diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..8d89461 --- /dev/null +++ b/.gitignore @@ -0,0 +1,2 @@ +charts +Chart.lock diff --git a/.helmignore b/.helmignore new file mode 100644 index 0000000..7449b68 --- /dev/null +++ b/.helmignore @@ -0,0 +1,24 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +#charts/ +#Chart.lock diff --git a/Chart.lock b/Chart.lock deleted file mode 100644 index 11715b1..0000000 --- a/Chart.lock +++ /dev/null @@ -1,6 +0,0 @@ -dependencies: -- name: mariadb - repository: https://charts.bitnami.com - version: 7.3.0 -digest: sha256:eac0df60131cc9aa4784d84693592d56c9f12ddf8272881b66c2cdcf34e305d7 -generated: "2019-12-09T16:07:28.17872647-05:00" diff --git a/Chart.yaml b/Chart.yaml index be9770d..c9578b0 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -1,9 +1,11 @@ -name: gitea -version: 1.3.3 apiVersion: v2 -appVersion: 1.12.2 -description: Git with a cup of tea +name: gitea +description: Gitea Helm chart for Kubernetes +type: application +version: 1.4.1 +appVersion: 1.12.3 icon: https://docs.gitea.io/images/gitea.png + keywords: - git - issue tracker @@ -19,3 +21,21 @@ maintainers: email: charlie@charliedrage.com - name: Gitea Authors email: maintainers@gitea.io + - name: Konrad Lother + email: konrad.lother@novum-rgi.de + - name: Lucas Hahn + email: lucas.hahn@novum-rgi.de + +dependencies: +- name: memcached + repository: https://charts.bitnami.com/bitnami + version: 4.2.20 + condition: gitea.cache.enabled +- name: mysql + repository: https://charts.bitnami.com/bitnami + version: 6.14.8 + condition: gitea.database.builtIn.mysql.enabled +- name: postgresql + repository: https://charts.bitnami.com/bitnami + version: 8.6.4 + condition: gitea.database.builtIn.postgresql.enabled diff --git a/LICENSE b/LICENSE index 006bc99..bbf54de 100644 --- a/LICENSE +++ b/LICENSE @@ -1,6 +1,7 @@ MIT License Copyright (c) 2020 The Gitea Authors +Copyright (c) 2020 NOVUM-RGI Copyright (c) 2019 - 2020 Charlie Drage Copyright (c) 2018 John Felten diff --git a/README.md b/README.md index 2c6efad..cd83886 100644 --- a/README.md +++ b/README.md @@ -1,189 +1,249 @@ -# Gitea +# Gitea Helm Chart -[Gitea](https://gitea.com/) is a lightweight GitHub clone. This is for those who wish to self host their own git repos on kubernetes. +[Gitea](https://gitea.io/en-us/) is a community managed lightweight code hosting solution written in Go. It is published under the MIT license. -This chart is based upon the work done by [@jfelten](https://github.com/jfelten/gitea-helm-chart) - -## TLDR - -```sh -helm repo add k8s-land https://charts.k8s.land -helm install gitea k8s-land/gitea -``` +Readme will be updated with examples in the next few days ## Introduction -This chart bootstraps both [Gitea](http://gitea.com) and MariaDB. +This helm chart has taken some inspiration from https://github.com/jfelten/gitea-helm-chart +But takes a completly different approach in providing database and cache with dependencies. +Also this chart provides ldap and admin user configuration with values as well as it is deployed as statefulset to retain stored repositories. -In this chart, the following are ran: - - Gitea - - Memcached - - Mariadb +## Dependencies + +Gitea can be run with external database and cache. This chart provides those dependencies, which can be +enabled, or disabled via [configuration](#configuration). + +Dependencies: + +* Postgresql +* Memcached +* Mysql + +## Installing + +``` + helm repo add novum-rgi-helm https://novumrgi.github.io/helm/ + helm install gitea novum-rgi-helm/gitea +``` ## Prerequisites -- Kubernetes 1.12+ -- Helm 3.0+ -- PV provisioner for persistent data support +* Kubernetes 1.12+ +* Helm 3.0+ +* PV provisioner for persistent data support -## Installing the Chart +## Examples -By default, we use ingress to expose the service. +### Gitea Configuration -To install WITHOUT persistent storage / development: - -```bash -helm repo add k8s-land https://charts.k8s.land -helm install gitea k8s-land/gitea -``` - -For production / installing with persistent data: - -```sh -helm show values k8s-land/gitea > values.yaml -vim values.yaml # Edit to enable persistent storage -helm install gitea k8s-land/gitea -f values.yaml -``` - -### Database Configuration - -By default, we will launch a Mariadb database: +Gitea offers lots of configuration. This is fully described in the [Gitea Cheat Sheet](https://docs.gitea.io/en-us/config-cheat-sheet/). ```yaml -mariadb: - enabled: true + gitea: + config: + APP_NAME: "Gitea: With a cup of tea." + repository: + ROOT: "~/gitea-repositories" + repository.pull-request: + WORK_IN_PROGRESS_PREFIXES: "WIP:,[WIP]:" ``` -To use an external database, disable the in-pod database and fill in the "externalDB" values: +### Ports and external url + +By default port 3000 is used for web traffic and 22 for ssh. Those can be changed: ```yaml -mariadb: - enabled: false - -#Connect to an external database - externalDB: - dbUser: "postgres" - dbPassword: "" - dbHost: "db-service-name.namespace.svc.cluster.local" # or some external host - dbPort: "5432" - dbDatabase: "gitea" + service: + http: + port: 3000 + ssh: + port: 22 ``` -## Persistent Data +This helmchart automatically configures the clone urls to use the correct ports. You can change these ports by hand using the gitea.config dict. However you should know what you're doing. -By default, persistent data is not enabled and thus you'll have to enable it from within the `values.yaml`. +### Cache -Unless otherwise set to true, data will be deleted when the Pod is restarted. - -To prevent data loss, we will enable persistent data. - -First, enable persistency: +This helm chart can use a built in cache. The default is memcached from bitnami. ```yaml -persistence: - enabled: true + gitea: + cache: + builtIn: + enabled: true ``` - -If you wish for helm **NOT** to replace data when re-deploying (updating the chart), add the `resource-policy` annotation: +If the built in cache should not be used simply configure the cache in gitea.config ```yaml -persistence: - annotations: - "helm.sh/resource-policy": keep + gitea: + config: + cache: + ENABLED: true + ADAPTER: memory + INTERVAL: 60 + HOST: 127.0.0.1:9090 ``` +### Persistence -To use a previously created PVC / volume, use the following: +Gitea will be deployed as a statefulset. By simply enabling the persistence and setting the storage class according to your cluster +everything else will be taken care of. The following example will create a PVC as a part of the statefulset. This PVC will not be deleted +even if you uninstall the chart. +When using Postgresql as dependency, this will also be deployed as a statefulset by default. + +If you want to manage your own PVC you can simply pass the PVC name to the chart. ```yaml - existingGiteaClaim: gitea-gitea + persistence: + enabled: true + existingClaim: MyAwesomeGiteaClaim ``` -## Ingress And External Host/Ports +In case that peristence has been disabled it will simply use an empty dir volume. -Gitea requires ports to be exposed for accessibility. The recommended way is using **ingress**, however, you can supply `LoadBalancer` to your values alternatively. - -By default, we expose via an ingress: - -To expose via an ingress: +Postgresql handles the persistence in the exact same way. +You can interact with the postgres settings as displayed in the following example: ```yaml -ingress: - enabled: true + postgresql: + persistence: + enabled: true + existingClaim: MyAwesomeGiteaPostgresClaim ``` -To expose the web application this chart will generate an ingress using the ingress controller of choice if specified. If an ingress is enabled services.http.externalHost must be specified. To expose SSH services it relies on either a LoadBalancer or NodePort. +Mysql also handles persistence the same, even though it is not deployed as a statefulset. +You can interact with the postgres settings as displayed in the following example: -## Upgrading +```yaml + mysql: + persistence: + enabled: true + existingClaim: MyAwesomeGiteaMysqlClaim +``` -When upgrading, make sure you have the following enabled: +### Admin User - - Persistency for both mariadb + Gitea - - Using `existingGiteaClaim` - - Due to using the [bitnami/mariadb](https://github.com/helm/charts/tree/master/stable/mariadb) chart, make sure to HARDCODE your passwords within `values.yaml`. Or else you'll be unable to update mariadb +This chart enables you to create a default admin user. It is also possible to update the password for this user by upgrading or redeloying the chart. +It is not possible to delete an admin user after it has been created. This has to be done in the ui. + +```yaml + gitea: + admin: + username: "MyAwesomeGiteaAdmin" + password: "AReallyAwesomeGiteaPassword" + email: "gi@tea.com" +``` + +### LDAP Settings + +Like the admin user the ldap settings can be updated but also disabled or deleted. + +```yaml + gitea: + ldap: + enabled: true + name: 'MyAwesomeGiteaLdap' + securityProtocol: unencrypted + host: "127.0.0.1" + port: "389" + userSearchBase: ou=Users,dc=example,dc=com + userFilter: sAMAccountName=%s + adminFilter: CN=Admin,CN=Group,DC=example,DC=com + emailAttribute: mail + bindDn: CN=ldap read,OU=Spezial,DC=example,DC=com + bindPassword: JustAnotherBindPw + usernameAttribute: CN +``` ## Configuration -Refer to [values.yaml](values.yaml) for the full run-down on defaults. +### Others -The following table lists the configurable parameters of this chart and their default values. +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|statefulset.terminationGracePeriodSeconds| Image to start for this pod | gitea/gitea | -| Parameter | Description | Default | -|---------------------------------------|------------------------------------------------------------------------------------------------------------------------------|---------------------------| -| `images.gitea` | `gitea` image | `gitea/gitea:1.9.3` | -| `images.memcached` | `memcached` image | `memcached:1.5.19-alpine` | -| `images.pullPolicy` | Image pull policy | `IfNotPresent` | -| `images.pullSecrets` | Specify an array of pull secrets | `[]` | -| `memcached.maxItemMemory` | Max item memory | `64` | -| `memcached.verbosity` | Verbosity | `v` | -| `memcached.extendedOptions` | Extended options for memcached | `modern` | -| `ingress.enabled` | Switch to create ingress for this chart deployment | `true` | -| `ingress.hostname ` | Hostname to be used for the ingress | `gitea.local` | -| `ingress.certManager` | Asks if we want to use cert-manager or not (let's encrypt, etc.) | `true` | -| `ingress.annotations` | Annotations used by the ingress | `[]` | -| `ingress.hosts ` | Additional hosts to be used by the ingress | `[]` | -| `ingress.tls ` | TLS secret keys to be used with Gitea | `[]` | -| `service.http.serviceType` | type of kubernetes services used for http i.e. ClusterIP, NodePort or LoadBalancer | `ClusterIP` | -| `service.http.port` | http port for web traffic | `3000` | -| `service.http.NodePort` | Manual NodePort for web traffic | `nil` | -| `service.http.externalPort` | Port exposed on the internet by a load balancer or firewall that redirects to the ingress or NodePort | `8280` | -| `service.http.externalHost` | IP or DNS name exposed on the internet by a load balancer or firewall that redirects to the ingress or Node for http traffic | `gitea.local` | -| `service.ssh.serviceType` | type of kubernetes services used for ssh i.e. ClusterIP, NodePort or LoadBalancer | `ClusterIP` | -| `service.ssh.port` | http port for web traffic | `22` | -| `service.ssh.NodePort` | Manual NodePort for ssh traffic | `nil` | -| `service.ssh.externalPort` | Port exposed on the internet by a load balancer or firewall that redirects to the ingress or NodePort | `nil` | -| `service.ssh.externalHost` | IP or DNS name exposed on the internet by a load balancer or firewall that redirects to the ingress or Node for http traffic | `gitea.local` | -| `resources.gitea.requests.memory` | gitea container memory request | `500Mi` | -| `resources.gitea.requests.cpu` | gitea container request cpu | `1000m` | -| `resources.gitea.limits.memory` | gitea container memory limits | `2Gi` | -| `resources.gitea.limits.cpu` | gitea container CPU/Memory resource requests/limits | `1` | -| `resources.memcached.requests.memory` | memcached container memory request | `64Mi` | -| `resources.memcached.requests.cpu` | memcached container request cpu | `50m` | -| `persistence.enabled` | Create PVCs to store gitea data | `false` | -| `persistence.existingGiteaClaim` | Already existing PVC that should be used for gitea data. | `nil` | -| `persistence.giteaSize` | Size of gitea pvc to create | `10Gi` | -| `persistence.annotations` | Annotations to set on created PVCs | `nil` | -| `persistence.storageClass` | StorageClass to use for dynamic provision if not 'default' | `nil` | -| `podAnnotations` | Annotations to set on the pod | `{}` | -| `mariadb.enabled` | Enable or diable mariadb | `true` | -| `mariadb.replication.enabled` | Enable or diable replication | `false` | -| `mariadb.db.name` | Default name | `gitea` | -| `mariadb.db.user` | Default user | `gitea` | -| `mariadb.persistence.enabled` | Enable or diable persistence | `true` | -| `mariadb.persistence.accessMode` | What access mode to use | `ReadWriteOnce` | -| `mariadb.persistence.size` | What size of database to use | `8Gi` | -| `externalDB.dbUser` | external db user | ` unset` | -| `externalDB.dbPassword` | external db password | ` unset` | -| `externalDB.dbHost` | external db host | ` unset` | -| `externalDB.dbPort` | external db port | ` unset` | -| `externalDB.dbDatabase` | external db database name | ` unset` | -| `config.disableInstaller` | Disable the installer | `false` | -| `config.offlineMode` | Sets Gitea's Offline Mode. Values are `true` or `false`. | `false` | -| `config.requireSignin` | Require Gitea user to be signed in to see any pages. Values are `true` or `false`. | `false` | -| `config.disableRegistration` | Disable Gitea's user registration. Values are `true` or `false`. | `false` | -| `config.openidSignin` | Allow login with OpenID. Values are `true` or `false`. | `true` | -| `nodeSelector` | Node to be selected | `{}` | -| `affinity` | Affinity settings for pod assignment | `{}` | -| `tolerations` | Toleration labels for pod assignment | `[]` | -| `deploymentAnnotations` | Deployment annotations to be used | `{}` | -| `podAnnotations` | Pod deployment annotations to be used | `{}` | + +### Image + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|image.repository| Image to start for this pod | gitea/gitea | +|image.version| Image Version | 1.12.2 | +|image.pullPolicy| Image pull policy | Always | + +### Persistence + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|persistence.enabled| Enable persistence for Gitea |true| +|persistence.existingClaim| Use an existing claim to store repository information | | +|persistence.size| Size for persistence to store repo information | 10Gi | +|persistence.accessModes|AccessMode for persistence|| +|persistence.storageClass|Storage class for repository persistence|standard| + +### Ingress + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|ingress.enabled| enable ingress | false| +|ingress.annotations| add ingress annotations | | +|ingress.hosts| add hosts for ingress as string list | git.example.com | +|ingress.tls|add ingress tls settings|[]| + +### Service + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|service.http.type| Kubernetes service type for web traffic | ClusterIP | +|service.http.port| Port for web traffic | 3000 | +|service.ssh.type| Kubernetes service type for ssh traffic | ClusterIP | +|service.ssh.port| Port for ssh traffic | 22 | +|service.ssh.annotations| Additional ssh annotations for the ssh service || + +### Gitea Configuration + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|gitea.config | Everything in app.ini can be configured with this dict. See Examples for more details | {} | + +### Memcached BuiltIn + +Memcached is loaded as a dependency from [Bitnami](https://github.com/bitnami/charts/tree/master/bitnami/memcached) if enabled in the values. Complete Configuration can be taken from their website. + +The following parameters are the defaults set by this chart + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|memcached.service.port|Memcached Port| 11211| + +### Mysql BuiltIn + +Mysql is loaded as a dependency from stable. Configuration can be found from this [website](https://github.com/helm/charts/tree/master/stable/mysql) + +The following parameters are the defaults set by this chart + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|mysql.mysqlRootPassword|Password for the root user. Ignored if existing secret is provided|gitea| +|mysql.mysqlUser|Username of new user to create.|gitea| +|mysql.mysqlPassword|Password for the new user. Ignored if existing secret is provided|gitea| +|mysql.mysqlDatabase|Name for new database to create.|gitea| +|mysql.service.port|Port to connect to mysql service|3306| +|mysql.persistence|Persistence size for mysql |10Gi| + +### Postgresql BuiltIn + +Postgresql is loaded as a dependency from bitnami. Configuration can be found from this [Bitnami](https://github.com/bitnami/charts/tree/master/bitnami/postgresql) + +The following parameters are the defaults set by this chart + +| Parameter | Description | Default | +|---------------------|-----------------------------------|------------------------------| +|postgresql.global.postgresql.postgresqlDatabase| PostgreSQL database (overrides postgresqlDatabase)|gitea| +|postgresql.global.postgresql.postgresqlUsername| PostgreSQL username (overrides postgresqlUsername)|gitea| +|postgresql.global.postgresql.postgresqlPassword| PostgreSQL admin password (overrides postgresqlPassword)|gitea| +|postgresql.global.postgresql.servicePort|PostgreSQL port (overrides service.port)|5432| +|postgresql.persistence.size| PVC Storage Request for PostgreSQL volume |10Gi| diff --git a/charts/mariadb-7.3.0.tgz b/charts/mariadb-7.3.0.tgz deleted file mode 100644 index d8d116f..0000000 Binary files a/charts/mariadb-7.3.0.tgz and /dev/null differ diff --git a/requirements.yaml b/requirements.yaml deleted file mode 100644 index e435a27..0000000 --- a/requirements.yaml +++ /dev/null @@ -1,7 +0,0 @@ -dependencies: - - name: mariadb - version: 7.3.0 - repository: https://charts.bitnami.com - condition: mariadb.enabled - tags: - - mariadb diff --git a/templates/NOTES.txt b/templates/NOTES.txt index 5c07b3a..289e007 100644 --- a/templates/NOTES.txt +++ b/templates/NOTES.txt @@ -1,45 +1,19 @@ -1. Connect to your Gitea web URL by running: - +1. Get the application URL by running these commands: {{- if .Values.ingress.enabled }} - - Ingress is enabled for this chart deployment. Please access the web UI at {{ .Values.ingress.hostname }} - -{{- else if contains "NodePort" .Values.service.http.serviceType }} - - export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - echo http://$NODE_IP/ - -{{- else if contains "LoadBalancer" .Values.service.http.serviceType }} - - NOTE: It may take a few minutes for the LoadBalancer IP to be available. - Watch the status with: 'kubectl get svc -w {{ template "fullname" . }}http' - - export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ template "fullname" . }}http -o jsonpath='{.status.loadBalancer.ingress[0].ip}') - echo http://$SERVICE_IP/ -{{- else if contains "ClusterIP" .Values.service.http.serviceType }} - - export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app={{ template "fullname" . }}" -o jsonpath="{.items[0].metadata.name}") - echo http://127.0.0.1:8080/ - kubectl port-forward $POD_NAME 8080:80 +{{- range $host := .Values.ingress.hosts }} + http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host }}/ {{- end }} - -2. Connect to your Gitea ssh port: - -{{- if contains "NodePort" .Values.service.ssh.serviceType }} - +{{- else if contains "NodePort" .Values.service.http.type }} + export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "gitea.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - echo http://$NODE_IP/ - -{{- else if contains "LoadBalancer" .Values.service.ssh.serviceType }} - - NOTE: It may take a few minutes for the LoadBalancer IP to be available. - Watch the status with: 'kubectl get svc -w {{ template "fullname" . }}-ssh' - - export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ template "fullname" . }}-ssh -o jsonpath='{.status.loadBalancer.ingress[0].ip}') - echo http://$SERVICE_IP/ -{{- else if contains "ClusterIP" .Values.service.ssh.serviceType }} - - export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app={{ template "fullname" . }}" -o jsonpath="{.items[0].metadata.name}") - echo http://127.0.0.1:8080/ - kubectl port-forward $POD_NAME 8022:22 + echo http://$NODE_IP:$NODE_PORT +{{- else if contains "LoadBalancer" .Values.service.http.type }} + NOTE: It may take a few minutes for the LoadBalancer IP to be available. + You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "gitea.fullname" . }}' + export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "gitea.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") + echo http://$SERVICE_IP:{{ .Values.service.port }} +{{- else if contains "ClusterIP" .Values.service.http.type }} + export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "gitea.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}") + echo "Visit http://127.0.0.1:{{ .Values.service.http.port }} to use your application" + kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME {{ .Values.service.http.port }}:{{ .Values.service.http.port }} {{- end }} diff --git a/templates/_helpers.tpl b/templates/_helpers.tpl index f662ef5..6ccd2e7 100644 --- a/templates/_helpers.tpl +++ b/templates/_helpers.tpl @@ -2,30 +2,88 @@ {{/* Expand the name of the chart. */}} -{{- define "name" -}} +{{- define "gitea.name" -}} {{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} {{- end -}} {{/* Create a default fully qualified app name. -We truncate at 24 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. */}} -{{- define "fullname" -}} +{{- define "gitea.fullname" -}} +{{- if .Values.fullnameOverride -}} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} {{- $name := default .Chart.Name .Values.nameOverride -}} -{{- printf "%s-%s" .Release.Name $name | trunc 24 -}} +{{- if contains $name .Release.Name -}} +{{- .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} {{- end -}} -{{- define "mariadb.fullname" -}} -{{- printf "%s-%s" .Release.Name "mariadb" | trunc 63 | trimSuffix "-" -}} +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "gitea.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{/* +Common labels +*/}} +{{- define "gitea.labels" -}} +helm.sh/chart: {{ include "gitea.chart" . }} +{{ include "gitea.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end -}} + +{{/* +Selector labels +*/}} +{{- define "gitea.selectorLabels" -}} +app.kubernetes.io/name: {{ include "gitea.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end -}} + +{{- define "postgresql.dns" -}} +{{- printf "%s-postgresql.%s.svc.cluster.local:%g" .Release.Name .Release.Namespace .Values.postgresql.global.postgresql.servicePort -}} +{{- end -}} + +{{- define "db.servicename" -}} +{{- if .Values.gitea.database.builtIn.postgresql.enabled -}} +{{- printf "%s-postgresql" .Release.Name -}} +{{- else if .Values.gitea.database.builtIn.mysql.enabled -}} +{{- printf "%s-mysql" .Release.Name -}} +{{- else -}} +{{ .Values.gitea.database.external.host }} +{{- end -}} +{{- end -}} + +{{- define "db.port" -}} +{{- if .Values.gitea.database.builtIn.postgresql.enabled -}} +{{ .Values.postgresql.global.postgresql.servicePort }} +{{- else if .Values.gitea.database.builtIn.mysql.enabled -}} +{{ .Values.mysql.service.port }} +{{- else -}} +{{ .Values.gitea.database.external.port }} +{{- end -}} +{{- end -}} + +{{- define "mysql.dns" -}} +{{- printf "%s-mysql.%s.svc.cluster.local:%g" .Release.Name .Release.Namespace .Values.mysql.service.port | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{- define "memcached.dns" -}} +{{- printf "%s-memcached.%s.svc.cluster.local:%g" .Release.Name .Release.Namespace .Values.memcached.service.port | trunc 63 | trimSuffix "-" -}} +{{- end -}} + +{{- define "gitea.default_domain" -}} +{{- printf "%s-gitea.%s.svc.cluster.local" (include "gitea.fullname" .) .Release.Namespace | trunc 63 | trimSuffix "-" -}} {{- end -}} -{{/* -Return the appropriate apiVersion for ingress. -*/}} -{{- define "gitea.ingress.apiVersion" -}} -{{- if semverCompare "<1.14-0" .Capabilities.KubeVersion.GitVersion -}} -{{- print "extensions/v1beta1" -}} -{{- else -}} -{{- print "networking.k8s.io/v1beta1" -}} -{{- end -}} -{{- end -}} diff --git a/templates/deployment.yaml b/templates/deployment.yaml deleted file mode 100644 index c00cfb1..0000000 --- a/templates/deployment.yaml +++ /dev/null @@ -1,52 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: {{ template "fullname" . }} - labels: - app: {{ template "fullname" . }} - chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" - release: "{{ .Release.Name }}" - heritage: "{{ .Release.Service }}" -spec: - replicas: 1 - selector: - matchLabels: - app: {{ template "fullname" . }} -{{- with .Values.deploymentStrategy }} - strategy: -{{ toYaml . | trim | indent 4 }} -{{- end }} - template: - metadata: - labels: - app: {{ template "fullname" . }} - {{- with .Values.podAnnotations }} - annotations: - {{- toYaml . | nindent 8 }} - {{- end }} - spec: - containers: - {{ include "gitea" . | indent 6 }} - {{ include "memcached" . | indent 6 }} - initContainers: - {{ include "init" . | indent 6 }} - volumes: - - name: gitea-data - {{- if .Values.persistence.enabled }} - {{- if .Values.persistence.directGiteaVolumeMount }} -{{ tpl .Values.persistence.directGiteaVolumeMount . | indent 8 }} - {{- else }} - persistentVolumeClaim: - claimName: {{ .Values.persistence.existingGiteaClaim | default (include "fullname" .) }} - {{- end }} - {{- else }} - emptyDir: {} - {{- end }} - - name: gitea-config - configMap: - name: {{ template "fullname" . }} - - {{- if .Values.imagePullSecrets }} - imagePullSecrets: - - name: {{ .Values.imagePullSecrets }} - {{- end }} diff --git a/templates/gitea/_container.tpl b/templates/gitea/_container.tpl deleted file mode 100644 index 033e668..0000000 --- a/templates/gitea/_container.tpl +++ /dev/null @@ -1,46 +0,0 @@ -{{/* -Create helm partial for gitea server -*/}} -{{- define "gitea" }} -- name: gitea - image: {{ .Values.images.gitea }} - imagePullPolicy: {{ .Values.images.pullPolicy }} - env: - - name: DATABASE_PASSWORD - valueFrom: - secretKeyRef: - {{- if .Values.mariadb.enabled }} - name: {{ template "mariadb.fullname" . }} - key: mariadb-password - {{- else }} - name: {{ printf "%s-%s" .Release.Name "externaldb" }} - key: db-password - {{- end }} - ports: - - name: ssh - containerPort: 22 - - name: http - containerPort: 3000 - livenessProbe: - tcpSocket: - port: http - initialDelaySeconds: 200 - timeoutSeconds: 1 - periodSeconds: 10 - successThreshold: 1 - failureThreshold: 10 - readinessProbe: - tcpSocket: - port: http - initialDelaySeconds: 5 - periodSeconds: 10 - successThreshold: 1 - failureThreshold: 3 - resources: -{{ toYaml .Values.resources.gitea | indent 10 }} - volumeMounts: - - name: gitea-data - mountPath: /data - - name: gitea-config - mountPath: /etc/gitea -{{- end }} diff --git a/templates/gitea/config.yaml b/templates/gitea/config.yaml new file mode 100644 index 0000000..825d612 --- /dev/null +++ b/templates/gitea/config.yaml @@ -0,0 +1,100 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ include "gitea.fullname" . }} + labels: + {{- include "gitea.labels" . | nindent 4 }} +data: + app.ini: |- + {{- if not (hasKey .Values.gitea.config "cache") -}} + {{- $_ := set .Values.gitea.config "cache" dict -}} + {{- end -}} + + {{- if not (hasKey .Values.gitea.config "server") -}} + {{- $_ := set .Values.gitea.config "server" dict -}} + {{- end -}} + + {{- if not (hasKey .Values.gitea.config "database") -}} + {{- $_ := set .Values.gitea.config "database" dict -}} + {{- end -}} + + {{- if not (hasKey .Values.gitea.config "security") -}} + {{- $_ := set .Values.gitea.config "security" dict -}} + {{- end -}} + + {{- /* security default settings */ -}} + {{- if not .Values.gitea.config.security.INSTALL_LOCK -}} + {{- $_ := set .Values.gitea.config.security "INSTALL_LOCK" "true" -}} + {{- end -}} + + {{- /* server default settings */ -}} + {{- if not (hasKey .Values.gitea.config.server "HTTP_PORT") -}} + {{- $_ := set .Values.gitea.config.server "HTTP_PORT" .Values.service.http.port -}} + {{- end -}} + {{- if not .Values.gitea.config.server.PROTOCOL -}} + {{- $_ := set .Values.gitea.config.server "PROTOCOL" "http" -}} + {{- end -}} + {{- if not (.Values.gitea.config.server.DOMAIN) -}} + {{- if gt (len .Values.ingress.hosts) 0 -}} + {{- $_ := set .Values.gitea.config.server "DOMAIN" (index .Values.ingress.hosts 0) -}} + {{- else -}} + {{- $_ := set .Values.gitea.config.server "DOMAIN" (include "gitea.default_domain" .) -}} + {{- end -}} + {{- end -}} + {{- if not .Values.gitea.config.server.ROOT_URL -}} + {{- if .Values.ingress.enabled -}} + {{- if gt (len .Values.ingress.tls) 0 -}} + {{- $_ := set .Values.gitea.config.server "ROOT_URL" (printf "%s://%s" .Values.gitea.config.server.PROTOCOL (index (index .Values.ingress.tls 0).hosts 0)) -}} + {{- else -}} + {{- $_ := set .Values.gitea.config.server "ROOT_URL" (printf "%s://%s" .Values.gitea.config.server.PROTOCOL (index .Values.ingress.hosts 0)) -}} + {{- end -}} + {{- else -}} + {{- $_ := set .Values.gitea.config.server "ROOT_URL" (printf "%s://%s" .Values.gitea.config.server.PROTOCOL .Values.gitea.config.server.DOMAIN) -}} + {{- end -}} + {{- end -}} + {{- if not .Values.gitea.config.server.SSH_DOMAIN -}} + {{- $_ := set .Values.gitea.config.server "SSH_DOMAIN" .Values.gitea.config.server.DOMAIN -}} + {{- end -}} + {{- if not .Values.gitea.config.server.SSH_PORT -}} + {{- $_ := set .Values.gitea.config.server "SSH_PORT" .Values.service.ssh.port -}} + {{- end -}} + {{- if not (hasKey .Values.gitea.config.server "SSH_LISTEN_PORT") -}} + {{- $_ := set .Values.gitea.config.server "SSH_LISTEN_PORT" .Values.gitea.config.server.SSH_PORT -}} + {{- end -}} + + {{- /* database default settings */ -}} + {{- if .Values.gitea.database.builtIn.postgresql.enabled -}} + {{- $_ := set .Values.gitea.config.database "DB_TYPE" "postgres" -}} + {{- $_ := set .Values.gitea.config.database "HOST" (include "postgresql.dns" .) -}} + {{- $_ := set .Values.gitea.config.database "NAME" .Values.postgresql.global.postgresql.postgresqlDatabase -}} + {{- $_ := set .Values.gitea.config.database "USER" .Values.postgresql.global.postgresql.postgresqlUsername -}} + {{- $_ := set .Values.gitea.config.database "PASSWD" .Values.postgresql.global.postgresql.postgresqlPassword -}} + {{ else if .Values.gitea.database.builtIn.mysql.enabled -}} + {{- $_ := set .Values.gitea.config.database "DB_TYPE" "mysql" -}} + {{- $_ := set .Values.gitea.config.database "HOST" (include "mysql.dns" .) -}} + {{- $_ := set .Values.gitea.config.database "NAME" .Values.mysql.db.name -}} + {{- $_ := set .Values.gitea.config.database "USER" .Values.mysql.db.user -}} + {{- $_ := set .Values.gitea.config.database "PASSWD" .Values.mysql.db.password -}} + {{- end -}} + + {{- /* cache default settings */ -}} + {{- if .Values.gitea.cache.builtIn.enabled -}} + {{- $_ := set .Values.gitea.config.cache "ENABLED" "true" -}} + {{- $_ := set .Values.gitea.config.cache "ADAPTER" "memcache" -}} + {{- $_ := set .Values.gitea.config.cache "HOST" (include "memcached.dns" .) -}} + {{- end -}} + + {{- /* autogenerate app.ini */ -}} + {{- range $key, $value := .Values.gitea.config }} + {{- if kindIs "map" $value }} + {{- if gt (len $value) 0 }} + + [{{ $key }}] + {{- range $n_key, $n_value := $value }} + {{ $n_key | upper }} = {{ $n_value }} + {{- end }} + {{- end }} + {{- else }} + {{ $key | upper }} = {{ $value }} + {{- end }} + {{- end }} \ No newline at end of file diff --git a/templates/gitea/gitea-config.yaml b/templates/gitea/gitea-config.yaml deleted file mode 100644 index 61a21b9..0000000 --- a/templates/gitea/gitea-config.yaml +++ /dev/null @@ -1,725 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ template "fullname" . }} - labels: - app: {{ template "fullname" . }} - chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" - release: "{{ .Release.Name }}" - heritage: "{{ .Release.Service }}" -data: - app.ini: |- - ; This file lists the default values used by Gitea - ; Copy required sections to your own app.ini (default is custom/conf/app.ini) - ; and modify as needed. - - ; see https://docs.gitea.io/en-us/config-cheat-sheet/ for additional documentation. - - ; App name that shows in every page title - APP_NAME = Gitea: Git with a cup of tea - ; Change it if you run locally - RUN_USER = git - ; Either "dev", "prod" or "test", default is "dev" - RUN_MODE = dev - - [repository] - ROOT = - SCRIPT_TYPE = bash - ; Default ANSI charset - ANSI_CHARSET = - ; Force every new repository to be private - FORCE_PRIVATE = false - ; Default privacy setting when creating a new repository, allowed values: last, private, public. Default is last which means the last setting used. - DEFAULT_PRIVATE = last - ; Global limit of repositories per user, applied at creation time. -1 means no limit - MAX_CREATION_LIMIT = -1 - ; Mirror sync queue length, increase if mirror syncing starts hanging - MIRROR_QUEUE_LENGTH = 1000 - ; Patch test queue length, increase if pull request patch testing starts hanging - PULL_REQUEST_QUEUE_LENGTH = 1000 - ; Preferred Licenses to place at the top of the List - ; The name here must match the filename in conf/license or custom/conf/license - PREFERRED_LICENSES = Apache License 2.0,MIT License - ; Disable the ability to interact with repositories using the HTTP protocol - DISABLE_HTTP_GIT = false - ; Force ssh:// clone url instead of scp-style uri when default SSH port is used - USE_COMPAT_SSH_URI = false - - [repository.editor] - ; List of file extensions for which lines should be wrapped in the CodeMirror editor - ; Separate extensions with a comma. To line wrap files without an extension, just put a comma - LINE_WRAP_EXTENSIONS = .txt,.md,.markdown,.mdown,.mkd, - ; Valid file modes that have a preview API associated with them, such as api/v1/markdown - ; Separate the values by commas. The preview tab in edit mode won't be displayed if the file extension doesn't match - PREVIEWABLE_FILE_MODES = markdown - - [repository.local] - ; Path for local repository copy. Defaults to `tmp/local-repo` - LOCAL_COPY_PATH = tmp/local-repo - ; Path for local wiki copy. Defaults to `tmp/local-wiki` - LOCAL_WIKI_PATH = tmp/local-wiki - - [repository.upload] - ; Whether repository file uploads are enabled. Defaults to `true` - ENABLED = true - ; Path for uploads. Defaults to `data/tmp/uploads` (tmp gets deleted on gitea restart) - TEMP_PATH = data/tmp/uploads - ; One or more allowed types, e.g. image/jpeg|image/png. Nothing means any file type - ALLOWED_TYPES = - ; Max size of each file in megabytes. Defaults to 3MB - FILE_MAX_SIZE = 3 - ; Max number of files per upload. Defaults to 5 - MAX_FILES = 5 - - [repository.pull-request] - ; List of prefixes used in Pull Request title to mark them as Work In Progress - WORK_IN_PROGRESS_PREFIXES=WIP:,[WIP] - - [ui] - ; Number of repositories that are displayed on one explore page - EXPLORE_PAGING_NUM = 20 - ; Number of issues that are displayed on one page - ISSUE_PAGING_NUM = 10 - ; Number of maximum commits displayed in one activity feed - FEED_MAX_COMMIT_NUM = 5 - ; Number of maximum commits displayed in commit graph. - GRAPH_MAX_COMMIT_NUM = 100 - ; Number of line of codes shown for a code comment - CODE_COMMENT_LINES = 4 - ; Value of `theme-color` meta tag, used by Android >= 5.0 - ; An invalid color like "none" or "disable" will have the default style - ; More info: https://developers.google.com/web/updates/2014/11/Support-for-theme-color-in-Chrome-39-for-Android - THEME_COLOR_META_TAG = `#6cc644` - ; Max size of files to be displayed (default is 8MiB) - MAX_DISPLAY_FILE_SIZE = 8388608 - ; Whether the email of the user should be shown in the Explore Users page - SHOW_USER_EMAIL = true - ; Set the default theme for the Gitea install - DEFAULT_THEME = gitea - - - [ui.admin] - ; Number of users that are displayed on one page - USER_PAGING_NUM = 50 - ; Number of repos that are displayed on one page - REPO_PAGING_NUM = 50 - ; Number of notices that are displayed on one page - NOTICE_PAGING_NUM = 25 - ; Number of organizations that are displayed on one page - ORG_PAGING_NUM = 50 - - [ui.user] - ; Number of repos that are displayed on one page - REPO_PAGING_NUM = 15 - - [ui.meta] - AUTHOR = Gitea - Git with a cup of tea - DESCRIPTION = Gitea (Git with a cup of tea) is a painless self-hosted Git service written in Go - KEYWORDS = go,git,self-hosted,gitea - - [markdown] - ; Enable hard line break extension - ENABLE_HARD_LINE_BREAK = false - ; List of custom URL-Schemes that are allowed as links when rendering Markdown - ; for example git,magnet - CUSTOM_URL_SCHEMES = - ; List of file extensions that should be rendered/edited as Markdown - ; Separate the extensions with a comma. To render files without any extension as markdown, just put a comma - FILE_EXTENSIONS = .md,.markdown,.mdown,.mkd - - [server] - ; The protocol the server listens on. One of 'http', 'https', 'unix' or 'fcgi'. - - ; PROTOCOL hardcoded to http since tls is delegated to ingress - PROTOCOL = http - {{- if .Values.service.http.externalHost }} - DOMAIN = {{ .Values.service.http.externalHost }} - {{- else if .Values.ingress.enabled }} - DOMAIN = {{ .Values.ingress.hostname }} - {{- else }} - DOMAIN = {{ template "fullname" . }}-http.{{ .Release.Namespace }}.svc.cluster.local - {{- end -}} - {{ if .Values.ingress.tls }} - {{- $proto := set . "proto" "https" }} - {{- else -}} - {{- $proto := set . "proto" "http" }} - {{- end -}} - {{- if and .Values.service.http.externalHost ( .Values.service.http.externalPort ) }} - ROOT_URL = {{ .proto }}://{{ .Values.service.http.externalHost }}:{{ .Values.service.http.externalPort }}/ - {{- else if .Values.service.http.externalHost }} - ROOT_URL = {{ .proto }}://{{ .Values.service.http.externalHost }}/ - {{- else if .Values.ingress.enabled }} - ROOT_URL = %(PROTOCOL)s://%(DOMAIN)s - {{- else }} - ROOT_URL = %(PROTOCOL)s://%(DOMAIN)s:%(HTTP_PORT)s/ - {{- end -}} - ; The address to listen on. Either a IPv4/IPv6 address or the path to a unix socket. - HTTP_ADDR = 0.0.0.0 - HTTP_PORT = {{ .Values.service.http.port }} - ; If REDIRECT_OTHER_PORT is true, and PROTOCOL is set to https an http server - ; will be started on PORT_TO_REDIRECT and it will redirect plain, non-secure http requests to the main - ; ROOT_URL. Defaults are false for REDIRECT_OTHER_PORT and 80 for - ; PORT_TO_REDIRECT. - REDIRECT_OTHER_PORT = false - PORT_TO_REDIRECT = 80 - ; Permission for unix socket - UNIX_SOCKET_PERMISSION = 666 - ; Local (DMZ) URL for Gitea workers (such as SSH update) accessing web service. - ; In most cases you do not need to change the default value. - ; Alter it only if your SSH server node is not the same as HTTP node. - ; Do not set this variable if PROTOCOL is set to 'unix'. - LOCAL_ROOT_URL = %(PROTOCOL)s://%(HTTP_ADDR)s:%(HTTP_PORT)s/ - ; Disable SSH feature when not available - DISABLE_SSH = false - ; Whether to use the builtin SSH server or not. - START_SSH_SERVER = false - ; Username to use for the builtin SSH server. If blank, then it is the value of RUN_USER. - BUILTIN_SSH_SERVER_USER = - ; Domain name to be exposed in clone URL - {{- if .Values.service.ssh.externalHost }} - SSH_DOMAIN = {{ .Values.service.ssh.externalHost }} - {{- else }} - SSH_DOMAIN = {{ template "fullname" . }}-ssh.{{ .Release.Namespace }}.svc.cluster.local - {{- end }} - ; THe network interface the builtin SSH server should listen on - SSH_LISTEN_HOST = - ; Port number to be exposed in clone URL - {{- if .Values.service.ssh.externalPort }} - SSH_PORT = {{ .Values.service.ssh.externalPort }} - {{- else }} - SSH_PORT = {{ .Values.service.ssh.port }} - {{- end }} - ; The port number the builtin SSH server should listen on - SSH_LISTEN_PORT = {{ .Values.service.ssh.port }} - ; Root path of SSH directory, default is '~/.ssh', but you have to use '/home/git/.ssh'. - SSH_ROOT_PATH = - ; Gitea will create a authorized_keys file by default when it is not using the internal ssh server - ; If you intend to use the AuthorizedKeysCommand functionality then you should turn this off. - SSH_CREATE_AUTHORIZED_KEYS_FILE = true - ; For the built-in SSH server, choose the ciphers to support for SSH connections, - ; for system SSH this setting has no effect - SSH_SERVER_CIPHERS = aes128-ctr, aes192-ctr, aes256-ctr, aes128-gcm@openssh.com, arcfour256, arcfour128 - ; For the built-in SSH server, choose the key exchange algorithms to support for SSH connections, - ; for system SSH this setting has no effect - SSH_SERVER_KEY_EXCHANGES = diffie-hellman-group1-sha1, diffie-hellman-group14-sha1, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, curve25519-sha256@libssh.org - ; For the built-in SSH server, choose the MACs to support for SSH connections, - ; for system SSH this setting has no effect - SSH_SERVER_MACS = hmac-sha2-256-etm@openssh.com, hmac-sha2-256, hmac-sha1, hmac-sha1-96 - ; Directory to create temporary files in when testing public keys using ssh-keygen, - ; default is the system temporary directory. - SSH_KEY_TEST_PATH = - ; Path to ssh-keygen, default is 'ssh-keygen' which means the shell is responsible for finding out which one to call. - SSH_KEYGEN_PATH = ssh-keygen - ; Enable SSH Authorized Key Backup when rewriting all keys, default is true - SSH_BACKUP_AUTHORIZED_KEYS = true - ; Enable exposure of SSH clone URL to anonymous visitors, default is false - SSH_EXPOSE_ANONYMOUS = false - ; Indicate whether to check minimum key size with corresponding type - MINIMUM_KEY_SIZE_CHECK = false - ; Disable CDN even in "prod" mode - OFFLINE_MODE = {{ .Values.config.offlineMode }} - DISABLE_ROUTER_LOG = false - ; Generate steps: - ; $ ./gitea cert -ca=true -duration=8760h0m0s -host=myhost.example.com - ; - ; Or from a .pfx file exported from the Windows certificate store (do - ; not forget to export the private key): - ; $ openssl pkcs12 -in cert.pfx -out cert.pem -nokeys - ; $ openssl pkcs12 -in cert.pfx -out key.pem -nocerts -nodes - CERT_FILE = custom/https/cert.pem - KEY_FILE = custom/https/key.pem - ; Root directory containing templates and static files. - ; default is the path where Gitea is executed - STATIC_ROOT_PATH = - ; Default path for App data - APP_DATA_PATH = data - ; Application level GZIP support - ENABLE_GZIP = false - ; Application profiling (memory and cpu) - ; For "web" command it listens on localhost:6060 - ; For "serve" command it dumps to disk at PPROF_DATA_PATH as (cpuprofile|memprofile)__ - ENABLE_PPROF = false - ; PPROF_DATA_PATH, use an absolute path when you start gitea as service - PPROF_DATA_PATH = data/tmp/pprof - ; Landing page, can be "home", "explore", or "organizations" - LANDING_PAGE = home - ; Enables git-lfs support. true or false, default is false. - LFS_START_SERVER = false - ; Where your lfs files reside, default is data/lfs. - LFS_CONTENT_PATH = data/lfs - ; LFS authentication secret, change this yourself - LFS_JWT_SECRET = - ; LFS authentication validity period (in time.Duration), pushes taking longer than this may fail. - LFS_HTTP_AUTH_EXPIRY = 20m - - - ; Define allowed algorithms and their minimum key length (use -1 to disable a type) - [ssh.minimum_key_sizes] - ED25519 = 256 - ECDSA = 256 - RSA = 2048 - DSA = 1024 - - [database] - {{ if .Values.externalDB }} - ; Either "mysql", "postgres", "mssql" or "sqlite3", it's your choice - DB_TYPE = {{ .Values.dbType }} - HOST = {{ .Values.externalDB.dbHost }}:{{ .Values.externalDB.dbPort }} - NAME = {{ .Values.externalDB.dbDatabase }} - USER = {{ .Values.externalDB.dbUser }} - PASSWD = {{ .Values.externalDB.dbPassword }} - {{ else if .Values.mariadb.enabled }} - ; Either "mysql", "postgres", "mssql" or "sqlite3", it's your choice - DB_TYPE = mysql - HOST = {{ template "mariadb.fullname" . }}:3306 - NAME = {{ .Values.mariadb.db.name }} - USER = {{ .Values.mariadb.db.user }} - ; Use PASSWD = `your password` for quoting if you use special characters in the password. - {{ if .Values.mariadb.password }} - PASSWD = {{ .Values.mariadb.db.password }} - {{ else }} - PASSWD = MARIADB_PASSWORD - {{ end }} - {{ end }} - ; For "postgres" only, either "disable", "require" or "verify-full" - SSL_MODE = disable - ; For "sqlite3" and "tidb", use an absolute path when you start gitea as service - PATH = data/gitea.db - ; For "sqlite3" only. Query timeout - SQLITE_TIMEOUT = 500 - ; For iterate buffer, default is 50 - ITERATE_BUFFER_SIZE = 50 - ; Show the database generated SQL - LOG_SQL = true - - [indexer] - ISSUE_INDEXER_PATH = indexers/issues.bleve - ; repo indexer by default disabled, since it uses a lot of disk space - REPO_INDEXER_ENABLED = false - REPO_INDEXER_PATH = indexers/repos.bleve - UPDATE_BUFFER_LEN = 20 - MAX_FILE_SIZE = 1048576 - - [admin] - ; Disallow regular (non-admin) users from creating organizations. - DISABLE_REGULAR_ORG_CREATION = false - - [security] - ; Whether the installer is disabled - INSTALL_LOCK = {{ .Values.config.disableInstaller }} - ; !!CHANGE THIS TO KEEP YOUR USER DATA SAFE!! - {{ if .Values.config.secretKey }} - SECRET_KEY = {{ .Values.config.secretKey }} - {{ else }} - SECRET_KEY = {{ randAlphaNum 64 | quote }} - {{ end }} - - - ; How long to remember that an user is logged in before requiring relogin (in days) - LOGIN_REMEMBER_DAYS = 7 - COOKIE_USERNAME = gitea_awesome - COOKIE_REMEMBER_NAME = gitea_incredible - ; Reverse proxy authentication header name of user name - REVERSE_PROXY_AUTHENTICATION_USER = X-WEBAUTH-USER - ; The minimum password length for new Users - MIN_PASSWORD_LENGTH = 6 - ; Set to true to allow users to import local server paths - IMPORT_LOCAL_PATHS = false - ; Set to true to prevent all users (including admin) from creating custom git hooks - DISABLE_GIT_HOOKS = false - - [openid] - ; - ; OpenID is an open, standard and decentralized authentication protocol. - ; Your identity is the address of a webpage you provide, which describes - ; how to prove you are in control of that page. - ; - ; For more info: https://en.wikipedia.org/wiki/OpenID - ; - ; Current implementation supports OpenID-2.0 - ; - ; Tested to work providers at the time of writing: - ; - Any GNUSocial node (your.hostname.tld/username) - ; - Any SimpleID provider (http://simpleid.koinic.net) - ; - http://openid.org.cn/ - ; - openid.stackexchange.com - ; - login.launchpad.net - ; - .livejournal.com - ; - ; Whether to allow signin in via OpenID - ENABLE_OPENID_SIGNIN = {{ .Values.config.openidSignin }} - ; Whether to allow registering via OpenID - ; Do not include to rely on rhw DISABLE_REGISTRATION setting - ;ENABLE_OPENID_SIGNUP = true - ; Allowed URI patterns (POSIX regexp). - ; Space separated. - ; Only these would be allowed if non-blank. - ; Example value: trusted.domain.org trusted.domain.net - WHITELISTED_URIS = - ; Forbidden URI patterns (POSIX regexp). - ; Space separated. - ; Only used if WHITELISTED_URIS is blank. - ; Example value: loadaverage.org/badguy stackexchange.com/.*spammer - BLACKLISTED_URIS = - - [service] - ; Time limit to confirm account/email registration - ACTIVE_CODE_LIVE_MINUTES = 180 - ; Time limit to perform the reset of a forgotten password - RESET_PASSWD_CODE_LIVE_MINUTES = 180 - ; Whether a new user needs to confirm their email when registering. - REGISTER_EMAIL_CONFIRM = false - ; List of domain names that are allowed to be used to register on a Gitea instance - ; gitea.io,example.com - EMAIL_DOMAIN_WHITELIST= - ; Disallow registration, only allow admins to create accounts. - DISABLE_REGISTRATION = {{ .Values.config.disableRegistration }} - ; Allow registration only using third-party services, it works only when DISABLE_REGISTRATION is false - ALLOW_ONLY_EXTERNAL_REGISTRATION = false - ; User must sign in to view anything. - REQUIRE_SIGNIN_VIEW = {{ .Values.config.requireSignin }} - ; Mail notification - ENABLE_NOTIFY_MAIL = false - ; More detail: https://github.com/gogits/gogs/issues/165 - ENABLE_REVERSE_PROXY_AUTHENTICATION = false - ENABLE_REVERSE_PROXY_AUTO_REGISTRATION = false - ; Enable captcha validation for registration - ENABLE_CAPTCHA = false - ; Type of captcha you want to use. Options: image, recaptcha - CAPTCHA_TYPE = image - ; Enable recaptcha to use Google's recaptcha service - ; Go to https://www.google.com/recaptcha/admin to sign up for a key - RECAPTCHA_SECRET = - RECAPTCHA_SITEKEY = - ; Default value for KeepEmailPrivate - ; Each new user will get the value of this setting copied into their profile - DEFAULT_KEEP_EMAIL_PRIVATE = false - ; Default value for AllowCreateOrganization - ; Every new user will have rights set to create organizations depending on this setting - DEFAULT_ALLOW_CREATE_ORGANIZATION = true - ; Default value for EnableDependencies - ; Repositories will use dependencies by default depending on this setting - DEFAULT_ENABLE_DEPENDENCIES = true - ; Enable heatmap on users profiles. - ENABLE_USER_HEATMAP = true - ; Enable Timetracking - ENABLE_TIMETRACKING = true - ; Default value for EnableTimetracking - ; Repositories will use timetracking by default depending on this setting - DEFAULT_ENABLE_TIMETRACKING = true - ; Default value for AllowOnlyContributorsToTrackTime - ; Only users with write permissions can track time if this is true - DEFAULT_ALLOW_ONLY_CONTRIBUTORS_TO_TRACK_TIME = true - ; Default value for the domain part of the user's email address in the git log - ; if he has set KeepEmailPrivate to true. The user's email will be replaced with a - ; concatenation of the user name in lower case, "@" and NO_REPLY_ADDRESS. - NO_REPLY_ADDRESS = noreply.example.org - - [webhook] - ; Hook task queue length, increase if webhook shooting starts hanging - QUEUE_LENGTH = 1000 - ; Deliver timeout in seconds - DELIVER_TIMEOUT = 5 - ; Allow insecure certification - SKIP_TLS_VERIFY = false - ; Number of history information in each page - PAGING_NUM = 10 - - [mailer] - ENABLED = false - ; Buffer length of channel, keep it as it is if you don't know what it is. - SEND_BUFFER_LEN = 100 - ; Name displayed in mail title - SUBJECT = %(APP_NAME)s - ; Mail server - ; Gmail: smtp.gmail.com:587 - ; QQ: smtp.qq.com:465 - ; Note, if the port ends with "465", SMTPS will be used. Using STARTTLS on port 587 is recommended per RFC 6409. If the server supports STARTTLS it will always be used. - HOST = - ; Disable HELO operation when hostnames are different. - DISABLE_HELO = - ; Custom hostname for HELO operation, if no value is provided, one is retrieved from system. - HELO_HOSTNAME = - ; Do not verify the certificate of the server. Only use this for self-signed certificates - SKIP_VERIFY = - ; Use client certificate - USE_CERTIFICATE = false - CERT_FILE = custom/mailer/cert.pem - KEY_FILE = custom/mailer/key.pem - ; Should SMTP connection use TLS - IS_TLS_ENABLED = false - ; Mail from address, RFC 5322. This can be just an email address, or the `"Name" ` format - FROM = - ; Mailer user name and password - USER = - ; Use PASSWD = `your password` for quoting if you use special characters in the password. - PASSWD = - ; Send mails as plain text - SEND_AS_PLAIN_TEXT = false - ; Enable sendmail (override SMTP) - USE_SENDMAIL = false - ; Specify an alternative sendmail binary - SENDMAIL_PATH = sendmail - ; Specify any extra sendmail arguments - SENDMAIL_ARGS = - - [cache] - ; Either "memory", "redis", or "memcache", default is "memory" - ADAPTER = memcache - ; For "memory" only, GC interval in seconds, default is 60 - INTERVAL = 60 - ; For "redis" and "memcache", connection host address - ;redis: network=tcp,addr=:6379,password=macaron,db=0,pool_size=100,idle_timeout=180 - HOST = 127.0.0.1:11211 - ; Time to keep items in cache if not used, default is 16 hours. - ; Setting it to 0 disables caching - ITEM_TTL = 16h - - [session] - ; Either "memory", "file", or "redis", default is "memory" - PROVIDER = memory - ; Provider config options - ; memory: doesn't have any config yet - ; file: session file path, e.g. `data/sessions` - ; redis: network=tcp,addr=:6379,password=macaron,db=0,pool_size=100,idle_timeout=180 - ; mysql: go-sql-driver/mysql dsn config string, e.g. `root:password@/session_table` - PROVIDER_CONFIG = data/sessions - ; Session cookie name - COOKIE_NAME = i_like_gitea - ; If you use session in https only, default is false - COOKIE_SECURE = false - ; Enable set cookie, default is true - ENABLE_SET_COOKIE = true - ; Session GC time interval in seconds, default is 86400 (1 day) - GC_INTERVAL_TIME = 86400 - ; Session life time in seconds, default is 86400 (1 day) - SESSION_LIFE_TIME = 86400 - - [picture] - AVATAR_UPLOAD_PATH = data/avatars - ; Max Width and Height of uploaded avatars. This is to limit the amount of RAM - ; used when resizing the image. - AVATAR_MAX_WIDTH = 4096 - AVATAR_MAX_HEIGHT = 3072 - ; Chinese users can choose "duoshuo" - ; or a custom avatar source, like: http://cn.gravatar.com/avatar/ - GRAVATAR_SOURCE = gravatar - ; This value will always be true in offline mode. - DISABLE_GRAVATAR = false - ; Federated avatar lookup uses DNS to discover avatar associated - ; with emails, see https://www.libravatar.org - ; This value will always be false in offline mode or when Gravatar is disabled. - ENABLE_FEDERATED_AVATAR = false - - [attachment] - ; Whether attachments are enabled. Defaults to `true` - ENABLED = true - ; Path for attachments. Defaults to `data/attachments` - PATH = data/attachments - ; One or more allowed types, e.g. image/jpeg|image/png - ALLOWED_TYPES = image/jpeg|image/png|application/zip|application/gzip - ; Max size of each file. Defaults to 4MB - MAX_SIZE = 4 - ; Max number of files per upload. Defaults to 5 - MAX_FILES = 5 - - [log] - ROOT_PATH = - ; Either "console", "file", "conn", "smtp" or "database", default is "console" - ; Use comma to separate multiple modes, e.g. "console, file" - MODE = console - ; Buffer length of the channel, keep it as it is if you don't know what it is. - BUFFER_LEN = 10000 - ; Either "Trace", "Debug", "Info", "Warn", "Error", "Critical", default is "Trace" - LEVEL = Critical - - ; For "console" mode only - [log.console] - LEVEL = - - ; For "file" mode only - [log.file] - LEVEL = - ; This enables automated log rotate(switch of following options), default is true - LOG_ROTATE = true - ; Max number of lines in a single file, default is 1000000 - MAX_LINES = 1000000 - ; Max size shift of a single file, default is 28 means 1 << 28, 256MB - MAX_SIZE_SHIFT = 28 - ; Segment log daily, default is true - DAILY_ROTATE = true - ; delete the log file after n days, default is 7 - MAX_DAYS = 7 - - ; For "conn" mode only - [log.conn] - LEVEL = - ; Reconnect host for every single message, default is false - RECONNECT_ON_MSG = false - ; Try to reconnect when connection is lost, default is false - RECONNECT = false - ; Either "tcp", "unix" or "udp", default is "tcp" - PROTOCOL = tcp - ; Host address - ADDR = - - ; For "smtp" mode only - [log.smtp] - LEVEL = - ; Name displayed in mail title, default is "Diagnostic message from server" - SUBJECT = Diagnostic message from server - ; Mail server - HOST = - ; Mailer user name and password - USER = - ; Use PASSWD = `your password` for quoting if you use special characters in the password. - PASSWD = - ; Receivers, can be one or more, e.g. 1@example.com,2@example.com - RECEIVERS = - - ; For "database" mode only - [log.database] - LEVEL = - ; Either "mysql" or "postgres" - DRIVER = - ; Based on xorm, e.g.: root:root@localhost/gitea?charset=utf8 - CONN = - - [cron] - ; Enable running cron tasks periodically. - ENABLED = true - ; Run cron tasks when Gitea starts. - RUN_AT_START = false - - ; Update mirrors - [cron.update_mirrors] - SCHEDULE = @every 10m - - ; Repository health check - [cron.repo_health_check] - SCHEDULE = @every 24h - TIMEOUT = 60s - ; Arguments for command 'git fsck', e.g. "--unreachable --tags" - ; see more on http://git-scm.com/docs/git-fsck - ARGS = - - ; Check repository statistics - [cron.check_repo_stats] - RUN_AT_START = true - SCHEDULE = @every 24h - - ; Clean up old repository archives - [cron.archive_cleanup] - ; Whether to enable the job - ENABLED = true - ; Whether to always run at least once at start up time (if ENABLED) - RUN_AT_START = true - ; Time interval for job to run - SCHEDULE = @every 24h - ; Archives created more than OLDER_THAN ago are subject to deletion - OLDER_THAN = 24h - - ; Synchronize external user data (only LDAP user synchronization is supported) - [cron.sync_external_users] - ; Synchronize external user data when starting server (default false) - RUN_AT_START = false - ; Interval as a duration between each synchronization (default every 24h) - SCHEDULE = @every 24h - ; Create new users, update existing user data and disable users that are not in external source anymore (default) - ; or only create new users if UPDATE_EXISTING is set to false - UPDATE_EXISTING = true - - [git] - ; Disables highlight of added and removed changes - DISABLE_DIFF_HIGHLIGHT = false - ; Max number of lines allowed in a single file in diff view - MAX_GIT_DIFF_LINES = 1000 - ; Max number of allowed characters in a line in diff view - MAX_GIT_DIFF_LINE_CHARACTERS = 5000 - ; Max number of files shown in diff view - MAX_GIT_DIFF_FILES = 100 - ; Arguments for command 'git gc', e.g. "--aggressive --auto" - ; see more on http://git-scm.com/docs/git-gc/ - GC_ARGS = - - ; Operation timeout in seconds - [git.timeout] - MIGRATE = 600 - MIRROR = 300 - CLONE = 300 - PULL = 300 - GC = 60 - - [mirror] - ; Default interval as a duration between each check - DEFAULT_INTERVAL = 8h - ; Min interval as a duration must be > 1m - MIN_INTERVAL = 10m - - [api] - ; Enables Swagger. True or false; default is true. - ENABLE_SWAGGER = true - ; Max number of items in a page - MAX_RESPONSE_ITEMS = 50 - - [i18n] - LANGS = en-US,zh-CN,zh-HK,zh-TW,de-DE,fr-FR,nl-NL,lv-LV,ru-RU,uk-UA,ja-JP,es-ES,pt-BR,pl-PL,bg-BG,it-IT,fi-FI,tr-TR,cs-CZ,sr-SP,sv-SE,ko-KR - NAMES = English,简体中文,繁體中文(香港),繁體中文(台灣),Deutsch,français,Nederlands,latviešu,русский,Українська,日本語,español,português do Brasil,polski,български,italiano,suomi,Türkçe,čeština,српски,svenska,한국어 - - ; Used for datetimepicker - [i18n.datelang] - en-US = en - zh-CN = zh - zh-HK = zh-HK - zh-TW = zh-TW - de-DE = de - fr-FR = fr - nl-NL = nl - lv-LV = lv - ru-RU = ru - uk-UA = uk - ja-JP = ja - es-ES = es - pt-BR = pt-BR - pl-PL = pl - bg-BG = bg - it-IT = it - fi-FI = fi - tr-TR = tr - cs-CZ = cs-CZ - sr-SP = sr - sv-SE = sv - ko-KR = ko - - [U2F] - ; Two Factor authentication with security keys - ; https://developers.yubico.com/U2F/App_ID.html - ;APP_ID = %(PROTOCOL)s://%(DOMAIN)s:%(HTTP_PORT)s/ - ; Comma seperated list of truisted facets - ;TRUSTED_FACETS = %(PROTOCOL)s://%(DOMAIN)s:%(HTTP_PORT)s/ - - ; Extension mapping to highlight class - ; e.g. .toml=ini - [highlight.mapping] - - [other] - SHOW_FOOTER_BRANDING = false - ; Show version information about Gitea and Go in the footer - SHOW_FOOTER_VERSION = true - ; Show template execution time in the footer - SHOW_FOOTER_TEMPLATE_LOAD_TIME = true - - [markup.asciidoc] - ENABLED = false - ; List of file extensions that should be rendered by an external command - FILE_EXTENSIONS = .adoc,.asciidoc - ; External command to render all matching extensions - RENDER_COMMAND = "asciidoc --out-file=- -" - ; Don't pass the file on STDIN, pass the filename as argument instead. - IS_INPUT_FILE = false - - [metrics] - ; Enables metrics endpoint. True or false; default is false. - ENABLED = false - ; If you want to add authorization, specify a token here - TOKEN = diff --git a/templates/gitea/gitea-http-svc.yaml b/templates/gitea/gitea-http-svc.yaml deleted file mode 100644 index 38b016d..0000000 --- a/templates/gitea/gitea-http-svc.yaml +++ /dev/null @@ -1,20 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: {{ template "fullname" . }}-http - labels: - app: {{ template "fullname" . }} - chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" - release: "{{ .Release.Name }}" - heritage: "{{ .Release.Service }}" -spec: - type: {{ .Values.service.http.serviceType }} - ports: - - name: http - port: {{ .Values.service.http.port }} - {{- if .Values.service.http.nodePort }} - nodePort: {{ .Values.service.http.nodePort }} - {{- end }} - targetPort: {{ .Values.service.http.port }} - selector: - app: {{ template "fullname" . }} diff --git a/templates/gitea/gitea-pvc.yaml b/templates/gitea/gitea-pvc.yaml deleted file mode 100644 index dde81d0..0000000 --- a/templates/gitea/gitea-pvc.yaml +++ /dev/null @@ -1,29 +0,0 @@ -{{- if and .Values.persistence.enabled (not .Values.persistence.existingGiteaClaim) (not .Values.persistence.directGiteaVolumeMount) -}} -kind: PersistentVolumeClaim -apiVersion: v1 -metadata: - name: {{ template "fullname" . }} - labels: - app: {{ template "fullname" . }} - chart: gitea - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} -{{- if .Values.persistence.annotations }} - annotations: -{{ toYaml .Values.persistence.annotations | indent 4 }} -{{- end }} - -spec: - accessModes: - - {{ .Values.persistence.accessMode | quote }} - resources: - requests: - storage: {{ .Values.persistence.giteaSize | quote }} -{{- if .Values.persistence.storageClass }} -{{- if (eq "-" .Values.persistence.storageClass) }} - storageClassName: "" -{{- else }} - storageClassName: "{{ .Values.persistence.storageClass }}" -{{- end }} -{{- end }} -{{- end }} diff --git a/templates/gitea/gitea-ssh-svc.yaml b/templates/gitea/gitea-ssh-svc.yaml deleted file mode 100644 index aa00440..0000000 --- a/templates/gitea/gitea-ssh-svc.yaml +++ /dev/null @@ -1,24 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: {{ template "fullname" . }}-ssh - labels: - app: {{ template "fullname" . }} - chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" - release: "{{ .Release.Name }}" - heritage: "{{ .Release.Service }}" -spec: - type: {{ .Values.service.ssh.serviceType }} - {{- with .Values.service.ssh.externalIPs }} - externalIPs: - {{ toYaml . | indent 2 | trim }} - {{- end }} - ports: - - name: ssh - port: {{ .Values.service.ssh.port }} - targetPort: ssh - {{- if .Values.service.ssh.nodePort }} - nodePort: {{ .Values.service.ssh.nodePort }} - {{- end }} - selector: - app: {{ template "fullname" . }} diff --git a/templates/gitea/http-svc.yaml b/templates/gitea/http-svc.yaml new file mode 100644 index 0000000..3c6dda4 --- /dev/null +++ b/templates/gitea/http-svc.yaml @@ -0,0 +1,18 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "gitea.fullname" . }}-http + labels: + {{- include "gitea.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.http.type }} + clusterIP: None + ports: + - name: http + port: {{ .Values.service.http.port }} + {{- if .Values.service.http.nodePort }} + nodePort: {{ .Values.service.http.nodePort }} + {{- end }} + targetPort: {{ .Values.gitea.config.server.HTTP_PORT }} + selector: + {{- include "gitea.selectorLabels" . | nindent 4 }} diff --git a/templates/gitea/ingress.yaml b/templates/gitea/ingress.yaml new file mode 100644 index 0000000..aa5e508 --- /dev/null +++ b/templates/gitea/ingress.yaml @@ -0,0 +1,39 @@ +{{- if .Values.ingress.enabled -}} +{{- $fullName := include "gitea.fullname" . -}} +{{- $httpPort := .Values.service.http.port -}} +{{- if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}} +apiVersion: networking.k8s.io/v1beta1 +{{- else -}} +apiVersion: extensions/v1beta1 +{{- end }} +kind: Ingress +metadata: + name: {{ $fullName }} + labels: + {{- include "gitea.labels" . | nindent 4 }} + {{- with .Values.ingress.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +spec: +{{- if .Values.ingress.tls }} + tls: + {{- range .Values.ingress.tls }} + - hosts: + {{- range .hosts }} + - {{ . | quote }} + {{- end }} + secretName: {{ .secretName }} + {{- end }} +{{- end }} + rules: + {{- range .Values.ingress.hosts }} + - host: {{ . | quote }} + http: + paths: + - path: / + backend: + serviceName: {{ $fullName }}-http + servicePort: {{ $httpPort }} + {{- end }} +{{- end }} diff --git a/templates/gitea/ssh-svc.yaml b/templates/gitea/ssh-svc.yaml new file mode 100644 index 0000000..793fcb6 --- /dev/null +++ b/templates/gitea/ssh-svc.yaml @@ -0,0 +1,26 @@ +apiVersion: v1 +kind: Service +metadata: + name: {{ include "gitea.fullname" . }}-ssh + labels: + {{- include "gitea.labels" . | nindent 4 }} + annotations: +{{ toYaml .Values.service.ssh.annotations | indent 4 }} +spec: + type: {{ .Values.service.ssh.type }} + {{- if and .Values.service.ssh.loadBalancerIP (eq .Values.service.ssh.type "LoadBalancer") }} + loadBalancerIP: {{ .Values.service.ssh.loadBalancerIP }} + {{- end }} + {{- if ne .Values.service.ssh.type "LoadBalancer" }} + clusterIP: None + {{- end }} + ports: + - name: ssh + port: {{ .Values.service.ssh.port }} + targetPort: {{ .Values.gitea.config.server.SSH_LISTEN_PORT }} + protocol: TCP + {{- if .Values.service.ssh.nodePort }} + nodePort: {{ .Values.service.ssh.nodePort }} + {{- end }} + selector: + {{- include "gitea.selectorLabels" . | nindent 4 }} diff --git a/templates/gitea/statefulset.yaml b/templates/gitea/statefulset.yaml new file mode 100644 index 0000000..4f260be --- /dev/null +++ b/templates/gitea/statefulset.yaml @@ -0,0 +1,151 @@ +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: {{ include "gitea.fullname" . }} + labels: + {{- include "gitea.labels" . | nindent 4 }} +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + {{- include "gitea.selectorLabels" . | nindent 6 }} + serviceName: {{ include "gitea.fullname" . }} + template: + metadata: + annotations: + checksum/config: {{ include (print $.Template.BasePath "/gitea/config.yaml") . | sha256sum }} + labels: + {{- include "gitea.selectorLabels" . | nindent 8 }} + spec: + securityContext: + fsGroup: 1000 + initContainers: + - name: init + image: "{{ .Values.image.repository }}:{{ .Values.image.version }}" + env: + - name: SCRIPT + value: &script |- + mkdir -p /data/gitea/conf + cp /etc/gitea/conf/app.ini /data/gitea/conf/app.ini + chmod a+rwx /data/gitea/conf/app.ini + nc -v -w2 -z {{ include "db.servicename" . }} {{ include "db.port" . }} && \ + su git -c ' \ + set -x; \ + gitea migrate; \ + {{- if and .Values.gitea.admin.username .Values.gitea.admin.password }} + gitea admin create-user --username {{ .Values.gitea.admin.username }} --password '{{ .Values.gitea.admin.password }}' --email {{ .Values.gitea.admin.email }} --admin \ + || \ + gitea admin change-password --username {{ .Values.gitea.admin.username }} --password '{{ .Values.gitea.admin.password }}'; \ + {{- end }} + {{- if .Values.gitea.ldap.enabled }} + gitea admin auth add-ldap \ + --name {{ .Values.gitea.ldap.name | quote }} \ + --security-protocol {{ .Values.gitea.ldap.securityProtocol | quote }} \ + --host {{ .Values.gitea.ldap.host | quote }} \ + --port {{ .Values.gitea.ldap.port | int}} \ + --user-search-base {{ .Values.gitea.ldap.userSearchBase | quote }} \ + --user-filter {{ .Values.gitea.ldap.userFilter | quote }} \ + --admin-filter {{ .Values.gitea.ldap.adminFilter | quote }} \ + --email-attribute {{ .Values.gitea.ldap.emailAttribute | quote }} \ + --bind-dn {{ .Values.gitea.ldap.bindDn | quote }} \ + --bind-password {{ .Values.gitea.ldap.bindPassword | quote }} \ + --synchronize-users \ + --username-attribute {{ .Values.gitea.ldap.usernameAttribute | quote }} \ + || \ + ( \ + export GITEA_AUTH_ID=$(gitea admin auth list | grep {{ .Values.gitea.ldap.name | quote }} | awk -F " " "{print \$1}"); \ + gitea admin auth update-ldap --id ${GITEA_AUTH_ID} \ + --name {{ .Values.gitea.ldap.name | quote }} \ + --security-protocol {{ .Values.gitea.ldap.securityProtocol | quote }} \ + --host {{ .Values.gitea.ldap.host | quote }} \ + --port {{ .Values.gitea.ldap.port | int}} \ + --user-search-base {{ .Values.gitea.ldap.userSearchBase | quote }} \ + --user-filter {{ .Values.gitea.ldap.userFilter | quote }} \ + --admin-filter {{ .Values.gitea.ldap.adminFilter | quote }} \ + --email-attribute {{ .Values.gitea.ldap.emailAttribute | quote }} \ + --bind-dn {{ .Values.gitea.ldap.bindDn | quote }} \ + --bind-password {{ .Values.gitea.ldap.bindPassword | quote }} \ + --synchronize-users \ + --username-attribute {{ .Values.gitea.ldap.usernameAttribute | quote }} \ + ) \ + {{- end }} + ' + command: ["/bin/sh",'-c', *script] + volumeMounts: + - name: config + mountPath: /etc/gitea/conf + - name: data + mountPath: /data + terminationGracePeriodSeconds: {{ .Values.statefulset.terminationGracePeriodSeconds }} + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.version }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + # SSH Port values have to be set here as well for openssh configuration + - name: SSH_LISTEN_PORT + value: {{ .Values.gitea.config.server.SSH_LISTEN_PORT | quote }} + - name: SSH_PORT + value: {{ .Values.gitea.config.server.SSH_PORT | quote }} + ports: + - name: ssh + containerPort: {{ .Values.gitea.config.server.SSH_LISTEN_PORT }} + - name: http + containerPort: {{ .Values.gitea.config.server.HTTP_PORT }} + livenessProbe: + tcpSocket: + port: http + initialDelaySeconds: 200 + timeoutSeconds: 1 + periodSeconds: 10 + successThreshold: 1 + failureThreshold: 10 + readinessProbe: + tcpSocket: + port: http + initialDelaySeconds: 5 + periodSeconds: 10 + successThreshold: 1 + failureThreshold: 3 + resources: + {{- toYaml .Values.resources | nindent 12 }} + volumeMounts: + - name: data + mountPath: /data + {{- with .Values.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + {{- with .Values.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} + volumes: + - name: config + configMap: + name: {{ include "gitea.fullname" . }} + {{- if and .Values.persistence.enabled .Values.persistence.existingClaim }} + - name: data + persistentVolumeClaim: + claimName: {{ .Values.persistence.existingClaim }} + {{- else if not .Values.persistence.enabled }} + - name: data + emptyDir: {} + {{- else if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }} + volumeClaimTemplates: + - metadata: + name: data + spec: + accessModes: + {{- range .Values.persistence.accessModes }} + - {{ . | quote }} + {{- end }} + storageClassName: {{ .Values.persistence.storageClass | default "standard" | quote }} + resources: + requests: + storage: {{ .Values.persistence.size | quote }} + {{- end }} diff --git a/templates/ingress.yaml b/templates/ingress.yaml deleted file mode 100644 index 31a5b51..0000000 --- a/templates/ingress.yaml +++ /dev/null @@ -1,42 +0,0 @@ -{{- if .Values.ingress.enabled }} -apiVersion: {{ template "gitea.ingress.apiVersion" . }} -kind: Ingress -metadata: - name: {{ template "fullname" . }} - labels: - app: "{{ template "fullname" . }}" - chart: "{{ .Chart.Name }}-{{ .Chart.Version }}" - release: {{ .Release.Name | quote }} - heritage: {{ .Release.Service | quote }} - annotations: - {{- if .Values.ingress.certManager }} - kubernetes.io/tls-acme: "true" - {{- end }} - {{- range $key, $value := .Values.ingress.annotations }} - {{ $key }}: {{ $value | quote }} - {{- end }} -spec: - rules: - {{- if .Values.ingress.hostname }} - - host: {{ .Values.ingress.hostname }} - http: - paths: - - path: / - backend: - serviceName: {{ template "fullname" . }}-http - servicePort: {{ .Values.service.http.port }} - {{- end }} - {{- range .Values.ingress.hosts }} - - host: {{ .name }} - http: - paths: - - path: {{ default "/" .path }} - backend: - serviceName: "{{ template "fullname" $ }}-http" - servicePort: {{ $.Values.service.http.port }} - {{- end }} - {{- if .Values.ingress.tls }} - tls: -{{ toYaml .Values.ingress.tls | indent 4 }} - {{- end }} -{{- end }} diff --git a/templates/init/_container.tpl b/templates/init/_container.tpl deleted file mode 100644 index 6a02e84..0000000 --- a/templates/init/_container.tpl +++ /dev/null @@ -1,31 +0,0 @@ -{{/* -Create helm partial for gitea server -*/}} -{{- define "init" }} -- name: init - image: {{ .Values.images.gitea }} - imagePullPolicy: {{ .Values.images.pullPolicy }} - env: - - name: MARIADB_PASSWORD - valueFrom: - secretKeyRef: - {{- if .Values.mariadb.enabled }} - name: {{ template "mariadb.fullname" . }} - key: mariadb-password - {{- else }} - name: {{ printf "%s-%s" .Release.Name "externaldb" }} - key: db-password - {{- end }} - - name: SCRIPT - value: &script |- - mkdir -p /datatmp/gitea/conf - if [ ! -f /datatmp/gitea/conf/app.ini ]; then - sed "s/MARIADB_PASSWORD/${MARIADB_PASSWORD}/g" < /etc/gitea/app.ini > /datatmp/gitea/conf/app.ini - fi - command: ["/bin/sh",'-c', *script] - volumeMounts: - - name: gitea-data - mountPath: /datatmp - - name: gitea-config - mountPath: /etc/gitea -{{- end }} diff --git a/templates/memcached/_container.tpl b/templates/memcached/_container.tpl deleted file mode 100644 index 2472ad8..0000000 --- a/templates/memcached/_container.tpl +++ /dev/null @@ -1,35 +0,0 @@ -{{/* -Create helm partial for memcached -*/}} -{{- define "memcached" }} -- name: memcached - image: {{ .Values.images.memcached }} - imagePullPolicy: {{ .Values.images.pullPolicy }} - command: - - memcached - - -m {{ .Values.memcached.maxItemMemory }} - {{- if .Values.memcached.extendedOptions }} - - -o - - {{ .Values.memcached.extendedOptions }} - {{- end }} - {{- if .Values.memcached.verbosity }} - - -{{ .Values.memcached.verbosity }} - {{- end }} - ports: - - name: memcache - containerPort: 11211 - livenessProbe: - tcpSocket: - port: memcache - initialDelaySeconds: 30 - timeoutSeconds: 5 - readinessProbe: - tcpSocket: - port: memcache - initialDelaySeconds: 5 - timeoutSeconds: 1 - securityContext: - runAsUser: 1000 - resources: -{{ toYaml .Values.resources.memcached | indent 10 }} -{{- end }} diff --git a/templates/tests/test-connection.yaml b/templates/tests/test-connection.yaml new file mode 100644 index 0000000..2a5fd54 --- /dev/null +++ b/templates/tests/test-connection.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Pod +metadata: + name: "{{ include "gitea.fullname" . }}-test-connection" + labels: +{{ include "gitea.labels" . | nindent 4 }} + annotations: + "helm.sh/hook": test-success +spec: + containers: + - name: wget + image: busybox + command: ['wget'] + args: ['{{ include "gitea.fullname" . }}:{{ .Values.service.port }}'] + restartPolicy: Never diff --git a/values.yaml b/values.yaml index 85bc9a7..00d74c4 100644 --- a/values.yaml +++ b/values.yaml @@ -1,230 +1,131 @@ -## Gitea image -## ref: https://hub.docker.com/r/gitea/gitea/tags/ -## +# Default values for gitea. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. -tags: - mariadb: true +replicaCount: 1 -images: - registry: docker.io - gitea: "gitea/gitea:1.12.2" - memcached: "memcached:1.5.19-alpine" - pullPolicy: IfNotPresent - ## Optionally specify an array of imagePullSecrets. - ## Secrets must be manually created in the namespace. - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ - ## - # pullSecrets: - # - myRegistryKeySecretName +image: + repository: gitea/gitea + version: 1.12.3 + pullPolicy: Always -## Cache settings for memcache -memcached: - maxItemMemory: 64 - verbosity: v - extendedOptions: modern +imagePullSecrets: [] -## Configure the ingress resource that allows you to access the -## Gitea installation. Set up the URL -## ref: http://kubernetes.io/docs/user-guide/ingress/ -## -ingress: - ## Set to true to enable ingress record generation - enabled: true - - ## Set this to true in order to add the corresponding annotations for cert-manager - certManager: false - - ## When the ingress is enabled, a host pointing to this will be created - hostname: gitea.local - - ## Ingress annotations done as key:value pairs - ## For a full list of possible ingress annotations, please see - ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md - ## - ## If tls is set to true, annotation ingress.kubernetes.io/secure-backends: "true" will automatically be set - ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set - annotations: {} - # certmanager.k8s.io/cluster-issuer: letsencrypt-prod - # kubernetes.io/ingress.class: nginx - - ## The list of additional hostnames to be covered with this ingress record. - ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array - # hosts: - # - name: gitea.local - # path: / - - ## The tls configuration for the ingress - ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls - ## Uncomment below to enable tls / https for let's encrypt / cert-manager - # tls: - # - hosts: - # - gitea.local - # secretName: gitea.tls - - secrets: - ## If you're providing your own certificates, please use this to add the certificates as secrets - ## key and certificate should start with -----BEGIN CERTIFICATE----- or - ## -----BEGIN RSA PRIVATE KEY----- - ## - ## name should line up with a tlsSecret set further up - ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set - ## - ## It is also possible to create and manage the certificates outside of this helm chart - ## Please see README.md for more information - # - name: gitea.local-tls - # key: - # certificate: - # - -## This chart defaults to using an ingress for http, but change to LoadBalancer if using you cluster supports it service: - - ## This can stay as ClusterIP as (by default) we use ingress http: - serviceType: ClusterIP + type: ClusterIP port: 3000 - ## Make the external port available - # externalPort: 8280 - # externalHost: gitea.local - - ## SSH is commonly on port 22.. however.. you most likely already have port 22 being used by your node. - ## so we use port 8022. ssh: - serviceType: LoadBalancer + type: ClusterIP port: 22 - #nodePort: 30222 - ## If serving on a different external port used for determining the ssh url in the gui - externalPort: 8022 - externalHost: gitea.local - externalIPs: [] + #loadBalancerIP: + #nodePort: + annotations: -## Configure resource requests and limits -## ref: http://kubernetes.io/docs/user-guide/compute-resources/ -## -resources: - gitea: - requests: - memory: 500Mi - cpu: 1000m - limits: - memory: 2Gi - cpu: 1 - memcached: - requests: - memory: 64Mi - cpu: 50m - -## Update strategy - for deployments with RWO PVs attached and with a -## single replicas = 1, an update can get stuck, as the previous pod -## remains attached to the PVC. Changing the strategy to "Recreate" -## will terminate the single previous pod, so that the new, incoming -## pod can attach to the PV -# deploymentStrategy: -# rollingUpdate: -# type: "Recreate" -# type: "RollingUpdate" -# maxSurge: 1 -# maxUnavailable: 1 - -## Enable persistence using Persistent Volume Claims -## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ -## ref: -## -persistence: +ingress: enabled: false - # existingGiteaClaim: gitea-gitea - giteaSize: 10Gi - # storageClass: glusterfs - accessMode: ReadWriteMany - ## addtional annotations for PVCs. Uncommenting will prevent the PVC from being deleted. - annotations: - "helm.sh/resource-policy": keep + annotations: {} + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: "true" + hosts: + - git.example.com + tls: [] + # - secretName: chart-example-tls + # hosts: + # - git.example.com -## if you want to mount a volume directly without using a storageClass or pvcs -# directGiteaVolumeMount: -# glusterfs: -# endpoints: "192.168.1.1 192.168.1.2 192.168.1.3" -# path: giteaData -# directPostgresVolumeMount: -# glusterfs: -# endpoints: "192.168.1.1 192.168.1.2 192.168.1.3" -# path: giteaPostgresData +resources: {} + # We usually recommend not to specify default resources and to leave this as a conscious + # choice for the user. This also increases chances charts run on environments with little + # resources, such as Minikube. If you do want to specify resources, uncomment the following + # lines, adjust them as necessary, and remove the curly braces after 'resources:'. + # limits: + # cpu: 100m + # memory: 128Mi + # requests: + # cpu: 100m + # memory: 128Mi - - -## -## MariaDB chart configuration -## -## https://github.com/helm/charts/blob/master/stable/mariadb/values.yaml -## -mariadb: - ## Whether to deploy a mariadb server to satisfy the applications database requirements. To use an external database set this to false and configure the externalDatabase parameters - enabled: true - ## Disable MariaDB replication - replication: - enabled: false - - ## Create a database and a database user - ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run - ## - db: - name: gitea - user: gitea - ## If the password is not specified, mariadb will generates a random password - ## - # password: ThisIsMySuperSecretPassword - - ## MariaDB admin password - ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#setting-the-root-password-on-first-run - ## - rootUser: - # password: ThisIsMySuperSecretPassword - - ## Enable persistence using Persistent Volume Claims - ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ - ## - master: - persistence: - enabled: false - ## mariadb data Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - # storageClass: "-" - accessMode: ReadWriteOnce - size: 8Gi - -## Connect to an external database instead -# externalDB: -# dbUser: "postgres" -# dbPassword: "" -# dbHost: "service-name.namespace.svc.cluster.local" # or some external host -# dbPort: "5432" -# dbDatabase: "gitea" - - -## Actual Gitea configuration (modified the default .ini file for Gitea) -## This will skip the initial installation screen. You must have a secretKey already defined -## and disableInstaller set to True -config: -## secretKey: ThisIsMySuperSecretKeyThatsUsedInterally - disableInstaller: false - offlineMode: false - requireSignin: false - disableRegistration: false - openidSignin: true - -## Common helm annotations -## Node labels and tolerations for pod assignment -## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector -## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#taints-and-tolerations-beta-feature nodeSelector: {} + tolerations: [] + affinity: {} -## Annotations for the deployment and pods. -deploymentAnnotations: {} -podAnnotations: {} +statefulset: + terminationGracePeriodSeconds: 60 + +persistence: + enabled: true + # existingClaim: + size: 10Gi + accessModes: + - ReadWriteOnce + storageClass: standard + +gitea: + admin: + username: gitea_admin + password: r8sA8CPHD9!bt6d + email: "gitea@local.domain" + + ldap: + enabled: false + name: "" + securityProtocol: "" + host: "" + port: "" + userSearchBase: "" + userFilter: "" + adminFilter: "" + emailAttribute: "" + bindDn: "" + bindPassword: "" + usernameAttribute: "" + + config: {} + # APP_NAME: "Gitea: Git with a cup of tea" + # RUN_MODE: dev + # + # server: + # SSH_PORT: 22 + # + # security: + # PASSWORD_COMPLEXITY: spec + + database: + builtIn: + postgresql: + enabled: true + mysql: + enabled: false + + cache: + builtIn: + enabled: true + +memcached: + service: + port: 11211 + +postgresql: + global: + postgresql: + postgresqlDatabase: gitea + postgresqlUsername: gitea + postgresqlPassword: gitea + servicePort: 5432 + persistence: + size: 10Gi + +mysql: + root: + password: gitea + db: + user: gitea + password: gitea + name: gitea + service: + port: 3306 + persistence: + size: 10Gi