Add full Gateway API support for exposing Gitea via HTTPRoute, TCPRoute, BackendTLSPolicy, and ClientSettingsPolicy resources. New templates: - `httpRoute.yaml` — renders an HTTPRoute with configurable parentRefs, hostnames, and rules (defaults to PathPrefix `/`) - `tcpRoute.yaml` — renders a TCPRoute for SSH traffic - `backendTLSPolicy.yaml` — renders a BackendTLSPolicy for encrypted backend connections with required validation config - `clientSettingsPolicy.yaml` — renders an NGINX Gateway Fabric ClientSettingsPolicy to raise the request body size limit Infrastructure: - `gatewayAPI.enabled` global toggle gates all resources - Resources grouped under `gatewayAPI.core.*` and `gatewayAPI.nginx.*` - Helper templates extracted into dedicated `_*.tpl` files - Service name helpers (`gitea.service.http.name`, `gitea.service.ssh.name`) extracted into `_services.tpl`; service templates renamed to camelCase - `ROOT_URL`, `DOMAIN`, and `SSH_DOMAIN` auto-resolve from `httpRoute.hostnames[0]`; `httpRoute.tls` switches to `https` Documentation: - New `docs/gateway-api.md` with topology examples, BackendTLSPolicy setup, sectionName guidance, SSH considerations, and NGINX body size limit configuration - `.github/copilot-instructions.md` with project conventions - README parameter table auto-generated via `make readme` Tests: - Helm unit tests for all four new resource templates - Config tests for hostname/TLS resolution from Gateway API values Co-authored-by: Todd Marimon <toddmarimon@gmail.com>
90 lines
2.3 KiB
YAML
90 lines
2.3 KiB
YAML
suite: Test Gateway API backendTLSPolicy.yaml
|
|
release:
|
|
name: gitea-unittests
|
|
namespace: testing
|
|
templates:
|
|
- templates/gitea/backendTLSPolicy.yaml
|
|
tests:
|
|
- it: should not render when gatewayAPI.enabled is false
|
|
set:
|
|
gatewayAPI:
|
|
enabled: false
|
|
core:
|
|
backendTLSPolicy:
|
|
enabled: true
|
|
validation:
|
|
hostname: git.internal
|
|
caCertificateRefs:
|
|
- name: gitea-ca
|
|
group: ""
|
|
kind: ConfigMap
|
|
asserts:
|
|
- hasDocuments:
|
|
count: 0
|
|
|
|
- it: should not render when backendTLSPolicy.enabled is false
|
|
set:
|
|
gatewayAPI:
|
|
enabled: true
|
|
gatewayAPI.core.backendTLSPolicy.enabled: false
|
|
asserts:
|
|
- hasDocuments:
|
|
count: 0
|
|
|
|
- it: should render a BackendTLSPolicy targeting the http Service by default
|
|
set:
|
|
gatewayAPI:
|
|
enabled: true
|
|
core:
|
|
backendTLSPolicy:
|
|
enabled: true
|
|
validation:
|
|
hostname: git.internal
|
|
caCertificateRefs:
|
|
- name: gitea-ca
|
|
group: ""
|
|
kind: ConfigMap
|
|
asserts:
|
|
- hasDocuments:
|
|
count: 1
|
|
- isKind:
|
|
of: BackendTLSPolicy
|
|
- equal:
|
|
path: apiVersion
|
|
value: gateway.networking.k8s.io/v1
|
|
- equal:
|
|
path: metadata.name
|
|
value: gitea-unittests
|
|
- equal:
|
|
path: spec.targetRefs[0].name
|
|
value: gitea-unittests-http
|
|
- equal:
|
|
path: spec.targetRefs[0].kind
|
|
value: Service
|
|
- equal:
|
|
path: spec.validation.hostname
|
|
value: git.internal
|
|
|
|
- it: should fail when validation is missing
|
|
set:
|
|
gatewayAPI:
|
|
enabled: true
|
|
core:
|
|
backendTLSPolicy:
|
|
enabled: true
|
|
asserts:
|
|
- failedTemplate:
|
|
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
|
|
|
|
- it: should fail when validation is an empty dict
|
|
set:
|
|
gatewayAPI:
|
|
enabled: true
|
|
core:
|
|
backendTLSPolicy:
|
|
enabled: true
|
|
validation: {}
|
|
asserts:
|
|
- failedTemplate:
|
|
errorMessage: gatewayAPI.core.backendTLSPolicy.validation is required
|