diff --git a/images/blacklist/helm/Chart.yaml b/images/blacklist/helm/Chart.yaml index e5558339..5402b892 100644 --- a/images/blacklist/helm/Chart.yaml +++ b/images/blacklist/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/spamhaus/rbldnsd type: application -version: 0.1.5 +version: 0.1.9 appVersion: "1.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/blacklist/helm/templates/NOTES.txt b/images/blacklist/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/blacklist/helm/templates/NOTES.txt +++ b/images/blacklist/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/blacklist/helm/templates/app.yaml b/images/blacklist/helm/templates/app.yaml index 2061fa8a..ee3d586c 100644 --- a/images/blacklist/helm/templates/app.yaml +++ b/images/blacklist/helm/templates/app.yaml @@ -1,9 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} +{{- include "chartlib.listener" . }} --- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/data-sync/helm/Chart.yaml b/images/data-sync/helm/Chart.yaml index 1cface8f..240b0d66 100644 --- a/images/data-sync/helm/Chart.yaml +++ b/images/data-sync/helm/Chart.yaml @@ -9,5 +9,6 @@ version: 0.1.18 appVersion: "2.54.0-4.14.3-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/data-sync/helm/templates/NOTES.txt b/images/data-sync/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/data-sync/helm/templates/NOTES.txt +++ b/images/data-sync/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/data-sync/helm/templates/app.yaml b/images/data-sync/helm/templates/app.yaml index b4b1ef34..ee3d586c 100644 --- a/images/data-sync/helm/templates/app.yaml +++ b/images/data-sync/helm/templates/app.yaml @@ -4,9 +4,9 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} +{{- include "chartlib.listener" . }} --- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} --- diff --git a/images/ddclient/helm/Chart.yaml b/images/ddclient/helm/Chart.yaml index be6d64cf..97bbbfb0 100644 --- a/images/ddclient/helm/Chart.yaml +++ b/images/ddclient/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/ddclient/ddclient/ type: application -version: 0.1.5 +version: 0.1.6 appVersion: "4.0.0-r2" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/ddclient/helm/templates/NOTES.txt b/images/ddclient/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/ddclient/helm/templates/NOTES.txt +++ b/images/ddclient/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/ddclient/helm/templates/app.yaml b/images/ddclient/helm/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/images/ddclient/helm/templates/app.yaml +++ b/images/ddclient/helm/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/dhcpd-dns-pxe/helm/Chart.yaml b/images/dhcpd-dns-pxe/helm/Chart.yaml index 2dff1307..2595673b 100644 --- a/images/dhcpd-dns-pxe/helm/Chart.yaml +++ b/images/dhcpd-dns-pxe/helm/Chart.yaml @@ -7,9 +7,10 @@ sources: - https://source.isc.org/git/dhcp.git - http://thekelleys.org.uk/gitweb/?p=dnsmasq.git type: application -version: 0.2.3 +version: 0.2.4 appVersion: "3.0.3-r0-2.93-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/dhcpd-dns-pxe/helm/templates/NOTES.txt b/images/dhcpd-dns-pxe/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/dhcpd-dns-pxe/helm/templates/NOTES.txt +++ b/images/dhcpd-dns-pxe/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/dhcpd-dns-pxe/helm/templates/app.yaml b/images/dhcpd-dns-pxe/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/dhcpd-dns-pxe/helm/templates/app.yaml +++ b/images/dhcpd-dns-pxe/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/dovecot/helm/Chart.yaml b/images/dovecot/helm/Chart.yaml index ad2d4b3b..7d46d672 100644 --- a/images/dovecot/helm/Chart.yaml +++ b/images/dovecot/helm/Chart.yaml @@ -6,12 +6,13 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/vdukhovni/dovecot type: application -version: 0.1.17 +version: 0.1.18 appVersion: "2.4.5-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: data-sync version: 0.1.3 repository: https://instantlinux.github.io/docker-tools diff --git a/images/dovecot/helm/templates/NOTES.txt b/images/dovecot/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/dovecot/helm/templates/NOTES.txt +++ b/images/dovecot/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/dovecot/helm/templates/app.yaml b/images/dovecot/helm/templates/app.yaml index aeeec90a..ee3d586c 100644 --- a/images/dovecot/helm/templates/app.yaml +++ b/images/dovecot/helm/templates/app.yaml @@ -1,10 +1,10 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/ez-ipupdate/helm/Chart.yaml b/images/ez-ipupdate/helm/Chart.yaml index 1ffe55a5..0bce34b4 100644 --- a/images/ez-ipupdate/helm/Chart.yaml +++ b/images/ez-ipupdate/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://sourceforge.net/projects/ez-ipupdate/ type: application -version: 0.1.3 +version: 0.1.4 appVersion: "3.0.10-r13" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/ez-ipupdate/helm/templates/NOTES.txt b/images/ez-ipupdate/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/ez-ipupdate/helm/templates/NOTES.txt +++ b/images/ez-ipupdate/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/ez-ipupdate/helm/templates/app.yaml b/images/ez-ipupdate/helm/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/images/ez-ipupdate/helm/templates/app.yaml +++ b/images/ez-ipupdate/helm/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/git-dump/helm/Chart.yaml b/images/git-dump/helm/Chart.yaml index 0d79fa27..bc1dfac1 100644 --- a/images/git-dump/helm/Chart.yaml +++ b/images/git-dump/helm/Chart.yaml @@ -5,9 +5,10 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.20 +version: 0.1.21 appVersion: "2.54.0-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/git-dump/helm/templates/NOTES.txt b/images/git-dump/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/git-dump/helm/templates/NOTES.txt +++ b/images/git-dump/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/git-dump/helm/templates/app.yaml b/images/git-dump/helm/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/images/git-dump/helm/templates/app.yaml +++ b/images/git-dump/helm/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/git-pull/helm/Chart.yaml b/images/git-pull/helm/Chart.yaml index 5eebf9c2..f03e93d5 100644 --- a/images/git-pull/helm/Chart.yaml +++ b/images/git-pull/helm/Chart.yaml @@ -5,10 +5,10 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.18 +version: 0.1.19 appVersion: "2.54.0-r0" dependencies: - name: chartlib - version: 0.1.8 - # repository: https://instantlinux.github.io/docker-tools - repository: file://../chartlib + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/git-pull/helm/templates/NOTES.txt b/images/git-pull/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/git-pull/helm/templates/NOTES.txt +++ b/images/git-pull/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/git-pull/helm/templates/app.yaml b/images/git-pull/helm/templates/app.yaml index 9b786d6d..ee3d586c 100644 --- a/images/git-pull/helm/templates/app.yaml +++ b/images/git-pull/helm/templates/app.yaml @@ -1,15 +1,13 @@ {{- include "chartlib.configmap" . }} --- -{{- include "chartlib.daemonset" . }} ---- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/haproxy-keepalived/helm/Chart.yaml b/images/haproxy-keepalived/helm/Chart.yaml index 55f97e33..8e620168 100644 --- a/images/haproxy-keepalived/helm/Chart.yaml +++ b/images/haproxy-keepalived/helm/Chart.yaml @@ -7,9 +7,10 @@ sources: - https://github.com/haproxy/haproxy - https://github.com/acassen/keepalived type: application -version: 0.1.24 +version: 0.1.25 appVersion: "3.4.4-alpine-2.3.4-r2" dependencies: - name: chartlib - version: 0.1.8 - repository: http://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/haproxy-keepalived/helm/templates/NOTES.txt b/images/haproxy-keepalived/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/haproxy-keepalived/helm/templates/NOTES.txt +++ b/images/haproxy-keepalived/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/haproxy-keepalived/helm/templates/app.yaml b/images/haproxy-keepalived/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/haproxy-keepalived/helm/templates/app.yaml +++ b/images/haproxy-keepalived/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/il-v1/helm/Chart.yaml b/images/il-v1/helm/Chart.yaml index cf4dc590..a04881bf 100644 --- a/images/il-v1/helm/Chart.yaml +++ b/images/il-v1/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://git.instantlinux.net/richb/instantlinux type: application -version: 0.1.0 +version: 0.1.1 appVersion: "latest" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/il-v1/helm/templates/NOTES.txt b/images/il-v1/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/il-v1/helm/templates/NOTES.txt +++ b/images/il-v1/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/il-v1/helm/templates/app.yaml b/images/il-v1/helm/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/images/il-v1/helm/templates/app.yaml +++ b/images/il-v1/helm/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/mariadb-galera/helm/Chart.yaml b/images/mariadb-galera/helm/Chart.yaml index c6970e69..a353071f 100644 --- a/images/mariadb-galera/helm/Chart.yaml +++ b/images/mariadb-galera/helm/Chart.yaml @@ -7,9 +7,10 @@ sources: - https://github.com/MariaDB/server - https://github.com/MariaDB/galera type: application -version: 0.1.4 +version: 0.1.5 appVersion: "12.3.2" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/mariadb-galera/helm/templates/NOTES.txt b/images/mariadb-galera/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/mariadb-galera/helm/templates/NOTES.txt +++ b/images/mariadb-galera/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/mariadb-galera/helm/templates/app.yaml b/images/mariadb-galera/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/mariadb-galera/helm/templates/app.yaml +++ b/images/mariadb-galera/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/mysqldump/helm/Chart.yaml b/images/mysqldump/helm/Chart.yaml index c701c544..be13a589 100644 --- a/images/mysqldump/helm/Chart.yaml +++ b/images/mysqldump/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/mariadb/server/tree/10.5/client type: application -version: 0.1.19 +version: 0.1.20 appVersion: "11.8.8-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/mysqldump/helm/templates/NOTES.txt b/images/mysqldump/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/mysqldump/helm/templates/NOTES.txt +++ b/images/mysqldump/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/mysqldump/helm/templates/app.yaml b/images/mysqldump/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/mysqldump/helm/templates/app.yaml +++ b/images/mysqldump/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/mythtv-backend/helm/Chart.yaml b/images/mythtv-backend/helm/Chart.yaml index 9bd07118..25854371 100644 --- a/images/mythtv-backend/helm/Chart.yaml +++ b/images/mythtv-backend/helm/Chart.yaml @@ -6,12 +6,13 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/mythtv/mythtv type: application -version: 0.1.24 -appVersion: "36.0-fixes.202608221819.b6ed364d3f" +version: 0.1.25 +appVersion: "36.0-fixes.202609121718.b6ed364d3f" dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: data-sync version: 0.1.3 repository: https://instantlinux.github.io/docker-tools diff --git a/images/mythtv-backend/helm/templates/NOTES.txt b/images/mythtv-backend/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/mythtv-backend/helm/templates/NOTES.txt +++ b/images/mythtv-backend/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/mythtv-backend/helm/templates/app.yaml b/images/mythtv-backend/helm/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/images/mythtv-backend/helm/templates/app.yaml +++ b/images/mythtv-backend/helm/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/images/mythtv-backend/helm/values.yaml b/images/mythtv-backend/helm/values.yaml index 10d9eb1e..7af840c7 100644 --- a/images/mythtv-backend/helm/values.yaml +++ b/images/mythtv-backend/helm/values.yaml @@ -84,30 +84,8 @@ service: autoscaling: enabled: false -authelia: - # To override, use tlsHostname at top level - fqdn: authtotp.example.com - ip: 10.101.1.5 - path: /Myth/LoginUser gateway: enabled: true -ingress: - # This ingress exposes your MythTV schedule and operational controls to - # the public Internet. Set up the admin user before enabling. See - # https://github.com/instantlinux/docker-tools/blob/main/images/mythtv-backend/README.md#upgrade-notes - enabled: false -ingressTOTP: - # Enable this ingress for TOTP if you have Authelia installed, - # along with an external DNS name. - # TODO: this helm chart does trigger TOTP, but Authelia's login - # splash page doesn't come up. The http-post operation to - # /Myth/LoginUser fails to redirect. But you can manually - # bring it up (e.g. https://authtotp.example.com) and authenticate - # there, then come back to the MythTV dashboard's login link. - # Fixing that is a low-priority, as ingress-nginx is deprecated - # and there may be an easier way to implement TOTP under envoy - # gateway. - enabled: false # Subchart data-sync, maintains persistent data across nodes data-sync: diff --git a/images/nut-upsd/helm/Chart.yaml b/images/nut-upsd/helm/Chart.yaml index 0278021e..0bb31236 100644 --- a/images/nut-upsd/helm/Chart.yaml +++ b/images/nut-upsd/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/networkupstools/nut type: application -version: 0.1.13 +version: 0.1.14 appVersion: "2.8.5-r1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/nut-upsd/helm/templates/NOTES.txt b/images/nut-upsd/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/nut-upsd/helm/templates/NOTES.txt +++ b/images/nut-upsd/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/nut-upsd/helm/templates/app.yaml b/images/nut-upsd/helm/templates/app.yaml index 6efcf22b..ee3d586c 100644 --- a/images/nut-upsd/helm/templates/app.yaml +++ b/images/nut-upsd/helm/templates/app.yaml @@ -4,8 +4,10 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} +{{- include "chartlib.listener" . }} --- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/openldap/helm/Chart.yaml b/images/openldap/helm/Chart.yaml index d517c3fd..7d6b9a51 100644 --- a/images/openldap/helm/Chart.yaml +++ b/images/openldap/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://git.openldap.org/openldap/openldap type: application -version: 0.1.10 +version: 0.1.11 appVersion: "2.6.14-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/openldap/helm/templates/NOTES.txt b/images/openldap/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/openldap/helm/templates/NOTES.txt +++ b/images/openldap/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/openldap/helm/templates/app.yaml b/images/openldap/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/openldap/helm/templates/app.yaml +++ b/images/openldap/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/postfix-python/helm/Chart.yaml b/images/postfix-python/helm/Chart.yaml index 4964df71..0147c276 100644 --- a/images/postfix-python/helm/Chart.yaml +++ b/images/postfix-python/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/vdukhovni/postfix type: application -version: 0.1.25 +version: 0.1.26 appVersion: "3.11.6-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/postfix-python/helm/templates/NOTES.txt b/images/postfix-python/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/postfix-python/helm/templates/NOTES.txt +++ b/images/postfix-python/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/postfix-python/helm/templates/app.yaml b/images/postfix-python/helm/templates/app.yaml index aeeec90a..ee3d586c 100644 --- a/images/postfix-python/helm/templates/app.yaml +++ b/images/postfix-python/helm/templates/app.yaml @@ -1,10 +1,10 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/proftpd/helm/Chart.yaml b/images/proftpd/helm/Chart.yaml index 39813574..feacaacf 100644 --- a/images/proftpd/helm/Chart.yaml +++ b/images/proftpd/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/proftpd/proftpd type: application -version: 0.1.15 +version: 0.1.16 appVersion: "1.3.9c-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/proftpd/helm/templates/NOTES.txt b/images/proftpd/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/proftpd/helm/templates/NOTES.txt +++ b/images/proftpd/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/proftpd/helm/templates/app.yaml b/images/proftpd/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/proftpd/helm/templates/app.yaml +++ b/images/proftpd/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/rsyslogd/helm/Chart.yaml b/images/rsyslogd/helm/Chart.yaml index e9610a62..0c2be51d 100644 --- a/images/rsyslogd/helm/Chart.yaml +++ b/images/rsyslogd/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/rsyslog/rsyslog type: application -version: 0.1.16 +version: 0.1.17 appVersion: "8.2604.0-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/rsyslogd/helm/templates/NOTES.txt b/images/rsyslogd/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/rsyslogd/helm/templates/NOTES.txt +++ b/images/rsyslogd/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/rsyslogd/helm/templates/app.yaml b/images/rsyslogd/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/rsyslogd/helm/templates/app.yaml +++ b/images/rsyslogd/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/samba-dc/helm/Chart.yaml b/images/samba-dc/helm/Chart.yaml index 98642b56..ccdcf47f 100644 --- a/images/samba-dc/helm/Chart.yaml +++ b/images/samba-dc/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - ttps://gitlab.com/samba-team/samba type: application -version: 0.1.20 +version: 0.1.21 appVersion: "4.23.10-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/samba-dc/helm/templates/NOTES.txt b/images/samba-dc/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/samba-dc/helm/templates/NOTES.txt +++ b/images/samba-dc/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/samba-dc/helm/templates/app.yaml b/images/samba-dc/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/samba-dc/helm/templates/app.yaml +++ b/images/samba-dc/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/samba/helm/Chart.yaml b/images/samba/helm/Chart.yaml index ad13b692..b1cb1f5a 100644 --- a/images/samba/helm/Chart.yaml +++ b/images/samba/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://gitlab.com/samba-team/samba type: application -version: 0.1.20 +version: 0.1.21 appVersion: "4.23.10-r0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/samba/helm/templates/NOTES.txt b/images/samba/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/samba/helm/templates/NOTES.txt +++ b/images/samba/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/samba/helm/templates/app.yaml b/images/samba/helm/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/images/samba/helm/templates/app.yaml +++ b/images/samba/helm/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/images/spamassassin/helm/Chart.yaml b/images/spamassassin/helm/Chart.yaml index 5e1f3c9f..cf0645da 100644 --- a/images/spamassassin/helm/Chart.yaml +++ b/images/spamassassin/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://svn.apache.org/viewvc/spamassassin type: application -version: 0.1.5 +version: 0.1.6 appVersion: "4.0.2-3" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/spamassassin/helm/templates/NOTES.txt b/images/spamassassin/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/spamassassin/helm/templates/NOTES.txt +++ b/images/spamassassin/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/spamassassin/helm/templates/app.yaml b/images/spamassassin/helm/templates/app.yaml index b4b1ef34..ee3d586c 100644 --- a/images/spamassassin/helm/templates/app.yaml +++ b/images/spamassassin/helm/templates/app.yaml @@ -4,9 +4,9 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} +{{- include "chartlib.listener" . }} --- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} --- diff --git a/images/squirrelmail/helm/Chart.yaml b/images/squirrelmail/helm/Chart.yaml index 72fef932..8818cd37 100644 --- a/images/squirrelmail/helm/Chart.yaml +++ b/images/squirrelmail/helm/Chart.yaml @@ -5,9 +5,10 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.1 +version: 0.1.2 appVersion: "latest" dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/squirrelmail/helm/templates/NOTES.txt b/images/squirrelmail/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/squirrelmail/helm/templates/NOTES.txt +++ b/images/squirrelmail/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/squirrelmail/helm/templates/app.yaml b/images/squirrelmail/helm/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/images/squirrelmail/helm/templates/app.yaml +++ b/images/squirrelmail/helm/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/images/weewx/helm-nginx/Chart.yaml b/images/weewx/helm-nginx/Chart.yaml index 39aa8c50..77355f2c 100644 --- a/images/weewx/helm-nginx/Chart.yaml +++ b/images/weewx/helm-nginx/Chart.yaml @@ -5,9 +5,10 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.6 +version: 0.1.7 appVersion: "1.31.2-alpine" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/weewx/helm-nginx/templates/NOTES.txt b/images/weewx/helm-nginx/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/weewx/helm-nginx/templates/NOTES.txt +++ b/images/weewx/helm-nginx/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/weewx/helm-nginx/templates/app.yaml b/images/weewx/helm-nginx/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/images/weewx/helm-nginx/templates/app.yaml +++ b/images/weewx/helm-nginx/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/images/weewx/helm-nginx/values.yaml b/images/weewx/helm-nginx/values.yaml index f66dbbe8..be9d0908 100644 --- a/images/weewx/helm-nginx/values.yaml +++ b/images/weewx/helm-nginx/values.yaml @@ -67,10 +67,19 @@ service: type: ClusterIP autoscaling: enabled: false +gateway: + enabled: true + external: true + name: gateway-2 + listeners: + - name: http + hostname: wx.example.com + port: 80 + protocol: HTTP -ingress: - hosts: - - host: wx.example.com - paths: - - path: / - pathType: Prefix +# ingress: +# hosts: +# - host: wx.example.com +# paths: +# - path: / +# pathType: Prefix diff --git a/images/weewx/helm/Chart.yaml b/images/weewx/helm/Chart.yaml index 7c8a61e9..55705d4d 100644 --- a/images/weewx/helm/Chart.yaml +++ b/images/weewx/helm/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/weewx/weewx/ type: application -version: 0.1.11 +version: 0.1.12 appVersion: "5.5.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/images/weewx/helm/templates/NOTES.txt b/images/weewx/helm/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/images/weewx/helm/templates/NOTES.txt +++ b/images/weewx/helm/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/images/weewx/helm/templates/app.yaml b/images/weewx/helm/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/images/weewx/helm/templates/app.yaml +++ b/images/weewx/helm/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/k8s/Makefile b/k8s/Makefile index 1b41b5ef..4b700c75 100644 --- a/k8s/Makefile +++ b/k8s/Makefile @@ -91,10 +91,9 @@ INSTALL_YAML = $(basename $(wildcard install/*.yaml)) \ $(addprefix imports/, $(IMPORTS)) VOLUMES_YAML = $(basename $(wildcard volumes/*.yaml)) -install: install/admin-user cluster_network imports \ - install_imports namespace_config fluent-bit remote_volumes \ - sops data-sync-ssh persistent secrets install/ingress-nginx \ - infra storage_localdefault +install: install/admin-user cluster_network imports install_imports \ + namespace_config fluent-bit remote_volumes sops data-sync-ssh \ + persistent secrets infra storage_localdefault namespace_config: install/namespace install/namespace-user secrets/regcred diff --git a/k8s/Makefile.vars b/k8s/Makefile.vars index b0f329c4..be420552 100644 --- a/k8s/Makefile.vars +++ b/k8s/Makefile.vars @@ -1,8 +1,9 @@ # Variables for Kubernetes resources -# These are referred to from within resource yaml files -# Customize values as needed -# NOTE: if using helm, provide a yaml file to override values (see -# the CHARTS rule in Makefile.helm). +# These are referred to from within ./install/*.yaml files and +# docker-compose files under ../services. Customize values as needed +# NOTE: for helm, for each chart instance provide a yaml file as +# ~/docker/admin/services/values/.yaml to override values; +# global overrides can be placed in ~/docker/admin/services/values.yaml. export DOMAIN ?= domain.com @@ -26,21 +27,15 @@ export POOL_SIZE_SMALL = 500Mi export TZ ?= UTC # IP addresses - TODO replace static IPs with names, if practical -export AUTHELIA_IP ?= 10.101.1.5 export COREDNS_IP ?= 10.96.0.10 -export K8S_INGRESS_NGINX_IP ?= 10.101.1.2 export MONITOR_EXT_IP ?= 192.168.1.20 export NODE_LOCAL_DNS_IP ?= 169.254.0.10 export RSYSLOGD_IP ?= 10.101.1.40 -# Exposed nodePorts - install/ingress-nginx.yaml -export NODEPORT_HTTP ?= 30080 -export NODEPORT_HTTPS ?= 30443 - # Ports configured in ingress-nginx.yaml -export PORT_DOVECOT_IMAPD ?= 843 -export PORT_DOVECOT_IMAPS ?= 993 -export PORT_DOVECOT_SMTP ?= 825 -export PORT_GIT_SSH ?= 8999 -# export PORT_POSTFIX_INTERNAL ?= 3425 -export PORT_POSTFIX_EXTERNAL ?= 3525 +# export PORT_DOVECOT_IMAPD ?= 843 +# export PORT_DOVECOT_IMAPS ?= 993 +# export PORT_DOVECOT_SMTP ?= 825 +# export PORT_GIT_SSH ?= 8999 +# # export PORT_POSTFIX_INTERNAL ?= 3425 +# export PORT_POSTFIX_EXTERNAL ?= 3525 diff --git a/k8s/Makefile.versions b/k8s/Makefile.versions index 5f6c9f65..f8fea28c 100644 --- a/k8s/Makefile.versions +++ b/k8s/Makefile.versions @@ -1,10 +1,8 @@ # Third-party versions export VERSION_CERT_MANAGER ?= 1.21.2 -export VERSION_DEFAULTBACKEND ?= 1.5 export VERSION_ENVOY_GATEWAY ?= 1.9.1 export VERSION_FLANNEL ?= 0.28.9 export VERSION_HELM ?= 4.3.0 -export VERSION_INGRESS_NGINX ?= 1.15.1 export VERSION_METRICS ?= 2.18.0 export VERSION_NODE_LOCAL_DNS ?= 1.36.4 VERSION_SOPS ?= 3.13.0 diff --git a/k8s/README.md b/k8s/README.md index 439f53db..c427ba93 100644 --- a/k8s/README.md +++ b/k8s/README.md @@ -30,7 +30,6 @@ kubeadm suite: * A k8sudo script to encrypt/decrypt k8s admin key * Mozilla [sops](https://github.com/mozilla/sops/blob/master/README.rst) with encryption (to keep credentials in local git repo) * Encryption for internal etcd -* MFA using [Authelia](https://github.com/clems4ever/authelia) and Google Authenticator * Calico or flannel networking * Fluent Bit for container-log aggregation * Envoy API gateway diff --git a/k8s/helm/authelia/Chart.yaml b/k8s/helm-deprecated/authelia/Chart.yaml similarity index 100% rename from k8s/helm/authelia/Chart.yaml rename to k8s/helm-deprecated/authelia/Chart.yaml diff --git a/k8s/helm/authelia/subcharts/ldap/.helmignore b/k8s/helm-deprecated/authelia/subcharts/ldap/.helmignore similarity index 100% rename from k8s/helm/authelia/subcharts/ldap/.helmignore rename to k8s/helm-deprecated/authelia/subcharts/ldap/.helmignore diff --git a/k8s/helm/authelia/subcharts/ldap/Chart.yaml b/k8s/helm-deprecated/authelia/subcharts/ldap/Chart.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/ldap/Chart.yaml rename to k8s/helm-deprecated/authelia/subcharts/ldap/Chart.yaml diff --git a/k8s/helm/authelia/subcharts/ldap/templates/NOTES.txt b/k8s/helm-deprecated/authelia/subcharts/ldap/templates/NOTES.txt similarity index 100% rename from k8s/helm/authelia/subcharts/ldap/templates/NOTES.txt rename to k8s/helm-deprecated/authelia/subcharts/ldap/templates/NOTES.txt diff --git a/k8s/helm/authelia/subcharts/ldap/templates/app.yaml b/k8s/helm-deprecated/authelia/subcharts/ldap/templates/app.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/ldap/templates/app.yaml rename to k8s/helm-deprecated/authelia/subcharts/ldap/templates/app.yaml diff --git a/k8s/helm/authelia/subcharts/ldap/templates/tests/test-connection.yaml b/k8s/helm-deprecated/authelia/subcharts/ldap/templates/tests/test-connection.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/ldap/templates/tests/test-connection.yaml rename to k8s/helm-deprecated/authelia/subcharts/ldap/templates/tests/test-connection.yaml diff --git a/k8s/helm/authelia/subcharts/ldap/values.yaml b/k8s/helm-deprecated/authelia/subcharts/ldap/values.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/ldap/values.yaml rename to k8s/helm-deprecated/authelia/subcharts/ldap/values.yaml diff --git a/k8s/helm/authelia/subcharts/redis/.helmignore b/k8s/helm-deprecated/authelia/subcharts/redis/.helmignore similarity index 100% rename from k8s/helm/authelia/subcharts/redis/.helmignore rename to k8s/helm-deprecated/authelia/subcharts/redis/.helmignore diff --git a/k8s/helm/authelia/subcharts/redis/Chart.yaml b/k8s/helm-deprecated/authelia/subcharts/redis/Chart.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/redis/Chart.yaml rename to k8s/helm-deprecated/authelia/subcharts/redis/Chart.yaml diff --git a/k8s/helm/authelia/subcharts/redis/templates/NOTES.txt b/k8s/helm-deprecated/authelia/subcharts/redis/templates/NOTES.txt similarity index 100% rename from k8s/helm/authelia/subcharts/redis/templates/NOTES.txt rename to k8s/helm-deprecated/authelia/subcharts/redis/templates/NOTES.txt diff --git a/k8s/helm/authelia/subcharts/redis/templates/app.yaml b/k8s/helm-deprecated/authelia/subcharts/redis/templates/app.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/redis/templates/app.yaml rename to k8s/helm-deprecated/authelia/subcharts/redis/templates/app.yaml diff --git a/k8s/helm/authelia/subcharts/redis/templates/tests/test-connection.yaml b/k8s/helm-deprecated/authelia/subcharts/redis/templates/tests/test-connection.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/redis/templates/tests/test-connection.yaml rename to k8s/helm-deprecated/authelia/subcharts/redis/templates/tests/test-connection.yaml diff --git a/k8s/helm/authelia/subcharts/redis/values.yaml b/k8s/helm-deprecated/authelia/subcharts/redis/values.yaml similarity index 100% rename from k8s/helm/authelia/subcharts/redis/values.yaml rename to k8s/helm-deprecated/authelia/subcharts/redis/values.yaml diff --git a/k8s/helm/authelia/templates/NOTES.txt b/k8s/helm-deprecated/authelia/templates/NOTES.txt similarity index 100% rename from k8s/helm/authelia/templates/NOTES.txt rename to k8s/helm-deprecated/authelia/templates/NOTES.txt diff --git a/k8s/helm/authelia/templates/app.yaml b/k8s/helm-deprecated/authelia/templates/app.yaml similarity index 100% rename from k8s/helm/authelia/templates/app.yaml rename to k8s/helm-deprecated/authelia/templates/app.yaml diff --git a/k8s/helm/authelia/templates/configmap.yaml b/k8s/helm-deprecated/authelia/templates/configmap.yaml similarity index 100% rename from k8s/helm/authelia/templates/configmap.yaml rename to k8s/helm-deprecated/authelia/templates/configmap.yaml diff --git a/k8s/helm/authelia/templates/tests/test-connection.yaml b/k8s/helm-deprecated/authelia/templates/tests/test-connection.yaml similarity index 100% rename from k8s/helm/authelia/templates/tests/test-connection.yaml rename to k8s/helm-deprecated/authelia/templates/tests/test-connection.yaml diff --git a/k8s/helm/authelia/values.yaml b/k8s/helm-deprecated/authelia/values.yaml similarity index 100% rename from k8s/helm/authelia/values.yaml rename to k8s/helm-deprecated/authelia/values.yaml diff --git a/k8s/helm/apache/Chart.yaml b/k8s/helm/apache/Chart.yaml index 48db7dcc..89bd0c8a 100644 --- a/k8s/helm/apache/Chart.yaml +++ b/k8s/helm/apache/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/apache/httpd type: application -version: 0.1.0 +version: 0.1.1 appVersion: "2.4.68" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/apache/templates/NOTES.txt b/k8s/helm/apache/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/apache/templates/NOTES.txt +++ b/k8s/helm/apache/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/apache/templates/app.yaml b/k8s/helm/apache/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/apache/templates/app.yaml +++ b/k8s/helm/apache/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/apache/values.yaml b/k8s/helm/apache/values.yaml index 759c1f21..5c59353b 100644 --- a/k8s/helm/apache/values.yaml +++ b/k8s/helm/apache/values.yaml @@ -51,19 +51,12 @@ service: ports: - { port: 80, targetPort: 80, name: apache } type: ClusterIP - -ingress: - enabled: true - className: "" - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/enable-access-log: "false" - nginx.ingress.kubernetes.io/proxy-body-size: "50m" - nginx.ingress.kubernetes.io/ssl-redirect: "false" - autoscaling: enabled: false +gateway: + enabled: true + external: true + name: gateway-2 configmap: data: diff --git a/k8s/helm/chartlib/Chart.yaml b/k8s/helm/chartlib/Chart.yaml index 075d0e4d..1bb4929c 100644 --- a/k8s/helm/chartlib/Chart.yaml +++ b/k8s/helm/chartlib/Chart.yaml @@ -4,4 +4,4 @@ description: Standard templates library sources: - https://github.com/instantlinux/docker-tools type: library -version: 0.1.10 +version: 0.1.11 diff --git a/k8s/helm/chartlib/templates/_ingress.tpl b/k8s/helm/chartlib/templates/_ingress.tpl deleted file mode 100644 index c06b5f4c..00000000 --- a/k8s/helm/chartlib/templates/_ingress.tpl +++ /dev/null @@ -1,77 +0,0 @@ -{{- define "chartlib.ingress" -}} -{{- if hasKey .Values "ingress" -}} -{{- if or .Values.ingress.enabled (not (hasKey .Values.ingress "enabled")) -}} -{{- $fullName := include "local.fullname" . -}} -{{- $svcPort := .Values.ingress.port | default (index .Values.service.ports 0).port -}} -{{- if and .Values.ingress.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }} - {{- if not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class") }} - {{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className}} - {{- end }} -{{- end }} -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: {{ $fullName }} - labels: - {{- include "local.labels" . | nindent 4 }} - annotations: - {{- if hasKey .Values.ingress "annotations" }} - {{- toYaml .Values.ingress.annotations | nindent 4 }} - {{- else }} - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - {{- end }} -spec: - ingressClassName: {{ .Values.ingress.className }} - {{- if hasKey .Values.ingress "tls" }} - tls: - {{- range .Values.ingress.tls }} - - hosts: - {{- range .hosts }} - - {{ . | quote }} - {{- end }} - secretName: {{ .secretName }} - {{- end }} - {{- else if hasKey .Values "tlsHostname" }} - tls: - - hosts: - - {{ .Values.tlsHostname }} - secretName: tls-{{ $fullName }} - {{- end }} - rules: - {{- if hasKey .Values.ingress "rules" }} - {{- with .Values.ingress.rules }} - {{- toYaml . | nindent 4 }} - {{- end }} - {{- else }} - {{- if hasKey .Values.ingress "hosts" }} - {{- range .Values.ingress.hosts }} - - host: {{ .host | quote }} - http: - paths: - {{- range .paths }} - - path: {{ .path }} - pathType: {{ .pathType }} - backend: - service: - name: {{ $fullName }} - port: - number: {{ $svcPort }} - {{- end }} - {{- end }} - {{- else if hasKey .Values "tlsHostname" }} - - host: {{ .Values.tlsHostname }} - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: {{ $fullName }} - port: - number: {{ $svcPort }} - {{- end }} - {{- end }} -{{- end }} -{{- end }} -{{- end }} diff --git a/k8s/helm/chartlib/templates/_ingresstotp.tpl b/k8s/helm/chartlib/templates/_ingresstotp.tpl deleted file mode 100644 index e028e05d..00000000 --- a/k8s/helm/chartlib/templates/_ingresstotp.tpl +++ /dev/null @@ -1,74 +0,0 @@ -{{- define "chartlib.ingresstotp" -}} -{{- if hasKey .Values "ingressTOTP" -}} -{{- if or .Values.ingressTOTP.enabled (not (hasKey .Values.ingressTOTP "enabled")) -}} -{{- $fullName := include "local.fullname" . -}} -{{- $svcPort := .Values.ingressTOTP.port | default (index .Values.service.ports 0).port -}} -{{- if and .Values.ingressTOTP.className (not (semverCompare ">=1.18-0" .Capabilities.KubeVersion.GitVersion)) }} - {{- if not (hasKey .Values.ingressTOTP.annotations "kubernetes.io/ingress.class") }} - {{- $_ := set .Values.ingressTOTP.annotations "kubernetes.io/ingress.class" .Values.ingressTOTP.className}} - {{- end }} -{{- end }} -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: {{ $fullName }}-totp - labels: - {{- include "local.labels" . | nindent 4 }} - annotations: - {{- if hasKey .Values.ingressTOTP "annotations" }} - {{- toYaml .Values.ingressTOTP.annotations | nindent 4 }} - {{- else }} - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/auth-url: http://{{ .Values.authelia.ip }}/api/verify - nginx.ingress.kubernetes.io/auth-signin: https://{{ .Values.authelia.fqdn }} - nginx.ingress.kubernetes.io/use-regex: "true" - {{- end }} -spec: - ingressClassName: {{ .Values.ingressTOTP.className }} - {{- if hasKey .Values.ingressTOTP "tls" }} - tls: - {{- range .Values.ingressTOTP.tls }} - - hosts: - {{- range .hosts }} - - {{ . | quote }} - {{- end }} - secretName: {{ .secretName }} - {{- end }} - {{- else if hasKey .Values "tlsHostname" }} - tls: - - hosts: - - {{ .Values.tlsHostname }} - secretName: tls-{{ $fullName }} - {{- end }} - rules: - {{- if hasKey .Values.ingressTOTP "hosts" }} - {{- range .Values.ingressTOTP.hosts }} - - host: {{ .host | quote }} - http: - paths: - {{- range .paths }} - - path: {{ .path }} - pathType: {{ .pathType }} - backend: - service: - name: {{ $fullName }} - port: - number: {{ $svcPort }} - {{- end }} - {{- end }} - {{- else }} - - host: {{ .Values.tlsHostname }} - http: - paths: - - backend: - service: - name: {{ $fullName }} - port: - number: {{ $svcPort }} - path: {{ .Values.authelia.path }} - pathType: Prefix - {{- end }} -{{- end }} -{{- end }} -{{- end }} diff --git a/k8s/helm/chartlib/templates/_listener.yaml b/k8s/helm/chartlib/templates/_listener.yaml index 8e437675..81bd2642 100644 --- a/k8s/helm/chartlib/templates/_listener.yaml +++ b/k8s/helm/chartlib/templates/_listener.yaml @@ -53,7 +53,7 @@ spec: parentRefs: - kind: ListenerSet name: {{ $fullName }} - sectionName: https + sectionName: http{{- if hasKey .Values "tlsHostname" }}s{{ end }} rules: {{- if hasKey .Values.gateway "routeRules" }} {{- toYaml .Values.gateway.routeRules | nindent 2 }} @@ -66,6 +66,7 @@ spec: - name: {{ $fullName }} port: {{ $svcPort }} {{- end }} +{{- if hasKey .Values "tlsHostname" }} --- apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute @@ -82,62 +83,7 @@ spec: requestRedirect: scheme: https statusCode: 308 -{{- if and (hasKey .Values.gateway "totp") .Values.gateway.totp -}} --- -apiVersion: gateway.networking.k8s.io/v1 -kind: HTTPRoute -metadata: - name: {{ $fullName }}-authelia -spec: - parentRefs: - - kind: ListenerSet - name: {{ $fullName }} - sectionName: https - rules: - - matches: - - path: - type: PathPrefix - value: {{ .Values.authelia.path }} - backendRefs: - - name: {{ $fullName }} - port: {{ $svcPort }} ---- -apiVersion: gateway.envoyproxy.io/v1alpha1 -kind: SecurityPolicy -metadata: - name: {{ $fullName }}-totp -spec: - targetRefs: - - group: gateway.networking.k8s.io - # kind: HTTPRoute - # name: {{ $fullName }}-authelia - kind: Gateway - name: {{ .Values.gateway.name | default "gateway-1" }} - extAuth: - failOpen: false - headersToExtAuth: - - accept - - authorization - - cookie - - location - - proxy-authorization - - x-forwarded-host - - x-forwarded-method - - x-forwarded-proto - - x-forwarded-uri - http: - backendRefs: - - name: {{ .Values.authelia.service | default "authelia" }} - port: {{ .Values.authelia.port | default 80 }} - {{- if hasKey .Values.authelia "namespace" }} - namespace: {{ .Values.authelia.namespace }} - {{- end }} - headersToBackend: - - Remote-Email - - Remote-Groups - - Remote-Name - - Remote-User - path: /api/authz/ext-authz/ {{- end }} {{- end }} {{- end }} diff --git a/k8s/helm/etcd/templates/NOTES.txt b/k8s/helm/etcd/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/etcd/templates/NOTES.txt +++ b/k8s/helm/etcd/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/etcd/templates/app.yaml b/k8s/helm/etcd/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/etcd/templates/app.yaml +++ b/k8s/helm/etcd/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/gitea/Chart.yaml b/k8s/helm/gitea/Chart.yaml index 192ea3dc..d7571e35 100644 --- a/k8s/helm/gitea/Chart.yaml +++ b/k8s/helm/gitea/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/go-gitea/gitea type: application -version: 0.1.11 +version: 0.1.12 appVersion: 1.27.3-rootless dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/gitea/templates/NOTES.txt b/k8s/helm/gitea/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/gitea/templates/NOTES.txt +++ b/k8s/helm/gitea/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/gitea/templates/app.yaml b/k8s/helm/gitea/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/k8s/helm/gitea/templates/app.yaml +++ b/k8s/helm/gitea/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/k8s/helm/gitea/values.yaml b/k8s/helm/gitea/values.yaml index 66892a07..93815788 100644 --- a/k8s/helm/gitea/values.yaml +++ b/k8s/helm/gitea/values.yaml @@ -101,9 +101,3 @@ autoscaling: gateway: enabled: true -ingress: - enabled: false - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/enable-access-log: "false" diff --git a/k8s/helm/grafana/Chart.yaml b/k8s/helm/grafana/Chart.yaml index b3bb6ebe..6ff48120 100644 --- a/k8s/helm/grafana/Chart.yaml +++ b/k8s/helm/grafana/Chart.yaml @@ -11,13 +11,14 @@ version: 0.1.6 appVersion: 13.0.6 dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: prometheus - version: 0.1.4 + version: 0.1.5 repository: file://subcharts/prometheus condition: prometheus.enabled - name: alertmanager - version: 0.1.2 + version: 0.1.3 repository: file://subcharts/alertmanager condition: alertmanager.enabled diff --git a/k8s/helm/grafana/subcharts/alertmanager/Chart.yaml b/k8s/helm/grafana/subcharts/alertmanager/Chart.yaml index 4540fff2..6783c53f 100644 --- a/k8s/helm/grafana/subcharts/alertmanager/Chart.yaml +++ b/k8s/helm/grafana/subcharts/alertmanager/Chart.yaml @@ -6,9 +6,9 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/r/prom/alertmanager type: application -version: 0.1.2 +version: 0.1.3 appVersion: "v0.33.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/grafana/subcharts/alertmanager/templates/app.yaml b/k8s/helm/grafana/subcharts/alertmanager/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/grafana/subcharts/alertmanager/templates/app.yaml +++ b/k8s/helm/grafana/subcharts/alertmanager/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/grafana/subcharts/prometheus/Chart.yaml b/k8s/helm/grafana/subcharts/prometheus/Chart.yaml index 94776f9a..ba40db6d 100644 --- a/k8s/helm/grafana/subcharts/prometheus/Chart.yaml +++ b/k8s/helm/grafana/subcharts/prometheus/Chart.yaml @@ -6,9 +6,9 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/r/prom/prometheus type: application -version: 0.1.4 +version: 0.1.5 appVersion: "v3.13.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/grafana/subcharts/prometheus/templates/app.yaml b/k8s/helm/grafana/subcharts/prometheus/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/grafana/subcharts/prometheus/templates/app.yaml +++ b/k8s/helm/grafana/subcharts/prometheus/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/grafana/templates/NOTES.txt b/k8s/helm/grafana/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/grafana/templates/NOTES.txt +++ b/k8s/helm/grafana/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/grafana/templates/app.yaml b/k8s/helm/grafana/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/k8s/helm/grafana/templates/app.yaml +++ b/k8s/helm/grafana/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/k8s/helm/grafana/values.yaml b/k8s/helm/grafana/values.yaml index 09640acb..66494508 100644 --- a/k8s/helm/grafana/values.yaml +++ b/k8s/helm/grafana/values.yaml @@ -80,21 +80,8 @@ service: type: ClusterIP autoscaling: enabled: false - -authelia: - fqdn: authtotp.example.com - ip: 10.101.1.5 - path: /login gateway: enabled: true -ingress: - enabled: false - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/enable-access-log: "false" -ingressTOTP: - enabled: false # Subchart parameters prometheus: diff --git a/k8s/helm/guacamole/Chart.yaml b/k8s/helm/guacamole/Chart.yaml index 2bc2fadf..a8098b8d 100644 --- a/k8s/helm/guacamole/Chart.yaml +++ b/k8s/helm/guacamole/Chart.yaml @@ -13,11 +13,11 @@ version: 0.1.6 appVersion: "1.6.0" dependencies: - name: chartlib - version: 0.1.10 + version: 0.1.11 repository: oci://registry-1.docker.io/instantlinux - name: guacamole-server - version: 0.1.6 + version: 0.1.7 repository: file://subcharts/guacamole-server - name: guacd - version: 0.1.5 + version: 0.1.6 repository: file://subcharts/guacd diff --git a/k8s/helm/guacamole/subcharts/guacamole-server/Chart.yaml b/k8s/helm/guacamole/subcharts/guacamole-server/Chart.yaml index 2f04c49b..79ff149f 100644 --- a/k8s/helm/guacamole/subcharts/guacamole-server/Chart.yaml +++ b/k8s/helm/guacamole/subcharts/guacamole-server/Chart.yaml @@ -6,9 +6,9 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/apache/guacamole-server type: application -version: 0.1.6 +version: 0.1.7 appVersion: "1.6.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/guacamole/subcharts/guacamole-server/templates/app.yaml b/k8s/helm/guacamole/subcharts/guacamole-server/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/k8s/helm/guacamole/subcharts/guacamole-server/templates/app.yaml +++ b/k8s/helm/guacamole/subcharts/guacamole-server/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/k8s/helm/guacamole/subcharts/guacd/Chart.yaml b/k8s/helm/guacamole/subcharts/guacd/Chart.yaml index ff92cb43..c4c25d96 100644 --- a/k8s/helm/guacamole/subcharts/guacd/Chart.yaml +++ b/k8s/helm/guacamole/subcharts/guacd/Chart.yaml @@ -6,9 +6,9 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/apache/guacamole-client type: application -version: 0.1.5 +version: 0.1.6 appVersion: "1.6.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/guacamole/subcharts/guacd/templates/app.yaml b/k8s/helm/guacamole/subcharts/guacd/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/guacamole/subcharts/guacd/templates/app.yaml +++ b/k8s/helm/guacamole/subcharts/guacd/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/guacamole/templates/NOTES.txt b/k8s/helm/guacamole/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/guacamole/templates/NOTES.txt +++ b/k8s/helm/guacamole/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/headscale/Chart.yaml b/k8s/helm/headscale/Chart.yaml index 088cdbb5..d6c2f66a 100644 --- a/k8s/helm/headscale/Chart.yaml +++ b/k8s/helm/headscale/Chart.yaml @@ -6,13 +6,14 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/juanfont/headscale type: application -version: 0.1.1 +version: 0.1.2 appVersion: "0.29.3" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: headplane - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/headplane condition: headplane.enabled diff --git a/k8s/helm/headscale/subcharts/headplane/Chart.yaml b/k8s/helm/headscale/subcharts/headplane/Chart.yaml index e6e004e5..a93e5c64 100644 --- a/k8s/helm/headscale/subcharts/headplane/Chart.yaml +++ b/k8s/helm/headscale/subcharts/headplane/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/tale/headplane type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from ghcr.io in top-level values.yaml appVersion: "0.0.1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/headscale/subcharts/headplane/templates/app.yaml b/k8s/helm/headscale/subcharts/headplane/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/headscale/subcharts/headplane/templates/app.yaml +++ b/k8s/helm/headscale/subcharts/headplane/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/headscale/subcharts/headplane/values.yaml b/k8s/helm/headscale/subcharts/headplane/values.yaml index 47bbe127..1bcbb07e 100644 --- a/k8s/helm/headscale/subcharts/headplane/values.yaml +++ b/k8s/helm/headscale/subcharts/headplane/values.yaml @@ -45,6 +45,3 @@ service: type: ClusterIP autoscaling: enabled: false - -ingress: - enabled: false diff --git a/k8s/helm/headscale/templates/NOTES.txt b/k8s/helm/headscale/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/headscale/templates/NOTES.txt +++ b/k8s/helm/headscale/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/headscale/templates/app.yaml b/k8s/helm/headscale/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/headscale/templates/app.yaml +++ b/k8s/helm/headscale/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/headscale/values.yaml b/k8s/helm/headscale/values.yaml index b6a4c1fe..d8e1e10e 100644 --- a/k8s/helm/headscale/values.yaml +++ b/k8s/helm/headscale/values.yaml @@ -58,41 +58,33 @@ service: - { port: 3478, targetPort: 3478, name: stun, protocol: UDP } - { port: 41641, targetPort: 41461, name: wireguard, protocol: UDP } type: ClusterIP - -ingress: - enabled: true - className: "" - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/enable-access-log: "false" - nginx.ingress.kubernetes.io/proxy-buffering: "off" - nginx.ingress.kubernetes.io/proxy-read-timeout: "3600" - nginx.ingress.kubernetes.io/proxy-send-timeout: "3600" - nginx.ingress.kubernetes.io/configuration-snippet: | - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection $connection_upgrade; - rules: - - host: headscale.example.com - http: - paths: - - path: /admin - backend: - service: - name: headscale-headplane - port: - number: 3000 - pathType: Prefix - - path: / - backend: - service: - name: headscale - port: - number: 8080 - pathType: Prefix - autoscaling: enabled: false +gateway: + enabled: true + external: true + name: gateway-2 + routeRules: + - backendRefs: + - group: "" + kind: Service + name: headscale + port: 8080 + weight: 1 + matches: + - path: + type: PathPrefix + value: / + - backendRefs: + - group: "" + kind: Service + name: headscale-headplane + port: 3000 + weight: 1 + matches: + - path: + type: PathPrefix + value: /admin configmap: data: diff --git a/k8s/helm/immich/Chart.yaml b/k8s/helm/immich/Chart.yaml index a1461fae..7b96e7dc 100644 --- a/k8s/helm/immich/Chart.yaml +++ b/k8s/helm/immich/Chart.yaml @@ -6,19 +6,20 @@ sources: - https://github.com/immich-app/immich - https://github.com/instantlinux/docker-tools type: application -version: 0.1.3 +version: 0.1.4 # Reminder, update tag for ml instance in values.yaml appVersion: v3.0.1 dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: ml - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/ml - name: postgres - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/postgres - name: valkey - version: 0.1.1 + version: 0.1.2 repository: file://subcharts/valkey diff --git a/k8s/helm/immich/subcharts/ml/Chart.yaml b/k8s/helm/immich/subcharts/ml/Chart.yaml index 29a90154..7168dd00 100644 --- a/k8s/helm/immich/subcharts/ml/Chart.yaml +++ b/k8s/helm/immich/subcharts/ml/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - ghcr.io/immich-app/immich-machine-learning type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: "0.0.1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/immich/subcharts/ml/templates/app.yaml b/k8s/helm/immich/subcharts/ml/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/immich/subcharts/ml/templates/app.yaml +++ b/k8s/helm/immich/subcharts/ml/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/immich/subcharts/postgres/Chart.yaml b/k8s/helm/immich/subcharts/postgres/Chart.yaml index 5d84c96b..dc58c68f 100644 --- a/k8s/helm/immich/subcharts/postgres/Chart.yaml +++ b/k8s/helm/immich/subcharts/postgres/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/_/postgres type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: "0.0.1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/immich/subcharts/postgres/templates/app.yaml b/k8s/helm/immich/subcharts/postgres/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/immich/subcharts/postgres/templates/app.yaml +++ b/k8s/helm/immich/subcharts/postgres/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/immich/subcharts/valkey/Chart.yaml b/k8s/helm/immich/subcharts/valkey/Chart.yaml index af73c069..643c5d5e 100644 --- a/k8s/helm/immich/subcharts/valkey/Chart.yaml +++ b/k8s/helm/immich/subcharts/valkey/Chart.yaml @@ -6,9 +6,9 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/r/valkey/valkey type: application -version: 0.1.1 +version: 0.1.2 appVersion: "9.1.0-alpine" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/immich/subcharts/valkey/templates/app.yaml b/k8s/helm/immich/subcharts/valkey/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/immich/subcharts/valkey/templates/app.yaml +++ b/k8s/helm/immich/subcharts/valkey/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/immich/subcharts/valkey/values.yaml b/k8s/helm/immich/subcharts/valkey/values.yaml index 32b9c858..99881b03 100644 --- a/k8s/helm/immich/subcharts/valkey/values.yaml +++ b/k8s/helm/immich/subcharts/valkey/values.yaml @@ -57,8 +57,6 @@ service: type: ClusterIP autoscaling: enabled: false -ingress: - enabled: false configmap: name: valkey-config diff --git a/k8s/helm/immich/templates/NOTES.txt b/k8s/helm/immich/templates/NOTES.txt index f8c53210..7309f065 100644 --- a/k8s/helm/immich/templates/NOTES.txt +++ b/k8s/helm/immich/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") @@ -26,5 +22,3 @@ {{- end }} {{- end }} {{- end }} -2. Make sure to set the versionPrev value to the version returned in - /var/www/html/config/config.php after most recent upgrade diff --git a/k8s/helm/immich/templates/app.yaml b/k8s/helm/immich/templates/app.yaml index b925dd1f..ee3d586c 100644 --- a/k8s/helm/immich/templates/app.yaml +++ b/k8s/helm/immich/templates/app.yaml @@ -4,10 +4,10 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/k8s/helm/immich/values.yaml b/k8s/helm/immich/values.yaml index 3e4bfbd9..27a413b7 100644 --- a/k8s/helm/immich/values.yaml +++ b/k8s/helm/immich/values.yaml @@ -136,8 +136,16 @@ service: ports: - { port: 80, targetPort: 2283 } type: ClusterIP +autoscaling: + enabled: false +gateway: + enabled: true + external: true + name: gateway-2 ingress: + # TODO remove + enabled: false annotations: cert-manager.io/cluster-issuer: letsencrypt-prod kubernetes.io/ingress.class: nginx @@ -155,9 +163,6 @@ ingress: proxy_set_header Connection "upgrade"; proxy_cookie_path: ""; -autoscaling: - enabled: false - configmap: name: immich enabled: false diff --git a/k8s/helm/infra/Chart.yaml b/k8s/helm/infra/Chart.yaml index bff29269..a645e45e 100644 --- a/k8s/helm/infra/Chart.yaml +++ b/k8s/helm/infra/Chart.yaml @@ -5,9 +5,9 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.0 +version: 0.1.1 appVersion: "0.1.0" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.10 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/infra/templates/NOTES.txt b/k8s/helm/infra/templates/NOTES.txt index 62ea3f4b..b5af3d91 100644 --- a/k8s/helm/infra/templates/NOTES.txt +++ b/k8s/helm/infra/templates/NOTES.txt @@ -1,28 +1,8 @@ -{{- if hasKey .Values "service" }} -{{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} -1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} -{{- else if contains "NodePort" .Values.service.type }} - export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) - export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - echo http://$NODE_IP:$NODE_PORT -{{- else if contains "LoadBalancer" .Values.service.type }} - NOTE: It may take a few minutes for the LoadBalancer IP to be available. - You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "local.fullname" . }}' - export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "local.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") - echo http://$SERVICE_IP:{{ .Values.service.port }} -{{- else if contains "ClusterIP" .Values.service.type }} - export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "local.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}") - export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}") - echo "Visit http://127.0.0.1:8080 to use your application" - kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT -{{- end }} -{{- end }} -{{- end }} -{{- end }} +This infra chart defined the following: +- cert-manager issuers for letsencrypt and selfSigned +- API gateways {{- range .Values.gateways }} {{ .name }}{{ end }} +- daily k8s backup to {{ .Values.k8sBackup.destPath }} +- default CPU and memory limits for {{ .Values.namespace }} namespace +- local-storage class default +- cluster role permissions for prometheus +- node port {{ .Values.rsyslogExt.nodePort }} for rsyslog diff --git a/k8s/helm/infra/templates/gateway.yaml b/k8s/helm/infra/templates/gateway.yaml index 3ff3f699..1f19b990 100644 --- a/k8s/helm/infra/templates/gateway.yaml +++ b/k8s/helm/infra/templates/gateway.yaml @@ -1,25 +1,27 @@ +{{ $labels := include "local.labels" . -}} +{{- range $gateway := .Values.gateways }} --- apiVersion: gateway.networking.k8s.io/v1 kind: GatewayClass metadata: - name: envoy-class + name: {{ $gateway.class }} labels: - {{- include "local.labels" . | nindent 4 }} + {{- $labels | nindent 4 }} spec: controllerName: gateway.envoyproxy.io/gatewayclass-controller parametersRef: group: gateway.envoyproxy.io kind: EnvoyProxy - name: {{ .Values.gateway.config }} - namespace: {{ .Values.gateway.crdNamespace }} + name: {{ $gateway.config }} + namespace: {{ $gateway.crdNamespace | default "envoy-gateway-system" }} --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: EnvoyProxy metadata: - name: {{ .Values.gateway.config }} - namespace: {{ .Values.gateway.crdNamespace }} + name: {{ $gateway.config }} + namespace: {{ $gateway.crdNamespace | default "envoy-gateway-system" }} labels: - {{- include "local.labels" . | nindent 4 }} + {{- $labels | nindent 4 }} spec: provider: type: Kubernetes @@ -34,32 +36,32 @@ spec: - name: http port: 80 protocol: TCP - nodePort: {{ .Values.gateway.nodeport_http }} + nodePort: {{ $gateway.nodeport_http }} - name: https port: 443 protocol: TCP - nodePort: {{ .Values.gateway.nodeport_https }} + nodePort: {{ .nodeport_https }} --- apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: - name: {{ .Values.gateway.name }} - namespace: {{ .Values.namespace }} + name: {{ $gateway.name }} + namespace: {{ $.Values.namespace }} labels: - {{- include "local.labels" . | nindent 4 }} + {{- $labels | nindent 4 }} spec: - gatewayClassName: envoy-class + gatewayClassName: {{ $gateway.class }} allowedListeners: namespaces: from: Selector selector: matchLabels: - kubernetes.io/metadata.name: {{ .Values.namespace }} + kubernetes.io/metadata.name: {{ $.Values.namespace }} listeners: # at least one dummy listener is needed; here we also add support for # TCP listeners; all http listeners are defined with ListenerSets - {{- if hasKey .Values.gateway "listeners" }} - {{- range .Values.gateway.listeners }} + {{- if hasKey $gateway "listeners" }} + {{- range $gateway.listeners }} - name: {{ .name }} protocol: TCP port: {{ .port }} @@ -72,22 +74,22 @@ spec: protocol: HTTP port: 80 {{- end }} -{{- if ne .Values.namespace .Values.authelia.namespace }} +{{- range $gateway.listeners }} --- -apiVersion: gateway.networking.k8s.io/v1beta1 -kind: ReferenceGrant +apiVersion: gateway.networking.k8s.io/v1 +kind: TCPRoute metadata: - name: envoy-authelia-integration - namespace: {{ .Values.authelia.namespace }} + name: {{ .name }} + namespace: {{ $.Values.namespace }} labels: - {{- include "local.labels" . | nindent 4 }} + {{- $labels | nindent 4 }} spec: - from: - - group: gateway.envoyproxy.io - kind: SecurityPolicy - namespace: {{ .Values.infra.namespace }} - to: - - group: "" - kind: Service - name: {{ .Values.authelia.service | default "authelia" }} + parentRefs: + - name: {{ $gateway.name }} + sectionName: {{ .name }} + rules: + - backendRefs: + - name: {{ .service }} + port: {{ .port }} +{{- end }} {{- end }} diff --git a/k8s/helm/infra/templates/listeners.yaml b/k8s/helm/infra/templates/listeners.yaml deleted file mode 100644 index 14a33aad..00000000 --- a/k8s/helm/infra/templates/listeners.yaml +++ /dev/null @@ -1,18 +0,0 @@ -{{- if hasKey .Values.gateway "listeners" }} -{{- range .Values.gateway.listeners }} ---- -apiVersion: gateway.networking.k8s.io/v1 -kind: TCPRoute -metadata: - name: {{ .name }} - namespace: {{ $.Values.namespace }} -spec: - parentRefs: - - name: {{ $.Values.gateway.name }} - sectionName: {{ .name }} - rules: - - backendRefs: - - name: {{ .service }} - port: {{ .port }} -{{- end }} -{{- end }} diff --git a/k8s/helm/infra/values.yaml b/k8s/helm/infra/values.yaml index d6a34463..ff3d285a 100644 --- a/k8s/helm/infra/values.yaml +++ b/k8s/helm/infra/values.yaml @@ -20,11 +20,14 @@ certManager: solvers: - solver: http01 enabled: true -gateway: - config: envoy-config - name: gateway-1 +gateways: +- name: gateway-1 + class: envoy-internal + config: envoy-config-internal crdNamespace: envoy-gateway-system listeners: [] + nodeport_http: 30080 + nodeport_https: 30443 k8sBackup: destPath: /var/backup/k8s etcdVersion: 3.5.15-0 @@ -39,15 +42,3 @@ limits: request: 64Mi rsyslogExt: nodePort: 30514 -nameOverride: "" -fullnameOverride: "" - -serviceAccount: - enabled: true - name: example-privileged -service: - clusterIP: 10.101.1.19 - ports: [ port: 2379 ] - type: ClusterIP -autoscaling: - enabled: false diff --git a/k8s/helm/jira/Chart.yaml b/k8s/helm/jira/Chart.yaml index 89490a72..1dfc40dd 100644 --- a/k8s/helm/jira/Chart.yaml +++ b/k8s/helm/jira/Chart.yaml @@ -6,13 +6,14 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/r/atlassian/jira-core type: application -version: 0.1.7 +version: 0.1.8 appVersion: "9.12.1" dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: mariadb - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/mariadb condition: mariadb.enabled diff --git a/k8s/helm/jira/subcharts/mariadb/Chart.yaml b/k8s/helm/jira/subcharts/mariadb/Chart.yaml index 38090673..dabde9ec 100644 --- a/k8s/helm/jira/subcharts/mariadb/Chart.yaml +++ b/k8s/helm/jira/subcharts/mariadb/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/_/mariadb type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: "0.0.1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/jira/subcharts/mariadb/templates/app.yaml b/k8s/helm/jira/subcharts/mariadb/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/jira/subcharts/mariadb/templates/app.yaml +++ b/k8s/helm/jira/subcharts/mariadb/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/jira/templates/NOTES.txt b/k8s/helm/jira/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/jira/templates/NOTES.txt +++ b/k8s/helm/jira/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/jira/templates/app.yaml b/k8s/helm/jira/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/k8s/helm/jira/templates/app.yaml +++ b/k8s/helm/jira/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/k8s/helm/jira/values.yaml b/k8s/helm/jira/values.yaml index cc34a42d..a8d1f2ac 100644 --- a/k8s/helm/jira/values.yaml +++ b/k8s/helm/jira/values.yaml @@ -71,13 +71,8 @@ service: autoscaling: enabled: false -authelia: - fqdn: authtotp.example.com - ip: 10.101.1.5 - path: /login.jsp gateway: enabled: true - totp: false mariadb: enabled: false diff --git a/k8s/helm/nexus/Chart.yaml b/k8s/helm/nexus/Chart.yaml index 065cab43..82421f5c 100644 --- a/k8s/helm/nexus/Chart.yaml +++ b/k8s/helm/nexus/Chart.yaml @@ -5,13 +5,14 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.16 +version: 0.1.17 appVersion: "3.96.1" dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: postgres - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/postgres condition: postgres.enabled diff --git a/k8s/helm/nexus/subcharts/postgres/Chart.yaml b/k8s/helm/nexus/subcharts/postgres/Chart.yaml index 5d84c96b..46a82462 100644 --- a/k8s/helm/nexus/subcharts/postgres/Chart.yaml +++ b/k8s/helm/nexus/subcharts/postgres/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/_/postgres type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: "0.0.1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.1 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/nexus/subcharts/postgres/templates/app.yaml b/k8s/helm/nexus/subcharts/postgres/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/nexus/subcharts/postgres/templates/app.yaml +++ b/k8s/helm/nexus/subcharts/postgres/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/nexus/templates/NOTES.txt b/k8s/helm/nexus/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/nexus/templates/NOTES.txt +++ b/k8s/helm/nexus/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/nexus/templates/app.yaml b/k8s/helm/nexus/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/k8s/helm/nexus/templates/app.yaml +++ b/k8s/helm/nexus/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/k8s/helm/nexus/values.yaml b/k8s/helm/nexus/values.yaml index 4516bc3e..2b516dbf 100644 --- a/k8s/helm/nexus/values.yaml +++ b/k8s/helm/nexus/values.yaml @@ -1,6 +1,5 @@ # Default values for nexus. -autheliaIP: 10.0.10.10 domain: example.com tlsHostname: nexus.example.com deployment: @@ -63,7 +62,8 @@ service: ports: - { port: 80, targetPort: 8081, name: nexus } - { port: 5001, targetPort: 5000, name: registry } - +autoscaling: + enabled: false gateway: enabled: true routeRules: @@ -87,41 +87,6 @@ gateway: - path: type: PathPrefix value: /v2/ -ingress: - enabled: false - className: "" - annotations: - kubernetes.io/ingress.class: nginx - # kubernetes.io/tls-acme: "true" - cert-manager.io/cluster-issuer: letsencrypt-prod - nginx.ingress.kubernetes.io/enable-access-log: "false" - nginx.ingress.kubernetes.io/proxy-body-size: 500m - nginx.ingress.kubernetes.io/proxy-request-buffering: "off" - rules: - - host: nexus.example.com - http: - paths: - - path: / - backend: - service: - name: nexus - port: - number: 80 - pathType: Prefix - - path: /v2/ - backend: - service: - name: nexus - port: - number: 5001 - pathType: Prefix - tls: - - hosts: - - nexus.example.com - secretName: nexus.example.com - -autoscaling: - enabled: false configmap: name: nexus diff --git a/k8s/helm/owntone/Chart.yaml b/k8s/helm/owntone/Chart.yaml index a796589c..db1fc79a 100644 --- a/k8s/helm/owntone/Chart.yaml +++ b/k8s/helm/owntone/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/owntone/owntone-server type: application -version: 0.1.1 +version: 0.1.3 appVersion: "29.2" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/owntone/templates/NOTES.txt b/k8s/helm/owntone/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/owntone/templates/NOTES.txt +++ b/k8s/helm/owntone/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/owntone/templates/app.yaml b/k8s/helm/owntone/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/k8s/helm/owntone/templates/app.yaml +++ b/k8s/helm/owntone/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/k8s/helm/radicale/Chart.yaml b/k8s/helm/radicale/Chart.yaml index beb05480..8fc7eba4 100644 --- a/k8s/helm/radicale/Chart.yaml +++ b/k8s/helm/radicale/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/Kozea/Radicale type: application -version: 0.1.0 +version: 0.1.1 appVersion: "3.7.7" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/radicale/templates/NOTES.txt b/k8s/helm/radicale/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/radicale/templates/NOTES.txt +++ b/k8s/helm/radicale/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/radicale/templates/app.yaml b/k8s/helm/radicale/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/radicale/templates/app.yaml +++ b/k8s/helm/radicale/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/radicale/values.yaml b/k8s/helm/radicale/values.yaml index c6101d60..d985b76b 100644 --- a/k8s/helm/radicale/values.yaml +++ b/k8s/helm/radicale/values.yaml @@ -65,18 +65,12 @@ service: ports: - { port: 80, targetPort: 5232, name: radicale } type: ClusterIP - -ingress: - enabled: true - className: "" - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/enable-access-log: "false" - nginx.ingress.kubernetes.io/proxy-body-size: "50m" - autoscaling: enabled: false +gateway: + enabled: true + external: true + name: gateway-2 configmap: data: diff --git a/k8s/helm/restic/Chart.yaml b/k8s/helm/restic/Chart.yaml index 133ec131..ed703f0d 100644 --- a/k8s/helm/restic/Chart.yaml +++ b/k8s/helm/restic/Chart.yaml @@ -6,11 +6,12 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/restic/restic type: application -version: 0.1.26 +version: 0.1.27 # Remember to update restic== in values.yaml as releases are published; # the values.yaml file is not able to reference .Chart.appVersion appVersion: "0.18.1-r7" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/restic/templates/NOTES.txt b/k8s/helm/restic/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/restic/templates/NOTES.txt +++ b/k8s/helm/restic/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/restic/templates/app.yaml b/k8s/helm/restic/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/restic/templates/app.yaml +++ b/k8s/helm/restic/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/snappymail/Chart.yaml b/k8s/helm/snappymail/Chart.yaml index abaee719..fd159be9 100644 --- a/k8s/helm/snappymail/Chart.yaml +++ b/k8s/helm/snappymail/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://github.com/the-djmaze/snappymail type: application -version: 0.1.1 +version: 0.1.2 appVersion: "v2.38.2" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/snappymail/templates/NOTES.txt b/k8s/helm/snappymail/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/snappymail/templates/NOTES.txt +++ b/k8s/helm/snappymail/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/snappymail/templates/app.yaml b/k8s/helm/snappymail/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/snappymail/templates/app.yaml +++ b/k8s/helm/snappymail/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/snappymail/values.yaml b/k8s/helm/snappymail/values.yaml index 1840c912..93ca4d01 100644 --- a/k8s/helm/snappymail/values.yaml +++ b/k8s/helm/snappymail/values.yaml @@ -38,11 +38,7 @@ service: type: ClusterIP autoscaling: enabled: false - -ingress: - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/client-body-buffer-size: 20m - nginx.ingress.kubernetes.io/enable-access-log: "false" - nginx.ingress.kubernetes.io/proxy-body-size: 20m +gateway: + enabled: true + external: true + name: gateway-2 diff --git a/k8s/helm/splunk/Chart.yaml b/k8s/helm/splunk/Chart.yaml index e8b2ed8f..9de5bbd2 100644 --- a/k8s/helm/splunk/Chart.yaml +++ b/k8s/helm/splunk/Chart.yaml @@ -2,10 +2,10 @@ # a user-seed.conf in mounted volume. Details are found at: # http://docs.splunk.com/Documentation/Splunk/latest/Admin/user-seedconf # -# The free version of splunk does not have login splash page. Included here are -# ingress definitions that define basic-auth and TOTP. Add a k8s secret -# named splunk-auth containing a key named auth. See this URL: -# https://github.com/kubernetes/ingress-nginx/blob/master/docs/examples/auth/basic/README.md +# The free version of splunk does not have login splash page. Included here is +# an API-gateway definition that defines basic-auth. Add a k8s secret +# named splunk-auth containing a key named .htpasswd. See this URL: +# https://gateway.envoyproxy.io/docs/tasks/security/basic-auth/ apiVersion: v2 name: splunk @@ -15,9 +15,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/r/splunk/splunk type: application -version: 0.1.19 +version: 0.1.20 appVersion: "10.4.1" dependencies: - name: chartlib - version: 0.1.10 - repository: oci://registry-1.docker.io/instantlinux + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/splunk/templates/NOTES.txt b/k8s/helm/splunk/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/splunk/templates/NOTES.txt +++ b/k8s/helm/splunk/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/splunk/templates/app.yaml b/k8s/helm/splunk/templates/app.yaml index a32c0217..ee3d586c 100644 --- a/k8s/helm/splunk/templates/app.yaml +++ b/k8s/helm/splunk/templates/app.yaml @@ -4,10 +4,6 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} ---- {{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} diff --git a/k8s/helm/splunk/values.yaml b/k8s/helm/splunk/values.yaml index 4d60ec14..a8960dc6 100644 --- a/k8s/helm/splunk/values.yaml +++ b/k8s/helm/splunk/values.yaml @@ -75,13 +75,8 @@ service: autoscaling: enabled: false -authelia: - fqdn: authtotp.example.com - ip: 10.101.1.5 - path: /en-US/account/login gateway: enabled: true - totp: false routeRules: - backendRefs: - group: "" diff --git a/k8s/helm/synapse/Chart.yaml b/k8s/helm/synapse/Chart.yaml index f37a3dcd..fe9bc96a 100644 --- a/k8s/helm/synapse/Chart.yaml +++ b/k8s/helm/synapse/Chart.yaml @@ -6,21 +6,22 @@ sources: - https://github.com/matrix-org/synapse - https://hub.docker.com/r/matrixdotorg/synapse type: application -version: 0.1.0 +version: 0.1.1 appVersion: v1.126.0 dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux - name: admin - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/admin condition: admin.enabled - name: element - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/element condition: element.enabled - name: postgres - version: 0.1.0 + version: 0.1.1 repository: file://subcharts/postgres condition: postgres.enabled diff --git a/k8s/helm/synapse/subcharts/admin/Chart.yaml b/k8s/helm/synapse/subcharts/admin/Chart.yaml index 551703e1..ccf21e6c 100644 --- a/k8s/helm/synapse/subcharts/admin/Chart.yaml +++ b/k8s/helm/synapse/subcharts/admin/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/Awesome-Technologies/synapse-admin - https://hub.docker.com/r/awesometechnologies/synapse-admin type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: 0.0.1 dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/synapse/subcharts/admin/templates/app.yaml b/k8s/helm/synapse/subcharts/admin/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/synapse/subcharts/admin/templates/app.yaml +++ b/k8s/helm/synapse/subcharts/admin/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/synapse/subcharts/admin/values.yaml b/k8s/helm/synapse/subcharts/admin/values.yaml index b38af897..84cb4baa 100644 --- a/k8s/helm/synapse/subcharts/admin/values.yaml +++ b/k8s/helm/synapse/subcharts/admin/values.yaml @@ -19,16 +19,7 @@ service: type: ClusterIP autoscaling: enabled: false - -authelia: - fqdn: authtotp.example.com - ip: 10.101.1.5 - path: /_matrix/client/r0/login -ingress: - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - nginx.ingress.kubernetes.io/enable-access-log: "false" - kubernetes.io/ingress.class: nginx - # className: nginx -ingressTOTP: +gateway: enabled: true + external: true + name: gateway-2 diff --git a/k8s/helm/synapse/subcharts/element/Chart.yaml b/k8s/helm/synapse/subcharts/element/Chart.yaml index c7fb0b96..12be6735 100644 --- a/k8s/helm/synapse/subcharts/element/Chart.yaml +++ b/k8s/helm/synapse/subcharts/element/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/element-hq/element-web - https://hub.docker.com/r/vectorim/element-web type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: v0.0.1 dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/synapse/subcharts/element/templates/app.yaml b/k8s/helm/synapse/subcharts/element/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/k8s/helm/synapse/subcharts/element/templates/app.yaml +++ b/k8s/helm/synapse/subcharts/element/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/k8s/helm/synapse/subcharts/element/values.yaml b/k8s/helm/synapse/subcharts/element/values.yaml index c9efddfc..98df6b49 100644 --- a/k8s/helm/synapse/subcharts/element/values.yaml +++ b/k8s/helm/synapse/subcharts/element/values.yaml @@ -48,10 +48,3 @@ service: type: ClusterIP autoscaling: enabled: false - -ingress: - hosts: - - host: element.example.com - paths: - - path: / - pathType: Prefix diff --git a/k8s/helm/synapse/subcharts/postgres/Chart.yaml b/k8s/helm/synapse/subcharts/postgres/Chart.yaml index 5d84c96b..dc58c68f 100644 --- a/k8s/helm/synapse/subcharts/postgres/Chart.yaml +++ b/k8s/helm/synapse/subcharts/postgres/Chart.yaml @@ -6,10 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://hub.docker.com/_/postgres type: application -version: 0.1.0 +version: 0.1.1 # specify version tag from hub.docker.com in top-level values.yaml appVersion: "0.0.1" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/helm/synapse/subcharts/postgres/templates/app.yaml b/k8s/helm/synapse/subcharts/postgres/templates/app.yaml index 5a01911b..ee3d586c 100644 --- a/k8s/helm/synapse/subcharts/postgres/templates/app.yaml +++ b/k8s/helm/synapse/subcharts/postgres/templates/app.yaml @@ -4,9 +4,7 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- diff --git a/k8s/helm/synapse/templates/NOTES.txt b/k8s/helm/synapse/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/synapse/templates/NOTES.txt +++ b/k8s/helm/synapse/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/synapse/templates/app.yaml b/k8s/helm/synapse/templates/app.yaml index 527f6710..ee3d586c 100644 --- a/k8s/helm/synapse/templates/app.yaml +++ b/k8s/helm/synapse/templates/app.yaml @@ -1,7 +1,11 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- +{{- include "chartlib.listener" . }} +--- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} diff --git a/k8s/helm/synapse/templates/ingress.yaml b/k8s/helm/synapse/templates/ingress.yaml deleted file mode 100644 index c337693c..00000000 --- a/k8s/helm/synapse/templates/ingress.yaml +++ /dev/null @@ -1,67 +0,0 @@ -{{- $fullName := include "local.fullname" . -}} -{{- $svcPort := .Values.ingress.port | default (index .Values.service.ports 0).port -}} -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: {{ $fullName }} - labels: - {{- include "local.labels" . | nindent 4 }} - annotations: - {{- if hasKey .Values.ingress "annotations" }} - {{- toYaml .Values.ingress.annotations | nindent 4 }} - {{- else }} - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - {{- end }} -spec: - ingressClassName: {{ .Values.ingress.className }} - {{- if hasKey .Values.ingress "tls" }} - tls: - {{- range .Values.ingress.tls }} - - hosts: - {{- range .hosts }} - - {{ . | quote }} - {{- end }} - secretName: {{ .secretName }} - {{- end }} - {{- else if hasKey .Values "tlsHostname" }} - tls: - - hosts: - - {{ .Values.tlsHostname }} - secretName: tls-{{ $fullName }} - {{- end }} - rules: - {{- if hasKey .Values.ingress "rules" }} - {{- with .Values.ingress.rules }} - {{- toYaml . | nindent 4 }} - {{- end }} - {{- else }} - {{- if hasKey .Values.ingress "hosts" }} - {{- toYaml .Values.ingress.hosts | nindent 4 }} - {{- else if hasKey .Values "tlsHostname" }} - - host: {{ .Values.tlsHostname }} - http: - paths: - - path: /_matrix - pathType: Prefix - backend: - service: - name: {{ $fullName }} - port: - number: {{ $svcPort }} - - path: /_synapse - pathType: Prefix - backend: - service: - name: {{ $fullName }} - port: - number: {{ $svcPort }} - - path: / - pathType: Prefix - backend: - service: - name: {{ $fullName }}-element - port: - number: {{ $svcPort }} - {{- end }} - {{- end }} diff --git a/k8s/helm/synapse/values.yaml b/k8s/helm/synapse/values.yaml index d33212da..a80dd355 100644 --- a/k8s/helm/synapse/values.yaml +++ b/k8s/helm/synapse/values.yaml @@ -151,44 +151,63 @@ service: type: ClusterIP autoscaling: enabled: false - -ingress: - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - nginx.ingress.kubernetes.io/enable-access-log: "false" - nginx.ingress.kubernetes.io/proxy-body-size: 30m - kubernetes.io/ingress.class: nginx - # className: nginx +gateway: + enabled: true + external: true + name: gateway-2 + routeRules: + - backendRefs: + - group: "" + kind: Service + name: synapse-element + port: 80 + weight: 1 + matches: + - path: + type: PathPrefix + value: / + - backendRefs: + - group: "" + kind: Service + name: synapse + port: 80 + weight: 1 + matches: + - path: + type: PathPrefix + value: /_matrix + - backendRefs: + - group: "" + kind: Service + name: synapse + port: 80 + weight: 1 + matches: + - path: + type: PathPrefix + value: /_synapse # Subchart parameters admin: tlsHostname: synapse-admin.example.com enabled: true image: - tag: 0.10.3 + tag: 0.11.4 deployment: env: react_app_server: http://synapse-admin.example.com - ingress: - tls: - - secretName: tls-synapse-admin - hosts: - - synapse-admin.example.com element: enabled: true fullnameOverride: synapse-element image: - tag: v1.11.95 + tag: v1.12.29 deployment: env: country_code: US homeserver_url: https://synapse.example.com room_directory_servers: [ matrix.org ] server_name: My matrix instance - # No separate ingress; use the top-level synapse ingress - ingress: - enabled: false nginx: # Enable this to serve .well-known service discovery on top-level @@ -215,4 +234,4 @@ postgres: key: database_password name: synapse image: - tag: 17.4-alpine + tag: 17.11-alpine diff --git a/k8s/helm/vaultwarden/Chart.yaml b/k8s/helm/vaultwarden/Chart.yaml index 93a543df..27c807d8 100644 --- a/k8s/helm/vaultwarden/Chart.yaml +++ b/k8s/helm/vaultwarden/Chart.yaml @@ -5,9 +5,10 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.11 +version: 0.1.12 appVersion: "1.37.1-alpine" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/vaultwarden/templates/NOTES.txt b/k8s/helm/vaultwarden/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/vaultwarden/templates/NOTES.txt +++ b/k8s/helm/vaultwarden/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/vaultwarden/templates/app.yaml b/k8s/helm/vaultwarden/templates/app.yaml index 5b83e9c4..ee3d586c 100644 --- a/k8s/helm/vaultwarden/templates/app.yaml +++ b/k8s/helm/vaultwarden/templates/app.yaml @@ -1,11 +1,13 @@ +{{- include "chartlib.configmap" . }} +--- {{- include "chartlib.deployment" . }} --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/k8s/helm/vaultwarden/values.yaml b/k8s/helm/vaultwarden/values.yaml index 71be3e39..d9777a9d 100644 --- a/k8s/helm/vaultwarden/values.yaml +++ b/k8s/helm/vaultwarden/values.yaml @@ -72,14 +72,9 @@ service: ports: - { port: 80, targetPort: 80, name: http } - { port: 3012, targetPort: 3012, name: websocket } - -ingress: - enabled: true - className: "" - annotations: - kubernetes.io/ingress.class: nginx - cert-manager.io/cluster-issuer: letsencrypt-prod - nginx.ingress.kubernetes.io/enable-access-log: "false" - autoscaling: enabled: false +gateway: + enabled: true + external: true + name: gateway-2 diff --git a/k8s/helm/wordpress/Chart.yaml b/k8s/helm/wordpress/Chart.yaml index ec335898..2f5bf0cc 100644 --- a/k8s/helm/wordpress/Chart.yaml +++ b/k8s/helm/wordpress/Chart.yaml @@ -6,9 +6,10 @@ sources: - https://github.com/instantlinux/docker-tools - https://build.trac.wordpress.org/browser type: application -version: 0.1.6 +version: 0.1.7 appVersion: "7.0.0-php8.5-apache" dependencies: - name: chartlib - version: 0.1.8 - repository: https://instantlinux.github.io/docker-tools + version: 0.1.11 + repository: oci://ghcr.io/instantlinux/charts + # also available at oci://registry-1.docker.io/instantlinux diff --git a/k8s/helm/wordpress/templates/NOTES.txt b/k8s/helm/wordpress/templates/NOTES.txt index 62ea3f4b..7309f065 100644 --- a/k8s/helm/wordpress/templates/NOTES.txt +++ b/k8s/helm/wordpress/templates/NOTES.txt @@ -1,13 +1,9 @@ {{- if hasKey .Values "service" }} {{- if or .Values.service.enabled (not (hasKey .Values.service "enabled")) }} 1. Get the application URL by running these commands: -{{- if hasKey .Values "ingress" }} -{{- if .Values.ingress.enabled }} -{{- range $host := .Values.ingress.hosts }} - {{- range .paths }} - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} - {{- end }} -{{- end }} +{{- if hasKey .Values "tlsHostname" }} +{{- if .Values.gateway.enabled }} +Visit https://{{ .Values.tlsHostname }} {{- else if contains "NodePort" .Values.service.type }} export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "local.fullname" . }}) export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") diff --git a/k8s/helm/wordpress/templates/app.yaml b/k8s/helm/wordpress/templates/app.yaml index b925dd1f..ee3d586c 100644 --- a/k8s/helm/wordpress/templates/app.yaml +++ b/k8s/helm/wordpress/templates/app.yaml @@ -4,10 +4,10 @@ --- {{- include "chartlib.hpa" . }} --- -{{- include "chartlib.ingress" . }} ---- -{{- include "chartlib.ingresstotp" . }} +{{- include "chartlib.listener" . }} --- {{- include "chartlib.service" . }} --- {{- include "chartlib.serviceaccount" . }} +--- +{{- include "chartlib.statefulset" . }} diff --git a/k8s/helm/wordpress/values.yaml b/k8s/helm/wordpress/values.yaml index 3dcf67f4..21963e85 100644 --- a/k8s/helm/wordpress/values.yaml +++ b/k8s/helm/wordpress/values.yaml @@ -85,21 +85,13 @@ service: type: ClusterIP autoscaling: enabled: false +gateway: + enabled: true + external: true + name: gateway-2 configmap: data: local-php.ini: | upload_max_filesize = 32M post_max_size = 40M - -authelia: - fqdn: authtotp.example.com - ip: 10.101.1.5 - path: /(wp-login.php|wp-admin) -ingress: - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/enable-access-log: "false" -ingressTOTP: - enabled: true diff --git a/k8s/install/ingress-nginx.yaml b/k8s/install/ingress-nginx.yaml deleted file mode 100644 index 7c846243..00000000 --- a/k8s/install/ingress-nginx.yaml +++ /dev/null @@ -1,291 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: $SERVICE_NAME - namespace: $K8S_NAMESPACE - labels: - k8s-app: nginx-ingress-controller -spec: - clusterIP: $K8S_INGRESS_NGINX_IP - selector: - k8s-app: nginx-ingress-controller - ports: - - { port: 80, targetPort: 80, name: http } - - { port: 443, targetPort: 443, name: https } - - { port: $PORT_GIT_SSH, name: git-ssh } - sessionAffinity: ClientIP ---- -apiVersion: v1 -kind: Service -metadata: - name: $SERVICE_NAME-external - namespace: $K8S_NAMESPACE -spec: - type: NodePort - ports: - - { port: 80, nodePort: $NODEPORT_HTTP, targetPort: 80, name: http } - - { port: 443, nodePort: $NODEPORT_HTTPS, targetPort: 443, name: https } - selector: - k8s-app: nginx-ingress-controller - sessionAffinity: ClientIP ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: nginx-ingress-controller - namespace: $K8S_NAMESPACE - labels: - k8s-app: nginx-ingress-controller -spec: - replicas: 2 - revisionHistoryLimit: 0 - selector: - matchLabels: - k8s-app: nginx-ingress-controller - template: - metadata: - labels: - k8s-app: nginx-ingress-controller - name: nginx-ingress-controller - annotations: - prometheus.io/port: '10254' - prometheus.io/scrape: 'true' - spec: - terminationGracePeriodSeconds: 60 - containers: - # - image: quay.io/kubernetes-ingress-controller/nginx-ingress-controller:$VERSION_INGRESS_NGINX - - image: registry.k8s.io/ingress-nginx/controller:v$VERSION_INGRESS_NGINX - name: nginx-ingress-controller - ports: - - containerPort: 80 - - containerPort: 443 - env: - - name: POD_NAME - valueFrom: - fieldRef: - fieldPath: metadata.name - - name: POD_NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - args: - - /nginx-ingress-controller - - --configmap=$K8S_NAMESPACE/nginx-ingress-controller - - --ingress-class=nginx - - --election-id=ingress-controller-leader-external - - --default-backend-service=$(POD_NAMESPACE)/default-http-backend - - --tcp-services-configmap=$K8S_NAMESPACE/ingress-tcp-services - resources: - limits: - memory: 1024Mi - requests: - cpu: 50m - memory: 192Mi - affinity: - podAntiAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - - labelSelector: - matchExpressions: - - key: k8s-app - operator: In - values: - - nginx-ingress-controller - topologyKey: "kubernetes.io/hostname" - serviceAccountName: pod-ingress-privileged ---- -apiVersion: v1 -kind: Service -metadata: - name: default-http-backend - namespace: $K8S_NAMESPACE - labels: - app.kubernetes.io/name: default-http-backend -spec: - clusterIP: None - ports: - - { port: 80, targetPort: 8080 } - selector: - app.kubernetes.io/name: default-http-backend ---- -# default backend for requests with unknown routes -apiVersion: apps/v1 -kind: Deployment -metadata: - name: default-http-backend - namespace: $K8S_NAMESPACE - labels: - app.kubernetes.io/name: default-http-backend -spec: - replicas: 1 - selector: - matchLabels: - app.kubernetes.io/name: default-http-backend - template: - metadata: - labels: - app.kubernetes.io/name: default-http-backend - spec: - terminationGracePeriodSeconds: 60 - containers: - - name: default-http-backend - image: registry.k8s.io/defaultbackend-amd64:$VERSION_DEFAULTBACKEND - ports: - - containerPort: 8080 ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: Role -metadata: - name: ingress-pod-user - namespace: $K8S_NAMESPACE -rules: -- apiGroups: [""] - resources: - - pods - - services - verbs: [get, list] -- apiGroups: [""] - resources: - - configmaps - - events - verbs: [create, get, list, update] ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: RoleBinding -metadata: - name: pod-user-binding - namespace: $K8S_NAMESPACE -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: ingress-pod-user -subjects: -- kind: ServiceAccount - name: pod-ingress-privileged - namespace: $K8S_NAMESPACE ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - labels: - k8s-app: nginx-ingress-controller - name: nginx-ingress-controller - name: nginx-ingress-controller -rules: - - apiGroups: - - "" - resources: - - configmaps - - endpoints - - nodes - - pods - - secrets - verbs: - - list - - watch - - apiGroups: - - "" - resources: - - namespaces - verbs: - - get - - "" - resources: - - nodes - verbs: - - get - - apiGroups: - - "" - resources: - - services - verbs: - - get - - list - - watch - - apiGroups: - - extensions - - "networking.k8s.io" - resources: - - ingresses - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - extensions - - "networking.k8s.io" - resources: - - ingresses/status - verbs: - - update - - apiGroups: - - "networking.k8s.io" - resources: - - ingressclasses - verbs: - - get - - list - - watch - - apiGroups: - - "coordination.k8s.io" - resources: - - leases - verbs: [create, get, list, update] - - apiGroups: - - "discovery.k8s.io" - resources: - - endpointslices - verbs: [get, list, watch] ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - labels: - k8s-app: nginx-ingress-controller - name: nginx-ingress-controller - name: nginx-ingress-controller -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: nginx-ingress-controller -subjects: - - kind: ServiceAccount - name: pod-ingress-privileged - namespace: $K8S_NAMESPACE ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: pod-ingress-privileged - namespace: $K8S_NAMESPACE ---- -apiVersion: v1 -kind: ConfigMap -metadata: - name: ingress-tcp-services - namespace: $K8S_NAMESPACE -data: - # Routing for custom TCP ports served by this ingress - $PORT_GIT_SSH: $K8S_NAMESPACE/gitea:$PORT_GIT_SSH - $PORT_POSTFIX_EXTERNAL: $K8S_NAMESPACE/postfix:$PORT_POSTFIX_EXTERNAL - $PORT_DOVECOT_IMAPD: $K8S_NAMESPACE/dovecot:$PORT_DOVECOT_IMAPD - $PORT_DOVECOT_IMAPS: $K8S_NAMESPACE/dovecot:$PORT_DOVECOT_IMAPS - $PORT_DOVECOT_SMTP: $K8S_NAMESPACE/dovecot:$PORT_DOVECOT_SMTP ---- -apiVersion: v1 -kind: ConfigMap -metadata: - name: nginx-ingress-controller - namespace: $K8S_NAMESPACE -data: - # needed for some services that use config snippets, e.g. for - # adjusting fastcgi_buffers - annotations-risk-level: Critical - allowSnippetAnnotations: "true" diff --git a/k8s/install/monitor.yaml b/k8s/install/monitor.yaml index 2d936f68..0678f58b 100644 --- a/k8s/install/monitor.yaml +++ b/k8s/install/monitor.yaml @@ -5,70 +5,97 @@ apiVersion: v1 kind: Service metadata: labels: - app.kubernetes.io/name: $SERVICE_NAME + kubernetes.io/service-name: $SERVICE_NAME name: $SERVICE_NAME + namespace: $K8S_NAMESPACE spec: ports: - - { port: 80, targetPort: 80 } + - { port: 80, targetPort: 80, name: monitor } type: ClusterIP --- -apiVersion: v1 -kind: Endpoints +apiVersion: discovery.k8s.io/v1 +kind: EndpointSlice metadata: name: $SERVICE_NAME -subsets: - - addresses: - - ip: $MONITOR_EXT_IP - ports: - - { port: 80, name: monitor, protocol: TCP } + namespace: $K8S_NAMESPACE + labels: + kubernetes.io/service-name: $SERVICE_NAME +addressType: IPv4 +endpoints: + - addresses: [ $MONITOR_EXT_IP ] +ports: + - name: monitor + protocol: TCP + port: 80 --- -apiVersion: networking.k8s.io/v1 -kind: Ingress +apiVersion: gateway.networking.k8s.io/v1 +kind: ListenerSet metadata: + name: $SERVICE_NAME + namespace: $K8S_NAMESPACE labels: app.kubernetes.io/name: $SERVICE_NAME - name: $SERVICE_NAME annotations: - kubernetes.io/ingress.class: nginx + cert-manager.io/cluster-issuer: letsencrypt-prod spec: - tls: - - secretName: tls-$SERVICE_NAME - hosts: - - $SERVICE_NAME.$DOMAIN + parentRef: + group: gateway.networking.k8s.io + kind: Gateway + name: gateway-2 + namespace: $K8S_NAMESPACE + listeners: + - name: https + hostname: $SERVICE_NAME.$DOMAIN + port: 443 + protocol: HTTPS + tls: + mode: Terminate + certificateRefs: + - name: tls-$SERVICE_NAME + - name: http + hostname: $SERVICE_NAME.$DOMAIN + port: 80 + protocol: HTTP +--- +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute +metadata: + name: $SERVICE_NAME + namespace: $K8S_NAMESPACE +spec: + parentRefs: + - kind: ListenerSet + name: $SERVICE_NAME + sectionName: https rules: - - host: $SERVICE_NAME.$DOMAIN - http: - paths: - - path: / - backend: - service: - name: $SERVICE_NAME - port: - number: 80 - pathType: Prefix + - matches: + - path: + type: PathPrefix + value: / + backendRefs: + - name: $SERVICE_NAME + port: 80 + - matches: + - path: + type: PathPrefix + value: / + backendRefs: + - name: $SERVICE_NAME + port: 80 --- -apiVersion: networking.k8s.io/v1 -kind: Ingress +apiVersion: gateway.networking.k8s.io/v1 +kind: HTTPRoute metadata: - name: $SERVICE_NAME-totp - annotations: - cert-manager.io/cluster-issuer: letsencrypt-prod - kubernetes.io/ingress.class: nginx - nginx.ingress.kubernetes.io/auth-url: http://$AUTHELIA_IP/api/verify - nginx.ingress.kubernetes.io/auth-signin: https://authtotp.$DOMAIN + name: $SERVICE_NAME-https-redirect + namespace: $K8S_NAMESPACE spec: - tls: - - secretName: tls-$SERVICE_NAME - hosts: - - $SERVICE_NAME.$DOMAIN + parentRefs: + - kind: ListenerSet + name: $SERVICE_NAME + sectionName: http rules: - - host: $SERVICE_NAME.$DOMAIN - http: - paths: - - path: /NagiosQL/index.php - backend: - service: - name: $SERVICE_NAME - port: - number: 80 - pathType: Prefix + - filters: + - type: RequestRedirect + requestRedirect: + scheme: https + statusCode: 308 diff --git a/k8s/install/namespace-user.yaml b/k8s/install/namespace-user.yaml index c966334f..2ff2eb57 100644 --- a/k8s/install/namespace-user.yaml +++ b/k8s/install/namespace-user.yaml @@ -65,6 +65,10 @@ rules: - challenges - orders verbs: [get, list] +- apiGroups: [discovery.k8s.io] + resources: + - endpointslices + verbs: ["*"] - apiGroups: [networking.k8s.io] resources: - ingresses