`securityContext` was deprecated when the chart split it into a pod-level and a container-level value. It only ever acted as a fallback for the runtime container: when the container-level value was empty, the deprecated map was used instead. That fallback silently changed behaviour depending on whether an unrelated value happened to be set, and it kept a third security-related values path alive next to `deployment.securityContext` and `deployment.gitea.securityContext`. With the fallback gone, `gitea.runtimeContainerSecurityContext` was identical to `gitea.containerSecurityContext`, so the helper was dropped and the Gitea container now reuses the shared one. A deprecation check fails the render when the removed value is still set, because silently ignoring it would drop `runAsUser`, `runAsNonRoot` or the capability set and let the container run with weaker restrictions than intended. BREAKING CHANGE: `securityContext` no longer exists. Use `deployment.securityContext` for the pod-level and `deployment.gitea.securityContext` for the container-level security context. Installations that still set `securityContext` will fail to render unless `checkDeprecation` is set to `false`. Co-authored-by: Copilot <copilot@github.com>
113 lines
5.0 KiB
YAML
113 lines
5.0 KiB
YAML
{{- if .Values.checkDeprecation -}}
|
|
{{/* CUSTOM PROBES */}}
|
|
{{- if .Values.gitea.customLivenessProbe -}}
|
|
{{- fail "`gitea.customLivenessProbe` does no longer exist. Please refer to the changelog and configure `gitea.livenessProbe` instead." -}}
|
|
{{- end -}}
|
|
{{- if .Values.gitea.customReadinessProbe -}}
|
|
{{- fail "`gitea.customReadinessProbe` does no longer exist. Please refer to the changelog and configure `gitea.readinessProbe` instead." -}}
|
|
{{- end -}}
|
|
{{- if .Values.gitea.customStartupProbe -}}
|
|
{{- fail "`gitea.customStartupProbe` does no longer exist. Please refer to the changelog and configure `gitea.startupProbe` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* LDAP SOURCES */}}
|
|
{{- if kindIs "map" .Values.gitea.ldap -}}
|
|
{{- fail "You can configure multiple LDAP sources. Please refer to the changelog and switch `gitea.ldap` from object to array notation." -}}
|
|
{{- end -}}
|
|
|
|
{{/* OAUTH SOURCES */}}
|
|
{{- if kindIs "map" .Values.gitea.oauth -}}
|
|
{{- fail "You can configure multiple OAuth sources. Please refer to the changelog and switch `gitea.oauth` from object to array notation." -}}
|
|
{{- end -}}
|
|
|
|
{{/* BUILTIN */}}
|
|
{{- if .Values.gitea.cache -}}
|
|
{{- if .Values.gitea.cache.builtIn -}}
|
|
{{- fail "`gitea.cache.builtIn` does no longer exist. Please use `memcached` at root level instead." -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- if .Values.gitea.database -}}
|
|
{{- if .Values.gitea.database.builtIn -}}
|
|
{{- fail "`gitea.database.builtIn` does no longer exist. Builtin databases can be configured inside the dependencies itself. Please refer to the changelog." -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- if .Values.gitea.admin -}}
|
|
{{- fail "`gitea.admin` does no longer exist. Please refer to the changelog and configure `secrets.admin` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* SIGNING */}}
|
|
{{- if .Values.signing -}}
|
|
{{- fail "`signing` does no longer exist. Please refer to the changelog and configure `secrets.gpg` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* AFFINITY */}}
|
|
{{- if .Values.affinity -}}
|
|
{{- fail "`affinity` does no longer exist. Please refer to the changelog and configure `deployment.affinity` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* CONTAINER SECURITY CONTEXT */}}
|
|
{{- if .Values.containerSecurityContext -}}
|
|
{{- fail "`containerSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.gitea.securityContext` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* DEPLOYMENT ENV */}}
|
|
{{- if .Values.deployment.env -}}
|
|
{{- fail "`deployment.env` does no longer exist. Please refer to the changelog and configure `deployment.gitea.env` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* DNS CONFIG */}}
|
|
{{- if .Values.dnsConfig -}}
|
|
{{- fail "`dnsConfig` does no longer exist. Please refer to the changelog and configure `deployment.dnsConfig` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* NODE SELECTOR */}}
|
|
{{- if .Values.nodeSelector -}}
|
|
{{- fail "`nodeSelector` does no longer exist. Please refer to the changelog and configure `deployment.nodeSelector` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* PRIORITY CLASS NAME */}}
|
|
{{- if .Values.priorityClassName -}}
|
|
{{- fail "`priorityClassName` does no longer exist. Please refer to the changelog and configure `deployment.priorityClassName` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* POD SECURITY CONTEXT */}}
|
|
{{- if .Values.podSecurityContext -}}
|
|
{{- fail "`podSecurityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* RESOURCES */}}
|
|
{{- if .Values.resources -}}
|
|
{{- fail "`resources` does no longer exist. Please refer to the changelog and configure `deployment.gitea.resources` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* REPLICA COUNT */}}
|
|
{{- if .Values.replicaCount -}}
|
|
{{- fail "`replicaCount` does no longer exist. Please refer to the changelog and configure `deployment.replicas` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* SCHEDULER NAME */}}
|
|
{{- if .Values.schedulerName -}}
|
|
{{- fail "`schedulerName` does no longer exist. Please refer to the changelog and configure `deployment.schedulerName` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* SECURITY CONTEXT */}}
|
|
{{- if .Values.securityContext -}}
|
|
{{- fail "`securityContext` does no longer exist. Please refer to the changelog and configure `deployment.securityContext` and `deployment.gitea.securityContext` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* STRATEGY */}}
|
|
{{- if .Values.strategy -}}
|
|
{{- fail "`strategy` does no longer exist. Please refer to the changelog and configure `deployment.strategy` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* TOLERATIONS */}}
|
|
{{- if .Values.tolerations -}}
|
|
{{- fail "`tolerations` does no longer exist. Please refer to the changelog and configure `deployment.tolerations` instead." -}}
|
|
{{- end -}}
|
|
|
|
{{/* TOPOLOGY SPREAD CONSTRAINTS */}}
|
|
{{- if .Values.topologySpreadConstraints -}}
|
|
{{- fail "`topologySpreadConstraints` does no longer exist. Please refer to the changelog and configure `deployment.topologySpreadConstraints` instead." -}}
|
|
{{- end -}}
|
|
{{- end -}}
|