16321b52c7
dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.
배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.
## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존
| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |
차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.
## 신규 추가 (5개)
infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.
longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.
## custom-values — 버전과 결합된 이미지 핀 정리
카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.
- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
`registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
(기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
넣지 않았다 — 소비 측에서 주입한다.
## 검증
12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).
## 범위에서 뺀 것
- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.
## 후속 과제
dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
563 lines
22 KiB
Smarty
563 lines
22 KiB
Smarty
{{/* vim: set filetype=mustache: */}}
|
|
{{/*
|
|
Expand the name of the chart.
|
|
*/}}
|
|
|
|
{{- define "gitea.name" -}}
|
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Create a default fully qualified app name.
|
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
If release name contains chart name it will be used as a full name.
|
|
*/}}
|
|
{{- define "gitea.fullname" -}}
|
|
{{- if .Values.fullnameOverride -}}
|
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
|
{{- else -}}
|
|
{{- $name := default .Chart.Name .Values.nameOverride -}}
|
|
{{- if contains $name .Release.Name -}}
|
|
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
|
{{- else -}}
|
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Create a default worker name.
|
|
*/}}
|
|
{{- define "gitea.workername" -}}
|
|
{{- printf "%s-%s" .global.Release.Name .worker | trunc 63 | trimSuffix "-" -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Create chart name and version as used by the chart label.
|
|
*/}}
|
|
{{- define "gitea.chart" -}}
|
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Create image name and tag used by the deployment.
|
|
*/}}
|
|
{{- define "gitea.image" -}}
|
|
{{- $fullOverride := .Values.image.fullOverride | default "" -}}
|
|
{{- $registry := .Values.global.imageRegistry | default .Values.image.registry -}}
|
|
{{- $repository := .Values.image.repository -}}
|
|
{{- $separator := ":" -}}
|
|
{{- $tag := .Values.image.tag | default .Chart.AppVersion | toString -}}
|
|
{{- $rootless := ternary "-rootless" "" (.Values.image.rootless) -}}
|
|
{{- $digest := "" -}}
|
|
{{- if .Values.image.digest }}
|
|
{{- $digest = (printf "@%s" (.Values.image.digest | toString)) -}}
|
|
{{- end -}}
|
|
{{- if $fullOverride }}
|
|
{{- printf "%s" $fullOverride -}}
|
|
{{- else if $registry }}
|
|
{{- printf "%s/%s%s%s%s%s" $registry $repository $separator $tag $rootless $digest -}}
|
|
{{- else -}}
|
|
{{- printf "%s%s%s%s%s" $repository $separator $tag $rootless $digest -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Docker Image Registry Secret Names evaluating values as templates
|
|
*/}}
|
|
{{- define "gitea.images.pullSecrets" -}}
|
|
{{- $pullSecrets := .Values.imagePullSecrets -}}
|
|
{{- range .Values.global.imagePullSecrets -}}
|
|
{{- $pullSecrets = append $pullSecrets (dict "name" .) -}}
|
|
{{- end -}}
|
|
{{- if (not (empty $pullSecrets)) }}
|
|
imagePullSecrets:
|
|
{{ toYaml $pullSecrets }}
|
|
{{- end }}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Return true when OpenShift compatibility defaults should be rendered.
|
|
If openshift.enabled is unset, auto-detect via the SCC API.
|
|
*/}}
|
|
{{- define "gitea.openshift.enabled" -}}
|
|
{{- if kindIs "bool" .Values.openshift.enabled -}}
|
|
{{ ternary "true" "false" .Values.openshift.enabled }}
|
|
{{- else if .Capabilities.APIVersions.Has "security.openshift.io/v1/SecurityContextConstraints" -}}
|
|
true
|
|
{{- else -}}
|
|
false
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Return the pod's hostUsers setting when OpenShift compatibility is enabled.
|
|
*/}}
|
|
{{- define "gitea.hostUsers" -}}
|
|
{{- if eq (include "gitea.openshift.enabled" . | trim) "true" -}}
|
|
{{- if kindIs "bool" .Values.openshift.hostUsers -}}
|
|
{{ ternary "true" "false" .Values.openshift.hostUsers }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Render pod securityContext. On non-OpenShift clusters an empty map defaults fsGroup to 1000.
|
|
*/}}
|
|
{{- define "gitea.podSecurityContext" -}}
|
|
{{- $podSecurityContext := deepCopy .Values.podSecurityContext -}}
|
|
{{- if and (ne (include "gitea.openshift.enabled" . | trim) "true") (not (hasKey $podSecurityContext "fsGroup")) -}}
|
|
{{- $_ := set $podSecurityContext "fsGroup" 1000 -}}
|
|
{{- end -}}
|
|
{{- if gt (len $podSecurityContext) 0 -}}
|
|
{{ toYaml $podSecurityContext }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Render container securityContext with OpenShift restricted SCC defaults when enabled.
|
|
*/}}
|
|
{{- define "gitea.containerSecurityContext" -}}
|
|
{{- $root := index . 0 -}}
|
|
{{- $containerSecurityContext := deepCopy (index . 1) -}}
|
|
{{- if eq (include "gitea.openshift.enabled" $root | trim) "true" -}}
|
|
{{- $containerSecurityContext = mergeOverwrite (dict
|
|
"allowPrivilegeEscalation" false
|
|
"capabilities" (dict "drop" (list "ALL"))
|
|
"runAsNonRoot" true
|
|
"seccompProfile" (dict "type" "RuntimeDefault")
|
|
) $containerSecurityContext -}}
|
|
{{- end -}}
|
|
{{- if gt (len $containerSecurityContext) 0 -}}
|
|
{{ toYaml $containerSecurityContext }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Render the securityContext for init containers that execute Gitea/GPG commands.
|
|
These default to runAsUser 1000 outside OpenShift to preserve existing behavior.
|
|
*/}}
|
|
{{- define "gitea.commandInitContainerSecurityContext" -}}
|
|
{{- $root := index . 0 -}}
|
|
{{- $containerSecurityContext := deepCopy (index . 1) -}}
|
|
{{- if and (ne (include "gitea.openshift.enabled" $root | trim) "true") (not (hasKey $containerSecurityContext "runAsUser")) -}}
|
|
{{- $_ := set $containerSecurityContext "runAsUser" 1000 -}}
|
|
{{- end -}}
|
|
{{- include "gitea.containerSecurityContext" (list $root $containerSecurityContext) -}}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Render the runtime container securityContext while honoring the deprecated securityContext value.
|
|
*/}}
|
|
{{- define "gitea.runtimeContainerSecurityContext" -}}
|
|
{{- $containerSecurityContext := deepCopy .Values.containerSecurityContext -}}
|
|
{{- if and (eq (len $containerSecurityContext) 0) .Values.securityContext -}}
|
|
{{- $containerSecurityContext = deepCopy .Values.securityContext -}}
|
|
{{- end -}}
|
|
{{- include "gitea.containerSecurityContext" (list . $containerSecurityContext) -}}
|
|
{{- end -}}
|
|
|
|
|
|
{{/*
|
|
Storage Class
|
|
*/}}
|
|
{{- define "gitea.persistence.storageClass" -}}
|
|
{{- $storageClass := (tpl ( default "" .Values.persistence.storageClass) .) | default (tpl ( default "" .Values.global.storageClass) .) }}
|
|
{{- if $storageClass }}
|
|
storageClassName: {{ $storageClass | quote }}
|
|
{{- end }}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Common labels
|
|
*/}}
|
|
{{- define "gitea.labels" -}}
|
|
helm.sh/chart: {{ include "gitea.chart" . }}
|
|
app: {{ include "gitea.name" . }}
|
|
{{ include "gitea.selectorLabels" . }}
|
|
app.kubernetes.io/version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
|
version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.labels.actRunner" -}}
|
|
helm.sh/chart: {{ include "gitea.chart" . }}
|
|
app: {{ include "gitea.name" . }}-act-runner
|
|
{{ include "gitea.selectorLabels.actRunner" . }}
|
|
app.kubernetes.io/version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
|
version: {{ .Values.image.tag | default .Chart.AppVersion | quote }}
|
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
{{- end -}}
|
|
|
|
{{/*
|
|
Selector labels
|
|
*/}}
|
|
{{- define "gitea.selectorLabels" -}}
|
|
app.kubernetes.io/name: {{ include "gitea.name" . }}
|
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.selectorLabels.actRunner" -}}
|
|
app.kubernetes.io/name: {{ include "gitea.name" . }}-act-runner
|
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
{{- end -}}
|
|
|
|
{{- define "postgresql-ha.dns" -}}
|
|
{{- if (index .Values "postgresql-ha").enabled -}}
|
|
{{- printf "%s-postgresql-ha-pgpool.%s.svc.%s:%g" .Release.Name .Release.Namespace .Values.clusterDomain (index .Values "postgresql-ha" "service" "ports" "postgresql") -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "postgresql.dns" -}}
|
|
{{- if (index .Values "postgresql").enabled -}}
|
|
{{- printf "%s-postgresql.%s.svc.%s:%g" .Release.Name .Release.Namespace .Values.clusterDomain .Values.postgresql.global.postgresql.service.ports.postgresql -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "valkey.dns" -}}
|
|
{{- if and ((index .Values "valkey-cluster").enabled) ((index .Values "valkey").enabled) -}}
|
|
{{- fail "valkey and valkey-cluster cannot be enabled at the same time. Please only choose one." -}}
|
|
{{- else if (index .Values "valkey-cluster").enabled -}}
|
|
{{- printf "redis+cluster://:%s@%s-valkey-cluster-headless.%s.svc.%s:%g/0?pool_size=100&idle_timeout=180s&" (index .Values "valkey-cluster").global.valkey.password .Release.Name .Release.Namespace .Values.clusterDomain (index .Values "valkey-cluster").service.ports.valkey -}}
|
|
{{- else if (index .Values "valkey").enabled -}}
|
|
{{- printf "redis://:%s@%s-valkey-primary.%s.svc.%s:%g/0?pool_size=100&idle_timeout=180s&" (index .Values "valkey").global.valkey.password .Release.Name .Release.Namespace .Values.clusterDomain (index .Values "valkey").master.service.ports.valkey -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "valkey.port" -}}
|
|
{{- if (index .Values "valkey-cluster").enabled -}}
|
|
{{ (index .Values "valkey-cluster").service.ports.valkey }}
|
|
{{- else if (index .Values "valkey").enabled -}}
|
|
{{ (index .Values "valkey").master.service.ports.valkey }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "valkey.servicename" -}}
|
|
{{- if (index .Values "valkey-cluster").enabled -}}
|
|
{{- printf "%s-valkey-cluster-headless.%s.svc" .Release.Name .Release.Namespace -}}
|
|
{{- else if (index .Values "valkey").enabled -}}
|
|
{{- printf "%s-valkey-primary.%s.svc" .Release.Name .Release.Namespace -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.default_domain" -}}
|
|
{{- printf "%s-http.%s.svc.%s" (include "gitea.fullname" .) .Release.Namespace .Values.clusterDomain -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.public_hostname" -}}
|
|
{{- if and .Values.route.enabled .Values.route.host -}}
|
|
{{ tpl .Values.route.host . }}
|
|
{{- else if gt (len .Values.ingress.hosts) 0 -}}
|
|
{{ tpl (index .Values.ingress.hosts 0).host $ }}
|
|
{{- else -}}
|
|
{{ include "gitea.default_domain" . }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.ldap_settings" -}}
|
|
{{- $idx := index . 0 }}
|
|
{{- $values := index . 1 }}
|
|
|
|
{{- if not (hasKey $values "bindDn") -}}
|
|
{{- $_ := set $values "bindDn" "" -}}
|
|
{{- end -}}
|
|
|
|
{{- if not (hasKey $values "bindPassword") -}}
|
|
{{- $_ := set $values "bindPassword" "" -}}
|
|
{{- end -}}
|
|
|
|
{{- $flags := list "notActive" "skipTlsVerify" "allowDeactivateAll" "synchronizeUsers" "attributesInBind" -}}
|
|
{{- range $key, $val := $values -}}
|
|
{{- if and (ne $key "enabled") (ne $key "existingSecret") -}}
|
|
{{- if eq $key "bindDn" -}}
|
|
{{- printf "--%s \"${GITEA_LDAP_BIND_DN_%d}\" " ($key | kebabcase) ($idx) -}}
|
|
{{- else if eq $key "bindPassword" -}}
|
|
{{- printf "--%s \"${GITEA_LDAP_PASSWORD_%d}\" " ($key | kebabcase) ($idx) -}}
|
|
{{- else if eq $key "port" -}}
|
|
{{- printf "--%s %d " $key ($val | int) -}}
|
|
{{- else if has $key $flags -}}
|
|
{{- printf "--%s " ($key | kebabcase) -}}
|
|
{{- else -}}
|
|
{{- printf "--%s %s " ($key | kebabcase) ($val | squote) -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.oauth_settings" -}}
|
|
{{- $idx := index . 0 }}
|
|
{{- $values := index . 1 }}
|
|
|
|
{{- if not (hasKey $values "key") -}}
|
|
{{- $_ := set $values "key" (printf "${GITEA_OAUTH_KEY_%d}" $idx) -}}
|
|
{{- end -}}
|
|
|
|
{{- if not (hasKey $values "secret") -}}
|
|
{{- $_ := set $values "secret" (printf "${GITEA_OAUTH_SECRET_%d}" $idx) -}}
|
|
{{- end -}}
|
|
|
|
{{- range $key, $val := $values -}}
|
|
{{- if ne $key "existingSecret" -}}
|
|
{{- printf "--%s %s " ($key | kebabcase) ($val | quote) -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.public_protocol" -}}
|
|
{{- if and .Values.route.enabled .Values.route.tls.termination -}}
|
|
https
|
|
{{- else if and .Values.ingress.enabled (gt (len .Values.ingress.tls) 0) -}}
|
|
https
|
|
{{- else -}}
|
|
{{ .Values.gitea.config.server.PROTOCOL }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.inline_configuration" -}}
|
|
{{- include "gitea.inline_configuration.init" . -}}
|
|
{{- include "gitea.inline_configuration.defaults" . -}}
|
|
|
|
{{- $generals := list -}}
|
|
{{- $inlines := dict -}}
|
|
|
|
{{- range $key, $value := .Values.gitea.config }}
|
|
{{- if kindIs "map" $value }}
|
|
{{- if gt (len $value) 0 }}
|
|
{{- $section := default list (get $inlines $key) -}}
|
|
{{- range $n_key, $n_value := $value }}
|
|
{{- $section = append $section (printf "%s=%v" $n_key $n_value) -}}
|
|
{{- end }}
|
|
{{- $_ := set $inlines $key (join "\n" $section) -}}
|
|
{{- end -}}
|
|
{{- else }}
|
|
{{- if or (eq $key "APP_NAME") (eq $key "RUN_USER") (eq $key "RUN_MODE") -}}
|
|
{{- $generals = append $generals (printf "%s=%s" $key $value) -}}
|
|
{{- else -}}
|
|
{{- (printf "Key %s cannot be on top level of configuration" $key) | fail -}}
|
|
{{- end -}}
|
|
|
|
{{- end }}
|
|
{{- end }}
|
|
|
|
{{- $_ := set $inlines "_generals_" (join "\n" $generals) -}}
|
|
{{- toYaml $inlines -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.inline_configuration.init" -}}
|
|
{{- if not (hasKey .Values.gitea.config "cache") -}}
|
|
{{- $_ := set .Values.gitea.config "cache" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "server") -}}
|
|
{{- $_ := set .Values.gitea.config "server" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "metrics") -}}
|
|
{{- $_ := set .Values.gitea.config "metrics" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "database") -}}
|
|
{{- $_ := set .Values.gitea.config "database" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "security") -}}
|
|
{{- $_ := set .Values.gitea.config "security" dict -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.repository -}}
|
|
{{- $_ := set .Values.gitea.config "repository" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "oauth2") -}}
|
|
{{- $_ := set .Values.gitea.config "oauth2" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "session") -}}
|
|
{{- $_ := set .Values.gitea.config "session" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "queue") -}}
|
|
{{- $_ := set .Values.gitea.config "queue" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "queue.issue_indexer") -}}
|
|
{{- $_ := set .Values.gitea.config "queue.issue_indexer" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "indexer") -}}
|
|
{{- $_ := set .Values.gitea.config "indexer" dict -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config "actions") -}}
|
|
{{- $_ := set .Values.gitea.config "actions" dict -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.inline_configuration.defaults" -}}
|
|
{{- include "gitea.inline_configuration.defaults.server" . -}}
|
|
{{- include "gitea.inline_configuration.defaults.database" . -}}
|
|
|
|
{{- if not .Values.gitea.config.repository.ROOT -}}
|
|
{{- $_ := set .Values.gitea.config.repository "ROOT" "/data/git/gitea-repositories" -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.security.INSTALL_LOCK -}}
|
|
{{- $_ := set .Values.gitea.config.security "INSTALL_LOCK" "true" -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config.metrics "ENABLED") -}}
|
|
{{- $_ := set .Values.gitea.config.metrics "ENABLED" .Values.gitea.metrics.enabled -}}
|
|
{{- end -}}
|
|
{{- if and (not (hasKey .Values.gitea.config.metrics "TOKEN")) (.Values.gitea.metrics.token) (.Values.gitea.metrics.enabled) -}}
|
|
{{- $_ := set .Values.gitea.config.metrics "TOKEN" .Values.gitea.metrics.token -}}
|
|
{{- end -}}
|
|
{{- /* valkey queue */ -}}
|
|
{{- if or ((index .Values "valkey-cluster").enabled) ((index .Values "valkey").enabled) -}}
|
|
{{- $_ := set .Values.gitea.config.queue "TYPE" "redis" -}}
|
|
{{- $_ := set .Values.gitea.config.queue "CONN_STR" (include "valkey.dns" .) -}}
|
|
{{- $_ := set .Values.gitea.config.session "PROVIDER" "redis" -}}
|
|
{{- $_ := set .Values.gitea.config.session "PROVIDER_CONFIG" (include "valkey.dns" .) -}}
|
|
{{- $_ := set .Values.gitea.config.cache "ADAPTER" "redis" -}}
|
|
{{- $_ := set .Values.gitea.config.cache "HOST" (include "valkey.dns" .) -}}
|
|
{{- else -}}
|
|
{{- if not (get .Values.gitea.config.session "PROVIDER") -}}
|
|
{{- $_ := set .Values.gitea.config.session "PROVIDER" "memory" -}}
|
|
{{- end -}}
|
|
{{- if not (get .Values.gitea.config.session "PROVIDER_CONFIG") -}}
|
|
{{- $_ := set .Values.gitea.config.session "PROVIDER_CONFIG" "" -}}
|
|
{{- end -}}
|
|
{{- if not (get .Values.gitea.config.queue "TYPE") -}}
|
|
{{- $_ := set .Values.gitea.config.queue "TYPE" "level" -}}
|
|
{{- end -}}
|
|
{{- if not (get .Values.gitea.config.queue "CONN_STR") -}}
|
|
{{- $_ := set .Values.gitea.config.queue "CONN_STR" "" -}}
|
|
{{- end -}}
|
|
{{- if not (get .Values.gitea.config.cache "ADAPTER") -}}
|
|
{{- $_ := set .Values.gitea.config.cache "ADAPTER" "memory" -}}
|
|
{{- end -}}
|
|
{{- if not (get .Values.gitea.config.cache "HOST") -}}
|
|
{{- $_ := set .Values.gitea.config.cache "HOST" "" -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.indexer.ISSUE_INDEXER_TYPE -}}
|
|
{{- $_ := set .Values.gitea.config.indexer "ISSUE_INDEXER_TYPE" "db" -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.inline_configuration.defaults.server" -}}
|
|
{{- if not (hasKey .Values.gitea.config.server "HTTP_PORT") -}}
|
|
{{- $_ := set .Values.gitea.config.server "HTTP_PORT" .Values.service.http.port -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.server.PROTOCOL -}}
|
|
{{- $_ := set .Values.gitea.config.server "PROTOCOL" "http" -}}
|
|
{{- end -}}
|
|
{{- if not (.Values.gitea.config.server.DOMAIN) -}}
|
|
{{- $_ := set .Values.gitea.config.server "DOMAIN" (include "gitea.public_hostname" .) -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.server.ROOT_URL -}}
|
|
{{- $_ := set .Values.gitea.config.server "ROOT_URL" (printf "%s://%s" (include "gitea.public_protocol" .) .Values.gitea.config.server.DOMAIN) -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.server.SSH_DOMAIN -}}
|
|
{{- $_ := set .Values.gitea.config.server "SSH_DOMAIN" .Values.gitea.config.server.DOMAIN -}}
|
|
{{- end -}}
|
|
{{- if not .Values.gitea.config.server.SSH_PORT -}}
|
|
{{- $_ := set .Values.gitea.config.server "SSH_PORT" .Values.service.ssh.port -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config.server "START_SSH_SERVER") -}}
|
|
{{- if .Values.image.rootless -}}
|
|
{{- $_ := set .Values.gitea.config.server "START_SSH_SERVER" "true" -}}
|
|
{{- if not (hasKey .Values.gitea.config.server "SSH_LISTEN_PORT") -}}
|
|
{{- if not .Values.gitea.config.server.SSH_LISTEN_PORT -}}
|
|
{{- $_ := set .Values.gitea.config.server "SSH_LISTEN_PORT" .Values.gitea.config.server.SSH_PORT -}}
|
|
{{- else -}}
|
|
{{- $_ := set .Values.gitea.config.server "SSH_LISTEN_PORT" .Values.gitea.config.server.SSH_LISTEN_PORT -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- else -}}
|
|
{{- $_ := set .Values.gitea.config.server "START_SSH_SERVER" "false" -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config.server "APP_DATA_PATH") -}}
|
|
{{- $_ := set .Values.gitea.config.server "APP_DATA_PATH" "/data" -}}
|
|
{{- end -}}
|
|
{{- if not (hasKey .Values.gitea.config.server "ENABLE_PPROF") -}}
|
|
{{- $_ := set .Values.gitea.config.server "ENABLE_PPROF" false -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.inline_configuration.defaults.database" -}}
|
|
{{- if (index .Values "postgresql-ha" "enabled") -}}
|
|
{{- $_ := set .Values.gitea.config.database "DB_TYPE" "postgres" -}}
|
|
{{- if not (.Values.gitea.config.database.HOST) -}}
|
|
{{- $_ := set .Values.gitea.config.database "HOST" (include "postgresql-ha.dns" .) -}}
|
|
{{- end -}}
|
|
{{- $_ := set .Values.gitea.config.database "NAME" (index .Values "postgresql-ha" "global" "postgresql" "database") -}}
|
|
{{- $_ := set .Values.gitea.config.database "USER" (index .Values "postgresql-ha" "global" "postgresql" "username") -}}
|
|
{{- $_ := set .Values.gitea.config.database "PASSWD" (index .Values "postgresql-ha" "global" "postgresql" "password") -}}
|
|
{{- end -}}
|
|
{{- if (index .Values "postgresql" "enabled") -}}
|
|
{{- $_ := set .Values.gitea.config.database "DB_TYPE" "postgres" -}}
|
|
{{- if not (.Values.gitea.config.database.HOST) -}}
|
|
{{- $_ := set .Values.gitea.config.database "HOST" (include "postgresql.dns" .) -}}
|
|
{{- end -}}
|
|
{{- $_ := set .Values.gitea.config.database "NAME" .Values.postgresql.global.postgresql.auth.database -}}
|
|
{{- $_ := set .Values.gitea.config.database "USER" .Values.postgresql.global.postgresql.auth.username -}}
|
|
{{- $_ := set .Values.gitea.config.database "PASSWD" .Values.postgresql.global.postgresql.auth.password -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.init-additional-mounts" -}}
|
|
{{- /* Honor the deprecated extraVolumeMounts variable when defined */ -}}
|
|
{{- if gt (len .Values.extraInitVolumeMounts) 0 -}}
|
|
{{- toYaml .Values.extraInitVolumeMounts -}}
|
|
{{- else if gt (len .Values.extraVolumeMounts) 0 -}}
|
|
{{- toYaml .Values.extraVolumeMounts -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.container-additional-mounts" -}}
|
|
{{- /* Honor the deprecated extraVolumeMounts variable when defined */ -}}
|
|
{{- if gt (len .Values.extraContainerVolumeMounts) 0 -}}
|
|
{{- toYaml .Values.extraContainerVolumeMounts -}}
|
|
{{- else if gt (len .Values.extraVolumeMounts) 0 -}}
|
|
{{- toYaml .Values.extraVolumeMounts -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.gpg-key-secret-name" -}}
|
|
{{ default (printf "%s-gpg-key" (include "gitea.fullname" .)) .Values.signing.existingSecret }}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.serviceAccountName" -}}
|
|
{{ .Values.serviceAccount.name | default (include "gitea.fullname" .) }}
|
|
{{- end -}}
|
|
|
|
{{- define "ingress.annotations" -}}
|
|
{{- if .Values.ingress.annotations }}
|
|
annotations:
|
|
{{- $tp := typeOf .Values.ingress.annotations }}
|
|
{{- if eq $tp "string" }}
|
|
{{- tpl .Values.ingress.annotations . | nindent 4 }}
|
|
{{- else }}
|
|
{{- toYaml .Values.ingress.annotations | nindent 4 }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.admin.passwordMode" -}}
|
|
{{- if has .Values.gitea.admin.passwordMode (tuple "keepUpdated" "initialOnlyNoReset" "initialOnlyRequireReset") -}}
|
|
{{ .Values.gitea.admin.passwordMode }}
|
|
{{- else -}}
|
|
{{ printf "gitea.admin.passwordMode must be set to one of 'keepUpdated', 'initialOnlyNoReset', or 'initialOnlyRequireReset'. Received: '%s'" .Values.gitea.admin.passwordMode | fail }}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
|
|
{{/* Create a functioning probe object for rendering. Given argument must be either a livenessProbe, readinessProbe, or startupProbe */}}
|
|
{{- define "gitea.deployment.probe" -}}
|
|
{{- $probe := unset . "enabled" -}}
|
|
{{- $probeKeys := keys $probe -}}
|
|
{{- $containsCustomMethod := false -}}
|
|
{{- $chartDefaultMethod := "tcpSocket" -}}
|
|
{{- $nonChartDefaultMethods := list "exec" "httpGet" "grpc" -}}
|
|
{{- range $probeKeys -}}
|
|
{{- if has . $nonChartDefaultMethods -}}
|
|
{{- $containsCustomMethod = true -}}
|
|
{{- end -}}
|
|
{{- end -}}
|
|
{{- if $containsCustomMethod -}}
|
|
{{- $probe = unset . $chartDefaultMethod -}}
|
|
{{- end -}}
|
|
{{- toYaml $probe -}}
|
|
{{- end -}}
|
|
|
|
{{- define "gitea.metrics-secret-name" -}}
|
|
{{ default (printf "%s-metrics-secret" (include "gitea.fullname" .)) }}
|
|
{{- end -}}
|