` to enable source IP preservation | `nil` |
| `service.ssh.externalIPs` | External IPs for service | `nil` |
| `service.ssh.ipFamilyPolicy` | SSH service dual-stack policy | `nil` |
| `service.http.loadBalancerSourceRanges` | Source range filter for http loadbalancer. | `[]` |
| `service.http.annotations` | HTTP service annotations. | `{}` |
| `service.http.labels` | HTTP service additional labels. | `{}` |
| `service.http.loadBalancerClass` | Loadbalancer class. | `nil` |
| `service.ssh.type` | Kubernetes service type for ssh traffic. | `ClusterIP` |
| `service.ssh.port` | Port number for ssh traffic. | `22` |
| `service.ssh.clusterIP` | ClusterIP setting for ssh autosetup for deployment is None. | `None` |
| `service.ssh.loadBalancerIP` | LoadBalancer IP setting. | `nil` |
| `service.ssh.nodePort` | NodePort for ssh service. | `nil` |
| `service.ssh.externalTrafficPolicy` | If `service.ssh.type` is `NodePort` or `LoadBalancer`, set this to `Local` to enable source IP preservation. | `nil` |
| `service.ssh.externalIPs` | External IPs for service. | `nil` |
| `service.ssh.ipFamilyPolicy` | SSH service dual-stack policy. | `nil` |
| `service.ssh.ipFamilies` | SSH service dual-stack familiy selection,for dual-stack parameters see official kubernetes [dual-stack concept documentation](https://kubernetes.io/docs/concepts/services-networking/dual-stack/). | `nil` |
| `service.ssh.hostPort` | HostPort for ssh service | `nil` |
| `service.ssh.loadBalancerSourceRanges` | Source range filter for ssh loadbalancer | `[]` |
| `service.ssh.annotations` | SSH service annotations | `{}` |
| `service.ssh.labels` | SSH service additional labels | `{}` |
| `service.ssh.loadBalancerClass` | Loadbalancer class | `nil` |
| `service.ssh.hostPort` | HostPort for ssh service. | `nil` |
| `service.ssh.loadBalancerSourceRanges` | Source range filter for ssh loadbalancer. | `[]` |
| `service.ssh.annotations` | SSH service annotations. | `{}` |
| `service.ssh.labels` | SSH service additional labels. | `{}` |
| `service.ssh.loadBalancerClass` | Loadbalancer class. | `nil` |
### ServiceAccount
| Name | Description | Value |
| --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `serviceAccount.create` | Enable the creation of a ServiceAccount | `false` |
| `serviceAccount.name` | Name of the created ServiceAccount, defaults to release name. Can also link to an externally provided ServiceAccount that should be used. | `""` |
| `serviceAccount.automountServiceAccountToken` | Enable/disable auto mounting of the service account token | `false` |
| `serviceAccount.imagePullSecrets` | Image pull secrets, available to the ServiceAccount | `[]` |
| `serviceAccount.annotations` | Custom annotations for the ServiceAccount | `{}` |
| `serviceAccount.labels` | Custom labels for the ServiceAccount | `{}` |
| Name | Description | Value |
| ------------------------------------------------------------------ | ---------------------------------------------------------- | ------- |
| `serviceAccount.enabled` | Assign the pod to use the ServiceAccount. | `true` |
| `serviceAccount.existingServiceAccount.enabled` | Enable using an existing ServiceAccount. | `false` |
| `serviceAccount.existingServiceAccount.existingServiceAccountName` | Name of the existing ServiceAccount to use. | `""` |
| `serviceAccount.new.annotations` | Custom annotations for the ServiceAccount. | `{}` |
| `serviceAccount.new.labels` | Custom labels for the ServiceAccount. | `{}` |
| `serviceAccount.new.automountServiceAccountToken` | Enable/disable auto mounting of the service account token. | `false` |
| `serviceAccount.new.imagePullSecrets` | Image pull secrets, available to the ServiceAccount. | `[]` |
### Persistence
| Name | Description | Value |
| ------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ---------------------- |
| `persistence.enabled` | Enable persistent storage | `true` |
| `persistence.create` | Whether to create the persistentVolumeClaim for shared storage | `true` |
| `persistence.mount` | Whether the persistentVolumeClaim should be mounted (even if not created) | `true` |
| `persistence.claimName` | Use an existing claim to store repository information | `gitea-shared-storage` |
| `persistence.size` | Size for persistence to store repo information | `10Gi` |
| `persistence.accessModes` | AccessMode for persistence | `["ReadWriteOnce"]` |
| `persistence.labels` | Labels for the persistence volume claim to be created | `{}` |
| `persistence.annotations.helm.sh/resource-policy` | Resource policy for the persistence volume claim | `keep` |
| `persistence.storageClass` | Name of the storage class to use | `nil` |
| `persistence.subPath` | Subdirectory of the volume to mount at | `nil` |
| `persistence.volumeName` | Name of persistent volume in PVC | `""` |
| `extraContainers` | Additional sidecar containers to run in the pod | `[]` |
| `extraInitVolumeMounts` | Mounts that are only mapped into the init-containers. Can be used for additional preconfiguration. | `[]` |
| `extraVolumeMounts` | **DEPRECATED** Additional volume mounts for init containers and the Gitea main container | `[]` |
| Name | Description | Value |
| --------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ------------------- |
| `persistence.enabled` | Enable persistent storage. | `false` |
| `persistence.existingPersistentVolumeClaim.enabled` | Enable using an existing persistent volume claim. | `false` |
| `persistence.existingPersistentVolumeClaim.persistentVolumeClaimName` | Name of the existing persistent volume claim to use. | `""` |
| `persistence.new.annotations.helm.sh/resource-policy` | Resource policy for the new persistent volume claim. | `keep` |
| `persistence.new.labels` | Labels for the new persistent volume claim. | `{}` |
| `persistence.new.accessModes` | AccessMode for the new persistent volume claim. | `["ReadWriteOnce"]` |
| `persistence.new.persistentVolumeName` | Name of the persistent volume for the new persistent volume claim. | `""` |
| `persistence.new.size` | Size for the new persistent volume claim. | `10Gi` |
| `persistence.new.storageClassName` | Name of the storage class to use for the new persistent volume claim. | `""` |
| `persistence.new.subPath` | Subdirectory of the volume to mount at for the new persistent volume claim. | `""` |
| `extraContainers` | Additional sidecar containers to run in the pod. | `[]` |
| `extraInitVolumeMounts` | Mounts that are only mapped into the init-containers. Can be used for additional preconfiguration. | `[]` |
| `extraVolumeMounts` | **DEPRECATED** Additional volume mounts for init containers and the Gitea main container. | `[]` |
### Init
| Name | Description | Value |
| ------------------------------------------ | ------------------------------------------------------------------------------------ | ------------ |
| `initPreScript` | Bash shell script copied verbatim to the start of the init-container. | `""` |
| `initContainersScriptsVolumeMountPath` | Path to mount the scripts consumed from the Secrets | `/usr/sbinx` |
| `initContainers.resources.limits` | initContainers.limits Kubernetes resource limits for init containers | `{}` |
| `initContainers.resources.requests.cpu` | initContainers.requests.cpu Kubernetes cpu resource limits for init containers | `100m` |
| `initContainers.resources.requests.memory` | initContainers.requests.memory Kubernetes memory resource limits for init containers | `128Mi` |
| Name | Description | Value |
| ------------------------------------------ | ------------------------------------------------------------------------------------- | ------------ |
| `initPreScript` | Bash shell script copied verbatim to the start of the init-container. | `""` |
| `initContainersScriptsVolumeMountPath` | Path to mount the scripts consumed from the Secrets. | `/usr/sbinx` |
| `initContainers.resources.limits` | initContainers.limits Kubernetes resource limits for init containers. | `{}` |
| `initContainers.resources.requests.cpu` | initContainers.requests.cpu Kubernetes cpu resource limits for init containers. | `100m` |
| `initContainers.resources.requests.memory` | initContainers.requests.memory Kubernetes memory resource limits for init containers. | `128Mi` |
### Gitea
| Name | Description | Value |
| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `gitea.metrics.enabled` | Enable Gitea metrics | `false` |
| `gitea.metrics.enabled` | Enable Gitea metrics. | `false` |
| `gitea.metrics.token` | used for `bearer` token authentication on metrics endpoint. If not specified or empty metrics endpoint is public. | `nil` |
| `gitea.metrics.serviceMonitor.enabled` | Enable Gitea metrics service monitor. Requires, that `gitea.metrics.enabled` is also set to true, to enable metrics generally. | `false` |
| `gitea.metrics.serviceMonitor.interval` | Interval at which metrics should be scraped. If not specified Prometheus' global scrape interval is used. | `""` |
@@ -1324,116 +1325,116 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
| `gitea.metrics.serviceMonitor.scheme` | HTTP scheme to use for scraping. For example `http` or `https`. Default is http. | `""` |
| `gitea.metrics.serviceMonitor.scrapeTimeout` | Timeout after which the scrape is ended. If not specified, global Prometheus scrape timeout is used. | `""` |
| `gitea.metrics.serviceMonitor.tlsConfig` | TLS configuration to use when scraping the metric endpoint by Prometheus. | `{}` |
| `gitea.ldap` | LDAP configuration | `[]` |
| `gitea.oauth` | OAuth configuration | `[]` |
| `gitea.config.server.SSH_PORT` | SSH port for rootlful Gitea image | `22` |
| `gitea.config.server.SSH_LISTEN_PORT` | SSH port for rootless Gitea image | `2222` |
| `gitea.additionalConfigSources` | Additional configuration from secret or configmap | `[]` |
| `gitea.additionalConfigFromEnvs` | Additional configuration sources from environment variables | `[]` |
| `gitea.ldap` | LDAP configuration. | `[]` |
| `gitea.oauth` | OAuth configuration. | `[]` |
| `gitea.config.server.SSH_PORT` | SSH port for rootlful Gitea image. | `22` |
| `gitea.config.server.SSH_LISTEN_PORT` | SSH port for rootless Gitea image. | `2222` |
| `gitea.additionalConfigSources` | Additional configuration from secret or configmap. | `[]` |
| `gitea.additionalConfigFromEnvs` | Additional configuration sources from environment variables. | `[]` |
| `gitea.extraEnvSourceFile` | Source environment variables from a file during init container startup. This is especially useful for reading environment variable files generated by the Vault agent-injector. | `nil` |
| `gitea.podAnnotations` | Annotations for the Gitea pod | `{}` |
| `gitea.podAnnotations` | Annotations for the Gitea pod. | `{}` |
| `gitea.ssh.logLevel` | Configure OpenSSH's log level. Only available for root-based Gitea image. | `INFO` |
### LivenessProbe
| Name | Description | Value |
| ----------------------------------------- | ------------------------------------------------ | ------ |
| `gitea.livenessProbe.enabled` | Enable liveness probe | `true` |
| `gitea.livenessProbe.tcpSocket.port` | Port to probe for liveness | `http` |
| `gitea.livenessProbe.initialDelaySeconds` | Initial delay before liveness probe is initiated | `200` |
| `gitea.livenessProbe.timeoutSeconds` | Timeout for liveness probe | `1` |
| `gitea.livenessProbe.periodSeconds` | Period for liveness probe | `10` |
| `gitea.livenessProbe.successThreshold` | Success threshold for liveness probe | `1` |
| `gitea.livenessProbe.failureThreshold` | Failure threshold for liveness probe | `10` |
| Name | Description | Value |
| ----------------------------------------- | ------------------------------------------------- | ------ |
| `gitea.livenessProbe.enabled` | Enable liveness probe. | `true` |
| `gitea.livenessProbe.tcpSocket.port` | Port to probe for liveness. | `http` |
| `gitea.livenessProbe.initialDelaySeconds` | Initial delay before liveness probe is initiated. | `200` |
| `gitea.livenessProbe.timeoutSeconds` | Timeout for liveness probe. | `1` |
| `gitea.livenessProbe.periodSeconds` | Period for liveness probe. | `10` |
| `gitea.livenessProbe.successThreshold` | Success threshold for liveness probe. | `1` |
| `gitea.livenessProbe.failureThreshold` | Failure threshold for liveness probe. | `10` |
### ReadinessProbe
| Name | Description | Value |
| ------------------------------------------ | ------------------------------------------------- | ------ |
| `gitea.readinessProbe.enabled` | Enable readiness probe | `true` |
| `gitea.readinessProbe.tcpSocket.port` | Port to probe for readiness | `http` |
| `gitea.readinessProbe.initialDelaySeconds` | Initial delay before readiness probe is initiated | `5` |
| `gitea.readinessProbe.timeoutSeconds` | Timeout for readiness probe | `1` |
| `gitea.readinessProbe.periodSeconds` | Period for readiness probe | `10` |
| `gitea.readinessProbe.successThreshold` | Success threshold for readiness probe | `1` |
| `gitea.readinessProbe.failureThreshold` | Failure threshold for readiness probe | `3` |
| Name | Description | Value |
| ------------------------------------------ | -------------------------------------------------- | ------ |
| `gitea.readinessProbe.enabled` | Enable readiness probe. | `true` |
| `gitea.readinessProbe.tcpSocket.port` | Port to probe for readiness. | `http` |
| `gitea.readinessProbe.initialDelaySeconds` | Initial delay before readiness probe is initiated. | `5` |
| `gitea.readinessProbe.timeoutSeconds` | Timeout for readiness probe. | `1` |
| `gitea.readinessProbe.periodSeconds` | Period for readiness probe. | `10` |
| `gitea.readinessProbe.successThreshold` | Success threshold for readiness probe. | `1` |
| `gitea.readinessProbe.failureThreshold` | Failure threshold for readiness probe. | `3` |
### StartupProbe
| Name | Description | Value |
| ---------------------------------------- | ----------------------------------------------- | ------- |
| `gitea.startupProbe.enabled` | Enable startup probe | `false` |
| `gitea.startupProbe.tcpSocket.port` | Port to probe for startup | `http` |
| `gitea.startupProbe.initialDelaySeconds` | Initial delay before startup probe is initiated | `60` |
| `gitea.startupProbe.timeoutSeconds` | Timeout for startup probe | `1` |
| `gitea.startupProbe.periodSeconds` | Period for startup probe | `10` |
| `gitea.startupProbe.successThreshold` | Success threshold for startup probe | `1` |
| `gitea.startupProbe.failureThreshold` | Failure threshold for startup probe | `10` |
| Name | Description | Value |
| ---------------------------------------- | ------------------------------------------------ | ------- |
| `gitea.startupProbe.enabled` | Enable startup probe. | `false` |
| `gitea.startupProbe.tcpSocket.port` | Port to probe for startup. | `http` |
| `gitea.startupProbe.initialDelaySeconds` | Initial delay before startup probe is initiated. | `60` |
| `gitea.startupProbe.timeoutSeconds` | Timeout for startup probe. | `1` |
| `gitea.startupProbe.periodSeconds` | Period for startup probe. | `10` |
| `gitea.startupProbe.successThreshold` | Success threshold for startup probe. | `1` |
| `gitea.startupProbe.failureThreshold` | Failure threshold for startup probe. | `10` |
### valkey
| Name | Description | Value |
| ------------------------------------------ | -------------------------------------------------- | -------------------------- |
| `valkey.enabled` | Enable valkey standalone or replicated | `false` |
| `valkey.image.registry` | Image registry | `docker.io` |
| `valkey.image.repository` | Image repository | `valkey/valkey` |
| `valkey.image.tag` | Image tag | `""` |
| `valkey.auth.enabled` | Enable ACL-based authentication | `true` |
| `valkey.auth.aclUsers.default.permissions` | ACL permissions for the default user | `~* &* +@all` |
| `valkey.auth.aclUsers.default.password` | Password for the default user | `changeme` |
| `valkey.service.port` | Port of Valkey service | `6379` |
| `valkey.enabled` | Enable valkey standalone or replicated. | `false` |
| `valkey.image.registry` | Image registry. | `docker.io` |
| `valkey.image.repository` | Image repository. | `valkey/valkey` |
| `valkey.image.tag` | Image tag. | `""` |
| `valkey.auth.enabled` | Enable ACL-based authentication. | `true` |
| `valkey.auth.aclUsers.default.permissions` | ACL permissions for the default user. | `~* &* +@all` |
| `valkey.auth.aclUsers.default.password` | Password for the default user. | `changeme` |
| `valkey.service.port` | Port of Valkey service. | `6379` |
| `valkey.dataStorage.enabled` | Enable persistence using Persistent Volume Claims. | `false` |
| `valkey.dataStorage.className` | Persistent Volume storage class. | `""` |
| `valkey.dataStorage.requestedSize` | Persistent Volume size. | `8Gi` |
| `valkey.replica.enabled` | Enable replication | `false` |
| `valkey.replica.replicas` | Number of Valkey replica instances to deploy | `3` |
| `valkey.replica.enabled` | Enable replication. | `false` |
| `valkey.replica.replicas` | Number of Valkey replica instances to deploy. | `3` |
| `valkey.replica.persistence.size` | Persistent Volume size for replicas. | `8Gi` |
| `valkey.replica.persistence.storageClass` | Persistent Volume storage class for replicas. | `""` |
| `valkey.metrics.enabled` | Enable Prometheus exporter sidecar | `false` |
| `valkey.metrics.exporter.image.registry` | Image registry | `ghcr.io` |
| `valkey.metrics.exporter.image.repository` | Image repository | `oliver006/redis_exporter` |
| `valkey.metrics.exporter.image.tag` | Image tag | `""` |
| `valkey.metrics.enabled` | Enable Prometheus exporter sidecar. | `false` |
| `valkey.metrics.exporter.image.registry` | Image registry. | `ghcr.io` |
| `valkey.metrics.exporter.image.repository` | Image repository. | `oliver006/redis_exporter` |
| `valkey.metrics.exporter.image.tag` | Image tag. | `""` |
### PostgreSQL HA
| Name | Description | Value |
| -------------------------------------------------- | ---------------------------------------------------------------- | --------------------------------- |
| `postgresql-ha.enabled` | Enable PostgreSQL HA | `true` |
| `postgresql-ha.global.postgresql.database` | Name for a custom database to create (overrides `auth.database`) | `gitea` |
| `postgresql-ha.global.postgresql.username` | Name for a custom user to create (overrides `auth.username`) | `gitea` |
| `postgresql-ha.global.postgresql.password` | Name for a custom password to create (overrides `auth.password`) | `gitea` |
| `postgresql-ha.metrics.image.repository` | Image repository, eg. `bitnamilegacy/postgres-exporter`. | `bitnamilegacy/postgres-exporter` |
| `postgresql-ha.postgresql.image.repository` | Image repository, eg. `bitnamilegacy/postgresql-repmgr`. | `bitnamilegacy/postgresql-repmgr` |
| `postgresql-ha.postgresql.repmgrPassword` | Repmgr Password | `changeme2` |
| `postgresql-ha.postgresql.postgresPassword` | postgres Password | `changeme1` |
| `postgresql-ha.postgresql.password` | Password for the `gitea` user (overrides `auth.password`) | `changeme4` |
| `postgresql-ha.pgpool.adminPassword` | pgpool adminPassword | `changeme3` |
| `postgresql-ha.pgpool.image.repository` | Image repository, eg. `bitnamilegacy/pgpool`. | `bitnamilegacy/pgpool` |
| `postgresql-ha.pgpool.srCheckPassword` | pgpool srCheckPassword | `changeme4` |
| `postgresql-ha.service.ports.postgresql` | PostgreSQL service port (overrides `service.ports.postgresql`) | `5432` |
| `postgresql-ha.persistence.enabled` | Enable persistence. | `true` |
| `postgresql-ha.persistence.storageClass` | Persistent Volume Storage Class. | `""` |
| `postgresql-ha.persistence.size` | PVC Storage Request for PostgreSQL HA volume | `10Gi` |
| `postgresql-ha.volumePermissions.image.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
| Name | Description | Value |
| -------------------------------------------------- | ----------------------------------------------------------------- | --------------------------------- |
| `postgresql-ha.enabled` | Enable PostgreSQL HA. | `true` |
| `postgresql-ha.global.postgresql.database` | Name for a custom database to create (overrides `auth.database`). | `gitea` |
| `postgresql-ha.global.postgresql.username` | Name for a custom user to create (overrides `auth.username`). | `gitea` |
| `postgresql-ha.global.postgresql.password` | Name for a custom password to create (overrides `auth.password`). | `gitea` |
| `postgresql-ha.metrics.image.repository` | Image repository, eg. `bitnamilegacy/postgres-exporter`. | `bitnamilegacy/postgres-exporter` |
| `postgresql-ha.postgresql.image.repository` | Image repository, eg. `bitnamilegacy/postgresql-repmgr`. | `bitnamilegacy/postgresql-repmgr` |
| `postgresql-ha.postgresql.repmgrPassword` | Repmgr Password. | `changeme2` |
| `postgresql-ha.postgresql.postgresPassword` | postgres Password. | `changeme1` |
| `postgresql-ha.postgresql.password` | Password for the `gitea` user (overrides `auth.password`). | `changeme4` |
| `postgresql-ha.pgpool.adminPassword` | pgpool adminPassword. | `changeme3` |
| `postgresql-ha.pgpool.image.repository` | Image repository, eg. `bitnamilegacy/pgpool`. | `bitnamilegacy/pgpool` |
| `postgresql-ha.pgpool.srCheckPassword` | pgpool srCheckPassword. | `changeme4` |
| `postgresql-ha.service.ports.postgresql` | PostgreSQL service port (overrides `service.ports.postgresql`). | `5432` |
| `postgresql-ha.persistence.enabled` | Enable persistence. | `true` |
| `postgresql-ha.persistence.storageClass` | Persistent Volume Storage Class. | `""` |
| `postgresql-ha.persistence.size` | PVC Storage Request for PostgreSQL HA volume. | `10Gi` |
| `postgresql-ha.volumePermissions.image.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
### PostgreSQL
| Name | Description | Value |
| ------------------------------------------------------- | ---------------------------------------------------------------- | --------------------------------- |
| `postgresql.enabled` | Enable PostgreSQL | `false` |
| `postgresql.global.postgresql.auth.password` | Password for the `gitea` user (overrides `auth.password`) | `gitea` |
| `postgresql.global.postgresql.auth.database` | Name for a custom database to create (overrides `auth.database`) | `gitea` |
| `postgresql.global.postgresql.auth.username` | Name for a custom user to create (overrides `auth.username`) | `gitea` |
| `postgresql.global.postgresql.service.ports.postgresql` | PostgreSQL service port (overrides `service.ports.postgresql`) | `5432` |
| `postgresql.image.repository` | Image repository, eg. `bitnamilegacy/postgresql`. | `bitnamilegacy/postgresql` |
| `postgresql.primary.persistence.enabled` | Enable persistence. | `true` |
| `postgresql.primary.persistence.storageClass` | Persistent Volume storage class. | `""` |
| `postgresql.primary.persistence.size` | PVC Storage Request for PostgreSQL volume. | `10Gi` |
| `postgresql.readReplicas.persistence.enabled` | Enable PostgreSQL read only data persistence using PVC. | `true` |
| `postgresql.readReplicas.persistence.storageClass` | Persistent Volume storage class. | `""` |
| `postgresql.readReplicas.persistence.size` | PVC Storage Request for PostgreSQL volume. | `""` |
| `postgresql.metrics.image.repository` | Image repository, eg. `bitnamilegacy/postgres-exporter`. | `bitnamilegacy/postgres-exporter` |
| `postgresql.volumePermissions.image.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
| Name | Description | Value |
| ------------------------------------------------------- | ----------------------------------------------------------------- | --------------------------------- |
| `postgresql.enabled` | Enable PostgreSQL. | `false` |
| `postgresql.global.postgresql.auth.password` | Password for the `gitea` user (overrides `auth.password`). | `gitea` |
| `postgresql.global.postgresql.auth.database` | Name for a custom database to create (overrides `auth.database`). | `gitea` |
| `postgresql.global.postgresql.auth.username` | Name for a custom user to create (overrides `auth.username`). | `gitea` |
| `postgresql.global.postgresql.service.ports.postgresql` | PostgreSQL service port (overrides `service.ports.postgresql`). | `5432` |
| `postgresql.image.repository` | Image repository, eg. `bitnamilegacy/postgresql`. | `bitnamilegacy/postgresql` |
| `postgresql.primary.persistence.enabled` | Enable persistence. | `true` |
| `postgresql.primary.persistence.storageClass` | Persistent Volume storage class. | `""` |
| `postgresql.primary.persistence.size` | PVC Storage Request for PostgreSQL volume. | `10Gi` |
| `postgresql.readReplicas.persistence.enabled` | Enable PostgreSQL read only data persistence using PVC. | `true` |
| `postgresql.readReplicas.persistence.storageClass` | Persistent Volume storage class. | `""` |
| `postgresql.readReplicas.persistence.size` | PVC Storage Request for PostgreSQL volume. | `""` |
| `postgresql.metrics.image.repository` | Image repository, eg. `bitnamilegacy/postgres-exporter`. | `bitnamilegacy/postgres-exporter` |
| `postgresql.volumePermissions.image.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
### Advanced
@@ -1443,7 +1444,7 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
| `test.enabled` | Set it to false to disable test-connection Pod. | `true` |
| `test.image.name` | Image name for the wget container used in the test-connection Pod. | `busybox` |
| `test.image.tag` | Image tag for the wget container used in the test-connection Pod. | `latest` |
| `extraDeploy` | Array of extra objects to deploy with the release | `[]` |
| `extraDeploy` | Array of extra objects to deploy with the release. | `[]` |
## Contributing
+908
View File
File diff suppressed because it is too large Load Diff
+2
View File
@@ -9,11 +9,13 @@
"npm": ">=8.0.0"
},
"scripts": {
"readme:link": "markdown-link-check *.md",
"readme:lint": "markdownlint *.md -f",
"readme:parameters": "readme-generator -v values.yaml -r README.md"
},
"devDependencies": {
"@bitnami/readme-generator-for-helm": "^2.5.0",
"markdown-link-check": "^3.13.6",
"markdownlint-cli": "^0.49.0"
}
}
+136
View File
@@ -0,0 +1,136 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"gitea>gitea/renovate-config",
"helpers:pinGitHubActionDigests",
":automergeMinor",
"schedule:automergeDaily",
"schedule:weekends"
],
"labels": [
"kind/dependency"
],
"digest": {
"automerge": true
},
"automergeStrategy": "squash",
"git-submodules": {
"enabled": true
},
"customManagers": [
{
"description": "Gitea-version of https://docs.renovatebot.com/presets-regexManagers/#regexmanagersgithubactionsversions",
"customType": "regex",
"managerFilePatterns": [
"/.gitea/workflows/.+\\.ya?ml$/"
],
"matchStrings": [
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?_VERSION\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s"
]
},
{
"description": "Detect helm-unittest yaml schema file",
"customType": "regex",
"managerFilePatterns": [
"/.vscode/settings\\.json$/"
],
"matchStrings": [
"https:\\/\\/raw\\.githubusercontent\\.com\\/(?<depName>[^\\s]+?)\\/(?<currentValue>v[0-9.]+?)\\/schema\\/helm-testsuite\\.json"
],
"datasourceTemplate": "github-releases"
},
{
"description": "Automatically detect new Gitea releases",
"customType": "regex",
"datasourceTemplate": "github-releases",
"depNameTemplate": "gitea/gitea",
"extractVersionTemplate": "^v(?<version>.*)$",
"managerFilePatterns": [
"/(^|/)Chart\\.ya?ml$/"
],
"matchStrings": [
"^appVersion:\\s+[\"']?(?<currentVersion>\\S+)[\"']?$"
]
}
],
"lockFileMaintenance": {
"enabled": true,
"commitMessageAction": "update",
"commitMessageTopic": "lockfiles",
"schedule": [
"at any time"
]
},
"packageRules": [
{
"groupName": "subcharts (minor & patch)",
"matchManagers": [
"helmv3"
],
"matchUpdateTypes": [
"minor",
"patch",
"digest"
]
},
{
"groupName": "bats testing framework",
"matchManagers": [
"git-submodules"
],
"matchUpdateTypes": [
"minor",
"patch",
"digest"
]
},
{
"groupName": "workflow dependencies (minor & patch)",
"matchManagers": [
"github-actions",
"npm",
"custom.regex"
],
"matchUpdateTypes": [
"minor",
"patch",
"digest"
],
"matchFileNames": [
"!Chart.yaml"
]
},
{
"description": "Update README.md on changes in values.yaml",
"matchManagers": [
"helm-values"
],
"postUpgradeTasks": {
"commands": [
"install-tool node",
"make readme"
],
"fileFilters": [
"README.md"
],
"executionMode": "update"
}
},
{
"description": "Override changelog url for Helm image, to have release notes in our PRs",
"matchDepNames": [
"alpine/helm"
],
"changelogUrl": "https://github.com/helm/helm"
},
{
"description": "Bump Gitea as fast as possible - not only on weekends",
"matchDepNames": [
"go-gitea/gitea"
],
"schedule": [
"at any time"
]
}
]
}
-136
View File
@@ -1,136 +0,0 @@
{
$schema: "https://docs.renovatebot.com/renovate-schema.json",
extends: [
"gitea>gitea/renovate-config",
"helpers:pinGitHubActionDigests",
":automergeMinor",
"schedule:automergeDaily",
"schedule:weekends",
],
labels: [
"kind/dependency",
],
digest: {
automerge: true,
},
automergeStrategy: "squash",
"git-submodules": {
enabled: true,
},
customManagers: [
{
description: "Gitea-version of https://docs.renovatebot.com/presets-regexManagers/#regexmanagersgithubactionsversions",
customType: "regex",
managerFilePatterns: [
"/.gitea/workflows/.+\\.ya?ml$/",
],
matchStrings: [
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?_VERSION\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s",
],
},
{
description: "Detect helm-unittest yaml schema file",
customType: "regex",
managerFilePatterns: [
"/.vscode/settings\\.json$/",
],
matchStrings: [
"https:\\/\\/raw\\.githubusercontent\\.com\\/(?<depName>[^\\s]+?)\\/(?<currentValue>v[0-9.]+?)\\/schema\\/helm-testsuite\\.json",
],
datasourceTemplate: "github-releases",
},
{
description: "Automatically detect new Gitea releases",
customType: "regex",
datasourceTemplate: "github-releases",
depNameTemplate: "gitea/gitea",
extractVersionTemplate: "^v(?<version>.*)$",
managerFilePatterns: [
"/(^|/)Chart\\.ya?ml$/",
],
matchStrings: [
"^appVersion:\\s+[\"']?(?<currentVersion>\\S+)[\"']?$",
],
},
],
lockFileMaintenance: {
"enabled": true,
"commitMessageAction": "update",
"commitMessageTopic": "lockfiles",
schedule: [
"at any time",
]
},
packageRules: [
{
groupName: "subcharts (minor & patch)",
matchManagers: [
"helmv3",
],
matchUpdateTypes: [
"minor",
"patch",
"digest",
],
},
{
groupName: "bats testing framework",
matchManagers: [
"git-submodules",
],
matchUpdateTypes: [
"minor",
"patch",
"digest",
],
},
{
groupName: "workflow dependencies (minor & patch)",
matchManagers: [
"github-actions",
"npm",
"custom.regex",
],
matchUpdateTypes: [
"minor",
"patch",
"digest",
],
matchFileNames: [
"!Chart.yaml",
],
},
{
description: "Update README.md on changes in values.yaml",
matchManagers: [
"helm-values",
],
postUpgradeTasks: {
commands: [
"install-tool node",
"make readme",
],
fileFilters: [
"README.md",
],
executionMode: "update",
},
},
{
description: "Override changelog url for Helm image, to have release notes in our PRs",
matchDepNames: [
"alpine/helm",
],
changelogUrl: "https://github.com/helm/helm",
},
{
description: "Bump Gitea as fast as possible - not only on weekends",
matchDepNames: [
"go-gitea/gitea",
],
schedule: [
"at any time",
],
},
],
}
-15
View File
@@ -154,17 +154,6 @@ These default to runAsUser 1000 outside OpenShift to preserve existing behavior.
{{- include "gitea.containerSecurityContext" (list $root $containerSecurityContext) -}}
{{- end -}}
{{/*
Storage Class
*/}}
{{- define "gitea.persistence.storageClass" -}}
{{- $storageClass := (tpl ( default "" .Values.persistence.storageClass) .) | default (tpl ( default "" .Values.global.storageClass) .) }}
{{- if $storageClass }}
storageClassName: {{ $storageClass | quote }}
{{- end }}
{{- end -}}
{{/*
Common labels
*/}}
@@ -504,10 +493,6 @@ https
{{- end -}}
{{- end -}}
{{- define "gitea.serviceAccountName" -}}
{{ .Values.serviceAccount.name | default (include "gitea.fullname" .) }}
{{- end -}}
{{- define "ingress.annotations" -}}
{{- if .Values.ingress.annotations }}
annotations:
@@ -40,8 +40,8 @@
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
{{- with $config.volumeMounts }}
@@ -105,8 +105,8 @@
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
- name: inline-config-sources
mountPath: /env-to-ini-mounts/inlines/
@@ -168,8 +168,8 @@
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
- name: gpg-private-key
mountPath: /raw
@@ -292,8 +292,8 @@
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
{{- with $config.volumeMounts }}
+38
View File
@@ -0,0 +1,38 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.persistentVolumeClaim.annotations" -}}
{{- with .Values.persistence.new.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.persistentVolumeClaim.enabled" -}}
{{- if and .Values.persistence.enabled (not .Values.persistence.existingPersistentVolumeClaim.enabled) -}}
true
{{- else -}}
false
{{- end }}
{{- end }}
{{/* labels */}}
{{- define "gitea.persistentVolumeClaim.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.persistence.new.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
{{/* name */}}
{{- define "gitea.persistentVolumeClaim.name" -}}
{{- if .Values.persistence.existingPersistentVolumeClaim.enabled -}}
{{ required "persistence.existingPersistentVolumeClaim.persistentVolumeClaimName is required when persistence.existingPersistentVolumeClaim.enabled is true" .Values.persistence.existingPersistentVolumeClaim.persistentVolumeClaimName }}
{{- else -}}
{{ include "gitea.fullname" . }}
{{- end }}
{{- end }}
@@ -54,7 +54,7 @@ Arguments: (list $root $key)
{{- $name := include (printf "gitea.secret.%s.name" $key) $root -}}
{{- lookup "v1" "Secret" $namespace $name | toYaml | sha256sum -}}
{{- else -}}
{{- include (printf "%s/gitea/secret_%s.yaml" $root.Template.BasePath $key) $root | sha256sum -}}
{{- include (printf "%s/secret_%s.yaml" $root.Template.BasePath $key) $root | sha256sum -}}
{{- end -}}
{{- end }}
+38
View File
@@ -0,0 +1,38 @@
{{/* vim: set filetype=mustache: */}}
{{/* annotations */}}
{{- define "gitea.serviceAccount.annotations" -}}
{{- with .Values.serviceAccount.new.annotations }}
{{- toYaml . -}}
{{- end }}
{{- end }}
{{/* enabled */}}
{{- define "gitea.serviceAccount.enabled" -}}
{{- if and .Values.serviceAccount.enabled (not .Values.serviceAccount.existingServiceAccount.enabled) -}}
true
{{- else -}}
false
{{- end }}
{{- end }}
{{/* labels */}}
{{- define "gitea.serviceAccount.labels" -}}
{{ include "gitea.labels" . }}
{{- with .Values.serviceAccount.new.labels }}
{{ toYaml . }}
{{- end }}
{{- end }}
{{/* name */}}
{{- define "gitea.serviceAccount.name" -}}
{{- if .Values.serviceAccount.existingServiceAccount.enabled -}}
{{ required "serviceAccount.existingServiceAccount.existingServiceAccountName is required when serviceAccount.existingServiceAccount.enabled is true" .Values.serviceAccount.existingServiceAccount.existingServiceAccountName }}
{{- else -}}
{{ include "gitea.fullname" . }}
{{- end }}
{{- end }}
@@ -42,8 +42,8 @@ spec:
{{- if .Values.deployment.schedulerName }}
schedulerName: "{{ .Values.deployment.schedulerName }}"
{{- end }}
{{- if (or .Values.serviceAccount.create .Values.serviceAccount.name) }}
serviceAccountName: {{ include "gitea.serviceAccountName" . }}
{{- if .Values.serviceAccount.enabled }}
serviceAccountName: {{ include "gitea.serviceAccount.name" . }}
{{- end }}
{{- if .Values.deployment.priorityClassName }}
priorityClassName: "{{ .Values.deployment.priorityClassName }}"
@@ -145,8 +145,8 @@ spec:
mountPath: /tmp
- name: data
mountPath: /data
{{- if .Values.persistence.subPath }}
subPath: {{ .Values.persistence.subPath }}
{{- if .Values.persistence.new.subPath }}
subPath: {{ .Values.persistence.new.subPath }}
{{- end }}
{{- include "gitea.container-additional-mounts" . | nindent 12 }}
{{- if .Values.extraContainers }}
@@ -211,12 +211,10 @@ spec:
defaultMode: 0100
{{- end }}
{{- if .Values.persistence.enabled }}
{{- if .Values.persistence.mount }}
- name: data
persistentVolumeClaim:
claimName: {{ .Values.persistence.claimName }}
{{- end }}
{{- else if not .Values.persistence.enabled }}
claimName: {{ include "gitea.persistentVolumeClaim.name" . }}
{{- else }}
- name: data
emptyDir: {}
{{- end }}
@@ -1,26 +0,0 @@
{{- if and .Values.persistence.enabled .Values.persistence.create }}
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: {{ .Values.persistence.claimName }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
annotations:
{{ .Values.persistence.annotations | toYaml | indent 4}}
labels:
{{ .Values.persistence.labels | toYaml | indent 4}}
spec:
accessModes:
{{- if gt (.Values.deployment.replicas | int) 1 }}
- ReadWriteMany
{{- else }}
{{- .Values.persistence.accessModes | toYaml | nindent 4 }}
{{- end }}
volumeMode: Filesystem
{{- include "gitea.persistence.storageClass" . | nindent 2 }}
{{- with .Values.persistence.volumeName }}
volumeName: {{ . }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.size }}
{{- end }}
-21
View File
@@ -1,21 +0,0 @@
{{- if .Values.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "gitea.serviceAccountName" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
labels:
{{- include "gitea.labels" . | nindent 4 }}
{{- with .Values.serviceAccount.labels }}
{{- . | toYaml | nindent 4 }}
{{- end }}
{{- with .Values.serviceAccount.annotations }}
annotations:
{{- . | toYaml | nindent 4 }}
{{- end }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
{{- with .Values.serviceAccount.imagePullSecrets }}
imagePullSecrets:
{{- . | toYaml | nindent 2 }}
{{- end }}
{{- end }}
+33
View File
@@ -0,0 +1,33 @@
{{- if eq (include "gitea.persistentVolumeClaim.enabled" .) "true" }}
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
{{- with (include "gitea.persistentVolumeClaim.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.persistentVolumeClaim.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.persistentVolumeClaim.name" . }}
namespace: {{ .Release.Namespace }}
spec:
accessModes:
{{- if gt (.Values.deployment.replicas | int) 1 }}
- ReadWriteMany
{{- else }}
{{- .Values.persistence.new.accessModes | toYaml | nindent 4 }}
{{- end }}
resources:
requests:
storage: {{ .Values.persistence.new.size }}
{{- with .Values.persistence.new.storageClassName }}
storageClassName: {{ . }}
{{- end }}
volumeMode: Filesystem
{{- with .Values.persistence.new.persistentVolumeName }}
volumeName: {{ . }}
{{- end }}
{{- end }}
@@ -37,8 +37,8 @@ stringData:
{{- end }}
{{- end }}
{{- if eq (first .Values.persistence.accessModes) "ReadWriteOnce" -}}
{{- fail "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany." -}}
{{- if eq (first .Values.persistence.new.accessModes) "ReadWriteOnce" -}}
{{- fail "When using multiple replicas, a RWX file system is required and persistence.new.accessModes[0] must be set to ReadWriteMany." -}}
{{- end }}
{{- if .Values.gitea.config.indexer -}}
{{- if eq .Values.gitea.config.indexer.ISSUE_INDEXER_TYPE "bleve" -}}
+21
View File
@@ -0,0 +1,21 @@
{{- if eq (include "gitea.serviceAccount.enabled" .) "true" }}
---
apiVersion: v1
kind: ServiceAccount
metadata:
{{- with (include "gitea.serviceAccount.annotations" .) }}
annotations:
{{- . | nindent 4 }}
{{- end }}
{{- with (include "gitea.serviceAccount.labels" .) }}
labels:
{{- . | nindent 4 }}
{{- end }}
name: {{ include "gitea.serviceAccount.name" . }}
namespace: {{ .Values.namespace | default .Release.Namespace }}
automountServiceAccountToken: {{ .Values.serviceAccount.new.automountServiceAccountToken }}
{{- with .Values.serviceAccount.new.imagePullSecrets }}
imagePullSecrets:
{{- . | toYaml | nindent 2 }}
{{- end }}
{{- end }}
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_admin.yaml
- templates/secret_admin.yaml
tests:
- it: skips rendering when the admin user is disabled
set:
+3 -3
View File
@@ -3,17 +3,17 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_inlineConfig.yaml
- templates/secret_inlineConfig.yaml
tests:
- it: "actions are enabled by default (based on vanilla Gitea behavior)"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
notExists:
path: stringData.actions
- it: "actions can be disabled via inline config"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea.config.actions.ENABLED: false
asserts:
+3 -3
View File
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "cache is configured correctly for valkey"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: true
@@ -17,7 +17,7 @@ tests:
HOST=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- it: "cache is configured correctly for 'memory' when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -30,7 +30,7 @@ tests:
HOST=
- it: "cache can be customized when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -3,11 +3,11 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
tests:
- it: uses `gitea config edit-ini` to write app.ini from environment variables
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: metrics token is set
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
@@ -18,7 +18,7 @@ tests:
ENABLED=true
TOKEN=somepassword
- it: metrics token is empty
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
@@ -31,7 +31,7 @@ tests:
value: |-
ENABLED=true
- it: metrics token is nil
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
@@ -44,7 +44,7 @@ tests:
value: |-
ENABLED=true
- it: does not configures a token if metrics are disabled
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea:
metrics:
+3 -3
View File
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "queue is configured correctly for valkey"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: true
@@ -17,7 +17,7 @@ tests:
TYPE=redis
- it: "queue is configured correctly for 'levelDB' when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -30,7 +30,7 @@ tests:
TYPE=level
- it: "queue can be customized when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "[default values] uses ingress host for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -22,7 +22,7 @@ tests:
################################################
- it: "[no ingress hosts] uses gitea http service for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
ingress:
hosts: []
@@ -43,7 +43,7 @@ tests:
################################################
- it: "[provided via values] uses that for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
gitea.config.server.DOMAIN: provided.example.com
ingress:
@@ -69,7 +69,7 @@ tests:
################################################
- it: "[route enabled] uses route host for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
route:
enabled: true
@@ -91,7 +91,7 @@ tests:
################################################
- it: "[route tls termination] uses https for ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
route:
enabled: true
@@ -107,7 +107,7 @@ tests:
################################################
- it: "[HTTPRoute enabled] uses first hostname for DOMAIN|SSH_DOMAIN|ROOT_URL"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
ingress:
hosts: []
@@ -137,7 +137,7 @@ tests:
################################################
- it: "[HTTPRoute tls] switches ROOT_URL to https"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
ingress:
hosts: []
+3 -3
View File
@@ -4,7 +4,7 @@ release:
namespace: testing
tests:
- it: "session is configured correctly for valkey"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: true
@@ -17,7 +17,7 @@ tests:
PROVIDER_CONFIG=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- it: "session is configured correctly for 'memory' when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -30,7 +30,7 @@ tests:
PROVIDER_CONFIG=
- it: "session can be customized when valkey is disabled"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
set:
valkey:
enabled: false
@@ -106,7 +106,7 @@ tests:
name: gitea-unittests-postgresql-ha-pgpool
namespace: testing
- it: "[gitea] connects to pgpool service"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -115,14 +115,14 @@ tests:
- it: "[gitea] connects to pgpool service with custom cluster domain"
set:
clusterDomain: my-special-cluster.local
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
path: stringData.database
pattern: HOST=gitea-unittests-postgresql-ha-pgpool.testing.svc.my-special-cluster.local:1234
- it: "[gitea] connects to configured database"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -65,7 +65,7 @@ tests:
name: gitea-unittests-postgresql
namespace: testing
- it: "[gitea] connects to postgresql service"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -74,14 +74,14 @@ tests:
- it: "[gitea] connects to postgresql service with custom cluster domain"
set:
clusterDomain: my-special-cluster.local
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
path: stringData.database
pattern: HOST=gitea-unittests-postgresql.testing.svc.my-special-cluster.local:1234
- it: "[gitea] connects to configured database"
template: templates/gitea/secret_inlineConfig.yaml
template: templates/secret_inlineConfig.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -35,7 +35,7 @@ tests:
targetPort: tcp
protocol: TCP
- it: "[gitea] waits for valkey to be up and running"
template: templates/gitea/secret_init.yaml
template: templates/secret_init.yaml
asserts:
- documentIndex: 0
matchRegex:
@@ -44,7 +44,7 @@ tests:
- it: "[gitea] waits for valkey to be up and running with custom cluster domain"
set:
clusterDomain: my-special-cluster.local
template: templates/gitea/secret_init.yaml
template: templates/secret_init.yaml
asserts:
- documentIndex: 0
matchRegex:
+21 -18
View File
@@ -3,22 +3,23 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: fails with multiple replicas and "GIT_GC_REPOS" enabled
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
persistence:
accessModes:
- ReadWriteMany
new:
accessModes:
- ReadWriteMany
gitea:
config:
cron:
@@ -28,21 +29,22 @@ tests:
- failedTemplate:
errorMessage: "Invoking the garbage collector via CRON is not yet supported when running with multiple replicas. Please set 'gitea.config.cron.GIT_GC_REPOS.enabled = false'."
- it: fails with multiple replicas and RWX file system not set
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
asserts:
- failedTemplate:
errorMessage: "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany."
errorMessage: "When using multiple replicas, a RWX file system is required and persistence.new.accessModes[0] must be set to ReadWriteMany."
- it: fails with multiple replicas and bleve issue indexer
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
persistence:
accessModes:
- ReadWriteMany
new:
accessModes:
- ReadWriteMany
gitea:
config:
indexer:
@@ -51,13 +53,14 @@ tests:
- failedTemplate:
errorMessage: "When using multiple replicas, the issue indexer (gitea.config.indexer.ISSUE_INDEXER_TYPE) must be set to a HA-ready provider such as 'meilisearch', 'elasticsearch' or 'db' (if the DB is HA-ready)."
- it: fails with multiple replicas and bleve repo indexer
template: templates/gitea/secret_config.yaml
template: templates/secret_config.yaml
set:
deployment:
replicas: 2
persistence:
accessModes:
- ReadWriteMany
new:
accessModes:
- ReadWriteMany
gitea:
config:
indexer:
+11 -11
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: reads the admin credentials from the generated secret
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- contains:
path: spec.template.spec.initContainers[2].env
@@ -45,7 +45,7 @@ tests:
value: keepUpdated
- it: reads the admin credentials from the configured keys of an existing secret
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.existingSecret.enabled: true
secrets.admin.existingSecret.secretName: custom-admin-secret
@@ -79,7 +79,7 @@ tests:
name: custom-admin-secret
- it: omits the admin environment when the admin user is disabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.enabled: false
asserts:
@@ -95,7 +95,7 @@ tests:
any: true
- it: fails on an unsupported password mode
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.passwordMode: unsupported
asserts:
+39 -39
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: renders a deployment
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- hasDocuments:
count: 1
@@ -21,14 +21,14 @@ tests:
apiVersion: apps/v1
name: gitea-unittests
- it: renders no deployment when disabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.enabled: false
asserts:
- hasDocuments:
count: 0
- it: deployment labels are set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.labels:
hello: world
@@ -46,7 +46,7 @@ tests:
content:
hello: world
- it: deployment labels are not in selector matchLabels
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.labels:
custom-label: custom-value
@@ -58,7 +58,7 @@ tests:
app.kubernetes.io/name: gitea
app.kubernetes.io/instance: gitea-unittests
- it: deployment labels are always rendered
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- isSubset:
path: metadata.labels
@@ -68,12 +68,12 @@ tests:
app.kubernetes.io/instance: gitea-unittests
app.kubernetes.io/managed-by: Helm
- it: deployment annotations are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: metadata.annotations
- it: deployment annotations are set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.annotations:
hello: world
@@ -86,7 +86,7 @@ tests:
asserts:
- notExists:
path: spec.template.spec.nodeSelector
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: nodeSelector is defined
set:
deployment.nodeSelector:
@@ -98,14 +98,14 @@ tests:
content:
foo: bar
bar: foo
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: affinity is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.affinity
- it: affinity is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.affinity:
nodeAffinity:
@@ -129,12 +129,12 @@ tests:
values:
- linux
- it: dnsConfig is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.dnsConfig
- it: dnsConfig is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.dnsConfig:
nameservers:
@@ -152,12 +152,12 @@ tests:
- name: ndots
value: "2"
- it: priorityClassName is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.priorityClassName
- it: priorityClassName is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.priorityClassName: high-priority
asserts:
@@ -165,12 +165,12 @@ tests:
path: spec.template.spec.priorityClassName
value: high-priority
- it: schedulerName is undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.schedulerName
- it: schedulerName is defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.schedulerName: stork
asserts:
@@ -178,7 +178,7 @@ tests:
path: spec.template.spec.schedulerName
value: stork
- it: strategy defaults to a rolling update
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.strategy
@@ -188,7 +188,7 @@ tests:
maxUnavailable: 0
maxSurge: 100%
- it: strategy omits rollingUpdate for other strategy types
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.strategy.type: Recreate
asserts:
@@ -197,12 +197,12 @@ tests:
value:
type: Recreate
- it: tolerations are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.tolerations
- it: tolerations are defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.tolerations:
- key: database/type
@@ -218,12 +218,12 @@ tests:
value: postgres
effect: NoSchedule
- it: topologySpreadConstraints are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.topologySpreadConstraints
- it: topologySpreadConstraints are defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.topologySpreadConstraints:
- topologyKey: kubernetes.io/hostname
@@ -244,7 +244,7 @@ tests:
app.kubernetes.io/instance: gitea-unittests
- it: "injects TMP_EXISTING_ENVS_FILE as environment variable to 'init-app-ini' init container"
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- contains:
path: spec.template.spec.initContainers[1].env
@@ -252,7 +252,7 @@ tests:
name: TMP_EXISTING_ENVS_FILE
value: /tmp/existing-envs
- it: "injects ENV_TO_INI_MOUNT_POINT as environment variable to 'init-app-ini' init container"
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- contains:
path: spec.template.spec.initContainers[1].env
@@ -260,7 +260,7 @@ tests:
name: ENV_TO_INI_MOUNT_POINT
value: /env-to-ini-mounts
- it: "deployment.gitea.env is injected into all init containers and the gitea container"
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.env:
- name: VARIABLE
@@ -287,7 +287,7 @@ tests:
name: VARIABLE
value: my-value
- it: CPU resources are defined as well as GOMAXPROCS
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.resources:
limits:
@@ -315,7 +315,7 @@ tests:
cpu: 100ms
memory: 100Mi
- it: container resources default to an empty map and GOMAXPROCS is omitted
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.containers[0].resources
@@ -329,12 +329,12 @@ tests:
divisor: "1"
resource: limits.cpu
- it: pod level resources are undefined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.resources
- it: pod level resources are defined
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.resources:
limits:
@@ -354,7 +354,7 @@ tests:
cpu: 250m
memory: 256Mi
- it: Init containers have correct volumeMount path
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
initContainersScriptsVolumeMountPath: "/custom/init/path"
asserts:
@@ -365,7 +365,7 @@ tests:
path: spec.template.spec.initContainers[*].volumeMounts[?(@.name=="config")].mountPath
value: "/custom/init/path"
- it: Init containers have correct volumeMount path if there is no override
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.initContainers[*].volumeMounts[?(@.name=="init")].mountPath
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: omits the checksum annotations by default
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.enabled: true
secrets.config.enabled: true
@@ -38,7 +38,7 @@ tests:
path: spec.template.metadata.annotations["checksum/metrics"]
- it: adds a checksum annotation for every Secret when addSHASumAnnotation is enabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.addSHASumAnnotation: true
secrets.admin.enabled: true
@@ -75,7 +75,7 @@ tests:
path: spec.template.metadata.annotations["checksum/metrics"]
- it: omits the checksum annotation of a single disabled Secret only
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.addSHASumAnnotation: false
secrets.admin.enabled: true
@@ -112,7 +112,7 @@ tests:
path: spec.template.metadata.annotations["checksum/metrics"]
- it: adds the checksum of Secrets provided by the user
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.admin.enabled: true
secrets.admin.addSHASumAnnotation: true
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: Renders a deployment
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- hasDocuments:
count: 1
@@ -21,7 +21,7 @@ tests:
apiVersion: apps/v1
name: gitea-unittests
- it: Deployment with empty additionalConfigFromEnvs
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.additionalConfigFromEnvs: []
asserts:
@@ -49,7 +49,7 @@ tests:
- name: ENV_TO_INI_MOUNT_POINT
value: /env-to-ini-mounts
- it: Deployment with standard additionalConfigFromEnvs
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.additionalConfigFromEnvs: [{name: GITEA_database_HOST, value: my-db:123}, {name: GITEA_database_USER, value: my-user}]
asserts:
@@ -81,7 +81,7 @@ tests:
- name: GITEA_database_USER
value: my-user
- it: Deployment with templated additionalConfigFromEnvs
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.misc.host: my-db-host:321
gitea.misc.user: my-db-user
@@ -115,7 +115,7 @@ tests:
- name: GITEA_database_USER
value: my-db-user
- it: Deployment with additionalConfigFromEnvs templated secret name
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.misc.existingSecret: my-db-secret
gitea.additionalConfigFromEnvs[0]:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deprecation.yaml
- templates/deprecation.yaml
tests:
- it: renders nothing with the default values
asserts:
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: uses direct execution when extraEnvSourceFile is not set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.initContainers[1].command
@@ -26,7 +26,7 @@ tests:
path: spec.template.spec.initContainers[2].args
- it: sources env file in init-app-ini when extraEnvSourceFile is set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
extraEnvSourceFile: /vault/secrets/gitea
@@ -42,7 +42,7 @@ tests:
pattern: config_environment\.sh
- it: sources env file in configure-gitea when extraEnvSourceFile is set
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
extraEnvSourceFile: /vault/secrets/gitea
@@ -58,7 +58,7 @@ tests:
pattern: configure_gitea\.sh
- it: sources env file in configure-gpg when extraEnvSourceFile is set with signing enabled
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -77,7 +77,7 @@ tests:
pattern: configure_gpg_environment\.sh
- it: includes file existence check in source command
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
extraEnvSourceFile: /vault/secrets/gitea
@@ -3,23 +3,23 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: Render the deployment (default)
asserts:
- hasDocuments:
count: 1
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- lengthEqual:
path: spec.template.spec.initContainers
count: 3
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: Render the deployment (signing)
set:
@@ -29,11 +29,11 @@ tests:
asserts:
- hasDocuments:
count: 1
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- lengthEqual:
path: spec.template.spec.initContainers
count: 4
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: Render the deployment (extraInitContainers)
set:
@@ -54,22 +54,22 @@ tests:
asserts:
- hasDocuments:
count: 1
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- lengthEqual:
path: spec.template.spec.initContainers
count: 6
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- equal:
path: spec.template.spec.initContainers[0].name
value: bar
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- equal:
path: spec.template.spec.initContainers[5].name
value: foo
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
- it: renders the chart-managed init containers in the configured order
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- link: "initConfigureGitea"
@@ -83,7 +83,7 @@ tests:
value: init-directories
- it: fails when an init container entry sets both container and link
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- link: "initDirectories"
@@ -95,7 +95,7 @@ tests:
errorMessage: "deployment.initContainers[0]: `container` and `link` are mutually exclusive"
- it: fails when an init container entry sets neither container nor link
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- name: foo
@@ -104,7 +104,7 @@ tests:
errorMessage: "deployment.initContainers[0]: either `container` or `link` must be set"
- it: fails when an init container links to an unknown configuration
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initContainers:
- link: "initSomething"
@@ -6,22 +6,22 @@ chart:
# Override appVersion to be consistent with used digest :)
appVersion: 1.19.3
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: default values
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- equal:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3-rootless"
- it: tag override
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.tag: "1.19.4"
asserts:
@@ -29,7 +29,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.4-rootless"
- it: root-based image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: false
asserts:
@@ -37,7 +37,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3"
- it: scoped registry
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.registry: "example.com"
asserts:
@@ -45,7 +45,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "example.com/gitea:1.19.3-rootless"
- it: global registry
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
global.imageRegistry: "global.example.com"
asserts:
@@ -53,7 +53,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "global.example.com/gitea:1.19.3-rootless"
- it: digest for rootless image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment:
gitea:
@@ -65,7 +65,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3-rootless@sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
- it: image fullOverride (does not append rootless)
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment:
gitea:
@@ -82,7 +82,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3"
- it: digest for root-based image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment:
gitea:
@@ -94,7 +94,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.19.3@sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
- it: digest and global registry
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
global.imageRegistry: "global.example.com"
deployment.gitea.image.digest: "sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
@@ -103,7 +103,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "global.example.com/gitea:1.19.3-rootless@sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
- it: correctly renders floating tag references
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
# use non-quoted values on purpose. See: https://gitea.com/gitea/helm-gitea/issues/631
deployment.gitea.image.tag: 1.21
@@ -124,7 +124,7 @@ tests:
path: spec.template.spec.containers[0].image
value: "docker.gitea.com/gitea:1.21-rootless"
- it: init containers use their own image configuration
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initDirectories.image.registry: "init.example.com"
deployment.initDirectories.image.tag: "1.19.4"
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: appends the per-container env
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initDirectories.env:
- name: INIT_DIRECTORIES
@@ -38,7 +38,7 @@ tests:
value: "1"
- it: renders the per-container envFrom
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initAppIni.envFrom:
- secretRef:
@@ -53,7 +53,7 @@ tests:
name: special-secret
- it: appends the per-container volumeMounts
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initConfigureGitea.volumeMounts:
- name: my-configmap-volume
@@ -74,7 +74,7 @@ tests:
readOnly: true
- it: overrides the resources of a single init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.initDirectories.resources:
requests:
@@ -94,7 +94,7 @@ tests:
memory: 128Mi
- it: overrides the security context of a single init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.securityContext:
runAsUser: 1000
@@ -109,7 +109,7 @@ tests:
value: 1000
- it: renders the envFrom of the gitea container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.envFrom:
- configMapRef:
@@ -122,7 +122,7 @@ tests:
name: special-config
- it: omits envFrom when unset
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].envFrom
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_inlineConfig.yaml
- templates/secret_inlineConfig.yaml
tests:
- it: inline config stringData.server using TPL
set:
+11 -11
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: renders openshift-compatible defaults for chart-managed containers
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift.enabled: true
asserts:
@@ -62,7 +62,7 @@ tests:
type: RuntimeDefault
- it: does not force runAsUser 1000 for command init containers on OpenShift
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift.enabled: true
secrets.gpg.enabled: true
@@ -75,7 +75,7 @@ tests:
path: spec.template.spec.initContainers[3].securityContext.runAsUser
- it: preserves explicit pod and container security context overrides on OpenShift
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift:
enabled: true
@@ -103,7 +103,7 @@ tests:
value: 1000620000
- it: renders an explicit hostUsers=false override on OpenShift
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
openshift:
enabled: true
+17 -17
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: renders default liveness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].livenessProbe.enabled
@@ -27,7 +27,7 @@ tests:
port: http
timeoutSeconds: 1
- it: renders default readiness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].readinessProbe.enabled
@@ -42,12 +42,12 @@ tests:
port: http
timeoutSeconds: 1
- it: does not render a default startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notExists:
path: spec.template.spec.containers[0].startupProbe
- it: allows enabling a startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea.startupProbe.enabled: true
asserts:
@@ -65,7 +65,7 @@ tests:
timeoutSeconds: 1
- it: allows overwriting the default port of the liveness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
livenessProbe:
@@ -79,7 +79,7 @@ tests:
port: my-port
- it: allows overwriting the default port of the readiness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
readinessProbe:
@@ -93,7 +93,7 @@ tests:
port: my-port
- it: allows overwriting the default port of the startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
startupProbe:
@@ -108,7 +108,7 @@ tests:
port: my-port
- it: allows using a non-default method as liveness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
livenessProbe:
@@ -136,7 +136,7 @@ tests:
timeoutSeconds: 13372
- it: allows using a non-default method as readiness probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
readinessProbe:
@@ -164,7 +164,7 @@ tests:
timeoutSeconds: 13372
- it: allows using a non-default method as startup probe
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
gitea:
startupProbe:
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: supports adding a sidecar container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
extraContainers:
- name: sidecar-bob
+11 -11
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: skips gpg init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notContains:
path: spec.template.spec.initContainers
@@ -20,7 +20,7 @@ tests:
content:
name: configure-gpg
- it: skips gpg env in `init-directories` init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: false
asserts:
@@ -29,14 +29,14 @@ tests:
content:
name: GNUPGHOME
- it: skips gpg env in runtime container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notContains:
path: spec.template.spec.containers[0].env
content:
name: GNUPGHOME
- it: skips gpg volume spec
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
asserts:
- notContains:
path: spec.template.spec.volumes
+13 -13
View File
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: adds gpg init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -49,7 +49,7 @@ tests:
mountPath: /raw
readOnly: true
- it: adds gpg env in `init-directories` init container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -64,7 +64,7 @@ tests:
name: custom-gpg-secret
key: gpgHome
- it: adds gpg env in runtime container
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -79,7 +79,7 @@ tests:
name: custom-gpg-secret
key: gpgHome
- it: reads the gpg home from the configured key of an existing secret
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -95,7 +95,7 @@ tests:
name: custom-gpg-secret
key: custom-gpg-home
- it: adds gpg volume spec
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.new.privateKey: "gpg-key-placeholder"
@@ -111,7 +111,7 @@ tests:
path: private.asc
defaultMode: 0100
- it: supports gpg volume spec with external reference
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
secrets.gpg.enabled: true
secrets.gpg.existingSecret.enabled: true
@@ -3,16 +3,16 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
- templates/deployment.yaml
- templates/secret_admin.yaml
- templates/secret_config.yaml
- templates/secret_gpg.yaml
- templates/secret_init.yaml
- templates/secret_inlineConfig.yaml
- templates/secret_metrics.yaml
tests:
- it: supports defining SSH log level for root based image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: false
asserts:
@@ -22,7 +22,7 @@ tests:
name: SSH_LOG_LEVEL
value: "INFO"
- it: supports overriding SSH log level
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: false
gitea.ssh.logLevel: "DEBUG"
@@ -33,7 +33,7 @@ tests:
name: SSH_LOG_LEVEL
value: "DEBUG"
- it: supports overriding SSH log level (even when image.fullOverride set)
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.19.3
deployment.gitea.image.rootless: false
@@ -45,7 +45,7 @@ tests:
name: SSH_LOG_LEVEL
value: "DEBUG"
- it: skips SSH_LOG_LEVEL for rootless image
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.rootless: true
gitea.ssh.logLevel: "DEBUG" # explicitly defining a non-standard level here
@@ -56,7 +56,7 @@ tests:
content:
name: SSH_LOG_LEVEL
- it: skips SSH_LOG_LEVEL for rootless image (even when image.fullOverride set)
template: templates/gitea/deployment.yaml
template: templates/deployment.yaml
set:
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.19.3
deployment.gitea.image.rootless: true
@@ -1,39 +1,17 @@
# File: tests/gitea-storageclass-tests.yaml
suite: storage class configuration tests
chart:
appVersion: 1.27.3
release:
name: gitea-storageclass-tests
name: gitea-unittests
namespace: testing
suite: Storage class configuration tests
templates:
- templates/gitea/persistentVolumeClaim.yaml
- templates/persistentVolumeClaim.yaml
tests:
- it: should set storageClassName when persistence.storageClass is defined
template: templates/gitea/persistentVolumeClaim.yaml
- it: Set storageClassName when persistence.new.storageClassName is defined
set:
persistence.storageClass: "my-storage-class"
asserts:
- equal:
path: "spec.storageClassName"
value: "my-storage-class"
- it: should set global.storageClass when persistence.storageClass is not defined
template: templates/gitea/persistentVolumeClaim.yaml
set:
global.storageClass: "default-storage-class"
persistence.enabled: true
persistence.new.storageClassName: my-storage-class
asserts:
- equal:
path: spec.storageClassName
value: "default-storage-class"
- it: should set storageClassName when persistence.storageClass is defined and global.storageClass is defined
template: templates/gitea/persistentVolumeClaim.yaml
set:
global.storageClass: "default-storage-class"
persistence.storageClass: "my-storage-class"
asserts:
- equal:
path: spec.storageClassName
value: "my-storage-class"
value: my-storage-class
@@ -3,11 +3,11 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/service_ssh.yaml
- templates/gitea/service_http.yaml
- templates/service_ssh.yaml
- templates/service_http.yaml
tests:
- it: supports adding custom labels to sshService
template: templates/gitea/service_ssh.yaml
template: templates/service_ssh.yaml
set:
service:
ssh:
@@ -19,7 +19,7 @@ tests:
value: "testvalue"
- it: keeps existing labels (ssh)
template: templates/gitea/service_ssh.yaml
template: templates/service_ssh.yaml
set:
service:
ssh:
@@ -29,7 +29,7 @@ tests:
path: metadata.labels["app"]
- it: supports adding custom labels to httpService
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -41,7 +41,7 @@ tests:
value: "testvalue"
- it: keeps existing labels (http)
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -51,7 +51,7 @@ tests:
path: metadata.labels["app"]
- it: render service.ssh.loadBalancerClass if set and type is LoadBalancer
template: templates/gitea/service_ssh.yaml
template: templates/service_ssh.yaml
set:
service:
ssh:
@@ -73,7 +73,7 @@ tests:
value: ["1.2.3.4/32", "5.6.7.8/32"]
- it: does not render when loadbalancer properties are set but type is not loadBalancerClass
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -92,7 +92,7 @@ tests:
path: spec.loadBalancerSourceRanges
- it: does not render loadBalancerClass by default even when type is LoadBalancer
template: templates/gitea/service_http.yaml
template: templates/service_http.yaml
set:
service:
http:
@@ -107,8 +107,8 @@ tests:
- it: both ssh and http services exist
templates:
- templates/gitea/service_ssh.yaml
- templates/gitea/service_http.yaml
- templates/service_ssh.yaml
- templates/service_http.yaml
asserts:
- matchRegex:
path: metadata.name
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/backendTLSPolicy.yaml
- templates/backendTLSPolicy.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/clientSettingsPolicy.yaml
- templates/clientSettingsPolicy.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/httpRoute.yaml
- templates/httpRoute.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/tcpRoute.yaml
- templates/tcpRoute.yaml
tests:
- it: should not render when gatewayAPI.enabled is false
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_gpg.yaml
- templates/secret_gpg.yaml
tests:
- it: renders nothing
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_gpg.yaml
- templates/secret_gpg.yaml
tests:
- it: fails rendering when nothing is configured
set:
+14 -14
View File
@@ -1,11 +1,11 @@
suite: Test ingress.yaml
chart:
appVersion: 1.27.3
release:
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
suite: Test ingress.yaml
templates:
- templates/gitea/ingress.yaml
- templates/ingress.yaml
tests:
- it: Skip ingress if ingress is disabled
set:
@@ -41,15 +41,15 @@ tests:
- containsDocument:
kind: Ingress
apiVersion: networking.k8s.io/v1
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
- notExists:
path: metadata.annotations
- isSubset:
path: metadata.labels
content:
app: gitea
app.kubernetes.io/instance: gitea-unittest
app.kubernetes.io/instance: gitea-unittests
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: gitea
app.kubernetes.io/version: 1.27.3
@@ -66,7 +66,7 @@ tests:
paths:
- backend:
service:
name: gitea-unittest-http
name: gitea-unittests-http
port:
number: 3000
path: /
@@ -101,8 +101,8 @@ tests:
- containsDocument:
kind: Ingress
apiVersion: networking.k8s.io/v1
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
- contains:
path: spec.rules
content:
@@ -111,7 +111,7 @@ tests:
paths:
- backend:
service:
name: gitea-unittest-http
name: gitea-unittests-http
port:
number: 32000
path: /
@@ -131,8 +131,8 @@ tests:
- containsDocument:
kind: Ingress
apiVersion: networking.k8s.io/v1
name: gitea-unittest
namespace: gitea-debug
name: gitea-unittests
namespace: testing
- isSubset:
path: metadata.annotations
content:
@@ -140,4 +140,4 @@ tests:
- isSubset:
path: metadata.labels
content:
custom-label: custom-value
custom-label: custom-value
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_init.yaml
- templates/secret_init.yaml
tests:
- it: renders a secret
asserts:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_init.yaml
- templates/secret_init.yaml
tests:
- it: runs gpg in batch mode
set:
@@ -63,7 +63,7 @@ tests:
chown -v 1000:1000 "${GNUPGHOME}"
fi
- it: it does not chown /data even when image.fullOverride is set
template: templates/gitea/secret_init.yaml
template: templates/secret_init.yaml
set:
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.20.5
asserts:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_init.yaml
- templates/secret_init.yaml
tests:
- it: runs gpg in batch mode
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_metrics.yaml
- templates/secret_metrics.yaml
tests:
- it: renders nothing if monitoring disabled and gitea.metrics.token empty
set:
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/secret_metrics.yaml
- templates/secret_metrics.yaml
tests:
- it: renders nothing if monitoring enabled and gitea.metrics.token empty
set:
@@ -0,0 +1,29 @@
chart:
appVersion: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
release:
name: gitea-unittests
namespace: testing
suite: PVC template
templates:
- templates/persistentVolumeClaim.yaml
tests:
- it: Skip persistentVolumeClaim if persistentVolumeClaim is disabled
set:
persistence.enabled: false
asserts:
- hasDocuments:
count: 0
- it: Render persistentVolumeClaim with default values
set:
persistence.enabled: true
persistence.new.storageClassName: "my-storage-class"
asserts:
- containsDocument:
apiVersion: v1
kind: PersistentVolumeClaim
name: gitea-unittests
namespace: testing
- equal:
path: spec.storageClassName
value: "my-storage-class"
-19
View File
@@ -1,19 +0,0 @@
suite: PVC template
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/persistentVolumeClaim.yaml
tests:
- it: Storage Class using TPL
set:
global.persistence.storageClass: "storage-class"
persistence.enabled: true
persistence.create: true
persistence.storageClass: "{{ .Values.global.persistence.storageClass }}"
asserts:
- isKind:
of: PersistentVolumeClaim
- equal:
path: spec.storageClassName
value: "storage-class"
+1 -1
View File
@@ -3,7 +3,7 @@ release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/route.yaml
- templates/route.yaml
tests:
- it: should create route when route.enabled is true
set:
@@ -0,0 +1,102 @@
chart:
appVersion: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
release:
name: gitea-unittests
namespace: testing
suite: ServiceAccount template
templates:
- templates/serviceAccount.yaml
tests:
- it: Render the ServiceAccount by default
asserts:
- hasDocuments:
count: 1
- containsDocument:
kind: ServiceAccount
apiVersion: v1
name: gitea-unittests
namespace: testing
- notExists:
path: metadata.annotations
- equal:
path: metadata.labels
value:
app: gitea
app.kubernetes.io/instance: gitea-unittests
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: gitea
app.kubernetes.io/version: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
helm.sh/chart: gitea-0.0.0
version: 1.27.3 # renovate: datasource=docker registryUrl=https://docker.gitea.com depName=gitea
- equal:
path: automountServiceAccountToken
value: false
- notExists:
path: imagePullSecrets
- it: Skip rendering when serviceAccount.enabled is false
set:
serviceAccount:
enabled: false
asserts:
- hasDocuments:
count: 0
- it: Skip rendering when an existing ServiceAccount is used
set:
serviceAccount:
existingServiceAccount:
enabled: true
existingServiceAccountName: externally-existing-serviceaccount
asserts:
- hasDocuments:
count: 0
- it: Add custom labels when serviceAccount.new.labels is defined
set:
serviceAccount:
new:
labels:
custom: label
asserts:
- equal:
path: metadata.labels.custom
value: label
- it: Add custom annotations when serviceAccount.new.annotations is defined
set:
serviceAccount:
new:
annotations:
myCustom: annotation
asserts:
- equal:
path: metadata.annotations.myCustom
value: annotation
- it: Mount the token when serviceAccount.new.automountServiceAccountToken is true
set:
serviceAccount:
new:
automountServiceAccountToken: true
asserts:
- equal:
path: automountServiceAccountToken
value: true
- it: Reference image pull secrets when serviceAccount.new.imagePullSecrets is defined
set:
serviceAccount:
new:
imagePullSecrets:
- name: testing-image-pull-secret
- name: another-pull-secret
asserts:
- contains:
path: imagePullSecrets
content:
name: testing-image-pull-secret
- contains:
path: imagePullSecrets
content:
name: another-pull-secret
-82
View File
@@ -1,82 +0,0 @@
suite: ServiceAccount template (basic)
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceAccount.yaml
tests:
- it: skips rendering by default
asserts:
- hasDocuments:
count: 0
- it: renders default ServiceAccount object with serviceAccount.create=true
set:
serviceAccount.create: true
asserts:
- hasDocuments:
count: 1
- containsDocument:
kind: ServiceAccount
apiVersion: v1
name: gitea-unittests
- equal:
path: automountServiceAccountToken
value: false
- notExists:
path: imagePullSecrets
- notExists:
path: metadata.annotations
- it: allows for adding custom labels
set:
serviceAccount:
create: true
labels:
custom: label
asserts:
- equal:
path: metadata.labels.custom
value: label
- it: allows for adding custom annotations
set:
serviceAccount:
create: true
annotations:
myCustom: annotation
asserts:
- equal:
path: metadata.annotations.myCustom
value: annotation
- it: allows to override the generated name
set:
serviceAccount:
create: true
name: provided-serviceaccount-name
asserts:
- equal:
path: metadata.name
value: provided-serviceaccount-name
- it: allows to mount the token
set:
serviceAccount:
create: true
automountServiceAccountToken: true
asserts:
- equal:
path: automountServiceAccountToken
value: true
- it: allows to reference image pull secrets
set:
serviceAccount:
create: true
imagePullSecrets:
- name: testing-image-pull-secret
- name: another-pull-secret
asserts:
- contains:
path: imagePullSecrets
content:
name: testing-image-pull-secret
- contains:
path: imagePullSecrets
content:
name: another-pull-secret
@@ -1,37 +0,0 @@
suite: ServiceAccount template (reference)
release:
name: gitea-unittests
namespace: testing
templates:
- templates/gitea/serviceAccount.yaml
- templates/gitea/deployment.yaml
- templates/gitea/secret_admin.yaml
- templates/gitea/secret_config.yaml
- templates/gitea/secret_gpg.yaml
- templates/gitea/secret_init.yaml
- templates/gitea/secret_inlineConfig.yaml
- templates/gitea/secret_metrics.yaml
tests:
- it: does not modify the deployment by default
template: templates/gitea/deployment.yaml
asserts:
- notExists:
path: spec.serviceAccountName
- it: adds the reference to the deployment with serviceAccount.create=true
template: templates/gitea/deployment.yaml
set:
serviceAccount.create: true
asserts:
- equal:
path: spec.template.spec.serviceAccountName
value: gitea-unittests
- it: allows referencing an externally created ServiceAccount to the deployment
template: templates/gitea/deployment.yaml
set:
serviceAccount:
create: false # explicitly set to define rendering behavior
name: "externally-existing-serviceaccount"
asserts:
- equal:
path: spec.template.spec.serviceAccountName
value: externally-existing-serviceaccount

Some files were not shown because too many files have changed in this diff Show More