27 Commits
Author SHA1 Message Date
volker.raschekandCopilot 562001dc0b fix(deployment): run plugin container as the reposilite user
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 27s
Generate README / generate-parameters (push) Successful in 42s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 42s
Release / publish-chart (push) Successful in 1m16s
The reposilite entrypoint chowns /app to 977:977 whenever it starts as root. The plugin container downloaded
the jar as its own image user (101), so after the first start the file was owned by 977:977 with mode 0644.
Since the plugins emptyDir survives a container restart within the same pod, a restarted plugin container
could no longer overwrite the existing jar and aborted with "Permission denied", which left the pod in a
permanent Init:CrashLoopBackOff until the pod itself was recreated.

Run the plugin container as 977:977 by default and expose the security context as
deployment.pluginContainer.securityContext, so it can be aligned when PUID/PGID are overridden.

Co-authored-by: Copilot <copilot@github.com>
2026-09-27 18:13:56 +02:00
CSRBot b2b9ab19a0 Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.10.0' (#48) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 14s
2026-09-22 22:18:31 +00:00
CSRBot efd7b694a3 chore(deps): update docker.io/library/node docker tag to v26.10.0
Helm / helm-lint (push) Successful in 7s
Helm / helm-unittest (push) Successful in 23s
Helm / helm-unittest (pull_request) Successful in 14s
Helm / helm-lint (pull_request) Successful in 7s
2026-09-22 22:18:12 +00:00
CSRBot aef598fabe Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.9.0' (#47) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 6s
Helm / helm-unittest (push) Successful in 18s
2026-09-17 01:16:23 +00:00
CSRBot 8d7337a996 chore(deps): update docker.io/library/node docker tag to v26.9.0
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 19s
Helm / helm-lint (pull_request) Successful in 12s
Helm / helm-unittest (pull_request) Successful in 17s
2026-09-17 01:16:02 +00:00
CSRBot e196b1facc Merge pull request 'chore(deps): update actions/checkout action to v7' (#46) from renovate/actions-checkout-7.x into master
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 36s
2026-09-15 15:37:49 +00:00
CSRBot b09c8c900a chore(deps): update actions/checkout action to v7
Helm / helm-lint (pull_request) Successful in 12s
Helm / helm-unittest (pull_request) Successful in 23s
Helm / helm-lint (push) Successful in 12s
Helm / helm-unittest (push) Successful in 24s
2026-09-15 15:37:43 +00:00
CSRBot 1d0107e4e8 Merge pull request 'chore(deps): update dependency helm to v4.3.0' (#44) from renovate/helm-4.x into master
Helm / helm-lint (push) Successful in 12s
Helm / helm-unittest (push) Successful in 12s
2026-09-10 00:23:09 +00:00
CSRBot 9e20779904 chore(deps): update dependency helm to v4.3.0
Helm / helm-unittest (push) Successful in 21s
Helm / helm-lint (pull_request) Successful in 10s
Helm / helm-lint (push) Successful in 10s
Helm / helm-unittest (pull_request) Successful in 13s
2026-09-10 00:23:03 +00:00
CSRBot ada215ac95 Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.8.2' (#43) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 13s
2026-09-10 00:22:32 +00:00
CSRBot 82497b5549 chore(deps): update docker.io/library/node docker tag to v26.8.2
Helm / helm-lint (pull_request) Successful in 11s
Helm / helm-unittest (push) Successful in 12s
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (pull_request) Successful in 13s
2026-09-10 00:22:13 +00:00
CSRBot 6a0430932d Merge pull request 'chore(deps): update docker.io/curlimages/curl docker tag to v8.22.0' (#42) from renovate/container-images into master
Generate README / generate-parameters (push) Successful in 35s
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Failing after 12s
Markdown linter / markdown-link-checker (push) Successful in 47s
Markdown linter / markdown-lint (push) Successful in 30s
2026-09-02 21:23:19 +00:00
CSRBot 913559cb68 chore(deps): update docker.io/curlimages/curl docker tag to v8.22.0
Generate README / generate-parameters (push) Successful in 53s
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 30s
Markdown linter / markdown-link-checker (push) Successful in 54s
Markdown linter / markdown-lint (push) Successful in 31s
Generate README / generate-parameters (pull_request) Successful in 35s
Helm / helm-lint (pull_request) Successful in 11s
Helm / helm-unittest (pull_request) Failing after 12s
Markdown linter / markdown-link-checker (pull_request) Successful in 41s
Markdown linter / markdown-lint (pull_request) Successful in 31s
2026-09-02 21:23:07 +00:00
CSRBot 306101a95a Merge pull request 'chore(deps): update dzikoysk/reposilite docker tag to v3.6.3' (#41) from renovate/container-images into master
Helm / helm-lint (push) Failing after 0s
Helm / helm-unittest (push) Failing after 1s
2026-08-30 15:22:11 +00:00
CSRBot 2355ee2ae8 chore(deps): update dzikoysk/reposilite docker tag to v3.6.3
Helm / helm-lint (push) Failing after 1s
Helm / helm-unittest (push) Failing after 1s
Helm / helm-lint (pull_request) Failing after 1s
Helm / helm-unittest (pull_request) Failing after 0s
2026-08-30 15:22:05 +00:00
CSRBot c0428c9f79 Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.8.1' (#40) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 13s
Helm / helm-unittest (push) Successful in 16s
2026-08-27 18:22:24 +00:00
CSRBot 677a32a22b chore(deps): update docker.io/library/node docker tag to v26.8.1
Helm / helm-unittest (pull_request) Successful in 16s
Helm / helm-lint (push) Successful in 6s
Helm / helm-lint (pull_request) Successful in 6s
Helm / helm-unittest (push) Successful in 23s
2026-08-27 18:22:06 +00:00
CSRBot 1ce689a440 Merge pull request 'chore(deps): update dzikoysk/reposilite docker tag to v3.6.2' (#39) from renovate/container-images into master
Helm / helm-lint (push) Successful in 12s
Helm / helm-unittest (push) Successful in 16s
2026-08-14 21:21:39 +00:00
CSRBot 3472867330 chore(deps): update dzikoysk/reposilite docker tag to v3.6.2
Helm / helm-lint (push) Successful in 7s
Helm / helm-lint (pull_request) Successful in 6s
Helm / helm-unittest (push) Successful in 24s
Helm / helm-unittest (pull_request) Successful in 15s
2026-08-14 21:21:34 +00:00
CSRBot a6472dd74e Merge pull request 'chore(deps): update dependency helm to v4.2.4' (#37) from renovate/helm-4.x into master
Helm / helm-lint (push) Successful in 5s
Helm / helm-unittest (push) Successful in 15s
2026-08-13 18:24:29 +00:00
CSRBot 99580a070b chore(deps): update dependency helm to v4.2.4
Helm / helm-lint (push) Successful in 6s
Helm / helm-unittest (push) Successful in 16s
Helm / helm-lint (pull_request) Successful in 5s
Helm / helm-unittest (pull_request) Successful in 15s
2026-08-13 18:24:17 +00:00
CSRBot 4115456bcc Merge pull request 'chore(deps): update dzikoysk/reposilite docker tag to v3.6.1' (#36) from renovate/container-images into master
Helm / helm-lint (push) Successful in 13s
Helm / helm-unittest (push) Successful in 15s
2026-08-13 03:17:03 +00:00
CSRBot b3868abfd0 chore(deps): update dzikoysk/reposilite docker tag to v3.6.1
Helm / helm-lint (push) Successful in 7s
Helm / helm-lint (pull_request) Successful in 6s
Helm / helm-unittest (push) Successful in 23s
Helm / helm-unittest (pull_request) Successful in 14s
2026-08-13 03:16:55 +00:00
CSRBot 176a43e1fd Merge pull request 'chore(deps): update dzikoysk/reposilite docker tag to v3.6.0' (#35) from renovate/container-images into master
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 14s
2026-08-11 03:18:33 +00:00
CSRBot 089eb0f09c chore(deps): update dzikoysk/reposilite docker tag to v3.6.0
Helm / helm-lint (pull_request) Successful in 7s
Helm / helm-lint (push) Successful in 6s
Helm / helm-unittest (pull_request) Successful in 23s
Helm / helm-unittest (push) Successful in 15s
2026-08-11 03:18:27 +00:00
CSRBot 0a5f22aebd Merge pull request 'chore(deps): update docker.io/library/node docker tag to v26.7.0' (#33) from renovate/update-docker.iolibrarynode into master
Helm / helm-lint (push) Successful in 12s
Helm / helm-unittest (push) Successful in 25s
2026-08-09 18:27:04 +00:00
CSRBot 24665e2018 chore(deps): update docker.io/library/node docker tag to v26.7.0
Helm / helm-lint (push) Successful in 11s
Helm / helm-unittest (push) Successful in 16s
Helm / helm-lint (pull_request) Successful in 12s
Helm / helm-unittest (pull_request) Successful in 17s
2026-08-09 18:26:45 +00:00
9 changed files with 74 additions and 56 deletions
+2 -2
View File
@@ -15,14 +15,14 @@ on:
jobs: jobs:
generate-parameters: generate-parameters:
container: container:
image: docker.io/library/node:26.5.1-alpine image: docker.io/library/node:26.10.0-alpine
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install tooling - name: Install tooling
run: | run: |
apk update apk update
apk add git npm apk add git npm
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Generate parameter section in README - name: Generate parameter section in README
run: | run: |
npm install npm install
+4 -4
View File
@@ -14,10 +14,10 @@ jobs:
helm-lint: helm-lint:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 - uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with: with:
version: v4.2.3 # renovate: datasource=github-releases depName=helm/helm version: v4.3.0 # renovate: datasource=github-releases depName=helm/helm
- name: Lint helm files - name: Lint helm files
run: | run: |
helm lint --values values.yaml . helm lint --values values.yaml .
@@ -25,10 +25,10 @@ jobs:
helm-unittest: helm-unittest:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1 - uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with: with:
version: v4.2.3 # renovate: datasource=github-releases depName=helm/helm version: v4.3.0 # renovate: datasource=github-releases depName=helm/helm
- env: - env:
HELM_UNITTEST_VERSION: v1.0.0 #renovate: datasource=github-releases depName=helm-unittest/helm-unittest HELM_UNITTEST_VERSION: v1.0.0 #renovate: datasource=github-releases depName=helm-unittest/helm-unittest
name: Install helm-unittest name: Install helm-unittest
+4 -4
View File
@@ -15,14 +15,14 @@ on:
jobs: jobs:
markdown-link-checker: markdown-link-checker:
container: container:
image: docker.io/library/node:26.5.1-alpine image: docker.io/library/node:26.10.0-alpine
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install tooling - name: Install tooling
run: | run: |
apk update apk update
apk add git npm apk add git npm
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Verify links in markdown files - name: Verify links in markdown files
run: | run: |
npm install npm install
@@ -30,14 +30,14 @@ jobs:
markdown-lint: markdown-lint:
container: container:
image: docker.io/library/node:26.5.1-alpine image: docker.io/library/node:26.10.0-alpine
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install tooling - name: Install tooling
run: | run: |
apk update apk update
apk add git apk add git
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Lint markdown files - name: Lint markdown files
run: | run: |
npm install npm install
+2 -2
View File
@@ -8,7 +8,7 @@ on:
jobs: jobs:
publish-chart: publish-chart:
container: container:
image: docker.io/volkerraschek/helm:4.2.3 image: docker.io/volkerraschek/helm:3.19.2
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Install packages via apk - name: Install packages via apk
@@ -16,7 +16,7 @@ jobs:
apk update apk update
apk add git npm jq yq apk add git npm jq yq
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with: with:
fetch-depth: 0 fetch-depth: 0
+1 -1
View File
@@ -5,7 +5,7 @@ annotations:
- name: support - name: support
url: https://git.cryptic.systems/volker.raschek/reposilite-charts/issues url: https://git.cryptic.systems/volker.raschek/reposilite-charts/issues
apiVersion: v2 apiVersion: v2
appVersion: "3.5.28" appVersion: "3.6.3"
description: | description: |
Lightweight and easy-to-use repository management software Lightweight and easy-to-use repository management software
dedicated for the Maven based artifacts in the JVM ecosystem dedicated for the Maven based artifacts in the JVM ecosystem
+4 -2
View File
@@ -271,7 +271,7 @@ spec:
### Deployment ### Deployment
| Name | Description | Value | | Name | Description | Value |
| -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ------------------------------------------- | | ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
| `deployment.annotations` | Additional deployment annotations. | `{}` | | `deployment.annotations` | Additional deployment annotations. | `{}` |
| `deployment.labels` | Additional deployment labels. | `{}` | | `deployment.labels` | Additional deployment labels. | `{}` |
| `deployment.additionalContainers` | List of additional containers. | `[]` | | `deployment.additionalContainers` | List of additional containers. | `[]` |
@@ -298,8 +298,10 @@ spec:
| `deployment.pluginContainer.args` | Arguments passed to the plugin container. | `["--location","--fail","--max-time","60"]` | | `deployment.pluginContainer.args` | Arguments passed to the plugin container. | `["--location","--fail","--max-time","60"]` |
| `deployment.pluginContainer.image.registry` | Image registry, eg. `docker.io`. | `docker.io` | | `deployment.pluginContainer.image.registry` | Image registry, eg. `docker.io`. | `docker.io` |
| `deployment.pluginContainer.image.repository` | Image repository, eg. `curlimages/curl`. | `curlimages/curl` | | `deployment.pluginContainer.image.repository` | Image repository, eg. `curlimages/curl`. | `curlimages/curl` |
| `deployment.pluginContainer.image.tag` | Custom image tag, eg. `0.1.0`. | `8.21.0` | | `deployment.pluginContainer.image.tag` | Custom image tag, eg. `0.1.0`. | `8.22.0` |
| `deployment.pluginContainer.image.pullPolicy` | Image pull policy. | `IfNotPresent` | | `deployment.pluginContainer.image.pullPolicy` | Image pull policy. | `IfNotPresent` |
| `deployment.pluginContainer.securityContext.runAsGroup` | Group id of the plugin container. | `977` |
| `deployment.pluginContainer.securityContext.runAsUser` | User id of the plugin container. | `977` |
| `deployment.priorityClassName` | PriorityClassName of the Reposilite deployment. | `""` | | `deployment.priorityClassName` | PriorityClassName of the Reposilite deployment. | `""` |
| `deployment.replicas` | Number of replicas for the Reposilite deployment. | `1` | | `deployment.replicas` | Number of replicas for the Reposilite deployment. | `1` |
| `deployment.restartPolicy` | Restart policy of the Reposilite deployment. | `""` | | `deployment.restartPolicy` | Restart policy of the Reposilite deployment. | `""` |
+5 -1
View File
@@ -71,7 +71,11 @@
{{- if eq (include "reposilite.plugins.prometheus.enabled" $) "true" }} {{- if eq (include "reposilite.plugins.prometheus.enabled" $) "true" }}
{{- $fileName := splitList "/" (tpl .Values.config.plugins.prometheus.url $) | last }} {{- $fileName := splitList "/" (tpl .Values.config.plugins.prometheus.url $) | last }}
{{- $individualArgs := concat $pluginContainerArgs (list "--output" $fileName (tpl .Values.config.plugins.prometheus.url $)) }} {{- $individualArgs := concat $pluginContainerArgs (list "--output" $fileName (tpl .Values.config.plugins.prometheus.url $)) }}
{{- $initContainers = concat $initContainers (list (dict "args" $individualArgs "name" "download-prometheus-plugin" "image" $pluginContainerImage "volumeMounts" $pluginContainerVolumeMounts)) }} {{- $pluginContainer := dict "args" $individualArgs "name" "download-prometheus-plugin" "image" $pluginContainerImage "volumeMounts" $pluginContainerVolumeMounts }}
{{- with .Values.deployment.pluginContainer.securityContext }}
{{- $_ := set $pluginContainer "securityContext" . }}
{{- end }}
{{- $initContainers = concat $initContainers (list $pluginContainer) }}
{{- end }} {{- end }}
{{ toYaml (dict "initContainers" $initContainers) }} {{ toYaml (dict "initContainers" $initContainers) }}
+3
View File
@@ -30,6 +30,9 @@ tests:
- https://reposilite.com/plugins/prometheus.jar - https://reposilite.com/plugins/prometheus.jar
name: download-prometheus-plugin name: download-prometheus-plugin
image: docker.io/curlimages/curl:0.1.0 image: docker.io/curlimages/curl:0.1.0
securityContext:
runAsGroup: 977
runAsUser: 977
volumeMounts: volumeMounts:
- mountPath: /app/data/plugins - mountPath: /app/data/plugins
name: plugins name: plugins
+10 -1
View File
@@ -175,9 +175,18 @@ deployment:
image: image:
registry: docker.io registry: docker.io
repository: curlimages/curl repository: curlimages/curl
tag: "8.21.0" tag: "8.22.0"
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
## @param deployment.pluginContainer.securityContext.runAsGroup Group id of the plugin container.
## @param deployment.pluginContainer.securityContext.runAsUser User id of the plugin container.
# Reposilite chowns /app to 977:977 when its entrypoint starts as root. Downloading the plugin as a
# different user leaves behind a file the plugin container can no longer overwrite, which breaks every
# restart that reuses the emptyDir. Align this with PUID/PGID when those are overridden.
securityContext:
runAsGroup: 977
runAsUser: 977
## @param deployment.priorityClassName PriorityClassName of the Reposilite deployment. ## @param deployment.priorityClassName PriorityClassName of the Reposilite deployment.
priorityClassName: "" priorityClassName: ""