Change chart directory structure

This commit is contained in:
wbsong111
2026-01-19 16:11:44 +09:00
parent 0f2284bf35
commit 0436749932
5948 changed files with 119 additions and 79 deletions
@@ -0,0 +1,63 @@
CHART NAME: {{ .Chart.Name }}
CHART VERSION: {{ .Chart.Version }}
APP VERSION: {{ .Chart.AppVersion }}
Did you know there are enterprise versions of the Bitnami catalog? For enhanced secure software supply chain features, unlimited pulls from Docker, LTS support, or application customization, see Bitnami Premium or Tanzu Application Catalog. See https://www.arrow.com/globalecs/na/vendors/bitnami for more information.
** Please be patient while the chart is being deployed **
{{- if .Values.diagnosticMode.enabled }}
The chart has been deployed in diagnostic mode. All probes have been disabled and the command has been overwritten with:
command: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.command "context" $) | nindent 4 }}
args: {{- include "common.tplvalues.render" (dict "value" .Values.diagnosticMode.args "context" $) | nindent 4 }}
Get the list of pods by executing:
kubectl get pods --namespace {{ include "common.names.namespace" . | quote }} -l app.kubernetes.io/instance={{ .Release.Name }}
Access the pod you want to debug by executing
kubectl exec --namespace {{ include "common.names.namespace" . | quote }} -ti <NAME OF THE POD> -- bash
In order to replicate the container startup scripts execute this command:
/opt/bitnami/scripts/clickhouse/entrypoint.sh /opt/bitnami/scripts/clickhouse/run.sh
{{- else }}
ClickHouse is available in the following address:
{{- if .Values.externalAccess.enabled }}
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
kubectl get svc --namespace {{ template "common.names.namespace" . }} -l "app.kubernetes.io/name={{ template "common.names.fullname" . }},app.kubernetes.io/instance={{ .Release.Name }},app.kubernetes.io/component=clickhouse" -w
{{- else if (eq "LoadBalancer" .Values.service.type) }}
export SERVICE_IP=$(kubectl get svc --namespace {{ template "common.names.namespace" . }} {{ template "common.names.fullname" . }} --template "{{ "{{ range (index .status.loadBalancer.ingress 0) }}{{ . }}{{ end }}" }}")
{{- else if (eq "NodePort" .Values.service.type)}}
export NODE_IP=$(kubectl get nodes --namespace {{ template "common.names.namespace" . }} -o jsonpath="{.items[0].status.addresses[0].address}")
export NODE_PORT=$(kubectl get --namespace {{ template "common.names.namespace" . }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ template "common.names.fullname" . }})
{{- else if (eq "ClusterIP" .Values.service.type)}}
kubectl port-forward --namespace {{ template "common.names.namespace" . }} svc/{{ template "common.names.fullname" . }} {{ .Values.service.ports.tcp }}:9000 &
{{- end }}
Credentials:
echo "Username : {{ .Values.auth.username }}"
echo "Password : $(kubectl get secret --namespace {{ .Release.Namespace }} {{ include "clickhouse.secretName" . }} -o jsonpath="{.data.{{ include "clickhouse.secretKey" .}}}" | base64 -d)"
{{- end }}
{{- include "common.warnings.rollingTag" .Values.image }}
{{- include "clickhouse.validateValues" . }}
{{- include "common.warnings.resources" (dict "sections" (list "" "volumePermissions") "context" $) }}
{{- include "common.warnings.modifiedImages" (dict "images" (list .Values.image .Values.volumePermissions.image) "context" $) }}
{{- include "common.errors.insecureImages" (dict "images" (list .Values.image .Values.volumePermissions.image) "context" $) }}
@@ -0,0 +1,219 @@
{{/*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{/*
Return the proper ClickHouse image name
*/}}
{{- define "clickhouse.image" -}}
{{ include "common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }}
{{- end -}}
{{/*
Return the proper image name (for the init container volume-permissions image)
*/}}
{{- define "clickhouse.volumePermissions.image" -}}
{{- include "common.images.image" ( dict "imageRoot" .Values.volumePermissions.image "global" .Values.global ) -}}
{{- end -}}
{{/*
Return the proper Docker Image Registry Secret Names
*/}}
{{- define "clickhouse.imagePullSecrets" -}}
{{- include "common.images.pullSecrets" (dict "images" (list .Values.image .Values.volumePermissions.image) "global" .Values.global) -}}
{{- end -}}
{{/*
Return true if a TLS credentials secret object should be created
*/}}
{{- define "clickhouse.createTlsSecret" -}}
{{- if and .Values.tls.autoGenerated (not .Values.tls.certificatesSecret) }}
{{- true -}}
{{- end -}}
{{- end -}}
{{/*
Return the path to the CA cert file.
*/}}
{{- define "clickhouse.tlsSecretName" -}}
{{- if .Values.tls.autoGenerated }}
{{- printf "%s-crt" (include "common.names.fullname" .) -}}
{{- else -}}
{{ required "A secret containing TLS certificates is required when TLS is enabled" .Values.tls.certificatesSecret }}
{{- end -}}
{{- end -}}
{{/*
Return the path to the cert file.
*/}}
{{- define "clickhouse.tlsCert" -}}
{{- if .Values.tls.autoGenerated }}
{{- printf "/opt/bitnami/clickhouse/certs/tls.crt" -}}
{{- else -}}
{{- required "Certificate filename is required when TLS in enabled" .Values.tls.certFilename | printf "/opt/bitnami/clickhouse/certs/%s" -}}
{{- end -}}
{{- end -}}
{{/*
Return the path to the cert key file.
*/}}
{{- define "clickhouse.tlsCertKey" -}}
{{- if .Values.tls.autoGenerated }}
{{- printf "/opt/bitnami/clickhouse/certs/tls.key" -}}
{{- else -}}
{{- required "Certificate Key filename is required when TLS in enabled" .Values.tls.certKeyFilename | printf "/opt/bitnami/clickhouse/certs/%s" -}}
{{- end -}}
{{- end -}}
{{/*
Return the path to the CA cert file.
*/}}
{{- define "clickhouse.tlsCACert" -}}
{{- if .Values.tls.autoGenerated }}
{{- printf "/opt/bitnami/clickhouse/certs/ca.crt" -}}
{{- else -}}
{{- printf "/opt/bitnami/clickhouse/certs/%s" .Values.tls.certCAFilename -}}
{{- end -}}
{{- end -}}
{{/*
Get the ClickHouse configuration configmap.
*/}}
{{- define "clickhouse.configmapName" -}}
{{- if .Values.existingOverridesConfigmap -}}
{{- .Values.existingOverridesConfigmap -}}
{{- else }}
{{- printf "%s" (include "common.names.fullname" . ) -}}
{{- end -}}
{{- end -}}
{{/*
Get the ClickHouse configuration configmap.
*/}}
{{- define "clickhouse.extraConfigmapName" -}}
{{- if .Values.extraOverridesConfigmap -}}
{{- .Values.extraOverridesConfigmap -}}
{{- else }}
{{- printf "%s-extra" (include "common.names.fullname" . ) -}}
{{- end -}}
{{- end -}}
{{/*
Get the ClickHouse configuration users configmap.
*/}}
{{- define "clickhouse.usersExtraConfigmapName" -}}
{{- if .Values.usersExtraOverridesConfigmap -}}
{{- .Values.usersExtraOverridesConfigmap -}}
{{- else }}
{{- printf "%s-users-extra" (include "common.names.fullname" . ) -}}
{{- end -}}
{{- end -}}
{{/*
Get the Clickhouse password secret name
*/}}
{{- define "clickhouse.secretName" -}}
{{- if .Values.auth.existingSecret -}}
{{- .Values.auth.existingSecret -}}
{{- else }}
{{- printf "%s" (include "common.names.fullname" . ) -}}
{{- end -}}
{{- end -}}
{{/*
Get the ClickHouse password key inside the secret
*/}}
{{- define "clickhouse.secretKey" -}}
{{- if .Values.auth.existingSecret -}}
{{- .Values.auth.existingSecretKey -}}
{{- else }}
{{- print "admin-password" -}}
{{- end -}}
{{- end -}}
{{/*
Get the startialization scripts Secret name.
*/}}
{{- define "clickhouse.startdbScriptsSecret" -}}
{{- if .Values.startdbScriptsSecret -}}
{{- printf "%s" (tpl .Values.startdbScriptsSecret $) -}}
{{- else -}}
{{- printf "%s-start-scripts" (include "common.names.fullname" .) -}}
{{- end -}}
{{- end -}}
{{/*
Get the initialization scripts Secret name.
*/}}
{{- define "clickhouse.initdbScriptsSecret" -}}
{{- if .Values.initdbScriptsSecret -}}
{{- printf "%s" (tpl .Values.initdbScriptsSecret $) -}}
{{- else -}}
{{- printf "%s-init-scripts" (include "common.names.fullname" .) -}}
{{- end -}}
{{- end -}}
{{/*
Return the path to the CA cert file.
*/}}
{{- define "clickhouse.headlessServiceName" -}}
{{- printf "%s-headless" (include "common.names.fullname" .) -}}
{{- end -}}
{{/*
Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
*/}}
{{- define "clickhouse.zookeeper.fullname" -}}
{{- include "common.names.dependency.fullname" (dict "chartName" "zookeeper" "chartValues" .Values.zookeeper "context" $) -}}
{{- end -}}
{{/*
Return the path to the CA cert file.
*/}}
{{- define "clickhouse.zookeeper.headlessServiceName" -}}
{{- printf "%s-headless" (include "clickhouse.zookeeper.fullname" .) -}}
{{- end -}}
{{/*
Create the name of the service account to use
*/}}
{{- define "clickhouse.serviceAccountName" -}}
{{- if .Values.serviceAccount.create -}}
{{ default (include "common.names.fullname" .) .Values.serviceAccount.name }}
{{- else -}}
{{ default "default" .Values.serviceAccount.name }}
{{- end -}}
{{- end -}}
{{/*
Compile all warnings into a single message.
*/}}
{{- define "clickhouse.validateValues" -}}
{{- $messages := list -}}
{{- $messages := append $messages (include "clickhouse.validateValues.zookeeper" .) -}}
{{- $messages := without $messages "" -}}
{{- $message := join "\n" $messages -}}
{{- if $message -}}
{{- printf "\nVALUES VALIDATION:\n%s" $message -}}
{{- end -}}
{{- end -}}
{{/* Validate values of ClickHouse - [Zoo]keeper */}}
{{- define "clickhouse.validateValues.zookeeper" -}}
{{- if or (and .Values.keeper.enabled .Values.zookeeper.enabled) (and .Values.keeper.enabled .Values.externalZookeeper.servers) (and .Values.zookeeper.enabled .Values.externalZookeeper.servers) -}}
clickhouse: Multiple [Zoo]keeper
You can only use one [zoo]keeper
Please choose use ClickHouse keeper or
installing a Zookeeper chart (--set zookeeper.enabled=true) or
using an external instance (--set zookeeper.servers )
{{- end -}}
{{- if and (not .Values.keeper.enabled) (not .Values.zookeeper.enabled) (not .Values.externalZookeeper.servers) (ne (int .Values.shards) 1) (ne (int .Values.replicaCount) 1) -}}
clickhouse: No [Zoo]keeper
If you are deploying more than one ClickHouse instance, you need to enable [Zoo]keeper. Please choose installing a [Zoo]keeper (--set keeper.enabled=true) or (--set zookeeper.enabled=true) or
using an external instance (--set zookeeper.servers )
{{- end -}}
{{- end -}}
@@ -0,0 +1,20 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.extraOverrides (not .Values.extraOverridesConfigmap) }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-extra" (include "common.names.fullname" .) }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
data:
01_extra_overrides.xml: |
{{- include "common.tplvalues.render" (dict "value" .Values.extraOverrides "context" $) | nindent 4 }}
{{- end }}
@@ -0,0 +1,20 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.usersExtraOverrides (not .Values.usersExtraOverridesConfigmap) }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-users-extra" (include "common.names.fullname" .) }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
data:
01_users_extra_overrides.xml: |
{{- include "common.tplvalues.render" (dict "value" .Values.usersExtraOverrides "context" $) | nindent 4 }}
{{- end }}
@@ -0,0 +1,20 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if not .Values.existingOverridesConfigmap }}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ template "common.names.fullname" . }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
data:
00_default_overrides.xml: |
{{- include "common.tplvalues.render" (dict "value" .Values.defaultConfigurationOverrides "context" $) | nindent 4 }}
{{- end }}
@@ -0,0 +1,9 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- range .Values.extraDeploy }}
---
{{ include "common.tplvalues.render" (dict "value" . "context" $) }}
{{- end }}
@@ -0,0 +1,44 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.ingress.enabled }}
{{- if .Values.ingress.secrets }}
{{- range .Values.ingress.secrets }}
apiVersion: v1
kind: Secret
metadata:
name: {{ .name }}
namespace: {{ $.Release.Namespace | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" $.Values.commonLabels "context" $ ) | nindent 4 }}
{{- if $.Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $.Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
tls.crt: {{ .certificate | b64enc }}
tls.key: {{ .key | b64enc }}
---
{{- end }}
{{- end }}
{{- if and .Values.ingress.tls .Values.ingress.selfSigned }}
{{- $secretName := printf "%s-tls" .Values.ingress.hostname }}
{{- $ca := genCA "clickhouse-ca" 365 }}
{{- $cert := genSignedCert .Values.ingress.hostname nil (list .Values.ingress.hostname) 365 $ca }}
apiVersion: v1
kind: Secret
metadata:
name: {{ $secretName }}
namespace: {{ .Release.Namespace | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
tls.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.crt" "defaultValue" $cert.Cert "context" $) }}
tls.key: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.key" "defaultValue" $cert.Key "context" $) }}
ca.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "ca.crt" "defaultValue" $ca.Cert "context" $) }}
{{- end }}
{{- end }}
@@ -0,0 +1,59 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.ingress.enabled }}
apiVersion: {{ include "common.capabilities.ingress.apiVersion" . }}
kind: Ingress
metadata:
name: {{ include "common.names.fullname" . }}
namespace: {{ .Release.Namespace | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- if or .Values.ingress.annotations .Values.commonAnnotations }}
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.ingress.annotations .Values.commonAnnotations ) "context" . ) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
{{- end }}
spec:
{{- if and .Values.ingress.ingressClassName (eq "true" (include "common.ingress.supportsIngressClassname" .)) }}
ingressClassName: {{ .Values.ingress.ingressClassName | quote }}
{{- end }}
rules:
{{- if .Values.ingress.hostname }}
- host: {{ .Values.ingress.hostname | quote }}
http:
paths:
{{- if .Values.ingress.extraPaths }}
{{- toYaml .Values.ingress.extraPaths | nindent 10 }}
{{- end }}
- path: {{ .Values.ingress.path }}
{{- if eq "true" (include "common.ingress.supportsPathType" .) }}
pathType: {{ .Values.ingress.pathType }}
{{- end }}
backend: {{- include "common.ingress.backend" (dict "serviceName" (include "common.names.fullname" .) "servicePort" "http" "context" $) | nindent 14 }}
{{- end }}
{{- range .Values.ingress.extraHosts }}
- host: {{ .name | quote }}
http:
paths:
- path: {{ default "/" .path }}
{{- if eq "true" (include "common.ingress.supportsPathType" $) }}
pathType: {{ default "ImplementationSpecific" .pathType }}
{{- end }}
backend: {{- include "common.ingress.backend" (dict "serviceName" (include "common.names.fullname" $) "servicePort" "http" "context" $) | nindent 14 }}
{{- end }}
{{- if .Values.ingress.extraRules }}
{{- include "common.tplvalues.render" (dict "value" .Values.ingress.extraRules "context" $) | nindent 4 }}
{{- end }}
{{- if or (and .Values.ingress.tls (or (include "common.ingress.certManagerRequest" ( dict "annotations" .Values.ingress.annotations )) .Values.ingress.selfSigned)) .Values.ingress.extraTls }}
tls:
{{- if and .Values.ingress.tls (or (include "common.ingress.certManagerRequest" ( dict "annotations" .Values.ingress.annotations )) .Values.ingress.selfSigned) }}
- hosts:
- {{ .Values.ingress.hostname | quote }}
secretName: {{ printf "%s-tls" .Values.ingress.hostname }}
{{- end }}
{{- if .Values.ingress.extraTls }}
{{- include "common.tplvalues.render" (dict "value" .Values.ingress.extraTls "context" $) | nindent 4 }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,19 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.initdbScripts (not .Values.initdbScriptsSecret) }}
apiVersion: v1
kind: Secret
metadata:
name: {{ printf "%s-init-scripts" (include "common.names.fullname" .) }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
stringData:
{{- include "common.tplvalues.render" (dict "value" .Values.initdbScripts "context" .) | nindent 2 }}
{{- end }}
@@ -0,0 +1,136 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.networkPolicy.enabled }}
kind: NetworkPolicy
apiVersion: {{ include "common.capabilities.networkPolicy.apiVersion" . }}
metadata:
name: {{ include "common.names.fullname" . }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
spec:
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
podSelector:
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 6 }}
app.kubernetes.io/component: clickhouse
policyTypes:
- Ingress
- Egress
{{- if .Values.networkPolicy.allowExternalEgress }}
egress:
- {}
{{- else }}
egress:
# Allow dns resolution
- ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
# Allow outbound connections to other cluster pods
- ports:
- port: {{ .Values.service.ports.http }}
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.ports.https }}
{{- end }}
- port: {{ .Values.service.ports.tcp }}
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.ports.tcpSecure }}
{{- end }}
{{- if .Values.keeper.enabled }}
- port: {{ .Values.service.ports.keeper }}
- port: {{ .Values.service.ports.keeperInter }}
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.ports.keeperSecure }}
{{- end }}
{{- end }}
- port: {{ .Values.service.ports.mysql }}
- port: {{ .Values.service.ports.postgresql }}
- port: {{ .Values.service.ports.interserver }}
{{- if .Values.metrics.enabled }}
- port: {{ .Values.service.ports.metrics }}
{{- end }}
{{- if $.Values.externalAccess.enabled }}
- port: {{ $.Values.externalAccess.service.ports.http }}
{{- if $.Values.tls.enabled }}
- port: {{ $.Values.externalAccess.service.ports.https }}
{{- end }}
{{- if $.Values.metrics.enabled }}
- port: {{ $.Values.externalAccess.service.ports.metrics }}
{{- end }}
- port: {{ $.Values.externalAccess.service.ports.tcp }}
{{- if $.Values.tls.enabled }}
- port: {{ $.Values.externalAccess.service.ports.tcpSecure }}
{{- end }}
{{- if $.Values.keeper.enabled }}
- port: {{ $.Values.externalAccess.service.ports.keeper }}
- port: {{ $.Values.externalAccess.service.ports.keeperInter }}
{{- if $.Values.tls.enabled }}
- port: {{ $.Values.externalAccess.service.ports.keeperSecure }}
{{- end }}
{{- end }}
- port: {{ $.Values.externalAccess.service.ports.mysql }}
- port: {{ $.Values.externalAccess.service.ports.postgresql }}
- port: {{ $.Values.externalAccess.service.ports.interserver }}
{{- end }}
to:
- podSelector:
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 14 }}
{{- if .Values.networkPolicy.extraEgress }}
{{- include "common.tplvalues.render" ( dict "value" .Values.networkPolicy.extraEgress "context" $ ) | nindent 4 }}
{{- end }}
{{- end }}
ingress:
- ports:
- port: {{ $.Values.containerPorts.http }}
- port: {{ $.Values.containerPorts.tcp }}
- port: {{ $.Values.containerPorts.mysql }}
- port: {{ $.Values.containerPorts.postgresql }}
- port: {{ $.Values.containerPorts.interserver }}
{{- if $.Values.tls.enabled }}
- port: {{ $.Values.containerPorts.tcpSecure }}
- port: {{ $.Values.containerPorts.https }}
{{- end }}
{{- if $.Values.keeper.enabled }}
- port: {{ $.Values.containerPorts.keeper }}
- port: {{ $.Values.containerPorts.keeperInter }}
{{- if $.Values.tls.enabled }}
- port : {{ $.Values.containerPorts.keeperSecure }}
{{- end }}
{{- end }}
{{- if $.Values.metrics.enabled }}
- port: {{ $.Values.containerPorts.metrics }}
{{- end }}
{{- if not .Values.networkPolicy.allowExternal }}
from:
- podSelector:
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 14 }}
app.kubernetes.io/component: clickhouse
- podSelector:
matchLabels:
{{ include "common.names.fullname" . }}-client: "true"
{{- if .Values.networkPolicy.ingressNSMatchLabels }}
- namespaceSelector:
matchLabels:
{{- range $key, $value := .Values.networkPolicy.ingressNSMatchLabels }}
{{ $key | quote }}: {{ $value | quote }}
{{- end }}
{{- if .Values.networkPolicy.ingressNSPodMatchLabels }}
podSelector:
matchLabels:
{{- range $key, $value := .Values.networkPolicy.ingressNSPodMatchLabels }}
{{ $key | quote }}: {{ $value | quote }}
{{- end }}
{{- end }}
{{- end }}
{{- end }}
{{- if .Values.networkPolicy.extraIngress }}
{{- include "common.tplvalues.render" ( dict "value" .Values.networkPolicy.extraIngress "context" $ ) | nindent 4 }}
{{- end }}
{{- end }}
@@ -0,0 +1,34 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.pdb.create }}
{{- $shards := .Values.shards | int }}
{{- range $i, $e := until $shards }}
apiVersion: {{ include "common.capabilities.policy.apiVersion" $ }}
kind: PodDisruptionBudget
metadata:
name: {{ printf "%s-shard%d" (include "common.names.fullname" $ ) $i }}
namespace: {{ include "common.names.namespace" $ | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" $.Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
shard: {{ $i | quote }}
{{- if $.Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $.Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
spec:
{{- if $.Values.pdb.minAvailable }}
minAvailable: {{ $.Values.pdb.minAvailable }}
{{- end }}
{{- if or $.Values.pdb.maxUnavailable (not $.Values.pdb.minAvailable) }}
maxUnavailable: {{ $.Values.pdb.maxUnavailable | default 1 }}
{{- end }}
{{- $podLabels := include "common.tplvalues.merge" (dict "values" (list $.Values.podLabels $.Values.commonLabels) "context" $) }}
selector:
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 6 }}
app.kubernetes.io/component: clickhouse
shard: {{ $i | quote }}
---
{{- end }}
{{- end }}
@@ -0,0 +1,24 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.metrics.enabled .Values.metrics.prometheusRule.enabled .Values.metrics.prometheusRule.rules }}
apiVersion: monitoring.coreos.com/v1
kind: PrometheusRule
metadata:
name: {{ include "common.names.fullname" . }}
namespace: {{ default .Release.Namespace .Values.metrics.prometheusRule.namespace | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: metrics
{{- if .Values.metrics.prometheusRule.additionalLabels }}
{{- include "common.tplvalues.render" ( dict "value" .Values.metrics.prometheusRule.additionalLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
spec:
groups:
- name: {{ include "common.names.fullname" . }}
rules: {{- toYaml .Values.metrics.prometheusRule.rules | nindent 8 }}
{{- end }}
@@ -0,0 +1,34 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ printf "%s-scripts" (include "common.names.fullname" .) }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
data:
setup.sh: |-
#!/bin/bash
# Execute entrypoint as usual after obtaining KEEPER_SERVER_ID
# check KEEPER_SERVER_ID in persistent volume via myid
# if not present, set based on POD hostname
if [[ -f "/bitnami/clickhouse/keeper/data/myid" ]]; then
export KEEPER_SERVER_ID="$(cat /bitnami/clickhouse/keeper/data/myid)"
else
HOSTNAME="$(hostname -s)"
if [[ $HOSTNAME =~ (.*)-([0-9]+)$ ]]; then
export KEEPER_SERVER_ID=${BASH_REMATCH[2]}
else
echo "Failed to get index from hostname $HOST"
exit 1
fi
fi
exec /opt/bitnami/scripts/clickhouse/entrypoint.sh /opt/bitnami/scripts/clickhouse/run.sh "$@"
@@ -0,0 +1,20 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if not .Values.auth.existingSecret }}
apiVersion: v1
kind: Secret
metadata:
name: {{ template "common.names.fullname" . }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
type: Opaque
data:
admin-password: {{ include "common.secrets.passwords.manage" (dict "secret" (include "common.names.fullname" .) "key" "admin-password" "providedValues" (list "auth.password") "context" $) }}
{{- end }}
@@ -0,0 +1,19 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if .Values.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ include "clickhouse.serviceAccountName" . }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if or .Values.serviceAccount.annotations .Values.commonAnnotations }}
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.serviceAccount.annotations .Values.commonAnnotations ) "context" . ) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
{{- end }}
automountServiceAccountToken: {{ .Values.serviceAccount.automountServiceAccountToken }}
{{- end }}
@@ -0,0 +1,155 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if $.Values.externalAccess.enabled }}
{{- $shards := $.Values.shards | int }}
{{- $replicas := $.Values.replicaCount | int }}
{{- $totalNodes := mul $shards $replicas }}
{{- range $shard, $e := until $shards }}
{{- range $i, $_e := until $replicas }}
{{- $loadBalancerAnnotationPosOffset := mul $shard $replicas }}
{{- $loadBalancerAnnotationPosition := add $loadBalancerAnnotationPosOffset $i }}
{{- $targetPod := printf "%s-shard%d-%d" (include "common.names.fullname" $) $shard $i }}
apiVersion: v1
kind: Service
metadata:
name: {{ printf "%s-external" $targetPod | trunc 63 | trimSuffix "-" }}
namespace: {{ $.Release.Namespace | quote }}
{{- $labels := include "common.tplvalues.merge" ( dict "values" ( list $.Values.externalAccess.service.labels $.Values.commonLabels ) "context" $ ) }}
labels: {{- include "common.labels.standard" ( dict "customLabels" $labels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
pod: {{ $targetPod }}
{{- if or $.Values.externalAccess.service.annotations $.Values.commonAnnotations $.Values.externalAccess.service.loadBalancerAnnotations }}
annotations:
{{- if and (not (empty $.Values.externalAccess.service.loadBalancerAnnotations)) (eq (len $.Values.externalAccess.service.loadBalancerAnnotations) $totalNodes) }}
{{ include "common.tplvalues.render" ( dict "value" (index $.Values.externalAccess.service.loadBalancerAnnotations $loadBalancerAnnotationPosition) "context" $) | nindent 4 }}
{{- end }}
{{- if $.Values.externalAccess.service.annotations }}
{{- include "common.tplvalues.render" ( dict "value" $.Values.externalAccess.service.annotations "context" $) | nindent 4 }}
{{- end }}
{{- if $.Values.commonAnnotations }}
{{- include "common.tplvalues.render" ( dict "value" $.Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
{{- end }}
spec:
type: {{ $.Values.externalAccess.service.type }}
{{- if eq $.Values.externalAccess.service.type "LoadBalancer" }}
{{- if and (not (empty $.Values.externalAccess.service.loadBalancerIPs)) (eq (len $.Values.externalAccess.service.loadBalancerIPs) $totalNodes) }}
loadBalancerIP: {{ index $.Values.externalAccess.service.loadBalancerIPs $i }}
{{- end }}
{{- if $.Values.externalAccess.service.loadBalancerSourceRanges }}
loadBalancerSourceRanges: {{- toYaml $.Values.externalAccess.service.loadBalancerSourceRanges | nindent 4 }}
{{- end }}
{{- end }}
ports:
- name: http
port: {{ $.Values.externalAccess.service.ports.http }}
targetPort: http
{{- if not (empty $.Values.externalAccess.service.nodePorts.http) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.http $i }}
{{- else }}
nodePort: null
{{- end }}
{{- if $.Values.tls.enabled }}
- name: https
port: {{ $.Values.externalAccess.service.ports.https }}
targetPort: https
{{- if not (empty $.Values.externalAccess.service.nodePorts.https) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.https $i }}
{{- else }}
nodePort: null
{{- end }}
{{- end }}
{{- if $.Values.metrics.enabled }}
- name: http-metrics
port: {{ $.Values.externalAccess.service.ports.metrics }}
targetPort: http-metrics
{{- if not (empty $.Values.externalAccess.service.nodePorts.metrics) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.metrics $i }}
{{- else }}
nodePort: null
{{- end }}
{{- end }}
- name: tcp
port: {{ $.Values.externalAccess.service.ports.tcp }}
targetPort: tcp
{{- if not (empty $.Values.externalAccess.service.nodePorts.tcp) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.tcp $i }}
{{- else }}
nodePort: null
{{- end }}
{{- if $.Values.tls.enabled }}
- name: tcp-secure
port: {{ $.Values.externalAccess.service.ports.tcpSecure }}
targetPort: tcp-secure
{{- if not (empty $.Values.externalAccess.service.nodePorts.tcpSecure) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.tcpSecure $i }}
{{- else }}
nodePort: null
{{- end }}
{{- end }}
{{- if $.Values.keeper.enabled }}
- name: tcp-keeper
port: {{ $.Values.externalAccess.service.ports.keeper }}
targetPort: tcp-keeper
{{- if not (empty $.Values.externalAccess.service.nodePorts.keeper) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.keeper $i }}
{{- else }}
nodePort: null
{{- end }}
- name: tcp-keeperinter
port: {{ $.Values.externalAccess.service.ports.keeperInter }}
targetPort: tcp-keeperinter
{{- if not (empty $.Values.externalAccess.service.nodePorts.keeperInter) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.keeperInter $i }}
{{- else }}
nodePort: null
{{- end }}
{{- if $.Values.tls.enabled }}
- name: tcp-keepertls
port: {{ $.Values.externalAccess.service.ports.keeperSecure }}
targetPort: tcp-keepertls
{{- if not (empty $.Values.externalAccess.service.nodePorts.keeperSecure) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.keeperSecure $i }}
{{- else }}
nodePort: null
{{- end }}
{{- end }}
{{- end }}
- name: tcp-mysql
port: {{ $.Values.externalAccess.service.ports.mysql }}
targetPort: tcp-mysql
{{- if not (empty $.Values.externalAccess.service.nodePorts.mysql) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.mysql $i }}
{{- else }}
nodePort: null
{{- end }}
- name: tcp-postgresql
port: {{ $.Values.externalAccess.service.ports.postgresql }}
targetPort: tcp-postgresql
{{- if not (empty $.Values.externalAccess.service.nodePorts.postgresql) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.postgresql $i }}
{{- else }}
nodePort: null
{{- end }}
- name: tcp-intersrv
port: {{ $.Values.externalAccess.service.ports.interserver }}
targetPort: tcp-intersrv
{{- if not (empty $.Values.externalAccess.service.nodePorts.interserver) }}
nodePort: {{ index $.Values.externalAccess.service.nodePorts.interserver $i }}
{{- else }}
nodePort: null
{{- end }}
{{- if $.Values.externalAccess.service.extraPorts }}
{{- include "common.tplvalues.render" (dict "value" $.Values.externalAccess.service.extraPorts "context" $) | nindent 4 }}
{{- end }}
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list $.Values.podLabels $.Values.commonLabels ) "context" $ ) }}
selector: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
statefulset.kubernetes.io/pod-name: {{ $targetPod }}
---
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,69 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: Service
metadata:
name: {{ include "clickhouse.headlessServiceName" . }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if or .Values.service.headless.annotations .Values.commonAnnotations }}
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.service.headless.annotations .Values.commonAnnotations ) "context" . ) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
{{- end }}
spec:
type: ClusterIP
clusterIP: None
publishNotReadyAddresses: true
ports:
- name: http
targetPort: http
port: {{ .Values.containerPorts.http }}
protocol: TCP
- name: tcp
targetPort: tcp
port: {{ .Values.containerPorts.tcp }}
protocol: TCP
{{- if .Values.tls.enabled }}
- name: tcp-secure
targetPort: tcp-secure
port: {{ .Values.containerPorts.tcpSecure }}
protocol: TCP
{{- end }}
{{- if .Values.keeper.enabled }}
- name: tcp-keeper
targetPort: tcp-keeper
port: {{ .Values.containerPorts.keeper }}
protocol: TCP
- name: tcp-keeperinter
targetPort: tcp-keeperinter
port: {{ .Values.containerPorts.keeperInter }}
protocol: TCP
{{- if .Values.tls.enabled }}
- name: tcp-keepertls
targetPort: tcp-keepertls
port: {{ .Values.containerPorts.keeperSecure }}
protocol: TCP
{{- end }}
{{- end }}
- name: tcp-mysql
targetPort: tcp-mysql
port: {{ .Values.containerPorts.mysql }}
protocol: TCP
- name: tcp-postgresql
targetPort: tcp-postgresql
port: {{ .Values.containerPorts.postgresql }}
protocol: TCP
- name: http-intersrv
targetPort: http-intersrv
port: {{ .Values.containerPorts.interserver }}
protocol: TCP
{{- if .Values.service.extraPorts }}
{{- include "common.tplvalues.render" (dict "value" .Values.service.extraPorts "context" $) | nindent 4 }}
{{- end }}
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
selector: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
@@ -0,0 +1,152 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
apiVersion: v1
kind: Service
metadata:
name: {{ template "common.names.fullname" . }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if or .Values.service.annotations .Values.commonAnnotations }}
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.service.annotations .Values.commonAnnotations ) "context" . ) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
{{- end }}
spec:
type: {{ .Values.service.type }}
{{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }}
clusterIP: {{ .Values.service.clusterIP }}
{{- end }}
{{- if .Values.service.sessionAffinity }}
sessionAffinity: {{ .Values.service.sessionAffinity }}
{{- end }}
{{- if .Values.service.sessionAffinityConfig }}
sessionAffinityConfig: {{- include "common.tplvalues.render" (dict "value" .Values.service.sessionAffinityConfig "context" $) | nindent 4 }}
{{- end }}
{{- if or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort") }}
externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }}
{{- end }}
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerSourceRanges)) }}
loadBalancerSourceRanges: {{- toYaml .Values.service.loadBalancerSourceRanges | nindent 4 }}
{{- end }}
{{- if and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP)) }}
loadBalancerIP: {{ .Values.service.loadBalancerIP }}
{{- end }}
ports:
- name: http
targetPort: http
port: {{ .Values.service.ports.http }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.http)) }}
nodePort: {{ .Values.service.nodePorts.http }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- if .Values.tls.enabled }}
- name: https
targetPort: https
port: {{ .Values.service.ports.https }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.https)) }}
nodePort: {{ .Values.service.nodePorts.https }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
- name: tcp
targetPort: tcp
port: {{ .Values.service.ports.tcp }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.tcp)) }}
nodePort: {{ .Values.service.nodePorts.tcp }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- if .Values.tls.enabled }}
- name: tcp-secure
targetPort: tcp-secure
port: {{ .Values.service.ports.tcpSecure }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.tcpSecure)) }}
nodePort: {{ .Values.service.nodePorts.tcpSecure }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
{{- if .Values.keeper.enabled }}
- name: tcp-keeper
targetPort: tcp-keeper
port: {{ .Values.service.ports.keeper }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.tcp)) }}
nodePort: {{ .Values.service.nodePorts.keeper }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
- name: tcp-keeperinter
targetPort: tcp-keeperinter
port: {{ .Values.service.ports.keeperInter }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.tcp)) }}
nodePort: {{ .Values.service.nodePorts.keeperInter }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- if .Values.tls.enabled }}
- name: tcp-keepertls
targetPort: tcp-keepertls
port: {{ .Values.service.ports.keeperSecure }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.tcpSecure)) }}
nodePort: {{ .Values.service.nodePorts.keeperSecure }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
{{- end }}
- name: tcp-mysql
targetPort: tcp-mysql
port: {{ .Values.service.ports.mysql }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.mysql)) }}
nodePort: {{ .Values.service.nodePorts.mysql }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
- name: tcp-postgresql
targetPort: tcp-postgresql
port: {{ .Values.service.ports.postgresql }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.postgresql)) }}
nodePort: {{ .Values.service.nodePorts.postgresql }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
- name: http-intersrv
targetPort: http-intersrv
port: {{ .Values.service.ports.interserver }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.interserver)) }}
nodePort: {{ .Values.service.nodePorts.interserver }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- if .Values.metrics.enabled }}
- name: http-metrics
targetPort: http-metrics
port: {{ .Values.service.ports.metrics }}
protocol: TCP
{{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.metrics)) }}
nodePort: {{ .Values.service.nodePorts.metrics }}
{{- else if eq .Values.service.type "ClusterIP" }}
nodePort: null
{{- end }}
{{- end }}
{{- if .Values.service.extraPorts }}
{{- include "common.tplvalues.render" (dict "value" .Values.service.extraPorts "context" $) | nindent 4 }}
{{- end }}
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list .Values.podLabels .Values.commonLabels ) "context" . ) }}
selector: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
@@ -0,0 +1,47 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.metrics.enabled .Values.metrics.serviceMonitor.enabled }}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: {{ include "common.names.fullname" . }}
namespace: {{ default (include "common.names.namespace" .) .Values.metrics.serviceMonitor.namespace | quote }}
{{- $labels := include "common.tplvalues.merge" ( dict "values" ( list .Values.metrics.serviceMonitor.labels .Values.commonLabels ) "context" . ) }}
labels: {{- include "common.labels.standard" ( dict "customLabels" $labels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if or .Values.metrics.serviceMonitor.annotations .Values.commonAnnotations }}
{{- $annotations := include "common.tplvalues.merge" ( dict "values" ( list .Values.metrics.serviceMonitor.annotations .Values.commonAnnotations ) "context" . ) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $annotations "context" $) | nindent 4 }}
{{- end }}
spec:
jobLabel: {{ .Values.metrics.serviceMonitor.jobLabel | quote }}
selector:
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 6 }}
{{- if .Values.metrics.serviceMonitor.selector }}
{{- include "common.tplvalues.render" (dict "value" .Values.metrics.serviceMonitor.selector "context" $) | nindent 6 }}
{{- end }}
endpoints:
- port: http-metrics
path: "/metrics"
{{- if .Values.metrics.serviceMonitor.interval }}
interval: {{ .Values.metrics.serviceMonitor.interval }}
{{- end }}
{{- if .Values.metrics.serviceMonitor.scrapeTimeout }}
scrapeTimeout: {{ .Values.metrics.serviceMonitor.scrapeTimeout }}
{{- end }}
{{- if .Values.metrics.serviceMonitor.honorLabels }}
honorLabels: {{ .Values.metrics.serviceMonitor.honorLabels }}
{{- end }}
{{- if .Values.metrics.serviceMonitor.metricRelabelings }}
metricRelabelings: {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.serviceMonitor.metricRelabelings "context" $) | nindent 8 }}
{{- end }}
{{- if .Values.metrics.serviceMonitor.relabelings }}
relabelings: {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.serviceMonitor.relabelings "context" $) | nindent 8 }}
{{- end }}
namespaceSelector:
matchNames:
- {{ include "common.names.namespace" . | quote }}
{{- end }}
@@ -0,0 +1,19 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if and .Values.startdbScripts (not .Values.startdbScriptsSecret) }}
apiVersion: v1
kind: Secret
metadata:
name: {{ printf "%s-start-scripts" (include "common.names.fullname" .) }}
namespace: {{ include "common.names.namespace" . | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
stringData:
{{- include "common.tplvalues.render" (dict "value" .Values.startdbScripts "context" .) | nindent 2 }}
{{- end }}
@@ -0,0 +1,464 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- $shards := .Values.shards | int }}
{{- range $i, $e := until $shards }}
apiVersion: {{ include "common.capabilities.statefulset.apiVersion" $ }}
kind: StatefulSet
metadata:
name: {{ printf "%s-shard%d" (include "common.names.fullname" $ ) $i }}
namespace: {{ include "common.names.namespace" $ | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" $.Values.commonLabels "context" $ ) | nindent 4 }}
app.kubernetes.io/component: clickhouse
shard: {{ $i | quote }}
{{- if $.Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $.Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
spec:
replicas: {{ $.Values.replicaCount }}
podManagementPolicy: {{ $.Values.podManagementPolicy | quote }}
{{- $podLabels := include "common.tplvalues.merge" ( dict "values" ( list $.Values.podLabels $.Values.commonLabels ) "context" $ ) }}
selector:
matchLabels: {{- include "common.labels.matchLabels" ( dict "customLabels" $podLabels "context" $ ) | nindent 6 }}
app.kubernetes.io/component: clickhouse
serviceName: {{ printf "%s-headless" (include "common.names.fullname" $) }}
{{- if $.Values.updateStrategy }}
updateStrategy: {{- toYaml $.Values.updateStrategy | nindent 4 }}
{{- end }}
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") $ | sha256sum }}
checksum/config-extra: {{ include (print $.Template.BasePath "/configmap-extra.yaml") $ | sha256sum }}
checksum/config-users-extra: {{ include (print $.Template.BasePath "/configmap-users-extra.yaml") $ | sha256sum }}
{{- if $.Values.podAnnotations }}
{{- include "common.tplvalues.render" (dict "value" $.Values.podAnnotations "context" $) | nindent 8 }}
{{- end }}
{{- if and $.Values.metrics.enabled $.Values.metrics.podAnnotations }}
{{- include "common.tplvalues.render" (dict "value" $.Values.metrics.podAnnotations "context" $) | nindent 8 }}
{{- end }}
labels: {{- include "common.labels.standard" ( dict "customLabels" $podLabels "context" $ ) | nindent 8 }}
app.kubernetes.io/component: clickhouse
shard: {{ $i | quote }}
spec:
serviceAccountName: {{ template "clickhouse.serviceAccountName" $ }}
{{- include "clickhouse.imagePullSecrets" $ | nindent 6 }}
automountServiceAccountToken: {{ $.Values.automountServiceAccountToken }}
{{- if $.Values.hostAliases }}
hostAliases: {{- include "common.tplvalues.render" (dict "value" $.Values.hostAliases "context" $) | nindent 8 }}
{{- end }}
{{- if $.Values.affinity }}
affinity: {{- include "common.tplvalues.render" ( dict "value" $.Values.affinity "context" $) | nindent 8 }}
{{- else }}
affinity:
podAffinity: {{- include "common.affinities.pods" (dict "type" $.Values.podAffinityPreset "component" "clickhouse" "customLabels" $podLabels "context" $) | nindent 10 }}
podAntiAffinity: {{- include "common.affinities.pods" (dict "type" $.Values.podAntiAffinityPreset "component" "clickhouse" "customLabels" $podLabels "extraPodAffinityTerms" (ternary (list (dict "extraMatchLabels" (dict "shard" $i) "topologyKey" "topology.kubernetes.io/zone")) (list) $.Values.distributeReplicasByZone) "context" $) | nindent 10 }}
nodeAffinity: {{- include "common.affinities.nodes" (dict "type" $.Values.nodeAffinityPreset.type "key" $.Values.nodeAffinityPreset.key "values" $.Values.nodeAffinityPreset.values) | nindent 10 }}
{{- end }}
{{- if $.Values.nodeSelector }}
nodeSelector: {{- include "common.tplvalues.render" ( dict "value" $.Values.nodeSelector "context" $) | nindent 8 }}
{{- end }}
{{- if $.Values.tolerations }}
tolerations: {{- include "common.tplvalues.render" (dict "value" $.Values.tolerations "context" $) | nindent 8 }}
{{- end }}
{{- if $.Values.priorityClassName }}
priorityClassName: {{ $.Values.priorityClassName | quote }}
{{- end }}
{{- if $.Values.schedulerName }}
schedulerName: {{ $.Values.schedulerName | quote }}
{{- end }}
{{- if $.Values.topologySpreadConstraints }}
topologySpreadConstraints: {{- include "common.tplvalues.render" (dict "value" $.Values.topologySpreadConstraints "context" $) | nindent 8 }}
{{- end }}
{{- if $.Values.podSecurityContext.enabled }}
securityContext: {{- include "common.compatibility.renderSecurityContext" (dict "secContext" $.Values.podSecurityContext "context" $) | nindent 8 }}
{{- end }}
{{- if $.Values.terminationGracePeriodSeconds }}
terminationGracePeriodSeconds: {{ $.Values.terminationGracePeriodSeconds }}
{{- end }}
initContainers:
{{- if and $.Values.tls.enabled (not $.Values.volumePermissions.enabled) }}
- name: copy-certs
image: {{ include "clickhouse.volumePermissions.image" $ }}
imagePullPolicy: {{ $.Values.volumePermissions.image.pullPolicy | quote }}
{{- if $.Values.resources }}
resources: {{- toYaml $.Values.resources | nindent 12 }}
{{- else if ne $.Values.resourcesPreset "none" }}
resources: {{- include "common.resources.preset" (dict "type" $.Values.resourcesPreset) | nindent 12 }}
{{- end }}
{{- if $.Values.containerSecurityContext.enabled }}
# We don't require a privileged container in this case
securityContext: {{- include "common.compatibility.renderSecurityContext" (dict "secContext" $.Values.containerSecurityContext "context" $) | nindent 12 }}
{{- end }}
command:
- /bin/sh
- -ec
- |
cp -L /tmp/certs/* /opt/bitnami/clickhouse/certs/
chmod 600 {{ include "clickhouse.tlsCertKey" $ }}
volumeMounts:
- name: raw-certificates
mountPath: /tmp/certs
- name: clickhouse-certificates
mountPath: /opt/bitnami/clickhouse/certs
- name: empty-dir
mountPath: /tmp
subPath: tmp-dir
{{- else if and $.Values.volumePermissions.enabled $.Values.persistence.enabled }}
- name: volume-permissions
image: {{ include "clickhouse.volumePermissions.image" $ }}
imagePullPolicy: {{ $.Values.volumePermissions.image.pullPolicy | quote }}
command:
- /bin/sh
- -ec
- |
mkdir -p /bitnami/clickhouse/data
chmod 700 /bitnami/clickhouse/data
{{- if $.Values.keeper.enabled }}
mkdir -p /bitnami/clickhouse/keeper
chmod 700 /bitnami/clickhouse/keeper
{{- end }}
chown {{ $.Values.containerSecurityContext.runAsUser }}:{{ $.Values.podSecurityContext.fsGroup }} /bitnami/clickhouse
find /bitnami/clickhouse -mindepth 1 -maxdepth 1 -not -name ".snapshot" -not -name "lost+found" | \
xargs -r chown -R {{ $.Values.containerSecurityContext.runAsUser }}:{{ $.Values.podSecurityContext.fsGroup }}
{{- if $.Values.tls.enabled }}
cp /tmp/certs/* /opt/bitnami/clickhouse/certs/
{{- if eq ( toString ( $.Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }}
chown -R `id -u`:`id -G | cut -d " " -f2` /opt/bitnami/clickhouse/certs/
{{- else }}
chown -R {{ $.Values.containerSecurityContext.runAsUser }}:{{ $.Values.podSecurityContext.fsGroup }} /opt/bitnami/clickhouse/certs/
{{- end }}
chmod 600 {{ include "clickhouse.tlsCertKey" $ }}
{{- end }}
securityContext: {{- include "common.tplvalues.render" (dict "value" $.Values.volumePermissions.containerSecurityContext "context" $) | nindent 12 }}
{{- if $.Values.volumePermissions.resources }}
resources: {{- toYaml $.Values.volumePermissions.resources | nindent 12 }}
{{- else if ne $.Values.volumePermissions.resourcesPreset "none" }}
resources: {{- include "common.resources.preset" (dict "type" $.Values.volumePermissions.resourcesPreset) | nindent 12 }}
{{- end }}
volumeMounts:
- name: data
mountPath: /bitnami/clickhouse
- name: empty-dir
mountPath: /tmp
subPath: tmp-dir
{{- if $.Values.tls.enabled }}
- name: raw-certificates
mountPath: /tmp/certs
- name: clickhouse-certificates
mountPath: /opt/bitnami/clickhouse/certs
{{- end }}
{{- end }}
{{- if $.Values.initContainers }}
{{- include "common.tplvalues.render" (dict "value" $.Values.initContainers "context" $) | nindent 8 }}
{{- end }}
containers:
- name: clickhouse
image: {{ template "clickhouse.image" $ }}
imagePullPolicy: {{ $.Values.image.pullPolicy }}
{{- if $.Values.containerSecurityContext.enabled }}
securityContext: {{- include "common.compatibility.renderSecurityContext" (dict "secContext" $.Values.containerSecurityContext "context" $) | nindent 12 }}
{{- end }}
{{- if $.Values.diagnosticMode.enabled }}
command: {{- include "common.tplvalues.render" (dict "value" $.Values.diagnosticMode.command "context" $) | nindent 12 }}
{{- else if $.Values.command }}
command: {{- include "common.tplvalues.render" (dict "value" $.Values.command "context" $) | nindent 12 }}
{{- end }}
{{- if $.Values.diagnosticMode.enabled }}
args: {{- include "common.tplvalues.render" (dict "value" $.Values.diagnosticMode.args "context" $) | nindent 12 }}
{{- else if $.Values.args }}
args: {{- include "common.tplvalues.render" (dict "value" $.Values.args "context" $) | nindent 12 }}
{{- end }}
env:
- name: BITNAMI_DEBUG
value: {{ ternary "true" "false" (or $.Values.image.debug $.Values.diagnosticMode.enabled) | quote }}
- name: CLICKHOUSE_HTTP_PORT
value: {{ $.Values.containerPorts.http | quote }}
- name: CLICKHOUSE_TCP_PORT
value: {{ $.Values.containerPorts.tcp | quote }}
- name: CLICKHOUSE_MYSQL_PORT
value: {{ $.Values.containerPorts.mysql | quote }}
- name: CLICKHOUSE_POSTGRESQL_PORT
value: {{ $.Values.containerPorts.postgresql | quote }}
- name: CLICKHOUSE_INTERSERVER_HTTP_PORT
value: {{ $.Values.containerPorts.interserver | quote }}
{{- if $.Values.tls.enabled }}
- name: CLICKHOUSE_TCP_SECURE_PORT
value: {{ $.Values.containerPorts.tcpSecure | quote }}
- name: CLICKHOUSE_HTTPS_PORT
value: {{ $.Values.containerPorts.https | quote }}
{{- end }}
{{- if $.Values.keeper.enabled }}
- name: CLICKHOUSE_KEEPER_PORT
value: {{ $.Values.containerPorts.keeper | quote }}
- name: CLICKHOUSE_KEEPER_INTER_PORT
value: {{ $.Values.containerPorts.keeperInter | quote }}
{{- if $.Values.tls.enabled }}
- name: CLICKHOUSE_KEEPER_SECURE_PORT
value: {{ $.Values.containerPorts.keeperSecure | quote }}
{{- end }}
{{- end }}
{{- if $.Values.metrics.enabled }}
- name: CLICKHOUSE_METRICS_PORT
value: {{ $.Values.containerPorts.metrics | quote }}
{{- end }}
- name: CLICKHOUSE_ADMIN_USER
value: {{ $.Values.auth.username | quote }}
- name: CLICKHOUSE_SHARD_ID
value: {{ printf "shard%d" $i | quote }}
- name: CLICKHOUSE_REPLICA_ID
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: CLICKHOUSE_ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: {{ include "clickhouse.secretName" $ }}
key: {{ include "clickhouse.secretKey" $ }}
{{- if $.Values.tls.enabled }}
- name: CLICKHOUSE_TLS_CERT_FILE
value: {{ include "clickhouse.tlsCert" $ | quote}}
- name: CLICKHOUSE_TLS_KEY_FILE
value: {{ include "clickhouse.tlsCertKey" $ | quote }}
- name: CLICKHOUSE_TLS_CA_FILE
value: {{ include "clickhouse.tlsCACert" $ | quote }}
{{- end }}
{{- if $.Values.extraEnvVars }}
{{- include "common.tplvalues.render" (dict "value" $.Values.extraEnvVars "context" $) | nindent 12 }}
{{- end }}
{{- if $.Values.keeper.enabled }}
{{- $replicas := $.Values.replicaCount | int }}
{{- range $j, $r := until $replicas }}
- name: {{ printf "KEEPER_NODE_%d" $j }}
value: {{ printf "%s-shard%d-%d.%s.%s.svc.%s" (include "common.names.fullname" $ ) $i $j (include "clickhouse.headlessServiceName" $) (include "common.names.namespace" $) $.Values.clusterDomain }}
{{- end }}
{{- else if $.Values.zookeeper.enabled }}
{{- $replicas := $.Values.zookeeper.replicaCount | int }}
{{- range $j, $r := until $replicas }}
- name: {{ printf "KEEPER_NODE_%d" $j }}
value: {{ printf "%s-%d.%s.%s.svc.%s" (include "clickhouse.zookeeper.fullname" $ ) $j (include "clickhouse.zookeeper.headlessServiceName" $) (include "common.names.namespace" $) $.Values.clusterDomain }}
{{- end }}
{{- end }}
envFrom:
{{- if $.Values.extraEnvVarsCM }}
- configMapRef:
name: {{ include "common.tplvalues.render" (dict "value" $.Values.extraEnvVarsCM "context" $) }}
{{- end }}
{{- if $.Values.extraEnvVarsSecret }}
- secretRef:
name: {{ include "common.tplvalues.render" (dict "value" $.Values.extraEnvVarsSecret "context" $) }}
{{- end }}
{{- if $.Values.resources }}
resources: {{- toYaml $.Values.resources | nindent 12 }}
{{- else if ne $.Values.resourcesPreset "none" }}
resources: {{- include "common.resources.preset" (dict "type" $.Values.resourcesPreset) | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: {{ $.Values.containerPorts.http }}
- name: tcp
containerPort: {{ $.Values.containerPorts.tcp }}
{{- if $.Values.tls.enabled }}
- name: https
containerPort: {{ $.Values.containerPorts.https }}
- name: tcp-secure
containerPort: {{ $.Values.containerPorts.tcpSecure }}
{{- end }}
{{- if $.Values.keeper.enabled }}
- name: tcp-keeper
containerPort: {{ $.Values.containerPorts.keeper }}
- name: tcp-keeperinter
containerPort: {{ $.Values.containerPorts.keeperInter }}
{{- if $.Values.tls.enabled }}
- name: tcp-keepertls
containerPort: {{ $.Values.containerPorts.keeperSecure }}
{{- end }}
{{- end }}
- name: tcp-postgresql
containerPort: {{ $.Values.containerPorts.postgresql }}
- name: tcp-mysql
containerPort: {{ $.Values.containerPorts.mysql }}
- name: http-intersrv
containerPort: {{ $.Values.containerPorts.interserver }}
{{- if $.Values.metrics.enabled }}
- name: http-metrics
containerPort: {{ $.Values.containerPorts.metrics }}
{{- end }}
{{- if not $.Values.diagnosticMode.enabled }}
{{- if $.Values.customLivenessProbe }}
livenessProbe: {{- include "common.tplvalues.render" (dict "value" $.Values.customLivenessProbe "context" $) | nindent 12 }}
{{- else if $.Values.livenessProbe.enabled }}
livenessProbe: {{- include "common.tplvalues.render" (dict "value" (omit $.Values.livenessProbe "enabled") "context" $) | nindent 12 }}
tcpSocket:
port: http
{{- end }}
{{- if $.Values.customReadinessProbe }}
readinessProbe: {{- include "common.tplvalues.render" (dict "value" $.Values.customReadinessProbe "context" $) | nindent 12 }}
{{- else if $.Values.readinessProbe.enabled }}
readinessProbe: {{- include "common.tplvalues.render" (dict "value" (omit $.Values.readinessProbe "enabled") "context" $) | nindent 12 }}
httpGet:
path: /ping
port: http
{{- end }}
{{- if $.Values.customStartupProbe }}
startupProbe: {{- include "common.tplvalues.render" (dict "value" $.Values.customStartupProbe "context" $) | nindent 12 }}
{{- else if $.Values.startupProbe.enabled }}
startupProbe: {{- include "common.tplvalues.render" (dict "value" (omit $.Values.startupProbe "enabled") "context" $) | nindent 12 }}
httpGet:
path: /ping
port: http
{{- end }}
{{- end }}
{{- if $.Values.lifecycleHooks }}
lifecycle: {{- include "common.tplvalues.render" (dict "value" $.Values.lifecycleHooks "context" $) | nindent 12 }}
{{- end }}
volumeMounts:
- name: empty-dir
mountPath: /opt/bitnami/clickhouse/etc
subPath: app-conf-dir
- name: empty-dir
mountPath: /opt/bitnami/clickhouse/logs
subPath: app-logs-dir
- name: empty-dir
mountPath: /opt/bitnami/clickhouse/tmp
subPath: app-tmp-dir
- name: empty-dir
mountPath: /tmp
subPath: tmp-dir
- name: scripts
mountPath: /scripts/setup.sh
subPath: setup.sh
- name: data
mountPath: /bitnami/clickhouse
- name: config
mountPath: /bitnami/clickhouse/etc/conf.d/default
{{- if or $.Values.extraOverridesConfigmap $.Values.extraOverrides }}
- name: extra-config
mountPath: /bitnami/clickhouse/etc/conf.d/extra-configmap
{{- end }}
{{- if or $.Values.usersExtraOverridesConfigmap $.Values.usersExtraOverrides }}
- name: users-extra-config
mountPath: /bitnami/clickhouse/etc/users.d/users-extra-configmap
{{- end }}
{{- if $.Values.extraOverridesSecret }}
- name: extra-secret
mountPath: /bitnami/clickhouse/etc/conf.d/extra-secret
{{- end }}
{{- if $.Values.usersExtraOverridesSecret }}
- name: users-extra-secret
mountPath: /bitnami/clickhouse/etc/users.d/users-extra-secret
{{- end }}
{{- if $.Values.tls.enabled }}
- name: clickhouse-certificates
mountPath: /bitnami/clickhouse/certs
{{- end }}
{{- if or $.Values.initdbScriptsSecret $.Values.initdbScripts }}
- name: custom-init-scripts
mountPath: /docker-entrypoint-initdb.d
{{- end }}
{{- if or $.Values.startdbScriptsSecret $.Values.startdbScripts }}
- name: custom-start-scripts
mountPath: /docker-entrypoint-startdb.d
{{- end }}
{{- if $.Values.extraVolumeMounts }}
{{- include "common.tplvalues.render" (dict "value" $.Values.extraVolumeMounts "context" $) | nindent 12 }}
{{- end }}
{{- if $.Values.sidecars }}
{{- include "common.tplvalues.render" ( dict "value" $.Values.sidecars "context" $) | nindent 8 }}
{{- end }}
volumes:
- name: scripts
configMap:
name: {{ printf "%s-scripts" (include "common.names.fullname" $) }}
defaultMode: 0755
- name: empty-dir
emptyDir: {}
- name: config
configMap:
name: {{ template "clickhouse.configmapName" $ }}
{{- if or $.Values.initdbScriptsSecret $.Values.initdbScripts }}
- name: custom-init-scripts
secret:
secretName: {{ include "clickhouse.initdbScriptsSecret" $ }}
{{- end }}
{{- if or $.Values.startdbScriptsSecret $.Values.startdbScripts }}
- name: custom-start-scripts
secret:
secretName: {{ include "clickhouse.startdbScriptsSecret" $ }}
{{- end }}
{{- if or $.Values.extraOverridesConfigmap $.Values.extraOverrides }}
- name: extra-config
configMap:
name: {{ template "clickhouse.extraConfigmapName" $ }}
{{- end }}
{{- if or $.Values.usersExtraOverridesConfigmap $.Values.usersExtraOverrides }}
- name: users-extra-config
configMap:
name: {{ template "clickhouse.usersExtraConfigmapName" $ }}
{{- end }}
{{- if $.Values.extraOverridesSecret }}
- name: extra-secret
secret:
secretName: {{ $.Values.extraOverridesSecret }}
{{- end }}
{{- if $.Values.usersExtraOverridesSecret }}
- name: users-extra-secret
secret:
secretName: {{ $.Values.usersExtraOverridesSecret }}
{{- end }}
{{- if not $.Values.persistence.enabled }}
- name: data
emptyDir: {}
{{- else if $.Values.persistence.existingClaim }}
- name: data
persistentVolumeClaim:
claimName: {{ tpl $.Values.persistence.existingClaim $ }}
{{- end }}
{{- if $.Values.tls.enabled }}
- name: raw-certificates
secret:
secretName: {{ include "clickhouse.tlsSecretName" $ }}
- name: clickhouse-certificates
emptyDir: {}
{{- end }}
{{- if $.Values.extraVolumes }}
{{- include "common.tplvalues.render" (dict "value" $.Values.extraVolumes "context" $) | nindent 8 }}
{{- end }}
{{- if or $.Values.extraVolumeClaimTemplates (and $.Values.persistence.enabled (not $.Values.persistence.existingClaim)) }}
volumeClaimTemplates:
{{- if and $.Values.persistence.enabled (not $.Values.persistence.existingClaim) }}
- apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: data
{{- if or $.Values.persistence.annotations $.Values.commonAnnotations }}
{{- $claimAnnotations := include "common.tplvalues.merge" ( dict "values" ( list $.Values.persistence.annotations $.Values.commonLabels ) "context" $ ) }}
annotations: {{- include "common.tplvalues.render" ( dict "value" $claimAnnotations "context" $ ) | nindent 10 }}
{{- end }}
{{- $claimLabels := include "common.tplvalues.merge" ( dict "values" ( list $.Values.persistence.labels $.Values.commonLabels ) "context" $ ) }}
labels: {{- include "common.labels.matchLabels" ( dict "customLabels" $claimLabels "context" $ ) | nindent 10 }}
app.kubernetes.io/component: clickhouse
spec:
accessModes:
{{- range $.Values.persistence.accessModes }}
- {{ . | quote }}
{{- end }}
resources:
requests:
storage: {{ $.Values.persistence.size | quote }}
{{- if $.Values.persistence.selector }}
selector: {{- include "common.tplvalues.render" (dict "value" $.Values.persistence.selector "context" $) | nindent 10 }}
{{- end }}
{{- if $.Values.persistence.dataSource }}
dataSource: {{- include "common.tplvalues.render" (dict "value" $.Values.persistence.dataSource "context" $) | nindent 10 }}
{{- end }}
{{- include "common.storage.class" (dict "persistence" $.Values.persistence "global" $.Values.global) | nindent 8 }}
{{- end }}
{{- if $.Values.extraVolumeClaimTemplates }}
{{- include "common.tplvalues.render" ( dict "value" $.Values.extraVolumeClaimTemplates "context" $) | nindent 4 }}
{{- end }}
{{- end }}
---
{{- end }}
@@ -0,0 +1,29 @@
{{- /*
Copyright Broadcom, Inc. All Rights Reserved.
SPDX-License-Identifier: APACHE-2.0
*/}}
{{- if (include "clickhouse.createTlsSecret" . ) }}
{{- $secretName := printf "%s-crt" (include "common.names.fullname" .) }}
{{- $ca := genCA "clickhouse-ca" 365 }}
{{- $fullname := include "common.names.fullname" . }}
{{- $releaseNamespace := .Release.Namespace }}
{{- $clusterDomain := .Values.clusterDomain }}
{{- $primaryHeadlessServiceName := printf "%s-headless" (include "common.names.fullname" .)}}
{{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "*.%s.%s.svc.%s" $primaryHeadlessServiceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $primaryHeadlessServiceName $releaseNamespace $clusterDomain) $fullname }}
{{- $cert := genSignedCert $fullname nil $altNames 365 $ca }}
apiVersion: v1
kind: Secret
metadata:
name: {{ $secretName }}
namespace: {{ .Release.Namespace | quote }}
labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
type: kubernetes.io/tls
data:
tls.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.crt" "defaultValue" $cert.Cert "context" $) }}
tls.key: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.key" "defaultValue" $cert.Key "context" $) }}
ca.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "ca.crt" "defaultValue" $ca.Cert "context" $) }}
{{- end }}