fix(redisinsight) code clean up (#3980)

* fix(redisinsight) code clean up

* fix some UX, and try rootless

* update docs

* root

Co-authored-by: Stavros kois <s.kois@outlook.com>
This commit is contained in:
Xstar97
2022-10-01 22:36:12 +03:00
committed by GitHub
co-authored by Stavros kois
parent 5e330cda0b
commit e2d9649e6d
4 changed files with 178 additions and 41 deletions
+19 -18
View File
@@ -1,29 +1,30 @@
annotations:
truecharts.org/SCALE-support: "true"
truecharts.org/catagories: |
- Tools-Utilities
apiVersion: v2
appVersion: "latest"
dependencies:
- name: common
repository: https://library-charts.truecharts.org
version: 10.6.4
kubeVersion: ">=1.16.0-0"
name: redisinsight
version: 0.0.28
appVersion: "1.13.0"
description: GUI for Redis.
type: application
deprecated: false
description: RedisInsight - The GUI for Redis.
home: https://truecharts.org/docs/charts/incubator/redisinsight
icon: https://truecharts.org/img/hotlink-ok/chart-icons/redisinsight.png
keywords:
- redisinsight
- Tools-Utilities
kubeVersion: ">=1.16.0-0"
maintainers:
- email: info@truecharts.org
name: TrueCharts
url: https://truecharts.org
name: redisinsight
sources:
- https://github.com/truecharts/charts/tree/master/charts/incubator/redisinsight
- https://redis.com/redis-enterprise/redis-insight/
- https://hub.docker.com/r/redislabs/redisinsight
type: application
version: 0.0.27
dependencies:
- name: common
repository: https://library-charts.truecharts.org
version: 10.6.4
maintainers:
- email: info@truecharts.org
name: TrueCharts
url: https://truecharts.org
annotations:
truecharts.org/catagories: |
- Tools-Utilities
truecharts.org/SCALE-support: "true"
truecharts.org/grade: U
@@ -0,0 +1,6 @@
# Installation Notes
- If using ingress and want to access this service with a domain add an entry to `Trusted Origins` like "https://app.mydomain.tld".
- Set `Log Level` with any option from the list: "DEBUG", "INFO", "WARNING", "ERROR" and "CRITICAL". Default is "WARNING".
- Check `Auth Prompt` to enable the authentication prompt that asks for authentication before opening an instance or when the user is idle.
- Set `Auth Timer` to a number for the idle timer for authentication prompt, in minutes. Default is 30.
+124 -11
View File
@@ -1,5 +1,7 @@
# Include{groups}
portals: {}
portals:
open:
# Include{portalLink}
questions:
# Include{global}
# Include{controller}
@@ -10,51 +12,162 @@ questions:
# Include{recreate}
# Include{controllerExpert}
# Include{controllerExpertExtraArgs}
# Include{containerConfig}
- variable: redisinsight
group: Container Configuration
label: Redis Insight Configuration
schema:
additional_attrs: true
type: dict
attrs:
- variable: trusted_origins
label: Trusted Origins
description: Configures the trusted origins of the application. ex https://app.mydomain.tld
schema:
type: list
default: []
items:
- variable: origin
label: Trusted Origin
schema:
type: string
required: true
default: ""
- variable: log_level
label: Log Level
description: Configures the log level of the application.
schema:
type: string
required: true
default: WARNING
enum:
- value: DEBUG
description: DEBUG
- value: INFO
description: INFO
- value: WARNING
description: WARNING
- value: ERROR
description: ERROR
- value: CRITICAL
description: CRITICAL
- variable: auth_prompt
label: Auth Prompt
description: Enables authentication prompt that asks for authentication before opening an instance or when the user is idle.
schema:
type: boolean
default: false
- variable: auth_timer
label: Auth Timer
description: Idle timer value for authentication prompt, in minutes..
schema:
type: int
default: 30
# Include{serviceRoot}
- variable: main
label: Main Service
description: The Primary service on which the healthcheck runs, often the webUI
schema:
additional_attrs: true
type: dict
attrs:
# Include{serviceSelectorLoadBalancer}
# Include{serviceSelectorExtras}
- variable: main
label: Main Service Port Configuration
schema:
additional_attrs: true
type: dict
attrs:
- variable: port
label: Port
description: This port exposes the container port on the service
schema:
type: int
default: 10579
required: true
# Include{advancedPortHTTP}
- variable: targetPort
label: Target Port
description: The internal(!) port on the container the Application runs on
schema:
type: int
default: 10579
# Include{serviceExpertRoot}
default: false
# Include{serviceExpert}
# Include{serviceList}
# Include{persistenceRoot}
- variable: config
label: App Config Storage
description: Stores the Application Configuration.
schema:
additional_attrs: true
type: dict
attrs:
# Include{persistenceBasic}
# Include{persistenceAdvanced}
- variable: logs
label: App Logs Storage
description: Stores the Application Logs.
schema:
additional_attrs: true
type: dict
attrs:
# Include{persistenceBasic}
# Include{persistenceAdvanced}
# Include{persistenceList}
# Include{ingressRoot}
- variable: main
label: Main Ingress
schema:
additional_attrs: true
type: dict
attrs:
# Include{ingressDefault}
# Include{ingressTLS}
# Include{ingressTraefik}
# Include{ingressExpert}
# Include{ingressList}
# Include{security}
# Include{securityContextAdvancedRoot}
- variable: privileged
label: "Privileged mode"
label: Privileged mode
schema:
type: boolean
default: false
- variable: readOnlyRootFilesystem
label: "ReadOnly Root Filesystem"
label: ReadOnly Root Filesystem
schema:
type: boolean
default: false
- variable: allowPrivilegeEscalation
label: "Allow Privilege Escalation"
label: Allow Privilege Escalation
schema:
type: boolean
default: false
- variable: runAsNonRoot
label: "runAsNonRoot"
label: runAsNonRoot
schema:
type: boolean
default: false
# Include{securityContextAdvanced}
# Include{podSecurityContextRoot}
- variable: runAsUser
label: "runAsUser"
description: "The UserID of the user running the application"
label: runAsUser
description: The UserID of the user running the application
schema:
type: int
default: 0
- variable: runAsGroup
label: "runAsGroup"
description: The groupID this App of the user running the application"
label: runAsGroup
description: The groupID this App of the user running the application
schema:
type: int
default: 0
- variable: fsGroup
label: "fsGroup"
description: "The group that should own ALL storage."
label: fsGroup
description: The group that should own ALL storage.
schema:
type: int
default: 568
+29 -12
View File
@@ -1,28 +1,45 @@
env: {}
image:
pullPolicy: IfNotPresent
repository: tccr.io/truecharts/redisinsight
tag: latest@sha256:d89be8436458397ab87d0e577c218165276a93995f53d489c774eb3f437f846d
persistence: {}
redisinsight:
log_level: WARNING
trusted_origins: []
auth_prompt: false
auth_timer: 30
env:
RIPORT: "{{ .Values.service.main.ports.main.port }}"
RIHOMEDIR: /config
RILOGDIR: /logs
RILOGLEVEL: "{{ .Values.redisinsight.log_level }}"
RITRUSTEDORIGINS: '{{ join "," .Values.redisinsight.trusted_origins }}'
RIAUTHPROMPT: "{{ .Values.redisinsight.auth_prompt }}"
RIAUTHTIMER: "{{ .Values.redisinsight.auth_timer }}"
podSecurityContext:
runAsGroup: 0
runAsUser: 0
probes:
liveness:
enabled: false
readiness:
enabled: false
startup:
enabled: false
securityContext:
readOnlyRootFilesystem: false
runAsNonRoot: false
service:
main:
enabled: false
ports:
main:
enabled: false
protocol: HTTP
port: 10579
persistence:
config:
enabled: true
mountPath: /config
logs:
enabled: true
mountPath: /logs
portal:
enabled: false
enabled: true