Compare commits
111
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e17a4e7a7b
|
||
|
|
41dcb48564
|
||
|
|
6deb39df15
|
||
|
|
cc99cada4d
|
||
|
|
e8f3a058ce
|
||
|
|
c409e201b3
|
||
|
|
ab24bcd9a5
|
||
|
|
00ccfc6734
|
||
|
|
377306b418
|
||
|
|
3c9fc19829
|
||
|
|
f385d22b56
|
||
|
|
34dd14e3d8
|
||
|
|
efd6536c1a
|
||
|
|
80592de2d0
|
||
|
|
56119038ec
|
||
|
|
9e12eeccab
|
||
|
|
20de800294
|
||
|
|
25b3fff3eb
|
||
|
|
9fb628f7db
|
||
|
|
55964679ea
|
||
|
|
150c08eabc
|
||
|
|
229ba12744
|
||
|
|
3535611d4d
|
||
|
|
4d82f17ce6
|
||
|
|
a4c6893874
|
||
|
|
4884dc0fe0
|
||
|
|
bebe2a6009
|
||
|
|
ab86f7b408 | ||
|
|
11c2b41451
|
||
|
|
f8124aa603
|
||
|
|
aa0538450c | ||
|
|
42a8af41e0 | ||
|
|
2c7ae63070 | ||
|
|
b01db983ab | ||
|
|
311cb9fe37
|
||
|
|
407a7027bc | ||
|
|
fbf1f4a62d
|
||
|
|
4f4bd4927c
|
||
|
|
0d6085f68d
|
||
|
|
7d9bf145b2
|
||
|
|
4f4db6858b
|
||
|
|
01a34e129c
|
||
|
|
60017bfc9e
|
||
|
|
8f85cf5ea4
|
||
|
|
cf84d7d79f
|
||
|
|
475df2f4a5
|
||
|
|
efb67b1f98
|
||
|
|
580c3be51f | ||
|
|
7747a001f7 | ||
|
|
5005037dbf | ||
|
|
61d6d23e8a | ||
|
|
b6ded8da2b | ||
|
|
e97e59263e | ||
|
|
78276bc037 | ||
|
|
26910244e6 | ||
|
|
8198a89a16 | ||
|
|
323b6bc863 | ||
|
|
84988194ad | ||
|
|
44d77838e8 | ||
|
|
7de27dead8 | ||
|
|
1baf2d0656 | ||
|
|
905552ec2d | ||
|
|
f4f358f7c4 | ||
|
|
b34a2a1c5e | ||
|
|
cd77a3ea0d | ||
|
|
682cfec590 | ||
|
|
c4f9f8a098 | ||
|
|
b7663bb95f | ||
|
|
a02a7feb6e | ||
|
|
e725a53e1c | ||
|
|
0fb15a6421 | ||
|
|
935b517ecd | ||
|
|
fd1f64ec1e | ||
|
|
1914cfd6b9 | ||
|
|
e8dff81392 | ||
|
|
4036f02c19 | ||
|
|
59c510fc0e | ||
|
|
5e4de283d7 | ||
|
|
794aa4f96c | ||
|
|
675a66a12d | ||
|
|
27c334d4dc | ||
|
|
8d7ecd02e9 | ||
|
|
92015afb10 | ||
|
|
8b1cac117a | ||
|
|
717bfb61da | ||
|
|
8034f75fa1 | ||
|
|
9601822aff | ||
|
|
0e2d0a0229 | ||
|
|
e673346bb8 | ||
|
|
be3c6f232a | ||
|
|
fd558004df | ||
|
|
9f50a4d8e6 | ||
|
|
9c54a7141d | ||
|
|
94dc4cb959 | ||
|
|
e37b9bf7b5 | ||
|
|
94f2b8e26d | ||
|
|
d51e459d35 | ||
|
|
ffdb192c59 | ||
|
|
d537d5d9ec | ||
|
|
02e181b659 | ||
|
|
30dbe405cb | ||
|
|
0eed2385cc | ||
|
|
d8265c8bd5 | ||
|
|
6af304e270 | ||
|
|
9e5e86aa8e | ||
|
|
44c279c4cd | ||
|
|
458605ddb6 | ||
|
|
70653c83e6 | ||
|
|
c02a65fc82 | ||
|
|
f6cc35f2a8 | ||
|
|
7e58847b23 |
@@ -1,114 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
CHART_FILE="Chart.yaml"
|
||||
if [ ! -f "${CHART_FILE}" ]; then
|
||||
echo "ERROR: ${CHART_FILE} not found!" 1>&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
DEFAULT_NEW_TAG="$(git tag --sort=-version:refname | head -n 1)"
|
||||
DEFAULT_OLD_TAG="$(git tag --sort=-version:refname | head -n 2 | tail -n 1)"
|
||||
|
||||
if [ -z "${1}" ]; then
|
||||
read -p "Enter start tag [${DEFAULT_OLD_TAG}]: " OLD_TAG
|
||||
if [ -z "${OLD_TAG}" ]; then
|
||||
OLD_TAG="${DEFAULT_OLD_TAG}"
|
||||
fi
|
||||
|
||||
while [ -z "$(git tag --list "${OLD_TAG}")" ]; do
|
||||
echo "ERROR: Tag '${OLD_TAG}' not found!" 1>&2
|
||||
read -p "Enter start tag [${DEFAULT_OLD_TAG}]: " OLD_TAG
|
||||
if [ -z "${OLD_TAG}" ]; then
|
||||
OLD_TAG="${DEFAULT_OLD_TAG}"
|
||||
fi
|
||||
done
|
||||
else
|
||||
OLD_TAG=${1}
|
||||
if [ -z "$(git tag --list "${OLD_TAG}")" ]; then
|
||||
echo "ERROR: Tag '${OLD_TAG}' not found!" 1>&2
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ -z "${2}" ]; then
|
||||
read -p "Enter end tag [${DEFAULT_NEW_TAG}]: " NEW_TAG
|
||||
if [ -z "${NEW_TAG}" ]; then
|
||||
NEW_TAG="${DEFAULT_NEW_TAG}"
|
||||
fi
|
||||
|
||||
while [ -z "$(git tag --list "${NEW_TAG}")" ]; do
|
||||
echo "ERROR: Tag '${NEW_TAG}' not found!" 1>&2
|
||||
read -p "Enter end tag [${DEFAULT_NEW_TAG}]: " NEW_TAG
|
||||
if [ -z "${NEW_TAG}" ]; then
|
||||
NEW_TAG="${DEFAULT_NEW_TAG}"
|
||||
fi
|
||||
done
|
||||
else
|
||||
NEW_TAG=${2}
|
||||
|
||||
if [ -z "$(git tag --list "${NEW_TAG}")" ]; then
|
||||
echo "ERROR: Tag '${NEW_TAG}' not found!" 1>&2
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
CHANGE_LOG_YAML=$(mktemp)
|
||||
echo "[]" > "${CHANGE_LOG_YAML}"
|
||||
|
||||
function map_type_to_kind() {
|
||||
case "${1}" in
|
||||
feat)
|
||||
echo "added"
|
||||
;;
|
||||
fix)
|
||||
echo "fixed"
|
||||
;;
|
||||
chore|style|test|ci|docs|refac)
|
||||
echo "changed"
|
||||
;;
|
||||
revert)
|
||||
echo "removed"
|
||||
;;
|
||||
sec)
|
||||
echo "security"
|
||||
;;
|
||||
*)
|
||||
echo "skip"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
COMMIT_TITLES="$(git log --pretty=format:"%s" "${OLD_TAG}..${NEW_TAG}")"
|
||||
|
||||
echo "INFO: Generate change log entries from ${OLD_TAG} until ${NEW_TAG}"
|
||||
|
||||
while IFS= read -r line; do
|
||||
if [[ "${line}" =~ ^([a-zA-Z]+)(\([^\)]+\))?\:\ (.+)$ ]]; then
|
||||
TYPE="${BASH_REMATCH[1]}"
|
||||
KIND=$(map_type_to_kind "${TYPE}")
|
||||
|
||||
if [ "${KIND}" == "skip" ]; then
|
||||
continue
|
||||
fi
|
||||
|
||||
DESC="${BASH_REMATCH[3]}"
|
||||
|
||||
echo "- ${KIND}: ${DESC}"
|
||||
|
||||
jq --arg kind "${KIND}" --arg description "${DESC}" '. += [ $ARGS.named ]' < "${CHANGE_LOG_YAML}" > "${CHANGE_LOG_YAML}.new"
|
||||
mv "${CHANGE_LOG_YAML}.new" "${CHANGE_LOG_YAML}"
|
||||
|
||||
fi
|
||||
done <<< "${COMMIT_TITLES}"
|
||||
|
||||
if [ -s "${CHANGE_LOG_YAML}" ]; then
|
||||
yq --inplace --input-format json --output-format yml "${CHANGE_LOG_YAML}"
|
||||
yq --no-colors --inplace ".annotations.\"artifacthub.io/changes\" |= loadstr(\"${CHANGE_LOG_YAML}\") | sort_keys(.)" "${CHART_FILE}"
|
||||
else
|
||||
echo "ERROR: Changelog file is empty: ${CHANGE_LOG_YAML}" 1>&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
rm "${CHANGE_LOG_YAML}"
|
||||
@@ -8,12 +8,12 @@ on:
|
||||
jobs:
|
||||
changelog:
|
||||
runs-on: ubuntu-latest
|
||||
container: docker.io/thegeeklab/git-sv:2.0.11
|
||||
container: docker.io/thegeeklab/git-sv:2.1.3
|
||||
steps:
|
||||
- name: install tools
|
||||
run: |
|
||||
apk add -q --update --no-cache nodejs curl jq sed
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Generate upcoming changelog
|
||||
|
||||
@@ -11,9 +11,9 @@ on:
|
||||
jobs:
|
||||
check-and-test:
|
||||
runs-on: ubuntu-latest
|
||||
container: commitlint/commitlint:20.5.1
|
||||
container: docker.io/commitlint/commitlint:21.2.1
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7.0.0
|
||||
- name: check PR title
|
||||
run: |
|
||||
echo "${{ gitea.event.pull_request.title }}" | commitlint --config .commitlintrc.json
|
||||
|
||||
@@ -9,7 +9,7 @@ jobs:
|
||||
generate-chart-publish:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
@@ -21,22 +21,13 @@ jobs:
|
||||
- name: Install helm
|
||||
env:
|
||||
# renovate: datasource=docker depName=alpine/helm
|
||||
HELM_VERSION: "3.20.2"
|
||||
HELM_VERSION: "3.21.3"
|
||||
run: |
|
||||
curl --fail --location --output /dev/stdout --silent --show-error https://get.helm.sh/helm-v${HELM_VERSION}-linux-$(dpkg --print-architecture).tar.gz | tar --extract --gzip --file /dev/stdin
|
||||
mv linux-$(dpkg --print-architecture)/helm /usr/local/bin/
|
||||
rm --force --recursive linux-$(dpkg --print-architecture) helm-v${HELM_VERSION}-linux-$(dpkg --print-architecture).tar.gz
|
||||
helm version
|
||||
|
||||
- name: Install yq
|
||||
env:
|
||||
YQ_VERSION: v4.45.4 # renovate: datasource=github-releases depName=mikefarah/yq
|
||||
run: |
|
||||
curl --fail --location --output /dev/stdout --silent --show-error https://github.com/mikefarah/yq/releases/download/${YQ_VERSION}/yq_linux_$(dpkg --print-architecture).tar.gz | tar --extract --gzip --file /dev/stdin
|
||||
mv yq_linux_$(dpkg --print-architecture) /usr/local/bin
|
||||
rm --force --recursive yq_linux_$(dpkg --print-architecture) yq_linux_$(dpkg --print-architecture).tar.gz
|
||||
yq --version
|
||||
|
||||
- name: Install docker-ce via apt
|
||||
run: |
|
||||
install -m 0755 -d /etc/apt/keyrings
|
||||
@@ -53,20 +44,14 @@ jobs:
|
||||
|
||||
- name: Import GPG key
|
||||
id: import_gpg
|
||||
uses: https://github.com/crazy-max/ghaction-import-gpg@v6
|
||||
uses: https://github.com/crazy-max/ghaction-import-gpg@v7
|
||||
with:
|
||||
gpg_private_key: ${{ secrets.GPGSIGN_KEY }}
|
||||
passphrase: ${{ secrets.GPGSIGN_PASSPHRASE }}
|
||||
fingerprint: CC64B1DB67ABBEECAB24B6455FC346329753F4B0
|
||||
|
||||
- name: Add Artifacthub.io annotations
|
||||
run: |
|
||||
NEW_TAG="$(git tag --sort=-version:refname | head --lines 1)"
|
||||
OLD_TAG="$(git tag --sort=-version:refname | head --lines 2 | tail --lines 1)"
|
||||
.gitea/scripts/add-annotations.sh "${OLD_TAG}" "${NEW_TAG}"
|
||||
|
||||
- name: Print Chart.yaml
|
||||
run: cat Chart.yaml
|
||||
uses: volker-raschek/ah-annotations@v0.2.0
|
||||
|
||||
# Using helm gpg plugin as 'helm package --sign' has issues with gpg2: https://github.com/helm/helm/issues/2843
|
||||
- name: package chart
|
||||
@@ -85,26 +70,25 @@ jobs:
|
||||
helm push gitea/gitea-${GITHUB_REF#refs/tags/v}.tgz oci://registry-1.docker.io/giteacharts
|
||||
helm registry logout registry-1.docker.io
|
||||
|
||||
- name: aws credential configure
|
||||
uses: https://github.com/aws-actions/configure-aws-credentials@v5
|
||||
with:
|
||||
aws-access-key-id: ${{ secrets.AWS_KEY_ID }}
|
||||
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
|
||||
aws-region: ${{ secrets.AWS_REGION }}
|
||||
|
||||
- name: Copy files to S3 and clear cache
|
||||
- name: Copy files to Cloudflare R2
|
||||
env:
|
||||
AWS_ACCESS_KEY_ID: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }}
|
||||
AWS_SECRET_ACCESS_KEY: ${{ secrets.CLOUDFLARE_R2_SECRET_ACCESS_KEY }}
|
||||
AWS_DEFAULT_REGION: auto
|
||||
CLOUDFLARE_R2_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_R2_ACCOUNT_ID }}
|
||||
CLOUDFLARE_R2_BUCKET: ${{ secrets.CLOUDFLARE_R2_BUCKET }}
|
||||
run: |
|
||||
aws s3 sync gitea/ s3://${{ secrets.AWS_S3_BUCKET}}/charts/
|
||||
aws s3 sync gitea/ s3://${CLOUDFLARE_R2_BUCKET}/charts/ --endpoint-url https://${CLOUDFLARE_R2_ACCOUNT_ID}.r2.cloudflarestorage.com
|
||||
|
||||
release-gitea:
|
||||
needs: generate-chart-publish
|
||||
runs-on: ubuntu-latest
|
||||
container: docker.io/thegeeklab/git-sv:2.0.11
|
||||
container: docker.io/thegeeklab/git-sv:2.1.3
|
||||
steps:
|
||||
- name: install tools
|
||||
run: |
|
||||
apk add -q --update --no-cache nodejs
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7.0.0
|
||||
with:
|
||||
fetch-tags: true
|
||||
fetch-depth: 0
|
||||
|
||||
@@ -10,27 +10,32 @@ on:
|
||||
|
||||
env:
|
||||
# renovate: datasource=github-releases depName=helm-unittest/helm-unittest
|
||||
HELM_UNITTEST_VERSION: "v1.0.3"
|
||||
HELM_UNITTEST_VERSION: "v1.1.1"
|
||||
|
||||
jobs:
|
||||
check-and-test:
|
||||
runs-on: ubuntu-latest
|
||||
container: alpine/helm:3.20.2
|
||||
container: docker.io/alpine/helm:4.2.3
|
||||
steps:
|
||||
- name: install tools
|
||||
run: |
|
||||
apk update
|
||||
apk add --update bash make nodejs npm yamllint ncurses
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v7.0.0
|
||||
- name: define helm repositories
|
||||
run: |
|
||||
helm repo add bitnami https://charts.bitnami.com/bitnami
|
||||
helm repo add valkey https://valkey.io/valkey-helm
|
||||
helm repo update
|
||||
- name: install chart dependencies
|
||||
run: helm dependency build
|
||||
- name: lint
|
||||
run: helm lint
|
||||
run: helm lint .
|
||||
- name: template
|
||||
run: helm template --debug gitea-helm .
|
||||
- name: prepare unit test environment
|
||||
run: |
|
||||
helm plugin install --version ${{ env.HELM_UNITTEST_VERSION }} https://github.com/helm-unittest/helm-unittest
|
||||
helm plugin install --verify=false --version ${{ env.HELM_UNITTEST_VERSION }} https://github.com/helm-unittest/helm-unittest
|
||||
git submodule update --init --recursive
|
||||
- name: unit tests
|
||||
env:
|
||||
|
||||
@@ -0,0 +1,65 @@
|
||||
# Gitea Helm Chart — Copilot Instructions
|
||||
|
||||
## Project Overview
|
||||
|
||||
Kubernetes Helm chart for deploying [Gitea](https://gitea.com). Uses Go/Helm templating (`templates/`), YAML values (`values.yaml`), and includes sub-charts for PostgreSQL, PostgreSQL-HA, Valkey, and Valkey-cluster.
|
||||
|
||||
## Build & Test
|
||||
|
||||
```bash
|
||||
make readme # Regenerate README.md parameter table + lint
|
||||
make unittests-helm # Run Helm unit tests (helm-unittest plugin required)
|
||||
make unittests-bash # Run bash/bats script tests (requires git submodule init)
|
||||
make unittests # Both of the above
|
||||
```
|
||||
|
||||
Always run `make readme` after changing `values.yaml` `@param` annotations.
|
||||
Always run `make unittests-helm` after changing templates or unit tests.
|
||||
|
||||
## Conventions
|
||||
|
||||
### values.yaml
|
||||
|
||||
- Use `## @param path.to.key Description` annotations for every user-facing value. These drive the auto-generated README parameter table.
|
||||
- Property ordering within a resource block: `enabled`, `annotations`, `labels` first, then type-specific fields.
|
||||
- Top-level keys are sorted alphabetically within their section group.
|
||||
- Use [Helm Values](https://docs.renovatebot.com/modules/manager/helm-values/#additional-information) pattern from renovatebot. Ensure that the attributes `registry`, `repository` and `tag` are available as part of the dict `image`. For example:
|
||||
|
||||
```yaml
|
||||
image:
|
||||
registry: docker.io
|
||||
repository: library/busybox
|
||||
tag: 0.1.0
|
||||
```
|
||||
|
||||
### Templates
|
||||
|
||||
- Helm templates live in `templates/gitea/`. Helpers live in `templates/_helpers.tpl`.
|
||||
- Use camelCase for all files and variables (e.g `httpRoute`, `backendTLSPolicy`, `gatewayAPI`, `statefulSet`).
|
||||
- Use `include "gitea.fullname"` for naming resources.
|
||||
- Use `fail` for required-value validation with clear error messages referencing the full values path.
|
||||
- Ensure, that the attributes `annotations`, `labels`, `name` and `namespace` are alphabetically sorted.
|
||||
- Render all attributes, even if they are empty, to prevent drift in Argo CD. For example, `labels` must be rendered, while `annotations` are defined as `yaml:"annotations,omitempty"`.
|
||||
- Use plural for `*.tpl` files, because they may contain functions for multiple resources of the same kind (e.g. `_services.tpl` for `httpService.yaml` or `sshService.yaml`, `_backendTLSPolicies.tpl` for `backendTLSPolicy.yaml`).
|
||||
- Use as prefix of YAML files the resource kind (e.g., `deployment.yaml` for `Deployment` resources). If there are multiple resources of the same kind, use a descriptive suffix (e.g., `deployment_metrics.yaml` for a `Deployment` related to metrics).
|
||||
|
||||
### Unit Tests
|
||||
|
||||
- Helm unit tests live in `unittests/helm/` mirroring the template structure.
|
||||
- Test files are YAML using the [helm-unittest](https://github.com/helm-unittest/helm-unittest) format.
|
||||
- Each test must set all required values explicitly — do not rely on cross-test state.
|
||||
- The `values.yaml` file must pass `yamllint`. The configuration is in `.yamllint`. Use `make yamllint` to run the linter.
|
||||
- The title of the unit test should clearly describe the scenario being tested. As title must be use a short sentence starting with a capital letter and ending without a period.
|
||||
- Each unit test must explicitly set a custom namespace and release name, rather than relying on defaults.
|
||||
|
||||
### Commits & PRs
|
||||
|
||||
- Follow [Conventional Commits](https://www.conventionalcommits.org/en/v1.0.0/) for PR titles and commit messages (e.g. `feat:`, `fix:`, `refactor:`, `docs:`, `style:`).
|
||||
- See `CONTRIBUTING.md` for full PR requirements.
|
||||
- Explain in detail why a change is needed, not just what the change is. Include links to relevant issues, PRs, or external references.
|
||||
- Add co-authors for any contributions that are not your own. Use the `Co-authored-by:` trailer in the commit message.
|
||||
|
||||
### Documentation
|
||||
|
||||
- `docs/` contains topic-specific guides (e.g. `gateway-api.md`, `ha-setup.md`).
|
||||
- `README.md` parameter tables are auto-generated — never edit them manually.
|
||||
Vendored
+5
-1
@@ -1,7 +1,11 @@
|
||||
{
|
||||
"yaml.schemas": {
|
||||
"https://raw.githubusercontent.com/helm-unittest/helm-unittest/v1.0.3/schema/helm-testsuite.json": [
|
||||
"https://raw.githubusercontent.com/helm-unittest/helm-unittest/v1.1.1/schema/helm-testsuite.json": [
|
||||
"/unittests/**/*.yaml"
|
||||
],
|
||||
"https://docs.renovatebot.com/renovate-schema.json":[
|
||||
"renovate.json",
|
||||
"renovate.json5"
|
||||
]
|
||||
},
|
||||
"yaml.schemaStore.enable": true,
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
* @rossigee @volker.raschek @ChristopherHX
|
||||
* @volker.raschek @ChristopherHX
|
||||
|
||||
+4
-7
@@ -5,11 +5,8 @@ dependencies:
|
||||
- name: postgresql-ha
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 16.3.2
|
||||
- name: valkey-cluster
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 3.0.24
|
||||
- name: valkey
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 3.0.31
|
||||
digest: sha256:ceb6a1890cfdc2627abb85d3e2a4baa64d30afd21dcfabce978a824a67f0a2bb
|
||||
generated: "2025-08-30T00:03:04.59764502Z"
|
||||
repository: https://valkey.io/valkey-helm
|
||||
version: 0.10.0
|
||||
digest: sha256:1afecbf0d4fc9f48e31417573d4bed7e0ac7848040b9e0c5f3989ada9d1f944f
|
||||
generated: "2026-07-20T19:52:11.548874634+02:00"
|
||||
|
||||
+3
-12
@@ -3,8 +3,7 @@ name: gitea
|
||||
description: Gitea Helm chart for Kubernetes
|
||||
type: application
|
||||
version: 0.0.0
|
||||
# renovate datasource=github-releases depName=go-gitea/gitea extractVersion=^v(?<version>.*)$
|
||||
appVersion: 1.26.0
|
||||
appVersion: 1.27.3
|
||||
icon: https://gitea.com/assets/img/logo.svg
|
||||
|
||||
annotations:
|
||||
@@ -26,9 +25,6 @@ sources:
|
||||
- https://docker.gitea.com/gitea
|
||||
|
||||
maintainers:
|
||||
# https://gitea.com/rossigee
|
||||
- name: Ross Golder
|
||||
email: ross@golder.org
|
||||
# https://gitea.com/volker.raschek
|
||||
- name: Markus Pesch
|
||||
email: markus.pesch+apps@cryptic.systems
|
||||
@@ -50,13 +46,8 @@ dependencies:
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 16.3.2
|
||||
condition: postgresql-ha.enabled
|
||||
# https://github.com/bitnami/charts/blob/main/bitnami/valkey-cluster/Chart.yaml
|
||||
- name: valkey-cluster
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 3.0.24
|
||||
condition: valkey-cluster.enabled
|
||||
# https://github.com/bitnami/charts/blob/main/bitnami/valkey/Chart.yaml
|
||||
- name: valkey
|
||||
repository: oci://registry-1.docker.io/bitnamicharts
|
||||
version: 3.0.31
|
||||
repository: https://valkey.io/valkey-helm
|
||||
version: 0.10.0
|
||||
condition: valkey.enabled
|
||||
|
||||
@@ -38,21 +38,22 @@
|
||||
- [Renovate](#renovate)
|
||||
- [Parameters](#parameters)
|
||||
- [Global](#global)
|
||||
- [strategy](#strategy)
|
||||
- [deployment](#deployment)
|
||||
- [Gateway API](#gateway-api)
|
||||
- [Ingress](#ingress)
|
||||
- [Network](#network)
|
||||
- [Image](#image)
|
||||
- [Security](#security)
|
||||
- [Route](#route)
|
||||
- [Secrets](#secrets)
|
||||
- [Service](#service)
|
||||
- [Ingress](#ingress)
|
||||
- [deployment](#deployment)
|
||||
- [ServiceAccount](#serviceaccount)
|
||||
- [Persistence](#persistence-1)
|
||||
- [Init](#init)
|
||||
- [Signing](#signing)
|
||||
- [Gitea](#gitea)
|
||||
- [LivenessProbe](#livenessprobe)
|
||||
- [ReadinessProbe](#readinessprobe)
|
||||
- [StartupProbe](#startupprobe)
|
||||
- [valkey-cluster](#valkey-cluster)
|
||||
- [valkey](#valkey)
|
||||
- [PostgreSQL HA](#postgresql-ha)
|
||||
- [PostgreSQL](#postgresql)
|
||||
@@ -79,7 +80,7 @@ There might be times when the chart is behind the latest Gitea release.
|
||||
This might be caused by different reasons, most often due to time constraints of the maintainers (remember, all work here is done voluntarily in the spare time of people).
|
||||
If you're eager to use the latest Gitea version earlier than this chart catches up, then change the tag in `values.yaml` to the latest Gitea version.
|
||||
Note that besides the exact Gitea version one can also use the `:1` tag to automatically follow the latest Gitea version.
|
||||
This should be combined with `image.pullPolicy: "Always"`.
|
||||
This should be combined with `deployment.gitea.image.pullPolicy: "Always"`.
|
||||
Important: Using the `:1` will also automatically jump to new minor release (e.g. from 1.13 to 1.14) which may eventually cause incompatibilities if major/breaking changes happened between these versions.
|
||||
This is due to Gitea not strictly following [semantic versioning](https://semver.org/#summary) as breaking changes do not increase the major version.
|
||||
I.e., "minor" version bumps are considered "major".
|
||||
@@ -96,14 +97,13 @@ Users can also configure their own external providers via the configuration.
|
||||
These dependencies are enabled by default:
|
||||
|
||||
- PostgreSQL HA ([Bitnami PostgreSQL-HA](https://github.com/bitnami/charts/blob/main/bitnami/postgresql-ha/Chart.yaml))
|
||||
- Valkey-Cluster ([Bitnami Valkey-Cluster](https://github.com/bitnami/charts/blob/main/bitnami/valkey-cluster/Chart.yaml))
|
||||
- Valkey ([Official Valkey Helm Chart](https://github.com/valkey-io/valkey-helm))
|
||||
|
||||
### Non-HA Dependencies
|
||||
|
||||
Alternatively, the following non-HA replacements are available:
|
||||
|
||||
- PostgreSQL ([Bitnami PostgreSQL](https://github.com/bitnami/charts/blob/main/bitnami/postgresql/Chart.yaml))
|
||||
- Valkey ([Bitnami Valkey](https://github.com/bitnami/charts/blob/main/bitnami/valkey/Chart.yaml))
|
||||
|
||||
### Dependency Versioning
|
||||
|
||||
@@ -121,8 +121,7 @@ Please double-check the image repository and available tags in the sub-chart:
|
||||
|
||||
- [PostgreSQL-HA](https://hub.docker.com/r/bitnami/postgresql-repmgr/tags)
|
||||
- [PostgreSQL](https://hub.docker.com/r/bitnami/postgresql/tags)
|
||||
- [Valkey Cluster](https://hub.docker.com/r/bitnami/valkey-cluster/tags)
|
||||
- [Valkey](https://hub.docker.com/r/bitnami/valkey/tags)
|
||||
- [Valkey](https://hub.docker.com/r/valkey/valkey/tags)
|
||||
|
||||
and look up the image tag which fits your needs on Dockerhub.
|
||||
|
||||
@@ -262,7 +261,7 @@ ENABLED = false
|
||||
|
||||
#### Rootless Defaults
|
||||
|
||||
If `.Values.image.rootless: true`, then the following will occur. In case you use `.Values.image.fullOverride`, check that this works in your image:
|
||||
If `.Values.deployment.gitea.image.rootless: true`, then the following will occur. In case you use `.Values.deployment.gitea.image.fullOverride`, check that this works in your image:
|
||||
|
||||
- `$HOME` becomes `/data/gitea/git`
|
||||
|
||||
@@ -280,6 +279,45 @@ If `.Values.image.rootless: true`, then the following will occur. In case you us
|
||||
|
||||
[see deployment.yaml](./templates/gitea/deployment.yaml) template inside container "env" declarations
|
||||
|
||||
#### OpenShift Compatibility
|
||||
|
||||
When installing on OpenShift, enable the compatibility profile so chart-managed pods render SCC-safe defaults and the Gitea init containers stop forcing `runAsUser: 1000`:
|
||||
|
||||
```yaml
|
||||
openshift:
|
||||
enabled: true
|
||||
```
|
||||
|
||||
When enabled, the chart applies `allowPrivilegeEscalation: false`, drops all
|
||||
Linux capabilities, sets `runAsNonRoot: true` and uses
|
||||
`seccompProfile.type: RuntimeDefault`.
|
||||
|
||||
The deployment keeps the existing vanilla Kubernetes behavior when OpenShift
|
||||
compatibility is disabled. Auto-detection relies on the
|
||||
`security.openshift.io/v1/SecurityContextConstraints` API, so set
|
||||
`openshift.enabled: true` explicitly when rendering outside a live cluster.
|
||||
|
||||
The PodSpec `hostUsers` field is independent of the OpenShift profile and is only
|
||||
rendered when `deployment.hostUsers` is set to a boolean. When left unset, the
|
||||
field is omitted so the platform default applies.
|
||||
|
||||
If you also want to expose Gitea through an OpenShift Route, enable the optional Route resource:
|
||||
|
||||
```yaml
|
||||
route:
|
||||
enabled: true
|
||||
host: git.apps.example.com
|
||||
tls:
|
||||
termination: edge
|
||||
```
|
||||
|
||||
When `route.host` is set, the chart uses it for `DOMAIN`, `SSH_DOMAIN`, and `ROOT_URL`. Setting `route.tls.termination` also switches the default `ROOT_URL` scheme to `https`.
|
||||
|
||||
#### Gateway API
|
||||
|
||||
The chart can also expose Gitea through Gateway API resources (`HTTPRoute`, `TCPRoute`, `BackendTLSPolicy`, and optionally `Gateway`).
|
||||
See [docs/gateway-api.md](docs/gateway-api.md) for the full guide, including how routes interact with `ROOT_URL`/`DOMAIN` resolution and recommended topologies.
|
||||
|
||||
#### Session, Cache and Queue
|
||||
|
||||
The session, cache and queue settings are set to use the built-in Valkey Cluster sub-chart dependency.
|
||||
@@ -288,7 +326,7 @@ If Valkey Cluster is disabled, the chart will fall back to the Gitea defaults wh
|
||||
While these will work and even not cause immediate issues after startup, **they are not recommended for production use**.
|
||||
Reasons being that a single pod will take on all the work for `session` and `cache` tasks in its available memory.
|
||||
It is likely that the pod will run out of memory or will face substantial memory spikes, depending on the workload.
|
||||
External tools such as `valkey-cluster` or `memcached` handle these workloads much better.
|
||||
External tools such as `valkey` or `memcached` handle these workloads much better.
|
||||
|
||||
### Single-Pod Configurations
|
||||
|
||||
@@ -301,8 +339,6 @@ If HA is not needed/desired, the following configurations can be used to deploy
|
||||
<summary>values.yml</summary>
|
||||
|
||||
```yaml
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: true
|
||||
postgresql:
|
||||
@@ -334,8 +370,6 @@ If HA is not needed/desired, the following configurations can be used to deploy
|
||||
<summary>values.yml</summary>
|
||||
|
||||
```yaml
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
postgresql:
|
||||
@@ -381,7 +415,7 @@ gitea:
|
||||
```
|
||||
|
||||
This would mount the two additional volumes (`oauth` and `some-additionals`) from different sources to the init container where the _app.ini_ gets updated.
|
||||
All files mounted that way will be read and converted to environment variables and then added to the _app.ini_ using [environment-to-ini](https://github.com/go-gitea/gitea/tree/main/contrib/environment-to-ini).
|
||||
All files mounted that way will be read and converted to environment variables and then added to the _app.ini_ using [Gitea config edit-ini](https://docs.gitea.com/administration/config-cheat-sheet#use-environment-variables-to-setup-gitea).
|
||||
|
||||
The key of such additional source represents the section inside the _app.ini_.
|
||||
The value for each key can be multiline ini-like definitions.
|
||||
@@ -422,10 +456,10 @@ Users are able to define their own environment variables, which are loaded into
|
||||
We also support to directly interact with the generated _app.ini_.
|
||||
|
||||
To inject self defined variables into the _app.ini_ a certain format needs to be honored.
|
||||
This is described in detail on the [env-to-ini](https://github.com/go-gitea/gitea/tree/main/contrib/environment-to-ini) page.
|
||||
This is described in detail on the [Gitea config edit-ini](https://docs.gitea.com/administration/config-cheat-sheet#use-environment-variables-to-setup-gitea) page.
|
||||
|
||||
Prior to Gitea 1.20 and Chart 9.0.0 the helm chart had a custom prefix `ENV_TO_INI`.
|
||||
After the support for a custom prefix was removed in Gite core, the prefix was changed to `GITEA`.
|
||||
After the support for a custom prefix was removed in Gitea core, the prefix was changed to `GITEA`.
|
||||
|
||||
For example a database setting needs to have the following format:
|
||||
|
||||
@@ -538,19 +572,13 @@ More about this issue [under this link](https://gitea.com/gitea/helm-gitea/issue
|
||||
|
||||
### Cache
|
||||
|
||||
The cache handling is done via `valkey-cluster` (via the `bitnami` chart) by default.
|
||||
This deployment is HA-ready but can also be used for single-pod deployments.
|
||||
By default, 6 replicas are deployed for a working `valkey-cluster` deployment.
|
||||
Many cloud providers offer a managed valkey service, which can be used instead of the built-in `valkey-cluster`.
|
||||
The cache handling is done via `valkey` (via the [official Valkey Helm chart](https://github.com/valkey-io/valkey-helm)) by default.
|
||||
|
||||
```yaml
|
||||
valkey-cluster:
|
||||
valkey:
|
||||
enabled: true
|
||||
```
|
||||
|
||||
⚠️ The valkey charts [do not work well with special characters in the password](https://gitea.com/gitea/helm-chart/issues/690).
|
||||
Consider omitting such or open an issue in the Bitnami repo and let us know once this got fixed.
|
||||
|
||||
### Persistence
|
||||
|
||||
Gitea will be deployed as a deployment.
|
||||
@@ -596,8 +624,9 @@ This has to be done in the ui.
|
||||
You cannot use `admin` as username.
|
||||
|
||||
```yaml
|
||||
gitea:
|
||||
secrets:
|
||||
admin:
|
||||
new:
|
||||
username: "MyAwesomeGiteaAdmin"
|
||||
password: "AReallyAwesomeGiteaPassword"
|
||||
email: "gi@tea.com"
|
||||
@@ -612,16 +641,22 @@ metadata:
|
||||
name: gitea-admin-secret
|
||||
type: Opaque
|
||||
stringData:
|
||||
email: gi@tea.com
|
||||
username: MyAwesomeGiteaAdmin
|
||||
password: AReallyAwesomeGiteaPassword
|
||||
```
|
||||
|
||||
```yaml
|
||||
gitea:
|
||||
secrets:
|
||||
admin:
|
||||
existingSecret: gitea-admin-secret
|
||||
existingSecret:
|
||||
enabled: true
|
||||
secretName: gitea-admin-secret
|
||||
```
|
||||
|
||||
The keys within the existing Secret can be customized via `secrets.admin.existingSecret.emailKey`,
|
||||
`secrets.admin.existingSecret.passwordKey` and `secrets.admin.existingSecret.usernameKey`.
|
||||
|
||||
Whether you use the existing Secret or specify a user name and password, there are three modes for how the admin user password is created or set.
|
||||
|
||||
- `keepUpdated` (the default) will set the admin user password, and reset it to the defined value every time the pod is recreated.
|
||||
@@ -631,11 +666,13 @@ Whether you use the existing Secret or specify a user name and password, there a
|
||||
These modes can be set like the following:
|
||||
|
||||
```yaml
|
||||
gitea:
|
||||
secrets:
|
||||
admin:
|
||||
passwordMode: initialOnlyRequireReset
|
||||
```
|
||||
|
||||
Set `secrets.admin.enabled` to `false` to skip the admin user handling entirely.
|
||||
|
||||
### LDAP Settings
|
||||
|
||||
Like the admin user the LDAP settings can be updated.
|
||||
@@ -741,17 +778,20 @@ When using the rootless image the gpg key folder is not persistent by default.
|
||||
If you consider using signed commits for internal Gitea activities (e.g. initial commit), you'd need to provide a signing key.
|
||||
Prior to [PR186](https://gitea.com/gitea/helm-gitea/pulls/186), imported keys had to be re-imported once the container got replaced by another.
|
||||
|
||||
The mentioned PR introduced a new configuration object `signing` allowing you to configure prerequisites for commit signing.
|
||||
The `secrets.gpg` object allows you to configure the prerequisites for commit signing.
|
||||
By default this section is disabled to maintain backwards compatibility.
|
||||
|
||||
```yaml
|
||||
signing:
|
||||
secrets:
|
||||
gpg:
|
||||
enabled: false
|
||||
new:
|
||||
gpgHome: /data/git/.gnupg
|
||||
```
|
||||
|
||||
Regardless of the used container image the `signing` object allows to specify a private gpg key.
|
||||
Either using the `signing.privateKey` to define the key inline, or refer to an existing secret containing the key data by using `signing.existingSecret`.
|
||||
Regardless of the used container image the `secrets.gpg` object allows to specify a private gpg key.
|
||||
Either using `secrets.gpg.new.privateKey` to define the key inline, or refer to an existing Secret containing the key data by
|
||||
using `secrets.gpg.existingSecret`.
|
||||
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
@@ -760,6 +800,7 @@ metadata:
|
||||
name: custom-gitea-gpg-key
|
||||
type: Opaque
|
||||
stringData:
|
||||
gpgHome: /data/git/.gnupg
|
||||
privateKey: |-
|
||||
-----BEGIN PGP PRIVATE KEY BLOCK-----
|
||||
...
|
||||
@@ -767,10 +808,17 @@ stringData:
|
||||
```
|
||||
|
||||
```yaml
|
||||
signing:
|
||||
existingSecret: custom-gitea-gpg-key
|
||||
secrets:
|
||||
gpg:
|
||||
enabled: true
|
||||
existingSecret:
|
||||
enabled: true
|
||||
secretName: custom-gitea-gpg-key
|
||||
```
|
||||
|
||||
The keys within the existing Secret can be customized via `secrets.gpg.existingSecret.gpgHomeKey` and
|
||||
`secrets.gpg.existingSecret.privateKeyKey`.
|
||||
|
||||
To use the gpg key, Gitea needs to be configured accordingly.
|
||||
A detailed description can be found in the [official Gitea documentation](https://docs.gitea.com/administration/signing#general-configuration).
|
||||
|
||||
@@ -817,6 +865,30 @@ gitea:
|
||||
podAnnotations: {}
|
||||
```
|
||||
|
||||
### Secret checksum annotations
|
||||
|
||||
Each Secret of the chart has an `addSHASumAnnotation` option (disabled by default). It adds a
|
||||
`checksum/<secret>` pod annotation so that a change to the Secret triggers a rolling update of the
|
||||
Gitea pod.
|
||||
|
||||
The SHA sum is computed differently depending on where the Secret comes from:
|
||||
|
||||
- **Chart-managed Secrets** (`secrets.<secret>.existingSecret.enabled: false`): the SHA sum is
|
||||
computed from the manifest rendered by the chart. The cluster still holds the pre-upgrade state of
|
||||
that Secret during rendering, so it cannot be used as the source.
|
||||
- **User-provided Secrets** (`secrets.<secret>.existingSecret.enabled: true`): the content is unknown
|
||||
to the chart, so the Secret is looked up in the cluster via Helm's `lookup` function.
|
||||
|
||||
The lookup is the reason why the option is disabled by default:
|
||||
|
||||
- The credentials used by Helm need `get` permission on Secrets in the release namespace.
|
||||
- The lookup returns nothing during client-side rendering, for example with `helm template`, during
|
||||
`helm install --dry-run`, or with Argo CD unless the Helm chart is rendered against a live cluster.
|
||||
The annotation is still emitted, but its value stays constant and therefore no longer triggers a
|
||||
rollout. Keep `secrets.<secret>.addSHASumAnnotation: false` in that case and trigger rollouts by
|
||||
other means, for example with stakater's [reloader](https://github.com/stakater/Reloader) as
|
||||
described below.
|
||||
|
||||
## TLS certificate rotation
|
||||
|
||||
If Gitea uses TLS certificates that are mounted as a secret in the container file system, Gitea will not automatically apply them when the TLS certificates are rotated.
|
||||
@@ -849,15 +921,16 @@ Custom themes can be added via k8s secrets and referencing them in `values.yaml`
|
||||
The [http provider](https://registry.terraform.io/providers/hashicorp/http/latest/docs/data-sources/http) is useful here.
|
||||
|
||||
```yaml
|
||||
extraVolumes:
|
||||
- name: gitea-themes
|
||||
secret:
|
||||
secretName: gitea-themes
|
||||
|
||||
extraVolumeMounts:
|
||||
deployment:
|
||||
gitea:
|
||||
volumeMounts:
|
||||
- name: gitea-themes
|
||||
readOnly: true
|
||||
mountPath: "/data/gitea/public/assets/css"
|
||||
volumes:
|
||||
- name: gitea-themes
|
||||
secret:
|
||||
secretName: gitea-themes
|
||||
```
|
||||
|
||||
The secret can be created via `terraform`:
|
||||
@@ -916,7 +989,9 @@ To be able to use a digest value which is automatically updated by `Renovate` a
|
||||
Here's an examplary `values.yml` definition which makes use of a digest:
|
||||
|
||||
```yaml
|
||||
image:
|
||||
deployment:
|
||||
gitea:
|
||||
image:
|
||||
repository: gitea/gitea
|
||||
tag: 1.20.2
|
||||
digest: sha256:6e3b85a36653894d6741d0aefb41dfaac39044e028a42e0a520cc05ebd7bfc3f
|
||||
@@ -943,45 +1018,228 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
### Global
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------- | ---------------------------------------------------------------------------------------------- | ----- |
|
||||
| ------------------------- | ------------------------------------------------------------------------- | ----- |
|
||||
| `global.imageRegistry` | global image registry override | `""` |
|
||||
| `global.imagePullSecrets` | global image pull secrets override; can be extended by `imagePullSecrets` | `[]` |
|
||||
| `global.storageClass` | global storage class override | `""` |
|
||||
| `global.hostAliases` | global hostAliases which will be added to the pod's hosts files | `[]` |
|
||||
| `namespace` | An explicit namespace to deploy Gitea into. Defaults to the release namespace if not specified | `""` |
|
||||
| `replicaCount` | number of replicas for the deployment | `1` |
|
||||
|
||||
### strategy
|
||||
### deployment
|
||||
|
||||
| Name | Description | Value |
|
||||
| --------------------------------------- | -------------- | --------------- |
|
||||
| `strategy.type` | strategy type | `RollingUpdate` |
|
||||
| `strategy.rollingUpdate.maxSurge` | maxSurge | `100%` |
|
||||
| `strategy.rollingUpdate.maxUnavailable` | maxUnavailable | `0` |
|
||||
| `clusterDomain` | cluster domain | `cluster.local` |
|
||||
| -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |
|
||||
| `deployment.enabled` | Enable the deployment of Gitea. | `true` |
|
||||
| `deployment.annotations` | Annotations for the Gitea deployment to be created | `{}` |
|
||||
| `deployment.labels` | Labels for the deployment | `{}` |
|
||||
| `deployment.affinity` | Affinity for the deployment. | `{}` |
|
||||
| `deployment.dnsConfig` | dnsConfig of the Gitea deployment. | `{}` |
|
||||
| `deployment.gitea.env` | Additional environment variables to pass to the Gitea container. | `[]` |
|
||||
| `deployment.gitea.envFrom` | List of environment variables mounted from configMaps or secrets for the Gitea container. | `[]` |
|
||||
| `deployment.gitea.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
|
||||
| `deployment.gitea.image.repository` | Image to start for this pod | `gitea` |
|
||||
| `deployment.gitea.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
|
||||
| `deployment.gitea.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
|
||||
| `deployment.gitea.image.pullPolicy` | Image pull policy | `IfNotPresent` |
|
||||
| `deployment.gitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||
| `deployment.gitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.gitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||
| `deployment.gitea.resources` | Compute Resources required by Gitea container. Cannot be updated. | `nil` |
|
||||
| `deployment.gitea.securityContext` | Security context of the Gitea container. Used as fallback for the chart-managed init containers. | `{}` |
|
||||
| `deployment.gitea.volumeMounts` | Additional volume mounts. | `[]` |
|
||||
| `deployment.hostUsers` | Use the host's user namespace. When unset, the field is omitted so the platform default is used. | `nil` |
|
||||
| `deployment.initContainers` | List of initContainers. The order is important. First init container in the list will be executed first. The link refers to the corresponding init container configuration. | `[]` |
|
||||
| `deployment.initDirectories.env` | Additional environment variables to pass to the init container. | `[]` |
|
||||
| `deployment.initDirectories.envFrom` | List of environment variables mounted from configMaps or secrets for the initDirectories container. | `[]` |
|
||||
| `deployment.initDirectories.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
|
||||
| `deployment.initDirectories.image.repository` | Image to start for this pod | `gitea` |
|
||||
| `deployment.initDirectories.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
|
||||
| `deployment.initDirectories.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
|
||||
| `deployment.initDirectories.image.pullPolicy` | Image pull policy | `IfNotPresent` |
|
||||
| `deployment.initDirectories.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||
| `deployment.initDirectories.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initDirectories.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||
| `deployment.initDirectories.resources` | Compute Resources required by the initDirectories container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
|
||||
| `deployment.initDirectories.securityContext` | Security context of the initDirectories container. Defaults to `deployment.gitea.securityContext`. | `{}` |
|
||||
| `deployment.initDirectories.volumeMounts` | Additional volume mounts. | `[]` |
|
||||
| `deployment.initAppIni.env` | Additional environment variables to pass to the init container. | `[]` |
|
||||
| `deployment.initAppIni.envFrom` | List of environment variables mounted from configMaps or secrets for the initAppIni container. | `[]` |
|
||||
| `deployment.initAppIni.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
|
||||
| `deployment.initAppIni.image.repository` | Image to start for this pod | `gitea` |
|
||||
| `deployment.initAppIni.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
|
||||
| `deployment.initAppIni.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
|
||||
| `deployment.initAppIni.image.pullPolicy` | Image pull policy | `IfNotPresent` |
|
||||
| `deployment.initAppIni.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||
| `deployment.initAppIni.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initAppIni.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||
| `deployment.initAppIni.resources` | Compute Resources required by the initAppIni container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
|
||||
| `deployment.initAppIni.securityContext` | Security context of the initAppIni container. Defaults to `deployment.gitea.securityContext`. | `{}` |
|
||||
| `deployment.initAppIni.volumeMounts` | Additional volume mounts. | `[]` |
|
||||
| `deployment.initConfigureGPG.env` | Additional environment variables to pass to the init container. | `[]` |
|
||||
| `deployment.initConfigureGPG.envFrom` | List of environment variables mounted from configMaps or secrets for the initConfigureGPG container. | `[]` |
|
||||
| `deployment.initConfigureGPG.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
|
||||
| `deployment.initConfigureGPG.image.repository` | Image to start for this pod | `gitea` |
|
||||
| `deployment.initConfigureGPG.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
|
||||
| `deployment.initConfigureGPG.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
|
||||
| `deployment.initConfigureGPG.image.pullPolicy` | Image pull policy | `IfNotPresent` |
|
||||
| `deployment.initConfigureGPG.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||
| `deployment.initConfigureGPG.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initConfigureGPG.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||
| `deployment.initConfigureGPG.resources` | Compute Resources required by the initConfigureGPG container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
|
||||
| `deployment.initConfigureGPG.securityContext` | Security context of the initConfigureGPG container. Defaults to `deployment.gitea.securityContext`. | `{}` |
|
||||
| `deployment.initConfigureGPG.volumeMounts` | Additional volume mounts. | `[]` |
|
||||
| `deployment.initConfigureGitea.env` | Additional environment variables to pass to the init container. | `[]` |
|
||||
| `deployment.initConfigureGitea.envFrom` | List of environment variables mounted from configMaps or secrets for the initConfigureGitea container. | `[]` |
|
||||
| `deployment.initConfigureGitea.image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
|
||||
| `deployment.initConfigureGitea.image.repository` | Image to start for this pod | `gitea` |
|
||||
| `deployment.initConfigureGitea.image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
|
||||
| `deployment.initConfigureGitea.image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
|
||||
| `deployment.initConfigureGitea.image.pullPolicy` | Image pull policy | `IfNotPresent` |
|
||||
| `deployment.initConfigureGitea.image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||
| `deployment.initConfigureGitea.image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `deployment.initConfigureGitea.image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||
| `deployment.initConfigureGitea.resources` | Compute Resources required by the initConfigureGitea container. Defaults to `initContainers.resources`. Cannot be updated. | `nil` |
|
||||
| `deployment.initConfigureGitea.securityContext` | Security context of the initConfigureGitea container. Defaults to `deployment.gitea.securityContext`. | `{}` |
|
||||
| `deployment.initConfigureGitea.volumeMounts` | Additional volume mounts. | `[]` |
|
||||
| `deployment.nodeSelector` | NodeSelector for the deployment | `{}` |
|
||||
| `deployment.priorityClassName` | priorityClassName for the deployment | `""` |
|
||||
| `deployment.replicas` | Number of replicas for the Gitea deployment. | `1` |
|
||||
| `deployment.resources` | Resources is the total amount of CPU and Memory resources required by all containers in the pod. | `{}` |
|
||||
| `deployment.schedulerName` | Use an alternate scheduler, e.g. "stork" | `""` |
|
||||
| `deployment.securityContext` | Pod security context. On non-OpenShift clusters the chart defaults `fsGroup` to `1000` when this map is empty. | `{}` |
|
||||
| `deployment.strategy.type` | Deployment strategy used to replace old pods, either `RollingUpdate` or `Recreate`. | `RollingUpdate` |
|
||||
| `deployment.strategy.rollingUpdate.maxSurge` | Number or percentage of pods that may be created above the desired replica count. Only used with `RollingUpdate`. | `100%` |
|
||||
| `deployment.strategy.rollingUpdate.maxUnavailable` | Number or percentage of pods that may be unavailable during the update. Only used with `RollingUpdate`. | `0` |
|
||||
| `deployment.terminationGracePeriodSeconds` | How long to wait until forcefully kill the pod | `60` |
|
||||
| `deployment.tolerations` | Tolerations of the Gitea deployment. | `[]` |
|
||||
| `deployment.topologySpreadConstraints` | TopologySpreadConstraints for the deployment | `[]` |
|
||||
| `deployment.volumes` | Additional volumes to mount into the pods of the Gitea deployment. | `[]` |
|
||||
|
||||
### Gateway API
|
||||
|
||||
| Name | Description | Value |
|
||||
| --------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||
| `gatewayAPI.enabled` | Enable deployment of Gateway API resources | `false` |
|
||||
| `gatewayAPI.core.backendTLSPolicy.enabled` | Render a BackendTLSPolicy resource for encrypted backend traffic | `false` |
|
||||
| `gatewayAPI.core.backendTLSPolicy.annotations` | Annotations applied to the BackendTLSPolicy | `{}` |
|
||||
| `gatewayAPI.core.backendTLSPolicy.labels` | Additional labels applied to the BackendTLSPolicy | `{}` |
|
||||
| `gatewayAPI.core.backendTLSPolicy.targetRefs` | Target references for the BackendTLSPolicy. Defaults to the HTTP service. | `[]` |
|
||||
| `gatewayAPI.core.backendTLSPolicy.validation` | Validation configuration (required when enabled). See `docs/gateway-api.md`. | `{}` |
|
||||
| `gatewayAPI.core.backendTLSPolicy.validation.caCertificateRefs` | CA certificate references for the BackendTLSPolicy validation. See `docs/gateway-api.md`. | |
|
||||
| `gatewayAPI.core.backendTLSPolicy.validation.hostname` | Hostname for the BackendTLSPolicy validation. Must be the Common Name (CN) or a Subject Alternative Name (SAN) of the Gitea server certificate. See `docs/gateway-api.md`. | |
|
||||
| `gatewayAPI.core.httpRoute.enabled` | Render an HTTPRoute resource | `false` |
|
||||
| `gatewayAPI.core.httpRoute.annotations` | Annotations applied to the HTTPRoute | `{}` |
|
||||
| `gatewayAPI.core.httpRoute.labels` | Additional labels applied to the HTTPRoute | `{}` |
|
||||
| `gatewayAPI.core.httpRoute.tls` | When true, treat the upstream Gateway as terminating TLS so `ROOT_URL` uses `https`. | `false` |
|
||||
| `gatewayAPI.core.httpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
|
||||
| `gatewayAPI.core.httpRoute.hostnames` | List of hostnames for the HTTPRoute. | `[]` |
|
||||
| `gatewayAPI.core.httpRoute.rules` | Custom routing rules. Defaults to a PathPrefix `/` rule targeting the HTTP service. | `[]` |
|
||||
| `gatewayAPI.core.tcpRoute.enabled` | Render a TCPRoute resource (typically for SSH) | `false` |
|
||||
| `gatewayAPI.core.tcpRoute.annotations` | Annotations applied to the TCPRoute | `{}` |
|
||||
| `gatewayAPI.core.tcpRoute.labels` | Additional labels applied to the TCPRoute | `{}` |
|
||||
| `gatewayAPI.core.tcpRoute.parentRefs` | Parent gateway references (required when enabled). | `[]` |
|
||||
| `gatewayAPI.core.tcpRoute.rules` | Custom routing rules. Defaults to a rule targeting the SSH service. | `[]` |
|
||||
| `gatewayAPI.nginx.clientSettingsPolicies.enabled` | Render a ClientSettingsPolicy (NGINX Gateway Fabric) to raise the client request body limit | `false` |
|
||||
| `gatewayAPI.nginx.clientSettingsPolicies.annotations` | Annotations applied to the ClientSettingsPolicy | `{}` |
|
||||
| `gatewayAPI.nginx.clientSettingsPolicies.labels` | Additional labels applied to the ClientSettingsPolicy | `{}` |
|
||||
| `gatewayAPI.nginx.clientSettingsPolicies.targetRef` | Target reference for the ClientSettingsPolicy. Defaults to the chart's HTTPRoute. | `{}` |
|
||||
| `gatewayAPI.nginx.clientSettingsPolicies.body` | Client body settings (required when enabled), e.g. `maxSize`. See `docs/gateway-api.md`. | `{}` |
|
||||
|
||||
### Ingress
|
||||
|
||||
| Name | Description | Value |
|
||||
| -------------------------------- | ---------------------------------------------------------------------------------------------- | ----------------- |
|
||||
| `ingress.enabled` | Enable ingress | `false` |
|
||||
| `ingress.annotations` | Additional annotations. | `{}` |
|
||||
| `ingress.labels` | Additional labels. | `{}` |
|
||||
| `ingress.className` | DEPRECATED: Ingress class name. | `nginx` |
|
||||
| `ingress.pathType` | Ingress Path Type | `Prefix` |
|
||||
| `ingress.hosts[0].host` | Default Ingress host | `git.example.com` |
|
||||
| `ingress.hosts[0].paths[0].path` | Default Ingress path | `/` |
|
||||
| `ingress.tls` | Ingress tls settings | `[]` |
|
||||
| `namespace` | An explicit namespace to deploy Gitea into. Defaults to the release namespace if not specified | `""` |
|
||||
|
||||
### Network
|
||||
|
||||
| Name | Description | Value |
|
||||
| --------------- | ------------------------------------------------------------------------ | --------------- |
|
||||
| `clusterDomain` | Domain of the Cluster. Domain is part of internally issued certificates. | `cluster.local` |
|
||||
|
||||
### Image
|
||||
|
||||
| Name | Description | Value |
|
||||
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ |
|
||||
| `image.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
|
||||
| `image.repository` | Image to start for this pod | `gitea` |
|
||||
| `image.tag` | Visit: [Image tag](https://hub.docker.com/r/gitea/gitea/tags?page=1&ordering=last_updated). Defaults to `appVersion` within Chart.yaml. | `""` |
|
||||
| `image.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
|
||||
| `image.pullPolicy` | Image pull policy | `IfNotPresent` |
|
||||
| `image.rootless` | Wether or not to pull the rootless version of Gitea, only works on Gitea 1.14.x or higher | `true` |
|
||||
| `image.fullOverride` | Completely overrides the image registry, path/image, tag and digest. **Adjust `image.rootless` accordingly and review [Rootless defaults](#rootless-defaults).** | `""` |
|
||||
| ------------------ | ----------------------------------- | ----- |
|
||||
| `imagePullSecrets` | Secret to use for pulling the image | `[]` |
|
||||
|
||||
### Security
|
||||
|
||||
| Name | Description | Value |
|
||||
| ---------------------------- | --------------------------------------------------------------- | ------ |
|
||||
| `podSecurityContext.fsGroup` | Set the shared file system group for all containers in the pod. | `1000` |
|
||||
| `containerSecurityContext` | Security context | `{}` |
|
||||
| `securityContext` | Run init and Gitea containers as a specific securityContext | `{}` |
|
||||
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------ | ----- |
|
||||
| `openshift.enabled` | Enable OpenShift compatibility defaults for chart-managed pods. Defaults to auto-detect based on the SecurityContextConstraints API. | `nil` |
|
||||
| `podDisruptionBudget` | Pod disruption budget | `{}` |
|
||||
|
||||
### Route
|
||||
|
||||
| Name | Description | Value |
|
||||
| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ------- |
|
||||
| `route.enabled` | Enable OpenShift Route | `false` |
|
||||
| `route.annotations` | Route annotations | `{}` |
|
||||
| `route.host` | Route host. When unset, OpenShift may generate one and Gitea URL defaults fall back to ingress/service values. | `""` |
|
||||
| `route.path` | Route path | `""` |
|
||||
| `route.wildcardPolicy` | Route wildcard policy | `None` |
|
||||
| `route.tls.termination` | Route TLS termination type | `nil` |
|
||||
| `route.tls.insecureEdgeTerminationPolicy` | Route insecure edge termination policy | `nil` |
|
||||
| `route.tls.key` | Route TLS key | `nil` |
|
||||
| `route.tls.certificate` | Route TLS certificate | `nil` |
|
||||
| `route.tls.caCertificate` | Route TLS CA certificate | `nil` |
|
||||
| `route.tls.destinationCACertificate` | Route destination CA certificate | `nil` |
|
||||
|
||||
### Secrets
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
|
||||
| `secrets.admin.enabled` | Create and keep the Gitea admin user in sync | `true` |
|
||||
| `secrets.admin.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the admin Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
|
||||
| `secrets.admin.passwordMode` | Mode for how to set/update the admin user password. Options are: initialOnlyNoReset, initialOnlyRequireReset, and keepUpdated | `keepUpdated` |
|
||||
| `secrets.admin.existingSecret.enabled` | Use an already existing Secret instead of creating the admin Secret | `false` |
|
||||
| `secrets.admin.existingSecret.secretName` | Name of the already existing admin Secret | `""` |
|
||||
| `secrets.admin.existingSecret.emailKey` | Key of the email address in the existing admin Secret | `email` |
|
||||
| `secrets.admin.existingSecret.passwordKey` | Key of the password in the existing admin Secret | `password` |
|
||||
| `secrets.admin.existingSecret.usernameKey` | Key of the username in the existing admin Secret | `username` |
|
||||
| `secrets.admin.new.annotations` | Annotations for the admin Secret | `{}` |
|
||||
| `secrets.admin.new.labels` | Labels for the admin Secret | `{}` |
|
||||
| `secrets.admin.new.email` | Email of the Gitea admin user | `gitea@local.domain` |
|
||||
| `secrets.admin.new.password` | Password of the Gitea admin user. | `r8sA8CPHD9!bt6d` |
|
||||
| `secrets.admin.new.username` | Username of the Gitea admin user | `gitea_admin` |
|
||||
| `secrets.config.enabled` | Enable mounting of the config Secret. | `true` |
|
||||
| `secrets.config.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the config Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
|
||||
| `secrets.config.existingSecret.enabled` | Use an already existing Secret instead of creating the config Secret | `false` |
|
||||
| `secrets.config.existingSecret.secretName` | Name of the already existing config Secret | `""` |
|
||||
| `secrets.config.new.annotations` | Annotations for the config Secret | `{}` |
|
||||
| `secrets.config.new.labels` | Labels for the config Secret | `{}` |
|
||||
| `secrets.gpg.enabled` | Enable mounting of a GPG key to sign Git commits. | `false` |
|
||||
| `secrets.gpg.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the GPG key Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
|
||||
| `secrets.gpg.existingSecret.enabled` | Use an already existing Secret instead of creating the GPG key Secret | `false` |
|
||||
| `secrets.gpg.existingSecret.secretName` | Name of the already existing GPG key Secret | `""` |
|
||||
| `secrets.gpg.existingSecret.gpgHomeKey` | Key of the GPG home directory in the existing GPG key Secret | `gpgHome` |
|
||||
| `secrets.gpg.existingSecret.privateKeyKey` | Key of the private key in the existing GPG key Secret. | `privateKey` |
|
||||
| `secrets.gpg.new.annotations` | Annotations for the GPG key Secret | `{}` |
|
||||
| `secrets.gpg.new.labels` | Labels for the GPG key Secret | `{}` |
|
||||
| `secrets.gpg.new.gpgHome` | Path to the GPG home directory. | `/data/git/.gnupg` |
|
||||
| `secrets.gpg.new.privateKey` | Content of the private GPG key in armored format. | `""` |
|
||||
| `secrets.init.enabled` | Enable mounting of the init Secret. | `true` |
|
||||
| `secrets.init.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the init Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
|
||||
| `secrets.init.existingSecret.enabled` | Use an already existing Secret instead of creating the init Secret | `false` |
|
||||
| `secrets.init.existingSecret.secretName` | Name of the already existing init Secret | `""` |
|
||||
| `secrets.init.new.annotations` | Annotations for the init Secret | `{}` |
|
||||
| `secrets.init.new.labels` | Labels for the init Secret | `{}` |
|
||||
| `secrets.inlineConfig.enabled` | Enable mounting of the inline configuration Secret. | `true` |
|
||||
| `secrets.inlineConfig.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the inline configuration Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
|
||||
| `secrets.inlineConfig.existingSecret.enabled` | Use an already existing Secret instead of creating the inline configuration Secret | `false` |
|
||||
| `secrets.inlineConfig.existingSecret.secretName` | Name of the already existing inline configuration Secret | `""` |
|
||||
| `secrets.inlineConfig.new.annotations` | Annotations for the inline configuration Secret | `{}` |
|
||||
| `secrets.inlineConfig.new.labels` | Labels for the inline configuration Secret | `{}` |
|
||||
| `secrets.metrics.enabled` | Enable mounting of the metrics Secret. | `true` |
|
||||
| `secrets.metrics.addSHASumAnnotation` | Add a pod annotation with the SHA sum of the metrics Secret to trigger a rollout on change. Further information can be found in the [documentation](./README.md#secret-checksum-annotation). | `false` |
|
||||
| `secrets.metrics.existingSecret.enabled` | Use an already existing Secret instead of creating the metrics Secret | `false` |
|
||||
| `secrets.metrics.existingSecret.secretName` | Name of the already existing metrics Secret | `""` |
|
||||
| `secrets.metrics.new.annotations` | Annotations for the metrics Secret | `{}` |
|
||||
| `secrets.metrics.new.labels` | Labels for the metrics Secret | `{}` |
|
||||
|
||||
### Service
|
||||
|
||||
| Name | Description | Value |
|
||||
@@ -1014,35 +1272,6 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
| `service.ssh.labels` | SSH service additional labels | `{}` |
|
||||
| `service.ssh.loadBalancerClass` | Loadbalancer class | `nil` |
|
||||
|
||||
### Ingress
|
||||
|
||||
| Name | Description | Value |
|
||||
| -------------------------------- | ------------------------------- | ----------------- |
|
||||
| `ingress.enabled` | Enable ingress | `false` |
|
||||
| `ingress.className` | DEPRECATED: Ingress class name. | `""` |
|
||||
| `ingress.pathType` | Ingress Path Type | `Prefix` |
|
||||
| `ingress.annotations` | Ingress annotations | `{}` |
|
||||
| `ingress.hosts[0].host` | Default Ingress host | `git.example.com` |
|
||||
| `ingress.hosts[0].paths[0].path` | Default Ingress path | `/` |
|
||||
| `ingress.tls` | Ingress tls settings | `[]` |
|
||||
|
||||
### deployment
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------ | ------------------------------------------------------ | ----- |
|
||||
| `resources` | Kubernetes resources | `{}` |
|
||||
| `schedulerName` | Use an alternate scheduler, e.g. "stork" | `""` |
|
||||
| `nodeSelector` | NodeSelector for the deployment | `{}` |
|
||||
| `tolerations` | Tolerations for the deployment | `[]` |
|
||||
| `affinity` | Affinity for the deployment | `{}` |
|
||||
| `topologySpreadConstraints` | TopologySpreadConstraints for the deployment | `[]` |
|
||||
| `dnsConfig` | dnsConfig for the deployment | `{}` |
|
||||
| `priorityClassName` | priorityClassName for the deployment | `""` |
|
||||
| `deployment.env` | Additional environment variables to pass to containers | `[]` |
|
||||
| `deployment.terminationGracePeriodSeconds` | How long to wait until forcefully kill the pod | `60` |
|
||||
| `deployment.labels` | Labels for the deployment | `{}` |
|
||||
| `deployment.annotations` | Annotations for the Gitea deployment to be created | `{}` |
|
||||
|
||||
### ServiceAccount
|
||||
|
||||
| Name | Description | Value |
|
||||
@@ -1057,7 +1286,7 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
### Persistence
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------------- | ----------------------------------------------------------------------------------------------------- | ---------------------- |
|
||||
| ------------------------------------------------- | -------------------------------------------------------------------------------------------------- | ---------------------- |
|
||||
| `persistence.enabled` | Enable persistent storage | `true` |
|
||||
| `persistence.create` | Whether to create the persistentVolumeClaim for shared storage | `true` |
|
||||
| `persistence.mount` | Whether the persistentVolumeClaim should be mounted (even if not created) | `true` |
|
||||
@@ -1070,10 +1299,6 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
| `persistence.subPath` | Subdirectory of the volume to mount at | `nil` |
|
||||
| `persistence.volumeName` | Name of persistent volume in PVC | `""` |
|
||||
| `extraContainers` | Additional sidecar containers to run in the pod | `[]` |
|
||||
| `preExtraInitContainers` | Additional init containers to run in the pod before Gitea runs it owns init containers. | `[]` |
|
||||
| `postExtraInitContainers` | Additional init containers to run in the pod after Gitea runs it owns init containers. | `[]` |
|
||||
| `extraVolumes` | Additional volumes to mount to the Gitea deployment | `[]` |
|
||||
| `extraContainerVolumeMounts` | Mounts that are only mapped into the Gitea runtime/main container, to e.g. override custom templates. | `[]` |
|
||||
| `extraInitVolumeMounts` | Mounts that are only mapped into the init-containers. Can be used for additional preconfiguration. | `[]` |
|
||||
| `extraVolumeMounts` | **DEPRECATED** Additional volume mounts for init containers and the Gitea main container | `[]` |
|
||||
|
||||
@@ -1087,24 +1312,10 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
| `initContainers.resources.requests.cpu` | initContainers.requests.cpu Kubernetes cpu resource limits for init containers | `100m` |
|
||||
| `initContainers.resources.requests.memory` | initContainers.requests.memory Kubernetes memory resource limits for init containers | `128Mi` |
|
||||
|
||||
### Signing
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------ | ----------------------------------------------------------------- | ------------------ |
|
||||
| `signing.enabled` | Enable commit/action signing | `false` |
|
||||
| `signing.gpgHome` | GPG home directory | `/data/git/.gnupg` |
|
||||
| `signing.privateKey` | Inline private gpg key for signed internal Git activity | `""` |
|
||||
| `signing.existingSecret` | Use an existing secret to store the value of `signing.privateKey` | `""` |
|
||||
|
||||
### Gitea
|
||||
|
||||
| Name | Description | Value |
|
||||
| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ | -------------------- |
|
||||
| `gitea.admin.username` | Username for the Gitea admin user | `gitea_admin` |
|
||||
| `gitea.admin.existingSecret` | Use an existing secret to store admin user credentials | `nil` |
|
||||
| `gitea.admin.password` | Password for the Gitea admin user | `r8sA8CPHD9!bt6d` |
|
||||
| `gitea.admin.email` | Email for the Gitea admin user | `gitea@local.domain` |
|
||||
| `gitea.admin.passwordMode` | Mode for how to set/update the admin user password. Options are: initialOnlyNoReset, initialOnlyRequireReset, and keepUpdated | `keepUpdated` |
|
||||
| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||
| `gitea.metrics.enabled` | Enable Gitea metrics | `false` |
|
||||
| `gitea.metrics.token` | used for `bearer` token authentication on metrics endpoint. If not specified or empty metrics endpoint is public. | `nil` |
|
||||
| `gitea.metrics.serviceMonitor.enabled` | Enable Gitea metrics service monitor. Requires, that `gitea.metrics.enabled` is also set to true, to enable metrics generally. | `false` |
|
||||
@@ -1119,6 +1330,7 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
| `gitea.config.server.SSH_LISTEN_PORT` | SSH port for rootless Gitea image | `2222` |
|
||||
| `gitea.additionalConfigSources` | Additional configuration from secret or configmap | `[]` |
|
||||
| `gitea.additionalConfigFromEnvs` | Additional configuration sources from environment variables | `[]` |
|
||||
| `gitea.extraEnvSourceFile` | Source environment variables from a file during init container startup. This is especially useful for reading environment variable files generated by the Vault agent-injector. | `nil` |
|
||||
| `gitea.podAnnotations` | Annotations for the Gitea pod | `{}` |
|
||||
| `gitea.ssh.logLevel` | Configure OpenSSH's log level. Only available for root-based Gitea image. | `INFO` |
|
||||
|
||||
@@ -1158,48 +1370,29 @@ To comply with the Gitea helm chart definition of the digest parameter, a "custo
|
||||
| `gitea.startupProbe.successThreshold` | Success threshold for startup probe | `1` |
|
||||
| `gitea.startupProbe.failureThreshold` | Failure threshold for startup probe | `10` |
|
||||
|
||||
### valkey-cluster
|
||||
|
||||
Valkey cluster and [Valkey](#valkey) cannot be enabled at the same time.
|
||||
|
||||
| Name | Description | Value |
|
||||
| --------------------------------------------------- | --------------------------------------------------------------------------- | ------------------------------ |
|
||||
| `valkey-cluster.enabled` | Enable valkey cluster | `true` |
|
||||
| `valkey-cluster.usePassword` | Whether to use password authentication. | `false` |
|
||||
| `valkey-cluster.usePasswordFiles` | Whether to mount passwords as files instead of environment variables. | `false` |
|
||||
| `valkey-cluster.image.repository` | Image repository, eg. `bitnamilegacy/valkey-cluster`. | `bitnamilegacy/valkey-cluster` |
|
||||
| `valkey-cluster.cluster.nodes` | Number of valkey cluster master nodes | `3` |
|
||||
| `valkey-cluster.cluster.replicas` | Number of valkey cluster master node replicas | `0` |
|
||||
| `valkey-cluster.metrics.image.repository` | Image repository, eg. `bitnamilegacy/redis-exporter`. | `bitnamilegacy/redis-exporter` |
|
||||
| `valkey-cluster.persistence.enabled` | Enable persistence on Valkey replicas nodes using Persistent Volume Claims. | `true` |
|
||||
| `valkey-cluster.persistence.storageClass` | Persistent Volume storage class. | `""` |
|
||||
| `valkey-cluster.persistence.size` | Persistent Volume size. | `8Gi` |
|
||||
| `valkey-cluster.service.ports.valkey` | Port of Valkey service | `6379` |
|
||||
| `valkey-cluster.sysctlImage.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
|
||||
| `valkey-cluster.volumePermissions.image.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
|
||||
|
||||
### valkey
|
||||
|
||||
Valkey and [Valkey cluster](#valkey-cluster) cannot be enabled at the same time.
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------- | --------------------------------------------------------------------------- | ------------------------------- |
|
||||
| ------------------------------------------ | -------------------------------------------------- | -------------------------- |
|
||||
| `valkey.enabled` | Enable valkey standalone or replicated | `false` |
|
||||
| `valkey.architecture` | Whether to use standalone or replication | `standalone` |
|
||||
| `valkey.kubectl.image.repository` | Image repository, eg. `bitnamilegacy/kubectl`. | `bitnamilegacy/kubectl` |
|
||||
| `valkey.image.repository` | Image repository, eg. `bitnamilegacy/valkey`. | `bitnamilegacy/valkey` |
|
||||
| `valkey.global.valkey.password` | Required password | `changeme` |
|
||||
| `valkey.master.count` | Number of Valkey master instances to deploy | `1` |
|
||||
| `valkey.master.service.ports.valkey` | Port of Valkey service | `6379` |
|
||||
| `valkey.metrics.image.repository` | Image repository, eg. `bitnamilegacy/redis-exporter`. | `bitnamilegacy/redis-exporter` |
|
||||
| `valkey.primary.persistence.enabled` | Enable persistence on Valkey replicas nodes using Persistent Volume Claims. | `true` |
|
||||
| `valkey.primary.persistence.storageClass` | Persistent Volume storage class. | `""` |
|
||||
| `valkey.primary.persistence.size` | Persistent Volume size. | `8Gi` |
|
||||
| `valkey.replica.persistence.enabled` | Enable persistence on Valkey replicas nodes using Persistent Volume Claims. | `true` |
|
||||
| `valkey.replica.persistence.storageClass` | Persistent Volume storage class. | `""` |
|
||||
| `valkey.replica.persistence.size` | Persistent Volume size. | `8Gi` |
|
||||
| `valkey.sentinel.image.repository` | Image repository, eg. `bitnamilegacy/sentinel`. | `bitnamilegacy/valkey-sentinel` |
|
||||
| `valkey.volumePermissions.image.repository` | Image repository, eg. `bitnamilegacy/os-shell`. | `bitnamilegacy/os-shell` |
|
||||
| `valkey.image.registry` | Image registry | `docker.io` |
|
||||
| `valkey.image.repository` | Image repository | `valkey/valkey` |
|
||||
| `valkey.image.tag` | Image tag | `""` |
|
||||
| `valkey.auth.enabled` | Enable ACL-based authentication | `true` |
|
||||
| `valkey.auth.aclUsers.default.permissions` | ACL permissions for the default user | `~* &* +@all` |
|
||||
| `valkey.auth.aclUsers.default.password` | Password for the default user | `changeme` |
|
||||
| `valkey.service.port` | Port of Valkey service | `6379` |
|
||||
| `valkey.dataStorage.enabled` | Enable persistence using Persistent Volume Claims. | `false` |
|
||||
| `valkey.dataStorage.className` | Persistent Volume storage class. | `""` |
|
||||
| `valkey.dataStorage.requestedSize` | Persistent Volume size. | `8Gi` |
|
||||
| `valkey.replica.enabled` | Enable replication | `false` |
|
||||
| `valkey.replica.replicas` | Number of Valkey replica instances to deploy | `3` |
|
||||
| `valkey.replica.persistence.size` | Persistent Volume size for replicas. | `8Gi` |
|
||||
| `valkey.replica.persistence.storageClass` | Persistent Volume storage class for replicas. | `""` |
|
||||
| `valkey.metrics.enabled` | Enable Prometheus exporter sidecar | `false` |
|
||||
| `valkey.metrics.exporter.image.registry` | Image registry | `ghcr.io` |
|
||||
| `valkey.metrics.exporter.image.repository` | Image repository | `oliver006/redis_exporter` |
|
||||
| `valkey.metrics.exporter.image.tag` | Image tag | `""` |
|
||||
|
||||
### PostgreSQL HA
|
||||
|
||||
@@ -1266,6 +1459,61 @@ If you miss this, blindly upgrading may delete your Postgres instance and you ma
|
||||
|
||||
<details>
|
||||
|
||||
<summary>To 13.0.0</summary>
|
||||
|
||||
<!-- prettier-ignore-start -->
|
||||
<!-- markdownlint-disable-next-line -->
|
||||
**Breaking changes**
|
||||
<!-- prettier-ignore-end -->
|
||||
|
||||
- All Secrets created by this chart are now configured through the new `secrets` section.
|
||||
It exposes `annotations`, `labels`, a checksum-annotation toggle and an `existingSecret` reference for each of the
|
||||
`admin`, `config`, `gpg`, `init`, `inlineConfig` and `metrics` Secrets.
|
||||
- The `gitea.admin` object has been replaced by `secrets.admin`.
|
||||
The chart fails to render if `gitea.admin` is still set.
|
||||
Migrate as follows:
|
||||
|
||||
| Old | New |
|
||||
| ------------------------------ | ------------------------------------------------------------------------------------ |
|
||||
| `gitea.admin.username` | `secrets.admin.new.username` |
|
||||
| `gitea.admin.password` | `secrets.admin.new.password` |
|
||||
| `gitea.admin.email` | `secrets.admin.new.email` |
|
||||
| `gitea.admin.passwordMode` | `secrets.admin.passwordMode` |
|
||||
| `gitea.admin.existingSecret` | `secrets.admin.existingSecret.enabled` and `secrets.admin.existingSecret.secretName` |
|
||||
|
||||
The admin credentials are no longer rendered as plain environment variable values into the Deployment. They are stored
|
||||
in a dedicated Secret and consumed via `secretKeyRef` instead. The email address is part of that Secret as well, so
|
||||
Secrets referenced via `secrets.admin.existingSecret` now need an `email` key in addition to `username` and
|
||||
`password`. All three key names are configurable via `secrets.admin.existingSecret.emailKey`,
|
||||
`secrets.admin.existingSecret.passwordKey` and `secrets.admin.existingSecret.usernameKey`.
|
||||
|
||||
Admin user handling was previously skipped implicitly when neither an existing Secret nor a username and password were
|
||||
set. It is now controlled explicitly via `secrets.admin.enabled`.
|
||||
- The top-level `signing` object has been replaced by `secrets.gpg`.
|
||||
The chart fails to render if `signing` is still set.
|
||||
Migrate as follows:
|
||||
|
||||
| Old | New |
|
||||
| ------------------------ | -------------------------------------------------------------------------------- |
|
||||
| `signing.enabled` | `secrets.gpg.enabled` |
|
||||
| `signing.gpgHome` | `secrets.gpg.new.gpgHome` |
|
||||
| `signing.privateKey` | `secrets.gpg.new.privateKey` |
|
||||
| `signing.existingSecret` | `secrets.gpg.existingSecret.enabled` and `secrets.gpg.existingSecret.secretName` |
|
||||
|
||||
The `gpgHome` path is now stored in the GPG key Secret and consumed via `secretKeyRef` instead of being rendered as a
|
||||
plain environment variable value.
|
||||
Existing Secrets referenced via `secrets.gpg.existingSecret` therefore need a `gpgHome` key in addition to
|
||||
`privateKey`. Both key names are configurable via `secrets.gpg.existingSecret.gpgHomeKey` and
|
||||
`secrets.gpg.existingSecret.privateKeyKey`.
|
||||
|
||||
- Renamed the generated Secrets to make their purpose obvious:
|
||||
the config Secret changed from `<fullname>` to `<fullname>-config` and the metrics Secret from
|
||||
`<fullname>-metrics-secret` to `<fullname>-metrics`.
|
||||
|
||||
</details>
|
||||
|
||||
<details>
|
||||
|
||||
<summary>To 12.0.0</summary>
|
||||
|
||||
<!-- prettier-ignore-start -->
|
||||
@@ -1281,6 +1529,7 @@ If you miss this, blindly upgrading may delete your Postgres instance and you ma
|
||||
This change was made to avoid overloading the existing helm chart, which is already quite large in size and configuration options.
|
||||
In addition, the existing maintainers team was not actively using "Actions" which slowed down development and community contributions.
|
||||
While the new chart is still young (and waiting for contributions! and maintainers), we believe that it is the best way moving forward for both parts.
|
||||
|
||||
- Migrated from Redis/Redis-cluster to Valkey/Valkey-cluster charts (#775).
|
||||
While marked as breaking, there is no need to migrate data.
|
||||
The cache will start to refill automatically.
|
||||
@@ -1403,7 +1652,7 @@ gitea:
|
||||
<!-- prettier-ignore-end -->
|
||||
|
||||
If you are facing errors like `WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED` due to this automatic transition:
|
||||
Have a look at [this discussion](https://gitea.com/gitea/helm-gitea/issues/487#issue-220660) and either set `image.rootless: false` or manually update your `~/.ssh/known_hosts` file(s).
|
||||
Have a look at [this discussion](https://gitea.com/gitea/helm-gitea/issues/487#issue-220660) and either set `deployment.gitea.image.rootless: false` or manually update your `~/.ssh/known_hosts` file(s).
|
||||
|
||||
<!-- prettier-ignore-start -->
|
||||
<!-- markdownlint-disable-next-line -->
|
||||
@@ -1527,7 +1776,7 @@ mariadb:
|
||||
|
||||
### App.ini generation <!-- omit from toc -->
|
||||
|
||||
The app.ini generation has changed and now utilizes the environment-to-ini script provided by newer Gitea versions.
|
||||
The app.ini generation has changed and now uses the `gitea config edit-ini` subcommand introduced in Gitea 1.26.
|
||||
This change ensures, that the app.ini is now persistent.
|
||||
|
||||
### Secret Key generation <!-- omit from toc -->
|
||||
|
||||
@@ -0,0 +1,269 @@
|
||||
# Gateway API
|
||||
|
||||
This chart can expose Gitea through [Kubernetes Gateway API](https://gateway-api.sigs.k8s.io/) resources
|
||||
alongside (or instead of) the existing `Ingress` and OpenShift `Route` support. The following resources
|
||||
are rendered:
|
||||
|
||||
- `HTTPRoute` — required for HTTP traffic
|
||||
- `TCPRoute` — optional, typically for SSH (port 22)
|
||||
- `BackendTLSPolicy` — optional, for encrypted backend traffic
|
||||
- `ClientSettingsPolicy` — optional, **NGINX Gateway Fabric only**, to raise the client request body size limit
|
||||
|
||||
All resources are disabled by default. Enabling them requires Gateway API CRDs (and an implementation that supports them) to already be installed in the cluster.
|
||||
|
||||
The chart does **not** render a `Gateway` resource — provisioning and managing the Gateway is the responsibility of the cluster / platform administrator.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
| Resource | API version | Status (as of writing) |
|
||||
| ---------------------- | ------------------------------------ | ---------------------- |
|
||||
| `HTTPRoute` | `gateway.networking.k8s.io/v1` | GA |
|
||||
| `TCPRoute` | `gateway.networking.k8s.io/v1` | GA (v1.4+) |
|
||||
| `BackendTLSPolicy` | `gateway.networking.k8s.io/v1` | GA (v1.2+) |
|
||||
| `ClientSettingsPolicy` | `gateway.nginx.org/v1alpha1` | NGINX Gateway Fabric |
|
||||
|
||||
## Common topology
|
||||
|
||||
Most users should attach to a pre-existing, shared `Gateway` managed by the cluster administrator:
|
||||
|
||||
```yaml
|
||||
gatewayAPI:
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
tls: true # the shared Gateway terminates TLS
|
||||
hostnames:
|
||||
- git.example.com
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: shared-gateway
|
||||
namespace: gateway-system
|
||||
sectionName: https-gitea # pin to a specific listener (see below)
|
||||
tcpRoute:
|
||||
enabled: true
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: shared-gateway
|
||||
namespace: gateway-system
|
||||
sectionName: ssh
|
||||
```
|
||||
|
||||
With this configuration:
|
||||
|
||||
- `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` resolve to the first HTTPRoute hostname.
|
||||
- Setting `gatewayAPI.core.httpRoute.tls: true` switches `ROOT_URL` to `https://`.
|
||||
- The default HTTPRoute rule forwards `/` to the Gitea HTTP `Service`. The default TCPRoute rule forwards to the SSH `Service`.
|
||||
- Custom `rules` and `hostnames` are rendered through `tpl`, so Helm template expressions work inside them.
|
||||
|
||||
### Why `sectionName` matters
|
||||
|
||||
Omitting `sectionName` attaches the route to **every** matching listener on the Gateway. On implementations
|
||||
that use per-host HTTPS listeners (Envoy Gateway, Cilium Gateway), that means Gitea's HTTPRoute will try
|
||||
to bind to every HTTPS listener — usually not what you want. Always pin to a named listener
|
||||
(e.g. `https-gitea`, `ssh`) when the Gateway has more than one. The corresponding listener on the Gateway
|
||||
side typically looks like:
|
||||
|
||||
```yaml
|
||||
listeners:
|
||||
- name: https-gitea
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
hostname: git.example.com
|
||||
tls:
|
||||
certificateRefs:
|
||||
- name: git-example-com-tls
|
||||
allowedRoutes:
|
||||
kinds:
|
||||
- kind: HTTPRoute
|
||||
namespaces:
|
||||
from: Selector
|
||||
selector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: gitea
|
||||
- name: ssh
|
||||
port: 22
|
||||
protocol: TCP
|
||||
allowedRoutes:
|
||||
kinds:
|
||||
- kind: TCPRoute
|
||||
namespaces:
|
||||
from: Selector
|
||||
selector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: gitea
|
||||
```
|
||||
|
||||
### Sharing a hostname between HTTP and SSH
|
||||
|
||||
HTTP (443) and SSH (22) are different ports, so a single hostname like `git.example.com` can serve both —
|
||||
clients disambiguate by port. This is the recommended pattern: one DNS record, `ssh git@git.example.com`
|
||||
and `https://git.example.com` both work, and `SSH_DOMAIN` / `DOMAIN` resolve to the same value with no
|
||||
extra configuration.
|
||||
|
||||
If you want SSH on a **different** hostname (e.g. `gitea-ssh.example.com`), set it explicitly — the chart
|
||||
cannot infer it from TCPRoute config because TCPRoutes don't carry hostnames:
|
||||
|
||||
```yaml
|
||||
gitea:
|
||||
config:
|
||||
server:
|
||||
SSH_DOMAIN: gitea-ssh.example.com
|
||||
```
|
||||
|
||||
## BackendTLSPolicy
|
||||
|
||||
Use this when the Gitea HTTP backend is terminating TLS itself (for example, when running Gitea with
|
||||
`PROTOCOL=https`, or when fronting another HTTPS service from the same chart) and the Gateway needs to
|
||||
verify the backend certificate before forwarding the request.
|
||||
|
||||
### Configuring Gitea to serve HTTPS directly
|
||||
|
||||
Gitea serves HTTPS via three `[server]` app.ini options
|
||||
([cheat sheet](https://docs.gitea.com/administration/config-cheat-sheet#server-server)). Mount the
|
||||
cert/key with `deployment.volumes` + `deployment.gitea.volumeMounts` and point Gitea at them with absolute paths:
|
||||
|
||||
```yaml
|
||||
gitea:
|
||||
config:
|
||||
server:
|
||||
PROTOCOL: https
|
||||
CERT_FILE: /etc/gitea-tls/tls.crt
|
||||
KEY_FILE: /etc/gitea-tls/tls.key
|
||||
|
||||
deployment:
|
||||
gitea:
|
||||
volumeMounts:
|
||||
- name: gitea-tls
|
||||
mountPath: /etc/gitea-tls
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: gitea-tls
|
||||
secret:
|
||||
secretName: gitea-backend-tls # cert-manager-issued Secret, etc.
|
||||
```
|
||||
|
||||
- Relative `CERT_FILE`/`KEY_FILE` values resolve against Gitea's `CustomPath` (`/data/gitea` in the
|
||||
official image); absolute paths are clearer.
|
||||
- Both options are ignored when `gitea.config.server.ENABLE_ACME` is `true`.
|
||||
- For chained certs, the server cert comes first, intermediates after.
|
||||
- The Service still forwards raw TCP — no `service.http.*` changes needed. The pod's container port
|
||||
(3000 by default) is now speaking HTTPS instead of HTTP.
|
||||
|
||||
### BackendTLSPolicy example
|
||||
|
||||
Verify the backend with a CA bundle stored in a `ConfigMap`:
|
||||
|
||||
```yaml
|
||||
gatewayAPI:
|
||||
core:
|
||||
backendTLSPolicy:
|
||||
enabled: true
|
||||
validation:
|
||||
hostname: gitea.svc.cluster.local
|
||||
caCertificateRefs:
|
||||
- name: gitea-backend-ca
|
||||
group: ""
|
||||
kind: ConfigMap
|
||||
```
|
||||
|
||||
This renders a single `BackendTLSPolicy` whose `targetRefs` defaults to the chart's HTTP `Service`
|
||||
(`<fullname>-http`), and whose `validation` is passed through verbatim. `validation` is required by the
|
||||
API; the template fails fast if omitted.
|
||||
|
||||
### System CA trust and explicit targetRefs
|
||||
|
||||
To trust the system CA store (Gateway API v1.1+) or target a different Service, use `wellKnownCACertificates`
|
||||
and `targetRefs`:
|
||||
|
||||
```yaml
|
||||
gatewayAPI:
|
||||
core:
|
||||
backendTLSPolicy:
|
||||
enabled: true
|
||||
targetRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: gitea-sidecar
|
||||
validation:
|
||||
hostname: sidecar.gitea.svc.cluster.local
|
||||
wellKnownCACertificates: System
|
||||
```
|
||||
|
||||
Notes:
|
||||
|
||||
- `targetRefs[].kind` is almost always `Service`; `group: ""` is the core API group.
|
||||
- `wellKnownCACertificates: System` requires Gateway API v1.1 and an implementation that supports it
|
||||
(otherwise stick with `caCertificateRefs`).
|
||||
- The corresponding HTTPRoute must reference the backend by the same `Service` (and, if used,
|
||||
`sectionName`/`port`) — `BackendTLSPolicy` attaches to the Service-side reference, not to the route.
|
||||
|
||||
## Raising the request body size limit (NGINX Gateway Fabric)
|
||||
|
||||
NGINX defaults `client_max_body_size` to `1m`. Requests exceeding it are rejected with `413 Request
|
||||
Entity Too Large`. This blocks uploading larger artifacts to Gitea's package/container registry (container
|
||||
images, DEB/RPM packages, etc.). With the NGINX **Ingress** controller you raised this via the
|
||||
`nginx.ingress.kubernetes.io/proxy-body-size` annotation — that annotation does **not** apply to Gateway
|
||||
API. NGINX Gateway Fabric instead reads the limit from a
|
||||
[`ClientSettingsPolicy`](https://docs.nginx.com/nginx-gateway-fabric/reference/api/) (`spec.body.maxSize`).
|
||||
|
||||
This is specific to **NGINX Gateway Fabric**. Other implementations (Envoy Gateway, Cilium, Istio, …) do
|
||||
**not** impose a default request body size limit, so large uploads work without any extra configuration —
|
||||
leave `gatewayAPI.nginx.clientSettingsPolicies` disabled.
|
||||
|
||||
```yaml
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
body:
|
||||
maxSize: 100m # bytes, or with a k / m / g suffix; 0 disables the limit
|
||||
```
|
||||
|
||||
This renders a single `ClientSettingsPolicy` whose `targetRef` defaults to the chart's `HTTPRoute`
|
||||
(`<fullname>`), so the limit applies to all traffic routed to Gitea. `body` is required when enabled; the
|
||||
template fails fast if omitted. `spec.body` is passed through verbatim, so other fields (e.g. `timeout`)
|
||||
are supported too.
|
||||
|
||||
To attach the policy elsewhere — for example the whole `Gateway` so the limit is inherited by every route —
|
||||
override `targetRef`:
|
||||
|
||||
```yaml
|
||||
gatewayAPI:
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
targetRef:
|
||||
group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: shared-gateway
|
||||
body:
|
||||
maxSize: 100m
|
||||
```
|
||||
|
||||
Notes:
|
||||
|
||||
- `ClientSettingsPolicy` is an inherited policy: attaching it to a `Gateway` cascades to its routes, while
|
||||
attaching it to an `HTTPRoute` scopes it to that route only.
|
||||
- The policy must live in the same namespace as its `targetRef`.
|
||||
- Gitea also enforces its own upload limits independently (`gitea.config` `[repository.upload]` and
|
||||
`[packages]` sections) — raising the proxy limit alone is not always sufficient.
|
||||
|
||||
## Interaction with `ingress` and `route`
|
||||
|
||||
The three exposure mechanisms are independent and can coexist, but `ROOT_URL` / `DOMAIN` / `SSH_DOMAIN` resolution uses the first defined source in this order:
|
||||
|
||||
1. `route.host` (when `route.enabled`)
|
||||
2. `httpRoute.hostnames[0]` (when `gatewayAPI.core.httpRoute.enabled`)
|
||||
3. First `ingress.hosts[0].host`
|
||||
4. The in-cluster Service DNS name
|
||||
|
||||
Likewise, `ROOT_URL` becomes `https://` if any of these terminate TLS: `route.tls.termination`, `ingress.tls`, or `gatewayAPI.core.httpRoute.tls`.
|
||||
|
||||
## SSH considerations
|
||||
|
||||
- `TCPRoute` is GA since Gateway API v1.4. Older CRD bundles only ship the `v1alpha2` version, so make sure the installed CRDs are at least v1.4.
|
||||
- If your Gateway implementation does not support `TCPRoute`, keep using `service.ssh.type: LoadBalancer` (or `NodePort`) and only enable `httpRoute` for HTTP traffic.
|
||||
- The default TCPRoute rule points at the Gitea SSH `Service` on `service.ssh.port` (typically 22), which itself proxies to `gitea.config.server.SSH_LISTEN_PORT` inside the pod.
|
||||
+1
-1
@@ -14,7 +14,7 @@ They might cost a bit more than using a self-hosted k8s variant but are usually
|
||||
Also they can be centrally managed and are not linked to the Gitea helm chart or namespace.
|
||||
Please consider using external services before you start with your Gitea HA setup, it will make your life (and the life of the Gitea maintainers) easier.
|
||||
|
||||
This helm chart tries to help as much as possible to simplify and assert the provisioning of a HA-ready Gitea instance by implementing smart conditionals if `replicaCount` is set to a value > 1.
|
||||
This helm chart tries to help as much as possible to simplify and assert the provisioning of a HA-ready Gitea instance by implementing smart conditionals if `deployment.replicas` is set to a value > 1.
|
||||
Nevertheless, we cannot guarantee for every possible combination of Gitea settings to work together perfectly in a HA setup.
|
||||
As a general advice, we recommend to have a test environment aside on which to test possible changes/upgrades before applying these to a production installation.
|
||||
|
||||
|
||||
Generated
+87
-57
@@ -8,7 +8,7 @@
|
||||
"license": "MIT",
|
||||
"devDependencies": {
|
||||
"@bitnami/readme-generator-for-helm": "^2.5.0",
|
||||
"markdownlint-cli": "^0.48.0"
|
||||
"markdownlint-cli": "^0.49.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=16.0.0",
|
||||
@@ -91,9 +91,9 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/brace-expansion": {
|
||||
"version": "1.1.14",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz",
|
||||
"integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==",
|
||||
"version": "1.1.16",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.16.tgz",
|
||||
"integrity": "sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -280,9 +280,9 @@
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/get-east-asian-width": {
|
||||
"version": "1.5.0",
|
||||
"resolved": "https://registry.npmjs.org/get-east-asian-width/-/get-east-asian-width-1.5.0.tgz",
|
||||
"integrity": "sha512-CQ+bEO+Tva/qlmw24dCejulK5pMzVnUOFOijVogd3KQs07HnRIgp8TGipvCCRT06xeYEbpbgwaCxglFyiuIcmA==",
|
||||
"version": "1.6.0",
|
||||
"resolved": "https://registry.npmjs.org/get-east-asian-width/-/get-east-asian-width-1.6.0.tgz",
|
||||
"integrity": "sha512-QRbvDIbx6YklUe6RxeTeleMR0yv3cYH6PsPZHcnVn7xv7zO1BHN8r0XETu8n6Ye3Q+ahtSarc3WgtNWmehIBfA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
@@ -402,10 +402,20 @@
|
||||
}
|
||||
},
|
||||
"node_modules/js-yaml": {
|
||||
"version": "4.1.1",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz",
|
||||
"integrity": "sha512-qQKT4zQxXl8lLwBtHMWwaTcGfFOZviOJet3Oy/xmGk2gZH677CJM9EvtfdSkgWcATZhj/55JZ0rmy3myCT5lsA==",
|
||||
"version": "4.2.0",
|
||||
"resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.2.0.tgz",
|
||||
"integrity": "sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/nodeca"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^2.0.1"
|
||||
@@ -432,9 +442,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/katex": {
|
||||
"version": "0.16.45",
|
||||
"resolved": "https://registry.npmjs.org/katex/-/katex-0.16.45.tgz",
|
||||
"integrity": "sha512-pQpZbdBu7wCTmQUh7ufPmLr0pFoObnGUoL/yhtwJDgmmQpbkg/0HSVti25Fu4rmd1oCR6NGWe9vqTWuWv3GcNA==",
|
||||
"version": "0.16.47",
|
||||
"resolved": "https://registry.npmjs.org/katex/-/katex-0.16.47.tgz",
|
||||
"integrity": "sha512-Eeo8Ys1doU1z+x8AZsPpQu+p/QcZBI5PeOo7QGQdy2x2m0MU/hYagBbGOmXwr5KVbEfVuWv9LpnQWeehogurjg==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
"https://opencollective.com/katex",
|
||||
@@ -459,10 +469,20 @@
|
||||
}
|
||||
},
|
||||
"node_modules/linkify-it": {
|
||||
"version": "5.0.0",
|
||||
"resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.0.tgz",
|
||||
"integrity": "sha512-5aHCbzQRADcdP+ATqnDuhhJ/MRIqDkZX5pyjFHRRysS8vZ5AbqGEoFIb6pYHPZ+L/OC2Lc+xT8uHVVR5CAK/wQ==",
|
||||
"version": "5.0.2",
|
||||
"resolved": "https://registry.npmjs.org/linkify-it/-/linkify-it-5.0.2.tgz",
|
||||
"integrity": "sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/markdown-it"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"uc.micro": "^2.0.0"
|
||||
@@ -476,15 +496,25 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/markdown-it": {
|
||||
"version": "14.1.1",
|
||||
"resolved": "https://registry.npmjs.org/markdown-it/-/markdown-it-14.1.1.tgz",
|
||||
"integrity": "sha512-BuU2qnTti9YKgK5N+IeMubp14ZUKUUw7yeJbkjtosvHiP0AZ5c8IAgEMk79D0eC8F23r4Ac/q8cAIFdm2FtyoA==",
|
||||
"version": "14.2.0",
|
||||
"resolved": "https://registry.npmjs.org/markdown-it/-/markdown-it-14.2.0.tgz",
|
||||
"integrity": "sha512-1TGiQiJVRQ3NPmZH6sx5Cfnmg6GQm9jvC1ch4TK511NjSJvjzKLzn5pPfZRNZkRPZP0HqCioSndqH8v2nRaWVQ==",
|
||||
"dev": true,
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/puzrin"
|
||||
},
|
||||
{
|
||||
"type": "github",
|
||||
"url": "https://github.com/sponsors/markdown-it"
|
||||
}
|
||||
],
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"argparse": "^2.0.1",
|
||||
"entities": "^4.4.0",
|
||||
"linkify-it": "^5.0.0",
|
||||
"linkify-it": "^5.0.1",
|
||||
"mdurl": "^2.0.0",
|
||||
"punycode.js": "^2.3.1",
|
||||
"uc.micro": "^2.1.0"
|
||||
@@ -508,9 +538,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/markdownlint": {
|
||||
"version": "0.40.0",
|
||||
"resolved": "https://registry.npmjs.org/markdownlint/-/markdownlint-0.40.0.tgz",
|
||||
"integrity": "sha512-UKybllYNheWac61Ia7T6fzuQNDZimFIpCg2w6hHjgV1Qu0w1TV0LlSgryUGzM0bkKQCBhy2FDhEELB73Kb0kAg==",
|
||||
"version": "0.41.0",
|
||||
"resolved": "https://registry.npmjs.org/markdownlint/-/markdownlint-0.41.0.tgz",
|
||||
"integrity": "sha512-xMUI3ChBuRuxuLF4ENvCZyS8z/+Jly1coUcZwErKLIB3sDj7ojpaTBa1e9YVPhSN4jGEIjYGQCldbTJS/hqS+A==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -522,40 +552,40 @@
|
||||
"micromark-extension-gfm-table": "2.1.1",
|
||||
"micromark-extension-math": "3.1.0",
|
||||
"micromark-util-types": "2.0.2",
|
||||
"string-width": "8.1.0"
|
||||
"string-width": "8.2.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=20"
|
||||
"node": ">=22"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/DavidAnson"
|
||||
}
|
||||
},
|
||||
"node_modules/markdownlint-cli": {
|
||||
"version": "0.48.0",
|
||||
"resolved": "https://registry.npmjs.org/markdownlint-cli/-/markdownlint-cli-0.48.0.tgz",
|
||||
"integrity": "sha512-NkZQNu2E0Q5qLEEHwWj674eYISTLD4jMHkBzDobujXd1kv+yCxi8jOaD/rZoQNW1FBBMMGQpuW5So8B51N/e0A==",
|
||||
"version": "0.49.0",
|
||||
"resolved": "https://registry.npmjs.org/markdownlint-cli/-/markdownlint-cli-0.49.0.tgz",
|
||||
"integrity": "sha512-vS5tWq5W91Gg33LD4pyAaXPclnz/sRvo6/RGOyDQjQ3eds2DkK6H4szUuE0M9TiRB/u/VBx1gtd9Ktrtx5WlSA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"commander": "~14.0.3",
|
||||
"commander": "~15.0.0",
|
||||
"deep-extend": "~0.6.0",
|
||||
"ignore": "~7.0.5",
|
||||
"js-yaml": "~4.1.1",
|
||||
"js-yaml": "~4.2.0",
|
||||
"jsonc-parser": "~3.3.1",
|
||||
"jsonpointer": "~5.0.1",
|
||||
"markdown-it": "~14.1.1",
|
||||
"markdownlint": "~0.40.0",
|
||||
"minimatch": "~10.2.4",
|
||||
"markdown-it": "~14.2.0",
|
||||
"markdownlint": "~0.41.0",
|
||||
"minimatch": "~10.2.5",
|
||||
"run-con": "~1.3.2",
|
||||
"smol-toml": "~1.6.0",
|
||||
"tinyglobby": "~0.2.15"
|
||||
"smol-toml": "~1.6.1",
|
||||
"tinyglobby": "~0.2.17"
|
||||
},
|
||||
"bin": {
|
||||
"markdownlint": "markdownlint.js"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=20"
|
||||
"node": ">=22"
|
||||
}
|
||||
},
|
||||
"node_modules/markdownlint-cli/node_modules/balanced-match": {
|
||||
@@ -569,9 +599,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/markdownlint-cli/node_modules/brace-expansion": {
|
||||
"version": "5.0.5",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.5.tgz",
|
||||
"integrity": "sha512-VZznLgtwhn+Mact9tfiwx64fA9erHH/MCXEUfB/0bX/6Fz6ny5EGTXYltMocqg4xFAQZtnO3DHWWXi8RiuN7cQ==",
|
||||
"version": "5.0.7",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.7.tgz",
|
||||
"integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -582,13 +612,13 @@
|
||||
}
|
||||
},
|
||||
"node_modules/markdownlint-cli/node_modules/commander": {
|
||||
"version": "14.0.3",
|
||||
"resolved": "https://registry.npmjs.org/commander/-/commander-14.0.3.tgz",
|
||||
"integrity": "sha512-H+y0Jo/T1RZ9qPP4Eh1pkcQcLRglraJaSLoyOtHxu6AapkjWVCy2Sit1QQ4x3Dng8qDlSsZEet7g5Pq06MvTgw==",
|
||||
"version": "15.0.0",
|
||||
"resolved": "https://registry.npmjs.org/commander/-/commander-15.0.0.tgz",
|
||||
"integrity": "sha512-z67u4ZhzCL/Tydu1lJARtEZYWbWaN7oYLHbsuzocr6y4N6WZAagG3RQ4FW61V1/0+jImpj293XfrcYnd1qxtPg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=20"
|
||||
"node": ">=22.12.0"
|
||||
}
|
||||
},
|
||||
"node_modules/markdownlint-cli/node_modules/minimatch": {
|
||||
@@ -1221,9 +1251,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/picomatch": {
|
||||
"version": "4.0.4",
|
||||
"resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.4.tgz",
|
||||
"integrity": "sha512-QP88BAKvMam/3NxH6vj2o21R6MjxZUAd6nlwAS/pnGvN9IVLocLHxGYIzFhg6fUQ+5th6P4dv4eW9jX3DSIj7A==",
|
||||
"version": "4.0.5",
|
||||
"resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.5.tgz",
|
||||
"integrity": "sha512-RvwwcruNjI1ncT5xRakeyS9Lf8lcItv34KD+aif+VH9kduAyfYBipGh12274xtenIPZ119/R9BdTBa8gAwSh0A==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
@@ -1283,14 +1313,14 @@
|
||||
}
|
||||
},
|
||||
"node_modules/string-width": {
|
||||
"version": "8.1.0",
|
||||
"resolved": "https://registry.npmjs.org/string-width/-/string-width-8.1.0.tgz",
|
||||
"integrity": "sha512-Kxl3KJGb/gxkaUMOjRsQ8IrXiGW75O4E3RPjFIINOVH8AMl2SQ/yWdTzWwF3FevIX9LcMAjJW+GRwAlAbTSXdg==",
|
||||
"version": "8.2.1",
|
||||
"resolved": "https://registry.npmjs.org/string-width/-/string-width-8.2.1.tgz",
|
||||
"integrity": "sha512-IIaP0g3iy9Cyy18w3M9YcaDudujEAVHKt3a3QJg1+sr/oX96TbaGUubG0hJyCjCBThFH+tFpcIyoUHUn1ogaLA==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"get-east-asian-width": "^1.3.0",
|
||||
"strip-ansi": "^7.1.0"
|
||||
"get-east-asian-width": "^1.5.0",
|
||||
"strip-ansi": "^7.1.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=20"
|
||||
@@ -1329,9 +1359,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/tinyglobby": {
|
||||
"version": "0.2.16",
|
||||
"resolved": "https://registry.npmjs.org/tinyglobby/-/tinyglobby-0.2.16.tgz",
|
||||
"integrity": "sha512-pn99VhoACYR8nFHhxqix+uvsbXineAasWm5ojXoN8xEwK5Kd3/TrhNn1wByuD52UxWRLy8pu+kRMniEi6Eq9Zg==",
|
||||
"version": "0.2.17",
|
||||
"resolved": "https://registry.npmjs.org/tinyglobby/-/tinyglobby-0.2.17.tgz",
|
||||
"integrity": "sha512-wXR/dYpcqKmfWpEdZjiKJOwCNFndD0DMnrW/cYjVGttEkBfVgcLFHoNrlj47mjOVic9yyNu65alsgF4NQyTa2g==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -1360,9 +1390,9 @@
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/yaml": {
|
||||
"version": "2.8.3",
|
||||
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.8.3.tgz",
|
||||
"integrity": "sha512-AvbaCLOO2Otw/lW5bmh9d/WEdcDFdQp2Z2ZUH3pX9U2ihyUY0nvLv7J6TrWowklRGPYbB/IuIMfYgxaCPg5Bpg==",
|
||||
"version": "2.9.0",
|
||||
"resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.0.tgz",
|
||||
"integrity": "sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==",
|
||||
"dev": true,
|
||||
"license": "ISC",
|
||||
"bin": {
|
||||
|
||||
+1
-1
@@ -14,6 +14,6 @@
|
||||
},
|
||||
"devDependencies": {
|
||||
"@bitnami/readme-generator-for-helm": "^2.5.0",
|
||||
"markdownlint-cli": "^0.48.0"
|
||||
"markdownlint-cli": "^0.49.0"
|
||||
}
|
||||
}
|
||||
+56
-52
@@ -1,51 +1,55 @@
|
||||
{
|
||||
$schema: 'https://docs.renovatebot.com/renovate-schema.json',
|
||||
$schema: "https://docs.renovatebot.com/renovate-schema.json",
|
||||
extends: [
|
||||
'gitea>gitea/renovate-config',
|
||||
':automergeMinor',
|
||||
'schedule:automergeDaily',
|
||||
'schedule:weekends',
|
||||
"gitea>gitea/renovate-config",
|
||||
"helpers:pinGitHubActionDigests",
|
||||
":automergeMinor",
|
||||
"schedule:automergeDaily",
|
||||
"schedule:weekends",
|
||||
],
|
||||
labels: [
|
||||
'kind/dependency',
|
||||
"kind/dependency",
|
||||
],
|
||||
digest: {
|
||||
automerge: true,
|
||||
},
|
||||
automergeStrategy: 'squash',
|
||||
'git-submodules': {
|
||||
automergeStrategy: "squash",
|
||||
"git-submodules": {
|
||||
enabled: true,
|
||||
},
|
||||
customManagers: [
|
||||
{
|
||||
description: 'Gitea-version of https://docs.renovatebot.com/presets-regexManagers/#regexmanagersgithubactionsversions',
|
||||
customType: 'regex',
|
||||
description: "Gitea-version of https://docs.renovatebot.com/presets-regexManagers/#regexmanagersgithubactionsversions",
|
||||
customType: "regex",
|
||||
managerFilePatterns: [
|
||||
'/.gitea/workflows/.+\\.ya?ml$/',
|
||||
"/.gitea/workflows/.+\\.ya?ml$/",
|
||||
],
|
||||
matchStrings: [
|
||||
'# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?_VERSION\\s*:\\s*["\']?(?<currentValue>.+?)["\']?\\s',
|
||||
"# renovate: datasource=(?<datasource>[a-z-.]+?) depName=(?<depName>[^\\s]+?)(?: (?:lookupName|packageName)=(?<packageName>[^\\s]+?))?(?: versioning=(?<versioning>[a-z-0-9]+?))?\\s+[A-Za-z0-9_]+?_VERSION\\s*:\\s*[\"']?(?<currentValue>.+?)[\"']?\\s",
|
||||
],
|
||||
},
|
||||
{
|
||||
description: 'Detect helm-unittest yaml schema file',
|
||||
customType: 'regex',
|
||||
description: "Detect helm-unittest yaml schema file",
|
||||
customType: "regex",
|
||||
managerFilePatterns: [
|
||||
'/.vscode/settings\\.json$/',
|
||||
"/.vscode/settings\\.json$/",
|
||||
],
|
||||
matchStrings: [
|
||||
'https:\\/\\/raw\\.githubusercontent\\.com\\/(?<depName>[^\\s]+?)\\/(?<currentValue>v[0-9.]+?)\\/schema\\/helm-testsuite\\.json',
|
||||
"https:\\/\\/raw\\.githubusercontent\\.com\\/(?<depName>[^\\s]+?)\\/(?<currentValue>v[0-9.]+?)\\/schema\\/helm-testsuite\\.json",
|
||||
],
|
||||
datasourceTemplate: 'github-releases',
|
||||
datasourceTemplate: "github-releases",
|
||||
},
|
||||
{
|
||||
description: 'Automatically detect new Gitea releases',
|
||||
customType: 'regex',
|
||||
description: "Automatically detect new Gitea releases",
|
||||
customType: "regex",
|
||||
datasourceTemplate: "github-releases",
|
||||
depNameTemplate: "gitea/gitea",
|
||||
extractVersionTemplate: "^v(?<version>.*)$",
|
||||
managerFilePatterns: [
|
||||
'/(^|/)Chart\\.yaml$/',
|
||||
"/(^|/)Chart\\.ya?ml$/",
|
||||
],
|
||||
matchStrings: [
|
||||
'# renovate datasource=(?<datasource>\\S+) depName=(?<depName>\\S+) extractVersion=(?<extractVersion>\\S+)\\nappVersion:\\s?(?<currentValue>\\S+)\\n',
|
||||
"^appVersion:\\s+[\"']?(?<currentVersion>\\S+)[\"']?$",
|
||||
],
|
||||
},
|
||||
],
|
||||
@@ -54,78 +58,78 @@
|
||||
"commitMessageAction": "update",
|
||||
"commitMessageTopic": "lockfiles",
|
||||
schedule: [
|
||||
'at any time',
|
||||
"at any time",
|
||||
]
|
||||
},
|
||||
packageRules: [
|
||||
{
|
||||
groupName: 'subcharts (minor & patch)',
|
||||
groupName: "subcharts (minor & patch)",
|
||||
matchManagers: [
|
||||
'helmv3',
|
||||
"helmv3",
|
||||
],
|
||||
matchUpdateTypes: [
|
||||
'minor',
|
||||
'patch',
|
||||
'digest',
|
||||
"minor",
|
||||
"patch",
|
||||
"digest",
|
||||
],
|
||||
},
|
||||
{
|
||||
groupName: 'bats testing framework',
|
||||
groupName: "bats testing framework",
|
||||
matchManagers: [
|
||||
'git-submodules',
|
||||
"git-submodules",
|
||||
],
|
||||
matchUpdateTypes: [
|
||||
'minor',
|
||||
'patch',
|
||||
'digest',
|
||||
"minor",
|
||||
"patch",
|
||||
"digest",
|
||||
],
|
||||
},
|
||||
{
|
||||
groupName: 'workflow dependencies (minor & patch)',
|
||||
groupName: "workflow dependencies (minor & patch)",
|
||||
matchManagers: [
|
||||
'github-actions',
|
||||
'npm',
|
||||
'custom.regex',
|
||||
"github-actions",
|
||||
"npm",
|
||||
"custom.regex",
|
||||
],
|
||||
matchUpdateTypes: [
|
||||
'minor',
|
||||
'patch',
|
||||
'digest',
|
||||
"minor",
|
||||
"patch",
|
||||
"digest",
|
||||
],
|
||||
matchFileNames: [
|
||||
'!Chart.yaml',
|
||||
"!Chart.yaml",
|
||||
],
|
||||
},
|
||||
{
|
||||
description: 'Update README.md on changes in values.yaml',
|
||||
description: "Update README.md on changes in values.yaml",
|
||||
matchManagers: [
|
||||
'helm-values',
|
||||
"helm-values",
|
||||
],
|
||||
postUpgradeTasks: {
|
||||
commands: [
|
||||
'install-tool node',
|
||||
'make readme',
|
||||
"install-tool node",
|
||||
"make readme",
|
||||
],
|
||||
fileFilters: [
|
||||
'README.md',
|
||||
"README.md",
|
||||
],
|
||||
executionMode: 'update',
|
||||
executionMode: "update",
|
||||
},
|
||||
},
|
||||
{
|
||||
description: 'Override changelog url for Helm image, to have release notes in our PRs',
|
||||
description: "Override changelog url for Helm image, to have release notes in our PRs",
|
||||
matchDepNames: [
|
||||
'alpine/helm',
|
||||
"alpine/helm",
|
||||
],
|
||||
changelogUrl: 'https://github.com/helm/helm',
|
||||
changelogUrl: "https://github.com/helm/helm",
|
||||
},
|
||||
{
|
||||
description: 'Bump Gitea as fast as possible - not only on weekends',
|
||||
description: "Bump Gitea as fast as possible - not only on weekends",
|
||||
matchDepNames: [
|
||||
'go-gitea/gitea',
|
||||
"go-gitea/gitea",
|
||||
],
|
||||
schedule: [
|
||||
'at any time',
|
||||
"at any time",
|
||||
],
|
||||
},
|
||||
],
|
||||
|
||||
@@ -78,7 +78,6 @@ function env2ini::reload_preset_envs() {
|
||||
rm $TMP_EXISTING_ENVS_FILE
|
||||
}
|
||||
|
||||
|
||||
function env2ini::process_config_file() {
|
||||
local config_file="${1}"
|
||||
local section="$(basename "${config_file}")"
|
||||
@@ -151,4 +150,4 @@ if [ -f ${GITEA_APP_INI} ]; then
|
||||
unset GITEA__SERVER__LFS_JWT_SECRET
|
||||
fi
|
||||
|
||||
environment-to-ini -o $GITEA_APP_INI
|
||||
gitea config edit-ini --apply-env --config "$GITEA_APP_INI" --out "$GITEA_APP_INI"
|
||||
|
||||
+8
-1
@@ -1,5 +1,12 @@
|
||||
1. Get the application URL by running these commands:
|
||||
{{- if .Values.ingress.enabled }}
|
||||
{{- if .Values.route.enabled }}
|
||||
{{- if .Values.route.host }}
|
||||
{{ include "gitea.public_protocol" . }}://{{ tpl .Values.route.host . }}{{ .Values.route.path }}
|
||||
{{- else }}
|
||||
export ROUTE_HOST=$(kubectl get route --namespace {{ .Release.Namespace }} {{ include "gitea.fullname" . }} -o jsonpath="{.spec.host}")
|
||||
echo {{ include "gitea.public_protocol" . }}://$ROUTE_HOST{{ .Values.route.path }}
|
||||
{{- end }}
|
||||
{{- else if .Values.ingress.enabled }}
|
||||
{{- range $host := .Values.ingress.hosts }}
|
||||
{{- range .paths }}
|
||||
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }}
|
||||
|
||||
+117
-51
@@ -43,15 +43,25 @@ Create chart name and version as used by the chart label.
|
||||
Create image name and tag used by the deployment.
|
||||
*/}}
|
||||
{{- define "gitea.image" -}}
|
||||
{{- $fullOverride := .Values.image.fullOverride | default "" -}}
|
||||
{{- $registry := .Values.global.imageRegistry | default .Values.image.registry -}}
|
||||
{{- $repository := .Values.image.repository -}}
|
||||
{{- include "gitea.image.name" (list . .Values.deployment.gitea.image) -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Create image name and tag from an arbitrary `image` dict.
|
||||
Arguments: (list $root $image)
|
||||
*/}}
|
||||
{{- define "gitea.image.name" -}}
|
||||
{{- $root := index . 0 -}}
|
||||
{{- $image := index . 1 -}}
|
||||
{{- $fullOverride := $image.fullOverride | default "" -}}
|
||||
{{- $registry := $root.Values.global.imageRegistry | default $image.registry -}}
|
||||
{{- $repository := $image.repository -}}
|
||||
{{- $separator := ":" -}}
|
||||
{{- $tag := .Values.image.tag | default .Chart.AppVersion | toString -}}
|
||||
{{- $rootless := ternary "-rootless" "" (.Values.image.rootless) -}}
|
||||
{{- $tag := $image.tag | default $root.Chart.AppVersion | toString -}}
|
||||
{{- $rootless := ternary "-rootless" "" ($image.rootless) -}}
|
||||
{{- $digest := "" -}}
|
||||
{{- if .Values.image.digest }}
|
||||
{{- $digest = (printf "@%s" (.Values.image.digest | toString)) -}}
|
||||
{{- if $image.digest }}
|
||||
{{- $digest = (printf "@%s" ($image.digest | toString)) -}}
|
||||
{{- end -}}
|
||||
{{- if $fullOverride }}
|
||||
{{- printf "%s" $fullOverride -}}
|
||||
@@ -76,6 +86,74 @@ imagePullSecrets:
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Return true when OpenShift compatibility defaults should be rendered.
|
||||
If openshift.enabled is unset, auto-detect via the SCC API.
|
||||
*/}}
|
||||
{{- define "gitea.openshift.enabled" -}}
|
||||
{{- if kindIs "bool" .Values.openshift.enabled -}}
|
||||
{{ ternary "true" "false" .Values.openshift.enabled }}
|
||||
{{- else if .Capabilities.APIVersions.Has "security.openshift.io/v1/SecurityContextConstraints" -}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Return the pod's hostUsers setting. Renders nothing unless explicitly set to a boolean.
|
||||
*/}}
|
||||
{{- define "gitea.hostUsers" -}}
|
||||
{{- if kindIs "bool" .Values.deployment.hostUsers -}}
|
||||
{{ ternary "true" "false" .Values.deployment.hostUsers }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Render pod securityContext. On non-OpenShift clusters an empty map defaults fsGroup to 1000.
|
||||
*/}}
|
||||
{{- define "gitea.deployment.securityContext" -}}
|
||||
{{- $securityContext := deepCopy .Values.deployment.securityContext -}}
|
||||
{{- if and (ne (include "gitea.openshift.enabled" . | trim) "true") (not (hasKey $securityContext "fsGroup")) -}}
|
||||
{{- $_ := set $securityContext "fsGroup" 1000 -}}
|
||||
{{- end -}}
|
||||
{{- if gt (len $securityContext) 0 -}}
|
||||
{{ toYaml $securityContext }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Render container securityContext with OpenShift restricted SCC defaults when enabled.
|
||||
*/}}
|
||||
{{- define "gitea.containerSecurityContext" -}}
|
||||
{{- $root := index . 0 -}}
|
||||
{{- $containerSecurityContext := deepCopy (index . 1) -}}
|
||||
{{- if eq (include "gitea.openshift.enabled" $root | trim) "true" -}}
|
||||
{{- $containerSecurityContext = mergeOverwrite (dict
|
||||
"allowPrivilegeEscalation" false
|
||||
"capabilities" (dict "drop" (list "ALL"))
|
||||
"runAsNonRoot" true
|
||||
"seccompProfile" (dict "type" "RuntimeDefault")
|
||||
) $containerSecurityContext -}}
|
||||
{{- end -}}
|
||||
{{- if gt (len $containerSecurityContext) 0 -}}
|
||||
{{ toYaml $containerSecurityContext }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Render the securityContext for init containers that execute Gitea/GPG commands.
|
||||
These default to runAsUser 1000 outside OpenShift to preserve existing behavior.
|
||||
*/}}
|
||||
{{- define "gitea.commandInitContainerSecurityContext" -}}
|
||||
{{- $root := index . 0 -}}
|
||||
{{- $containerSecurityContext := deepCopy (index . 1) -}}
|
||||
{{- if and (ne (include "gitea.openshift.enabled" $root | trim) "true") (not (hasKey $containerSecurityContext "runAsUser")) -}}
|
||||
{{- $_ := set $containerSecurityContext "runAsUser" 1000 -}}
|
||||
{{- end -}}
|
||||
{{- include "gitea.containerSecurityContext" (list $root $containerSecurityContext) -}}
|
||||
{{- end -}}
|
||||
|
||||
|
||||
{{/*
|
||||
Storage Class
|
||||
@@ -94,8 +172,8 @@ Common labels
|
||||
helm.sh/chart: {{ include "gitea.chart" . }}
|
||||
app: {{ include "gitea.name" . }}
|
||||
{{ include "gitea.selectorLabels" . }}
|
||||
app.kubernetes.io/version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
||||
version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/version: {{ .Values.deployment.gitea.image.tag | default .Chart.AppVersion | quote }}
|
||||
version: {{ .Values.deployment.gitea.image.tag | default .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end -}}
|
||||
|
||||
@@ -103,8 +181,8 @@ app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
helm.sh/chart: {{ include "gitea.chart" . }}
|
||||
app: {{ include "gitea.name" . }}-act-runner
|
||||
{{ include "gitea.selectorLabels.actRunner" . }}
|
||||
app.kubernetes.io/version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
||||
version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/version: {{ .Values.deployment.gitea.image.tag | default .Chart.AppVersion | quote }}
|
||||
version: {{ .Values.deployment.gitea.image.tag | default .Chart.AppVersion | quote }}
|
||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||
{{- end -}}
|
||||
|
||||
@@ -134,28 +212,20 @@ app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "valkey.dns" -}}
|
||||
{{- if and ((index .Values "valkey-cluster").enabled) ((index .Values "valkey").enabled) -}}
|
||||
{{- fail "valkey and valkey-cluster cannot be enabled at the same time. Please only choose one." -}}
|
||||
{{- else if (index .Values "valkey-cluster").enabled -}}
|
||||
{{- printf "redis+cluster://:%s@%s-valkey-cluster-headless.%s.svc.%s:%g/0?pool_size=100&idle_timeout=180s&" (index .Values "valkey-cluster").global.valkey.password .Release.Name .Release.Namespace .Values.clusterDomain (index .Values "valkey-cluster").service.ports.valkey -}}
|
||||
{{- else if (index .Values "valkey").enabled -}}
|
||||
{{- printf "redis://:%s@%s-valkey-headless.%s.svc.%s:%g/0?pool_size=100&idle_timeout=180s&" (index .Values "valkey").global.valkey.password .Release.Name .Release.Namespace .Values.clusterDomain (index .Values "valkey").master.service.ports.valkey -}}
|
||||
{{- if (index .Values "valkey").enabled -}}
|
||||
{{- printf "redis://:%s@%s-valkey.%s.svc.%s:%g/0?pool_size=100&idle_timeout=180s&" (index (index .Values "valkey").auth.aclUsers "default").password .Release.Name .Release.Namespace .Values.clusterDomain (index .Values "valkey").service.port -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "valkey.port" -}}
|
||||
{{- if (index .Values "valkey-cluster").enabled -}}
|
||||
{{ (index .Values "valkey-cluster").service.ports.valkey }}
|
||||
{{- else if (index .Values "valkey").enabled -}}
|
||||
{{ (index .Values "valkey").master.service.ports.valkey }}
|
||||
{{- if (index .Values "valkey").enabled -}}
|
||||
{{ (index .Values "valkey").service.port }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "valkey.servicename" -}}
|
||||
{{- if (index .Values "valkey-cluster").enabled -}}
|
||||
{{- printf "%s-valkey-cluster-headless.%s.svc.%s" .Release.Name .Release.Namespace .Values.clusterDomain -}}
|
||||
{{- else if (index .Values "valkey").enabled -}}
|
||||
{{- printf "%s-valkey-headless.%s.svc.%s" .Release.Name .Release.Namespace .Values.clusterDomain -}}
|
||||
{{- if (index .Values "valkey").enabled -}}
|
||||
{{- printf "%s-valkey.%s.svc.%s" .Release.Name .Release.Namespace .Values.clusterDomain -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -163,6 +233,18 @@ app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- printf "%s-http.%s.svc.%s" (include "gitea.fullname" .) .Release.Namespace .Values.clusterDomain -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.public_hostname" -}}
|
||||
{{- if and .Values.route.enabled .Values.route.host -}}
|
||||
{{ tpl .Values.route.host . }}
|
||||
{{- else if and .Values.gatewayAPI.enabled .Values.gatewayAPI.core.httpRoute.enabled (gt (len .Values.gatewayAPI.core.httpRoute.hostnames) 0) -}}
|
||||
{{ tpl (index .Values.gatewayAPI.core.httpRoute.hostnames 0) $ }}
|
||||
{{- else if gt (len .Values.ingress.hosts) 0 -}}
|
||||
{{ tpl (index .Values.ingress.hosts 0).host $ }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.default_domain" . }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.ldap_settings" -}}
|
||||
{{- $idx := index . 0 }}
|
||||
{{- $values := index . 1 }}
|
||||
@@ -213,7 +295,11 @@ app.kubernetes.io/instance: {{ .Release.Name }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.public_protocol" -}}
|
||||
{{- if and .Values.ingress.enabled (gt (len .Values.ingress.tls) 0) -}}
|
||||
{{- if and .Values.route.enabled .Values.route.tls.termination -}}
|
||||
https
|
||||
{{- else if and .Values.ingress.enabled (gt (len .Values.ingress.tls) 0) -}}
|
||||
https
|
||||
{{- else if and .Values.gatewayAPI.enabled .Values.gatewayAPI.core.httpRoute.enabled .Values.gatewayAPI.core.httpRoute.tls -}}
|
||||
https
|
||||
{{- else -}}
|
||||
{{ .Values.gitea.config.server.PROTOCOL }}
|
||||
@@ -306,7 +392,7 @@ https
|
||||
{{- $_ := set .Values.gitea.config.metrics "TOKEN" .Values.gitea.metrics.token -}}
|
||||
{{- end -}}
|
||||
{{- /* valkey queue */ -}}
|
||||
{{- if or ((index .Values "valkey-cluster").enabled) ((index .Values "valkey").enabled) -}}
|
||||
{{- if (index .Values "valkey").enabled -}}
|
||||
{{- $_ := set .Values.gitea.config.queue "TYPE" "redis" -}}
|
||||
{{- $_ := set .Values.gitea.config.queue "CONN_STR" (include "valkey.dns" .) -}}
|
||||
{{- $_ := set .Values.gitea.config.session "PROVIDER" "redis" -}}
|
||||
@@ -346,11 +432,7 @@ https
|
||||
{{- $_ := set .Values.gitea.config.server "PROTOCOL" "http" -}}
|
||||
{{- end -}}
|
||||
{{- if not (.Values.gitea.config.server.DOMAIN) -}}
|
||||
{{- if gt (len .Values.ingress.hosts) 0 -}}
|
||||
{{- $_ := set .Values.gitea.config.server "DOMAIN" ( tpl (index .Values.ingress.hosts 0).host $) -}}
|
||||
{{- else -}}
|
||||
{{- $_ := set .Values.gitea.config.server "DOMAIN" (include "gitea.default_domain" .) -}}
|
||||
{{- end -}}
|
||||
{{- $_ := set .Values.gitea.config.server "DOMAIN" (include "gitea.public_hostname" .) -}}
|
||||
{{- end -}}
|
||||
{{- if not .Values.gitea.config.server.ROOT_URL -}}
|
||||
{{- $_ := set .Values.gitea.config.server "ROOT_URL" (printf "%s://%s" (include "gitea.public_protocol" .) .Values.gitea.config.server.DOMAIN) -}}
|
||||
@@ -362,7 +444,7 @@ https
|
||||
{{- $_ := set .Values.gitea.config.server "SSH_PORT" .Values.service.ssh.port -}}
|
||||
{{- end -}}
|
||||
{{- if not (hasKey .Values.gitea.config.server "START_SSH_SERVER") -}}
|
||||
{{- if .Values.image.rootless -}}
|
||||
{{- if .Values.deployment.gitea.image.rootless -}}
|
||||
{{- $_ := set .Values.gitea.config.server "START_SSH_SERVER" "true" -}}
|
||||
{{- if not (hasKey .Values.gitea.config.server "SSH_LISTEN_PORT") -}}
|
||||
{{- if not .Values.gitea.config.server.SSH_LISTEN_PORT -}}
|
||||
@@ -415,17 +497,13 @@ https
|
||||
|
||||
{{- define "gitea.container-additional-mounts" -}}
|
||||
{{- /* Honor the deprecated extraVolumeMounts variable when defined */ -}}
|
||||
{{- if gt (len .Values.extraContainerVolumeMounts) 0 -}}
|
||||
{{- toYaml .Values.extraContainerVolumeMounts -}}
|
||||
{{- if gt (len .Values.deployment.gitea.volumeMounts) 0 -}}
|
||||
{{- toYaml .Values.deployment.gitea.volumeMounts -}}
|
||||
{{- else if gt (len .Values.extraVolumeMounts) 0 -}}
|
||||
{{- toYaml .Values.extraVolumeMounts -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.gpg-key-secret-name" -}}
|
||||
{{ default (printf "%s-gpg-key" (include "gitea.fullname" .)) .Values.signing.existingSecret }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.serviceAccountName" -}}
|
||||
{{ .Values.serviceAccount.name | default (include "gitea.fullname" .) }}
|
||||
{{- end -}}
|
||||
@@ -442,14 +520,6 @@ https
|
||||
{{- end }}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.admin.passwordMode" -}}
|
||||
{{- if has .Values.gitea.admin.passwordMode (tuple "keepUpdated" "initialOnlyNoReset" "initialOnlyRequireReset") -}}
|
||||
{{ .Values.gitea.admin.passwordMode }}
|
||||
{{- else -}}
|
||||
{{ printf "gitea.admin.passwordMode must be set to one of 'keepUpdated', 'initialOnlyNoReset', or 'initialOnlyRequireReset'. Received: '%s'" .Values.gitea.admin.passwordMode | fail }}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Create a functioning probe object for rendering. Given argument must be either a livenessProbe, readinessProbe, or startupProbe */}}
|
||||
{{- define "gitea.deployment.probe" -}}
|
||||
{{- $probe := unset . "enabled" -}}
|
||||
@@ -467,7 +537,3 @@ https
|
||||
{{- end -}}
|
||||
{{- toYaml $probe -}}
|
||||
{{- end -}}
|
||||
|
||||
{{- define "gitea.metrics-secret-name" -}}
|
||||
{{ default (printf "%s-metrics-secret" (include "gitea.fullname" .)) }}
|
||||
{{- end -}}
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.backendTLSPolicy.annotations" -}}
|
||||
{{- with .Values.gatewayAPI.core.backendTLSPolicy.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* enabled */}}
|
||||
|
||||
{{- define "gitea.backendTLSPolicy.enabled" -}}
|
||||
{{- if and .Values.gatewayAPI.enabled
|
||||
.Values.gatewayAPI.core.backendTLSPolicy.enabled
|
||||
-}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.backendTLSPolicy.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.gatewayAPI.core.backendTLSPolicy.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.clientSettingsPolicies.annotations" -}}
|
||||
{{- with .Values.gatewayAPI.nginx.clientSettingsPolicies.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* enabled */}}
|
||||
|
||||
{{- define "gitea.clientSettingsPolicies.enabled" -}}
|
||||
{{- if and .Values.gatewayAPI.enabled
|
||||
.Values.gatewayAPI.nginx.clientSettingsPolicies.enabled
|
||||
-}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.clientSettingsPolicies.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.gatewayAPI.nginx.clientSettingsPolicies.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,38 @@
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.deployment.annotations" -}}
|
||||
{{- with .Values.deployment.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* initContainers */}}
|
||||
|
||||
{{- define "gitea.deployment.initContainers" -}}
|
||||
{{- $links := list "initAppIni" "initConfigureGPG" "initConfigureGitea" "initDirectories" }}
|
||||
{{- range $index, $entry := .Values.deployment.initContainers }}
|
||||
{{- if and (hasKey $entry "container") (hasKey $entry "link") }}
|
||||
{{- fail (printf "deployment.initContainers[%d]: `container` and `link` are mutually exclusive" $index) }}
|
||||
{{- else if hasKey $entry "container" }}
|
||||
{{- list $entry.container | toYaml | nindent 0 }}
|
||||
{{- else if hasKey $entry "link" }}
|
||||
{{- if not (has $entry.link $links) }}
|
||||
{{- fail (printf "deployment.initContainers[%d]: unknown link `%s`, expected one of: %s" $index $entry.link (join ", " $links)) }}
|
||||
{{- end }}
|
||||
{{- with include (printf "gitea.initContainer.%s" $entry.link) $ }}
|
||||
{{- nindent 0 . }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
{{- fail (printf "deployment.initContainers[%d]: either `container` or `link` must be set" $index) }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.deployment.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.deployment.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.httpRoute.annotations" -}}
|
||||
{{- with .Values.gatewayAPI.core.httpRoute.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* enabled */}}
|
||||
|
||||
{{- define "gitea.httpRoute.enabled" -}}
|
||||
{{- if and .Values.gatewayAPI.enabled
|
||||
.Values.gatewayAPI.core.httpRoute.enabled
|
||||
-}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.httpRoute.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.gatewayAPI.core.httpRoute.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,32 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.ingress.annotations" -}}
|
||||
{{- with .Values.ingress.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.ingress.enabled" -}}
|
||||
{{- if and .Values.ingress.enabled .Values.service.http.enabled -}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.ingress.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.ingress.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* name */}}
|
||||
|
||||
{{- define "gitea.ingress.name" -}}
|
||||
{{ include "gitea.fullname" . }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,304 @@
|
||||
{{/* initDirectories */}}
|
||||
|
||||
{{- define "gitea.initContainer.initDirectories" -}}
|
||||
{{- $config := .Values.deployment.initDirectories -}}
|
||||
- name: init-directories
|
||||
image: "{{ include "gitea.image.name" (list . $config.image) }}"
|
||||
imagePullPolicy: {{ $config.image.pullPolicy }}
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/init_directory_structure.sh"
|
||||
env:
|
||||
- name: GITEA_APP_INI
|
||||
value: /data/gitea/conf/app.ini
|
||||
- name: GITEA_CUSTOM
|
||||
value: /data/gitea
|
||||
- name: GITEA_WORK_DIR
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
{{- if .Values.deployment.gitea.env }}
|
||||
{{- toYaml .Values.deployment.gitea.env | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.secrets.gpg.enabled }}
|
||||
- name: GNUPGHOME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "gitea.secret.gpg.name" . }}
|
||||
key: {{ include "gitea.secret.gpg.gpgHomeKey" . }}
|
||||
{{- end }}
|
||||
{{- with $config.env }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.envFrom }}
|
||||
envFrom:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: init
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: temp
|
||||
mountPath: /tmp
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
|
||||
{{- with $config.volumeMounts }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.containerSecurityContext" (list . (deepCopy ($config.securityContext | default .Values.deployment.gitea.securityContext))) | trim) }}
|
||||
securityContext:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml ($config.resources | default .Values.initContainers.resources) | nindent 4 }}
|
||||
{{- end }}
|
||||
|
||||
{{/* initAppIni */}}
|
||||
|
||||
{{- define "gitea.initContainer.initAppIni" -}}
|
||||
{{- $config := .Values.deployment.initAppIni -}}
|
||||
- name: init-app-ini
|
||||
image: "{{ include "gitea.image.name" (list . $config.image) }}"
|
||||
imagePullPolicy: {{ $config.image.pullPolicy }}
|
||||
{{- if .Values.gitea.extraEnvSourceFile }}
|
||||
command:
|
||||
- "/bin/bash"
|
||||
- "-c"
|
||||
args:
|
||||
- "test -f {{ .Values.gitea.extraEnvSourceFile }} && source {{ .Values.gitea.extraEnvSourceFile }} || { echo 'ERROR: Failed to source {{ .Values.gitea.extraEnvSourceFile }}'; exit 1; } && {{ .Values.initContainersScriptsVolumeMountPath }}/config_environment.sh"
|
||||
{{- else }}
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/config_environment.sh"
|
||||
{{- end }}
|
||||
env:
|
||||
- name: GITEA_APP_INI
|
||||
value: /data/gitea/conf/app.ini
|
||||
- name: GITEA_CUSTOM
|
||||
value: /data/gitea
|
||||
- name: GITEA_WORK_DIR
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
- name: TMP_EXISTING_ENVS_FILE
|
||||
value: /tmp/existing-envs
|
||||
- name: ENV_TO_INI_MOUNT_POINT
|
||||
value: /env-to-ini-mounts
|
||||
{{- if .Values.deployment.gitea.env }}
|
||||
{{- toYaml .Values.deployment.gitea.env | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.additionalConfigFromEnvs }}
|
||||
{{- tpl (toYaml .Values.gitea.additionalConfigFromEnvs) $ | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.env }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.envFrom }}
|
||||
envFrom:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: temp
|
||||
mountPath: /tmp
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
- name: inline-config-sources
|
||||
mountPath: /env-to-ini-mounts/inlines/
|
||||
{{- range $idx, $value := .Values.gitea.additionalConfigSources }}
|
||||
- name: additional-config-sources-{{ $idx }}
|
||||
mountPath: "/env-to-ini-mounts/additionals/{{ $idx }}/"
|
||||
{{- end }}
|
||||
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
|
||||
{{- with $config.volumeMounts }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.containerSecurityContext" (list . (deepCopy ($config.securityContext | default .Values.deployment.gitea.securityContext))) | trim) }}
|
||||
securityContext:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml ($config.resources | default .Values.initContainers.resources) | nindent 4 }}
|
||||
{{- end }}
|
||||
|
||||
{{/* initConfigureGPG */}}
|
||||
|
||||
{{- define "gitea.initContainer.initConfigureGPG" -}}
|
||||
{{- $config := .Values.deployment.initConfigureGPG -}}
|
||||
{{- if .Values.secrets.gpg.enabled -}}
|
||||
- name: configure-gpg
|
||||
image: "{{ include "gitea.image.name" (list . $config.image) }}"
|
||||
{{- if .Values.gitea.extraEnvSourceFile }}
|
||||
command:
|
||||
- "/bin/bash"
|
||||
- "-c"
|
||||
args:
|
||||
- "test -f {{ .Values.gitea.extraEnvSourceFile }} && source {{ .Values.gitea.extraEnvSourceFile }} || { echo 'ERROR: Failed to source {{ .Values.gitea.extraEnvSourceFile }}'; exit 1; } && {{ .Values.initContainersScriptsVolumeMountPath }}/configure_gpg_environment.sh"
|
||||
{{- else }}
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/configure_gpg_environment.sh"
|
||||
{{- end }}
|
||||
imagePullPolicy: {{ $config.image.pullPolicy }}
|
||||
{{- with (include "gitea.commandInitContainerSecurityContext" (list . (deepCopy ($config.securityContext | default .Values.deployment.gitea.securityContext))) | trim) }}
|
||||
securityContext:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: GNUPGHOME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "gitea.secret.gpg.name" . }}
|
||||
key: {{ include "gitea.secret.gpg.gpgHomeKey" . }}
|
||||
- name: TMP_RAW_GPG_KEY
|
||||
value: /raw/private.asc
|
||||
{{- with $config.env }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.envFrom }}
|
||||
envFrom:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: init
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
- name: gpg-private-key
|
||||
mountPath: /raw
|
||||
readOnly: true
|
||||
{{- if .Values.extraVolumeMounts }}
|
||||
{{- toYaml .Values.extraVolumeMounts | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.volumeMounts }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml ($config.resources | default .Values.initContainers.resources) | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* initConfigureGitea */}}
|
||||
|
||||
{{- define "gitea.initContainer.initConfigureGitea" -}}
|
||||
{{- $config := .Values.deployment.initConfigureGitea -}}
|
||||
- name: configure-gitea
|
||||
image: "{{ include "gitea.image.name" (list . $config.image) }}"
|
||||
{{- if .Values.gitea.extraEnvSourceFile }}
|
||||
command:
|
||||
- "/bin/bash"
|
||||
- "-c"
|
||||
args:
|
||||
- "test -f {{ .Values.gitea.extraEnvSourceFile }} && source {{ .Values.gitea.extraEnvSourceFile }} || { echo 'ERROR: Failed to source {{ .Values.gitea.extraEnvSourceFile }}'; exit 1; } && {{ .Values.initContainersScriptsVolumeMountPath }}/configure_gitea.sh"
|
||||
{{- else }}
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/configure_gitea.sh"
|
||||
{{- end }}
|
||||
imagePullPolicy: {{ $config.image.pullPolicy }}
|
||||
{{- with (include "gitea.commandInitContainerSecurityContext" (list . (deepCopy ($config.securityContext | default .Values.deployment.gitea.securityContext))) | trim) }}
|
||||
securityContext:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: GITEA_APP_INI
|
||||
value: /data/gitea/conf/app.ini
|
||||
- name: GITEA_CUSTOM
|
||||
value: /data/gitea
|
||||
- name: GITEA_WORK_DIR
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
{{- if $config.image.rootless }}
|
||||
- name: HOME
|
||||
value: /data/gitea/git
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.ldap }}
|
||||
{{- range $idx, $value := .Values.gitea.ldap }}
|
||||
{{- if $value.existingSecret }}
|
||||
- name: GITEA_LDAP_BIND_DN_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: bindDn
|
||||
name: {{ $value.existingSecret }}
|
||||
- name: GITEA_LDAP_PASSWORD_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: bindPassword
|
||||
name: {{ $value.existingSecret }}
|
||||
{{- else }}
|
||||
- name: GITEA_LDAP_BIND_DN_{{ $idx }}
|
||||
value: {{ $value.bindDn | quote }}
|
||||
- name: GITEA_LDAP_PASSWORD_{{ $idx }}
|
||||
value: {{ $value.bindPassword | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.oauth }}
|
||||
{{- range $idx, $value := .Values.gitea.oauth }}
|
||||
{{- if $value.existingSecret }}
|
||||
- name: GITEA_OAUTH_KEY_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: key
|
||||
name: {{ $value.existingSecret }}
|
||||
- name: GITEA_OAUTH_SECRET_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: secret
|
||||
name: {{ $value.existingSecret }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.secrets.admin.enabled }}
|
||||
- name: GITEA_ADMIN_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: {{ include "gitea.secret.admin.usernameKey" . }}
|
||||
name: {{ include "gitea.secret.admin.name" . }}
|
||||
- name: GITEA_ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: {{ include "gitea.secret.admin.passwordKey" . }}
|
||||
name: {{ include "gitea.secret.admin.name" . }}
|
||||
- name: GITEA_ADMIN_EMAIL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: {{ include "gitea.secret.admin.emailKey" . }}
|
||||
name: {{ include "gitea.secret.admin.name" . }}
|
||||
- name: GITEA_ADMIN_PASSWORD_MODE
|
||||
value: {{ include "gitea.secret.admin.passwordMode" $ }}
|
||||
{{- end }}
|
||||
{{- if .Values.deployment.gitea.env }}
|
||||
{{- toYaml .Values.deployment.gitea.env | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.env }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with $config.envFrom }}
|
||||
envFrom:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: init
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: temp
|
||||
mountPath: /tmp
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
{{- include "gitea.init-additional-mounts" . | nindent 4 }}
|
||||
{{- with $config.volumeMounts }}
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml ($config.resources | default .Values.initContainers.resources) | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,52 @@
|
||||
---
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.pod.annotations" -}}
|
||||
|
||||
{{/* secret - admin */}}
|
||||
{{- if and .Values.secrets.admin.enabled .Values.secrets.admin.addSHASumAnnotation }}
|
||||
checksum/admin: {{ include "gitea.secret.checksum" (list . "admin") }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - config */}}
|
||||
{{- if and .Values.secrets.config.enabled .Values.secrets.config.addSHASumAnnotation }}
|
||||
checksum/config: {{ include "gitea.secret.checksum" (list . "config") }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - gpg */}}
|
||||
{{- if and .Values.secrets.gpg.enabled .Values.secrets.gpg.addSHASumAnnotation }}
|
||||
checksum/gpg: {{ include "gitea.secret.checksum" (list . "gpg") }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - init */}}
|
||||
{{- if and .Values.secrets.init.enabled .Values.secrets.init.addSHASumAnnotation }}
|
||||
checksum/init: {{ include "gitea.secret.checksum" (list . "init") }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - inlineConfig */}}
|
||||
{{- if and .Values.secrets.inlineConfig.enabled .Values.secrets.inlineConfig.addSHASumAnnotation }}
|
||||
checksum/inlineConfig: {{ include "gitea.secret.checksum" (list . "inlineConfig") }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - metrics */}}
|
||||
{{- if and .Values.secrets.metrics.enabled .Values.secrets.metrics.addSHASumAnnotation }}
|
||||
checksum/metrics: {{ include "gitea.secret.checksum" (list . "metrics") }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - ldap */}}
|
||||
{{- range $idx, $value := .Values.gitea.ldap }}
|
||||
checksum/ldap_{{ $idx }}: {{ include "gitea.ldap_settings" (list $idx $value) | sha256sum }}
|
||||
{{- end }}
|
||||
|
||||
{{/* secret - oauth */}}
|
||||
{{- range $idx, $value := .Values.gitea.oauth }}
|
||||
checksum/oauth_{{ $idx }}: {{ include "gitea.oauth_settings" (list $idx $value) | sha256sum }}
|
||||
{{- end }}
|
||||
|
||||
{{/* custom pod annotations */}}
|
||||
{{- with .Values.gitea.podAnnotations }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
|
||||
{{- end }}
|
||||
@@ -0,0 +1,206 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.secret.admin.annotations" -}}
|
||||
{{- with .Values.secrets.admin.new.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.config.annotations" -}}
|
||||
{{- with .Values.secrets.config.new.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.gpg.annotations" -}}
|
||||
{{- with .Values.secrets.gpg.new.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.init.annotations" -}}
|
||||
{{- with .Values.secrets.init.new.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.inlineConfig.annotations" -}}
|
||||
{{- with .Values.secrets.inlineConfig.new.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.metrics.annotations" -}}
|
||||
{{- with .Values.secrets.metrics.new.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* checksums */}}
|
||||
|
||||
{{/*
|
||||
SHA sum of a Secret, used to trigger a rollout whenever its content changes.
|
||||
User-provided Secrets are looked up in the cluster, chart-managed ones are rendered, because the
|
||||
cluster still holds their pre-upgrade state.
|
||||
Arguments: (list $root $key)
|
||||
*/}}
|
||||
{{- define "gitea.secret.checksum" -}}
|
||||
{{- $root := index . 0 -}}
|
||||
{{- $key := index . 1 -}}
|
||||
{{- if (index $root.Values.secrets $key).existingSecret.enabled -}}
|
||||
{{- $namespace := $root.Values.namespace | default $root.Release.Namespace -}}
|
||||
{{- $name := include (printf "gitea.secret.%s.name" $key) $root -}}
|
||||
{{- lookup "v1" "Secret" $namespace $name | toYaml | sha256sum -}}
|
||||
{{- else -}}
|
||||
{{- include (printf "%s/gitea/secret_%s.yaml" $root.Template.BasePath $key) $root | sha256sum -}}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.secret.admin.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.secrets.admin.new.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.config.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.secrets.config.new.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.gpg.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.secrets.gpg.new.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.init.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.secrets.init.new.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.inlineConfig.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.secrets.inlineConfig.new.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.metrics.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.secrets.metrics.new.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* names */}}
|
||||
|
||||
{{- define "gitea.secret.admin.name" -}}
|
||||
{{- if .Values.secrets.admin.existingSecret.enabled -}}
|
||||
{{ required "`secrets.admin.existingSecret.secretName` must be set when `secrets.admin.existingSecret.enabled` is enabled" .Values.secrets.admin.existingSecret.secretName }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.fullname" . }}-admin
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.config.name" -}}
|
||||
{{- if .Values.secrets.config.existingSecret.enabled -}}
|
||||
{{ required "`secrets.config.existingSecret.secretName` must be set when `secrets.config.existingSecret.enabled` is enabled" .Values.secrets.config.existingSecret.secretName }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.fullname" . }}-config
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.gpg.name" -}}
|
||||
{{- if .Values.secrets.gpg.existingSecret.enabled -}}
|
||||
{{ required "`secrets.gpg.existingSecret.secretName` must be set when `secrets.gpg.existingSecret.enabled` is enabled" .Values.secrets.gpg.existingSecret.secretName }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.fullname" . }}-gpg-key
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.init.name" -}}
|
||||
{{- if .Values.secrets.init.existingSecret.enabled -}}
|
||||
{{ required "`secrets.init.existingSecret.secretName` must be set when `secrets.init.existingSecret.enabled` is enabled" .Values.secrets.init.existingSecret.secretName }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.fullname" . }}-init
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.inlineConfig.name" -}}
|
||||
{{- if .Values.secrets.inlineConfig.existingSecret.enabled -}}
|
||||
{{ required "`secrets.inlineConfig.existingSecret.secretName` must be set when `secrets.inlineConfig.existingSecret.enabled` is enabled" .Values.secrets.inlineConfig.existingSecret.secretName }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.fullname" . }}-inline-config
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.metrics.name" -}}
|
||||
{{- if .Values.secrets.metrics.existingSecret.enabled -}}
|
||||
{{ required "`secrets.metrics.existingSecret.secretName` must be set when `secrets.metrics.existingSecret.enabled` is enabled" .Values.secrets.metrics.existingSecret.secretName }}
|
||||
{{- else -}}
|
||||
{{ include "gitea.fullname" . }}-metrics
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* keys */}}
|
||||
|
||||
{{- define "gitea.secret.admin.emailKey" -}}
|
||||
{{- if .Values.secrets.admin.existingSecret.enabled -}}
|
||||
{{ .Values.secrets.admin.existingSecret.emailKey }}
|
||||
{{- else -}}
|
||||
email
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.admin.passwordKey" -}}
|
||||
{{- if .Values.secrets.admin.existingSecret.enabled -}}
|
||||
{{ .Values.secrets.admin.existingSecret.passwordKey }}
|
||||
{{- else -}}
|
||||
password
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.admin.usernameKey" -}}
|
||||
{{- if .Values.secrets.admin.existingSecret.enabled -}}
|
||||
{{ .Values.secrets.admin.existingSecret.usernameKey }}
|
||||
{{- else -}}
|
||||
username
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.gpg.gpgHomeKey" -}}
|
||||
{{- if .Values.secrets.gpg.existingSecret.enabled -}}
|
||||
{{ .Values.secrets.gpg.existingSecret.gpgHomeKey }}
|
||||
{{- else -}}
|
||||
gpgHome
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.secret.gpg.privateKeyKey" -}}
|
||||
{{- if .Values.secrets.gpg.existingSecret.enabled -}}
|
||||
{{ .Values.secrets.gpg.existingSecret.privateKeyKey }}
|
||||
{{- else -}}
|
||||
privateKey
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* misc */}}
|
||||
|
||||
{{- define "gitea.secret.admin.passwordMode" -}}
|
||||
{{- if has .Values.secrets.admin.passwordMode (tuple "keepUpdated" "initialOnlyNoReset" "initialOnlyRequireReset") -}}
|
||||
{{ .Values.secrets.admin.passwordMode }}
|
||||
{{- else -}}
|
||||
{{ printf "`secrets.admin.passwordMode` must be set to one of 'keepUpdated', 'initialOnlyNoReset', or 'initialOnlyRequireReset'. Received: '%s'" .Values.secrets.admin.passwordMode | fail }}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,11 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* names */}}
|
||||
|
||||
{{- define "gitea.service.http.name" -}}
|
||||
{{ include "gitea.fullname" . }}-http
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.service.ssh.name" -}}
|
||||
{{ include "gitea.fullname" . }}-ssh
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{/* vim: set filetype=mustache: */}}
|
||||
|
||||
{{/* annotations */}}
|
||||
|
||||
{{- define "gitea.tcpRoute.annotations" -}}
|
||||
{{- with .Values.gatewayAPI.core.tcpRoute.annotations }}
|
||||
{{- toYaml . -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{/* enabled */}}
|
||||
|
||||
{{- define "gitea.tcpRoute.enabled" -}}
|
||||
{{- if and .Values.gatewayAPI.enabled
|
||||
.Values.gatewayAPI.core.tcpRoute.enabled
|
||||
-}}
|
||||
true
|
||||
{{- else -}}
|
||||
false
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{/* labels */}}
|
||||
|
||||
{{- define "gitea.tcpRoute.labels" -}}
|
||||
{{ include "gitea.labels" . }}
|
||||
{{- with .Values.gatewayAPI.core.tcpRoute.labels }}
|
||||
{{ toYaml . }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{- if eq (include "gitea.backendTLSPolicy.enabled" .) "true" -}}
|
||||
{{- if not (keys .Values.gatewayAPI.core.backendTLSPolicy.validation) }}
|
||||
{{- fail "gatewayAPI.core.backendTLSPolicy.validation is required" }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: BackendTLSPolicy
|
||||
metadata:
|
||||
{{- with (include "gitea.backendTLSPolicy.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.backendTLSPolicy.labels" .) }}
|
||||
labels:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
spec:
|
||||
targetRefs:
|
||||
{{- if .Values.gatewayAPI.core.backendTLSPolicy.targetRefs }}
|
||||
{{- toYaml .Values.gatewayAPI.core.backendTLSPolicy.targetRefs | nindent 4 }}
|
||||
{{- else }}
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: {{ include "gitea.service.http.name" . }}
|
||||
{{- end }}
|
||||
validation:
|
||||
{{- toYaml .Values.gatewayAPI.core.backendTLSPolicy.validation | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -1,3 +0,0 @@
|
||||
{{- if .Values.actions -}}
|
||||
{{- fail "The actions sub-chart has been outsourced to a dedicated chart available at https://gitea.com/gitea/helm-actions. For assistance with the migration process, check https://gitea.com/gitea/helm-actions/issues/9." -}}
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,30 @@
|
||||
{{- if eq (include "gitea.clientSettingsPolicies.enabled" .) "true" -}}
|
||||
{{- if not (keys .Values.gatewayAPI.nginx.clientSettingsPolicies.body) }}
|
||||
{{- fail "gatewayAPI.nginx.clientSettingsPolicies.body is required" }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: gateway.nginx.org/v1alpha1
|
||||
kind: ClientSettingsPolicy
|
||||
metadata:
|
||||
{{- with (include "gitea.clientSettingsPolicies.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.clientSettingsPolicies.labels" .) }}
|
||||
labels:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
spec:
|
||||
targetRef:
|
||||
{{- if .Values.gatewayAPI.nginx.clientSettingsPolicies.targetRef }}
|
||||
{{- toYaml .Values.gatewayAPI.nginx.clientSettingsPolicies.targetRef | nindent 4 }}
|
||||
{{- else }}
|
||||
group: gateway.networking.k8s.io
|
||||
kind: HTTPRoute
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
{{- end }}
|
||||
body:
|
||||
{{- toYaml .Values.gatewayAPI.nginx.clientSettingsPolicies.body | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -1,57 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "gitea.fullname" . }}-inline-config
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{- include "gitea.inline_configuration" . | nindent 2 }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{ (.Files.Glob "scripts/init-containers/config/*.sh").AsConfig | indent 2 }}
|
||||
assertions: |
|
||||
|
||||
{{- /*assert that only one PG dep is enabled */ -}}
|
||||
{{- if and (.Values.postgresql.enabled) (index .Values "postgresql-ha" "enabled") -}}
|
||||
{{- fail "Only one of postgresql or postgresql-ha can be enabled at the same time." -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* multiple replicas assertions */ -}}
|
||||
{{- if gt (.Values.replicaCount | int) 1 -}}
|
||||
{{- if .Values.gitea.config.cron -}}
|
||||
{{- if .Values.gitea.config.cron.GIT_GC_REPOS -}}
|
||||
{{- if eq .Values.gitea.config.cron.GIT_GC_REPOS.ENABLED true -}}
|
||||
{{ fail "Invoking the garbage collector via CRON is not yet supported when running with multiple replicas. Please set 'gitea.config.cron.GIT_GC_REPOS.enabled = false'." }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if eq (first .Values.persistence.accessModes) "ReadWriteOnce" -}}
|
||||
{{- fail "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany." -}}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.config.indexer -}}
|
||||
{{- if eq .Values.gitea.config.indexer.ISSUE_INDEXER_TYPE "bleve" -}}
|
||||
{{- fail "When using multiple replicas, the issue indexer (gitea.config.indexer.ISSUE_INDEXER_TYPE) must be set to a HA-ready provider such as 'meilisearch', 'elasticsearch' or 'db' (if the DB is HA-ready)." -}}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.config.indexer.REPO_INDEXER_TYPE -}}
|
||||
{{- if eq .Values.gitea.config.indexer.REPO_INDEXER_TYPE "bleve" -}}
|
||||
{{- if .Values.gitea.config.indexer.REPO_INDEXER_ENABLED -}}
|
||||
{{- if eq .Values.gitea.config.indexer.REPO_INDEXER_ENABLED true -}}
|
||||
{{- fail "When using multiple replicas, the repo indexer (gitea.config.indexer.REPO_INDEXER_TYPE) must be set to 'meilisearch' or 'elasticsearch' or disabled." -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- end }}
|
||||
+68
-274
@@ -1,40 +1,33 @@
|
||||
{{- if .Values.deployment.enabled -}}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
{{- with (include "gitea.deployment.annotations" . | fromYaml) }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.deployment.labels" . | fromYaml) }}
|
||||
labels:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
annotations:
|
||||
{{- if .Values.deployment.annotations }}
|
||||
{{- toYaml .Values.deployment.annotations | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
{{- if .Values.deployment.labels }}
|
||||
{{- toYaml .Values.deployment.labels | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
replicas: {{ .Values.replicaCount }}
|
||||
replicas: {{ .Values.deployment.replicas }}
|
||||
strategy:
|
||||
type: {{ .Values.strategy.type }}
|
||||
{{- if eq .Values.strategy.type "RollingUpdate" }}
|
||||
type: {{ .Values.deployment.strategy.type }}
|
||||
{{- if eq .Values.deployment.strategy.type "RollingUpdate" }}
|
||||
rollingUpdate:
|
||||
maxUnavailable: {{ .Values.strategy.rollingUpdate.maxUnavailable }}
|
||||
maxSurge: {{ .Values.strategy.rollingUpdate.maxSurge }}
|
||||
maxUnavailable: {{ .Values.deployment.strategy.rollingUpdate.maxUnavailable }}
|
||||
maxSurge: {{ .Values.deployment.strategy.rollingUpdate.maxSurge }}
|
||||
{{- end }}
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "gitea.selectorLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
{{- with (include "gitea.pod.annotations" . | fromYaml) }}
|
||||
annotations:
|
||||
checksum/config: {{ include (print $.Template.BasePath "/gitea/config.yaml") . | sha256sum }}
|
||||
{{- range $idx, $value := .Values.gitea.ldap }}
|
||||
checksum/ldap_{{ $idx }}: {{ include "gitea.ldap_settings" (list $idx $value) | sha256sum }}
|
||||
{{- end }}
|
||||
{{- range $idx, $value := .Values.gitea.oauth }}
|
||||
checksum/oauth_{{ $idx }}: {{ include "gitea.oauth_settings" (list $idx $value) | sha256sum }}
|
||||
{{- end }}
|
||||
{{- with .Values.gitea.podAnnotations }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
@@ -43,250 +36,40 @@ spec:
|
||||
{{- toYaml .Values.deployment.labels | nindent 8 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.schedulerName }}
|
||||
schedulerName: "{{ .Values.schedulerName }}"
|
||||
{{- $hostUsers := include "gitea.hostUsers" . | trim }}
|
||||
{{- $securityContext := include "gitea.deployment.securityContext" . | trim }}
|
||||
{{- $containerSecurityContext := include "gitea.containerSecurityContext" (list . (deepCopy .Values.deployment.gitea.securityContext)) | trim }}
|
||||
{{- if .Values.deployment.schedulerName }}
|
||||
schedulerName: "{{ .Values.deployment.schedulerName }}"
|
||||
{{- end }}
|
||||
{{- if (or .Values.serviceAccount.create .Values.serviceAccount.name) }}
|
||||
serviceAccountName: {{ include "gitea.serviceAccountName" . }}
|
||||
{{- end }}
|
||||
{{- if .Values.priorityClassName }}
|
||||
priorityClassName: "{{ .Values.priorityClassName }}"
|
||||
{{- if .Values.deployment.priorityClassName }}
|
||||
priorityClassName: "{{ .Values.deployment.priorityClassName }}"
|
||||
{{- end }}
|
||||
{{- if $hostUsers }}
|
||||
hostUsers: {{ $hostUsers }}
|
||||
{{- end }}
|
||||
{{- include "gitea.images.pullSecrets" . | nindent 6 }}
|
||||
{{- if $securityContext }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||
{{- $securityContext | nindent 8 }}
|
||||
{{- end }}
|
||||
initContainers:
|
||||
{{- if .Values.preExtraInitContainers }}
|
||||
{{- toYaml .Values.preExtraInitContainers | nindent 8 }}
|
||||
{{- end }}
|
||||
- name: init-directories
|
||||
image: "{{ include "gitea.image" . }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/init_directory_structure.sh"
|
||||
env:
|
||||
- name: GITEA_APP_INI
|
||||
value: /data/gitea/conf/app.ini
|
||||
- name: GITEA_CUSTOM
|
||||
value: /data/gitea
|
||||
- name: GITEA_WORK_DIR
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
{{- if .Values.deployment.env }}
|
||||
{{- toYaml .Values.deployment.env | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if .Values.signing.enabled }}
|
||||
- name: GNUPGHOME
|
||||
value: {{ .Values.signing.gpgHome }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: init
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: temp
|
||||
mountPath: /tmp
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
{{- include "gitea.init-additional-mounts" . | nindent 12 }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
|
||||
resources:
|
||||
{{- toYaml .Values.initContainers.resources | nindent 12 }}
|
||||
- name: init-app-ini
|
||||
image: "{{ include "gitea.image" . }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/config_environment.sh"
|
||||
env:
|
||||
- name: GITEA_APP_INI
|
||||
value: /data/gitea/conf/app.ini
|
||||
- name: GITEA_CUSTOM
|
||||
value: /data/gitea
|
||||
- name: GITEA_WORK_DIR
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
- name: TMP_EXISTING_ENVS_FILE
|
||||
value: /tmp/existing-envs
|
||||
- name: ENV_TO_INI_MOUNT_POINT
|
||||
value: /env-to-ini-mounts
|
||||
{{- if .Values.deployment.env }}
|
||||
{{- toYaml .Values.deployment.env | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.additionalConfigFromEnvs }}
|
||||
{{- tpl (toYaml .Values.gitea.additionalConfigFromEnvs) $ | nindent 12 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: temp
|
||||
mountPath: /tmp
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
- name: inline-config-sources
|
||||
mountPath: /env-to-ini-mounts/inlines/
|
||||
{{- range $idx, $value := .Values.gitea.additionalConfigSources }}
|
||||
- name: additional-config-sources-{{ $idx }}
|
||||
mountPath: "/env-to-ini-mounts/additionals/{{ $idx }}/"
|
||||
{{- end }}
|
||||
{{- include "gitea.init-additional-mounts" . | nindent 12 }}
|
||||
securityContext:
|
||||
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
|
||||
resources:
|
||||
{{- toYaml .Values.initContainers.resources | nindent 12 }}
|
||||
{{- if .Values.signing.enabled }}
|
||||
- name: configure-gpg
|
||||
image: "{{ include "gitea.image" . }}"
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/configure_gpg_environment.sh"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
securityContext:
|
||||
{{- /* By default this container runs as user 1000 unless otherwise stated */ -}}
|
||||
{{- $csc := deepCopy .Values.containerSecurityContext -}}
|
||||
{{- if not (hasKey $csc "runAsUser") -}}
|
||||
{{- $_ := set $csc "runAsUser" 1000 -}}
|
||||
{{- end -}}
|
||||
{{- toYaml $csc | nindent 12 }}
|
||||
env:
|
||||
- name: GNUPGHOME
|
||||
value: {{ .Values.signing.gpgHome }}
|
||||
- name: TMP_RAW_GPG_KEY
|
||||
value: /raw/private.asc
|
||||
volumeMounts:
|
||||
- name: init
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
- name: gpg-private-key
|
||||
mountPath: /raw
|
||||
readOnly: true
|
||||
{{- if .Values.extraVolumeMounts }}
|
||||
{{- toYaml .Values.extraVolumeMounts | nindent 12 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml .Values.initContainers.resources | nindent 12 }}
|
||||
{{- end }}
|
||||
- name: configure-gitea
|
||||
image: "{{ include "gitea.image" . }}"
|
||||
command:
|
||||
- "{{ .Values.initContainersScriptsVolumeMountPath }}/configure_gitea.sh"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
securityContext:
|
||||
{{- /* By default this container runs as user 1000 unless otherwise stated */ -}}
|
||||
{{- $csc := deepCopy .Values.containerSecurityContext -}}
|
||||
{{- if not (hasKey $csc "runAsUser") -}}
|
||||
{{- $_ := set $csc "runAsUser" 1000 -}}
|
||||
{{- end -}}
|
||||
{{- toYaml $csc | nindent 12 }}
|
||||
env:
|
||||
- name: GITEA_APP_INI
|
||||
value: /data/gitea/conf/app.ini
|
||||
- name: GITEA_CUSTOM
|
||||
value: /data/gitea
|
||||
- name: GITEA_WORK_DIR
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
{{- if .Values.image.rootless }}
|
||||
- name: HOME
|
||||
value: /data/gitea/git
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.ldap }}
|
||||
{{- range $idx, $value := .Values.gitea.ldap }}
|
||||
{{- if $value.existingSecret }}
|
||||
- name: GITEA_LDAP_BIND_DN_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: bindDn
|
||||
name: {{ $value.existingSecret }}
|
||||
- name: GITEA_LDAP_PASSWORD_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: bindPassword
|
||||
name: {{ $value.existingSecret }}
|
||||
{{- else }}
|
||||
- name: GITEA_LDAP_BIND_DN_{{ $idx }}
|
||||
value: {{ $value.bindDn | quote }}
|
||||
- name: GITEA_LDAP_PASSWORD_{{ $idx }}
|
||||
value: {{ $value.bindPassword | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.oauth }}
|
||||
{{- range $idx, $value := .Values.gitea.oauth }}
|
||||
{{- if $value.existingSecret }}
|
||||
- name: GITEA_OAUTH_KEY_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: key
|
||||
name: {{ $value.existingSecret }}
|
||||
- name: GITEA_OAUTH_SECRET_{{ $idx }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: secret
|
||||
name: {{ $value.existingSecret }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.admin.existingSecret }}
|
||||
- name: GITEA_ADMIN_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: username
|
||||
name: {{ .Values.gitea.admin.existingSecret }}
|
||||
- name: GITEA_ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: password
|
||||
name: {{ .Values.gitea.admin.existingSecret }}
|
||||
{{- else }}
|
||||
- name: GITEA_ADMIN_USERNAME
|
||||
value: {{ .Values.gitea.admin.username | quote }}
|
||||
- name: GITEA_ADMIN_PASSWORD
|
||||
value: {{ .Values.gitea.admin.password | quote }}
|
||||
{{- end }}
|
||||
- name: GITEA_ADMIN_PASSWORD_MODE
|
||||
value: {{ include "gitea.admin.passwordMode" $ }}
|
||||
{{- if .Values.deployment.env }}
|
||||
{{- toYaml .Values.deployment.env | nindent 12 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: init
|
||||
mountPath: {{ .Values.initContainersScriptsVolumeMountPath }}
|
||||
- name: temp
|
||||
mountPath: /tmp
|
||||
- name: data
|
||||
mountPath: /data
|
||||
{{- if .Values.persistence.subPath }}
|
||||
subPath: {{ .Values.persistence.subPath }}
|
||||
{{- end }}
|
||||
{{- include "gitea.init-additional-mounts" . | nindent 12 }}
|
||||
resources:
|
||||
{{- toYaml .Values.initContainers.resources | nindent 12 }}
|
||||
{{- if .Values.postExtraInitContainers }}
|
||||
{{- toYaml .Values.postExtraInitContainers | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- include "gitea.deployment.initContainers" . | trim | nindent 8 }}
|
||||
terminationGracePeriodSeconds: {{ .Values.deployment.terminationGracePeriodSeconds }}
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
image: "{{ include "gitea.image" . }}"
|
||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||
imagePullPolicy: {{ .Values.deployment.gitea.image.pullPolicy }}
|
||||
env:
|
||||
# SSH Port values have to be set here as well for openssh configuration
|
||||
- name: SSH_LISTEN_PORT
|
||||
value: {{ .Values.gitea.config.server.SSH_LISTEN_PORT | quote }}
|
||||
- name: SSH_PORT
|
||||
value: {{ .Values.gitea.config.server.SSH_PORT | quote }}
|
||||
{{- if not .Values.image.rootless }}
|
||||
{{- if not .Values.deployment.gitea.image.rootless }}
|
||||
- name: SSH_LOG_LEVEL
|
||||
value: {{ .Values.gitea.ssh.logLevel | quote }}
|
||||
{{- end }}
|
||||
@@ -298,25 +81,34 @@ spec:
|
||||
value: /data
|
||||
- name: GITEA_TEMP
|
||||
value: /tmp/gitea
|
||||
{{- if and (hasKey .Values.resources "limits") (hasKey .Values.resources.limits "cpu") }}
|
||||
{{- with .Values.deployment.gitea.resources }}
|
||||
{{- if and (hasKey . "limits") (hasKey (.limits | default dict) "cpu") }}
|
||||
- name: GOMAXPROCS
|
||||
valueFrom:
|
||||
resourceFieldRef:
|
||||
divisor: "1"
|
||||
resource: limits.cpu
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
- name: TMPDIR
|
||||
value: /tmp/gitea
|
||||
{{- if .Values.image.rootless }}
|
||||
{{- if .Values.deployment.gitea.image.rootless }}
|
||||
- name: HOME
|
||||
value: /data/gitea/git
|
||||
{{- end }}
|
||||
{{- if .Values.signing.enabled }}
|
||||
{{- if .Values.secrets.gpg.enabled }}
|
||||
- name: GNUPGHOME
|
||||
value: {{ .Values.signing.gpgHome }}
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "gitea.secret.gpg.name" . }}
|
||||
key: {{ include "gitea.secret.gpg.gpgHomeKey" . }}
|
||||
{{- end }}
|
||||
{{- if .Values.deployment.env }}
|
||||
{{- toYaml .Values.deployment.env | nindent 12 }}
|
||||
{{- if .Values.deployment.gitea.env }}
|
||||
{{- toYaml .Values.deployment.gitea.env | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.deployment.gitea.envFrom }}
|
||||
envFrom:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: ssh
|
||||
@@ -343,13 +135,10 @@ spec:
|
||||
{{- include "gitea.deployment.probe" .Values.gitea.startupProbe | nindent 12 }}
|
||||
{{- end }}
|
||||
resources:
|
||||
{{- toYaml .Values.resources | nindent 12 }}
|
||||
{{- toYaml (.Values.deployment.gitea.resources | default dict) | nindent 12 }}
|
||||
{{- if $containerSecurityContext }}
|
||||
securityContext:
|
||||
{{- /* Honor the deprecated securityContext variable when defined */ -}}
|
||||
{{- if .Values.containerSecurityContext -}}
|
||||
{{ toYaml .Values.containerSecurityContext | nindent 12 -}}
|
||||
{{- else -}}
|
||||
{{ toYaml .Values.securityContext | nindent 12 -}}
|
||||
{{- $containerSecurityContext | nindent 12 }}
|
||||
{{- end }}
|
||||
volumeMounts:
|
||||
- name: temp
|
||||
@@ -367,53 +156,57 @@ spec:
|
||||
hostAliases:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.nodeSelector }}
|
||||
{{- with .Values.deployment.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.affinity }}
|
||||
{{- with .Values.deployment.affinity }}
|
||||
affinity:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.topologySpreadConstraints }}
|
||||
{{- with .Values.deployment.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.tolerations }}
|
||||
{{- with .Values.deployment.tolerations }}
|
||||
tolerations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if .Values.dnsConfig }}
|
||||
{{- if .Values.deployment.dnsConfig }}
|
||||
dnsConfig:
|
||||
{{- toYaml .Values.dnsConfig | nindent 8 }}
|
||||
{{- toYaml .Values.deployment.dnsConfig | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.deployment.resources }}
|
||||
resources:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
volumes:
|
||||
- name: init
|
||||
secret:
|
||||
secretName: {{ include "gitea.fullname" . }}-init
|
||||
secretName: {{ include "gitea.secret.init.name" . }}
|
||||
defaultMode: 110
|
||||
- name: config
|
||||
secret:
|
||||
secretName: {{ include "gitea.fullname" . }}
|
||||
secretName: {{ include "gitea.secret.config.name" . }}
|
||||
defaultMode: 110
|
||||
{{- if gt (len .Values.extraVolumes) 0 }}
|
||||
{{- toYaml .Values.extraVolumes | nindent 8 }}
|
||||
{{- if gt (len .Values.deployment.volumes) 0 }}
|
||||
{{- toYaml .Values.deployment.volumes | nindent 8 }}
|
||||
{{- end }}
|
||||
- name: inline-config-sources
|
||||
secret:
|
||||
secretName: {{ include "gitea.fullname" . }}-inline-config
|
||||
secretName: {{ include "gitea.secret.inlineConfig.name" . }}
|
||||
{{- range $idx, $value := .Values.gitea.additionalConfigSources }}
|
||||
- name: additional-config-sources-{{ $idx }}
|
||||
{{- toYaml $value | nindent 10 }}
|
||||
{{- end }}
|
||||
- name: temp
|
||||
emptyDir: {}
|
||||
{{- if .Values.signing.enabled }}
|
||||
{{- if .Values.secrets.gpg.enabled }}
|
||||
- name: gpg-private-key
|
||||
secret:
|
||||
secretName: {{ include "gitea.gpg-key-secret-name" . }}
|
||||
secretName: {{ include "gitea.secret.gpg.name" . }}
|
||||
items:
|
||||
- key: privateKey
|
||||
- key: {{ include "gitea.secret.gpg.privateKeyKey" . }}
|
||||
path: private.asc
|
||||
defaultMode: 0100
|
||||
{{- end }}
|
||||
@@ -427,3 +220,4 @@ spec:
|
||||
- name: data
|
||||
emptyDir: {}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -31,4 +31,107 @@
|
||||
{{- fail "`gitea.database.builtIn` does no longer exist. Builtin databases can be configured inside the dependencies itself. Please refer to the changelog." -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- if .Values.gitea.admin -}}
|
||||
{{- fail "`gitea.admin` does no longer exist. Please refer to the changelog and configure `secrets.admin` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* SIGNING */}}
|
||||
{{- if .Values.signing -}}
|
||||
{{- fail "`signing` does no longer exist. Please refer to the changelog and configure `secrets.gpg` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* AFFINITY */}}
|
||||
{{- if .Values.affinity -}}
|
||||
{{- fail "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* CONTAINER SECURITY CONTEXT */}}
|
||||
{{- if .Values.containerSecurityContext -}}
|
||||
{{- fail "`containerSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.gitea.securityContext` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* DEPLOYMENT ENV */}}
|
||||
{{- if .Values.deployment.env -}}
|
||||
{{- fail "`deployment.env` does no longer exist. Please refer to the changelog and configure `deployment.gitea.env` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* DNS CONFIG */}}
|
||||
{{- if .Values.dnsConfig -}}
|
||||
{{- fail "`dnsConfig` does no longer exist. Please refer to the changelog and configure `deployment.dnsConfig` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* EXTRA CONTAINER VOLUME MOUNTS */}}
|
||||
{{- if .Values.extraContainerVolumeMounts -}}
|
||||
{{- fail "`extraContainerVolumeMounts` does no longer exist. Please refer to the changelog and configure `deployment.gitea.volumeMounts` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* EXTRA VOLUMES */}}
|
||||
{{- if .Values.extraVolumes -}}
|
||||
{{- fail "`extraVolumes` does no longer exist. Please refer to the changelog and configure `deployment.volumes` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* NODE SELECTOR */}}
|
||||
{{- if .Values.nodeSelector -}}
|
||||
{{- fail "`nodeSelector` does no longer exist. Please refer to the changelog and configure `deployment.nodeSelector` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* OPENSHIFT HOST USERS */}}
|
||||
{{- if hasKey .Values.openshift "hostUsers" -}}
|
||||
{{- fail "`openshift.hostUsers` does no longer exist. Please refer to the changelog and configure `deployment.hostUsers` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* PRIORITY CLASS NAME */}}
|
||||
{{- if .Values.priorityClassName -}}
|
||||
{{- fail "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* POD SECURITY CONTEXT */}}
|
||||
{{- if .Values.podSecurityContext -}}
|
||||
{{- fail "`podSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* POST EXTRA INIT CONTAINERS */}}
|
||||
{{- if .Values.postExtraInitContainers -}}
|
||||
{{- fail "`postExtraInitContainers` does no longer exist. Please refer to the changelog and append an entry with a `container` key to `deployment.initContainers` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* PRE EXTRA INIT CONTAINERS */}}
|
||||
{{- if .Values.preExtraInitContainers -}}
|
||||
{{- fail "`preExtraInitContainers` does no longer exist. Please refer to the changelog and prepend an entry with a `container` key to `deployment.initContainers` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* RESOURCES */}}
|
||||
{{- if .Values.resources -}}
|
||||
{{- fail "`resources` does no longer exist. Please refer to the changelog and configure `deployment.gitea.resources` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* REPLICA COUNT */}}
|
||||
{{- if .Values.replicaCount -}}
|
||||
{{- fail "`replicaCount` does no longer exist. Please refer to the changelog and configure `deployment.replicas` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* SCHEDULER NAME */}}
|
||||
{{- if .Values.schedulerName -}}
|
||||
{{- fail "`schedulerName` does no longer exist. Please refer to the changelog and configure `deployment.schedulerName` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* SECURITY CONTEXT */}}
|
||||
{{- if .Values.securityContext -}}
|
||||
{{- fail "`securityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` and `deployment.gitea.securityContext` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* STRATEGY */}}
|
||||
{{- if .Values.strategy -}}
|
||||
{{- fail "`strategy` does no longer exist. Please refer to the changelog and configure `deployment.strategy` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* TOLERATIONS */}}
|
||||
{{- if .Values.tolerations -}}
|
||||
{{- fail "`tolerations` does no longer exist. Please refer to the changelog and configure `deployment.tolerations` instead." -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* TOPOLOGY SPREAD CONSTRAINTS */}}
|
||||
{{- if .Values.topologySpreadConstraints -}}
|
||||
{{- fail "`topologySpreadConstraints` does no longer exist. Please refer to the changelog and configure `deployment.topologySpreadConstraints` instead." -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -1,17 +0,0 @@
|
||||
{{- if .Values.signing.enabled -}}
|
||||
{{- if and (empty .Values.signing.privateKey) (empty .Values.signing.existingSecret) -}}
|
||||
{{- fail "Either specify `signing.privateKey` or `signing.existingSecret`" -}}
|
||||
{{- end }}
|
||||
{{- if and (not (empty .Values.signing.privateKey)) (empty .Values.signing.existingSecret) -}}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "gitea.gpg-key-secret-name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
type: Opaque
|
||||
data:
|
||||
privateKey: {{ .Values.signing.privateKey | b64enc }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,42 @@
|
||||
{{- if eq (include "gitea.httpRoute.enabled" .) "true" -}}
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
{{- with (include "gitea.httpRoute.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.httpRoute.labels" .) }}
|
||||
labels:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
spec:
|
||||
parentRefs:
|
||||
{{- if .Values.gatewayAPI.core.httpRoute.parentRefs }}
|
||||
{{- toYaml .Values.gatewayAPI.core.httpRoute.parentRefs | nindent 4 }}
|
||||
{{- else }}
|
||||
{{- fail "gatewayAPI.core.httpRoute.parentRefs is required" }}
|
||||
{{- end }}
|
||||
{{- with .Values.gatewayAPI.core.httpRoute.hostnames }}
|
||||
hostnames:
|
||||
{{- tpl (toYaml .) $ | nindent 4 }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- if .Values.gatewayAPI.core.httpRoute.rules }}
|
||||
{{- tpl (toYaml .Values.gatewayAPI.core.httpRoute.rules) $ | nindent 4 }}
|
||||
{{- else }}
|
||||
- matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: {{ include "gitea.service.http.name" . }}
|
||||
port: {{ .Values.service.http.port }}
|
||||
weight: 1
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -1,29 +1,20 @@
|
||||
{{- if .Values.ingress.enabled -}}
|
||||
{{- $fullName := include "gitea.fullname" . -}}
|
||||
{{- $httpPort := .Values.service.http.port -}}
|
||||
{{- if eq (include "gitea.ingress.enabled" .) "true" -}}
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: {{ $fullName }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
{{- with (include "gitea.ingress.annotations" .) }}
|
||||
annotations:
|
||||
{{- range $key, $value := .Values.ingress.annotations }}
|
||||
{{ $key }}: {{ $value | quote }}
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.ingress.labels" .) }}
|
||||
labels:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
name: {{ include "gitea.ingress.name" . }}
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
ingressClassName: {{ tpl .Values.ingress.className . }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ tpl . $ | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- range .Values.ingress.hosts }}
|
||||
- host: {{ tpl .host $ | quote }}
|
||||
@@ -36,17 +27,17 @@ spec:
|
||||
pathType: {{ default "Prefix" $.Values.ingress.pathType }}
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}-http
|
||||
name: {{ include "gitea.service.http.name" $ }}
|
||||
port:
|
||||
number: {{ $httpPort }}
|
||||
number: {{ $.Values.service.http.port }}
|
||||
{{- else }}
|
||||
- path: {{ .path | default "/" }}
|
||||
pathType: {{ .pathType | default "Prefix" }}
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}-http
|
||||
name: {{ include "gitea.service.http.name" $ }}
|
||||
port:
|
||||
number: {{ $httpPort }}
|
||||
number: {{ $.Values.service.http.port }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- else }}
|
||||
@@ -54,9 +45,19 @@ spec:
|
||||
pathType: "Prefix"
|
||||
backend:
|
||||
service:
|
||||
name: {{ $fullName }}-http
|
||||
name: {{ include "gitea.service.http.name" $ }}
|
||||
port:
|
||||
number: {{ $httpPort }}
|
||||
number: {{ $.Values.service.http.port }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- if .Values.ingress.tls }}
|
||||
tls:
|
||||
{{- range .Values.ingress.tls }}
|
||||
- hosts:
|
||||
{{- range .hosts }}
|
||||
- {{ tpl . $ | quote }}
|
||||
{{- end }}
|
||||
secretName: {{ .secretName }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
{{- if and (.Values.gitea.metrics.enabled) (.Values.gitea.metrics.serviceMonitor.enabled) (.Values.gitea.metrics.token) -}}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "gitea.metrics-secret-name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
type: Opaque
|
||||
data:
|
||||
token: {{ .Values.gitea.metrics.token | b64enc }}
|
||||
{{- end }}
|
||||
@@ -10,7 +10,7 @@ metadata:
|
||||
{{ .Values.persistence.labels | toYaml | indent 4}}
|
||||
spec:
|
||||
accessModes:
|
||||
{{- if gt (.Values.replicaCount | int) 1 }}
|
||||
{{- if gt (.Values.deployment.replicas | int) 1 }}
|
||||
- ReadWriteMany
|
||||
{{- else }}
|
||||
{{- .Values.persistence.accessModes | toYaml | nindent 4 }}
|
||||
@@ -0,0 +1,52 @@
|
||||
{{- if .Values.route.enabled -}}
|
||||
{{- $fullName := include "gitea.fullname" . -}}
|
||||
apiVersion: route.openshift.io/v1
|
||||
kind: Route
|
||||
metadata:
|
||||
name: {{ $fullName }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
{{- with .Values.route.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
{{- if .Values.route.host }}
|
||||
host: {{ tpl .Values.route.host . | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.route.path }}
|
||||
path: {{ tpl .Values.route.path . | quote }}
|
||||
{{- end }}
|
||||
to:
|
||||
kind: Service
|
||||
name: {{ include "gitea.service.http.name" . }}
|
||||
port:
|
||||
targetPort: http
|
||||
wildcardPolicy: {{ .Values.route.wildcardPolicy }}
|
||||
{{- with .Values.route.tls }}
|
||||
{{- if .termination }}
|
||||
tls:
|
||||
termination: {{ .termination }}
|
||||
{{- if .insecureEdgeTerminationPolicy }}
|
||||
insecureEdgeTerminationPolicy: {{ .insecureEdgeTerminationPolicy }}
|
||||
{{- end }}
|
||||
{{- if .key }}
|
||||
key: |
|
||||
{{- .key | nindent 6 }}
|
||||
{{- end }}
|
||||
{{- if .certificate }}
|
||||
certificate: |
|
||||
{{- .certificate | nindent 6 }}
|
||||
{{- end }}
|
||||
{{- if .caCertificate }}
|
||||
caCertificate: |
|
||||
{{- .caCertificate | nindent 6 }}
|
||||
{{- end }}
|
||||
{{- if .destinationCACertificate }}
|
||||
destinationCACertificate: |
|
||||
{{- .destinationCACertificate | nindent 6 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,21 @@
|
||||
{{- if and (.Values.secrets.admin.enabled) (not .Values.secrets.admin.existingSecret.enabled) -}}
|
||||
{{- if or (empty .Values.secrets.admin.new.username) (empty .Values.secrets.admin.new.password) -}}
|
||||
{{- fail "Either specify `secrets.admin.new.username` and `secrets.admin.new.password` or reference an existing Secret via `secrets.admin.existingSecret`" -}}
|
||||
{{- end }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
{{- with (include "gitea.secret.admin.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.secret.admin.labels" . | nindent 4 }}
|
||||
name: {{ include "gitea.secret.admin.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
type: Opaque
|
||||
data:
|
||||
email: {{ .Values.secrets.admin.new.email | b64enc }}
|
||||
password: {{ .Values.secrets.admin.new.password | b64enc }}
|
||||
username: {{ .Values.secrets.admin.new.username | b64enc }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,59 @@
|
||||
{{- /* Evaluated outside of the Secret so the guards also run with an existing Secret. */ -}}
|
||||
{{- $assertions := include "gitea.config.assertions" . -}}
|
||||
{{- if not .Values.secrets.config.existingSecret.enabled -}}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
{{- with (include "gitea.secret.config.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.secret.config.labels" . | nindent 4 }}
|
||||
name: {{ include "gitea.secret.config.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{ (.Files.Glob "scripts/init-containers/config/*.sh").AsConfig | indent 2 }}
|
||||
assertions: |
|
||||
{{- $assertions | nindent 4 }}
|
||||
{{- end }}
|
||||
|
||||
{{- define "gitea.config.assertions" -}}
|
||||
|
||||
{{- /*assert that only one PG dep is enabled */ -}}
|
||||
{{- if and (.Values.postgresql.enabled) (index .Values "postgresql-ha" "enabled") -}}
|
||||
{{- fail "Only one of postgresql or postgresql-ha can be enabled at the same time." -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* multiple replicas assertions */ -}}
|
||||
{{- if gt (.Values.deployment.replicas | int) 1 -}}
|
||||
{{- if .Values.gitea.config.cron -}}
|
||||
{{- if .Values.gitea.config.cron.GIT_GC_REPOS -}}
|
||||
{{- if eq .Values.gitea.config.cron.GIT_GC_REPOS.ENABLED true -}}
|
||||
{{ fail "Invoking the garbage collector via CRON is not yet supported when running with multiple replicas. Please set 'gitea.config.cron.GIT_GC_REPOS.enabled = false'." }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- if eq (first .Values.persistence.accessModes) "ReadWriteOnce" -}}
|
||||
{{- fail "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany." -}}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.config.indexer -}}
|
||||
{{- if eq .Values.gitea.config.indexer.ISSUE_INDEXER_TYPE "bleve" -}}
|
||||
{{- fail "When using multiple replicas, the issue indexer (gitea.config.indexer.ISSUE_INDEXER_TYPE) must be set to a HA-ready provider such as 'meilisearch', 'elasticsearch' or 'db' (if the DB is HA-ready)." -}}
|
||||
{{- end }}
|
||||
{{- if .Values.gitea.config.indexer.REPO_INDEXER_TYPE -}}
|
||||
{{- if eq .Values.gitea.config.indexer.REPO_INDEXER_TYPE "bleve" -}}
|
||||
{{- if .Values.gitea.config.indexer.REPO_INDEXER_ENABLED -}}
|
||||
{{- if eq .Values.gitea.config.indexer.REPO_INDEXER_ENABLED true -}}
|
||||
{{- fail "When using multiple replicas, the repo indexer (gitea.config.indexer.REPO_INDEXER_TYPE) must be set to 'meilisearch' or 'elasticsearch' or disabled." -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,20 @@
|
||||
{{- if and (.Values.secrets.gpg.enabled) (not .Values.secrets.gpg.existingSecret.enabled) -}}
|
||||
{{- if empty .Values.secrets.gpg.new.privateKey -}}
|
||||
{{- fail "Either specify `secrets.gpg.new.privateKey` or reference an existing Secret via `secrets.gpg.existingSecret`" -}}
|
||||
{{- end }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
{{- with (include "gitea.secret.gpg.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.secret.gpg.labels" . | nindent 4 }}
|
||||
name: {{ include "gitea.secret.gpg.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
type: Opaque
|
||||
data:
|
||||
gpgHome: {{ .Values.secrets.gpg.new.gpgHome | b64enc }}
|
||||
privateKey: {{ .Values.secrets.gpg.new.privateKey | b64enc }}
|
||||
{{- end }}
|
||||
@@ -1,10 +1,15 @@
|
||||
{{- if not .Values.secrets.init.existingSecret.enabled -}}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: {{ include "gitea.fullname" . }}-init
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
{{- with (include "gitea.secret.init.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
{{- include "gitea.secret.init.labels" . | nindent 4 }}
|
||||
name: {{ include "gitea.secret.init.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{ (.Files.Glob "scripts/init-containers/init/*.sh").AsConfig | indent 2 }}
|
||||
@@ -21,7 +26,7 @@ stringData:
|
||||
# END: initPreScript
|
||||
{{- end }}
|
||||
|
||||
{{- if not .Values.image.rootless }}
|
||||
{{- if not .Values.deployment.gitea.image.rootless }}
|
||||
chown -v 1000:1000 /data
|
||||
{{- end }}
|
||||
mkdir -pv /data/git/.ssh
|
||||
@@ -30,12 +35,12 @@ stringData:
|
||||
|
||||
# prepare temp directory structure
|
||||
mkdir -pv "${GITEA_TEMP}"
|
||||
{{- if not .Values.image.rootless }}
|
||||
{{- if not .Values.deployment.gitea.image.rootless }}
|
||||
chown -v 1000:1000 "${GITEA_TEMP}"
|
||||
{{- end }}
|
||||
chmod -v ug+rwx "${GITEA_TEMP}"
|
||||
|
||||
{{ if .Values.signing.enabled -}}
|
||||
{{ if .Values.secrets.gpg.enabled -}}
|
||||
if [ ! -d "${GNUPGHOME}" ]; then
|
||||
mkdir -pv "${GNUPGHOME}"
|
||||
chmod -v 700 "${GNUPGHOME}"
|
||||
@@ -79,7 +84,7 @@ stringData:
|
||||
{{- end }}
|
||||
|
||||
|
||||
{{- if or .Values.gitea.admin.existingSecret (and .Values.gitea.admin.username .Values.gitea.admin.password) }}
|
||||
{{- if .Values.secrets.admin.enabled }}
|
||||
function configure_admin_user() {
|
||||
local full_admin_list=$(gitea admin user list --admin)
|
||||
local actual_user_table=''
|
||||
@@ -105,7 +110,7 @@ stringData:
|
||||
local ACCOUNT_ID=$(echo "${actual_user_table}" | grep -E "\s+${GITEA_ADMIN_USERNAME}\s+" | awk -F " " "{printf \$1}")
|
||||
if [[ -z "${ACCOUNT_ID}" ]]; then
|
||||
local -a create_args
|
||||
create_args=(--admin --username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}" --email {{ .Values.gitea.admin.email | quote }})
|
||||
create_args=(--admin --username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}" --email "${GITEA_ADMIN_EMAIL}")
|
||||
if [[ "${GITEA_ADMIN_PASSWORD_MODE}" = initialOnlyRequireReset ]]; then
|
||||
create_args+=(--must-change-password=true)
|
||||
else
|
||||
@@ -123,7 +128,7 @@ stringData:
|
||||
# should add it to prevent requiring frequent admin password resets.
|
||||
local -a change_args
|
||||
change_args=(--username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}")
|
||||
if gitea admin user change-password --help | grep -qF -- '--must-change-password'; then
|
||||
if gitea admin user change-password --help | grep -F -- '--must-change-password' >/dev/null; then
|
||||
change_args+=(--must-change-password=false)
|
||||
fi
|
||||
gitea admin user change-password "${change_args[@]}"
|
||||
@@ -226,3 +231,4 @@ stringData:
|
||||
configure_oauth
|
||||
|
||||
echo '==== END GITEA CONFIGURATION ===='
|
||||
{{- end }}
|
||||
@@ -0,0 +1,19 @@
|
||||
{{- /* Evaluated outside of the Secret because it populates `.Values.gitea.config` for the other templates. */ -}}
|
||||
{{- $inlineConfiguration := include "gitea.inline_configuration" . -}}
|
||||
{{- if not .Values.secrets.inlineConfig.existingSecret.enabled -}}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
{{- with (include "gitea.secret.inlineConfig.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.secret.inlineConfig.labels" . | nindent 4 }}
|
||||
name: {{ include "gitea.secret.inlineConfig.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
type: Opaque
|
||||
stringData:
|
||||
{{- $inlineConfiguration | nindent 2 }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1,16 @@
|
||||
{{- if and (.Values.gitea.metrics.enabled) (.Values.gitea.metrics.serviceMonitor.enabled) (.Values.gitea.metrics.token) (not .Values.secrets.metrics.existingSecret.enabled) -}}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
{{- with (include "gitea.secret.metrics.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
labels:
|
||||
{{- include "gitea.secret.metrics.labels" . | nindent 4 }}
|
||||
name: {{ include "gitea.secret.metrics.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
type: Opaque
|
||||
data:
|
||||
token: {{ .Values.gitea.metrics.token | b64enc }}
|
||||
{{- end }}
|
||||
@@ -36,7 +36,7 @@ spec:
|
||||
authorization:
|
||||
type: Bearer
|
||||
credentials:
|
||||
name: {{ include "gitea.metrics-secret-name" . }}
|
||||
name: {{ include "gitea.secret.metrics.name" . }}
|
||||
key: token
|
||||
optional: false
|
||||
{{- end }}
|
||||
@@ -1,15 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "gitea.fullname" . }}-http
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
annotations:
|
||||
{{- toYaml .Values.service.http.annotations | nindent 4 }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
{{- if .Values.service.http.labels }}
|
||||
{{- toYaml .Values.service.http.labels | nindent 4 }}
|
||||
{{- end }}
|
||||
annotations:
|
||||
{{- toYaml .Values.service.http.annotations | nindent 4 }}
|
||||
name: {{ include "gitea.service.http.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
spec:
|
||||
type: {{ .Values.service.http.type }}
|
||||
{{- if eq .Values.service.http.type "LoadBalancer" }}
|
||||
@@ -1,15 +1,15 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "gitea.fullname" . }}-ssh
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
annotations:
|
||||
{{- toYaml .Values.service.ssh.annotations | nindent 4 }}
|
||||
labels:
|
||||
{{- include "gitea.labels" . | nindent 4 }}
|
||||
{{- if .Values.service.ssh.labels }}
|
||||
{{- toYaml .Values.service.ssh.labels | nindent 4 }}
|
||||
{{- end }}
|
||||
annotations:
|
||||
{{- toYaml .Values.service.ssh.annotations | nindent 4 }}
|
||||
name: {{ include "gitea.service.ssh.name" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
spec:
|
||||
type: {{ .Values.service.ssh.type }}
|
||||
{{- if eq .Values.service.ssh.type "LoadBalancer" }}
|
||||
@@ -0,0 +1,34 @@
|
||||
{{- if eq (include "gitea.tcpRoute.enabled" .) "true" -}}
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: TCPRoute
|
||||
metadata:
|
||||
{{- with (include "gitea.tcpRoute.annotations" .) }}
|
||||
annotations:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
{{- with (include "gitea.tcpRoute.labels" .) }}
|
||||
labels:
|
||||
{{- . | nindent 4 }}
|
||||
{{- end }}
|
||||
name: {{ include "gitea.fullname" . }}
|
||||
namespace: {{ .Values.namespace | default .Release.Namespace }}
|
||||
spec:
|
||||
parentRefs:
|
||||
{{- if .Values.gatewayAPI.core.tcpRoute.parentRefs }}
|
||||
{{- toYaml .Values.gatewayAPI.core.tcpRoute.parentRefs | nindent 4 }}
|
||||
{{- else }}
|
||||
{{- fail "gatewayAPI.core.tcpRoute.parentRefs is required" }}
|
||||
{{- end }}
|
||||
rules:
|
||||
{{- if .Values.gatewayAPI.core.tcpRoute.rules }}
|
||||
{{- tpl (toYaml .Values.gatewayAPI.core.tcpRoute.rules) $ | nindent 4 }}
|
||||
{{- else }}
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: {{ include "gitea.service.ssh.name" . }}
|
||||
port: {{ .Values.service.ssh.port }}
|
||||
weight: 1
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -9,10 +9,19 @@ metadata:
|
||||
annotations:
|
||||
"helm.sh/hook": test-success
|
||||
spec:
|
||||
{{- $hostUsers := include "gitea.hostUsers" . | trim }}
|
||||
{{- $testContainerSecurityContext := include "gitea.containerSecurityContext" (list . (dict)) | trim }}
|
||||
{{- if $hostUsers }}
|
||||
hostUsers: {{ $hostUsers }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: wget
|
||||
image: "{{ .Values.test.image.name }}:{{ .Values.test.image.tag }}"
|
||||
{{- if $testContainerSecurityContext }}
|
||||
securityContext:
|
||||
{{- $testContainerSecurityContext | nindent 8 }}
|
||||
{{- end }}
|
||||
command: ['wget']
|
||||
args: ['{{ include "gitea.fullname" . }}-http:{{ .Values.service.http.port }}']
|
||||
args: ['{{ include "gitea.service.http.name" . }}:{{ .Values.service.http.port }}']
|
||||
restartPolicy: Never
|
||||
{{- end }}
|
||||
|
||||
@@ -9,27 +9,51 @@ function setup() {
|
||||
export GITEA_APP_INI="$BATS_TEST_TMPDIR/app.ini"
|
||||
export TMP_EXISTING_ENVS_FILE="$BATS_TEST_TMPDIR/existing-envs"
|
||||
export ENV_TO_INI_MOUNT_POINT="$BATS_TEST_TMPDIR/env-to-ini-mounts"
|
||||
export GITEA_EDIT_INI_EXPECTED=0
|
||||
export PATH="$BATS_TEST_TMPDIR/bin:$PATH"
|
||||
|
||||
stub gitea \
|
||||
"generate secret INTERNAL_TOKEN : echo 'mocked-internal-token'" \
|
||||
"generate secret SECRET_KEY : echo 'mocked-secret-key'" \
|
||||
"generate secret JWT_SECRET : echo 'mocked-jwt-secret'" \
|
||||
"generate secret LFS_JWT_SECRET : echo 'mocked-lfs-jwt-secret'"
|
||||
mkdir -p "$BATS_TEST_TMPDIR/bin"
|
||||
cat >"$BATS_TEST_TMPDIR/bin/gitea" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
case "$*" in
|
||||
'generate secret INTERNAL_TOKEN')
|
||||
echo 'mocked-internal-token'
|
||||
;;
|
||||
'generate secret SECRET_KEY')
|
||||
echo 'mocked-secret-key'
|
||||
;;
|
||||
'generate secret JWT_SECRET')
|
||||
echo 'mocked-jwt-secret'
|
||||
;;
|
||||
'generate secret LFS_JWT_SECRET')
|
||||
echo 'mocked-lfs-jwt-secret'
|
||||
;;
|
||||
"config edit-ini --apply-env --config $GITEA_APP_INI --out $GITEA_APP_INI")
|
||||
if [ "$GITEA_EDIT_INI_EXPECTED" -eq 1 ]; then
|
||||
echo 'Stubbed gitea config edit-ini was called!'
|
||||
exit 0
|
||||
fi
|
||||
|
||||
echo 'Unexpected gitea config edit-ini invocation' >&2
|
||||
exit 127
|
||||
;;
|
||||
*)
|
||||
echo "Unexpected gitea invocation: $*" >&2
|
||||
exit 127
|
||||
;;
|
||||
esac
|
||||
EOF
|
||||
chmod +x "$BATS_TEST_TMPDIR/bin/gitea"
|
||||
}
|
||||
|
||||
function teardown() {
|
||||
unstub gitea
|
||||
# This condition exists due to https://github.com/jasonkarns/bats-mock/pull/37 being still open
|
||||
if [ $ENV_TO_INI_EXPECTED -eq 1 ]; then
|
||||
unstub environment-to-ini
|
||||
fi
|
||||
:
|
||||
}
|
||||
|
||||
# This function exists due to https://github.com/jasonkarns/bats-mock/pull/37 being still open
|
||||
function expect_environment_to_ini_call() {
|
||||
export ENV_TO_INI_EXPECTED=1
|
||||
stub environment-to-ini \
|
||||
"-o $GITEA_APP_INI : echo 'Stubbed environment-to-ini was called!'"
|
||||
function expect_gitea_config_edit_ini_call() {
|
||||
export GITEA_EDIT_INI_EXPECTED=1
|
||||
}
|
||||
|
||||
function execute_test_script() {
|
||||
@@ -56,18 +80,18 @@ function write_mounted_file() {
|
||||
}
|
||||
|
||||
@test "works as expected when nothing is configured" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
run $PROJECT_ROOT/scripts/init-containers/config/config_environment.sh
|
||||
|
||||
assert_success
|
||||
assert_line '...Initial secrets generated'
|
||||
assert_line 'Reloading preset envs...'
|
||||
assert_line '=== All configuration sources loaded ==='
|
||||
assert_line 'Stubbed environment-to-ini was called!'
|
||||
assert_line 'Stubbed gitea config edit-ini was called!'
|
||||
}
|
||||
|
||||
@test "exports initial secrets" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
run execute_test_script
|
||||
|
||||
assert_success
|
||||
@@ -78,7 +102,7 @@ function write_mounted_file() {
|
||||
}
|
||||
|
||||
@test "does NOT export initial secrets when app.ini already exists" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
touch $GITEA_APP_INI
|
||||
|
||||
run execute_test_script
|
||||
@@ -92,7 +116,7 @@ function write_mounted_file() {
|
||||
}
|
||||
|
||||
@test "ensures that preset environment variables take precedence over auto-generated ones" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
export GITEA__OAUTH2__JWT_SECRET="pre-defined-jwt-secret"
|
||||
|
||||
run execute_test_script
|
||||
@@ -102,7 +126,7 @@ function write_mounted_file() {
|
||||
}
|
||||
|
||||
@test "ensures that preset environment variables take precedence over mounted ones" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
export GITEA__OAUTH2__JWT_SECRET="pre-defined-jwt-secret"
|
||||
write_mounted_file "inlines" "oauth2" "$(cat << EOF
|
||||
JWT_SECRET=inline-jwt-secret
|
||||
@@ -117,7 +141,7 @@ EOF
|
||||
}
|
||||
|
||||
@test "ensures that additionals take precedence over inlines" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
write_mounted_file "inlines" "oauth2" "$(cat << EOF
|
||||
JWT_SECRET=inline-jwt-secret
|
||||
EOF
|
||||
@@ -136,7 +160,7 @@ EOF
|
||||
}
|
||||
|
||||
@test "ensures that dotted/dashed sections are properly masked" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
write_mounted_file "inlines" "repository.pull-request" "$(cat << EOF
|
||||
WORK_IN_PROGRESS_PREFIXES=WIP:,[WIP]
|
||||
EOF
|
||||
@@ -152,7 +176,7 @@ EOF
|
||||
##### THIS IS A BUG, BUT I WANT IT TO BE COVERED BY TESTS #####
|
||||
###############################################################
|
||||
@test "ensures uppercase section and setting names (🐞)" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
export GITEA__oauth2__JwT_Secret="pre-defined-jwt-secret"
|
||||
write_mounted_file "inlines" "repository.pull-request" "$(cat << EOF
|
||||
WORK_IN_progress_PREFIXES=WIP:,[WIP]
|
||||
@@ -167,7 +191,7 @@ EOF
|
||||
}
|
||||
|
||||
@test "treats top-level configuration as section-less" {
|
||||
expect_environment_to_ini_call
|
||||
expect_gitea_config_edit_ini_call
|
||||
write_mounted_file "inlines" "_generals_" "$(cat << EOF
|
||||
APP_NAME=Hello top-level configuration
|
||||
RUN_MODE=dev
|
||||
|
||||
@@ -0,0 +1,64 @@
|
||||
suite: Admin secret template
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/secret_admin.yaml
|
||||
tests:
|
||||
- it: skips rendering when the admin user is disabled
|
||||
set:
|
||||
secrets.admin.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: skips rendering using an existing secret reference
|
||||
set:
|
||||
secrets.admin.enabled: true
|
||||
secrets.admin.existingSecret.enabled: true
|
||||
secrets.admin.existingSecret.secretName: "external-secret-reference"
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: fails rendering without credentials
|
||||
set:
|
||||
secrets.admin.new.password: ""
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: Either specify `secrets.admin.new.username` and `secrets.admin.new.password` or reference an existing Secret via `secrets.admin.existingSecret`
|
||||
|
||||
- it: renders the secret specification with the default credentials
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- documentIndex: 0
|
||||
containsDocument:
|
||||
kind: Secret
|
||||
apiVersion: v1
|
||||
name: gitea-unittests-admin
|
||||
- isNotNullOrEmpty:
|
||||
path: metadata.labels
|
||||
- equal:
|
||||
path: data.email
|
||||
value: "Z2l0ZWFAbG9jYWwuZG9tYWlu"
|
||||
- equal:
|
||||
path: data.password
|
||||
value: "cjhzQThDUEhEOSFidDZk"
|
||||
- equal:
|
||||
path: data.username
|
||||
value: "Z2l0ZWFfYWRtaW4="
|
||||
|
||||
- it: supports custom annotations and labels
|
||||
set:
|
||||
secrets.admin.new.annotations:
|
||||
custom-annotation: annotation-value
|
||||
secrets.admin.new.labels:
|
||||
custom-label: label-value
|
||||
asserts:
|
||||
- equal:
|
||||
path: metadata.annotations["custom-annotation"]
|
||||
value: annotation-value
|
||||
- equal:
|
||||
path: metadata.labels["custom-label"]
|
||||
value: label-value
|
||||
@@ -1,12 +0,0 @@
|
||||
suite: Check if actions raises an error
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
tests:
|
||||
- it: fails when trying to configure actions due to removal
|
||||
set:
|
||||
actions:
|
||||
enabled: true
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: The actions sub-chart has been outsourced to a dedicated chart available at https://gitea.com/gitea/helm-actions. For assistance with the migration process, check https://gitea.com/gitea/helm-actions/issues/9.
|
||||
@@ -3,17 +3,17 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
tests:
|
||||
- it: "actions are enabled by default (based on vanilla Gitea behavior)"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
notExists:
|
||||
path: stringData.actions
|
||||
|
||||
- it: "actions can be disabled via inline config"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
gitea.config.actions.ENABLED: false
|
||||
asserts:
|
||||
|
||||
@@ -3,26 +3,9 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
tests:
|
||||
- it: "cache is configured correctly for valkey-cluster"
|
||||
template: templates/gitea/config.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: true
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
equal:
|
||||
path: stringData.cache
|
||||
value: |-
|
||||
ADAPTER=redis
|
||||
HOST=redis+cluster://:@gitea-unittests-valkey-cluster-headless.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
|
||||
- it: "cache is configured correctly for valkey"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: true
|
||||
asserts:
|
||||
@@ -31,13 +14,11 @@ tests:
|
||||
path: stringData.cache
|
||||
value: |-
|
||||
ADAPTER=redis
|
||||
HOST=redis://:changeme@gitea-unittests-valkey-headless.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
HOST=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
|
||||
- it: "cache is configured correctly for 'memory' when valkey (or valkey-cluster) is disabled"
|
||||
template: templates/gitea/config.yaml
|
||||
- it: "cache is configured correctly for 'memory' when valkey is disabled"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
@@ -48,11 +29,9 @@ tests:
|
||||
ADAPTER=memory
|
||||
HOST=
|
||||
|
||||
- it: "cache can be customized when valkey (or valkey-cluster) is disabled"
|
||||
template: templates/gitea/config.yaml
|
||||
- it: "cache can be customized when valkey is disabled"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
gitea.config.cache.ADAPTER: custom-adapter
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
suite: config template | config_environment.sh
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
tests:
|
||||
- it: uses `gitea config edit-ini` to write app.ini from environment variables
|
||||
template: templates/gitea/secret_config.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData["config_environment.sh"]
|
||||
pattern: 'gitea config edit-ini --apply-env --config .+GITEA_APP_INI.+ --out .+GITEA_APP_INI'
|
||||
@@ -4,7 +4,7 @@ release:
|
||||
namespace: testing
|
||||
tests:
|
||||
- it: metrics token is set
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
gitea:
|
||||
metrics:
|
||||
@@ -18,7 +18,7 @@ tests:
|
||||
ENABLED=true
|
||||
TOKEN=somepassword
|
||||
- it: metrics token is empty
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
gitea:
|
||||
metrics:
|
||||
@@ -31,7 +31,7 @@ tests:
|
||||
value: |-
|
||||
ENABLED=true
|
||||
- it: metrics token is nil
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
gitea:
|
||||
metrics:
|
||||
@@ -44,7 +44,7 @@ tests:
|
||||
value: |-
|
||||
ENABLED=true
|
||||
- it: does not configures a token if metrics are disabled
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
gitea:
|
||||
metrics:
|
||||
|
||||
@@ -3,26 +3,9 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
tests:
|
||||
- it: "queue is configured correctly for valkey-cluster"
|
||||
template: templates/gitea/config.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: true
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
equal:
|
||||
path: stringData.queue
|
||||
value: |-
|
||||
CONN_STR=redis+cluster://:@gitea-unittests-valkey-cluster-headless.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
TYPE=redis
|
||||
|
||||
- it: "queue is configured correctly for valkey"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: true
|
||||
asserts:
|
||||
@@ -30,14 +13,12 @@ tests:
|
||||
equal:
|
||||
path: stringData.queue
|
||||
value: |-
|
||||
CONN_STR=redis://:changeme@gitea-unittests-valkey-headless.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
CONN_STR=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
TYPE=redis
|
||||
|
||||
- it: "queue is configured correctly for 'levelDB' when valkey (and valkey-cluster) is disabled"
|
||||
template: templates/gitea/config.yaml
|
||||
- it: "queue is configured correctly for 'levelDB' when valkey is disabled"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
@@ -48,11 +29,9 @@ tests:
|
||||
CONN_STR=
|
||||
TYPE=level
|
||||
|
||||
- it: "queue can be customized when valkey (and valkey-cluster) are disabled"
|
||||
template: templates/gitea/config.yaml
|
||||
- it: "queue can be customized when valkey is disabled"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
gitea.config.queue.TYPE: custom-type
|
||||
|
||||
@@ -4,7 +4,7 @@ release:
|
||||
namespace: testing
|
||||
tests:
|
||||
- it: "[default values] uses ingress host for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
@@ -22,7 +22,7 @@ tests:
|
||||
################################################
|
||||
|
||||
- it: "[no ingress hosts] uses gitea http service for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
ingress:
|
||||
hosts: []
|
||||
@@ -43,7 +43,7 @@ tests:
|
||||
################################################
|
||||
|
||||
- it: "[provided via values] uses that for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
gitea.config.server.DOMAIN: provided.example.com
|
||||
ingress:
|
||||
@@ -65,3 +65,94 @@ tests:
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nROOT_URL=http://provided.example.com
|
||||
|
||||
################################################
|
||||
|
||||
- it: "[route enabled] uses route host for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
route:
|
||||
enabled: true
|
||||
host: route.example.com
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nDOMAIN=route.example.com
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nSSH_DOMAIN=route.example.com
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nROOT_URL=http://route.example.com
|
||||
|
||||
################################################
|
||||
|
||||
- it: "[route tls termination] uses https for ROOT_URL"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
route:
|
||||
enabled: true
|
||||
host: route.example.com
|
||||
tls:
|
||||
termination: edge
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nROOT_URL=https://route.example.com
|
||||
|
||||
################################################
|
||||
|
||||
- it: "[HTTPRoute enabled] uses first hostname for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
ingress:
|
||||
hosts: []
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
hostnames:
|
||||
- gw.example.com
|
||||
parentRefs:
|
||||
- name: shared-gateway
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nDOMAIN=gw.example.com
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nSSH_DOMAIN=gw.example.com
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nROOT_URL=http://gw.example.com
|
||||
|
||||
################################################
|
||||
|
||||
- it: "[HTTPRoute tls] switches ROOT_URL to https"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
ingress:
|
||||
hosts: []
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
tls: true
|
||||
hostnames:
|
||||
- gw.example.com
|
||||
parentRefs:
|
||||
- name: shared-gateway
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.server
|
||||
pattern: \nROOT_URL=https://gw.example.com
|
||||
|
||||
@@ -3,26 +3,9 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
tests:
|
||||
- it: "session is configured correctly for valkey-cluster"
|
||||
template: templates/gitea/config.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: true
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
equal:
|
||||
path: stringData.session
|
||||
value: |-
|
||||
PROVIDER=redis
|
||||
PROVIDER_CONFIG=redis+cluster://:@gitea-unittests-valkey-cluster-headless.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
|
||||
- it: "session is configured correctly for valkey"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: true
|
||||
asserts:
|
||||
@@ -31,13 +14,11 @@ tests:
|
||||
path: stringData.session
|
||||
value: |-
|
||||
PROVIDER=redis
|
||||
PROVIDER_CONFIG=redis://:changeme@gitea-unittests-valkey-headless.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
PROVIDER_CONFIG=redis://:changeme@gitea-unittests-valkey.testing.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
|
||||
|
||||
- it: "session is configured correctly for 'memory' when valkey (and valkey-cluster) is disabled"
|
||||
template: templates/gitea/config.yaml
|
||||
- it: "session is configured correctly for 'memory' when valkey is disabled"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
@@ -48,11 +29,9 @@ tests:
|
||||
PROVIDER=memory
|
||||
PROVIDER_CONFIG=
|
||||
|
||||
- it: "session can be customized when valkey (and valkey-cluster) is disabled"
|
||||
template: templates/gitea/config.yaml
|
||||
- it: "session can be customized when valkey is disabled"
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: false
|
||||
gitea.config.session.PROVIDER: custom-provider
|
||||
|
||||
@@ -106,14 +106,23 @@ tests:
|
||||
name: gitea-unittests-postgresql-ha-pgpool
|
||||
namespace: testing
|
||||
- it: "[gitea] connects to pgpool service"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.database
|
||||
pattern: HOST=gitea-unittests-postgresql-ha-pgpool.testing.svc.cluster.local:1234
|
||||
- it: "[gitea] connects to pgpool service with custom cluster domain"
|
||||
set:
|
||||
clusterDomain: my-special-cluster.local
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.database
|
||||
pattern: HOST=gitea-unittests-postgresql-ha-pgpool.testing.svc.my-special-cluster.local:1234
|
||||
- it: "[gitea] connects to configured database"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
|
||||
@@ -65,14 +65,23 @@ tests:
|
||||
name: gitea-unittests-postgresql
|
||||
namespace: testing
|
||||
- it: "[gitea] connects to postgresql service"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.database
|
||||
pattern: HOST=gitea-unittests-postgresql.testing.svc.cluster.local:1234
|
||||
- it: "[gitea] connects to postgresql service with custom cluster domain"
|
||||
set:
|
||||
clusterDomain: my-special-cluster.local
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData.database
|
||||
pattern: HOST=gitea-unittests-postgresql.testing.svc.my-special-cluster.local:1234
|
||||
- it: "[gitea] connects to configured database"
|
||||
template: templates/gitea/config.yaml
|
||||
template: templates/gitea/secret_inlineConfig.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
|
||||
@@ -1,90 +0,0 @@
|
||||
suite: Dependency checks | Customization integrity | valkey-cluster
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
set:
|
||||
valkey:
|
||||
enabled: false
|
||||
valkey-cluster:
|
||||
enabled: true
|
||||
usePassword: false
|
||||
cluster:
|
||||
nodes: 5
|
||||
replicas: 2
|
||||
tests:
|
||||
- it: "[valkey-cluster] configures correct nodes/replicas"
|
||||
template: charts/valkey-cluster/templates/valkey-statefulset.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
equal:
|
||||
path: spec.replicas
|
||||
value: 5
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: spec.template.spec.containers[0].args[0]
|
||||
pattern: VALKEY_CLUSTER_REPLICAS="2"
|
||||
- it: "[valkey-cluster] support auth-less connections"
|
||||
asserts:
|
||||
- template: charts/valkey-cluster/templates/secret.yaml
|
||||
hasDocuments:
|
||||
count: 0
|
||||
- template: charts/valkey-cluster/templates/valkey-statefulset.yaml
|
||||
documentIndex: 0
|
||||
contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: ALLOW_EMPTY_PASSWORD
|
||||
value: "yes"
|
||||
- it: "[valkey-cluster] support auth-full connections"
|
||||
set:
|
||||
valkey-cluster:
|
||||
usePassword: true
|
||||
asserts:
|
||||
- template: charts/valkey-cluster/templates/secret.yaml
|
||||
containsDocument:
|
||||
kind: Secret
|
||||
apiVersion: v1
|
||||
name: gitea-unittests-valkey-cluster
|
||||
namespace: testing
|
||||
- template: charts/valkey-cluster/templates/valkey-statefulset.yaml
|
||||
documentIndex: 0
|
||||
contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: REDISCLI_AUTH
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: gitea-unittests-valkey-cluster
|
||||
key: valkey-password
|
||||
- template: charts/valkey-cluster/templates/valkey-statefulset.yaml
|
||||
documentIndex: 0
|
||||
contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: REDISCLI_AUTH
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: gitea-unittests-valkey-cluster
|
||||
key: valkey-password
|
||||
- it: "[valkey-cluster] renders the referenced service"
|
||||
template: charts/valkey-cluster/templates/headless-svc.yaml
|
||||
asserts:
|
||||
- containsDocument:
|
||||
kind: Service
|
||||
apiVersion: v1
|
||||
name: gitea-unittests-valkey-cluster-headless
|
||||
namespace: testing
|
||||
- documentIndex: 0
|
||||
contains:
|
||||
path: spec.ports
|
||||
content:
|
||||
name: tcp-redis
|
||||
port: 6379
|
||||
targetPort: tcp-redis
|
||||
- it: "[gitea] waits for valkey-cluster to be up and running"
|
||||
template: templates/gitea/init.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData["configure_gitea.sh"]
|
||||
pattern: nc -vz -w2 gitea-unittests-valkey-cluster-headless.testing.svc.cluster.local 6379
|
||||
@@ -3,50 +3,50 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: true
|
||||
architecture: standalone
|
||||
global:
|
||||
valkey:
|
||||
auth:
|
||||
enabled: true
|
||||
aclUsers:
|
||||
default:
|
||||
permissions: "~* &* +@all"
|
||||
password: gitea-password
|
||||
master:
|
||||
count: 2
|
||||
tests:
|
||||
- it: "[valkey] configures correct 'master' nodes"
|
||||
template: charts/valkey/templates/primary/application.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
equal:
|
||||
path: spec.replicas
|
||||
value: 1
|
||||
- it: "[valkey] valkey.global.valkey.password is applied as expected"
|
||||
- it: "[valkey] valkey.auth.aclUsers.default.password is applied as expected"
|
||||
template: charts/valkey/templates/secret.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
equal:
|
||||
path: data["valkey-password"]
|
||||
path: data.default-password
|
||||
value: "Z2l0ZWEtcGFzc3dvcmQ="
|
||||
- it: "[valkey] renders the referenced service"
|
||||
template: charts/valkey/templates/headless-svc.yaml
|
||||
template: charts/valkey/templates/service.yaml
|
||||
asserts:
|
||||
- containsDocument:
|
||||
kind: Service
|
||||
apiVersion: v1
|
||||
name: gitea-unittests-valkey-headless
|
||||
namespace: testing
|
||||
name: gitea-unittests-valkey
|
||||
- documentIndex: 0
|
||||
contains:
|
||||
path: spec.ports
|
||||
content:
|
||||
name: tcp-redis
|
||||
name: tcp
|
||||
port: 6379
|
||||
targetPort: redis
|
||||
targetPort: tcp
|
||||
protocol: TCP
|
||||
- it: "[gitea] waits for valkey to be up and running"
|
||||
template: templates/gitea/init.yaml
|
||||
template: templates/gitea/secret_init.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData["configure_gitea.sh"]
|
||||
pattern: nc -vz -w2 gitea-unittests-valkey-headless.testing.svc.cluster.local 6379
|
||||
pattern: nc -vz -w2 gitea-unittests-valkey.testing.svc.cluster.local 6379
|
||||
- it: "[gitea] waits for valkey to be up and running with custom cluster domain"
|
||||
set:
|
||||
clusterDomain: my-special-cluster.local
|
||||
template: templates/gitea/secret_init.yaml
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: stringData["configure_gitea.sh"]
|
||||
pattern: nc -vz -w2 gitea-unittests-valkey.testing.svc.my-special-cluster.local 6379
|
||||
|
||||
@@ -29,24 +29,9 @@ tests:
|
||||
path: spec.template.spec.containers[0].image
|
||||
# IN CASE OF AN INTENTIONAL MAJOR BUMP, ADJUST THIS TEST
|
||||
pattern: bitnamilegacy/postgresql:17.+$
|
||||
- it: "[valkey-cluster] ensures we detect major image version upgrades"
|
||||
template: charts/valkey-cluster/templates/valkey-statefulset.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: true
|
||||
valkey:
|
||||
enabled: false
|
||||
asserts:
|
||||
- documentIndex: 0
|
||||
matchRegex:
|
||||
path: spec.template.spec.containers[0].image
|
||||
# IN CASE OF AN INTENTIONAL MAJOR BUMP, ADJUST THIS TEST
|
||||
pattern: bitnamilegacy/valkey-cluster:8.+$
|
||||
- it: "[valkey] ensures we detect major image version upgrades"
|
||||
template: charts/valkey/templates/primary/application.yaml
|
||||
template: charts/valkey/templates/deploy_valkey.yaml
|
||||
set:
|
||||
valkey-cluster:
|
||||
enabled: false
|
||||
valkey:
|
||||
enabled: true
|
||||
asserts:
|
||||
@@ -54,4 +39,4 @@ tests:
|
||||
matchRegex:
|
||||
path: spec.template.spec.containers[0].image
|
||||
# IN CASE OF AN INTENTIONAL MAJOR BUMP, ADJUST THIS TEST
|
||||
pattern: bitnamilegacy/valkey:8.+$
|
||||
pattern: valkey/valkey:9.+$
|
||||
|
||||
@@ -4,12 +4,18 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: fails with multiple replicas and "GIT_GC_REPOS" enabled
|
||||
template: templates/gitea/deployment.yaml
|
||||
template: templates/gitea/secret_config.yaml
|
||||
set:
|
||||
replicaCount: 2
|
||||
deployment:
|
||||
replicas: 2
|
||||
persistence:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
@@ -22,16 +28,18 @@ tests:
|
||||
- failedTemplate:
|
||||
errorMessage: "Invoking the garbage collector via CRON is not yet supported when running with multiple replicas. Please set 'gitea.config.cron.GIT_GC_REPOS.enabled = false'."
|
||||
- it: fails with multiple replicas and RWX file system not set
|
||||
template: templates/gitea/deployment.yaml
|
||||
template: templates/gitea/secret_config.yaml
|
||||
set:
|
||||
replicaCount: 2
|
||||
deployment:
|
||||
replicas: 2
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "When using multiple replicas, a RWX file system is required and persistence.accessModes[0] must be set to ReadWriteMany."
|
||||
- it: fails with multiple replicas and bleve issue indexer
|
||||
template: templates/gitea/deployment.yaml
|
||||
template: templates/gitea/secret_config.yaml
|
||||
set:
|
||||
replicaCount: 2
|
||||
deployment:
|
||||
replicas: 2
|
||||
persistence:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
@@ -43,9 +51,10 @@ tests:
|
||||
- failedTemplate:
|
||||
errorMessage: "When using multiple replicas, the issue indexer (gitea.config.indexer.ISSUE_INDEXER_TYPE) must be set to a HA-ready provider such as 'meilisearch', 'elasticsearch' or 'db' (if the DB is HA-ready)."
|
||||
- it: fails with multiple replicas and bleve repo indexer
|
||||
template: templates/gitea/deployment.yaml
|
||||
template: templates/gitea/secret_config.yaml
|
||||
set:
|
||||
replicaCount: 2
|
||||
deployment:
|
||||
replicas: 2
|
||||
persistence:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
|
||||
@@ -0,0 +1,103 @@
|
||||
suite: deployment template (admin user)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: reads the admin credentials from the generated secret
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: username
|
||||
name: gitea-unittests-admin
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: password
|
||||
name: gitea-unittests-admin
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_EMAIL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: email
|
||||
name: gitea-unittests-admin
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_PASSWORD_MODE
|
||||
value: keepUpdated
|
||||
|
||||
- it: reads the admin credentials from the configured keys of an existing secret
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.existingSecret.enabled: true
|
||||
secrets.admin.existingSecret.secretName: custom-admin-secret
|
||||
secrets.admin.existingSecret.emailKey: custom-email
|
||||
secrets.admin.existingSecret.passwordKey: custom-password
|
||||
secrets.admin.existingSecret.usernameKey: custom-username
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: custom-username
|
||||
name: custom-admin-secret
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: custom-password
|
||||
name: custom-admin-secret
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_EMAIL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
key: custom-email
|
||||
name: custom-admin-secret
|
||||
|
||||
- it: omits the admin environment when the admin user is disabled
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.enabled: false
|
||||
asserts:
|
||||
- notContains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_USERNAME
|
||||
any: true
|
||||
- notContains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: GITEA_ADMIN_PASSWORD_MODE
|
||||
any: true
|
||||
|
||||
- it: fails on an unsupported password mode
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.passwordMode: unsupported
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`secrets.admin.passwordMode` must be set to one of 'keepUpdated', 'initialOnlyNoReset', or 'initialOnlyRequireReset'. Received: 'unsupported'"
|
||||
@@ -4,7 +4,12 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: renders a deployment
|
||||
template: templates/gitea/deployment.yaml
|
||||
@@ -15,6 +20,13 @@ tests:
|
||||
kind: Deployment
|
||||
apiVersion: apps/v1
|
||||
name: gitea-unittests
|
||||
- it: renders no deployment when disabled
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
- it: deployment labels are set
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
@@ -45,6 +57,31 @@ tests:
|
||||
value:
|
||||
app.kubernetes.io/name: gitea
|
||||
app.kubernetes.io/instance: gitea-unittests
|
||||
- it: deployment labels are always rendered
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- isSubset:
|
||||
path: metadata.labels
|
||||
content:
|
||||
app: gitea
|
||||
app.kubernetes.io/name: gitea
|
||||
app.kubernetes.io/instance: gitea-unittests
|
||||
app.kubernetes.io/managed-by: Helm
|
||||
- it: deployment annotations are undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: metadata.annotations
|
||||
- it: deployment annotations are set
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.annotations:
|
||||
hello: world
|
||||
asserts:
|
||||
- equal:
|
||||
path: metadata.annotations
|
||||
value:
|
||||
hello: world
|
||||
- it: nodeSelector is undefined
|
||||
asserts:
|
||||
- notExists:
|
||||
@@ -52,7 +89,7 @@ tests:
|
||||
template: templates/gitea/deployment.yaml
|
||||
- it: nodeSelector is defined
|
||||
set:
|
||||
nodeSelector:
|
||||
deployment.nodeSelector:
|
||||
foo: bar
|
||||
bar: foo
|
||||
asserts:
|
||||
@@ -62,6 +99,149 @@ tests:
|
||||
foo: bar
|
||||
bar: foo
|
||||
template: templates/gitea/deployment.yaml
|
||||
- it: affinity is undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.affinity
|
||||
- it: affinity is defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.affinity
|
||||
value:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
- it: dnsConfig is undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.dnsConfig
|
||||
- it: dnsConfig is defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.dnsConfig:
|
||||
nameservers:
|
||||
- 192.0.2.1
|
||||
options:
|
||||
- name: ndots
|
||||
value: "2"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.dnsConfig
|
||||
value:
|
||||
nameservers:
|
||||
- 192.0.2.1
|
||||
options:
|
||||
- name: ndots
|
||||
value: "2"
|
||||
- it: priorityClassName is undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.priorityClassName
|
||||
- it: priorityClassName is defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.priorityClassName: high-priority
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.priorityClassName
|
||||
value: high-priority
|
||||
- it: schedulerName is undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.schedulerName
|
||||
- it: schedulerName is defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.schedulerName: stork
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.schedulerName
|
||||
value: stork
|
||||
- it: strategy defaults to a rolling update
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.strategy
|
||||
value:
|
||||
type: RollingUpdate
|
||||
rollingUpdate:
|
||||
maxUnavailable: 0
|
||||
maxSurge: 100%
|
||||
- it: strategy omits rollingUpdate for other strategy types
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.strategy.type: Recreate
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.strategy
|
||||
value:
|
||||
type: Recreate
|
||||
- it: tolerations are undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.tolerations
|
||||
- it: tolerations are defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.tolerations:
|
||||
- key: database/type
|
||||
operator: Equal
|
||||
value: postgres
|
||||
effect: NoSchedule
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.tolerations
|
||||
value:
|
||||
- key: database/type
|
||||
operator: Equal
|
||||
value: postgres
|
||||
effect: NoSchedule
|
||||
- it: topologySpreadConstraints are undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.topologySpreadConstraints
|
||||
- it: topologySpreadConstraints are defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.topologySpreadConstraints:
|
||||
- topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: DoNotSchedule
|
||||
maxSkew: 1
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: gitea-unittests
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.topologySpreadConstraints
|
||||
value:
|
||||
- topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: DoNotSchedule
|
||||
maxSkew: 1
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/instance: gitea-unittests
|
||||
|
||||
- it: "injects TMP_EXISTING_ENVS_FILE as environment variable to 'init-app-ini' init container"
|
||||
template: templates/gitea/deployment.yaml
|
||||
@@ -79,10 +259,37 @@ tests:
|
||||
content:
|
||||
name: ENV_TO_INI_MOUNT_POINT
|
||||
value: /env-to-ini-mounts
|
||||
- it: "deployment.gitea.env is injected into all init containers and the gitea container"
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.gitea.env:
|
||||
- name: VARIABLE
|
||||
value: my-value
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[0].env
|
||||
content:
|
||||
name: VARIABLE
|
||||
value: my-value
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[1].env
|
||||
content:
|
||||
name: VARIABLE
|
||||
value: my-value
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
content:
|
||||
name: VARIABLE
|
||||
value: my-value
|
||||
- contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: VARIABLE
|
||||
value: my-value
|
||||
- it: CPU resources are defined as well as GOMAXPROCS
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
resources:
|
||||
deployment.gitea.resources:
|
||||
limits:
|
||||
cpu: 200ms
|
||||
memory: 200Mi
|
||||
@@ -107,6 +314,45 @@ tests:
|
||||
requests:
|
||||
cpu: 100ms
|
||||
memory: 100Mi
|
||||
- it: container resources default to an empty map and GOMAXPROCS is omitted
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].resources
|
||||
value: {}
|
||||
- notContains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: GOMAXPROCS
|
||||
valueFrom:
|
||||
resourceFieldRef:
|
||||
divisor: "1"
|
||||
resource: limits.cpu
|
||||
- it: pod level resources are undefined
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.resources
|
||||
- it: pod level resources are defined
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.resources:
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.resources
|
||||
value:
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 250m
|
||||
memory: 256Mi
|
||||
- it: Init containers have correct volumeMount path
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
|
||||
@@ -0,0 +1,158 @@
|
||||
suite: deployment template (checksum annotations)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: omits the checksum annotations by default
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.enabled: true
|
||||
secrets.config.enabled: true
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.new.privateKey: |
|
||||
-----BEGIN PGP PRIVATE KEY BLOCK-----
|
||||
-----END PGP PRIVATE KEY BLOCK-----
|
||||
secrets.init.enabled: true
|
||||
secrets.inlineConfig.enabled: true
|
||||
secrets.metrics.enabled: true
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/admin"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/config"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/gpg"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/init"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/inlineConfig"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/metrics"]
|
||||
|
||||
- it: adds a checksum annotation for every Secret when addSHASumAnnotation is enabled
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.addSHASumAnnotation: true
|
||||
secrets.admin.enabled: true
|
||||
|
||||
secrets.config.addSHASumAnnotation: true
|
||||
secrets.config.enabled: true
|
||||
|
||||
secrets.gpg.addSHASumAnnotation: true
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.new.privateKey: |
|
||||
-----BEGIN PGP PRIVATE KEY BLOCK-----
|
||||
-----END PGP PRIVATE KEY BLOCK-----
|
||||
|
||||
secrets.init.addSHASumAnnotation: true
|
||||
secrets.init.enabled: true
|
||||
|
||||
secrets.inlineConfig.addSHASumAnnotation: true
|
||||
secrets.inlineConfig.enabled: true
|
||||
|
||||
secrets.metrics.addSHASumAnnotation: true
|
||||
secrets.metrics.enabled: true
|
||||
asserts:
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/admin"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/config"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/gpg"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/init"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/inlineConfig"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/metrics"]
|
||||
|
||||
- it: omits the checksum annotation of a single disabled Secret only
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.addSHASumAnnotation: false
|
||||
secrets.admin.enabled: true
|
||||
|
||||
secrets.config.addSHASumAnnotation: false
|
||||
secrets.config.enabled: true
|
||||
|
||||
secrets.gpg.addSHASumAnnotation: false
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.new.privateKey: |
|
||||
-----BEGIN PGP PRIVATE KEY BLOCK-----
|
||||
-----END PGP PRIVATE KEY BLOCK-----
|
||||
|
||||
secrets.init.addSHASumAnnotation: false
|
||||
secrets.init.enabled: true
|
||||
|
||||
secrets.inlineConfig.addSHASumAnnotation: false
|
||||
secrets.inlineConfig.enabled: true
|
||||
|
||||
secrets.metrics.addSHASumAnnotation: false
|
||||
secrets.metrics.enabled: true
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/admin"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/config"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/gpg"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/init"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/inlineConfig"]
|
||||
- notExists:
|
||||
path: spec.template.metadata.annotations["checksum/metrics"]
|
||||
|
||||
- it: adds the checksum of Secrets provided by the user
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.admin.enabled: true
|
||||
secrets.admin.addSHASumAnnotation: true
|
||||
secrets.admin.existingSecret.enabled: true
|
||||
secrets.admin.existingSecret.secretName: custom-admin
|
||||
|
||||
secrets.config.enabled: true
|
||||
secrets.config.addSHASumAnnotation: true
|
||||
secrets.config.existingSecret.enabled: true
|
||||
secrets.config.existingSecret.secretName: custom-config
|
||||
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.addSHASumAnnotation: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: custom-gpg
|
||||
|
||||
secrets.init.enabled: true
|
||||
secrets.init.addSHASumAnnotation: true
|
||||
secrets.init.existingSecret.enabled: true
|
||||
secrets.init.existingSecret.secretName: custom-init
|
||||
|
||||
secrets.inlineConfig.enabled: true
|
||||
secrets.inlineConfig.addSHASumAnnotation: true
|
||||
secrets.inlineConfig.existingSecret.enabled: true
|
||||
secrets.inlineConfig.existingSecret.secretName: custom-inline-config
|
||||
|
||||
secrets.metrics.enabled: true
|
||||
secrets.metrics.addSHASumAnnotation: true
|
||||
secrets.metrics.existingSecret.enabled: true
|
||||
secrets.metrics.existingSecret.secretName: custom-metrics
|
||||
asserts:
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/admin"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/config"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/gpg"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/init"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/inlineConfig"]
|
||||
- exists:
|
||||
path: spec.template.metadata.annotations["checksum/metrics"]
|
||||
@@ -4,7 +4,12 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: Renders a deployment
|
||||
template: templates/gitea/deployment.yaml
|
||||
|
||||
@@ -0,0 +1,208 @@
|
||||
suite: deprecation template (deployment)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deprecation.yaml
|
||||
tests:
|
||||
- it: renders nothing with the default values
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
- it: fails when the removed `affinity` value is set
|
||||
set:
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: kubernetes.io/os
|
||||
operator: In
|
||||
values:
|
||||
- linux
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead."
|
||||
- it: fails when the removed `containerSecurityContext` value is set
|
||||
set:
|
||||
containerSecurityContext:
|
||||
runAsUser: 1000
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`containerSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.gitea.securityContext` instead."
|
||||
- it: fails when the removed `deployment.env` value is set
|
||||
set:
|
||||
deployment.env:
|
||||
- name: VARIABLE
|
||||
value: my-value
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`deployment.env` does no longer exist. Please refer to the changelog and configure `deployment.gitea.env` instead."
|
||||
- it: fails when the removed `dnsConfig` value is set
|
||||
set:
|
||||
dnsConfig:
|
||||
nameservers:
|
||||
- 192.0.2.1
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`dnsConfig` does no longer exist. Please refer to the changelog and configure `deployment.dnsConfig` instead."
|
||||
- it: fails when the removed `extraContainerVolumeMounts` value is set
|
||||
set:
|
||||
extraContainerVolumeMounts:
|
||||
- name: postgres-ssl-vol
|
||||
mountPath: /pg-ssl
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`extraContainerVolumeMounts` does no longer exist. Please refer to the changelog and configure `deployment.gitea.volumeMounts` instead."
|
||||
- it: fails when the removed `extraVolumes` value is set
|
||||
set:
|
||||
extraVolumes:
|
||||
- name: postgres-ssl-vol
|
||||
secret:
|
||||
secretName: gitea-postgres-ssl
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`extraVolumes` does no longer exist. Please refer to the changelog and configure `deployment.volumes` instead."
|
||||
- it: fails when the removed `nodeSelector` value is set
|
||||
set:
|
||||
nodeSelector:
|
||||
foo: bar
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`nodeSelector` does no longer exist. Please refer to the changelog and configure `deployment.nodeSelector` instead."
|
||||
- it: fails when the removed `openshift.hostUsers` value is set
|
||||
set:
|
||||
openshift.hostUsers: false
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`openshift.hostUsers` does no longer exist. Please refer to the changelog and configure `deployment.hostUsers` instead."
|
||||
- it: fails when the removed `priorityClassName` value is set
|
||||
set:
|
||||
priorityClassName: high-priority
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead."
|
||||
- it: fails when the removed `podSecurityContext` value is set
|
||||
set:
|
||||
podSecurityContext:
|
||||
fsGroup: 1000
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`podSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` instead."
|
||||
- it: fails when the removed `postExtraInitContainers` value is set
|
||||
set:
|
||||
postExtraInitContainers:
|
||||
- name: post-init-container
|
||||
image: docker.io/library/busybox
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`postExtraInitContainers` does no longer exist. Please refer to the changelog and append an entry with a `container` key to `deployment.initContainers` instead."
|
||||
- it: fails when the removed `preExtraInitContainers` value is set
|
||||
set:
|
||||
preExtraInitContainers:
|
||||
- name: pre-init-container
|
||||
image: docker.io/library/busybox
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`preExtraInitContainers` does no longer exist. Please refer to the changelog and prepend an entry with a `container` key to `deployment.initContainers` instead."
|
||||
- it: fails when the removed `resources` value is set
|
||||
set:
|
||||
resources:
|
||||
limits:
|
||||
cpu: 100m
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`resources` does no longer exist. Please refer to the changelog and configure `deployment.gitea.resources` instead."
|
||||
- it: fails when the removed `replicaCount` value is set
|
||||
set:
|
||||
replicaCount: 2
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`replicaCount` does no longer exist. Please refer to the changelog and configure `deployment.replicas` instead."
|
||||
- it: fails when the removed `schedulerName` value is set
|
||||
set:
|
||||
schedulerName: stork
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`schedulerName` does no longer exist. Please refer to the changelog and configure `deployment.schedulerName` instead."
|
||||
- it: fails when the removed `securityContext` value is set
|
||||
set:
|
||||
securityContext:
|
||||
runAsUser: 1000
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`securityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` and `deployment.gitea.securityContext` instead."
|
||||
- it: fails when the removed `strategy` value is set
|
||||
set:
|
||||
strategy:
|
||||
type: Recreate
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`strategy` does no longer exist. Please refer to the changelog and configure `deployment.strategy` instead."
|
||||
- it: fails when the removed `tolerations` value is set
|
||||
set:
|
||||
tolerations:
|
||||
- key: database/type
|
||||
operator: Equal
|
||||
value: postgres
|
||||
effect: NoSchedule
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`tolerations` does no longer exist. Please refer to the changelog and configure `deployment.tolerations` instead."
|
||||
- it: fails when the removed `topologySpreadConstraints` value is set
|
||||
set:
|
||||
topologySpreadConstraints:
|
||||
- topologyKey: kubernetes.io/hostname
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "`topologySpreadConstraints` does no longer exist. Please refer to the changelog and configure `deployment.topologySpreadConstraints` instead."
|
||||
- it: skips the deprecation checks when `checkDeprecation` is disabled
|
||||
set:
|
||||
checkDeprecation: false
|
||||
affinity:
|
||||
nodeAffinity: {}
|
||||
containerSecurityContext:
|
||||
runAsUser: 1000
|
||||
deployment.env:
|
||||
- name: VARIABLE
|
||||
value: my-value
|
||||
dnsConfig:
|
||||
nameservers:
|
||||
- 192.0.2.1
|
||||
extraContainerVolumeMounts:
|
||||
- name: postgres-ssl-vol
|
||||
mountPath: /pg-ssl
|
||||
extraVolumes:
|
||||
- name: postgres-ssl-vol
|
||||
secret:
|
||||
secretName: gitea-postgres-ssl
|
||||
nodeSelector:
|
||||
foo: bar
|
||||
podSecurityContext:
|
||||
fsGroup: 1000
|
||||
postExtraInitContainers:
|
||||
- name: post-init-container
|
||||
image: docker.io/library/busybox
|
||||
preExtraInitContainers:
|
||||
- name: pre-init-container
|
||||
image: docker.io/library/busybox
|
||||
priorityClassName: high-priority
|
||||
replicaCount: 2
|
||||
resources:
|
||||
limits:
|
||||
cpu: 100m
|
||||
schedulerName: stork
|
||||
securityContext:
|
||||
runAsUser: 1000
|
||||
strategy:
|
||||
type: Recreate
|
||||
tolerations:
|
||||
- key: database/type
|
||||
operator: Equal
|
||||
value: postgres
|
||||
effect: NoSchedule
|
||||
topologySpreadConstraints:
|
||||
- topologyKey: kubernetes.io/hostname
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
@@ -0,0 +1,87 @@
|
||||
suite: deployment template (extraEnvSourceFile)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: uses direct execution when extraEnvSourceFile is not set
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].command
|
||||
value: ["/usr/sbinx/config_environment.sh"]
|
||||
- notExists:
|
||||
path: spec.template.spec.initContainers[1].args
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[2].command
|
||||
value: ["/usr/sbinx/configure_gitea.sh"]
|
||||
- notExists:
|
||||
path: spec.template.spec.initContainers[2].args
|
||||
|
||||
- it: sources env file in init-app-ini when extraEnvSourceFile is set
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
gitea:
|
||||
extraEnvSourceFile: /vault/secrets/gitea
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].command
|
||||
value: ["/bin/bash", "-c"]
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[1].args[0]
|
||||
pattern: source /vault/secrets/gitea
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[1].args[0]
|
||||
pattern: config_environment\.sh
|
||||
|
||||
- it: sources env file in configure-gitea when extraEnvSourceFile is set
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
gitea:
|
||||
extraEnvSourceFile: /vault/secrets/gitea
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[2].command
|
||||
value: ["/bin/bash", "-c"]
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[2].args[0]
|
||||
pattern: source /vault/secrets/gitea
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[2].args[0]
|
||||
pattern: configure_gitea\.sh
|
||||
|
||||
- it: sources env file in configure-gpg when extraEnvSourceFile is set with signing enabled
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
gitea:
|
||||
extraEnvSourceFile: /vault/secrets/gitea
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[2].command
|
||||
value: ["/bin/bash", "-c"]
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[2].args[0]
|
||||
pattern: source /vault/secrets/gitea
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[2].args[0]
|
||||
pattern: configure_gpg_environment\.sh
|
||||
|
||||
- it: includes file existence check in source command
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
gitea:
|
||||
extraEnvSourceFile: /vault/secrets/gitea
|
||||
asserts:
|
||||
- matchRegex:
|
||||
path: spec.template.spec.initContainers[1].args[0]
|
||||
pattern: "test -f /vault/secrets/gitea"
|
||||
@@ -4,7 +4,12 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: Render the deployment (default)
|
||||
asserts:
|
||||
@@ -18,7 +23,9 @@ tests:
|
||||
|
||||
- it: Render the deployment (signing)
|
||||
set:
|
||||
signing.enabled: true
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
@@ -30,13 +37,20 @@ tests:
|
||||
|
||||
- it: Render the deployment (extraInitContainers)
|
||||
set:
|
||||
postExtraInitContainers:
|
||||
- name: foo
|
||||
deployment.initContainers:
|
||||
- container:
|
||||
name: bar
|
||||
image: docker.io/library/busybox:latest
|
||||
preExtraInitContainers:
|
||||
- name: bar
|
||||
- link: "initDirectories"
|
||||
- link: "initAppIni"
|
||||
- link: "initConfigureGPG"
|
||||
- link: "initConfigureGitea"
|
||||
- container:
|
||||
name: foo
|
||||
image: docker.io/library/busybox:latest
|
||||
signing.enabled: true
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
@@ -45,15 +59,55 @@ tests:
|
||||
path: spec.template.spec.initContainers
|
||||
count: 6
|
||||
template: templates/gitea/deployment.yaml
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers
|
||||
content:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].name
|
||||
value: bar
|
||||
template: templates/gitea/deployment.yaml
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[5].name
|
||||
value: foo
|
||||
template: templates/gitea/deployment.yaml
|
||||
|
||||
- it: renders the chart-managed init containers in the configured order
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initContainers:
|
||||
- link: "initConfigureGitea"
|
||||
- link: "initDirectories"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].name
|
||||
value: configure-gitea
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].name
|
||||
value: init-directories
|
||||
|
||||
- it: fails when an init container entry sets both container and link
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initContainers:
|
||||
- link: "initDirectories"
|
||||
container:
|
||||
name: foo
|
||||
image: docker.io/library/busybox:latest
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "deployment.initContainers[0]: `container` and `link` are mutually exclusive"
|
||||
|
||||
- it: fails when an init container entry sets neither container nor link
|
||||
template: templates/gitea/deployment.yaml
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers
|
||||
content:
|
||||
name: bar
|
||||
image: docker.io/library/busybox:latest
|
||||
set:
|
||||
deployment.initContainers:
|
||||
- name: foo
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "deployment.initContainers[0]: either `container` or `link` must be set"
|
||||
|
||||
- it: fails when an init container links to an unknown configuration
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initContainers:
|
||||
- link: "initSomething"
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: "deployment.initContainers[0]: unknown link `initSomething`, expected one of: initAppIni, initConfigureGPG, initConfigureGitea, initDirectories"
|
||||
|
||||
@@ -7,7 +7,12 @@ chart:
|
||||
appVersion: 1.19.3
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: default values
|
||||
template: templates/gitea/deployment.yaml
|
||||
@@ -18,7 +23,7 @@ tests:
|
||||
- it: tag override
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.tag: "1.19.4"
|
||||
deployment.gitea.image.tag: "1.19.4"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].image
|
||||
@@ -26,7 +31,7 @@ tests:
|
||||
- it: root-based image
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.rootless: false
|
||||
deployment.gitea.image.rootless: false
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].image
|
||||
@@ -34,7 +39,7 @@ tests:
|
||||
- it: scoped registry
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.registry: "example.com"
|
||||
deployment.gitea.image.registry: "example.com"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].image
|
||||
@@ -50,6 +55,8 @@ tests:
|
||||
- it: digest for rootless image
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment:
|
||||
gitea:
|
||||
image:
|
||||
rootless: true
|
||||
digest: sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a
|
||||
@@ -60,6 +67,8 @@ tests:
|
||||
- it: image fullOverride (does not append rootless)
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment:
|
||||
gitea:
|
||||
image:
|
||||
fullOverride: docker.gitea.com/gitea:1.19.3
|
||||
# setting rootless, registry, repository, tag, and digest to prove that override works
|
||||
@@ -75,6 +84,8 @@ tests:
|
||||
- it: digest for root-based image
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment:
|
||||
gitea:
|
||||
image:
|
||||
rootless: false
|
||||
digest: sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a
|
||||
@@ -86,7 +97,7 @@ tests:
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
global.imageRegistry: "global.example.com"
|
||||
image.digest: "sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
|
||||
deployment.gitea.image.digest: "sha256:b28e8f3089b52ebe6693295df142f8c12eff354e9a4a5bfbb5c10f296c3a537a"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].image
|
||||
@@ -94,7 +105,11 @@ tests:
|
||||
- it: correctly renders floating tag references
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.tag: 1.21 # use non-quoted value on purpose. See: https://gitea.com/gitea/helm-gitea/issues/631
|
||||
# use non-quoted values on purpose. See: https://gitea.com/gitea/helm-gitea/issues/631
|
||||
deployment.gitea.image.tag: 1.21
|
||||
deployment.initDirectories.image.tag: 1.21
|
||||
deployment.initAppIni.image.tag: 1.21
|
||||
deployment.initConfigureGitea.image.tag: 1.21
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].image
|
||||
@@ -108,3 +123,18 @@ tests:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].image
|
||||
value: "docker.gitea.com/gitea:1.21-rootless"
|
||||
- it: init containers use their own image configuration
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initDirectories.image.registry: "init.example.com"
|
||||
deployment.initDirectories.image.tag: "1.19.4"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].image
|
||||
value: "init.example.com/gitea:1.19.4-rootless"
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].image
|
||||
value: "docker.gitea.com/gitea:1.19.3-rootless"
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].image
|
||||
value: "docker.gitea.com/gitea:1.19.3-rootless"
|
||||
|
||||
@@ -1,45 +0,0 @@
|
||||
suite: Test ingress tpl use
|
||||
templates:
|
||||
- templates/gitea/ingress.yaml
|
||||
tests:
|
||||
- it: Ingress Class using TPL
|
||||
set:
|
||||
global.ingress.className: "ingress-class"
|
||||
ingress.className: "{{ .Values.global.ingress.className }}"
|
||||
ingress.enabled: true
|
||||
ingress.hosts[0].host: "some-host"
|
||||
ingress.tls:
|
||||
- secretName: gitea-tls
|
||||
hosts:
|
||||
- "some-host"
|
||||
asserts:
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "some-host"
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "some-host"
|
||||
- equal:
|
||||
path: spec.ingressClassName
|
||||
value: "ingress-class"
|
||||
|
||||
- it: hostname using TPL
|
||||
set:
|
||||
global.giteaHostName: "gitea.example.com"
|
||||
ingress.enabled: true
|
||||
ingress.hosts[0].host: "{{ .Values.global.giteaHostName }}"
|
||||
ingress.tls:
|
||||
- secretName: gitea-tls
|
||||
hosts:
|
||||
- "{{ .Values.global.giteaHostName }}"
|
||||
asserts:
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "gitea.example.com"
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "gitea.example.com"
|
||||
@@ -0,0 +1,130 @@
|
||||
suite: deployment template (init container configuration)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: appends the per-container env
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initDirectories.env:
|
||||
- name: INIT_DIRECTORIES
|
||||
value: "1"
|
||||
deployment.gitea.env:
|
||||
- name: SHARED
|
||||
value: "1"
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[0].env
|
||||
content:
|
||||
name: INIT_DIRECTORIES
|
||||
value: "1"
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[0].env
|
||||
content:
|
||||
name: SHARED
|
||||
value: "1"
|
||||
- notContains:
|
||||
path: spec.template.spec.initContainers[1].env
|
||||
content:
|
||||
name: INIT_DIRECTORIES
|
||||
value: "1"
|
||||
|
||||
- it: renders the per-container envFrom
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initAppIni.envFrom:
|
||||
- secretRef:
|
||||
name: special-secret
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.initContainers[0].envFrom
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].envFrom
|
||||
value:
|
||||
- secretRef:
|
||||
name: special-secret
|
||||
|
||||
- it: appends the per-container volumeMounts
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initConfigureGitea.volumeMounts:
|
||||
- name: my-configmap-volume
|
||||
mountPath: /configmap
|
||||
readOnly: true
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[2].volumeMounts
|
||||
content:
|
||||
name: my-configmap-volume
|
||||
mountPath: /configmap
|
||||
readOnly: true
|
||||
- notContains:
|
||||
path: spec.template.spec.initContainers[0].volumeMounts
|
||||
content:
|
||||
name: my-configmap-volume
|
||||
mountPath: /configmap
|
||||
readOnly: true
|
||||
|
||||
- it: overrides the resources of a single init container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.initDirectories.resources:
|
||||
requests:
|
||||
cpu: 500m
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].resources
|
||||
value:
|
||||
requests:
|
||||
cpu: 500m
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].resources
|
||||
value:
|
||||
limits: {}
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
|
||||
- it: overrides the security context of a single init container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.gitea.securityContext:
|
||||
runAsUser: 1000
|
||||
deployment.initDirectories.securityContext:
|
||||
runAsUser: 2000
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].securityContext.runAsUser
|
||||
value: 2000
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].securityContext.runAsUser
|
||||
value: 1000
|
||||
|
||||
- it: renders the envFrom of the gitea container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
deployment.gitea.envFrom:
|
||||
- configMapRef:
|
||||
name: special-config
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].envFrom
|
||||
value:
|
||||
- configMapRef:
|
||||
name: special-config
|
||||
|
||||
- it: omits envFrom when unset
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.containers[0].envFrom
|
||||
- notExists:
|
||||
path: spec.template.spec.initContainers[0].envFrom
|
||||
@@ -3,7 +3,7 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
tests:
|
||||
- it: inline config stringData.server using TPL
|
||||
set:
|
||||
|
||||
@@ -0,0 +1,115 @@
|
||||
suite: deployment template (openshift)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: renders openshift-compatible defaults for chart-managed containers
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
openshift.enabled: true
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.hostUsers
|
||||
- notExists:
|
||||
path: spec.template.spec.securityContext
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[0].securityContext
|
||||
value:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsNonRoot: true
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[1].securityContext
|
||||
value:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsNonRoot: true
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[2].securityContext
|
||||
value:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsNonRoot: true
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].securityContext
|
||||
value:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsNonRoot: true
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
|
||||
- it: does not force runAsUser 1000 for command init containers on OpenShift
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
openshift.enabled: true
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: custom-gpg-secret
|
||||
asserts:
|
||||
- notExists:
|
||||
path: spec.template.spec.initContainers[2].securityContext.runAsUser
|
||||
- notExists:
|
||||
path: spec.template.spec.initContainers[3].securityContext.runAsUser
|
||||
|
||||
- it: preserves explicit pod and container security context overrides on OpenShift
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
openshift:
|
||||
enabled: true
|
||||
deployment:
|
||||
hostUsers: true
|
||||
securityContext:
|
||||
fsGroup: 1000620000
|
||||
gitea:
|
||||
securityContext:
|
||||
runAsUser: 1000620000
|
||||
runAsGroup: 1000620000
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.hostUsers
|
||||
value: true
|
||||
- equal:
|
||||
path: spec.template.spec.securityContext
|
||||
value:
|
||||
fsGroup: 1000620000
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[2].securityContext.runAsUser
|
||||
value: 1000620000
|
||||
- equal:
|
||||
path: spec.template.spec.containers[0].securityContext.runAsGroup
|
||||
value: 1000620000
|
||||
|
||||
- it: renders an explicit hostUsers=false override on OpenShift
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
openshift:
|
||||
enabled: true
|
||||
deployment:
|
||||
hostUsers: false
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.hostUsers
|
||||
value: false
|
||||
@@ -4,7 +4,12 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: renders default liveness probe
|
||||
template: templates/gitea/deployment.yaml
|
||||
|
||||
@@ -4,7 +4,12 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: supports adding a sidecar container
|
||||
template: templates/gitea/deployment.yaml
|
||||
|
||||
@@ -4,7 +4,12 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: skips gpg init container
|
||||
template: templates/gitea/deployment.yaml
|
||||
@@ -17,13 +22,12 @@ tests:
|
||||
- it: skips gpg env in `init-directories` init container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
signing.enabled: false
|
||||
secrets.gpg.enabled: false
|
||||
asserts:
|
||||
- notContains:
|
||||
path: spec.template.spec.initContainers[0].env
|
||||
content:
|
||||
name: GNUPGHOME
|
||||
value: /data/git/.gnupg
|
||||
- it: skips gpg env in runtime container
|
||||
template: templates/gitea/deployment.yaml
|
||||
asserts:
|
||||
|
||||
@@ -4,14 +4,19 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: adds gpg init container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
signing:
|
||||
enabled: true
|
||||
existingSecret: "custom-gpg-secret"
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.template.spec.initContainers[2].name
|
||||
@@ -27,7 +32,10 @@ tests:
|
||||
path: spec.template.spec.initContainers[2].env
|
||||
value:
|
||||
- name: GNUPGHOME
|
||||
value: /data/git/.gnupg
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: custom-gpg-secret
|
||||
key: gpgHome
|
||||
- name: TMP_RAW_GPG_KEY
|
||||
value: /raw/private.asc
|
||||
- equal:
|
||||
@@ -43,31 +51,54 @@ tests:
|
||||
- it: adds gpg env in `init-directories` init container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
signing.enabled: true
|
||||
signing.existingSecret: "custom-gpg-secret"
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.initContainers[0].env
|
||||
content:
|
||||
name: GNUPGHOME
|
||||
value: /data/git/.gnupg
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: custom-gpg-secret
|
||||
key: gpgHome
|
||||
- it: adds gpg env in runtime container
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
signing.enabled: true
|
||||
signing.existingSecret: "custom-gpg-secret"
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: GNUPGHOME
|
||||
value: /data/git/.gnupg
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: custom-gpg-secret
|
||||
key: gpgHome
|
||||
- it: reads the gpg home from the configured key of an existing secret
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "custom-gpg-secret"
|
||||
secrets.gpg.existingSecret.gpgHomeKey: custom-gpg-home
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
content:
|
||||
name: GNUPGHOME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: custom-gpg-secret
|
||||
key: custom-gpg-home
|
||||
- it: adds gpg volume spec
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
signing:
|
||||
enabled: true
|
||||
existingSecret: "gitea-unittests-gpg-key"
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.new.privateKey: "gpg-key-placeholder"
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.volumes
|
||||
@@ -82,9 +113,10 @@ tests:
|
||||
- it: supports gpg volume spec with external reference
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
signing:
|
||||
enabled: true
|
||||
existingSecret: custom-gpg-secret
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: custom-gpg-secret
|
||||
secrets.gpg.existingSecret.privateKeyKey: custom-private-key
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.volumes
|
||||
@@ -93,6 +125,6 @@ tests:
|
||||
secret:
|
||||
secretName: custom-gpg-secret
|
||||
items:
|
||||
- key: privateKey
|
||||
- key: custom-private-key
|
||||
path: private.asc
|
||||
defaultMode: 0100
|
||||
|
||||
@@ -4,12 +4,17 @@ release:
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/deployment.yaml
|
||||
- templates/gitea/config.yaml
|
||||
- templates/gitea/secret_admin.yaml
|
||||
- templates/gitea/secret_config.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
- templates/gitea/secret_init.yaml
|
||||
- templates/gitea/secret_inlineConfig.yaml
|
||||
- templates/gitea/secret_metrics.yaml
|
||||
tests:
|
||||
- it: supports defining SSH log level for root based image
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.rootless: false
|
||||
deployment.gitea.image.rootless: false
|
||||
asserts:
|
||||
- contains:
|
||||
path: spec.template.spec.containers[0].env
|
||||
@@ -19,7 +24,7 @@ tests:
|
||||
- it: supports overriding SSH log level
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.rootless: false
|
||||
deployment.gitea.image.rootless: false
|
||||
gitea.ssh.logLevel: "DEBUG"
|
||||
asserts:
|
||||
- contains:
|
||||
@@ -30,8 +35,8 @@ tests:
|
||||
- it: supports overriding SSH log level (even when image.fullOverride set)
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.fullOverride: docker.gitea.com/gitea:1.19.3
|
||||
image.rootless: false
|
||||
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.19.3
|
||||
deployment.gitea.image.rootless: false
|
||||
gitea.ssh.logLevel: "DEBUG"
|
||||
asserts:
|
||||
- contains:
|
||||
@@ -42,7 +47,7 @@ tests:
|
||||
- it: skips SSH_LOG_LEVEL for rootless image
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.rootless: true
|
||||
deployment.gitea.image.rootless: true
|
||||
gitea.ssh.logLevel: "DEBUG" # explicitly defining a non-standard level here
|
||||
asserts:
|
||||
- notContains:
|
||||
@@ -53,8 +58,8 @@ tests:
|
||||
- it: skips SSH_LOG_LEVEL for rootless image (even when image.fullOverride set)
|
||||
template: templates/gitea/deployment.yaml
|
||||
set:
|
||||
image.fullOverride: docker.gitea.com/gitea:1.19.3
|
||||
image.rootless: true
|
||||
deployment.gitea.image.fullOverride: docker.gitea.com/gitea:1.19.3
|
||||
deployment.gitea.image.rootless: true
|
||||
gitea.ssh.logLevel: "DEBUG" # explicitly defining a non-standard level here
|
||||
asserts:
|
||||
- notContains:
|
||||
|
||||
@@ -7,11 +7,11 @@ release:
|
||||
namespace: testing
|
||||
|
||||
templates:
|
||||
- templates/gitea/pvc.yaml
|
||||
- templates/gitea/persistentVolumeClaim.yaml
|
||||
|
||||
tests:
|
||||
- it: should set storageClassName when persistence.storageClass is defined
|
||||
template: templates/gitea/pvc.yaml
|
||||
template: templates/gitea/persistentVolumeClaim.yaml
|
||||
set:
|
||||
persistence.storageClass: "my-storage-class"
|
||||
asserts:
|
||||
@@ -20,7 +20,7 @@ tests:
|
||||
value: "my-storage-class"
|
||||
|
||||
- it: should set global.storageClass when persistence.storageClass is not defined
|
||||
template: templates/gitea/pvc.yaml
|
||||
template: templates/gitea/persistentVolumeClaim.yaml
|
||||
set:
|
||||
global.storageClass: "default-storage-class"
|
||||
asserts:
|
||||
@@ -29,7 +29,7 @@ tests:
|
||||
value: "default-storage-class"
|
||||
|
||||
- it: should set storageClassName when persistence.storageClass is defined and global.storageClass is defined
|
||||
template: templates/gitea/pvc.yaml
|
||||
template: templates/gitea/persistentVolumeClaim.yaml
|
||||
set:
|
||||
global.storageClass: "default-storage-class"
|
||||
persistence.storageClass: "my-storage-class"
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
suite: ssh-svc / http-svc template (Services configuration)
|
||||
suite: sshService / httpService template (Services configuration)
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/ssh-svc.yaml
|
||||
- templates/gitea/http-svc.yaml
|
||||
- templates/gitea/service_ssh.yaml
|
||||
- templates/gitea/service_http.yaml
|
||||
tests:
|
||||
- it: supports adding custom labels to ssh-svc
|
||||
template: templates/gitea/ssh-svc.yaml
|
||||
- it: supports adding custom labels to sshService
|
||||
template: templates/gitea/service_ssh.yaml
|
||||
set:
|
||||
service:
|
||||
ssh:
|
||||
@@ -19,7 +19,7 @@ tests:
|
||||
value: "testvalue"
|
||||
|
||||
- it: keeps existing labels (ssh)
|
||||
template: templates/gitea/ssh-svc.yaml
|
||||
template: templates/gitea/service_ssh.yaml
|
||||
set:
|
||||
service:
|
||||
ssh:
|
||||
@@ -28,8 +28,8 @@ tests:
|
||||
- exists:
|
||||
path: metadata.labels["app"]
|
||||
|
||||
- it: supports adding custom labels to http-svc
|
||||
template: templates/gitea/http-svc.yaml
|
||||
- it: supports adding custom labels to httpService
|
||||
template: templates/gitea/service_http.yaml
|
||||
set:
|
||||
service:
|
||||
http:
|
||||
@@ -41,7 +41,7 @@ tests:
|
||||
value: "testvalue"
|
||||
|
||||
- it: keeps existing labels (http)
|
||||
template: templates/gitea/http-svc.yaml
|
||||
template: templates/gitea/service_http.yaml
|
||||
set:
|
||||
service:
|
||||
http:
|
||||
@@ -51,7 +51,7 @@ tests:
|
||||
path: metadata.labels["app"]
|
||||
|
||||
- it: render service.ssh.loadBalancerClass if set and type is LoadBalancer
|
||||
template: templates/gitea/ssh-svc.yaml
|
||||
template: templates/gitea/service_ssh.yaml
|
||||
set:
|
||||
service:
|
||||
ssh:
|
||||
@@ -73,7 +73,7 @@ tests:
|
||||
value: ["1.2.3.4/32", "5.6.7.8/32"]
|
||||
|
||||
- it: does not render when loadbalancer properties are set but type is not loadBalancerClass
|
||||
template: templates/gitea/http-svc.yaml
|
||||
template: templates/gitea/service_http.yaml
|
||||
set:
|
||||
service:
|
||||
http:
|
||||
@@ -92,7 +92,7 @@ tests:
|
||||
path: spec.loadBalancerSourceRanges
|
||||
|
||||
- it: does not render loadBalancerClass by default even when type is LoadBalancer
|
||||
template: templates/gitea/http-svc.yaml
|
||||
template: templates/gitea/service_http.yaml
|
||||
set:
|
||||
service:
|
||||
http:
|
||||
@@ -107,8 +107,8 @@ tests:
|
||||
|
||||
- it: both ssh and http services exist
|
||||
templates:
|
||||
- templates/gitea/ssh-svc.yaml
|
||||
- templates/gitea/http-svc.yaml
|
||||
- templates/gitea/service_ssh.yaml
|
||||
- templates/gitea/service_http.yaml
|
||||
asserts:
|
||||
- matchRegex:
|
||||
path: metadata.name
|
||||
|
||||
@@ -0,0 +1,89 @@
|
||||
suite: Test Gateway API backendTLSPolicy.yaml
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/backendTLSPolicy.yaml
|
||||
tests:
|
||||
- it: should not render when gatewayAPI.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: false
|
||||
core:
|
||||
backendTLSPolicy:
|
||||
enabled: true
|
||||
validation:
|
||||
hostname: git.internal
|
||||
caCertificateRefs:
|
||||
- name: gitea-ca
|
||||
group: ""
|
||||
kind: ConfigMap
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should not render when backendTLSPolicy.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
gatewayAPI.core.backendTLSPolicy.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should render a BackendTLSPolicy targeting the http Service by default
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
backendTLSPolicy:
|
||||
enabled: true
|
||||
validation:
|
||||
hostname: git.internal
|
||||
caCertificateRefs:
|
||||
- name: gitea-ca
|
||||
group: ""
|
||||
kind: ConfigMap
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: BackendTLSPolicy
|
||||
- equal:
|
||||
path: apiVersion
|
||||
value: gateway.networking.k8s.io/v1
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: gitea-unittests
|
||||
- equal:
|
||||
path: spec.targetRefs[0].name
|
||||
value: gitea-unittests-http
|
||||
- equal:
|
||||
path: spec.targetRefs[0].kind
|
||||
value: Service
|
||||
- equal:
|
||||
path: spec.validation.hostname
|
||||
value: git.internal
|
||||
|
||||
- it: should fail when validation is missing
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
backendTLSPolicy:
|
||||
enabled: true
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
|
||||
|
||||
- it: should fail when validation is an empty dict
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
backendTLSPolicy:
|
||||
enabled: true
|
||||
validation: {}
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
|
||||
@@ -0,0 +1,105 @@
|
||||
suite: Test Gateway API clientSettingsPolicy.yaml
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/clientSettingsPolicy.yaml
|
||||
tests:
|
||||
- it: should not render when gatewayAPI.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: false
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
body:
|
||||
maxSize: 100m
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should not render when clientSettingsPolicies.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
gatewayAPI.nginx.clientSettingsPolicies.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should render a ClientSettingsPolicy targeting the HTTPRoute by default
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
body:
|
||||
maxSize: 100m
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: ClientSettingsPolicy
|
||||
- equal:
|
||||
path: apiVersion
|
||||
value: gateway.nginx.org/v1alpha1
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: gitea-unittests
|
||||
- equal:
|
||||
path: spec.targetRef.group
|
||||
value: gateway.networking.k8s.io
|
||||
- equal:
|
||||
path: spec.targetRef.kind
|
||||
value: HTTPRoute
|
||||
- equal:
|
||||
path: spec.targetRef.name
|
||||
value: gitea-unittests
|
||||
- equal:
|
||||
path: spec.body.maxSize
|
||||
value: 100m
|
||||
|
||||
- it: should honor a custom targetRef
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
targetRef:
|
||||
group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: shared-gateway
|
||||
body:
|
||||
maxSize: 100m
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.targetRef.kind
|
||||
value: Gateway
|
||||
- equal:
|
||||
path: spec.targetRef.name
|
||||
value: shared-gateway
|
||||
|
||||
- it: should fail when body is missing
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: gatewayAPI.nginx.clientSettingsPolicies.body is required
|
||||
|
||||
- it: should fail when body is an empty dict
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
nginx:
|
||||
clientSettingsPolicies:
|
||||
enabled: true
|
||||
body: {}
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: gatewayAPI.nginx.clientSettingsPolicies.body is required
|
||||
@@ -0,0 +1,117 @@
|
||||
suite: Test Gateway API httpRoute.yaml
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/httpRoute.yaml
|
||||
tests:
|
||||
- it: should not render when gatewayAPI.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: false
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
hostnames:
|
||||
- git.example.com
|
||||
parentRefs:
|
||||
- name: shared-gateway
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should not render when httpRoute.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
gatewayAPI.core.httpRoute.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should render a single HTTPRoute with default rule
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
annotations:
|
||||
example.io/owner: gitea
|
||||
hostnames:
|
||||
- git.example.com
|
||||
parentRefs:
|
||||
- name: shared-gateway
|
||||
namespace: gateway-system
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: HTTPRoute
|
||||
- equal:
|
||||
path: apiVersion
|
||||
value: gateway.networking.k8s.io/v1
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: gitea-unittests
|
||||
- equal:
|
||||
path: metadata.annotations["example.io/owner"]
|
||||
value: gitea
|
||||
- equal:
|
||||
path: spec.parentRefs[0].name
|
||||
value: shared-gateway
|
||||
- equal:
|
||||
path: spec.parentRefs[0].namespace
|
||||
value: gateway-system
|
||||
- equal:
|
||||
path: spec.hostnames[0]
|
||||
value: git.example.com
|
||||
- equal:
|
||||
path: spec.rules[0].matches[0].path.value
|
||||
value: /
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].group
|
||||
value: ""
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].kind
|
||||
value: Service
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].name
|
||||
value: gitea-unittests-http
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].port
|
||||
value: 3000
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].weight
|
||||
value: 1
|
||||
|
||||
- it: should fail when parentRefs missing
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
hostnames:
|
||||
- git.example.com
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: gatewayAPI.core.httpRoute.parentRefs is required
|
||||
|
||||
- it: hostname tpl rendering
|
||||
set:
|
||||
global:
|
||||
giteaHostName: gitea.tpl.example.com
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
httpRoute:
|
||||
enabled: true
|
||||
hostnames:
|
||||
- "{{ .Values.global.giteaHostName }}"
|
||||
parentRefs:
|
||||
- name: gw
|
||||
asserts:
|
||||
- equal:
|
||||
path: spec.hostnames[0]
|
||||
value: gitea.tpl.example.com
|
||||
@@ -0,0 +1,79 @@
|
||||
suite: Test Gateway API tcpRoute.yaml
|
||||
release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/tcpRoute.yaml
|
||||
tests:
|
||||
- it: should not render when gatewayAPI.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: false
|
||||
core:
|
||||
tcpRoute:
|
||||
enabled: true
|
||||
parentRefs:
|
||||
- name: shared-gateway
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should not render when tcpRoute.enabled is false
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
gatewayAPI.core.tcpRoute.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: should render a TCPRoute defaulting to the SSH service
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
tcpRoute:
|
||||
enabled: true
|
||||
parentRefs:
|
||||
- name: shared-gateway
|
||||
sectionName: ssh
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: TCPRoute
|
||||
- equal:
|
||||
path: apiVersion
|
||||
value: gateway.networking.k8s.io/v1
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: gitea-unittests
|
||||
- equal:
|
||||
path: spec.parentRefs[0].sectionName
|
||||
value: ssh
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].group
|
||||
value: ""
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].kind
|
||||
value: Service
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].name
|
||||
value: gitea-unittests-ssh
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].port
|
||||
value: 22
|
||||
- equal:
|
||||
path: spec.rules[0].backendRefs[0].weight
|
||||
value: 1
|
||||
|
||||
- it: should fail when parentRefs missing
|
||||
set:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
core:
|
||||
tcpRoute:
|
||||
enabled: true
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: gatewayAPI.core.tcpRoute.parentRefs is required
|
||||
@@ -3,11 +3,11 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/gpg-secret.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
tests:
|
||||
- it: renders nothing
|
||||
set:
|
||||
signing.enabled: false
|
||||
secrets.gpg.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
@@ -3,28 +3,26 @@ release:
|
||||
name: gitea-unittests
|
||||
namespace: testing
|
||||
templates:
|
||||
- templates/gitea/gpg-secret.yaml
|
||||
- templates/gitea/secret_gpg.yaml
|
||||
tests:
|
||||
- it: fails rendering when nothing is configured
|
||||
set:
|
||||
signing:
|
||||
enabled: true
|
||||
secrets.gpg.enabled: true
|
||||
asserts:
|
||||
- failedTemplate:
|
||||
errorMessage: Either specify `signing.privateKey` or `signing.existingSecret`
|
||||
errorMessage: Either specify `secrets.gpg.new.privateKey` or reference an existing Secret via `secrets.gpg.existingSecret`
|
||||
- it: skips rendering using external secret reference
|
||||
set:
|
||||
signing:
|
||||
enabled: true
|
||||
existingSecret: "external-secret-reference"
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.existingSecret.enabled: true
|
||||
secrets.gpg.existingSecret.secretName: "external-secret-reference"
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
- it: renders secret specification using inline gpg key
|
||||
set:
|
||||
signing:
|
||||
enabled: true
|
||||
privateKey: "gpg-key-placeholder"
|
||||
secrets.gpg.enabled: true
|
||||
secrets.gpg.new.privateKey: "gpg-key-placeholder"
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
@@ -35,6 +33,9 @@ tests:
|
||||
name: gitea-unittests-gpg-key
|
||||
- isNotNullOrEmpty:
|
||||
path: metadata.labels
|
||||
- equal:
|
||||
path: data.gpgHome
|
||||
value: "L2RhdGEvZ2l0Ly5nbnVwZw=="
|
||||
- equal:
|
||||
path: data.privateKey
|
||||
value: "Z3BnLWtleS1wbGFjZWhvbGRlcg=="
|
||||
|
||||
@@ -1,93 +0,0 @@
|
||||
suite: Test ingress.yaml
|
||||
templates:
|
||||
- templates/gitea/ingress.yaml
|
||||
tests:
|
||||
- it: should enable ingress when ingress.enabled is true
|
||||
set:
|
||||
ingress.enabled: true
|
||||
ingress.apiVersion: networking.k8s.io/v1
|
||||
ingress.annotations:
|
||||
kubernetes.io/ingress.class: nginx
|
||||
ingress.className: nginx
|
||||
ingress.tls:
|
||||
- hosts:
|
||||
- example.com
|
||||
secretName: tls-secret
|
||||
ingress.hosts:
|
||||
- host: example.com
|
||||
paths: ["/"]
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: metadata.name
|
||||
value: RELEASE-NAME-gitea
|
||||
- matchRegex:
|
||||
path: apiVersion
|
||||
pattern: networking.k8s.io/v1
|
||||
- equal:
|
||||
path: spec.ingressClassName
|
||||
value: nginx
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "example.com"
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "example.com"
|
||||
- equal:
|
||||
path: spec.tls[0].secretName
|
||||
value: tls-secret
|
||||
- equal:
|
||||
path: metadata.annotations["kubernetes.io/ingress.class"]
|
||||
value: nginx
|
||||
|
||||
- it: should not create ingress when ingress.enabled is false
|
||||
set:
|
||||
ingress.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: Ingress Class using TPL
|
||||
set:
|
||||
global.ingress.className: "ingress-class"
|
||||
ingress.className: "{{ .Values.global.ingress.className }}"
|
||||
ingress.enabled: true
|
||||
ingress.hosts[0].host: "some-host"
|
||||
ingress.tls:
|
||||
- secretName: gitea-tls
|
||||
hosts:
|
||||
- "some-host"
|
||||
asserts:
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "some-host"
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "some-host"
|
||||
- equal:
|
||||
path: spec.ingressClassName
|
||||
value: "ingress-class"
|
||||
|
||||
- it: hostname using TPL
|
||||
set:
|
||||
global.giteaHostName: "gitea.example.com"
|
||||
ingress.enabled: true
|
||||
ingress.hosts[0].host: "{{ .Values.global.giteaHostName }}"
|
||||
ingress.tls:
|
||||
- secretName: gitea-tls
|
||||
hosts:
|
||||
- "{{ .Values.global.giteaHostName }}"
|
||||
asserts:
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "gitea.example.com"
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "gitea.example.com"
|
||||
@@ -1,23 +0,0 @@
|
||||
suite: Test ingress with implicit path defaults
|
||||
templates:
|
||||
- templates/gitea/ingress.yaml
|
||||
tests:
|
||||
- it: should use default path and pathType when no paths are specified
|
||||
set:
|
||||
ingress.enabled: true
|
||||
ingress.hosts:
|
||||
- host: git.example.com
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "git.example.com"
|
||||
- equal:
|
||||
path: spec.rules[0].http.paths[0].path
|
||||
value: "/"
|
||||
- equal:
|
||||
path: spec.rules[0].http.paths[0].pathType
|
||||
value: "Prefix"
|
||||
@@ -1,45 +0,0 @@
|
||||
suite: Test ingress tpl use
|
||||
templates:
|
||||
- templates/gitea/ingress.yaml
|
||||
tests:
|
||||
- it: Ingress Class using TPL
|
||||
set:
|
||||
global.ingress.className: "ingress-class"
|
||||
ingress.className: "{{ .Values.global.ingress.className }}"
|
||||
ingress.enabled: true
|
||||
ingress.hosts[0].host: "some-host"
|
||||
ingress.tls:
|
||||
- secretName: gitea-tls
|
||||
hosts:
|
||||
- "some-host"
|
||||
asserts:
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "some-host"
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "some-host"
|
||||
- equal:
|
||||
path: spec.ingressClassName
|
||||
value: "ingress-class"
|
||||
|
||||
- it: hostname using TPL
|
||||
set:
|
||||
global.giteaHostName: "gitea.example.com"
|
||||
ingress.enabled: true
|
||||
ingress.hosts[0].host: "{{ .Values.global.giteaHostName }}"
|
||||
ingress.tls:
|
||||
- secretName: gitea-tls
|
||||
hosts:
|
||||
- "{{ .Values.global.giteaHostName }}"
|
||||
asserts:
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.tls[0].hosts[0]
|
||||
value: "gitea.example.com"
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "gitea.example.com"
|
||||
@@ -0,0 +1,143 @@
|
||||
suite: Test ingress.yaml
|
||||
chart:
|
||||
appVersion: 1.27.3
|
||||
release:
|
||||
name: gitea-unittest
|
||||
namespace: gitea-debug
|
||||
templates:
|
||||
- templates/gitea/ingress.yaml
|
||||
tests:
|
||||
- it: Skip ingress if ingress is disabled
|
||||
set:
|
||||
ingress.enabled: false
|
||||
service.http.enabled: true
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: Skip ingress if HTTP Service is disabled
|
||||
set:
|
||||
ingress.enabled: true
|
||||
service.http.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: Skip ingress if both ingress and HTTP Service are disabled
|
||||
set:
|
||||
ingress.enabled: false
|
||||
service.http.enabled: false
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 0
|
||||
|
||||
- it: Render ingress with default values
|
||||
set:
|
||||
ingress.enabled: true
|
||||
service.http.enabled: true
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- containsDocument:
|
||||
kind: Ingress
|
||||
apiVersion: networking.k8s.io/v1
|
||||
name: gitea-unittest
|
||||
namespace: gitea-debug
|
||||
- notExists:
|
||||
path: metadata.annotations
|
||||
- isSubset:
|
||||
path: metadata.labels
|
||||
content:
|
||||
app: gitea
|
||||
app.kubernetes.io/instance: gitea-unittest
|
||||
app.kubernetes.io/managed-by: Helm
|
||||
app.kubernetes.io/name: gitea
|
||||
app.kubernetes.io/version: 1.27.3
|
||||
helm.sh/chart: gitea-0.0.0
|
||||
version: 1.27.3
|
||||
- equal:
|
||||
path: spec.ingressClassName
|
||||
value: nginx
|
||||
- contains:
|
||||
path: spec.rules
|
||||
content:
|
||||
host: git.example.com
|
||||
http:
|
||||
paths:
|
||||
- backend:
|
||||
service:
|
||||
name: gitea-unittest-http
|
||||
port:
|
||||
number: 3000
|
||||
path: /
|
||||
pathType: Prefix
|
||||
|
||||
- it: Render ingress with TLS
|
||||
set:
|
||||
ingress.enabled: true
|
||||
ingress.tls:
|
||||
- hosts:
|
||||
- git.example.com
|
||||
secretName: tls-secret
|
||||
service.http.enabled: true
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- contains:
|
||||
path: spec.tls
|
||||
content:
|
||||
hosts:
|
||||
- git.example.com
|
||||
secretName: tls-secret
|
||||
|
||||
- it: Render ingress with custom HTTP service spec
|
||||
set:
|
||||
ingress.enabled: true
|
||||
service.http.enabled: true
|
||||
service.http.port: 32000
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- containsDocument:
|
||||
kind: Ingress
|
||||
apiVersion: networking.k8s.io/v1
|
||||
name: gitea-unittest
|
||||
namespace: gitea-debug
|
||||
- contains:
|
||||
path: spec.rules
|
||||
content:
|
||||
host: git.example.com
|
||||
http:
|
||||
paths:
|
||||
- backend:
|
||||
service:
|
||||
name: gitea-unittest-http
|
||||
port:
|
||||
number: 32000
|
||||
path: /
|
||||
pathType: Prefix
|
||||
|
||||
- it: Render ingress with custom annotations and labels
|
||||
set:
|
||||
ingress.enabled: true
|
||||
ingress.annotations:
|
||||
custom-annotation: custom-value
|
||||
ingress.labels:
|
||||
custom-label: custom-value
|
||||
service.http.enabled: true
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- containsDocument:
|
||||
kind: Ingress
|
||||
apiVersion: networking.k8s.io/v1
|
||||
name: gitea-unittest
|
||||
namespace: gitea-debug
|
||||
- isSubset:
|
||||
path: metadata.annotations
|
||||
content:
|
||||
custom-annotation: custom-value
|
||||
- isSubset:
|
||||
path: metadata.labels
|
||||
content:
|
||||
custom-label: custom-value
|
||||
@@ -1,26 +0,0 @@
|
||||
suite: Test ingress with structured paths
|
||||
templates:
|
||||
- templates/gitea/ingress.yaml
|
||||
tests:
|
||||
- it: should work with structured path definitions
|
||||
set:
|
||||
ingress.enabled: true
|
||||
ingress.hosts:
|
||||
- host: git.devxy.io
|
||||
paths:
|
||||
- path: /
|
||||
pathType: Prefix
|
||||
asserts:
|
||||
- hasDocuments:
|
||||
count: 1
|
||||
- isKind:
|
||||
of: Ingress
|
||||
- equal:
|
||||
path: spec.rules[0].host
|
||||
value: "git.devxy.io"
|
||||
- equal:
|
||||
path: spec.rules[0].http.paths[0].path
|
||||
value: "/"
|
||||
- equal:
|
||||
path: spec.rules[0].http.paths[0].pathType
|
||||
value: "Prefix"
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user