diff --git a/charts/incubator/lldap/.helmignore b/charts/incubator/lldap/.helmignore new file mode 100644 index 00000000000..77ca5567b26 --- /dev/null +++ b/charts/incubator/lldap/.helmignore @@ -0,0 +1,30 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +# OWNERS file for Kubernetes +OWNERS +# helm-docs templates +*.gotmpl +# docs folder +/docs +# icon +icon.png diff --git a/charts/incubator/lldap/Chart.yaml b/charts/incubator/lldap/Chart.yaml new file mode 100644 index 00000000000..3d32eb83596 --- /dev/null +++ b/charts/incubator/lldap/Chart.yaml @@ -0,0 +1,33 @@ +apiVersion: v2 +appVersion: "0.4.1" +dependencies: + - name: common + repository: https://library-charts.truecharts.org + version: 12.2.28 +deprecated: false +description: Lightweight ldap server for authentication and user management +home: https://truecharts.org/charts/incubator/lldap +icon: https://truecharts.org/img/hotlink-ok/chart-icons/lldap.png +keywords: + - lldap + - ldap + - authentication + - auth +kubeVersion: ">=1.16.0-0" +maintainers: + - email: info@truecharts.org + name: TrueCharts + url: https://truecharts.org +name: lldap +sources: + - https://github.com/truecharts/charts/tree/master/charts/lldap + - https://hub.docker.com/r/nitnelave/lldap + - https://github.com/nitnelave/lldap +type: application +version: 0.0.1 +annotations: + truecharts.org/catagories: | + - ldap + - auth + truecharts.org/SCALE-support: "true" + truecharts.org/grade: U diff --git a/charts/incubator/lldap/NOTES.txt b/charts/incubator/lldap/NOTES.txt new file mode 100644 index 00000000000..efcb74cb772 --- /dev/null +++ b/charts/incubator/lldap/NOTES.txt @@ -0,0 +1 @@ +{{- include "tc.v1.common.lib.chart.notes" $ -}} diff --git a/charts/incubator/lldap/README.md b/charts/incubator/lldap/README.md new file mode 100644 index 00000000000..e69de29bb2d diff --git a/charts/incubator/lldap/ci/default-values.yaml b/charts/incubator/lldap/ci/default-values.yaml new file mode 100644 index 00000000000..e69de29bb2d diff --git a/charts/incubator/lldap/questions.yaml b/charts/incubator/lldap/questions.yaml new file mode 100644 index 00000000000..80d5b04a944 --- /dev/null +++ b/charts/incubator/lldap/questions.yaml @@ -0,0 +1,117 @@ +# Include{groups} +portals: + open: +# Include{portalLink} +questions: +# Include{global} +# Include{controllerExpert} +# Include{fixedEnv} +# Include{containerConfig} + - variable: env + group: "App Configuration" + label: "Image Environment" + schema: + additional_attrs: true + type: dict + attrs: + - variable: LLDAP_LDAP_USER_PASS + group: "App Configuration" + label: "Admin Password" + schema: + type: string + required: true + default: "change me" + - variable: LLDAP_LDAP_BASE_DN + group: "App Configuration" + label: "Base DN for LDAP" + schema: + type: string + required: true + default: "dc=example,dc=com" +# Include{serviceRoot} + - variable: main + label: "Main Service" + description: "The Primary service on which the healthcheck runs, often the webUI" + schema: + type: dict + attrs: +# Include{serviceSelector} + - variable: main + label: "Main Service Port Configuration" + schema: + type: dict + attrs: + - variable: port + label: "Port" + description: "This port exposes the container port on the service" + schema: + type: int + default: 17170 + required: true + - variable: ldap + label: "LDAP Service Port Configuration" + description: "The Service in which external sources will connect to the LDAP service" + schema: + type: dict + attrs: + - variable: port + label: "Port" + description: "This port exposes the container port on the service" + schema: + type: int + default: 3890 + required: true +# Include{serviceExpertRoot} + default: false +# Include{serviceExpert} +# Include{serviceList} +# Include{persistenceRoot} + - variable: data + label: "App Config Storage" + description: "Stores the Application Configuration." + schema: + type: dict + attrs: +# Include{persistenceBasic} +# Include{persistenceList} +# Include{ingressRoot} + - variable: main + label: "Main Ingress" + schema: + type: dict + attrs: +# Include{ingressDefault} +# Include{ingressTLS} +# Include{ingressTraefik} +# Include{ingressExpert} +# Include{ingressList} +# Include{securityContextAdvanced} +# Include{podSecurityContextRoot} + - variable: runAsUser + label: "runAsUser" + description: "The UserID of the user running the application" + schema: + type: int + default: 568 + - variable: runAsGroup + label: "runAsGroup" + description: "The groupID this App of the user running the application" + schema: + type: int + default: 568 + - variable: fsGroup + label: "fsGroup" + description: "The group that should own ALL storage." + schema: + type: int + default: 568 +# Include{podSecurityContextAdvanced} +# Include{resources} +# Include{advanced} +# Include{postgresql} +# Include{postgresqlBasics} +# Include{addons} +# Include{codeserver} +# Include{promtail} +# Include{netshoot} +# Include{vpn} diff --git a/charts/incubator/lldap/templates/_secrets.tpl b/charts/incubator/lldap/templates/_secrets.tpl new file mode 100644 index 00000000000..72d887a228a --- /dev/null +++ b/charts/incubator/lldap/templates/_secrets.tpl @@ -0,0 +1,16 @@ +{{/* Define the secrets */}} +{{- define "lldap.secrets" -}} +{{- $basename := include "tc.v1.common.lib.chart.names.fullname" $ -}} +{{- $fetchname := printf "%s-secret" $basename -}} + +{{/* Initialize all keys */}} +{{- $secrets := randAlphaNum 50 }} + +enabled: true +data: + {{ with (lookup "v1" "Secret" .Release.Namespace $fetchname) }} + {{/* Get previous values and decode */}} + {{ $secrets = (index .data "LLDAP_JWT_SECRET") | b64dec }} + {{ end }} + LLDAP_JWT_SECRET: {{ $secrets }} +{{- end -}} diff --git a/charts/incubator/lldap/templates/common.yaml b/charts/incubator/lldap/templates/common.yaml new file mode 100644 index 00000000000..73045a83c70 --- /dev/null +++ b/charts/incubator/lldap/templates/common.yaml @@ -0,0 +1,11 @@ +{{/* Make sure all variables are set properly */}} +{{- include "tc.v1.common.loader.init" . }} + +{{/* Render secrets for LLDAP */}} +{{- $secrets := include "lldap.secrets" . | fromYaml -}} +{{- if $secrets -}} + {{- $_ := set .Values.secret "secret" $secrets -}} +{{- end -}} + +{{/* Render the templates */}} +{{ include "tc.v1.common.loader.apply" . }} diff --git a/charts/incubator/lldap/values.yaml b/charts/incubator/lldap/values.yaml new file mode 100644 index 00000000000..8f70b43829a --- /dev/null +++ b/charts/incubator/lldap/values.yaml @@ -0,0 +1,55 @@ +image: + repository: nitnelave/lldap + pullPolicy: IfNotPresent + tag: latest-debian + +securityContext: + container: + readOnlyRootFilesystem: false + +service: + main: + ports: + main: + targetPort: 17170 + port: 17170 + ldap: + ports: + main: + targetPort: 3890 + port: 3890 + +workload: + main: + podSpec: + containers: + main: + command: ["/app/lldap"] + args: ["run"] + env: + LLDAP_LDAP_BASE_DN: "dc=example,dc=com" + LLDAP_LDAP_USER_PASS: "change me" + LLDAP_JWT_SECRET: + - secretRef: + name: secrets + key: LLDAP_JWT_SECRET + LLDAP_key_file: "/data/private_key" + LLDAP_database_url: + secretKeyRef: + name: cnpg-main-urls + key: std + +persistence: + data: + enabled: true + mountPath: "/data" + +cnpg: + main: + enabled: true + user: lldap + database: lldap + +portal: + open: + enabled: true