9 Commits
Author SHA1 Message Date
CSRBot e5a9bcdd2d Merge pull request 'chore(deps): update dependency helm-unittest/helm-unittest to v1.2.1' (#50) from renovate/update-helm-plugins into master
Helm / helm-lint (push) Successful in 13s
Helm / helm-unittest (push) Successful in 16s
2026-10-03 16:08:47 +00:00
CSRBot 7400ca6407 chore(deps): update dependency helm-unittest/helm-unittest to v1.2.1
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 16s
Helm / helm-lint (pull_request) Successful in 12s
Helm / helm-unittest (pull_request) Successful in 16s
2026-10-03 16:08:40 +00:00
CSRBot d0dd429ee0 Merge pull request 'chore(deps): update dependency volker.raschek/reposilite-charts to v1.0.1' (#49) from renovate/volker.raschek-reposilite-charts-1.x into master
Helm / helm-lint (push) Successful in 13s
Markdown linter / markdown-link-checker (push) Successful in 53s
Generate README / generate-parameters (push) Successful in 29s
Helm / helm-unittest (push) Successful in 22s
Markdown linter / markdown-lint (push) Successful in 29s
2026-09-27 19:04:59 +00:00
CSRBot d2e3f376d6 chore(deps): update dependency volker.raschek/reposilite-charts to v1.0.1
renovate/artifacts Artifact file update failure
Generate README / generate-parameters (push) Successful in 31s
Helm / helm-unittest (push) Successful in 32s
Markdown linter / markdown-link-checker (push) Successful in 35s
Helm / helm-unittest (pull_request) Successful in 24s
Helm / helm-lint (push) Successful in 16s
Helm / helm-lint (pull_request) Successful in 8s
Markdown linter / markdown-lint (push) Successful in 40s
Markdown linter / markdown-lint (pull_request) Successful in 31s
Markdown linter / markdown-link-checker (pull_request) Successful in 1m16s
Generate README / generate-parameters (pull_request) Successful in 30s
2026-09-27 19:04:24 +00:00
volker.raschekandCopilot 562001dc0b fix(deployment): run plugin container as the reposilite user
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 27s
Generate README / generate-parameters (push) Successful in 42s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 42s
Release / publish-chart (push) Successful in 1m16s
The reposilite entrypoint chowns /app to 977:977 whenever it starts as root. The plugin container downloaded
the jar as its own image user (101), so after the first start the file was owned by 977:977 with mode 0644.
Since the plugins emptyDir survives a container restart within the same pod, a restarted plugin container
could no longer overwrite the existing jar and aborted with "Permission denied", which left the pod in a
permanent Init:CrashLoopBackOff until the pod itself was recreated.

Run the plugin container as 977:977 by default and expose the security context as
deployment.pluginContainer.securityContext, so it can be aligned when PUID/PGID are overridden.

Co-authored-by: Copilot <copilot@github.com>
2026-09-27 18:13:56 +02:00
CSRBot b2b9ab19a0 Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.10.0' (#48) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 14s
2026-09-22 22:18:31 +00:00
CSRBot efd7b694a3 chore(deps): update docker.io/library/node docker tag to v26.10.0
Helm / helm-lint (push) Successful in 7s
Helm / helm-unittest (push) Successful in 23s
Helm / helm-unittest (pull_request) Successful in 14s
Helm / helm-lint (pull_request) Successful in 7s
2026-09-22 22:18:12 +00:00
CSRBot aef598fabe Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.9.0' (#47) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 6s
Helm / helm-unittest (push) Successful in 18s
2026-09-17 01:16:23 +00:00
CSRBot 8d7337a996 chore(deps): update docker.io/library/node docker tag to v26.9.0
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 19s
Helm / helm-lint (pull_request) Successful in 12s
Helm / helm-unittest (pull_request) Successful in 17s
2026-09-17 01:16:02 +00:00
7 changed files with 68 additions and 50 deletions
+1 -1
View File
@@ -15,7 +15,7 @@ on:
jobs: jobs:
generate-parameters: generate-parameters:
container: container:
image: docker.io/library/node:26.8.2-alpine image: docker.io/library/node:26.10.0-alpine
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install tooling - name: Install tooling
+2 -2
View File
@@ -15,7 +15,7 @@ on:
jobs: jobs:
markdown-link-checker: markdown-link-checker:
container: container:
image: docker.io/library/node:26.8.2-alpine image: docker.io/library/node:26.10.0-alpine
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install tooling - name: Install tooling
@@ -30,7 +30,7 @@ jobs:
markdown-lint: markdown-lint:
container: container:
image: docker.io/library/node:26.8.2-alpine image: docker.io/library/node:26.10.0-alpine
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install tooling - name: Install tooling
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"yaml.schemas": { "yaml.schemas": {
"https://raw.githubusercontent.com/helm-unittest/helm-unittest/v1.1.2/schema/helm-testsuite.json": [ "https://raw.githubusercontent.com/helm-unittest/helm-unittest/v1.2.1/schema/helm-testsuite.json": [
"/unittests/**/*.yaml" "/unittests/**/*.yaml"
] ]
}, },
+7 -5
View File
@@ -37,7 +37,7 @@ version of the chart must be in sync with the `values.yaml`. Newer *minor* versi
versions can break something! versions can break something!
```bash ```bash
CHART_VERSION=1.0.0 CHART_VERSION=1.0.1
helm show values volker.raschek/reposilite --version "${CHART_VERSION}" > values.yaml helm show values volker.raschek/reposilite --version "${CHART_VERSION}" > values.yaml
``` ```
@@ -51,7 +51,7 @@ The helm chart also contains a persistent volume claim definition. It persistent
Use the `--set` argument to persist your data. Use the `--set` argument to persist your data.
```bash ```bash
CHART_VERSION=1.0.0 CHART_VERSION=1.0.1
helm install --version "${CHART_VERSION}" reposilite volker.raschek/reposilite \ helm install --version "${CHART_VERSION}" reposilite volker.raschek/reposilite \
persistentVolumeClaim.enabled=true persistentVolumeClaim.enabled=true
``` ```
@@ -72,7 +72,7 @@ connection problems.
> error. > error.
```bash ```bash
CHART_VERSION=1.0.0 CHART_VERSION=1.0.1
helm install --version "${CHART_VERSION}" reposilite volker.raschek/reposilite \ helm install --version "${CHART_VERSION}" reposilite volker.raschek/reposilite \
--set 'deployment.reposilite.env[1].name=REPOSILITE_LOCAL_SSLENABLED' \ --set 'deployment.reposilite.env[1].name=REPOSILITE_LOCAL_SSLENABLED' \
--set 'deployment.reposilite.env[1].value="true"' \ --set 'deployment.reposilite.env[1].value="true"' \
@@ -196,7 +196,7 @@ be set the credentials manually.
The following example enable Prometheus metrics with custom basic auth credentials: The following example enable Prometheus metrics with custom basic auth credentials:
```bash ```bash
CHART_VERSION=1.0.0 CHART_VERSION=1.0.1
helm install --version "${CHART_VERSION}" reposilite volker.raschek/reposilite \ helm install --version "${CHART_VERSION}" reposilite volker.raschek/reposilite \
--set 'prometheus.metrics.enabled=true' \ --set 'prometheus.metrics.enabled=true' \
--set 'prometheus.metrics.basicAuthUsername=my-username' \ --set 'prometheus.metrics.basicAuthUsername=my-username' \
@@ -271,7 +271,7 @@ spec:
### Deployment ### Deployment
| Name | Description | Value | | Name | Description | Value |
| -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ------------------------------------------- | | ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
| `deployment.annotations` | Additional deployment annotations. | `{}` | | `deployment.annotations` | Additional deployment annotations. | `{}` |
| `deployment.labels` | Additional deployment labels. | `{}` | | `deployment.labels` | Additional deployment labels. | `{}` |
| `deployment.additionalContainers` | List of additional containers. | `[]` | | `deployment.additionalContainers` | List of additional containers. | `[]` |
@@ -300,6 +300,8 @@ spec:
| `deployment.pluginContainer.image.repository` | Image repository, eg. `curlimages/curl`. | `curlimages/curl` | | `deployment.pluginContainer.image.repository` | Image repository, eg. `curlimages/curl`. | `curlimages/curl` |
| `deployment.pluginContainer.image.tag` | Custom image tag, eg. `0.1.0`. | `8.22.0` | | `deployment.pluginContainer.image.tag` | Custom image tag, eg. `0.1.0`. | `8.22.0` |
| `deployment.pluginContainer.image.pullPolicy` | Image pull policy. | `IfNotPresent` | | `deployment.pluginContainer.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.pluginContainer.securityContext.runAsGroup` | Group id of the plugin container. | `977` |
| `deployment.pluginContainer.securityContext.runAsUser` | User id of the plugin container. | `977` |
| `deployment.priorityClassName` | PriorityClassName of the Reposilite deployment. | `""` | | `deployment.priorityClassName` | PriorityClassName of the Reposilite deployment. | `""` |
| `deployment.replicas` | Number of replicas for the Reposilite deployment. | `1` | | `deployment.replicas` | Number of replicas for the Reposilite deployment. | `1` |
| `deployment.restartPolicy` | Restart policy of the Reposilite deployment. | `""` | | `deployment.restartPolicy` | Restart policy of the Reposilite deployment. | `""` |
+5 -1
View File
@@ -71,7 +71,11 @@
{{- if eq (include "reposilite.plugins.prometheus.enabled" $) "true" }} {{- if eq (include "reposilite.plugins.prometheus.enabled" $) "true" }}
{{- $fileName := splitList "/" (tpl .Values.config.plugins.prometheus.url $) | last }} {{- $fileName := splitList "/" (tpl .Values.config.plugins.prometheus.url $) | last }}
{{- $individualArgs := concat $pluginContainerArgs (list "--output" $fileName (tpl .Values.config.plugins.prometheus.url $)) }} {{- $individualArgs := concat $pluginContainerArgs (list "--output" $fileName (tpl .Values.config.plugins.prometheus.url $)) }}
{{- $initContainers = concat $initContainers (list (dict "args" $individualArgs "name" "download-prometheus-plugin" "image" $pluginContainerImage "volumeMounts" $pluginContainerVolumeMounts)) }} {{- $pluginContainer := dict "args" $individualArgs "name" "download-prometheus-plugin" "image" $pluginContainerImage "volumeMounts" $pluginContainerVolumeMounts }}
{{- with .Values.deployment.pluginContainer.securityContext }}
{{- $_ := set $pluginContainer "securityContext" . }}
{{- end }}
{{- $initContainers = concat $initContainers (list $pluginContainer) }}
{{- end }} {{- end }}
{{ toYaml (dict "initContainers" $initContainers) }} {{ toYaml (dict "initContainers" $initContainers) }}
+3
View File
@@ -30,6 +30,9 @@ tests:
- https://reposilite.com/plugins/prometheus.jar - https://reposilite.com/plugins/prometheus.jar
name: download-prometheus-plugin name: download-prometheus-plugin
image: docker.io/curlimages/curl:0.1.0 image: docker.io/curlimages/curl:0.1.0
securityContext:
runAsGroup: 977
runAsUser: 977
volumeMounts: volumeMounts:
- mountPath: /app/data/plugins - mountPath: /app/data/plugins
name: plugins name: plugins
+9
View File
@@ -178,6 +178,15 @@ deployment:
tag: "8.22.0" tag: "8.22.0"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
## @param deployment.pluginContainer.securityContext.runAsGroup Group id of the plugin container.
## @param deployment.pluginContainer.securityContext.runAsUser User id of the plugin container.
# Reposilite chowns /app to 977:977 when its entrypoint starts as root. Downloading the plugin as a
# different user leaves behind a file the plugin container can no longer overwrite, which breaks every
# restart that reuses the emptyDir. Align this with PUID/PGID when those are overridden.
securityContext:
runAsGroup: 977
runAsUser: 977
## @param deployment.priorityClassName PriorityClassName of the Reposilite deployment. ## @param deployment.priorityClassName PriorityClassName of the Reposilite deployment.
priorityClassName: "" priorityClassName: ""