(feat) Add Gitea (#1061)
* Initial Gitea App * use the correct nodeport and document ports
This commit is contained in:
@@ -0,0 +1,24 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
|
# OWNERS file for Kubernetes
|
||||||
|
OWNERS
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
appVersion: "1.15.3"
|
||||||
|
dependencies:
|
||||||
|
- name: common
|
||||||
|
repository: https://truecharts.org
|
||||||
|
version: 8.0.13
|
||||||
|
- condition: postgresql.enabled
|
||||||
|
name: postgresql
|
||||||
|
repository: https://truecharts.org/
|
||||||
|
version: 3.0.4
|
||||||
|
- condition: memcached.enabled
|
||||||
|
name: memcached
|
||||||
|
repository: https://charts.bitnami.com/bitnami
|
||||||
|
version: 5.15.3
|
||||||
|
deprecated: false
|
||||||
|
description: Self hosted GIT repositories
|
||||||
|
home: https://github.com/truecharts/apps/tree/master/charts/stable/gitea
|
||||||
|
icon: https://docs.gitea.io/images/gitea.png
|
||||||
|
keywords:
|
||||||
|
- git
|
||||||
|
- issue tracker
|
||||||
|
- code review
|
||||||
|
- wiki
|
||||||
|
- gitea
|
||||||
|
- gogs
|
||||||
|
kubeVersion: '>=1.16.0-0'
|
||||||
|
maintainers:
|
||||||
|
- email: info@truecharts.org
|
||||||
|
name: TrueCharts
|
||||||
|
url: truecharts.org
|
||||||
|
name: gitea
|
||||||
|
sources:
|
||||||
|
- https://gitea.com/gitea/helm-chart
|
||||||
|
- https://github.com/go-gitea/gitea
|
||||||
|
- https://hub.docker.com/r/gitea/gitea/
|
||||||
|
type: application
|
||||||
|
version: 0.0.1
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
categories:
|
||||||
|
- GIT
|
||||||
|
icon_url: https://docs.gitea.io/images/gitea.png
|
||||||
@@ -0,0 +1,122 @@
|
|||||||
|
##
|
||||||
|
# This file contains Values.yaml content that gets added to the output of questions.yaml
|
||||||
|
# It's ONLY meant for content that the user is NOT expected to change.
|
||||||
|
# Example: Everything under "image" is not included in questions.yaml but is included here.
|
||||||
|
##
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: gitea/gitea
|
||||||
|
tag: 1.15.3-rootless
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
postgresqlImage:
|
||||||
|
repository: bitnami/postgresql
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: 13.4.0@sha256:33c276dffe6140d32f357753993c4088cf945a2d02d4c20d310f5a5e9d6e4a36
|
||||||
|
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-env
|
||||||
|
|
||||||
|
initContainers:
|
||||||
|
0-init-postgresdb:
|
||||||
|
image: "{{ .Values.postgresqlImage.repository}}:{{ .Values.postgresqlImage.tag }}"
|
||||||
|
command:
|
||||||
|
- "sh"
|
||||||
|
- "-c"
|
||||||
|
- "until pg_isready -U gitea -h ${pghost} ; do sleep 2 ; done"
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
env:
|
||||||
|
- name: pghost
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: dbcreds
|
||||||
|
key: plainhost
|
||||||
|
1-init-directories:
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
command: ["/usr/sbin/init_directory_structure.sh"]
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
runAsNonRoot: false
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-env
|
||||||
|
volumeMounts:
|
||||||
|
- name: init
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: config
|
||||||
|
mountPath: /etc/gitea/conf
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
2-configure-gitea:
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
command: ["/usr/sbin/configure_gitea.sh"]
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-env
|
||||||
|
volumeMounts:
|
||||||
|
- name: init
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
|
||||||
|
# Configure commit/action signing prerequisites
|
||||||
|
signing:
|
||||||
|
enabled: true
|
||||||
|
gpgHome: /data/git/.gnupg
|
||||||
|
|
||||||
|
metrics:
|
||||||
|
enabled: false
|
||||||
|
serviceMonitor:
|
||||||
|
enabled: false
|
||||||
|
# additionalLabels:
|
||||||
|
# prometheus-release: prom1
|
||||||
|
|
||||||
|
ldap:
|
||||||
|
enabled: false
|
||||||
|
# name:
|
||||||
|
# securityProtocol:
|
||||||
|
# host:
|
||||||
|
# port:
|
||||||
|
# userSearchBase:
|
||||||
|
# userFilter:
|
||||||
|
# adminFilter:
|
||||||
|
# emailAttribute:
|
||||||
|
# bindDn:
|
||||||
|
# bindPassword:
|
||||||
|
# usernameAttribute:
|
||||||
|
# sshPublicKeyAttribute:
|
||||||
|
|
||||||
|
oauth:
|
||||||
|
enabled: false
|
||||||
|
# name:
|
||||||
|
# provider:
|
||||||
|
# key:
|
||||||
|
# secret:
|
||||||
|
# autoDiscoverUrl:
|
||||||
|
# useCustomUrls:
|
||||||
|
# customAuthUrl:
|
||||||
|
# customTokenUrl:
|
||||||
|
# customProfileUrl:
|
||||||
|
# customEmailUrl:
|
||||||
|
|
||||||
|
# Enabled postgres
|
||||||
|
postgresql:
|
||||||
|
enabled: true
|
||||||
|
postgresqlUsername: gitea
|
||||||
|
postgresqlDatabase: gitea
|
||||||
|
existingSecret: dbcreds
|
||||||
|
|
||||||
|
# -- memcached dependency settings
|
||||||
|
memcached:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
|
||||||
|
##
|
||||||
|
# Most other defaults are set in questions.yaml
|
||||||
|
# For other options please refer to the wiki, default_values.yaml or the common library chart
|
||||||
|
##
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,24 @@
|
|||||||
|
{{/* Define the configmap */}}
|
||||||
|
{{- define "gitea.configmap" -}}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: gitea-env
|
||||||
|
data:
|
||||||
|
GITEA_APP_INI: "/data/gitea/conf/app.ini"
|
||||||
|
GITEA_CUSTOM: "/data/gitea"
|
||||||
|
GITEA_WORK_DIR: "/data"
|
||||||
|
GITEA_TEMP: "/tmp/gitea"
|
||||||
|
GITEA_ADMIN_USERNAME: {{ .Values.admin.username }}
|
||||||
|
GITEA_ADMIN_PASSWORD: {{ .Values.admin.password }}
|
||||||
|
SSH_PORT: {{ .Values.service.ssh.ports.ssh.port | quote }}
|
||||||
|
SSH_LISTEN_PORT: {{ .Values.service.ssh.ports.ssh.targetPort | quote }}
|
||||||
|
GITEA_APP_INI: "/data/gitea/conf/app.ini"
|
||||||
|
GITEA_CUSTOM: "/data/gitea"
|
||||||
|
GITEA_WORK_DIR: "/data"
|
||||||
|
GITEA_TEMP: "/tmp/gitea"
|
||||||
|
TMPDIR: "/tmp/gitea"
|
||||||
|
GNUPGHOME: "/data/git/.gnupg"
|
||||||
|
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,270 @@
|
|||||||
|
{{/* Define the secrets */}}
|
||||||
|
{{- define "gitea.secrets" -}}
|
||||||
|
---
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "common.labels" . | nindent 4 }}
|
||||||
|
name: dbcreds
|
||||||
|
{{- $dbprevious := lookup "v1" "Secret" .Release.Namespace "dbcreds" }}
|
||||||
|
{{- $dbPass := "" }}
|
||||||
|
data:
|
||||||
|
{{- if $dbprevious }}
|
||||||
|
{{- $dbPass = ( index $dbprevious.data "postgresql-password" ) | b64dec }}
|
||||||
|
postgresql-password: {{ ( index $dbprevious.data "postgresql-password" ) }}
|
||||||
|
postgresql-postgres-password: {{ ( index $dbprevious.data "postgresql-postgres-password" ) }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $dbPass = randAlphaNum 50 }}
|
||||||
|
postgresql-password: {{ $dbPass | b64enc | quote }}
|
||||||
|
postgresql-postgres-password: {{ randAlphaNum 50 | b64enc | quote }}
|
||||||
|
{{- end }}
|
||||||
|
url: {{ ( printf "%v%v:%v@%v-%v:%v/%v" "postgresql://" .Values.postgresql.postgresqlUsername $dbPass .Release.Name "postgresql" "5432" .Values.postgresql.postgresqlDatabase ) | b64enc | quote }}
|
||||||
|
plainhost: {{ ( printf "%v-%v" .Release.Name "postgresql" ) | b64enc | quote }}
|
||||||
|
type: Opaque
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
{{- $DOMAIN := ( printf "%s-gitea.%s.svc.%s" .Release.Name .Release.Namespace "cluster.local" | quote ) -}}
|
||||||
|
{{- if and ( .Values.ingress.main.enabled ) ( gt (len .Values.ingress.main.hosts) 0 ) -}}
|
||||||
|
{{- $DOMAIN = (index .Values.ingress.main.hosts 0).host -}}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "common.labels" . | nindent 4 }}
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
app.ini: |-
|
||||||
|
APP_NAME = {{ .Values.config.APP_NAME }}
|
||||||
|
RUN_MODE = {{ .Values.config.RUN_MODE }}
|
||||||
|
|
||||||
|
[cache]
|
||||||
|
ADAPTER = memcache
|
||||||
|
ENABLED = true
|
||||||
|
HOST = {{ printf "%v-%v:%v" .Release.Name "memcached" "11211" }}
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if eq $catvalue.name "cache" }}
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
[database]
|
||||||
|
DB_TYPE = postgres
|
||||||
|
HOST = {{ printf "%v-%v:%v" .Release.Name "postgresql" "5432" }}
|
||||||
|
NAME = {{ .Values.postgresql.postgresqlDatabase }}
|
||||||
|
PASSWD = {{ $dbPass }}
|
||||||
|
USER = {{ .Values.postgresql.postgresqlUsername }}
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if eq $catvalue.name "database" }}
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
[metrics]
|
||||||
|
ENABLED = {{ .Values.metrics.enabled }}
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if eq $catvalue.name "metrics" }}
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
[repository]
|
||||||
|
ROOT = /data/git/gitea-repositories
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if eq $catvalue.name "repository" }}
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
|
||||||
|
[security]
|
||||||
|
INSTALL_LOCK = true
|
||||||
|
PASSWORD_COMPLEXITY = spec
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if eq $catvalue.name "security" }}
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
[server]
|
||||||
|
APP_DATA_PATH = /data
|
||||||
|
DOMAIN = {{ $DOMAIN }}
|
||||||
|
ENABLE_PPROF = false
|
||||||
|
HTTP_PORT = {{ .Values.service.main.ports.main.port }}
|
||||||
|
PROTOCOL = http
|
||||||
|
{{- if and ( .Values.ingress.main.enabled ) ( gt (len .Values.ingress.main.hosts) 0 ) }}
|
||||||
|
ROOT_URL = {{ printf "https://%s" $DOMAIN }}
|
||||||
|
{{- else }}
|
||||||
|
ROOT_URL = {{ printf "http://%s" $DOMAIN }}
|
||||||
|
{{- end }}
|
||||||
|
SSH_DOMAIN = {{ $DOMAIN }}
|
||||||
|
SSH_LISTEN_PORT = {{ .Values.service.ssh.ports.ssh.targetPort }}
|
||||||
|
SSH_PORT = {{ .Values.service.ssh.ports.ssh.port }}
|
||||||
|
START_SSH_SERVER = true
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if eq $catvalue.name "server" }}
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- range $catindex, $catvalue := .Values.customConfig }}
|
||||||
|
{{- if not ( or ( eq $catvalue.name "server" ) ( eq $catvalue.name "server" ) ( eq $catvalue.name "security" ) ( eq $catvalue.name "repository" ) ( eq $catvalue.name "metrics" ) ( eq $catvalue.name "database" ) ( eq $catvalue.name "cache" ) ) }}
|
||||||
|
[{{ $catvalue.name }}]
|
||||||
|
{{- range $index, $value := $catvalue.keys }}
|
||||||
|
{{ $value.name }} = {{ $value.value }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ include "common.names.fullname" . }}-init
|
||||||
|
labels:
|
||||||
|
{{- include "common.labels" . | nindent 4 }}
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
init_directory_structure.sh: |-
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
{{- if .Values.initPreScript }}
|
||||||
|
# BEGIN: initPreScript
|
||||||
|
{{- with .Values.initPreScript -}}
|
||||||
|
{{ . | nindent 4}}
|
||||||
|
{{- end -}}
|
||||||
|
# END: initPreScript
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
set -x
|
||||||
|
|
||||||
|
mkdir -p /data/git/.ssh
|
||||||
|
chmod -R 700 /data/git/.ssh
|
||||||
|
[ ! -d /data/gitea ] && mkdir -p /data/gitea/conf
|
||||||
|
|
||||||
|
# prepare temp directory structure
|
||||||
|
mkdir -p "${GITEA_TEMP}"
|
||||||
|
chown -Rf {{ .Values.podSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} "${GITEA_TEMP}"
|
||||||
|
chmod ug+rwx "${GITEA_TEMP}"
|
||||||
|
|
||||||
|
# Copy config file to writable volume
|
||||||
|
cp /etc/gitea/conf/app.ini /data/gitea/conf/app.ini
|
||||||
|
chown -Rf {{ .Values.podSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} "/data/gitea"
|
||||||
|
chmod a+rwx /data/gitea/conf/app.ini
|
||||||
|
|
||||||
|
# Patch dockercontainer for dynamic users
|
||||||
|
chown -Rf {{ .Values.podSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }} "/var/lib/gitea"
|
||||||
|
|
||||||
|
configure_gitea.sh: |-
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
|
||||||
|
# Connection retry inspired by https://gist.github.com/dublx/e99ea94858c07d2ca6de
|
||||||
|
function test_db_connection() {
|
||||||
|
local RETRY=0
|
||||||
|
local MAX=30
|
||||||
|
|
||||||
|
echo 'Wait for database to become avialable...'
|
||||||
|
until [ "${RETRY}" -ge "${MAX}" ]; do
|
||||||
|
nc -vz -w2 {{ printf "%v-%v" .Release.Name "postgresql" }} 5432 && break
|
||||||
|
RETRY=$[${RETRY}+1]
|
||||||
|
echo "...not ready yet (${RETRY}/${MAX})"
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "${RETRY}" -ge "${MAX}" ]; then
|
||||||
|
echo "Database not reachable after '${MAX}' attempts!"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
test_db_connection
|
||||||
|
|
||||||
|
|
||||||
|
echo '==== BEGIN GITEA MIGRATION ===='
|
||||||
|
|
||||||
|
gitea migrate
|
||||||
|
|
||||||
|
echo '==== BEGIN GITEA CONFIGURATION ===='
|
||||||
|
|
||||||
|
{{- if or .Values.admin.existingSecret (and .Values.admin.username .Values.admin.password) }}
|
||||||
|
function configure_admin_user() {
|
||||||
|
local ACCOUNT_ID=$(gitea admin user list --admin | grep -e "\s\+${GITEA_ADMIN_USERNAME}\s\+" | awk -F " " "{printf \$1}")
|
||||||
|
if [[ -z "${ACCOUNT_ID}" ]]; then
|
||||||
|
echo "No admin user '${GITEA_ADMIN_USERNAME}' found. Creating now..."
|
||||||
|
gitea admin user create --admin --username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}" --email {{ .Values.admin.email | quote }} --must-change-password=false
|
||||||
|
echo '...created.'
|
||||||
|
else
|
||||||
|
echo "Admin account '${GITEA_ADMIN_USERNAME}' already exist. Running update to sync password..."
|
||||||
|
gitea admin user change-password --username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}"
|
||||||
|
echo '...password sync done.'
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
configure_admin_user
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if .Values.ldap.enabled }}
|
||||||
|
function configure_ldap() {
|
||||||
|
local LDAP_NAME={{ (printf "%s" .Values.ldap.name) | squote }}
|
||||||
|
local GITEA_AUTH_ID=$(gitea admin auth list --vertical-bars | grep -E "\|${LDAP_NAME}\s+\|" | grep -iE '\|LDAP \(via BindDN\)\s+\|' | awk -F " " "{print \$1}")
|
||||||
|
|
||||||
|
if [[ -z "${GITEA_AUTH_ID}" ]]; then
|
||||||
|
echo "No ldap configuration found with name '${LDAP_NAME}'. Installing it now..."
|
||||||
|
gitea admin auth add-ldap {{- include "gitea.ldap_settings" . | indent 1 }}
|
||||||
|
echo '...installed.'
|
||||||
|
else
|
||||||
|
echo "Existing ldap configuration with name '${LDAP_NAME}': '${GITEA_AUTH_ID}'. Running update to sync settings..."
|
||||||
|
gitea admin auth update-ldap --id "${GITEA_AUTH_ID}" {{- include "gitea.ldap_settings" . | indent 1 }}
|
||||||
|
echo '...sync settings done.'
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
configure_ldap
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if .Values.oauth.enabled }}
|
||||||
|
function configure_oauth() {
|
||||||
|
local OAUTH_NAME={{ (printf "%s" .Values.oauth.name) | squote }}
|
||||||
|
local AUTH_ID=$(gitea admin auth list --vertical-bars | grep -E "\|${OAUTH_NAME}\s+\|" | grep -iE '\|OAuth2\s+\|' | awk -F " " "{print \$1}")
|
||||||
|
|
||||||
|
if [[ -z "${AUTH_ID}" ]]; then
|
||||||
|
echo "No oauth configuration found with name '${OAUTH_NAME}'. Installing it now..."
|
||||||
|
gitea admin auth add-oauth {{- include "gitea.oauth_settings" . | indent 1 }}
|
||||||
|
echo '...installed.'
|
||||||
|
else
|
||||||
|
echo "Existing oauth configuration with name '${OAUTH_NAME}': '${AUTH_ID}'. Running update to sync settings..."
|
||||||
|
gitea admin auth update-oauth --id "${AUTH_ID}" {{- include "gitea.oauth_settings" . | indent 1 }}
|
||||||
|
echo '...sync settings done.'
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
configure_oauth
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
echo '==== END GITEA CONFIGURATION ===='
|
||||||
|
|
||||||
|
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
{{/* Make sure all variables are set properly */}}
|
||||||
|
{{- include "common.values.setup" . }}
|
||||||
|
|
||||||
|
{{/* Render secrets for gitea */}}
|
||||||
|
{{- include "gitea.secrets" . }}
|
||||||
|
|
||||||
|
{{/* Render configmap for gitea */}}
|
||||||
|
{{- include "gitea.configmap" . }}
|
||||||
|
|
||||||
|
{{/* Append the general secret volumes to the volumes */}}
|
||||||
|
{{- define "gitea.initvolume" -}}
|
||||||
|
enabled: "true"
|
||||||
|
mountPath: "/secrets/ini"
|
||||||
|
readOnly: true
|
||||||
|
type: "custom"
|
||||||
|
volumeSpec:
|
||||||
|
secret:
|
||||||
|
secretName: {{ include "common.names.fullname" . }}-init
|
||||||
|
defaultMode: 0777
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{/* Append the general secret volumes to the volumes */}}
|
||||||
|
{{- define "gitea.configvolume" -}}
|
||||||
|
enabled: "true"
|
||||||
|
mountPath: "/secrets/config"
|
||||||
|
readOnly: true
|
||||||
|
type: "custom"
|
||||||
|
volumeSpec:
|
||||||
|
secret:
|
||||||
|
secretName: {{ include "common.names.fullname" . }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- $_ := set .Values.persistence "init" (include "gitea.initvolume" . | fromYaml) -}}
|
||||||
|
{{- $_ := set .Values.persistence "config" (include "gitea.configvolume" . | fromYaml) -}}
|
||||||
|
|
||||||
|
|
||||||
|
{{/* Render the templates */}}
|
||||||
|
{{ include "common.all" . }}
|
||||||
@@ -0,0 +1,152 @@
|
|||||||
|
image:
|
||||||
|
repository: gitea/gitea
|
||||||
|
tag: 1.15.3-rootless
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
|
postgresqlImage:
|
||||||
|
repository: bitnami/postgresql
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: 13.4.0@sha256:33c276dffe6140d32f357753993c4088cf945a2d02d4c20d310f5a5e9d6e4a36
|
||||||
|
|
||||||
|
service:
|
||||||
|
main:
|
||||||
|
ports:
|
||||||
|
main:
|
||||||
|
port: 3000
|
||||||
|
ssh:
|
||||||
|
ports:
|
||||||
|
ssh:
|
||||||
|
port: 2222
|
||||||
|
targetPort: 2222
|
||||||
|
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-env
|
||||||
|
|
||||||
|
initContainers:
|
||||||
|
0-init-postgresdb:
|
||||||
|
image: "{{ .Values.postgresqlImage.repository}}:{{ .Values.postgresqlImage.tag }}"
|
||||||
|
command:
|
||||||
|
- "sh"
|
||||||
|
- "-c"
|
||||||
|
- "until pg_isready -U gitea -h ${pghost} ; do sleep 2 ; done"
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
env:
|
||||||
|
- name: pghost
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: dbcreds
|
||||||
|
key: plainhost
|
||||||
|
1-init-directories:
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
command: ["/usr/sbin/init_directory_structure.sh"]
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
runAsNonRoot: false
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-env
|
||||||
|
volumeMounts:
|
||||||
|
- name: init
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: config
|
||||||
|
mountPath: /etc/gitea/conf
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
2-configure-gitea:
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
|
||||||
|
command: ["/usr/sbin/configure_gitea.sh"]
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-env
|
||||||
|
volumeMounts:
|
||||||
|
- name: init
|
||||||
|
mountPath: /usr/sbin
|
||||||
|
- name: temp
|
||||||
|
mountPath: /tmp
|
||||||
|
- name: data
|
||||||
|
mountPath: /data
|
||||||
|
|
||||||
|
persistence:
|
||||||
|
data:
|
||||||
|
enabled: true
|
||||||
|
mountPath: "/data"
|
||||||
|
type: pvc
|
||||||
|
accessMode: ReadWriteOnce
|
||||||
|
size: "100Gi"
|
||||||
|
temp:
|
||||||
|
enabled: true
|
||||||
|
mountPath: "/tmp"
|
||||||
|
type: emptyDir
|
||||||
|
varlib:
|
||||||
|
enabled: true
|
||||||
|
mountPath: "/var/lib/gitea"
|
||||||
|
type: emptyDir
|
||||||
|
|
||||||
|
# Configure commit/action signing prerequisites
|
||||||
|
signing:
|
||||||
|
enabled: true
|
||||||
|
gpgHome: /data/git/.gnupg
|
||||||
|
|
||||||
|
admin:
|
||||||
|
username: giteaadmin
|
||||||
|
password: r8sA8CPHD9!bt6d
|
||||||
|
email: "gitea@local.domain"
|
||||||
|
|
||||||
|
metrics:
|
||||||
|
enabled: false
|
||||||
|
serviceMonitor:
|
||||||
|
enabled: false
|
||||||
|
# additionalLabels:
|
||||||
|
# prometheus-release: prom1
|
||||||
|
|
||||||
|
ldap:
|
||||||
|
enabled: false
|
||||||
|
# name:
|
||||||
|
# securityProtocol:
|
||||||
|
# host:
|
||||||
|
# port:
|
||||||
|
# userSearchBase:
|
||||||
|
# userFilter:
|
||||||
|
# adminFilter:
|
||||||
|
# emailAttribute:
|
||||||
|
# bindDn:
|
||||||
|
# bindPassword:
|
||||||
|
# usernameAttribute:
|
||||||
|
# sshPublicKeyAttribute:
|
||||||
|
|
||||||
|
oauth:
|
||||||
|
enabled: false
|
||||||
|
# name:
|
||||||
|
# provider:
|
||||||
|
# key:
|
||||||
|
# secret:
|
||||||
|
# autoDiscoverUrl:
|
||||||
|
# useCustomUrls:
|
||||||
|
# customAuthUrl:
|
||||||
|
# customTokenUrl:
|
||||||
|
# customProfileUrl:
|
||||||
|
# customEmailUrl:
|
||||||
|
|
||||||
|
config:
|
||||||
|
APP_NAME: "Gitea: Git with a cup of tea"
|
||||||
|
RUN_MODE: dev
|
||||||
|
|
||||||
|
customConfig: []
|
||||||
|
# - name: test
|
||||||
|
# keys:
|
||||||
|
# - name: testkey
|
||||||
|
# value: testvalue
|
||||||
|
|
||||||
|
# Enabled postgres
|
||||||
|
postgresql:
|
||||||
|
enabled: true
|
||||||
|
postgresqlUsername: gitea
|
||||||
|
postgresqlDatabase: gitea
|
||||||
|
existingSecret: dbcreds
|
||||||
|
|
||||||
|
# -- memcached dependency settings
|
||||||
|
memcached:
|
||||||
|
enabled: true
|
||||||
@@ -9,6 +9,7 @@ These defaults can ofcoarse be changed, but as we guarantee "sane, working defau
|
|||||||
| k8s-gateway | main | | 53/UDP | Potenial conflict with pihole |
|
| k8s-gateway | main | | 53/UDP | Potenial conflict with pihole |
|
||||||
| pihole | dns | | 53/UDP | Potenial conflict with k8s-gateway |
|
| pihole | dns | | 53/UDP | Potenial conflict with k8s-gateway |
|
||||||
| pihole | dns-tcp | | 53 | |
|
| pihole | dns-tcp | | 53 | |
|
||||||
|
| Gitea | ssh | | 2222 | |
|
||||||
| Unifi | comm | | 8080 | |
|
| Unifi | comm | | 8080 | |
|
||||||
| traefik | main | 9000 | | |
|
| traefik | main | 9000 | | |
|
||||||
| traefik | web | | 9080 | Adviced to be changed to 80 |
|
| traefik | web | | 9080 | Adviced to be changed to 80 |
|
||||||
@@ -127,6 +128,6 @@ These defaults can ofcoarse be changed, but as we guarantee "sane, working defau
|
|||||||
| teamspeak3 | query | 36105 | | |
|
| teamspeak3 | query | 36105 | | |
|
||||||
| teamspeak3 | files | 36106 | | |
|
| teamspeak3 | files | 36106 | | |
|
||||||
| CodeServer | ADDON | 36107 | | |
|
| CodeServer | ADDON | 36107 | | |
|
||||||
|
| Gitea | main | 36108 | | |
|
||||||
|
|
||||||
|
##### Note: TCP and UPD ports that are the same in each App, are not by mistake.
|
||||||
#### Note: TCP and UPD ports that are the same in each App, are not by mistake.
|
|
||||||
|
|||||||
Reference in New Issue
Block a user