diff --git a/charts/incubator/grist/Chart.yaml b/charts/incubator/grist/Chart.yaml new file mode 100644 index 00000000000..fd81bdc69c3 --- /dev/null +++ b/charts/incubator/grist/Chart.yaml @@ -0,0 +1,29 @@ +apiVersion: v2 +appVersion: "10.6.2" +dependencies: +- name: common + repository: https://truecharts.org + version: 8.16.0 +description: Grist is a modern relational spreadsheet. It combine the flexibility of a spreadsheet with the robustness of a database to organize your data. +home: https://github.com/truecharts/apps/tree/master/charts/stable/grist +icon: https://truecharts.org/_static/img/appicons/grist-icon.png +keywords: +- grist +- spreadsheet +- database +kubeVersion: '>=1.16.0-0' +maintainers: +- email: info@truecharts.org + name: TrueCharts + url: https://truecharts.org +name: grist +sources: +- https://hub.docker.com/r/gristlabs/grist +- https://github.com/gristlabs/grist-core +- https://support.getgrist.com/ +version: 0.0.1 +annotations: + truecharts.org/catagories: | + - productivity + truecharts.org/SCALE-support: "true" + truecharts.org/grade: U diff --git a/charts/incubator/grist/questions.yaml b/charts/incubator/grist/questions.yaml new file mode 100644 index 00000000000..611c23aa1bb --- /dev/null +++ b/charts/incubator/grist/questions.yaml @@ -0,0 +1,503 @@ +# Include{groups} +portals: + open: + protocols: + - "$kubernetes-resource_configmap_portal_protocol" + host: + - "$kubernetes-resource_configmap_portal_host" + ports: + - "$kubernetes-resource_configmap_portal_port" +questions: + - variable: portal + group: "Container Image" + label: "Configure Portal Button" + schema: + type: dict + hidden: true + attrs: + - variable: enabled + label: "Enable" + description: "enable the portal button" + schema: + hidden: true + editable: false + type: boolean + default: true +# Include{global} + - variable: controller + group: "Controller" + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: advanced + label: "Show Advanced Controller Settings" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: type + description: "Please specify type of workload to deploy" + label: "(Advanced) Controller Type" + schema: + type: string + default: "deployment" + required: true + enum: + - value: "deployment" + description: "Deployment" + - value: "statefulset" + description: "Statefulset" + - value: "daemonset" + description: "Daemonset" + - variable: replicas + description: "Number of desired pod replicas" + label: "Desired Replicas" + schema: + type: int + default: 1 + required: true + - variable: strategy + description: "Please specify type of workload to deploy" + label: "(Advanced) Update Strategy" + schema: + type: string + default: "Recreate" + required: true + enum: + - value: "Recreate" + description: "Recreate: Kill existing pods before creating new ones" + - value: "RollingUpdate" + description: "RollingUpdate: Create new pods and then kill old ones" + - value: "OnDelete" + description: "(Legacy) OnDelete: ignore .spec.template changes" +# Include{controllerExpert} + # Docker specific env + - variable: env + group: "Container Configuration" + label: "Image Environment" + schema: + additional_attrs: true + type: dict + attrs: +# Include{fixedEnv} + - variable: GRIST_DEFAULT_EMAIL + label: "GRIST_DEFAULT_EMAIL" + description: "If set, login as this user if no other credentials presented" + schema: + type: string + default: "" + - variable: GRIST_DOMAIN + label: "GRIST_DOMAIN" + description: "In hosted Grist, Grist is served from subdomains of this domain" + schema: + type: string + default: "" + - variable: GRIST_SUPPORT_ANON + label: "GRIST_SUPPORT_ANON" + description: "If set to true, show UI for anonymous access." + schema: + type: boolean + default: false + - variable: GRIST_THROTTLE_CPU + label: "GRIST_THROTTLE_CPU" + description: "If set, CPU throttling is enabled" + schema: + type: boolean + default: false + - variable: GRIST_BACKUP_DELAY_SECS + label: "GRIST_BACKUP_DELAY_SECS" + description: "Wait this long after a doc change before making a backup" + schema: + type: int + default: 15 + - variable: ALLOWED_WEBHOOK_DOMAINS + label: "ALLOWED_WEBHOOK_DOMAINS" + description: "Comma-separated list of permitted domains to use in webhooks" + schema: + type: string + default: "" + - variable: enabledsandbox + label: "Sandbox" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: GRIST_SANDBOX_FLAVOR + label: "GRIST_SANDBOX_FLAVOR" + description: "If set, forces Grist to use the specified kind of sandbox." + schema: + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "pynbox" + description: "pynbox" + - value: "unsandboxed" + description: "unsandboxed" + - value: "docker" + description: "docker" + - value: "macSandboxExec" + description: "macSandboxExec" + - variable: GRIST_SANDBOX + label: "GRIST_SANDBOX" + description: "A program or image name to run as the sandbox. See NSandbox.ts for nerdy details." + schema: + type: string + default: "" + - variable: PYTHON_VERSION + label: "PYTHON_VERSION" + description: "If set, documents without an engine setting are assumed to use the specified version of python. Not all sandboxes support all versions." + schema: + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "2" + description: "2" + - value: "3" + description: "3" + - variable: PYTHON_VERSION_ON_CREATION + label: "PYTHON_VERSION_ON_CREATION" + description: "If set, newly created documents have an engine setting set to python2 or python3. Not all sandboxes support all versions." + schema: + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "2" + description: "2" + - value: "3" + description: "3" + - variable: secret + group: "Container Configuration" + label: "Secret Image Environment" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabledgdrive + label: "Google Drive Integration" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: GOOGLE_CLIENT_ID + label: "GOOGLE_CLIENT_ID" + description: "Set to the Google Client Id to be used with Google API client" + schema: + type: string + default: "" + - variable: GOOGLE_CLIENT_SECRET + label: "GOOGLE_CLIENT_SECRET" + description: "Set to the Google Client Secret to be used with Google API client" + schema: + type: string + private: true + default: "" + - variable: GOOGLE_API_KEY + label: "GOOGLE_API_KEY" + description: "Set to the Google API Key to be used with Google API client (accessing public files)" + schema: + type: string + private: true + default: "" + - variable: GOOGLE_DRIVE_SCOPE + label: "GOOGLE_DRIVE_SCOPE" + description: "Set to the scope requested for Google Drive integration (defaults to drive.file)" + schema: + type: string + private: true + default: "" + +# Include{containerConfig} + + - variable: service + group: "Networking and Services" + label: "Configure Service(s)" + schema: + additional_attrs: true + type: dict + attrs: + - variable: main + label: "Main Service" + description: "The Primary service on which the healthcheck runs, often the webUI" + schema: + additional_attrs: true + type: dict + attrs: +# Include{serviceSelector} + - variable: main + label: "Main Service Port Configuration" + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: "Port" + description: "This port exposes the container port on the service" + schema: + type: int + default: 10163 + required: true + - variable: advanced + label: "Show Advanced settings" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: protocol + label: "Port Type" + schema: + type: string + default: "HTTP" + enum: + - value: HTTP + description: "HTTP" + - value: "HTTPS" + description: "HTTPS" + - value: TCP + description: "TCP" + - value: "UDP" + description: "UDP" + - variable: nodePort + label: "Node Port (Optional)" + description: "This port gets exposed to the node. Only considered when service type is NodePort, Simple or LoadBalancer" + schema: + type: int + min: 9000 + max: 65535 + - variable: targetPort + label: "Target Port" + description: "The internal(!) port on the container the Application runs on" + schema: + type: int + default: 10163 + - variable: api + label: "API Service" + description: "API service" + schema: + additional_attrs: true + type: dict + attrs: +# Include{serviceSelector} + - variable: api + label: "API Service Port Configuration" + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: "Port" + description: "This port exposes the container port on the service" + schema: + type: int + default: 10164 + required: true + - variable: advanced + label: "Show Advanced settings" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: protocol + label: "Port Type" + schema: + type: string + default: "HTTP" + enum: + - value: HTTP + description: "HTTP" + - value: "HTTPS" + description: "HTTPS" + - value: TCP + description: "TCP" + - value: "UDP" + description: "UDP" + - variable: nodePort + label: "Node Port (Optional)" + description: "This port gets exposed to the node. Only considered when service type is NodePort, Simple or LoadBalancer" + schema: + type: int + min: 9000 + max: 65535 + - variable: targetPort + label: "Target Port" + description: "The internal(!) port on the container the Application runs on" + schema: + type: int + default: 10164 + + - variable: serviceexpert + group: "Networking and Services" + label: "Show Expert Config" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: hostNetwork + group: "Networking and Services" + label: "Host-Networking (Complicated)" + schema: + type: boolean + default: false + +# Include{serviceExpert} + +# Include{serviceList} + + - variable: persistence + label: "Integrated Persistent Storage" + description: "Integrated Persistent Storage" + group: "Storage and Persistence" + schema: + additional_attrs: true + type: dict + attrs: + - variable: persist + label: "App Persist Storage" + description: "Stores the Application Persist." + schema: + additional_attrs: true + type: dict + attrs: + - variable: type + label: "Type of Storage" + description: "Sets the persistence type, Anything other than PVC could break rollback!" + schema: + type: string + default: "simplePVC" + enum: + - value: "simplePVC" + description: "PVC (simple)" + - value: "simpleHP" + description: "HostPath (simple)" + - value: "emptyDir" + description: "emptyDir" + - value: "pvc" + description: "pvc" + - value: "hostPath" + description: "hostPath" +# Include{persistenceBasic} + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" +# Include{persistenceAdvanced} + +# Include{persistenceList} + + - variable: ingress + label: "" + group: "Ingress" + schema: + additional_attrs: true + type: dict + attrs: + - variable: main + label: "Main Ingress" + schema: + additional_attrs: true + type: dict + attrs: +# Include{ingressDefault} + +# Include{ingressTLS} + +# Include{ingressTraefik} + +# Include{ingressExpert} + +# Include{ingressList} + + - variable: advancedSecurity + label: "Show Advanced Security Settings" + group: "Security and Permissions" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: securityContext + label: "Security Context" + schema: + additional_attrs: true + type: dict + attrs: + - variable: privileged + label: "Privileged mode" + schema: + type: boolean + default: false + - variable: readOnlyRootFilesystem + label: "ReadOnly Root Filesystem" + schema: + type: boolean + default: false + - variable: allowPrivilegeEscalation + label: "Allow Privilege Escalation" + schema: + type: boolean + default: false + - variable: runAsNonRoot + label: "runAsNonRoot" + schema: + type: boolean + default: false +# Include{securityContextAdvanced} + + - variable: podSecurityContext + group: "Security and Permissions" + label: "Pod Security Context" + schema: + additional_attrs: true + type: dict + attrs: + - variable: runAsUser + label: "runAsUser" + description: "The UserID of the user running the application" + schema: + type: int + default: 0 + - variable: runAsGroup + label: "runAsGroup" + description: The groupID this App of the user running the application" + schema: + type: int + default: 0 + - variable: fsGroup + label: "fsGroup" + description: "The group that should own ALL storage." + schema: + type: int + default: 568 +# Include{podSecurityContextAdvanced} + +# Include{resources} + +# Include{advanced} + +# Include{addons} diff --git a/charts/incubator/grist/templates/common.yaml b/charts/incubator/grist/templates/common.yaml new file mode 100644 index 00000000000..a6613c2ce21 --- /dev/null +++ b/charts/incubator/grist/templates/common.yaml @@ -0,0 +1 @@ +{{ include "common.all" . }} diff --git a/charts/incubator/grist/values.yaml b/charts/incubator/grist/values.yaml new file mode 100644 index 00000000000..6756b939f2e --- /dev/null +++ b/charts/incubator/grist/values.yaml @@ -0,0 +1,45 @@ +image: + repository: gristlabs/grist + tag: latest@sha256:f28bc8762e602d5a4c0ef368ee3c8abe7b26bc4b90c7ad4ebc21e7b3ac7b3e70 + pullPolicy: IfNotPresent + +securityContext: + readOnlyRootFilesystem: false + runAsNonRoot: false + +podSecurityContext: + runAsUser: 0 + runAsGroup: 0 + +env: + PORT: "{{ .Values.service.main.ports.main.port }}" + HOME_PORT: "{{ .Values.service.api.ports.api.port }}" + GRIST_DEFAULT_EMAIL: "user@mydomain.com" + +# https://github.com/gristlabs/grist-core/issues/128 +# envValueFrom: +# REDIS_URL: +# secretKeyRef: +# name: rediscreds +# key: url + +service: + main: + ports: + main: + port: 10163 + targetPort: 10163 + api: + ports: + api: + port: 10164 + targetPort: 10164 + +persistence: + persist: + enabled: true + mountPath: "/persist" + +# redis: +# enabled: true +# existingSecret: "rediscreds" diff --git a/docs/_static/img/appicons/grist-icon.png b/docs/_static/img/appicons/grist-icon.png new file mode 100644 index 00000000000..db33b9d1546 Binary files /dev/null and b/docs/_static/img/appicons/grist-icon.png differ diff --git a/docs/manual/default-ports.md b/docs/manual/default-ports.md index dc9b8eb9c97..ae7df96297f 100644 --- a/docs/manual/default-ports.md +++ b/docs/manual/default-ports.md @@ -320,6 +320,8 @@ These defaults can of course be changed, but as we guarantee "sane, working defa | linkace | main | main | 10160 | TCP | | | librephotos | main | main | 10161 | TCP | | | pydio-cells | healthcheck | healthcheck | 10162 | TCP | | +| grist | main | main | 10163 | TCP | | +| grist | api | api | 10164 | TCP | | | satisfactory | beacon | beacon | 15000 | UDP | | | satisfactory | query | query | 15777 | UDP | | | minecraft-bedrock | main | main | 19132 | UDP | |