From 66977fe72205995e65f855590e808561eae3faf6 Mon Sep 17 00:00:00 2001 From: Rich Braun Date: Wed, 23 Sep 2026 21:19:40 -0700 Subject: [PATCH 1/2] SYS-593 fixes to infra and synapse charts; fix github action for helm publish --- .github/workflows/release.yaml | 6 +++--- k8s/Makefile | 6 +++--- k8s/Makefile.versions | 2 +- k8s/helm/infra/Chart.yaml | 4 ++-- k8s/{install => helm/infra/templates}/admin-user.yaml | 8 +++++--- k8s/helm/infra/templates/cert-manager.yaml | 2 ++ k8s/helm/infra/templates/gateway.yaml | 10 ++++++++-- k8s/helm/infra/templates/k8s-backup.yaml | 2 ++ k8s/helm/infra/templates/limits.yaml | 2 ++ k8s/helm/infra/templates/local-storage.yaml | 4 +++- k8s/helm/infra/templates/rsyslog-ext.yaml | 2 ++ k8s/helm/infra/values.yaml | 11 +++++++++++ k8s/helm/synapse/Chart.yaml | 6 +++--- k8s/helm/synapse/subcharts/admin/Chart.yaml | 2 +- k8s/helm/synapse/subcharts/admin/values.yaml | 2 -- k8s/install/namespace-user.yaml | 10 ++++++++++ 16 files changed, 58 insertions(+), 21 deletions(-) rename k8s/{install => helm/infra/templates}/admin-user.yaml (59%) diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 57ccc3ef..6e93c653 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -10,8 +10,8 @@ on: push: branches: [main] paths: - - k8s/helm/**/Chart.yaml - - images/**/helm/Chart.yaml + - k8s/helm/*/Chart.yaml + - images/*/helm/Chart.yaml jobs: find-charts: @@ -28,7 +28,7 @@ jobs: id: set-matrix run: | CHANGED=$(git diff --name-only HEAD^ HEAD | \ - grep -E "^(${CHART_DIR}/.*|images/.*/helm)/Chart.yaml" | \ + grep -E "^(${CHART_DIR}/[^/]+|images/[^/]+/helm)/Chart.yaml" | \ awk '{sub(/\/[^/]+$/, ""); print}' | \ jq -R . | jq -s -c .) echo "matrix={\"chart\":$CHANGED}" >> $GITHUB_OUTPUT diff --git a/k8s/Makefile b/k8s/Makefile index 4b700c75..6352acf9 100644 --- a/k8s/Makefile +++ b/k8s/Makefile @@ -91,9 +91,9 @@ INSTALL_YAML = $(basename $(wildcard install/*.yaml)) \ $(addprefix imports/, $(IMPORTS)) VOLUMES_YAML = $(basename $(wildcard volumes/*.yaml)) -install: install/admin-user cluster_network imports install_imports \ - namespace_config fluent-bit remote_volumes sops data-sync-ssh \ - persistent secrets infra storage_localdefault +install: cluster_network imports install_imports namespace_config fluent-bit \ + remote_volumes sops data-sync-ssh persistent secrets infra \ + storage_localdefault namespace_config: install/namespace install/namespace-user secrets/regcred diff --git a/k8s/Makefile.versions b/k8s/Makefile.versions index f8fea28c..f35fbb75 100644 --- a/k8s/Makefile.versions +++ b/k8s/Makefile.versions @@ -10,4 +10,4 @@ SOPS_SHA ?= f2e5ed5e57376789b0e12793adc848e54c2338906e51392 # Held back versions - more effort to upgrade export VERSION_CALICO ?= 3.16.5 -export VERSION_ETCD ?= 3.5.15-0 # for install/k8s-backup cron +export VERSION_ETCD ?= 3.5.15-0 # for infra k8sBackup cron diff --git a/k8s/helm/infra/Chart.yaml b/k8s/helm/infra/Chart.yaml index a645e45e..025e2be2 100644 --- a/k8s/helm/infra/Chart.yaml +++ b/k8s/helm/infra/Chart.yaml @@ -5,9 +5,9 @@ home: https://github.com/instantlinux/docker-tools sources: - https://github.com/instantlinux/docker-tools type: application -version: 0.1.1 +version: 0.1.2 appVersion: "0.1.0" dependencies: - name: chartlib - version: 0.1.10 + version: 0.1.11 repository: oci://ghcr.io/instantlinux/charts diff --git a/k8s/install/admin-user.yaml b/k8s/helm/infra/templates/admin-user.yaml similarity index 59% rename from k8s/install/admin-user.yaml rename to k8s/helm/infra/templates/admin-user.yaml index fd5a4837..b89a8f87 100644 --- a/k8s/install/admin-user.yaml +++ b/k8s/helm/infra/templates/admin-user.yaml @@ -1,19 +1,21 @@ +{{- if or .Values.adminUser.enabled (not (hasKey .Values "adminUser.enabled")) }} --- apiVersion: v1 kind: ServiceAccount metadata: - name: admin-user + name: {{ .Values.adminUser.name }} namespace: kube-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: - name: admin-user + name: {{ .Values.adminUser.name }} roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: cluster-admin subjects: - kind: ServiceAccount - name: admin-user + name: {{ .Values.adminUser.name }} namespace: kube-system +{{- end }} diff --git a/k8s/helm/infra/templates/cert-manager.yaml b/k8s/helm/infra/templates/cert-manager.yaml index 3ef84c83..2abe0706 100644 --- a/k8s/helm/infra/templates/cert-manager.yaml +++ b/k8s/helm/infra/templates/cert-manager.yaml @@ -1,3 +1,4 @@ +{{- if or .Values.certManager.enabled (not (hasKey .Values "certManager.enabled")) }} {{- if hasKey .Values.certManager.issuer "staging" }} --- apiVersion: cert-manager.io/v1 @@ -88,3 +89,4 @@ metadata: spec: ca: secretName: internal-root-cert +{{- end }} diff --git a/k8s/helm/infra/templates/gateway.yaml b/k8s/helm/infra/templates/gateway.yaml index 1f19b990..4d201e75 100644 --- a/k8s/helm/infra/templates/gateway.yaml +++ b/k8s/helm/infra/templates/gateway.yaml @@ -55,8 +55,14 @@ spec: namespaces: from: Selector selector: - matchLabels: - kubernetes.io/metadata.name: {{ $.Values.namespace }} + matchExpressions: + - key: kubernetes.io/metadata.name + operator: In + values: + - {{ $.Values.namespace }} + {{- if hasKey $gateway "allowNamespaces" }} + {{- toYaml $gateway.allowNamespaces | nindent 10 }} + {{- end }} listeners: # at least one dummy listener is needed; here we also add support for # TCP listeners; all http listeners are defined with ListenerSets diff --git a/k8s/helm/infra/templates/k8s-backup.yaml b/k8s/helm/infra/templates/k8s-backup.yaml index b35f5636..5eb70f1c 100644 --- a/k8s/helm/infra/templates/k8s-backup.yaml +++ b/k8s/helm/infra/templates/k8s-backup.yaml @@ -1,3 +1,4 @@ +{{- if or .Values.k8sBackup.enabled (not (hasKey .Values "k8sBackup.enabled")) }} --- apiVersion: batch/v1 kind: CronJob @@ -40,3 +41,4 @@ spec: type: Directory - name: backup hostPath: { path: {{ .Values.k8sBackup.destPath }} } +{{- end }} diff --git a/k8s/helm/infra/templates/limits.yaml b/k8s/helm/infra/templates/limits.yaml index 762918ef..36d40875 100644 --- a/k8s/helm/infra/templates/limits.yaml +++ b/k8s/helm/infra/templates/limits.yaml @@ -1,3 +1,4 @@ +{{- if or .Values.limits.enabled (not (hasKey .Values "limits.enabled")) }} --- apiVersion: v1 kind: LimitRange @@ -28,3 +29,4 @@ spec: defaultRequest: cpu: {{ .Values.limits.cpu.request }} type: Container +{{- end }} diff --git a/k8s/helm/infra/templates/local-storage.yaml b/k8s/helm/infra/templates/local-storage.yaml index c239d2ac..a28a9d65 100644 --- a/k8s/helm/infra/templates/local-storage.yaml +++ b/k8s/helm/infra/templates/local-storage.yaml @@ -1,12 +1,14 @@ +{{- if or .Values.localStorage.enabled (not (hasKey .Values "localStorage.enabled")) }} --- kind: StorageClass apiVersion: storage.k8s.io/v1 metadata: annotations: storageclass.kubernetes.io/is-default-class: "true" - name: local-storage + name: {{ .Values.localStorage.name }} labels: {{- include "local.labels" . | nindent 4 }} allowVolumeExpansion: false provisioner: kubernetes.io/no-provisioner volumeBindingMode: WaitForFirstConsumer +{{- end }} diff --git a/k8s/helm/infra/templates/rsyslog-ext.yaml b/k8s/helm/infra/templates/rsyslog-ext.yaml index 3988c9ac..fd69aa80 100644 --- a/k8s/helm/infra/templates/rsyslog-ext.yaml +++ b/k8s/helm/infra/templates/rsyslog-ext.yaml @@ -1,3 +1,4 @@ +{{- if or .Values.rsyslogExt.enabled (not (hasKey .Values "rsyslogExt.enabled")) }} --- # for remote VPN-connected systems apiVersion: v1 @@ -14,3 +15,4 @@ spec: selector: app.kubernetes.io/name: rsyslogd sessionAffinity: ClientIP +{{- end }} diff --git a/k8s/helm/infra/values.yaml b/k8s/helm/infra/values.yaml index ff3d285a..81936838 100644 --- a/k8s/helm/infra/values.yaml +++ b/k8s/helm/infra/values.yaml @@ -1,5 +1,11 @@ # Default values for infra. +# These sections are optional (add 'enabled: false' override to disable +# any that aren't applicable to your environment): +# adminUser, certManager, k8sBackup, limits, localStorage, rsyslogExt +# To disable gateway resources, override with an empty list []. namespace: default +adminUser: + name: admin-user certManager: email: admin@example.com issuer: @@ -22,6 +28,9 @@ certManager: enabled: true gateways: - name: gateway-1 + # gateway resources will launch in the namespace defined at top; to + # allow listenersets from other namespaces, list them here + # allowNamespaces: [ myapp ] class: envoy-internal config: envoy-config-internal crdNamespace: envoy-gateway-system @@ -40,5 +49,7 @@ limits: mem: default: 256Mi request: 64Mi +localStorage: + name: local-storage rsyslogExt: nodePort: 30514 diff --git a/k8s/helm/synapse/Chart.yaml b/k8s/helm/synapse/Chart.yaml index fe9bc96a..8bf2ff6f 100644 --- a/k8s/helm/synapse/Chart.yaml +++ b/k8s/helm/synapse/Chart.yaml @@ -6,15 +6,15 @@ sources: - https://github.com/matrix-org/synapse - https://hub.docker.com/r/matrixdotorg/synapse type: application -version: 0.1.1 -appVersion: v1.126.0 +version: 0.1.2 +appVersion: v1.161.0 dependencies: - name: chartlib version: 0.1.11 repository: oci://ghcr.io/instantlinux/charts # also available at oci://registry-1.docker.io/instantlinux - name: admin - version: 0.1.1 + version: 0.1.2 repository: file://subcharts/admin condition: admin.enabled - name: element diff --git a/k8s/helm/synapse/subcharts/admin/Chart.yaml b/k8s/helm/synapse/subcharts/admin/Chart.yaml index ccf21e6c..c04d3cd2 100644 --- a/k8s/helm/synapse/subcharts/admin/Chart.yaml +++ b/k8s/helm/synapse/subcharts/admin/Chart.yaml @@ -6,7 +6,7 @@ sources: - https://github.com/Awesome-Technologies/synapse-admin - https://hub.docker.com/r/awesometechnologies/synapse-admin type: application -version: 0.1.1 +version: 0.1.2 # specify version tag from hub.docker.com in top-level values.yaml appVersion: 0.0.1 dependencies: diff --git a/k8s/helm/synapse/subcharts/admin/values.yaml b/k8s/helm/synapse/subcharts/admin/values.yaml index 84cb4baa..18ebd575 100644 --- a/k8s/helm/synapse/subcharts/admin/values.yaml +++ b/k8s/helm/synapse/subcharts/admin/values.yaml @@ -21,5 +21,3 @@ autoscaling: enabled: false gateway: enabled: true - external: true - name: gateway-2 diff --git a/k8s/install/namespace-user.yaml b/k8s/install/namespace-user.yaml index 2ff2eb57..3f2a65ce 100644 --- a/k8s/install/namespace-user.yaml +++ b/k8s/install/namespace-user.yaml @@ -148,6 +148,16 @@ rules: - get - list - watch +- apiGroups: [gateway.networking.k8s.io] + resources: + - httproutes + - listenersets + - tcproutes + verbs: + - create + - get + - list + - view --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding From 5a54f6534d88bc42cc5bacdaede456b1e4319930 Mon Sep 17 00:00:00 2001 From: Rich Braun Date: Wed, 23 Sep 2026 21:25:32 -0700 Subject: [PATCH 2/2] SYS-593 wip --- k8s/install/namespace-user.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/k8s/install/namespace-user.yaml b/k8s/install/namespace-user.yaml index 3f2a65ce..7409ce97 100644 --- a/k8s/install/namespace-user.yaml +++ b/k8s/install/namespace-user.yaml @@ -154,7 +154,6 @@ rules: - listenersets - tcproutes verbs: - - create - get - list - view