mirror of
https://gitlab.com/oecis/charts.git
synced 2024-11-15 00:28:59 +00:00
migrate charts
This commit is contained in:
parent
cb608a94f0
commit
69ec141244
5
.envrc
Normal file
5
.envrc
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
mkdir -p $(pwd)/.terragrunt-cache/.plugins
|
||||||
|
export TERRAGRUNT_DOWNLOAD=$(pwd)/.terragrunt-cache
|
||||||
|
export TF_PLUGIN_CACHE_DIR=$(pwd)/.terragrunt-cache/.plugins
|
||||||
|
|
||||||
|
use nix
|
5
.gitignore
vendored
Normal file
5
.gitignore
vendored
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
### Helm ###
|
||||||
|
# Chart dependencies
|
||||||
|
**/charts/*.tgz
|
||||||
|
# Chart packages
|
||||||
|
dist/*.tgz
|
13
.pre-commit-config.yaml
Normal file
13
.pre-commit-config.yaml
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
repos:
|
||||||
|
- repo: https://github.com/norwoodj/helm-docs
|
||||||
|
rev: v1.2.0
|
||||||
|
hooks:
|
||||||
|
- id: helm-docs
|
||||||
|
args:
|
||||||
|
# Make the tool search for charts only under the `example-charts` directory
|
||||||
|
- --chart-search-root=charts
|
||||||
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||||
|
rev: v4.3.0
|
||||||
|
hooks:
|
||||||
|
- id: trailing-whitespace
|
||||||
|
- id: end-of-file-fixer
|
95
README.md
95
README.md
@ -1,92 +1,25 @@
|
|||||||
# charts
|
# charts
|
||||||
|
|
||||||
|
Here you can find a collection of oecis charts :)
|
||||||
|
|
||||||
|
# Publish charts
|
||||||
|
|
||||||
## Getting started
|
## Add oecis.io chart repo
|
||||||
|
|
||||||
To make it easy for you to get started with GitLab, here's a list of recommended next steps.
|
The credentials can be found in vault.
|
||||||
|
|
||||||
Already a pro? Just edit this README.md and make it your own. Want to make it easy? [Use the template at the bottom](#editing-this-readme)!
|
```sh
|
||||||
|
$ helm repo add --username <username> --password <password> oecis https://charts.oecis.io
|
||||||
## Add your files
|
|
||||||
|
|
||||||
- [ ] [Create](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#create-a-file) or [upload](https://docs.gitlab.com/ee/user/project/repository/web_editor.html#upload-a-file) files
|
|
||||||
- [ ] [Add files using the command line](https://docs.gitlab.com/ee/gitlab-basics/add-file.html#add-a-file-using-the-command-line) or push an existing Git repository with the following command:
|
|
||||||
|
|
||||||
```
|
|
||||||
cd existing_repo
|
|
||||||
git remote add origin https://gitlab.com/oecis/charts.git
|
|
||||||
git branch -M main
|
|
||||||
git push -uf origin main
|
|
||||||
```
|
```
|
||||||
|
|
||||||
## Integrate with your tools
|
## Install chartmuseum push plugin
|
||||||
|
|
||||||
- [ ] [Set up project integrations](https://gitlab.com/oecis/charts/-/settings/integrations)
|
```sh
|
||||||
|
$ helm plugin install https://github.com/chartmuseum/helm-push
|
||||||
|
```
|
||||||
|
|
||||||
## Collaborate with your team
|
## Push
|
||||||
|
|
||||||
- [ ] [Invite team members and collaborators](https://docs.gitlab.com/ee/user/project/members/)
|
```sh
|
||||||
- [ ] [Create a new merge request](https://docs.gitlab.com/ee/user/project/merge_requests/creating_merge_requests.html)
|
$ helm cm-push <path> oecis
|
||||||
- [ ] [Automatically close issues from merge requests](https://docs.gitlab.com/ee/user/project/issues/managing_issues.html#closing-issues-automatically)
|
```
|
||||||
- [ ] [Enable merge request approvals](https://docs.gitlab.com/ee/user/project/merge_requests/approvals/)
|
|
||||||
- [ ] [Set auto-merge](https://docs.gitlab.com/ee/user/project/merge_requests/merge_when_pipeline_succeeds.html)
|
|
||||||
|
|
||||||
## Test and Deploy
|
|
||||||
|
|
||||||
Use the built-in continuous integration in GitLab.
|
|
||||||
|
|
||||||
- [ ] [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/index.html)
|
|
||||||
- [ ] [Analyze your code for known vulnerabilities with Static Application Security Testing(SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
|
|
||||||
- [ ] [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
|
|
||||||
- [ ] [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
|
|
||||||
- [ ] [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
|
|
||||||
|
|
||||||
***
|
|
||||||
|
|
||||||
# Editing this README
|
|
||||||
|
|
||||||
When you're ready to make this README your own, just edit this file and use the handy template below (or feel free to structure it however you want - this is just a starting point!). Thank you to [makeareadme.com](https://www.makeareadme.com/) for this template.
|
|
||||||
|
|
||||||
## Suggestions for a good README
|
|
||||||
Every project is different, so consider which of these sections apply to yours. The sections used in the template are suggestions for most open source projects. Also keep in mind that while a README can be too long and detailed, too long is better than too short. If you think your README is too long, consider utilizing another form of documentation rather than cutting out information.
|
|
||||||
|
|
||||||
## Name
|
|
||||||
Choose a self-explaining name for your project.
|
|
||||||
|
|
||||||
## Description
|
|
||||||
Let people know what your project can do specifically. Provide context and add a link to any reference visitors might be unfamiliar with. A list of Features or a Background subsection can also be added here. If there are alternatives to your project, this is a good place to list differentiating factors.
|
|
||||||
|
|
||||||
## Badges
|
|
||||||
On some READMEs, you may see small images that convey metadata, such as whether or not all the tests are passing for the project. You can use Shields to add some to your README. Many services also have instructions for adding a badge.
|
|
||||||
|
|
||||||
## Visuals
|
|
||||||
Depending on what you are making, it can be a good idea to include screenshots or even a video (you'll frequently see GIFs rather than actual videos). Tools like ttygif can help, but check out Asciinema for a more sophisticated method.
|
|
||||||
|
|
||||||
## Installation
|
|
||||||
Within a particular ecosystem, there may be a common way of installing things, such as using Yarn, NuGet, or Homebrew. However, consider the possibility that whoever is reading your README is a novice and would like more guidance. Listing specific steps helps remove ambiguity and gets people to using your project as quickly as possible. If it only runs in a specific context like a particular programming language version or operating system or has dependencies that have to be installed manually, also add a Requirements subsection.
|
|
||||||
|
|
||||||
## Usage
|
|
||||||
Use examples liberally, and show the expected output if you can. It's helpful to have inline the smallest example of usage that you can demonstrate, while providing links to more sophisticated examples if they are too long to reasonably include in the README.
|
|
||||||
|
|
||||||
## Support
|
|
||||||
Tell people where they can go to for help. It can be any combination of an issue tracker, a chat room, an email address, etc.
|
|
||||||
|
|
||||||
## Roadmap
|
|
||||||
If you have ideas for releases in the future, it is a good idea to list them in the README.
|
|
||||||
|
|
||||||
## Contributing
|
|
||||||
State if you are open to contributions and what your requirements are for accepting them.
|
|
||||||
|
|
||||||
For people who want to make changes to your project, it's helpful to have some documentation on how to get started. Perhaps there is a script that they should run or some environment variables that they need to set. Make these steps explicit. These instructions could also be useful to your future self.
|
|
||||||
|
|
||||||
You can also document commands to lint the code or run tests. These steps help to ensure high code quality and reduce the likelihood that the changes inadvertently break something. Having instructions for running tests is especially helpful if it requires external setup, such as starting a Selenium server for testing in a browser.
|
|
||||||
|
|
||||||
## Authors and acknowledgment
|
|
||||||
Show your appreciation to those who have contributed to the project.
|
|
||||||
|
|
||||||
## License
|
|
||||||
For open source projects, say how it is licensed.
|
|
||||||
|
|
||||||
## Project status
|
|
||||||
If you have run out of energy or time for your project, put a note at the top of the README saying that development has slowed down or stopped completely. Someone may choose to fork your project or volunteer to step in as a maintainer or owner, allowing your project to keep going. You can also make an explicit request for maintainers.
|
|
||||||
|
21
charts/cert-manager-webhook-njalla/.helmignore
Normal file
21
charts/cert-manager-webhook-njalla/.helmignore
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
5
charts/cert-manager-webhook-njalla/Chart.yaml
Normal file
5
charts/cert-manager-webhook-njalla/Chart.yaml
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
appVersion: "1.0.1"
|
||||||
|
description: Helm chart for the njalla webhook for cert manager
|
||||||
|
name: cert-manager-webhook-njalla
|
||||||
|
version: 0.1.2
|
27
charts/cert-manager-webhook-njalla/README.md
Normal file
27
charts/cert-manager-webhook-njalla/README.md
Normal file
@ -0,0 +1,27 @@
|
|||||||
|
# cert-manager-webhook-njalla
|
||||||
|
|
||||||
|
![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![AppVersion: 1.0.1](https://img.shields.io/badge/AppVersion-1.0.1-informational?style=flat-square)
|
||||||
|
|
||||||
|
Helm chart for the njalla webhook for cert manager
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| certManager.namespace | string | `"cert-manager"` | |
|
||||||
|
| certManager.serviceAccountName | string | `"cert-manager"` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| groupName | string | `"oecis.io"` | |
|
||||||
|
| image.pullPolicy | string | `"Always"` | |
|
||||||
|
| image.repository | string | `"jrester/cert-manager-webhook-njalla"` | |
|
||||||
|
| image.tag | string | `"latest"` | |
|
||||||
|
| nameOverride | string | `""` | |
|
||||||
|
| nodeSelector | object | `{}` | |
|
||||||
|
| resources | object | `{}` | |
|
||||||
|
| service.port | int | `443` | |
|
||||||
|
| service.type | string | `"ClusterIP"` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
|
||||||
|
----------------------------------------------
|
||||||
|
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
48
charts/cert-manager-webhook-njalla/templates/_helpers.tpl
Normal file
48
charts/cert-manager-webhook-njalla/templates/_helpers.tpl
Normal file
@ -0,0 +1,48 @@
|
|||||||
|
{{/* vim: set filetype=mustache: */}}
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "cert-manager-webhook-njalla.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "cert-manager-webhook-njalla.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- if contains $name .Release.Name -}}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "cert-manager-webhook-njalla.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "cert-manager-webhook-njalla.selfSignedIssuer" -}}
|
||||||
|
{{ printf "%s-selfsign" (include "cert-manager-webhook-njalla.fullname" .) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "cert-manager-webhook-njalla.rootCAIssuer" -}}
|
||||||
|
{{ printf "%s-ca" (include "cert-manager-webhook-njalla.fullname" .) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "cert-manager-webhook-njalla.rootCACertificate" -}}
|
||||||
|
{{ printf "%s-ca" (include "cert-manager-webhook-njalla.fullname" .) }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "cert-manager-webhook-njalla.servingCertificate" -}}
|
||||||
|
{{ printf "%s-webhook-tls" (include "cert-manager-webhook-njalla.fullname" .) }}
|
||||||
|
{{- end -}}
|
19
charts/cert-manager-webhook-njalla/templates/apiservice.yaml
Normal file
19
charts/cert-manager-webhook-njalla/templates/apiservice.yaml
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: apiregistration.k8s.io/v1
|
||||||
|
kind: APIService
|
||||||
|
metadata:
|
||||||
|
name: v1alpha1.{{ .Values.groupName }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
annotations:
|
||||||
|
cert-manager.io/inject-ca-from: "{{ .Release.Namespace }}/{{ include "cert-manager-webhook-njalla.servingCertificate" . }}"
|
||||||
|
spec:
|
||||||
|
group: {{ .Values.groupName }}
|
||||||
|
groupPriorityMinimum: 1000
|
||||||
|
versionPriority: 15
|
||||||
|
service:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
version: v1alpha1
|
68
charts/cert-manager-webhook-njalla/templates/deployment.yaml
Normal file
68
charts/cert-manager-webhook-njalla/templates/deployment.yaml
Normal file
@ -0,0 +1,68 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
spec:
|
||||||
|
serviceAccountName: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
args:
|
||||||
|
- --tls-cert-file=/tls/tls.crt
|
||||||
|
- --tls-private-key-file=/tls/tls.key
|
||||||
|
env:
|
||||||
|
- name: GROUP_NAME
|
||||||
|
value: {{ .Values.groupName | quote }}
|
||||||
|
ports:
|
||||||
|
- name: https
|
||||||
|
containerPort: 443
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
scheme: HTTPS
|
||||||
|
path: /healthz
|
||||||
|
port: https
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
scheme: HTTPS
|
||||||
|
path: /healthz
|
||||||
|
port: https
|
||||||
|
volumeMounts:
|
||||||
|
- name: certs
|
||||||
|
mountPath: /tls
|
||||||
|
readOnly: true
|
||||||
|
resources:
|
||||||
|
{{ toYaml .Values.resources | indent 12 }}
|
||||||
|
volumes:
|
||||||
|
- name: certs
|
||||||
|
secret:
|
||||||
|
secretName: {{ include "cert-manager-webhook-njalla.servingCertificate" . }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{ toYaml . | indent 8 }}
|
||||||
|
{{- end }}
|
76
charts/cert-manager-webhook-njalla/templates/pki.yaml
Normal file
76
charts/cert-manager-webhook-njalla/templates/pki.yaml
Normal file
@ -0,0 +1,76 @@
|
|||||||
|
---
|
||||||
|
# Create a selfsigned Issuer, in order to create a root CA certificate for
|
||||||
|
# signing webhook serving certificates
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Issuer
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.selfSignedIssuer" . }}
|
||||||
|
namespace: {{ .Release.Namespace | quote }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
selfSigned: {}
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Generate a CA Certificate used to sign certificates for the webhook
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.rootCACertificate" . }}
|
||||||
|
namespace: {{ .Release.Namespace | quote }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
secretName: {{ include "cert-manager-webhook-njalla.rootCACertificate" . }}
|
||||||
|
duration: 43800h # 5y
|
||||||
|
issuerRef:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.selfSignedIssuer" . }}
|
||||||
|
commonName: "ca.cert-manager-webhook-njalla.cert-manager"
|
||||||
|
isCA: true
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Create an Issuer that uses the above generated CA certificate to issue certs
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Issuer
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.rootCAIssuer" . }}
|
||||||
|
namespace: {{ .Release.Namespace | quote }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
ca:
|
||||||
|
secretName: {{ include "cert-manager-webhook-njalla.rootCACertificate" . }}
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Finally, generate a serving certificate for the webhook to use
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.servingCertificate" . }}
|
||||||
|
namespace: {{ .Release.Namespace | quote }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
secretName: {{ include "cert-manager-webhook-njalla.servingCertificate" . }}
|
||||||
|
duration: 8760h # 1y
|
||||||
|
issuerRef:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.rootCAIssuer" . }}
|
||||||
|
dnsNames:
|
||||||
|
- {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
- {{ include "cert-manager-webhook-njalla.fullname" . }}.{{ .Release.Namespace }}
|
||||||
|
- {{ include "cert-manager-webhook-njalla.fullname" . }}.{{ .Release.Namespace }}.svc
|
129
charts/cert-manager-webhook-njalla/templates/rbac.yaml
Normal file
129
charts/cert-manager-webhook-njalla/templates/rbac.yaml
Normal file
@ -0,0 +1,129 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
---
|
||||||
|
# Grant the webhook permission to read the ConfigMap containing the Kubernetes
|
||||||
|
# apiserver's requestheader-ca-certificate.
|
||||||
|
# This ConfigMap is automatically created by the Kubernetes apiserver.
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:webhook-authentication-reader
|
||||||
|
namespace: kube-system
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: extension-apiserver-authentication-reader
|
||||||
|
subjects:
|
||||||
|
- apiGroup: ""
|
||||||
|
kind: ServiceAccount
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
# apiserver gets the auth-delegator role to delegate auth decisions to
|
||||||
|
# the core apiserver
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:auth-delegator
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: system:auth-delegator
|
||||||
|
subjects:
|
||||||
|
- apiGroup: ""
|
||||||
|
kind: ServiceAccount
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
---
|
||||||
|
# Grant cert-manager permission to validate using our apiserver
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:domain-solver
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- {{ .Values.groupName }}
|
||||||
|
resources:
|
||||||
|
- '*'
|
||||||
|
verbs:
|
||||||
|
- 'create'
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:domain-solver
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:domain-solver
|
||||||
|
subjects:
|
||||||
|
- apiGroup: ""
|
||||||
|
kind: ServiceAccount
|
||||||
|
name: {{ .Values.certManager.serviceAccountName }}
|
||||||
|
namespace: {{ .Values.certManager.namespace }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:flowcontrol-solver
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- "flowcontrol.apiserver.k8s.io"
|
||||||
|
resources:
|
||||||
|
- 'prioritylevelconfigurations'
|
||||||
|
- 'flowschemas'
|
||||||
|
verbs:
|
||||||
|
- 'list'
|
||||||
|
- 'watch'
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:flowcontrol-solver
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}:flowcontrol-solver
|
||||||
|
subjects:
|
||||||
|
- apiGroup: ""
|
||||||
|
kind: ServiceAccount
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace | quote }}
|
||||||
|
---
|
19
charts/cert-manager-webhook-njalla/templates/service.yaml
Normal file
19
charts/cert-manager-webhook-njalla/templates/service.yaml
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "cert-manager-webhook-njalla.fullname" . }}
|
||||||
|
labels:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
chart: {{ include "cert-manager-webhook-njalla.chart" . }}
|
||||||
|
release: {{ .Release.Name }}
|
||||||
|
heritage: {{ .Release.Service }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: https
|
||||||
|
protocol: TCP
|
||||||
|
name: https
|
||||||
|
selector:
|
||||||
|
app: {{ include "cert-manager-webhook-njalla.name" . }}
|
||||||
|
release: {{ .Release.Name }}
|
43
charts/cert-manager-webhook-njalla/values.yaml
Normal file
43
charts/cert-manager-webhook-njalla/values.yaml
Normal file
@ -0,0 +1,43 @@
|
|||||||
|
# The GroupName here is used to identify your company or business unit that
|
||||||
|
# created this webhook.
|
||||||
|
# For example, this may be "acme.mycompany.com".
|
||||||
|
# This name will need to be referenced in each Issuer's `webhook` stanza to
|
||||||
|
# inform cert-manager of where to send ChallengePayload resources in order to
|
||||||
|
# solve the DNS01 challenge.
|
||||||
|
# This group name should be **unique**, hence using your own company's domain
|
||||||
|
# here is recommended.
|
||||||
|
groupName: oecis.io
|
||||||
|
|
||||||
|
certManager:
|
||||||
|
namespace: cert-manager
|
||||||
|
serviceAccountName: cert-manager
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: jrester/cert-manager-webhook-njalla
|
||||||
|
tag: latest
|
||||||
|
pullPolicy: Always
|
||||||
|
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 443
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
# requests:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
23
charts/ladder/.helmignore
Normal file
23
charts/ladder/.helmignore
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
24
charts/ladder/Chart.yaml
Normal file
24
charts/ladder/Chart.yaml
Normal file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: ladder
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
43
charts/ladder/README.md
Normal file
43
charts/ladder/README.md
Normal file
@ -0,0 +1,43 @@
|
|||||||
|
# ladder
|
||||||
|
|
||||||
|
![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square)
|
||||||
|
|
||||||
|
A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| autoscaling.enabled | bool | `false` | |
|
||||||
|
| autoscaling.maxReplicas | int | `100` | |
|
||||||
|
| autoscaling.minReplicas | int | `1` | |
|
||||||
|
| autoscaling.targetCPUUtilizationPercentage | int | `80` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| image.repository | string | `"registry.oecis.io/oecis/ladder"` | |
|
||||||
|
| image.tag | string | `"v0.0.1"` | |
|
||||||
|
| imagePullSecrets | list | `[]` | |
|
||||||
|
| ingress.annotations | object | `{}` | |
|
||||||
|
| ingress.className | string | `""` | |
|
||||||
|
| ingress.enabled | bool | `false` | |
|
||||||
|
| ingress.hosts[0].host | string | `"chart-example.local"` | |
|
||||||
|
| ingress.hosts[0].paths[0].path | string | `"/"` | |
|
||||||
|
| ingress.hosts[0].paths[0].pathType | string | `"ImplementationSpecific"` | |
|
||||||
|
| ingress.tls | list | `[]` | |
|
||||||
|
| nameOverride | string | `""` | |
|
||||||
|
| nodeSelector | object | `{}` | |
|
||||||
|
| podAnnotations | object | `{}` | |
|
||||||
|
| podSecurityContext | object | `{}` | |
|
||||||
|
| replicaCount | int | `1` | |
|
||||||
|
| resources | object | `{}` | |
|
||||||
|
| securityContext | object | `{}` | |
|
||||||
|
| service.port | int | `8000` | |
|
||||||
|
| service.type | string | `"ClusterIP"` | |
|
||||||
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
|
| serviceAccount.create | bool | `true` | |
|
||||||
|
| serviceAccount.name | string | `""` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
|
||||||
|
----------------------------------------------
|
||||||
|
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
22
charts/ladder/templates/NOTES.txt
Normal file
22
charts/ladder/templates/NOTES.txt
Normal file
@ -0,0 +1,22 @@
|
|||||||
|
1. Get the application URL by running these commands:
|
||||||
|
{{- if .Values.ingress.enabled }}
|
||||||
|
{{- range $host := .Values.ingress.hosts }}
|
||||||
|
{{- range .paths }}
|
||||||
|
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else if contains "NodePort" .Values.service.type }}
|
||||||
|
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "ladder.fullname" . }})
|
||||||
|
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||||
|
echo http://$NODE_IP:$NODE_PORT
|
||||||
|
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||||
|
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||||
|
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "ladder.fullname" . }}'
|
||||||
|
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "ladder.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
||||||
|
echo http://$SERVICE_IP:{{ .Values.service.port }}
|
||||||
|
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||||
|
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "ladder.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
||||||
|
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
||||||
|
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||||
|
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
||||||
|
{{- end }}
|
62
charts/ladder/templates/_helpers.tpl
Normal file
62
charts/ladder/templates/_helpers.tpl
Normal file
@ -0,0 +1,62 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "ladder.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "ladder.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "ladder.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "ladder.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "ladder.chart" . }}
|
||||||
|
{{ include "ladder.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "ladder.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "ladder.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "ladder.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "ladder.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
61
charts/ladder/templates/deployment.yaml
Normal file
61
charts/ladder/templates/deployment.yaml
Normal file
@ -0,0 +1,61 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "ladder.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "ladder.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "ladder.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
28
charts/ladder/templates/hpa.yaml
Normal file
28
charts/ladder/templates/hpa.yaml
Normal file
@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.autoscaling.enabled }}
|
||||||
|
apiVersion: autoscaling/v2beta1
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: {{ include "ladder.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
scaleTargetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: {{ include "ladder.fullname" . }}
|
||||||
|
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||||
|
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||||
|
metrics:
|
||||||
|
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: memory
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
61
charts/ladder/templates/ingress.yaml
Normal file
61
charts/ladder/templates/ingress.yaml
Normal file
@ -0,0 +1,61 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{- $fullName := include "ladder.fullname" . -}}
|
||||||
|
{{- $svcPort := .Values.service.port -}}
|
||||||
|
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
|
||||||
|
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
|
||||||
|
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1beta1
|
||||||
|
{{- else -}}
|
||||||
|
apiVersion: extensions/v1beta1
|
||||||
|
{{- end }}
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
{{- range .paths }}
|
||||||
|
- path: {{ .path }}
|
||||||
|
{{- if and .pathType (semverCompare ">=1.18-0" $.Capabilities.KubeVersion.GitVersion) }}
|
||||||
|
pathType: {{ .pathType }}
|
||||||
|
{{- end }}
|
||||||
|
backend:
|
||||||
|
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.GitVersion }}
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
port:
|
||||||
|
number: {{ $svcPort }}
|
||||||
|
{{- else }}
|
||||||
|
serviceName: {{ $fullName }}
|
||||||
|
servicePort: {{ $svcPort }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
15
charts/ladder/templates/service.yaml
Normal file
15
charts/ladder/templates/service.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "ladder.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "ladder.selectorLabels" . | nindent 4 }}
|
12
charts/ladder/templates/serviceaccount.yaml
Normal file
12
charts/ladder/templates/serviceaccount.yaml
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "ladder.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
15
charts/ladder/templates/tests/test-connection.yaml
Normal file
15
charts/ladder/templates/tests/test-connection.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "ladder.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "ladder.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "ladder.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
82
charts/ladder/values.yaml
Normal file
82
charts/ladder/values.yaml
Normal file
@ -0,0 +1,82 @@
|
|||||||
|
# Default values for ladder.
|
||||||
|
# This is a YAML-formatted file.
|
||||||
|
# Declare variables to be passed into your templates.
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.oecis.io/oecis/ladder
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: "v0.0.1"
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
# Specifies whether a service account should be created
|
||||||
|
create: true
|
||||||
|
# Annotations to add to the service account
|
||||||
|
annotations: {}
|
||||||
|
# The name of the service account to use.
|
||||||
|
# If not set and create is true, a name is generated using the fullname template
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 8000
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
annotations: {}
|
||||||
|
# kubernetes.io/ingress.class: nginx
|
||||||
|
# kubernetes.io/tls-acme: "true"
|
||||||
|
hosts:
|
||||||
|
- host: chart-example.local
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: ImplementationSpecific
|
||||||
|
tls: []
|
||||||
|
# - secretName: chart-example-tls
|
||||||
|
# hosts:
|
||||||
|
# - chart-example.local
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
# requests:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 100
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
# targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
23
charts/mirage/.helmignore
Normal file
23
charts/mirage/.helmignore
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
6
charts/mirage/Chart.lock
Normal file
6
charts/mirage/Chart.lock
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
dependencies:
|
||||||
|
- name: postgresql
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 12.1.15
|
||||||
|
digest: sha256:0686bdb95219bbd8806328e63f8547c12c8da36e70776407cde1ac324221d631
|
||||||
|
generated: "2023-08-27T13:55:27.416126986+02:00"
|
30
charts/mirage/Chart.yaml
Normal file
30
charts/mirage/Chart.yaml
Normal file
@ -0,0 +1,30 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: mirage
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
||||||
|
|
||||||
|
dependencies:
|
||||||
|
- condition: global.postgresqlEnabled
|
||||||
|
name: postgresql
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 12.1.x
|
66
charts/mirage/README.md
Normal file
66
charts/mirage/README.md
Normal file
@ -0,0 +1,66 @@
|
|||||||
|
# mirage
|
||||||
|
|
||||||
|
![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square)
|
||||||
|
|
||||||
|
A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
| Repository | Name | Version |
|
||||||
|
|------------|------|---------|
|
||||||
|
| https://charts.bitnami.com/bitnami | postgresql | 12.1.x |
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| autoscaling.enabled | bool | `false` | |
|
||||||
|
| autoscaling.maxReplicas | int | `100` | |
|
||||||
|
| autoscaling.minReplicas | int | `1` | |
|
||||||
|
| autoscaling.targetCPUUtilizationPercentage | int | `80` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| global.postgresqlEnabled | bool | `true` | |
|
||||||
|
| image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| image.repository | string | `"registry.oecis.io/oecis/mirage"` | |
|
||||||
|
| image.tag | string | `"latest"` | |
|
||||||
|
| imagePullSecrets | list | `[]` | |
|
||||||
|
| ingress.annotations | object | `{}` | |
|
||||||
|
| ingress.className | string | `""` | |
|
||||||
|
| ingress.enabled | bool | `false` | |
|
||||||
|
| ingress.hosts[0].host | string | `"chart-example.local"` | |
|
||||||
|
| ingress.hosts[0].paths[0].path | string | `"/"` | |
|
||||||
|
| ingress.hosts[0].paths[0].pathType | string | `"ImplementationSpecific"` | |
|
||||||
|
| ingress.tls | list | `[]` | |
|
||||||
|
| mirage.autoMigration | bool | `true` | |
|
||||||
|
| mirage.canary | string | `"1"` | |
|
||||||
|
| mirage.db.database | string | `""` | |
|
||||||
|
| mirage.db.existingSecret | string | `""` | |
|
||||||
|
| mirage.db.host | string | `""` | |
|
||||||
|
| mirage.db.password | string | `""` | |
|
||||||
|
| mirage.db.port | int | `5432` | |
|
||||||
|
| mirage.db.secretKeys.dbPasswordKey | string | `"user-password"` | |
|
||||||
|
| mirage.db.user | string | `""` | |
|
||||||
|
| mirage.hostBaseUrl | string | `"http://localhost/"` | |
|
||||||
|
| mirage.hydra.internal | string | `"http://hydra"` | |
|
||||||
|
| mirage.keto.internal | string | `"http://keto"` | |
|
||||||
|
| mirage.kratos.external | string | `"http://kratos"` | |
|
||||||
|
| mirage.kratos.internal | string | `"http://kratos"` | |
|
||||||
|
| mirage.secretName | string | `nil` | |
|
||||||
|
| nameOverride | string | `""` | |
|
||||||
|
| nodeSelector | object | `{}` | |
|
||||||
|
| podAnnotations | object | `{}` | |
|
||||||
|
| podSecurityContext | object | `{}` | |
|
||||||
|
| postgres | object | `{}` | |
|
||||||
|
| replicaCount | int | `1` | |
|
||||||
|
| resources | object | `{}` | |
|
||||||
|
| securityContext | object | `{}` | |
|
||||||
|
| service.port | int | `4000` | |
|
||||||
|
| service.type | string | `"ClusterIP"` | |
|
||||||
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
|
| serviceAccount.create | bool | `true` | |
|
||||||
|
| serviceAccount.name | string | `""` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
|
||||||
|
----------------------------------------------
|
||||||
|
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
22
charts/mirage/templates/NOTES.txt
Normal file
22
charts/mirage/templates/NOTES.txt
Normal file
@ -0,0 +1,22 @@
|
|||||||
|
1. Get the application URL by running these commands:
|
||||||
|
{{- if .Values.ingress.enabled }}
|
||||||
|
{{- range $host := .Values.ingress.hosts }}
|
||||||
|
{{- range .paths }}
|
||||||
|
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else if contains "NodePort" .Values.service.type }}
|
||||||
|
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "mirage.fullname" . }})
|
||||||
|
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||||
|
echo http://$NODE_IP:$NODE_PORT
|
||||||
|
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||||
|
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||||
|
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "mirage.fullname" . }}'
|
||||||
|
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "mirage.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
||||||
|
echo http://$SERVICE_IP:{{ .Values.service.port }}
|
||||||
|
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||||
|
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "mirage.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
||||||
|
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
||||||
|
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||||
|
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
||||||
|
{{- end }}
|
62
charts/mirage/templates/_helpers.tpl
Normal file
62
charts/mirage/templates/_helpers.tpl
Normal file
@ -0,0 +1,62 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "mirage.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "mirage.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "mirage.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "mirage.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "mirage.chart" . }}
|
||||||
|
{{ include "mirage.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "mirage.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "mirage.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "mirage.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "mirage.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
142
charts/mirage/templates/deployment.yaml
Normal file
142
charts/mirage/templates/deployment.yaml
Normal file
@ -0,0 +1,142 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "mirage.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "mirage.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "mirage.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
{{- if .Values.mirage.autoMigration }}
|
||||||
|
initContainers:
|
||||||
|
- name: {{ .Chart.Name }}-init
|
||||||
|
command: ["/app/bin/migrate"]
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: OE_CANARY
|
||||||
|
value: {{ .Values.mirage.canary }}
|
||||||
|
- name: MIRAGE_SECRET_KEY_BASE
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.mirage.secretName }}
|
||||||
|
key: secretKeyBase
|
||||||
|
- name: MIRAGE_HOST_BASE_URL
|
||||||
|
value: {{ .Values.mirage.hostBaseUrl }}
|
||||||
|
- name: MIRAGE_EXTERNAL_KRATOS_BASE_URL
|
||||||
|
value: {{ .Values.mirage.kratos.external }}
|
||||||
|
- name: MIRAGE_INTERNAL_KRATOS_BASE_URL
|
||||||
|
value: {{ .Values.mirage.kratos.internal }}
|
||||||
|
- name: MIRAGE_INTERNAL_HYDRA_BASE_URL
|
||||||
|
value: {{ .Values.mirage.hydra.internal }}
|
||||||
|
- name: MIRAGE_INTERNAL_KETO_BASE_URL
|
||||||
|
value: {{ .Values.mirage.keto.internal }}
|
||||||
|
- name: MIRAGE_DB_USER
|
||||||
|
value: {{ .Values.mirage.db.user }}
|
||||||
|
- name: MIRAGE_DB_PASSWORD
|
||||||
|
{{- if .Values.mirage.db.existingSecret }}
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.mirage.db.existingSecret }}
|
||||||
|
key: {{ .Values.mirage.db.secretKeys.dbPasswordKey }}
|
||||||
|
{{- else }}
|
||||||
|
value: {{ .Values.config.db.password }}
|
||||||
|
{{- end }}
|
||||||
|
- name: MIRAGE_DB_HOST
|
||||||
|
value: {{ .Values.mirage.db.host }}
|
||||||
|
- name: MIRAGE_DB_PORT
|
||||||
|
value: {{ .Values.mirage.db.port | quote }}
|
||||||
|
- name: MIRAGE_DB_NAME
|
||||||
|
value: {{ .Values.mirage.db.database | quote }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
env:
|
||||||
|
- name: MIRAGE_CANARY
|
||||||
|
value: {{ .Values.mirage.canary }}
|
||||||
|
- name: MIRAGE_SECRET_KEY_BASE
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.mirage.secretName }}
|
||||||
|
key: secretKeyBase
|
||||||
|
- name: MIRAGE_HOST_BASE_URL
|
||||||
|
value: {{ .Values.mirage.hostBaseUrl }}
|
||||||
|
- name: MIRAGE_EXTERNAL_KRATOS_BASE_URL
|
||||||
|
value: {{ .Values.mirage.kratos.external }}
|
||||||
|
- name: MIRAGE_INTERNAL_KRATOS_BASE_URL
|
||||||
|
value: {{ .Values.mirage.kratos.internal }}
|
||||||
|
- name: MIRAGE_INTERNAL_HYDRA_BASE_URL
|
||||||
|
value: {{ .Values.mirage.hydra.internal }}
|
||||||
|
- name: MIRAGE_INTERNAL_KETO_BASE_URL
|
||||||
|
value: {{ .Values.mirage.keto.internal }}
|
||||||
|
- name: MIRAGE_DB_USER
|
||||||
|
value: {{ .Values.mirage.db.user }}
|
||||||
|
- name: MIRAGE_DB_PASSWORD
|
||||||
|
{{- if .Values.mirage.db.existingSecret }}
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.mirage.db.existingSecret }}
|
||||||
|
key: {{ .Values.mirage.db.secretKeys.dbPasswordKey }}
|
||||||
|
{{- else }}
|
||||||
|
value: {{ .Values.config.db.password }}
|
||||||
|
{{- end }}
|
||||||
|
- name: MIRAGE_DB_HOST
|
||||||
|
value: {{ .Values.mirage.db.host }}
|
||||||
|
- name: MIRAGE_DB_PORT
|
||||||
|
value: {{ .Values.mirage.db.port | quote }}
|
||||||
|
- name: MIRAGE_DB_NAME
|
||||||
|
value: {{ .Values.mirage.db.database | quote }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
28
charts/mirage/templates/hpa.yaml
Normal file
28
charts/mirage/templates/hpa.yaml
Normal file
@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.autoscaling.enabled }}
|
||||||
|
apiVersion: autoscaling/v2beta1
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: {{ include "mirage.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
scaleTargetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: {{ include "mirage.fullname" . }}
|
||||||
|
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||||
|
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||||
|
metrics:
|
||||||
|
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: memory
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
61
charts/mirage/templates/ingress.yaml
Normal file
61
charts/mirage/templates/ingress.yaml
Normal file
@ -0,0 +1,61 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{- $fullName := include "mirage.fullname" . -}}
|
||||||
|
{{- $svcPort := .Values.service.port -}}
|
||||||
|
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
|
||||||
|
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
|
||||||
|
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1beta1
|
||||||
|
{{- else -}}
|
||||||
|
apiVersion: extensions/v1beta1
|
||||||
|
{{- end }}
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
{{- range .paths }}
|
||||||
|
- path: {{ .path }}
|
||||||
|
{{- if and .pathType (semverCompare ">=1.18-0" $.Capabilities.KubeVersion.GitVersion) }}
|
||||||
|
pathType: {{ .pathType }}
|
||||||
|
{{- end }}
|
||||||
|
backend:
|
||||||
|
{{- if semverCompare ">=1.19-0" $.Capabilities.KubeVersion.GitVersion }}
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
port:
|
||||||
|
number: {{ $svcPort }}
|
||||||
|
{{- else }}
|
||||||
|
serviceName: {{ $fullName }}
|
||||||
|
servicePort: {{ $svcPort }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
15
charts/mirage/templates/service.yaml
Normal file
15
charts/mirage/templates/service.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "mirage.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "mirage.selectorLabels" . | nindent 4 }}
|
12
charts/mirage/templates/serviceaccount.yaml
Normal file
12
charts/mirage/templates/serviceaccount.yaml
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "mirage.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
15
charts/mirage/templates/tests/test-connection.yaml
Normal file
15
charts/mirage/templates/tests/test-connection.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "mirage.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "mirage.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "mirage.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
110
charts/mirage/values.yaml
Normal file
110
charts/mirage/values.yaml
Normal file
@ -0,0 +1,110 @@
|
|||||||
|
# Default values for frontend.
|
||||||
|
# This is a YAML-formatted file.
|
||||||
|
# Declare variables to be passed into your templates.
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: registry.oecis.io/oecis/mirage
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: "latest"
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
# Specifies whether a service account should be created
|
||||||
|
create: true
|
||||||
|
# Annotations to add to the service account
|
||||||
|
annotations: {}
|
||||||
|
# The name of the service account to use.
|
||||||
|
# If not set and create is true, a name is generated using the fullname template
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 4000
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
annotations: {}
|
||||||
|
# kubernetes.io/ingress.class: nginx
|
||||||
|
# kubernetes.io/tls-acme: "true"
|
||||||
|
hosts:
|
||||||
|
- host: chart-example.local
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: ImplementationSpecific
|
||||||
|
tls: []
|
||||||
|
# - secretName: chart-example-tls
|
||||||
|
# hosts:
|
||||||
|
# - chart-example.local
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
# requests:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 100
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
# targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
|
||||||
|
global:
|
||||||
|
postgresqlEnabled: true
|
||||||
|
|
||||||
|
postgres: {}
|
||||||
|
|
||||||
|
mirage:
|
||||||
|
secretName: null
|
||||||
|
hostBaseUrl: http://localhost/
|
||||||
|
canary: "1"
|
||||||
|
autoMigration: true
|
||||||
|
db:
|
||||||
|
host: ""
|
||||||
|
port: 5432
|
||||||
|
user: ""
|
||||||
|
password: ""
|
||||||
|
database: ""
|
||||||
|
existingSecret: ""
|
||||||
|
secretKeys:
|
||||||
|
dbPasswordKey: user-password
|
||||||
|
kratos:
|
||||||
|
external: http://kratos
|
||||||
|
internal: http://kratos
|
||||||
|
hydra:
|
||||||
|
internal: http://hydra
|
||||||
|
keto:
|
||||||
|
internal: http://keto
|
23
charts/tandoor/.helmignore
Normal file
23
charts/tandoor/.helmignore
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
24
charts/tandoor/Chart.yaml
Normal file
24
charts/tandoor/Chart.yaml
Normal file
@ -0,0 +1,24 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: tandoor
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.0
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "1.16.0"
|
70
charts/tandoor/README.md
Normal file
70
charts/tandoor/README.md
Normal file
@ -0,0 +1,70 @@
|
|||||||
|
# tandoor
|
||||||
|
|
||||||
|
![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square)
|
||||||
|
|
||||||
|
A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| autoscaling.enabled | bool | `false` | |
|
||||||
|
| autoscaling.maxReplicas | int | `100` | |
|
||||||
|
| autoscaling.minReplicas | int | `1` | |
|
||||||
|
| autoscaling.targetCPUUtilizationPercentage | int | `80` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| imagePullSecrets | list | `[]` | |
|
||||||
|
| ingress.annotations | object | `{}` | |
|
||||||
|
| ingress.className | string | `""` | |
|
||||||
|
| ingress.enabled | bool | `false` | |
|
||||||
|
| ingress.hosts[0].host | string | `"tandoor.local"` | |
|
||||||
|
| ingress.tls | list | `[]` | |
|
||||||
|
| nameOverride | string | `""` | |
|
||||||
|
| nginx.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| nginx.image.repository | string | `"nginx"` | |
|
||||||
|
| nginx.image.tag | string | `"mainline-alpine"` | |
|
||||||
|
| nginx.resources | object | `{}` | |
|
||||||
|
| nodeSelector | object | `{}` | |
|
||||||
|
| oauth2InitContainer.config | object | `{}` | |
|
||||||
|
| oauth2InitContainer.enabled | bool | `false` | |
|
||||||
|
| oauth2InitContainer.env | list | `[]` | |
|
||||||
|
| persistence.mediafiles.accessMode | string | `"ReadWriteOnce"` | |
|
||||||
|
| persistence.mediafiles.annotations | object | `{}` | |
|
||||||
|
| persistence.mediafiles.name | string | `"tandoor-mediafiles"` | |
|
||||||
|
| persistence.mediafiles.size | string | `"1Gi"` | |
|
||||||
|
| persistence.staticfiles.accessMode | string | `"ReadWriteOnce"` | |
|
||||||
|
| persistence.staticfiles.annotations | object | `{}` | |
|
||||||
|
| persistence.staticfiles.name | string | `"tandoor-staticfiles"` | |
|
||||||
|
| persistence.staticfiles.size | string | `"1Gi"` | |
|
||||||
|
| podAnnotations | object | `{}` | |
|
||||||
|
| podSecurityContext | object | `{}` | |
|
||||||
|
| replicaCount | int | `1` | |
|
||||||
|
| securityContext | object | `{}` | |
|
||||||
|
| service.gunicorn.name | string | `"gunicorn"` | |
|
||||||
|
| service.gunicorn.port | int | `80` | |
|
||||||
|
| service.gunicorn.type | string | `"ClusterIP"` | |
|
||||||
|
| service.nginx.name | string | `"nginx"` | |
|
||||||
|
| service.nginx.port | int | `80` | |
|
||||||
|
| service.nginx.type | string | `"ClusterIP"` | |
|
||||||
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
|
| serviceAccount.create | bool | `true` | |
|
||||||
|
| serviceAccount.name | string | `""` | |
|
||||||
|
| tandoor.config.encryptionSecret | string | `""` | |
|
||||||
|
| tandoor.config.existingSecret | string | `""` | |
|
||||||
|
| tandoor.config.postgres.db | string | `"tandoor"` | |
|
||||||
|
| tandoor.config.postgres.host | string | `""` | |
|
||||||
|
| tandoor.config.postgres.password | string | `""` | |
|
||||||
|
| tandoor.config.postgres.port | int | `5432` | |
|
||||||
|
| tandoor.config.postgres.user | string | `"tandoor"` | |
|
||||||
|
| tandoor.config.secretKeys.encryptionSecretKey | string | `"encryption-key"` | |
|
||||||
|
| tandoor.config.secretKeys.postgresUserPasswordKey | string | `"postgres-user-password"` | |
|
||||||
|
| tandoor.extraEnv | list | `[]` | |
|
||||||
|
| tandoor.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| tandoor.image.repository | string | `"vabene1111/recipes"` | |
|
||||||
|
| tandoor.image.tag | string | `"latest"` | |
|
||||||
|
| tandoor.resources | object | `{}` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
|
||||||
|
----------------------------------------------
|
||||||
|
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
75
charts/tandoor/templates/_helpers.tpl
Normal file
75
charts/tandoor/templates/_helpers.tpl
Normal file
@ -0,0 +1,75 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "tandoor.chart" . }}
|
||||||
|
{{ include "tandoor.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "tandoor.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "tandoor.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Construct the namespace for all namespaced resources
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
Preserve the default behavior of the Release namespace if no override is provided
|
||||||
|
*/}}
|
||||||
|
{{- define "tandoor.namespace" -}}
|
||||||
|
{{- if .Values.namespaceOverride -}}
|
||||||
|
{{- .Values.namespaceOverride | trunc 63 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- .Release.Namespace -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
27
charts/tandoor/templates/configmap.yaml
Normal file
27
charts/tandoor/templates/configmap.yaml
Normal file
@ -0,0 +1,27 @@
|
|||||||
|
kind: ConfigMap
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
name: tandoor-nginx-config
|
||||||
|
data:
|
||||||
|
nginx-config: |-
|
||||||
|
events {
|
||||||
|
worker_connections 1024;
|
||||||
|
}
|
||||||
|
http {
|
||||||
|
include mime.types;
|
||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
server_name _;
|
||||||
|
client_max_body_size 16M;
|
||||||
|
# serve static files
|
||||||
|
location /static/ {
|
||||||
|
alias /static/;
|
||||||
|
}
|
||||||
|
# serve media files
|
||||||
|
location /media/ {
|
||||||
|
alias /media/;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
177
charts/tandoor/templates/deployment.yaml
Normal file
177
charts/tandoor/templates/deployment.yaml
Normal file
@ -0,0 +1,177 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tandoor.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "tandoor.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "tandoor.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
volumes:
|
||||||
|
- name: mediafiles
|
||||||
|
persistentVolumeClaim:
|
||||||
|
{{- if not .Values.persistence.mediafiles.existingClaim }}
|
||||||
|
claimName: {{ .Values.persistence.mediafiles.name }}
|
||||||
|
{{- else }}
|
||||||
|
claimName: {{ .Values.persistence.mediafiles.existingClaim }}
|
||||||
|
{{- end }}
|
||||||
|
- name: staticfiles
|
||||||
|
persistentVolumeClaim:
|
||||||
|
{{- if not .Values.persistence.staticfiles.existingClaim }}
|
||||||
|
claimName: {{ .Values.persistence.staticfiles.name }}
|
||||||
|
{{- else }}
|
||||||
|
claimName: {{ .Values.persistence.staticfiles.existingClaim }}
|
||||||
|
{{- end }}
|
||||||
|
- name: nginx-config
|
||||||
|
configMap:
|
||||||
|
name: tandoor-nginx-config
|
||||||
|
{{- if .Values.oauth2InitContainer.enabled }}
|
||||||
|
- name: env
|
||||||
|
emptyDir:
|
||||||
|
medium: Memory
|
||||||
|
initContainers:
|
||||||
|
- name: {{ include "tandoor.fullname" . }}-oidc-env-populator
|
||||||
|
image: busybox
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /env
|
||||||
|
name: env
|
||||||
|
command: ["/bin/sh"]
|
||||||
|
args: ["-c", {{ quote (printf "echo 'export SOCIALACCOUNT_PROVIDERS=%q' > /env/oauth2_config" ( .Values.oauth2InitContainer.config | toJson )) }}]
|
||||||
|
{{- if not (empty .Values.oauth2InitContainer.env) }}
|
||||||
|
env:
|
||||||
|
{{- toYaml .Values.oauth2InitContainer.env | nindent 12 }}
|
||||||
|
{{- end}}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- name: {{ include "tandoor.fullname" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.tandoor.image.repository }}:{{ .Values.tandoor.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.tandoor.image.pullPolicy }}
|
||||||
|
{{- if .Values.oauth2InitContainer.enabled }}
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
echo "Loading oauth2 config from /env/oauth2_config"
|
||||||
|
source /env/oauth2_config
|
||||||
|
echo "Starting 'recipes'"
|
||||||
|
/opt/recipes/boot.sh
|
||||||
|
{{- end }}
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
scheme: HTTP
|
||||||
|
port: 8080
|
||||||
|
periodSeconds: 15
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
scheme: HTTP
|
||||||
|
port: 8080
|
||||||
|
periodSeconds: 15
|
||||||
|
env:
|
||||||
|
- name: DB_ENGINE
|
||||||
|
value: django.db.backends.postgresql_psycopg2
|
||||||
|
- name: POSTGRES_HOST
|
||||||
|
value: {{ .Values.tandoor.config.postgres.host | quote }}
|
||||||
|
- name: POSTGRES_PORT
|
||||||
|
value: {{ .Values.tandoor.config.postgres.port | quote }}
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
value: {{ .Values.tandoor.config.postgres.user | quote }}
|
||||||
|
- name: TANDOOR_PORT
|
||||||
|
value: "8080"
|
||||||
|
- name: GUNICORN_WORKERS
|
||||||
|
value: "2"
|
||||||
|
- name: GUNICORN_THREADS
|
||||||
|
value: "2"
|
||||||
|
- name: POSTGRES_PASSWORD
|
||||||
|
{{- if not .Values.tandoor.config.secretKeys.postgresUserPasswordKey }}
|
||||||
|
value: {{ .Values.tandoor.config.postgres.password | quote }}
|
||||||
|
{{- else }}
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.tandoor.config.existingSecret }}
|
||||||
|
key: {{ .Values.tandoor.config.secretKeys.postgresUserPasswordKey }}
|
||||||
|
{{- end }}
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value: {{ .Values.tandoor.config.postgres.db }}
|
||||||
|
- name: SECRET_KEY
|
||||||
|
{{- if not .Values.tandoor.config.secretKeys.encryptionSecretKey }}
|
||||||
|
value: {{ .Values.tandoor.config.encryptionSecret }}
|
||||||
|
{{- else }}
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.tandoor.config.existingSecret }}
|
||||||
|
key: {{ .Values.tandoor.config.secretKeys.encryptionSecretKey }}
|
||||||
|
{{- end}}
|
||||||
|
{{- if not (empty .Values.tandoor.extraEnv) }}
|
||||||
|
{{- toYaml .Values.tandoor.extraEnv | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.tandoor.resources | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /opt/recipes/mediafiles
|
||||||
|
name: mediafiles
|
||||||
|
- mountPath: /opt/recipes/staticfiles
|
||||||
|
name: staticfiles
|
||||||
|
{{- if .Values.oauth2InitContainer.enabled }}
|
||||||
|
- mountPath: /env
|
||||||
|
name: env
|
||||||
|
{{- end}}
|
||||||
|
- name: {{ include "tandoor.fullname" . }}-nginx
|
||||||
|
image: {{ .Values.nginx.image.repository }}:{{ .Values.nginx.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.nginx.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- containerPort: {{ .Values.service.nginx.port }}
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
- containerPort: {{ .Values.service.gunicorn.port }}
|
||||||
|
protocol: TCP
|
||||||
|
name: gunicorn
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.nginx.resources | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /media
|
||||||
|
name: mediafiles
|
||||||
|
readOnly: true
|
||||||
|
- mountPath: /static
|
||||||
|
name: staticfiles
|
||||||
|
readOnly: true
|
||||||
|
- mountPath: /etc/nginx/nginx.conf
|
||||||
|
name: nginx-config
|
||||||
|
readOnly: true
|
||||||
|
subPath: nginx-config
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
28
charts/tandoor/templates/hpa.yaml
Normal file
28
charts/tandoor/templates/hpa.yaml
Normal file
@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.autoscaling.enabled }}
|
||||||
|
apiVersion: autoscaling/v2beta1
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tandoor.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
scaleTargetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: {{ include "tandoor.fullname" . }}
|
||||||
|
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||||
|
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||||
|
metrics:
|
||||||
|
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: memory
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
60
charts/tandoor/templates/ingress.yaml
Normal file
60
charts/tandoor/templates/ingress.yaml
Normal file
@ -0,0 +1,60 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{- $fullName := include "tandoor.fullname" . -}}
|
||||||
|
{{- $gunicornPort := .Values.service.gunicorn.port }}
|
||||||
|
{{- $nginxPort := .Values.service.nginx.port }}
|
||||||
|
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1beta1
|
||||||
|
{{- else -}}
|
||||||
|
apiVersion: extensions/v1beta1
|
||||||
|
{{- end }}
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}-gunicorn
|
||||||
|
port:
|
||||||
|
number: {{ $gunicornPort }}
|
||||||
|
- path: /media
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{$fullName}}-nginx
|
||||||
|
port:
|
||||||
|
number: {{ $nginxPort }}
|
||||||
|
- path: /static
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{$fullName}}-nginx
|
||||||
|
port:
|
||||||
|
number: {{ $nginxPort }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
47
charts/tandoor/templates/pvc.yaml
Normal file
47
charts/tandoor/templates/pvc.yaml
Normal file
@ -0,0 +1,47 @@
|
|||||||
|
{{- if not .Values.persistence.staticfiles.existingClaim }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: {{ .Values.persistence.staticfiles.name }}
|
||||||
|
namespace: {{ include "tandoor.namespace" . }}
|
||||||
|
annotations:
|
||||||
|
{{- with .Values.persistence.staticfiles.annotations }}
|
||||||
|
{{ toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
helm.sh/resource-policy: keep
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.persistence.staticfiles.storageClass }}
|
||||||
|
storageClassName: {{ .Values.persistence.staticfiles.storageClass | quote }}
|
||||||
|
{{- end }}
|
||||||
|
accessModes:
|
||||||
|
- {{ .Values.persistence.staticfiles.accessMode }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.persistence.staticfiles.size | quote }}
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if not .Values.persistence.mediafiles.existingClaim }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: {{ .Values.persistence.mediafiles.name }}
|
||||||
|
namespace: {{ include "tandoor.namespace" . }}
|
||||||
|
annotations:
|
||||||
|
{{- with .Values.persistence.mediafiles.annotations }}
|
||||||
|
{{ toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
helm.sh/resource-policy: keep
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.persistence.mediafiles.storageClass }}
|
||||||
|
storageClassName: {{ .Values.persistence.mediafiles.storageClass | quote }}
|
||||||
|
{{- end }}
|
||||||
|
accessModes:
|
||||||
|
- {{ .Values.persistence.mediafiles.accessMode }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.persistence.mediafiles.size | quote }}
|
||||||
|
{{- end }}
|
33
charts/tandoor/templates/service.yaml
Normal file
33
charts/tandoor/templates/service.yaml
Normal file
@ -0,0 +1,33 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tandoor.fullname" . }}-gunicorn
|
||||||
|
namespace: {{ include "tandoor.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.gunicorn.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.gunicorn.port }}
|
||||||
|
targetPort: gunicorn
|
||||||
|
protocol: TCP
|
||||||
|
name: {{ .Values.service.gunicorn.name }}
|
||||||
|
selector:
|
||||||
|
{{- include "tandoor.selectorLabels" . | nindent 4 }}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tandoor.fullname" . }}-nginx
|
||||||
|
namespace: {{ include "tandoor.namespace" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.nginx.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.nginx.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: {{ .Values.service.nginx.name }}
|
||||||
|
selector:
|
||||||
|
{{- include "tandoor.selectorLabels" . | nindent 4 }}
|
12
charts/tandoor/templates/serviceaccount.yaml
Normal file
12
charts/tandoor/templates/serviceaccount.yaml
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "tandoor.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
15
charts/tandoor/templates/tests/test-connection.yaml
Normal file
15
charts/tandoor/templates/tests/test-connection.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "tandoor.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "tandoor.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "tandoor.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
134
charts/tandoor/values.yaml
Normal file
134
charts/tandoor/values.yaml
Normal file
@ -0,0 +1,134 @@
|
|||||||
|
# Default values for tandoor.
|
||||||
|
# This is a YAML-formatted file.
|
||||||
|
# Declare variables to be passed into your templates.
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
# namespaceOverride: "custom-namespace"
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
# Specifies whether a service account should be created
|
||||||
|
create: true
|
||||||
|
# Annotations to add to the service account
|
||||||
|
annotations: {}
|
||||||
|
# The name of the service account to use.
|
||||||
|
# If not set and create is true, a name is generated using the fullname template
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
persistence:
|
||||||
|
staticfiles:
|
||||||
|
name: tandoor-staticfiles
|
||||||
|
# existingClaim: ""
|
||||||
|
size: 1Gi
|
||||||
|
accessMode: ReadWriteOnce
|
||||||
|
# storageClass: ""
|
||||||
|
annotations: {}
|
||||||
|
mediafiles:
|
||||||
|
name: tandoor-mediafiles
|
||||||
|
# existingClaim: ""
|
||||||
|
size: 1Gi
|
||||||
|
accessMode: ReadWriteOnce
|
||||||
|
# storageClass: ""
|
||||||
|
annotations: {}
|
||||||
|
|
||||||
|
service:
|
||||||
|
gunicorn:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 80
|
||||||
|
name: gunicorn
|
||||||
|
nginx:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 80
|
||||||
|
name: nginx
|
||||||
|
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
annotations: {}
|
||||||
|
# kubernetes.io/ingress.class: nginx
|
||||||
|
# kubernetes.io/tls-acme: "true"
|
||||||
|
hosts:
|
||||||
|
- host: tandoor.local
|
||||||
|
|
||||||
|
tls: []
|
||||||
|
# - secretName: chart-example-tls
|
||||||
|
# hosts:
|
||||||
|
# - chart-example.local
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 100
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
# targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
# oauth2InitContainer is used to inject the oauth2 provider configuration
|
||||||
|
oauth2InitContainer:
|
||||||
|
enabled: false
|
||||||
|
config: {}
|
||||||
|
# openid_connect:
|
||||||
|
# SERVERS:
|
||||||
|
# - id: oecis
|
||||||
|
# name: Oecis
|
||||||
|
# server_url: https://hydra.oecis.io
|
||||||
|
# token_auth_method: client_secret_post
|
||||||
|
# APP:
|
||||||
|
# client_id: "$(OIDC_CLIENT_ID)"
|
||||||
|
# client_secret: "$(OIDC_CLIENT_SECRET)"
|
||||||
|
# you can use env to add secrets like OIDC_CLIENT_SECRET
|
||||||
|
env: []
|
||||||
|
nginx:
|
||||||
|
image:
|
||||||
|
repository: nginx
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: "mainline-alpine"
|
||||||
|
resources: {}
|
||||||
|
tandoor:
|
||||||
|
# extraEnv can be used to select an oauth2 provider:
|
||||||
|
# extraEnv:
|
||||||
|
# - name: SOCIAL_PROVIDERS
|
||||||
|
# value: allauth.socialaccount.providers.openid_connect
|
||||||
|
extraEnv: []
|
||||||
|
image:
|
||||||
|
repository: vabene1111/recipes
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: "latest"
|
||||||
|
resources: {}
|
||||||
|
config:
|
||||||
|
encryptionSecret: ""
|
||||||
|
postgres:
|
||||||
|
host: ""
|
||||||
|
port: 5432
|
||||||
|
user: tandoor
|
||||||
|
password: ""
|
||||||
|
db: tandoor
|
||||||
|
existingSecret: ""
|
||||||
|
secretKeys:
|
||||||
|
postgresUserPasswordKey: "postgres-user-password"
|
||||||
|
encryptionSecretKey: "encryption-key"
|
1
charts/vaultwarden/.github/FUNDING.yml
vendored
Normal file
1
charts/vaultwarden/.github/FUNDING.yml
vendored
Normal file
@ -0,0 +1 @@
|
|||||||
|
github: [guerzon]
|
5
charts/vaultwarden/.gitignore
vendored
Normal file
5
charts/vaultwarden/.gitignore
vendored
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
*.tgz
|
||||||
|
/.idea/*
|
||||||
|
.vscode
|
||||||
|
.DS_Store
|
||||||
|
testing-values.yaml
|
21
charts/vaultwarden/.helmignore
Normal file
21
charts/vaultwarden/.helmignore
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
33
charts/vaultwarden/CONTRIBUTING.md
Normal file
33
charts/vaultwarden/CONTRIBUTING.md
Normal file
@ -0,0 +1,33 @@
|
|||||||
|
|
||||||
|
# Contributing Guide
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
1. Fork this repository, develop, and test your changes.
|
||||||
|
2. Submit a pull request.
|
||||||
|
|
||||||
|
### Technical Requirements
|
||||||
|
|
||||||
|
When submitting a pull request, please ensure that:
|
||||||
|
|
||||||
|
- The PR follow [Helm best practices](https://helm.sh/docs/chart_best_practices/).
|
||||||
|
- Any change to a chart requires a version bump following [semver](https://semver.org/) principles.
|
||||||
|
- The tables of parameters are generated based on the metadata information from the `values.yaml` file, by using [this tool](https://github.com/bitnami-labs/readme-generator-for-helm).
|
||||||
|
|
||||||
|
A quick way to do this is to run the tool via Docker:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Clone and build:
|
||||||
|
git clone https://github.com/bitnami-labs/readme-generator-for-helm
|
||||||
|
cd readme-generator-for-helm/
|
||||||
|
docker build -t readme-gen .
|
||||||
|
|
||||||
|
# Run the tool and mount the current project directory.
|
||||||
|
cd <this-project-dir>
|
||||||
|
docker run --rm -d -it --name readmegen -v $(pwd):/mnt readme-gen bash
|
||||||
|
docker exec -it readmegen bash
|
||||||
|
|
||||||
|
# Update the values documentation
|
||||||
|
cd /mnt
|
||||||
|
readme-generator -v values.yaml -r README.md
|
||||||
|
```
|
15
charts/vaultwarden/Chart.yaml
Normal file
15
charts/vaultwarden/Chart.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: vaultwarden
|
||||||
|
description: vaultwarden is an unofficial Bitwarden-compatible server written in Rust
|
||||||
|
keywords:
|
||||||
|
- Rust
|
||||||
|
- vaultwarden
|
||||||
|
sources:
|
||||||
|
- https://github.com/guerzon/vaultwarden
|
||||||
|
- https://github.com/dani-garcia/vaultwarden
|
||||||
|
appVersion: 1.24.0
|
||||||
|
maintainers:
|
||||||
|
- name: Lester Guerzon
|
||||||
|
email: lester.guerzon@gmail.com
|
||||||
|
url: https://github.com/guerzon
|
||||||
|
version: 0.8.0
|
21
charts/vaultwarden/LICENSE
Normal file
21
charts/vaultwarden/LICENSE
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
MIT License
|
||||||
|
|
||||||
|
Copyright (c) 2022 Lester Guerzon
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||||
|
of this software and associated documentation files (the "Software"), to deal
|
||||||
|
in the Software without restriction, including without limitation the rights
|
||||||
|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||||
|
copies of the Software, and to permit persons to whom the Software is
|
||||||
|
furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all
|
||||||
|
copies or substantial portions of the Software.
|
||||||
|
|
||||||
|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||||
|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||||
|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||||
|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||||
|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||||
|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||||
|
SOFTWARE.
|
92
charts/vaultwarden/README.md
Normal file
92
charts/vaultwarden/README.md
Normal file
@ -0,0 +1,92 @@
|
|||||||
|
# vaultwarden
|
||||||
|
|
||||||
|
![Version: 0.8.0](https://img.shields.io/badge/Version-0.8.0-informational?style=flat-square) ![AppVersion: 1.24.0](https://img.shields.io/badge/AppVersion-1.24.0-informational?style=flat-square)
|
||||||
|
|
||||||
|
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
|
||||||
|
|
||||||
|
## Maintainers
|
||||||
|
|
||||||
|
| Name | Email | Url |
|
||||||
|
| ---- | ------ | --- |
|
||||||
|
| Lester Guerzon | <lester.guerzon@gmail.com> | <https://github.com/guerzon> |
|
||||||
|
|
||||||
|
## Source Code
|
||||||
|
|
||||||
|
* <https://github.com/guerzon/vaultwarden>
|
||||||
|
* <https://github.com/dani-garcia/vaultwarden>
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| adminToken.existingSecretKey | string | `"ADMIN_TOKEN"` | |
|
||||||
|
| adminToken.value | string | `"R@ndomToken$tring"` | |
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| database.dbName | string | `""` | |
|
||||||
|
| database.host | string | `""` | |
|
||||||
|
| database.password | string | `""` | |
|
||||||
|
| database.port | string | `""` | |
|
||||||
|
| database.type | string | `"default"` | |
|
||||||
|
| database.uriOverride | string | `""` | |
|
||||||
|
| database.username | string | `""` | |
|
||||||
|
| domain | string | `""` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| image.pullSecrets | list | `[]` | |
|
||||||
|
| image.registry | string | `"docker.io"` | |
|
||||||
|
| image.repository | string | `"vaultwarden/server"` | |
|
||||||
|
| image.tag | string | `"1.24.0"` | |
|
||||||
|
| ingress.additionalAnnotations | object | `{}` | |
|
||||||
|
| ingress.class | string | `"nginx"` | |
|
||||||
|
| ingress.enabled | bool | `false` | |
|
||||||
|
| ingress.hostname | string | `"warden.contoso.com"` | |
|
||||||
|
| ingress.nginxAllowList | string | `""` | |
|
||||||
|
| ingress.nginxIngressAnnotations | bool | `true` | |
|
||||||
|
| ingress.path | string | `"/"` | |
|
||||||
|
| ingress.pathType | string | `"ImplementationSpecific"` | |
|
||||||
|
| ingress.pathTypeWs | string | `"ImplementationSpecific"` | |
|
||||||
|
| ingress.pathWs | string | `"/notifications/hub"` | |
|
||||||
|
| ingress.tls | bool | `true` | |
|
||||||
|
| ingress.tlsSecret | string | `""` | |
|
||||||
|
| initContainers | list | `[]` | |
|
||||||
|
| invitationsAllowed | bool | `true` | |
|
||||||
|
| logging.enabled | bool | `false` | |
|
||||||
|
| logging.logfile | string | `"/data/vaultwarden.log"` | |
|
||||||
|
| logging.loglevel | string | `"warn"` | |
|
||||||
|
| nodeSelector | object | `{}` | |
|
||||||
|
| rocket.port | string | `"8080"` | |
|
||||||
|
| rocket.workers | string | `"10"` | |
|
||||||
|
| service.annotations | object | `{}` | |
|
||||||
|
| service.type | string | `"ClusterIP"` | |
|
||||||
|
| serviceAccount.create | bool | `true` | |
|
||||||
|
| serviceAccount.name | string | `"vaultwarden-svc"` | |
|
||||||
|
| showPassHint | string | `"false"` | |
|
||||||
|
| sidecars | list | `[]` | |
|
||||||
|
| signupDomains | string | `"contoso.com"` | |
|
||||||
|
| signupsAllowed | bool | `true` | |
|
||||||
|
| signupsVerify | string | `"true"` | |
|
||||||
|
| smtp.acceptInvalidCerts | string | `"false"` | |
|
||||||
|
| smtp.acceptInvalidHostnames | string | `"false"` | |
|
||||||
|
| smtp.authMechanism | string | `"Plain"` | |
|
||||||
|
| smtp.debug | bool | `false` | |
|
||||||
|
| smtp.from | string | `""` | |
|
||||||
|
| smtp.fromName | string | `""` | |
|
||||||
|
| smtp.host | string | `""` | |
|
||||||
|
| smtp.password.existingSecretKey | string | `"SMTP_PASSWORD"` | |
|
||||||
|
| smtp.password.value | string | `""` | |
|
||||||
|
| smtp.port | int | `25` | |
|
||||||
|
| smtp.security | string | `"starttls"` | |
|
||||||
|
| smtp.username.existingSecretKey | string | `"SMTP_USERNAME"` | |
|
||||||
|
| smtp.username.value | string | `""` | |
|
||||||
|
| storage.class | string | `"default"` | |
|
||||||
|
| storage.dataDir | string | `"/data"` | |
|
||||||
|
| storage.enabled | bool | `false` | |
|
||||||
|
| storage.size | string | `"15Gi"` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
| webVaultEnabled | string | `"true"` | |
|
||||||
|
| websocket.address | string | `"0.0.0.0"` | |
|
||||||
|
| websocket.enabled | bool | `true` | |
|
||||||
|
| websocket.port | int | `3012` | |
|
||||||
|
|
||||||
|
----------------------------------------------
|
||||||
|
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
17
charts/vaultwarden/demo.yaml
Normal file
17
charts/vaultwarden/demo.yaml
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
|
||||||
|
domain: "https://vaultwarden.contoso.com"
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
hostname: vaultwarden.contoso.com
|
||||||
|
class: "alb"
|
||||||
|
additionalAnnotations:
|
||||||
|
alb.ingress.kubernetes.io/scheme: internet-facing
|
||||||
|
alb.ingress.kubernetes.io/tags: Environment=dev,Team=test
|
||||||
|
alb.ingress.kubernetes.io/certificate-arn: "arn:aws:acm:eu-central-1:ACCOUNT:certificate/LONGID"
|
||||||
|
|
||||||
|
adminToken: "khit9gYQV6ax9LKTTm+s6QbZi5oiuR+3s1PEn9q3IRmCl9IQn7LmBpmFCOYTb7Mr"
|
||||||
|
|
||||||
|
image:
|
||||||
|
pullSecrets:
|
||||||
|
- myRegKey
|
7
charts/vaultwarden/templates/NOTES.txt
Normal file
7
charts/vaultwarden/templates/NOTES.txt
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
** Please be patient while the chart is being deployed **
|
||||||
|
|
||||||
|
Thanks for installing {{ .Chart.Name }}.
|
||||||
|
|
||||||
|
You have named your release: {{ .Release.Name }}.
|
||||||
|
|
||||||
|
Vaultwarden is accessible here: {{ .Values.ingress.hostname }}
|
31
charts/vaultwarden/templates/_helpers.tpl
Normal file
31
charts/vaultwarden/templates/_helpers.tpl
Normal file
@ -0,0 +1,31 @@
|
|||||||
|
{{/*
|
||||||
|
Return a default application name.
|
||||||
|
*/}}
|
||||||
|
{{- define "vaultwarden.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride -}}
|
||||||
|
{{- .Values.fullnameOverride | trunc 20 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
||||||
|
{{- if contains $name .Release.Name -}}
|
||||||
|
{{- .Release.Name | trunc 20 | trimSuffix "-" -}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 20 | trimSuffix "-" -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "dbPort" -}}
|
||||||
|
{{- if .Values.database.port }}
|
||||||
|
{{- printf "%s%s" ":" .Values.database.port }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s" "" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Return the database string
|
||||||
|
*/}}
|
||||||
|
{{ define "dbString" }}
|
||||||
|
{{- $var := print .Values.database.type "://" .Values.database.username ":" .Values.database.password "@" .Values.database.host (include "dbPort" . ) "/" .Values.database.dbName }}
|
||||||
|
{{- printf "%s" $var }}
|
||||||
|
{{- end -}}
|
45
charts/vaultwarden/templates/configmap.yaml
Normal file
45
charts/vaultwarden/templates/configmap.yaml
Normal file
@ -0,0 +1,45 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
data:
|
||||||
|
DOMAIN: {{ .Values.domain | quote }}
|
||||||
|
{{- if ne "default" .Values.database.type }}
|
||||||
|
{{- if .Values.database.uriOverride }}
|
||||||
|
DATABASE_URL: {{ .Values.database.uriOverride }}
|
||||||
|
{{- else }}
|
||||||
|
DATABASE_URL: {{ include "dbString" . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if and .Values.smtp.host .Values.smtp.from | quote }}
|
||||||
|
SMTP_HOST: {{ .Values.smtp.host | quote }}
|
||||||
|
SMTP_SECURITY: {{ .Values.smtp.security | quote }}
|
||||||
|
SMTP_PORT: {{ .Values.smtp.port | quote }}
|
||||||
|
SMTP_AUTH_MECHANISM: {{ .Values.smtp.authMechanism | quote }}
|
||||||
|
SMTP_FROM: {{ .Values.smtp.from | quote }}
|
||||||
|
SMTP_FROM_NAME: {{ default "Vaultwarden" .Values.smtp.fromName | quote }}
|
||||||
|
SMTP_DEBUG: {{ .Values.smtp.debug | quote }}
|
||||||
|
SMTP_ACCEPT_INVALID_HOSTNAMES: {{ .Values.smtp.acceptInvalidHostnames | quote }}
|
||||||
|
SMTP_ACCEPT_INVALID_CERTS: {{ .Values.smtp.acceptInvalidCerts | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.websocket.enabled }}
|
||||||
|
WEBSOCKET_ENABLED: "true"
|
||||||
|
WEBSOCKET_ADDRESS: {{ .Values.websocket.address | quote }}
|
||||||
|
WEBSOCKET_PORT: {{ .Values.websocket.port | quote }}
|
||||||
|
{{- end }}
|
||||||
|
DATA_FOLDER: {{ .Values.storage.dataDir | quote }}
|
||||||
|
ROCKET_PORT: {{ .Values.rocket.port | quote }}
|
||||||
|
ROCKET_WORKERS: {{ .Values.rocket.workers | quote }}
|
||||||
|
SHOW_PASSWORD_HINT: {{ .Values.showPassHint | quote }}
|
||||||
|
SIGNUPS_ALLOWED: {{ .Values.signupsAllowed | quote }}
|
||||||
|
INVITATIONS_ALLOWED: {{ .Values.invitationsAllowed | quote }}
|
||||||
|
SIGNUPS_DOMAINS_WHITELIST: {{ .Values.signupDomains | quote }}
|
||||||
|
SIGNUPS_VERIFY: {{ .Values.signupsVerify | quote }}
|
||||||
|
WEB_VAULT_ENABLED: {{ .Values.webVaultEnabled | quote }}
|
||||||
|
{{- if .Values.logging.enabled }}
|
||||||
|
LOG_FILE: {{ .Values.logging.logfile | quote }}
|
||||||
|
LOG_LEVEL: {{ .Values.logging.loglevel | quote }}
|
||||||
|
{{- end }}
|
71
charts/vaultwarden/templates/ingress.yaml
Normal file
71
charts/vaultwarden/templates/ingress.yaml
Normal file
@ -0,0 +1,71 @@
|
|||||||
|
{{- if .Values.ingress.enabled }}
|
||||||
|
{{- $newAPIversion := .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
|
||||||
|
{{- if $newAPIversion }}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
{{- else }}
|
||||||
|
apiVersion: extensions/v1beta1
|
||||||
|
{{- end }}
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
annotations:
|
||||||
|
ingress.kubernetes.io/rewrite-target: /
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.additionalAnnotations }}
|
||||||
|
{{- toYaml .Values.ingress.additionalAnnotations | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.nginxIngressAnnotations }}
|
||||||
|
nginx.ingress.kubernetes.io/configuration-snippet: |
|
||||||
|
more_set_headers "Request-Id: $req_id";
|
||||||
|
nginx.ingress.kubernetes.io/connection-proxy-header: "keep-alive"
|
||||||
|
nginx.ingress.kubernetes.io/enable-cors: "true"
|
||||||
|
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
||||||
|
nginx.ingress.kubernetes.io/limit-connections: "25"
|
||||||
|
nginx.ingress.kubernetes.io/limit-rps: "15"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-body-size: 1024m
|
||||||
|
nginx.ingress.kubernetes.io/proxy-connect-timeout: "10"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-send-timeout: "1800"
|
||||||
|
nginx.ingress.kubernetes.io/proxy-read-timeout: "1800"
|
||||||
|
{{- if .Values.ingress.nginxAllowList }}
|
||||||
|
nginx.ingress.kubernetes.io/whitelist-source-range: {{ .Values.ingress.nginxAllowList }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.ingress.class }}
|
||||||
|
ingressClassName: {{ .Values.ingress.class | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
- hosts:
|
||||||
|
- {{ .Values.ingress.hostname | quote }}
|
||||||
|
{{- if eq "nginx" .Values.ingress.class }}
|
||||||
|
secretName: {{ .Values.ingress.tlsSecret }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
- host: {{ .Values.ingress.hostname | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: {{ .Values.ingress.path }}
|
||||||
|
pathType: {{ .Values.ingress.pathType }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
port:
|
||||||
|
name: "http"
|
||||||
|
{{- if .Values.websocket.enabled }}
|
||||||
|
- path: {{ .Values.ingress.pathWs }}
|
||||||
|
pathType: {{ .Values.ingress.pathTypeWs }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
port:
|
||||||
|
name: "websocket"
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
48
charts/vaultwarden/templates/rbac.yaml
Normal file
48
charts/vaultwarden/templates/rbac.yaml
Normal file
@ -0,0 +1,48 @@
|
|||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ .Values.serviceAccount.name }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
rules:
|
||||||
|
- apiGroups: ["extensions", "apps"]
|
||||||
|
resources: ["deployments"]
|
||||||
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["pods"]
|
||||||
|
verbs: ["create","delete","get","list","patch","update","watch"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["pods/exec"]
|
||||||
|
verbs: ["create","delete","get","list","patch","update","watch"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["pods/log"]
|
||||||
|
verbs: ["get","list","watch"]
|
||||||
|
- apiGroups: [""]
|
||||||
|
resources: ["secrets"]
|
||||||
|
verbs: ["get"]
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
18
charts/vaultwarden/templates/secrets.yaml
Normal file
18
charts/vaultwarden/templates/secrets.yaml
Normal file
@ -0,0 +1,18 @@
|
|||||||
|
{{ if not (and (hasKey .Values.smtp "existingSecret") (hasKey .Values.adminToken "existingSecret")) }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
{{- if not (hasKey .Values.smtp "existingSecret") }}
|
||||||
|
SMTP_PASSWORD: {{ .Values.smtp.password.value | b64enc | quote }}
|
||||||
|
SMTP_USERNAME: {{ .Values.smtp.username.value | b64enc | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if not (hasKey .Values.adminToken "existingSecret") }}
|
||||||
|
ADMIN_TOKEN: {{ .Values.adminToken.value | b64enc | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{ end }}
|
26
charts/vaultwarden/templates/service.yaml
Normal file
26
charts/vaultwarden/templates/service.yaml
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
{{- if .Values.service.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.service.annotations | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type | quote }}
|
||||||
|
selector:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
ports:
|
||||||
|
- name: "http"
|
||||||
|
port: 80
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 8080
|
||||||
|
{{- if .Values.websocket.enabled }}
|
||||||
|
- name: "websocket"
|
||||||
|
port: 3012
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: {{ .Values.websocket.port }}
|
||||||
|
{{- end }}
|
102
charts/vaultwarden/templates/statefulset.yaml
Normal file
102
charts/vaultwarden/templates/statefulset.yaml
Normal file
@ -0,0 +1,102 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
spec:
|
||||||
|
serviceName: vaultwarden
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: vaultwarden
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: vaultwarden
|
||||||
|
app.kubernetes.io/component: vaultwarden
|
||||||
|
annotations:
|
||||||
|
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha1sum }}
|
||||||
|
checksum/secret: {{ include (print $.Template.BasePath "/secrets.yaml") . | sha1sum }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml .Values.nodeSelector | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml .Values.affinity | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml .Values.tolerations | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
initContainers:
|
||||||
|
{{- if .Values.initContainers }}
|
||||||
|
{{- toYaml .Values.initContainers | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- image: {{ .Values.image.registry }}/{{ .Values.image.repository }}:{{ .Values.image.tag }}
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
name: vaultwarden
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: {{ include "vaultwarden.fullname" . }}
|
||||||
|
env:
|
||||||
|
- name: SMTP_USERNAME
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ default (include "vaultwarden.fullname" .) .Values.smtp.existingSecret }}
|
||||||
|
key: {{ default "SMTP_USERNAME" .Values.smtp.username.existingSecretKey }}
|
||||||
|
- name: SMTP_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ default (include "vaultwarden.fullname" .) .Values.smtp.existingSecret }}
|
||||||
|
key: {{ default "SMTP_PASSWORD" .Values.smtp.password.existingSecretKey }}
|
||||||
|
- name: ADMIN_TOKEN
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ default (include "vaultwarden.fullname" .) .Values.adminToken.existingSecret }}
|
||||||
|
key: {{ default "ADMIN_TOKEN" .Values.adminToken.existingSecretKey }}
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
name: http
|
||||||
|
protocol: TCP
|
||||||
|
- containerPort: {{ .Values.websocket.port }}
|
||||||
|
name: websocket
|
||||||
|
protocol: TCP
|
||||||
|
{{- if .Values.storage.enabled }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: vaultwarden-data
|
||||||
|
mountPath: {{ .Values.storage.dataDir }}
|
||||||
|
{{- end }}
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 300m
|
||||||
|
memory: 1Gi
|
||||||
|
requests:
|
||||||
|
cpu: 50m
|
||||||
|
memory: 256Mi
|
||||||
|
{{- if .Values.sidecars }}
|
||||||
|
{{- toYaml .Values.sidecars | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
serviceAccountName: {{ .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.storage.enabled }}
|
||||||
|
persistentVolumeClaimRetentionPolicy:
|
||||||
|
whenDeleted: Retain
|
||||||
|
whenScaled: Retain
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: vaultwarden-data
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- "ReadWriteOnce"
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.storage.size }}
|
||||||
|
storageClassName: {{ default "default" .Values.storage.class }}
|
||||||
|
{{- end }}
|
282
charts/vaultwarden/values.yaml
Normal file
282
charts/vaultwarden/values.yaml
Normal file
@ -0,0 +1,282 @@
|
|||||||
|
|
||||||
|
## @section Vaultwarden settings
|
||||||
|
##
|
||||||
|
image:
|
||||||
|
## @param image.registry Vaultwarden image registry
|
||||||
|
##
|
||||||
|
registry: docker.io
|
||||||
|
## @param image.repository Vaultwarden image repository
|
||||||
|
##
|
||||||
|
repository: vaultwarden/server
|
||||||
|
##
|
||||||
|
## @param image.tag Vaultwarden image tag
|
||||||
|
## Ref: https://hub.docker.com/r/vaultwarden/server/tags
|
||||||
|
##
|
||||||
|
tag: "1.24.0"
|
||||||
|
## @param image.pullPolicy Vaultwarden image pull policy
|
||||||
|
## ref: https://kubernetes.io/docs/user-guide/images/#pre-pulling-images
|
||||||
|
##
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
## @param image.pullSecrets Specify docker-registry secret names
|
||||||
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
||||||
|
## Example:
|
||||||
|
## pullSecrets:
|
||||||
|
## - myRegistryKeySecretName
|
||||||
|
##
|
||||||
|
pullSecrets: []
|
||||||
|
## @param domain Domain name where the application is accessed
|
||||||
|
## Example: https://warden.contoso.com:8443
|
||||||
|
##
|
||||||
|
domain: ""
|
||||||
|
## @param websocket.enabled Enable websocket notifications
|
||||||
|
## @param websocket.address Websocket listen address
|
||||||
|
## @param websocket.port Websocket listen port
|
||||||
|
##
|
||||||
|
websocket:
|
||||||
|
enabled: true
|
||||||
|
address: "0.0.0.0"
|
||||||
|
port: 3012
|
||||||
|
## @param rocket.port Rocket port
|
||||||
|
## @param rocket.workers Rocket number of workers
|
||||||
|
##
|
||||||
|
rocket:
|
||||||
|
port: "8080"
|
||||||
|
workers: "10"
|
||||||
|
## @param webVaultEnabled Enable Web Vault
|
||||||
|
##
|
||||||
|
webVaultEnabled: "true"
|
||||||
|
|
||||||
|
## @section Security settings
|
||||||
|
##
|
||||||
|
## @param adminToken The admin token used for /admin
|
||||||
|
##
|
||||||
|
adminToken:
|
||||||
|
#existingSecret: vaultwarden
|
||||||
|
existingSecretKey: ADMIN_TOKEN
|
||||||
|
value: "R@ndomToken$tring"
|
||||||
|
## @param signupsAllowed By default, anyone who can access your instance can register for a new account.
|
||||||
|
## To disable this, set this parameter to false. Even when signupsAllowed=false, an existing user who is
|
||||||
|
## an organization owner or admin can still invite new users. If you want to disable this as well, set
|
||||||
|
## invitationsAllowed to false. The vaultwarden admin can invite anyone via the admin page, regardless
|
||||||
|
## of any of the restrictions above
|
||||||
|
##
|
||||||
|
## If signupDomains is set, then the value of signupsAllowed is ignored
|
||||||
|
signupsAllowed: true
|
||||||
|
## @param invitationsAllowed Even when registration is disabled, organization administrators or owners can
|
||||||
|
## invite users to join organization. After they are invited, they can register with the invited email even
|
||||||
|
## if signupsAllowed is actually set to false. You can disable this functionality completely by setting
|
||||||
|
## invitationsAllowed env variable to false
|
||||||
|
invitationsAllowed: true
|
||||||
|
## @param signupDomains List of domain names for users allowed to register
|
||||||
|
##
|
||||||
|
signupDomains: "contoso.com"
|
||||||
|
## @param signupsVerify Whether to require account verification for newly-registered users.
|
||||||
|
##
|
||||||
|
signupsVerify: "true"
|
||||||
|
## @param showPassHint Whether a password hint should be shown in the page.
|
||||||
|
##
|
||||||
|
showPassHint: "false"
|
||||||
|
## @param fullnameOverride String to override the application name.
|
||||||
|
##
|
||||||
|
fullnameOverride: ""
|
||||||
|
## @param serviceAccount.create Create a service account
|
||||||
|
## @param serviceAccount.name Name of the service account to create
|
||||||
|
##
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
name: "vaultwarden-svc"
|
||||||
|
|
||||||
|
## @section Exposure Parameters
|
||||||
|
##
|
||||||
|
|
||||||
|
## Ingress configuration
|
||||||
|
## Refer to the README for some examples
|
||||||
|
##
|
||||||
|
ingress:
|
||||||
|
## @param ingress.enabled Deploy an ingress resource.
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## @param ingress.class Ingress resource class
|
||||||
|
## The Ingress class to use, e. g. "nginx" for a nginx ingress controller or "alb" for a AWS LB controller.
|
||||||
|
#
|
||||||
|
class: "nginx"
|
||||||
|
## @param ingress.nginxIngressAnnotations Add nginx specific ingress annotations
|
||||||
|
## This annotations are only makes sense for the kubernetes nginx ingress controller (https://kubernetes.github.io/ingress-nginx/)
|
||||||
|
##
|
||||||
|
nginxIngressAnnotations: true
|
||||||
|
## @param ingress.additionalAnnotations Additional annotations for the ingress resource.
|
||||||
|
##
|
||||||
|
additionalAnnotations: {}
|
||||||
|
## @param ingress.tls Enable TLS on the ingress resource.
|
||||||
|
##
|
||||||
|
tls: true
|
||||||
|
## @param ingress.hostname Hostname for the ingress.
|
||||||
|
##
|
||||||
|
hostname: "warden.contoso.com"
|
||||||
|
## @param ingress.path Default application path for the ingress
|
||||||
|
##
|
||||||
|
path: "/"
|
||||||
|
## @param ingress.pathWs Path for the websocket ingress
|
||||||
|
##
|
||||||
|
pathWs: "/notifications/hub"
|
||||||
|
## @param ingress.pathType Path type for the ingress
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/services-networking/ingress/
|
||||||
|
##
|
||||||
|
pathType: "ImplementationSpecific"
|
||||||
|
## @param ingress.pathTypeWs Path type for the ingress
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/services-networking/ingress/
|
||||||
|
##
|
||||||
|
pathTypeWs: "ImplementationSpecific"
|
||||||
|
## @param ingress.tlsSecret Kubernetes secret containing the SSL certificate when using the "nginx" class.
|
||||||
|
##
|
||||||
|
tlsSecret: ""
|
||||||
|
## @param ingress.nginxAllowList Comma-separated list of IP addresses and subnets to allow.
|
||||||
|
##
|
||||||
|
nginxAllowList: ""
|
||||||
|
## TODO:
|
||||||
|
## - Add support for using cert-manager.
|
||||||
|
## - Support for multiple TLS hostnames.
|
||||||
|
##
|
||||||
|
|
||||||
|
## Service configuration
|
||||||
|
service:
|
||||||
|
## @param service.type Service type
|
||||||
|
##
|
||||||
|
type: "ClusterIP"
|
||||||
|
## @param service.annotations Additional annotations for the vaultwarden service
|
||||||
|
##
|
||||||
|
annotations: {}
|
||||||
|
|
||||||
|
## @section Database Configuration
|
||||||
|
##
|
||||||
|
database:
|
||||||
|
## @param database.type Database type, either mysql or postgresql
|
||||||
|
## Default is a sqlite database.
|
||||||
|
##
|
||||||
|
type: "default"
|
||||||
|
## @param database.host Database hostname or IP address
|
||||||
|
##
|
||||||
|
host: ""
|
||||||
|
## @param database.port Database port
|
||||||
|
## Default for MySQL is 3306, default for PostgreSQL is 5432
|
||||||
|
port: ""
|
||||||
|
## @param database.username Database username
|
||||||
|
##
|
||||||
|
username: ""
|
||||||
|
## @param database.password Database password
|
||||||
|
##
|
||||||
|
password: ""
|
||||||
|
## @param database.dbName Database name
|
||||||
|
##
|
||||||
|
dbName: ""
|
||||||
|
## @param database.uriOverride Manually specify the DB connection string
|
||||||
|
##
|
||||||
|
uriOverride: ""
|
||||||
|
|
||||||
|
## @section SMTP Configuration
|
||||||
|
##
|
||||||
|
smtp:
|
||||||
|
#existingSecret: vaultwarden
|
||||||
|
## @param smtp.host SMTP host
|
||||||
|
##
|
||||||
|
host: ""
|
||||||
|
## @param smtp.security SMTP Encryption method
|
||||||
|
## Possible values:
|
||||||
|
## - starttls: explicit TLS using ports 587 or 25
|
||||||
|
## - force_tls: implicit TLS using port 465
|
||||||
|
## - off: no encryption, using port 25, unless using STARTTLS
|
||||||
|
##
|
||||||
|
security: "starttls"
|
||||||
|
## @param smtp.port SMTP port
|
||||||
|
##
|
||||||
|
port: 25
|
||||||
|
## @param smtp.from SMTP sender email address
|
||||||
|
## Example: juan.delacruz@gmail.com
|
||||||
|
##
|
||||||
|
from: ""
|
||||||
|
## @param smtp.fromName SMTP sender FROM
|
||||||
|
##
|
||||||
|
fromName: ""
|
||||||
|
## @param smtp.username Username for the SMTP authentication.
|
||||||
|
## Example: juan
|
||||||
|
##
|
||||||
|
username:
|
||||||
|
existingSecretKey: SMTP_USERNAME
|
||||||
|
value: ""
|
||||||
|
## @param smtp.password Password for the SMTP service.
|
||||||
|
##
|
||||||
|
password:
|
||||||
|
existingSecretKey: SMTP_PASSWORD
|
||||||
|
value: ""
|
||||||
|
## @param smtp.authMechanism SMTP authentication mechanism
|
||||||
|
## Possible values: "Plain", "Login", "Xoauth2"
|
||||||
|
## Multiple options need to be separated by a comma. (not tested)
|
||||||
|
##
|
||||||
|
authMechanism: "Plain"
|
||||||
|
## @param smtp.acceptInvalidHostnames Accept Invalid Hostnames
|
||||||
|
##
|
||||||
|
acceptInvalidHostnames: "false"
|
||||||
|
## @param smtp.acceptInvalidCerts Accept Invalid Certificates
|
||||||
|
##
|
||||||
|
acceptInvalidCerts: "false"
|
||||||
|
## @param smtp.debug SMTP debugging
|
||||||
|
##
|
||||||
|
debug: false
|
||||||
|
|
||||||
|
## @section Storage Configuration
|
||||||
|
##
|
||||||
|
storage:
|
||||||
|
## @param storage.enabled Enable configuration for persistent storage
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## @param storage.size Storage size for /data
|
||||||
|
##
|
||||||
|
size: "15Gi"
|
||||||
|
## @param storage.class Specify the storage class
|
||||||
|
##
|
||||||
|
class: "default"
|
||||||
|
## @param storage.dataDir Specify the data directory
|
||||||
|
##
|
||||||
|
dataDir: "/data"
|
||||||
|
|
||||||
|
## @section Logging Configuration
|
||||||
|
##
|
||||||
|
logging:
|
||||||
|
## @param logging.enabled Enable logging to a file
|
||||||
|
##
|
||||||
|
enabled: false
|
||||||
|
## @param logging.logfile Specify logfile path for output log
|
||||||
|
##
|
||||||
|
logfile: "/data/vaultwarden.log"
|
||||||
|
## @param logging.loglevel Specify the log level
|
||||||
|
##
|
||||||
|
loglevel: "warn"
|
||||||
|
|
||||||
|
## @section Extra containers Configuration
|
||||||
|
##
|
||||||
|
|
||||||
|
## @param initContainers extra init containers for initializing the vaultwarden instance
|
||||||
|
##
|
||||||
|
initContainers: []
|
||||||
|
|
||||||
|
## @param sidecars extra containers running alongside the vaultwarden instance
|
||||||
|
##
|
||||||
|
sidecars: []
|
||||||
|
|
||||||
|
## @section Extra Configuration
|
||||||
|
##
|
||||||
|
|
||||||
|
## @param nodeSelector Node labels for pod assignment
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector
|
||||||
|
##
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
## @param affinity Affinity for pod assignment
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
|
||||||
|
##
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
## @param tolerations Tolerations for pod assignment
|
||||||
|
## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
|
||||||
|
##
|
||||||
|
tolerations: []
|
23
charts/vikunja/.helmignore
Normal file
23
charts/vikunja/.helmignore
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
9
charts/vikunja/Chart.lock
Normal file
9
charts/vikunja/Chart.lock
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
dependencies:
|
||||||
|
- name: postgresql
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 12.10.0
|
||||||
|
- name: redis
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 17.17.1
|
||||||
|
digest: sha256:5c1aa0e6714890ca5f363b5aff284d9367bc9fa8c51685adbe6bc59c1df16bf4
|
||||||
|
generated: "2023-08-27T15:35:50.6261449+02:00"
|
34
charts/vikunja/Chart.yaml
Normal file
34
charts/vikunja/Chart.yaml
Normal file
@ -0,0 +1,34 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: vikunja
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
# A chart can be either an 'application' or a 'library' chart.
|
||||||
|
#
|
||||||
|
# Application charts are a collection of templates that can be packaged into versioned archives
|
||||||
|
# to be deployed.
|
||||||
|
#
|
||||||
|
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
||||||
|
# a dependency of application charts to inject those utilities and functions into the rendering
|
||||||
|
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
||||||
|
type: application
|
||||||
|
|
||||||
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
|
# to the chart and its templates, including the app version.
|
||||||
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
|
version: 0.1.1
|
||||||
|
|
||||||
|
# This is the version number of the application being deployed. This version number should be
|
||||||
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
|
# It is recommended to use it with quotes.
|
||||||
|
appVersion: "0.20.4"
|
||||||
|
|
||||||
|
dependencies:
|
||||||
|
- condition: postgresql.enabled
|
||||||
|
name: postgresql
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 12.x.x
|
||||||
|
- condition: redis.enabled
|
||||||
|
name: redis
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 17.x.x
|
80
charts/vikunja/README.md
Normal file
80
charts/vikunja/README.md
Normal file
@ -0,0 +1,80 @@
|
|||||||
|
# vikunja
|
||||||
|
|
||||||
|
![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.20.4](https://img.shields.io/badge/AppVersion-0.20.4-informational?style=flat-square)
|
||||||
|
|
||||||
|
A Helm chart for Kubernetes
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
| Repository | Name | Version |
|
||||||
|
|------------|------|---------|
|
||||||
|
| https://charts.bitnami.com/bitnami | postgresql | 12.x.x |
|
||||||
|
| https://charts.bitnami.com/bitnami | redis | 17.x.x |
|
||||||
|
|
||||||
|
## Values
|
||||||
|
|
||||||
|
| Key | Type | Default | Description |
|
||||||
|
|-----|------|---------|-------------|
|
||||||
|
| affinity | object | `{}` | |
|
||||||
|
| autoscaling.enabled | bool | `false` | |
|
||||||
|
| autoscaling.maxReplicas | int | `100` | |
|
||||||
|
| autoscaling.minReplicas | int | `1` | |
|
||||||
|
| autoscaling.targetCPUUtilizationPercentage | int | `80` | |
|
||||||
|
| backend.extraEnv | list | `[]` | |
|
||||||
|
| backend.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| backend.image.repository | string | `"vikunja/api"` | |
|
||||||
|
| backend.image.tag | string | `"latest"` | |
|
||||||
|
| backend.service.port | int | `3456` | |
|
||||||
|
| backend.service.type | string | `"ClusterIP"` | |
|
||||||
|
| config.cache.enabled | bool | `false` | |
|
||||||
|
| config.cache.maxElementSize | int | `1000` | |
|
||||||
|
| config.cache.redis.enabled | bool | `false` | |
|
||||||
|
| config.cache.redis.host | string | `""` | |
|
||||||
|
| config.cache.type | string | `"redis"` | |
|
||||||
|
| config.db.database | string | `""` | |
|
||||||
|
| config.db.existingSecret | string | `""` | |
|
||||||
|
| config.db.host | string | `""` | |
|
||||||
|
| config.db.password | string | `""` | |
|
||||||
|
| config.db.secretKeys.dbPasswordKey | string | `"user-password"` | |
|
||||||
|
| config.db.type | string | `"postgres"` | |
|
||||||
|
| config.db.user | string | `""` | |
|
||||||
|
| config.frontendUrl | string | `"https://tasks.local"` | |
|
||||||
|
| config.jwt.existingSecret | string | `""` | |
|
||||||
|
| config.jwt.secretKeys.jwtSecretKey | string | `"jwt-secret"` | |
|
||||||
|
| config.linkSharing | bool | `true` | |
|
||||||
|
| config.log.level | string | `"ERROR"` | |
|
||||||
|
| config.registration | bool | `true` | |
|
||||||
|
| config.taskAttachments | bool | `true` | |
|
||||||
|
| frontend.extraEnv | list | `[]` | |
|
||||||
|
| frontend.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||||
|
| frontend.image.repository | string | `"vikunja/frontend"` | |
|
||||||
|
| frontend.image.tag | string | `"latest"` | |
|
||||||
|
| frontend.service.port | int | `80` | |
|
||||||
|
| frontend.service.type | string | `"ClusterIP"` | |
|
||||||
|
| fullnameOverride | string | `""` | |
|
||||||
|
| imagePullSecrets | list | `[]` | |
|
||||||
|
| ingress.annotations | object | `{}` | |
|
||||||
|
| ingress.className | string | `""` | |
|
||||||
|
| ingress.enabled | bool | `false` | |
|
||||||
|
| ingress.hosts[0].host | string | `"tasks.local"` | |
|
||||||
|
| ingress.tls | list | `[]` | |
|
||||||
|
| nameOverride | string | `""` | |
|
||||||
|
| nodeSelector | object | `{}` | |
|
||||||
|
| openIdInitContainer.config | object | `{}` | |
|
||||||
|
| openIdInitContainer.enabled | bool | `false` | |
|
||||||
|
| openIdInitContainer.env | list | `[]` | |
|
||||||
|
| podAnnotations | object | `{}` | |
|
||||||
|
| podSecurityContext | object | `{}` | |
|
||||||
|
| postgresql.enabled | bool | `true` | |
|
||||||
|
| redis.auth.enabled | bool | `false` | |
|
||||||
|
| redis.enabled | bool | `true` | |
|
||||||
|
| replicaCount | int | `1` | |
|
||||||
|
| resources | object | `{}` | |
|
||||||
|
| securityContext | object | `{}` | |
|
||||||
|
| serviceAccount.annotations | object | `{}` | |
|
||||||
|
| serviceAccount.create | bool | `true` | |
|
||||||
|
| serviceAccount.name | string | `""` | |
|
||||||
|
| tolerations | list | `[]` | |
|
||||||
|
|
||||||
|
----------------------------------------------
|
||||||
|
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
62
charts/vikunja/templates/_helpers.tpl
Normal file
62
charts/vikunja/templates/_helpers.tpl
Normal file
@ -0,0 +1,62 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "vikunja.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "vikunja.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "vikunja.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "vikunja.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "vikunja.chart" . }}
|
||||||
|
{{ include "vikunja.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "vikunja.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "vikunja.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "vikunja.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "vikunja.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
119
charts/vikunja/templates/backend/deployment.yaml
Normal file
119
charts/vikunja/templates/backend/deployment.yaml
Normal file
@ -0,0 +1,119 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vikunja.fullname" . }}-backend
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "vikunja.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "vikunja.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
{{- if .Values.openIdInitContainer.enabled }}
|
||||||
|
volumes:
|
||||||
|
- name: openid-config
|
||||||
|
emptyDir:
|
||||||
|
medium: Memory
|
||||||
|
initContainers:
|
||||||
|
- name: {{ .Chart.Name }}-openid-config-injector
|
||||||
|
image: busybox
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /config
|
||||||
|
name: openid-config
|
||||||
|
command: ["/bin/sh"]
|
||||||
|
args: ["-c", {{ quote (printf "echo -e %q > /config/config.yaml" ( .Values.openIdInitContainer.config | toYaml ))}}]
|
||||||
|
env:
|
||||||
|
{{- toYaml .Values.openIdInitContainer.env | nindent 12}}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}-backend
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.backend.image.repository }}:{{ .Values.backend.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.backend.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: api
|
||||||
|
containerPort: {{ .Values.backend.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /api/v1/info
|
||||||
|
port: api
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /api/v1/info
|
||||||
|
port: api
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
env:
|
||||||
|
- name: VIKUNJA_LOG_LEVEL
|
||||||
|
value: {{ .Values.config.log.level }}
|
||||||
|
{{- if .Values.config.cache.enabled }}
|
||||||
|
- name: VIKUNJA_CACHE_ENABLED
|
||||||
|
value: {{ .Values.config.cache.enabled | quote }}
|
||||||
|
- name: VIKUNJA_CACHE_TYPE
|
||||||
|
value: {{ .Values.config.cache.type }}
|
||||||
|
- name: VIKUNJA_CACHE_MAXELEMENTSIZE
|
||||||
|
value: {{ .Values.config.cache.maxElementSize | quote }}
|
||||||
|
- name: VIKUNJA_REDIS_ENABLED
|
||||||
|
value: {{ .Values.config.cache.redis.enabled | quote }}
|
||||||
|
- name: VIKUNJA_REDIS_HOST
|
||||||
|
value: {{ .Values.config.cache.redis.host }}
|
||||||
|
{{- end }}
|
||||||
|
- name: VIKUNJA_DATABASE_TYPE
|
||||||
|
value: {{ .Values.config.db.type }}
|
||||||
|
- name: VIKUNJA_DATABASE_HOST
|
||||||
|
value: {{ .Values.config.db.host }}
|
||||||
|
- name: VIKUNJA_DATABASE_DATABASE
|
||||||
|
value: {{ .Values.config.db.database }}
|
||||||
|
- name: VIKUNJA_DATABASE_PASSWORD
|
||||||
|
{{- if .Values.config.db.existingSecret }}
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: {{ .Values.config.db.existingSecret }}
|
||||||
|
key: {{ .Values.config.db.secretKeys.dbPasswordKey }}
|
||||||
|
{{- else }}
|
||||||
|
value: {{ .Values.config.db.password }}
|
||||||
|
{{- end }}
|
||||||
|
- name: VIKUNJA_DATABASE_USER
|
||||||
|
value: {{ .Values.config.db.user }}
|
||||||
|
- name: VIKUNJA_SERVICE_FRONTENDURL
|
||||||
|
value: {{ .Values.config.frontendUrl }}
|
||||||
|
{{- if not (empty .Values.backend.extraEnv) }}
|
||||||
|
{{- toYaml .Values.backend.extraEnv | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.openIdInitContainer.enabled }}
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /etc/vikunja
|
||||||
|
name: openid-config
|
||||||
|
{{- end}}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
15
charts/vikunja/templates/backend/service.yaml
Normal file
15
charts/vikunja/templates/backend/service.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vikunja.fullname" . }}-api
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.backend.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.backend.service.port }}
|
||||||
|
targetPort: api
|
||||||
|
protocol: TCP
|
||||||
|
name: api
|
||||||
|
selector:
|
||||||
|
{{- include "vikunja.selectorLabels" . | nindent 4 }}
|
65
charts/vikunja/templates/frontend/deployment.yaml
Normal file
65
charts/vikunja/templates/frontend/deployment.yaml
Normal file
@ -0,0 +1,65 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vikunja.fullname" . }}-frontend
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "vikunja.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "vikunja.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}-frontend
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.frontend.image.repository }}:{{ .Values.frontend.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.frontend.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.frontend.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- if not (empty .Values.backend.extraEnv) }}
|
||||||
|
env:
|
||||||
|
{{- toYaml .Values.backend.extraEnv | nindent 12 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
15
charts/vikunja/templates/frontend/service.yaml
Normal file
15
charts/vikunja/templates/frontend/service.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vikunja.fullname" . }}-frontend
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.frontend.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.frontend.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "vikunja.selectorLabels" . | nindent 4 }}
|
28
charts/vikunja/templates/hpa.yaml
Normal file
28
charts/vikunja/templates/hpa.yaml
Normal file
@ -0,0 +1,28 @@
|
|||||||
|
{{- if .Values.autoscaling.enabled }}
|
||||||
|
apiVersion: autoscaling/v2beta1
|
||||||
|
kind: HorizontalPodAutoscaler
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vikunja.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
scaleTargetRef:
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
name: {{ include "vikunja.fullname" . }}
|
||||||
|
minReplicas: {{ .Values.autoscaling.minReplicas }}
|
||||||
|
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
|
||||||
|
metrics:
|
||||||
|
{{- if .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: cpu
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
- type: Resource
|
||||||
|
resource:
|
||||||
|
name: memory
|
||||||
|
targetAverageUtilization: {{ .Values.autoscaling.targetMemoryUtilizationPercentage }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
72
charts/vikunja/templates/ingress.yaml
Normal file
72
charts/vikunja/templates/ingress.yaml
Normal file
@ -0,0 +1,72 @@
|
|||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{- $fullName := include "vikunja.fullname" . -}}
|
||||||
|
{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }}
|
||||||
|
{{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }}
|
||||||
|
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if semverCompare ">=1.19-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
{{- else if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}}
|
||||||
|
apiVersion: networking.k8s.io/v1beta1
|
||||||
|
{{- else -}}
|
||||||
|
apiVersion: extensions/v1beta1
|
||||||
|
{{- end }}
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if and .Values.ingress.className (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion) }}
|
||||||
|
ingressClassName: {{ .Values.ingress.className }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}-frontend
|
||||||
|
port:
|
||||||
|
name: http
|
||||||
|
- path: /api
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}-api
|
||||||
|
port:
|
||||||
|
name: api
|
||||||
|
- path: /dav
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}-api
|
||||||
|
port:
|
||||||
|
name: api
|
||||||
|
- path: /.well-known
|
||||||
|
pathType: Prefix
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}-api
|
||||||
|
port:
|
||||||
|
name: api
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
12
charts/vikunja/templates/serviceaccount.yaml
Normal file
12
charts/vikunja/templates/serviceaccount.yaml
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "vikunja.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "vikunja.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
131
charts/vikunja/values.yaml
Normal file
131
charts/vikunja/values.yaml
Normal file
@ -0,0 +1,131 @@
|
|||||||
|
# Default values for vikunja.
|
||||||
|
# This is a YAML-formatted file.
|
||||||
|
# Declare variables to be passed into your templates.
|
||||||
|
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
frontend:
|
||||||
|
image:
|
||||||
|
repository: vikunja/frontend
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: latest
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 80
|
||||||
|
extraEnv: []
|
||||||
|
backend:
|
||||||
|
image:
|
||||||
|
repository: vikunja/api
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
# Overrides the image tag whose default is the chart appVersion.
|
||||||
|
tag: latest
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 3456
|
||||||
|
extraEnv: []
|
||||||
|
openIdInitContainer:
|
||||||
|
enabled: false
|
||||||
|
config: {}
|
||||||
|
env: []
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
annotations: {}
|
||||||
|
# kubernetes.io/ingress.class: nginx
|
||||||
|
# kubernetes.io/tls-acme: "true"
|
||||||
|
hosts:
|
||||||
|
- host: tasks.local
|
||||||
|
|
||||||
|
tls: []
|
||||||
|
# - secretName: chart-example-tls
|
||||||
|
# hosts:
|
||||||
|
# - chart-example.local
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
# Specifies whether a service account should be created
|
||||||
|
create: true
|
||||||
|
# Annotations to add to the service account
|
||||||
|
annotations: {}
|
||||||
|
# The name of the service account to use.
|
||||||
|
# If not set and create is true, a name is generated using the fullname template
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
podSecurityContext: {}
|
||||||
|
# fsGroup: 2000
|
||||||
|
|
||||||
|
securityContext: {}
|
||||||
|
# capabilities:
|
||||||
|
# drop:
|
||||||
|
# - ALL
|
||||||
|
# readOnlyRootFilesystem: true
|
||||||
|
# runAsNonRoot: true
|
||||||
|
# runAsUser: 1000
|
||||||
|
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||||
|
# choice for the user. This also increases chances charts run on environments with little
|
||||||
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||||
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||||
|
# limits:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
# requests:
|
||||||
|
# cpu: 100m
|
||||||
|
# memory: 128Mi
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 100
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
# targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
redis:
|
||||||
|
enabled: true
|
||||||
|
auth:
|
||||||
|
enabled: false
|
||||||
|
postgresql:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
config:
|
||||||
|
log:
|
||||||
|
level: ERROR
|
||||||
|
jwt:
|
||||||
|
existingSecret: ""
|
||||||
|
secretKeys:
|
||||||
|
jwtSecretKey: jwt-secret
|
||||||
|
cache:
|
||||||
|
enabled: false
|
||||||
|
type: redis
|
||||||
|
maxElementSize: 1000
|
||||||
|
redis:
|
||||||
|
enabled: false
|
||||||
|
host: ""
|
||||||
|
db:
|
||||||
|
type: postgres
|
||||||
|
host: ""
|
||||||
|
user: ""
|
||||||
|
password: ""
|
||||||
|
database: ""
|
||||||
|
existingSecret: ""
|
||||||
|
secretKeys:
|
||||||
|
dbPasswordKey: user-password
|
||||||
|
frontendUrl: https://tasks.local
|
||||||
|
registration: true
|
||||||
|
linkSharing: true
|
||||||
|
taskAttachments: true
|
Loading…
Reference in New Issue
Block a user