fae1ec2668
breaking_change_check 결과 breaking=false — custom-values.yaml이 실제로 쓰는 키 (image, http.relativePath, command, ingress, proxy, resources, database, extraEnv) 중 어느 것도 diff에 걸리지 않았다. 유일한 템플릿 변경(probe 경로가 managementRelativePath를 coalesce로 우선하도록 바뀜)도 relativePath: "/" 를 그대로 쓰므로 동작 영향이 없다. CRD·의존성 변경 없음. appVersion은 26.6.4→26.7.2로 오르지만 custom-values.yaml이 자체 빌드 이미지 태그(26.7.1-bci15.7-hardened)를 명시적으로 고정하므로 이 업그레이드로 실제 배포 버전이 바뀌지는 않는다 — 26.7.2로 올리려면 hardened-containers에서 별도로 자체 빌드해야 한다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
117 lines
3.3 KiB
YAML
117 lines
3.3 KiB
YAML
{{- $ingress := .Values.ingress -}}
|
|
{{- if $ingress.enabled -}}
|
|
{{- $apiVersion := "networking.k8s.io/v1" -}}
|
|
{{- $fullName := ( include "keycloak.fullname" . ) -}}
|
|
apiVersion: {{ $apiVersion }}
|
|
kind: Ingress
|
|
metadata:
|
|
name: {{ $fullName }}
|
|
namespace: {{ include "keycloak.namespace" . }}
|
|
{{- with $ingress.annotations }}
|
|
annotations:
|
|
{{- range $key, $value := . }}
|
|
{{- printf "%s: %s" $key (tpl $value $ | quote) | nindent 4 }}
|
|
{{- end }}
|
|
{{- end }}
|
|
labels:
|
|
{{- include "keycloak.labels" . | nindent 4 }}
|
|
{{- range $key, $value := $ingress.labels }}
|
|
{{- printf "%s: %s" $key (tpl $value $ | quote) | nindent 4 }}
|
|
{{- end }}
|
|
spec:
|
|
{{- if $ingress.ingressClassName }}
|
|
ingressClassName: {{ $ingress.ingressClassName }}
|
|
{{- end }}
|
|
{{- if $ingress.tls }}
|
|
tls:
|
|
{{- range $ingress.tls }}
|
|
- hosts:
|
|
{{- range .hosts }}
|
|
- {{ tpl . $ | quote }}
|
|
{{- end }}
|
|
{{- with .secretName }}
|
|
secretName: {{ tpl . $ }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
rules:
|
|
{{- range .Values.ingress.rules }}
|
|
- host: {{ tpl .host $ | quote }}
|
|
http:
|
|
paths:
|
|
{{- range .paths }}
|
|
- path: {{ tpl .path $ | quote }}
|
|
pathType: {{ .pathType }}
|
|
backend:
|
|
service:
|
|
name: {{ default (printf "%s-http" $fullName) (.serviceName) }}
|
|
port:
|
|
name: {{ default ($ingress.servicePort) (.servicePort) }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- if $ingress.console.enabled }}
|
|
---
|
|
apiVersion: {{ $apiVersion }}
|
|
kind: Ingress
|
|
metadata:
|
|
name: {{ $fullName }}-console
|
|
namespace: {{ include "keycloak.namespace" . }}
|
|
{{- with $ingress.console.annotations }}
|
|
annotations:
|
|
{{- range $key, $value := . }}
|
|
{{- printf "%s: %s" $key (tpl $value $ | quote) | nindent 4 }}
|
|
{{- end }}
|
|
{{- end }}
|
|
labels:
|
|
{{- include "keycloak.labels" . | nindent 4 }}
|
|
{{- range $key, $value := $ingress.labels }}
|
|
{{- printf "%s: %s" $key (tpl $value $ | quote) | nindent 4 }}
|
|
{{- end }}
|
|
{{- range $key, $value := $ingress.console.labels }}
|
|
{{- printf "%s: %s" $key (tpl $value $ | quote) | nindent 4 }}
|
|
{{- end }}
|
|
spec:
|
|
{{- if $ingress.console.ingressClassName }}
|
|
ingressClassName: {{ $ingress.console.ingressClassName }}
|
|
{{- end }}
|
|
{{- if $ingress.console.tls }}
|
|
tls:
|
|
{{- range $ingress.console.tls }}
|
|
- hosts:
|
|
{{- range .hosts }}
|
|
- {{ tpl . $ | quote }}
|
|
{{- end }}
|
|
{{- with .secretName }}
|
|
secretName: {{ tpl . $ }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{ else if $ingress.tls }}
|
|
tls:
|
|
{{- range $ingress.tls }}
|
|
- hosts:
|
|
{{- range .hosts }}
|
|
- {{ tpl . $ | quote }}
|
|
{{- end }}
|
|
{{- with .secretName }}
|
|
secretName: {{ tpl . $ }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
rules:
|
|
{{- range .Values.ingress.console.rules }}
|
|
- host: {{ tpl .host $ | quote }}
|
|
http:
|
|
paths:
|
|
{{- range .paths }}
|
|
- path: {{ tpl .path $ | quote }}
|
|
pathType: {{ .pathType }}
|
|
backend:
|
|
service:
|
|
name: {{ default (printf "%s-http" $fullName) (.serviceName) }}
|
|
port:
|
|
name: {{ default ($ingress.servicePort) (.servicePort) }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end -}}
|
|
{{- end -}}
|