From 94be79e80cc0a463cb0c57c94d90040383a1f6d8 Mon Sep 17 00:00:00 2001 From: Stavros Kois <47820033+stavros-k@users.noreply.github.com> Date: Sat, 20 May 2023 22:34:47 +0300 Subject: [PATCH] feat(wordpress): BREAKING-CHANGE migrate to new common (#9025) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit **Description** ⚒️ Fixes # **⚙️ Type of change** - [x] ⚙️ Feature/App addition - [x] 🪛 Bugfix - [x] ⚠️ Breaking change (fix or feature that would cause existing functionality to not work as expected) - [x] 🔃 Refactor of current code **🧪 How Has This Been Tested?** **📃 Notes:** **✔️ Checklist:** - [x] ⚖️ My code follows the style guidelines of this project - [x] 👀 I have performed a self-review of my own code - [ ] #️⃣ I have commented my code, particularly in hard-to-understand areas - [ ] 📄 I have made corresponding changes to the documentation - [x] ⚠️ My changes generate no new warnings - [ ] 🧪 I have added tests to this description that prove my fix is effective or that my feature works - [x] ⬆️ I increased versions for any altered app according to semantic versioning **➕ App addition** If this PR is an app addition please make sure you have done the following. - [ ] 🪞 I have opened a PR on [truecharts/containers](https://github.com/truecharts/containers) adding the container to TrueCharts mirror repo. - [ ] 🖼️ I have added an icon in the Chart's root directory called `icon.png` --- _Please don't blindly check all the boxes. Read them and only check those that apply. Those checkboxes are there for the reviewer to see what is this all about and the status of this PR with a quick glance._ --------- Signed-off-by: Stavros Kois <47820033+stavros-k@users.noreply.github.com> --- charts/stable/wordpress/Chart.yaml | 6 +- charts/stable/wordpress/templates/_env.tpl | 191 ++++++++---------- charts/stable/wordpress/templates/common.yaml | 10 +- charts/stable/wordpress/values.yaml | 28 +-- 4 files changed, 108 insertions(+), 127 deletions(-) diff --git a/charts/stable/wordpress/Chart.yaml b/charts/stable/wordpress/Chart.yaml index 73f00b9affc..c003267e243 100644 --- a/charts/stable/wordpress/Chart.yaml +++ b/charts/stable/wordpress/Chart.yaml @@ -3,11 +3,11 @@ appVersion: "6.2.0" dependencies: - name: common repository: https://library-charts.truecharts.org - version: 11.1.2 + version: 12.8.1 - condition: mariadb.enabled name: mariadb repository: https://deps.truecharts.org/ - version: 5.0.35 + version: 7.0.27 description: The WordPress rich content management system can utilize plugins, widgets, and themes. home: https://truecharts.org/charts/stable/wordpress icon: https://truecharts.org/img/hotlink-ok/chart-icons/wordpress.png @@ -23,7 +23,7 @@ name: wordpress sources: - https://github.com/truecharts/charts/tree/master/charts/stable/wordpress - https://www.wordpress.org -version: 1.1.19 +version: 2.0.0 annotations: truecharts.org/catagories: | - website diff --git a/charts/stable/wordpress/templates/_env.tpl b/charts/stable/wordpress/templates/_env.tpl index 43f1b8c5088..7a77a6343b4 100644 --- a/charts/stable/wordpress/templates/_env.tpl +++ b/charts/stable/wordpress/templates/_env.tpl @@ -1,118 +1,93 @@ {{/* Wordpress environment variables */}} {{- define "wordpress.env" -}} - {{- $configName := printf "%s-env-config" (include "tc.common.names.fullname" .) }} - {{- $secretName := printf "%s-env-secret" (include "tc.common.names.fullname" .) }} ---- -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ $configName }} - labels: - {{- include "tc.common.labels" . | nindent 4 }} -data: - APACHE_HTTP_PORT_NUMBER: {{ .Values.service.main.ports.main.port | quote }} +configmap: + env-config: + enabled: true + data: + APACHE_HTTP_PORT_NUMBER: {{ .Values.service.main.ports.main.port | quote }} - {{/* Database */}} - WORDPRESS_DATABASE_PORT_NUMBER: "3306" - WORDPRESS_DATABASE_USER: {{ .Values.mariadb.mariadbUsername | quote }} - WORDPRESS_DATABASE_NAME: {{ .Values.mariadb.mariadbDatabase | quote }} + {{/* Database */}} + WORDPRESS_DATABASE_PORT_NUMBER: "3306" + WORDPRESS_DATABASE_USER: {{ .Values.mariadb.mariadbUsername | quote }} + WORDPRESS_DATABASE_NAME: {{ .Values.mariadb.mariadbDatabase | quote }} - {{/* Wordpress */}} - WORDPRESS_USERNAME: {{ .Values.wordpress.user | quote }} - WORDPRESS_EMAIL: {{ .Values.wordpress.email | quote }} - WORDPRESS_FIRST_NAME: {{ .Values.wordpress.first_name | quote }} - WORDPRESS_LAST_NAME: {{ .Values.wordpress.last_name | quote }} - WORDPRESS_BLOG_NAME: {{ .Values.wordpress.blog_name | quote }} - WORDPRESS_ENABLE_REVERSE_PROXY: {{ ternary "yes" "no" .Values.wordpress.enable_reverse_proxy_headers | quote }} + {{/* Wordpress */}} + WORDPRESS_USERNAME: {{ .Values.wordpress.user | quote }} + WORDPRESS_EMAIL: {{ .Values.wordpress.email | quote }} + WORDPRESS_FIRST_NAME: {{ .Values.wordpress.first_name | quote }} + WORDPRESS_LAST_NAME: {{ .Values.wordpress.last_name | quote }} + WORDPRESS_BLOG_NAME: {{ .Values.wordpress.blog_name | quote }} + WORDPRESS_ENABLE_REVERSE_PROXY: {{ ternary "yes" "no" .Values.wordpress.enable_reverse_proxy_headers | quote }} - {{- if .Values.smtp.enabled }} - WORDPRESS_SMTP_HOST: {{ .Values.smtp.host | quote }} - WORDPRESS_SMTP_PORT: {{ .Values.smtp.port | quote }} - {{- end }} + {{- if .Values.smtp.enabled }} + WORDPRESS_SMTP_HOST: {{ .Values.smtp.host | quote }} + WORDPRESS_SMTP_PORT: {{ .Values.smtp.port | quote }} + {{- end }} - {{- $php := get .Values "php-config" }} - {{/* PHP */}} - {{- with $php.PHP_ENABLE_OPCACHE }} - PHP_ENABLE_OPCACHE: {{ . | quote }} - {{- end }} - {{- with $php.PHP_EXPOSE_PHP }} - PHP_EXPOSE_PHP: {{ . | quote }} - {{- end }} - {{- with $php.PHP_MAX_EXECUTION_TIME }} - PHP_MAX_EXECUTION_TIME: {{ . | quote }} - {{- end }} - {{- with $php.PHP_MAX_INPUT_TIME }} - PHP_MAX_INPUT_TIME: {{ . | quote }} - {{- end }} - {{- with $php.PHP_MAX_INPUT_VARS }} - PHP_MAX_INPUT_VARS: {{ . | quote }} - {{- end }} - {{- with $php.PHP_MEMORY_LIMIT }} - PHP_MEMORY_LIMIT: {{ . | quote }} - {{- end }} - {{- with $php.PHP_POST_MAX_SIZE }} - PHP_POST_MAX_SIZE: {{ . | quote }} - {{- end }} - {{- with $php.PHP_UPLOAD_MAX_FILESIZE }} - PHP_UPLOAD_MAX_FILESIZE: {{ . | quote }} - {{- end }} ---- -apiVersion: v1 -kind: Secret -metadata: - name: {{ $secretName }} - labels: - {{- include "tc.common.labels" . | nindent 4 }} -data: - WORDPRESS_DATABASE_HOST: {{ printf "%v-%v" .Release.Name "mariadb" | b64enc }} - WORDPRESS_DATABASE_PASSWORD: {{ .Values.mariadb.mariadbPassword | trimAll "\"" | b64enc }} + {{- $php := get .Values "php-config" }} + {{/* PHP */}} + {{- with $php.PHP_ENABLE_OPCACHE }} + PHP_ENABLE_OPCACHE: {{ . | quote }} + {{- end }} + {{- with $php.PHP_EXPOSE_PHP }} + PHP_EXPOSE_PHP: {{ . | quote }} + {{- end }} + {{- with $php.PHP_MAX_EXECUTION_TIME }} + PHP_MAX_EXECUTION_TIME: {{ . | quote }} + {{- end }} + {{- with $php.PHP_MAX_INPUT_TIME }} + PHP_MAX_INPUT_TIME: {{ . | quote }} + {{- end }} + {{- with $php.PHP_MAX_INPUT_VARS }} + PHP_MAX_INPUT_VARS: {{ . | quote }} + {{- end }} + {{- with $php.PHP_MEMORY_LIMIT }} + PHP_MEMORY_LIMIT: {{ . | quote }} + {{- end }} + {{- with $php.PHP_POST_MAX_SIZE }} + PHP_POST_MAX_SIZE: {{ . | quote }} + {{- end }} + {{- with $php.PHP_UPLOAD_MAX_FILESIZE }} + PHP_UPLOAD_MAX_FILESIZE: {{ . | quote }} + {{- end }} - WORDPRESS_PASSWORD: {{ .Values.wordpress.pass | b64enc }} +{{- $secretName := printf "%s-env-secret" (include "tc.v1.common.lib.chart.names.fullname" .) }} +secret: + env-secret: + enabled: true + data: + WORDPRESS_DATABASE_HOST: {{ .Values.mariadb.creds.plainhost }} + WORDPRESS_DATABASE_PASSWORD: {{ .Values.mariadb.creds.mariadbPassword | trimAll "\"" }} - {{- if .Values.smtp.enabled }} - WORDPRESS_SMTP_USER: {{ .Values.smtp.user | b64enc }} - WORDPRESS_SMTP_PASSWORD: {{ .Values.smtp.pass | b64enc }} - {{- end }} - {{/* Salts */}} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_AUTH_KEY: {{ index .data "WORDPRESS_AUTH_KEY" }} - {{- else }} - WORDPRESS_AUTH_KEY: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_SECURE_AUTH_KEY: {{ index .data "WORDPRESS_SECURE_AUTH_KEY" }} - {{- else }} - WORDPRESS_SECURE_AUTH_KEY: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_LOGGED_IN_KEY: {{ index .data "WORDPRESS_LOGGED_IN_KEY" }} - {{- else }} - WORDPRESS_LOGGED_IN_KEY: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_NONCE_KEY: {{ index .data "WORDPRESS_NONCE_KEY" }} - {{- else }} - WORDPRESS_NONCE_KEY: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_AUTH_SALT: {{ index .data "WORDPRESS_AUTH_SALT" }} - {{- else }} - WORDPRESS_AUTH_SALT: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_SECURE_AUTH_SALT: {{ index .data "WORDPRESS_SECURE_AUTH_SALT" }} - {{- else }} - WORDPRESS_SECURE_AUTH_SALT: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_LOGGED_IN_SALT: {{ index .data "WORDPRESS_LOGGED_IN_SALT" }} - {{- else }} - WORDPRESS_LOGGED_IN_SALT: {{ randAlphaNum 32 | b64enc }} - {{- end }} - {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} - WORDPRESS_NONCE_SALT: {{ index .data "WORDPRESS_NONCE_SALT" }} - {{- else }} - WORDPRESS_NONCE_SALT: {{ randAlphaNum 32 | b64enc }} - {{- end }} + WORDPRESS_PASSWORD: {{ .Values.wordpress.pass }} + + {{- if .Values.smtp.enabled }} + WORDPRESS_SMTP_USER: {{ .Values.smtp.user }} + WORDPRESS_SMTP_PASSWORD: {{ .Values.smtp.pass }} + {{- end }} + + {{/* Salts */}} + WORDPRESS_AUTH_KEY: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_AUTH_KEY" "secret" $secretName) }} + WORDPRESS_SECURE_AUTH_KEY: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_SECURE_AUTH_KEY" "secret" $secretName) }} + WORDPRESS_LOGGED_IN_KEY: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_LOGGED_IN_KEY" "secret" $secretName) }} + WORDPRESS_NONCE_KEY: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_NONCE_KEY" "secret" $secretName) }} + WORDPRESS_AUTH_SALT: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_AUTH_SALT" "secret" $secretName) }} + WORDPRESS_SECURE_AUTH_SALT: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_SECURE_AUTH_SALT" "secret" $secretName) }} + WORDPRESS_LOGGED_IN_SALT: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_LOGGED_IN_SALT" "secret" $secretName) }} + WORDPRESS_NONCE_SALT: {{ include "wordpress.fetch" (dict "ns" .Release.Namespace "var" "WORDPRESS_NONCE_SALT" "secret" $secretName) }} {{- end }} + +{{- define "wordpress.fetch" -}} + {{- $var := .var -}} + {{- $secret := .secret -}} + {{- $ns := .ns -}} + {{- $ret := randAlphaNum 32 -}} + + {{- with (lookup "v1" "Secret" $ns $secret) -}} + {{- $ret = index .data $var | b64dec -}} + {{- end -}} + + {{- $ret -}} + +{{- end -}} diff --git a/charts/stable/wordpress/templates/common.yaml b/charts/stable/wordpress/templates/common.yaml index 14855161e4e..5f847ce389f 100644 --- a/charts/stable/wordpress/templates/common.yaml +++ b/charts/stable/wordpress/templates/common.yaml @@ -1,8 +1,10 @@ {{/* Make sure all variables are set properly */}} -{{- include "tc.common.loader.init" . }} +{{- include "tc.v1.common.loader.init" . }} -{{/* Plausible environment variables */}} -{{- include "wordpress.env" . }} +{{- $config := include "wordpress.env" . | fromYaml -}} +{{- if $config -}} + {{- $_ := mustMergeOverwrite .Values $config -}} +{{- end -}} {{/* Render the templates */}} -{{ include "tc.common.loader.apply" . }} +{{ include "tc.v1.common.loader.apply" . }} diff --git a/charts/stable/wordpress/values.yaml b/charts/stable/wordpress/values.yaml index cfc3b238015..018e153a8a2 100644 --- a/charts/stable/wordpress/values.yaml +++ b/charts/stable/wordpress/values.yaml @@ -4,10 +4,20 @@ image: tag: 6.2.0@sha256:b7676e38a56732d740702fae64ec135222303d2073a50826aa15df06e5f352b4 securityContext: - readOnlyRootFilesystem: false + container: + readOnlyRootFilesystem: false + runAsGroup: 0 -podSecurityContext: - runAsGroup: 0 +workload: + main: + podSpec: + containers: + main: + envFrom: + - configMapRef: + name: env-config + - secretRef: + name: env-secret wordpress: user: user @@ -35,17 +45,11 @@ php-config: PHP_POST_MAX_SIZE: "" PHP_UPLOAD_MAX_FILESIZE: "" -envFrom: - - configMapRef: - name: '{{ include "tc.common.names.fullname" . }}-env-config' - - secretRef: - name: '{{ include "tc.common.names.fullname" . }}-env-secret' - service: main: ports: main: - protocol: HTTP + protocol: http port: 10591 persistence: @@ -57,7 +61,7 @@ mariadb: enabled: true mariadbUsername: wordpress mariadbDatabase: wordpress - existingSecret: mariadbcreds portal: - enabled: true + open: + enabled: true