Add full Gateway API support for exposing Gitea via HTTPRoute, TCPRoute, BackendTLSPolicy, and ClientSettingsPolicy resources. New templates: - `httpRoute.yaml` — renders an HTTPRoute with configurable parentRefs, hostnames, and rules (defaults to PathPrefix `/`) - `tcpRoute.yaml` — renders a TCPRoute for SSH traffic - `backendTLSPolicy.yaml` — renders a BackendTLSPolicy for encrypted backend connections with required validation config - `clientSettingsPolicy.yaml` — renders an NGINX Gateway Fabric ClientSettingsPolicy to raise the request body size limit Infrastructure: - `gatewayAPI.enabled` global toggle gates all resources - Resources grouped under `gatewayAPI.core.*` and `gatewayAPI.nginx.*` - Helper templates extracted into dedicated `_*.tpl` files - Service name helpers (`gitea.service.http.name`, `gitea.service.ssh.name`) extracted into `_services.tpl`; service templates renamed to camelCase - `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` auto-resolve from `httpRoute.hostnames[0]`; `httpRoute.tls` switches to `https` Documentation: - New `docs/gateway-api.md` with topology examples, BackendTLSPolicy setup, sectionName guidance, SSH considerations, and NGINX body size limit configuration - `.github/copilot-instructions.md` with project conventions - README parameter table auto-generated via `make readme` Tests: - Helm unit tests for all four new resource templates - Config tests for hostname/TLS resolution from Gateway API values Co-authored-by: Todd Marimon <toddmarimon@gmail.com>
159 lines
4.5 KiB
YAML
159 lines
4.5 KiB
YAML
suite: config template | server section (domain related)
|
|
release:
|
|
name: gitea-unittests
|
|
namespace: testing
|
|
tests:
|
|
- it: "[default values] uses ingress host for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
|
template: templates/gitea/config.yaml
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nDOMAIN=git.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nSSH_DOMAIN=git.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=http://git.example.com
|
|
|
|
################################################
|
|
|
|
- it: "[no ingress hosts] uses gitea http service for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
|
template: templates/gitea/config.yaml
|
|
set:
|
|
ingress:
|
|
hosts: []
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nDOMAIN=gitea-unittests-http.testing.svc.cluster.local
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nSSH_DOMAIN=gitea-unittests-http.testing.svc.cluster.local
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=http://gitea-unittests-http.testing.svc.cluster.local
|
|
|
|
################################################
|
|
|
|
- it: "[provided via values] uses that for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
|
template: templates/gitea/config.yaml
|
|
set:
|
|
gitea.config.server.DOMAIN: provided.example.com
|
|
ingress:
|
|
hosts:
|
|
- host: non-used.example.com
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nDOMAIN=provided.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nSSH_DOMAIN=provided.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=http://provided.example.com
|
|
|
|
################################################
|
|
|
|
- it: "[route enabled] uses route host for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
|
template: templates/gitea/config.yaml
|
|
set:
|
|
route:
|
|
enabled: true
|
|
host: route.example.com
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nDOMAIN=route.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nSSH_DOMAIN=route.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=http://route.example.com
|
|
|
|
################################################
|
|
|
|
- it: "[route tls termination] uses https for ROOT_URL"
|
|
template: templates/gitea/config.yaml
|
|
set:
|
|
route:
|
|
enabled: true
|
|
host: route.example.com
|
|
tls:
|
|
termination: edge
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=https://route.example.com
|
|
|
|
################################################
|
|
|
|
- it: "[HTTPRoute enabled] uses first hostname for DOMAIN|SSH_DOMAIN|ROOT_URL"
|
|
template: templates/gitea/config.yaml
|
|
set:
|
|
ingress:
|
|
hosts: []
|
|
gatewayAPI:
|
|
enabled: true
|
|
core:
|
|
httpRoute:
|
|
enabled: true
|
|
hostnames:
|
|
- gw.example.com
|
|
parentRefs:
|
|
- name: shared-gateway
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nDOMAIN=gw.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nSSH_DOMAIN=gw.example.com
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=http://gw.example.com
|
|
|
|
################################################
|
|
|
|
- it: "[HTTPRoute tls] switches ROOT_URL to https"
|
|
template: templates/gitea/config.yaml
|
|
set:
|
|
ingress:
|
|
hosts: []
|
|
gatewayAPI:
|
|
enabled: true
|
|
core:
|
|
httpRoute:
|
|
enabled: true
|
|
tls: true
|
|
hostnames:
|
|
- gw.example.com
|
|
parentRefs:
|
|
- name: shared-gateway
|
|
asserts:
|
|
- documentIndex: 0
|
|
matchRegex:
|
|
path: stringData.server
|
|
pattern: \nROOT_URL=https://gw.example.com
|