Files
reposilite-charts/unittests/deployment/configPlugins.yaml
T
volker.raschekandCopilot 562001dc0b
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 27s
Generate README / generate-parameters (push) Successful in 42s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 42s
Release / publish-chart (push) Successful in 1m16s
fix(deployment): run plugin container as the reposilite user
The reposilite entrypoint chowns /app to 977:977 whenever it starts as root. The plugin container downloaded
the jar as its own image user (101), so after the first start the file was owned by 977:977 with mode 0644.
Since the plugins emptyDir survives a container restart within the same pod, a restarted plugin container
could no longer overwrite the existing jar and aborted with "Permission denied", which left the pod in a
permanent Init:CrashLoopBackOff until the pod itself was recreated.

Run the plugin container as 977:977 by default and expose the security context as
deployment.pluginContainer.securityContext, so it can be aligned when PUID/PGID are overridden.

Co-authored-by: Copilot <copilot@github.com>
2026-09-27 18:13:56 +02:00

45 lines
1.2 KiB
YAML

chart:
appVersion: 0.1.0
version: 0.1.0
suite: Test reposilite plugins
release:
name: reposilite-unittest
namespace: testing
templates:
- templates/deployment.yaml
- templates/secretPrometheusBasicAuth.yaml
tests:
- it: Test init containers for prometheus
set:
config.plugins.prometheus.enabled: true
config.plugins.prometheus.url: "https://reposilite.com/plugins/prometheus.jar"
deployment.pluginContainer.image.tag: 0.1.0
asserts:
- contains:
path: spec.template.spec.initContainers
content:
args:
- --location
- --fail
- --max-time
- "60"
- --output-dir
- /app/data/plugins
- --output
- prometheus.jar
- https://reposilite.com/plugins/prometheus.jar
name: download-prometheus-plugin
image: docker.io/curlimages/curl:0.1.0
securityContext:
runAsGroup: 977
runAsUser: 977
volumeMounts:
- mountPath: /app/data/plugins
name: plugins
template: templates/deployment.yaml
- contains:
path: spec.template.spec.volumes
content:
name: plugins
emptyDir: {}
template: templates/deployment.yaml