2021-01-09 17:54:42 +00:00
|
|
|
gitea_enabled: true
|
|
|
|
gitea_publish_web: false
|
|
|
|
gitea_publish_ssh: false
|
|
|
|
gitea_use_external_db: true
|
2021-01-25 18:04:57 +00:00
|
|
|
gitea_short_name: "gitea"
|
2021-01-09 17:54:42 +00:00
|
|
|
gitea_ingress_class: "{{ gitea_namespace | default(namespace) }}-{{ 'public' if gitea_publish_web else 'private' }}-gitea-ingress-nginx"
|
|
|
|
gitea_default_values:
|
2021-01-25 18:04:57 +00:00
|
|
|
service:
|
|
|
|
http:
|
|
|
|
clusterIP:
|
|
|
|
ssh:
|
|
|
|
clusterIP:
|
2021-01-09 17:54:42 +00:00
|
|
|
ingress:
|
|
|
|
enabled: true
|
|
|
|
annotations:
|
|
|
|
cert-manager.io/cluster-issuer: "letsencrypt-prod"
|
|
|
|
cert-manager.io/acme-dns01-provider: "rfc2136"
|
|
|
|
cert-manager.io/acme-challenge-type: "dns01"
|
|
|
|
nginx.ingress.kubernetes.io/proxy-body-size: "0"
|
|
|
|
nginx.ingress.kubernetes.io/proxy-read-timeout: "600"
|
|
|
|
nginx.ingress.kubernetes.io/proxy-send-timeout: "600"
|
2021-01-25 18:04:57 +00:00
|
|
|
kubernetes.io/ingress.class: "{{ gitea_ingress_class }}"
|
2021-01-09 17:54:42 +00:00
|
|
|
kubernetes.io/tls-acme: "true"
|
2021-01-25 18:04:57 +00:00
|
|
|
hosts:
|
|
|
|
- "{{ gitea_short_name }}.{{ domain }}"
|
|
|
|
tls:
|
|
|
|
- secretName: "{{ gitea_short_name }}.{{ domain }}-tls"
|
|
|
|
hosts:
|
|
|
|
- "{{ gitea_short_name }}.{{ domain }}"
|
|
|
|
|
2021-01-09 17:54:42 +00:00
|
|
|
persistence:
|
|
|
|
enabled: true
|
2021-01-25 18:04:57 +00:00
|
|
|
accessModes:
|
|
|
|
- "{{ gitea_storage_mode | default('ReadWriteMany') }}"
|
2021-01-09 17:54:42 +00:00
|
|
|
size: "{{ gitea_size | default('20Gi') }}"
|
|
|
|
storageClass: "{{ gitea_storage | default('nfs-ssd') }}"
|
|
|
|
## addtional annotations for PVCs. Uncommenting will prevent the PVC from being deleted.
|
|
|
|
annotations:
|
|
|
|
"helm.sh/resource-policy": keep
|
2021-01-25 18:04:57 +00:00
|
|
|
|
|
|
|
gitea:
|
|
|
|
admin:
|
|
|
|
username: "{{ gitea_admin_user | default('gitea') }}"
|
|
|
|
password: "{{ gitea_admin_pass | default(gitea_admin_password) }}"
|
|
|
|
email: "gitea@{{ mail_domain | default(domain) }}"
|
|
|
|
|
|
|
|
ldap:
|
|
|
|
enabled: true
|
|
|
|
name: OpenLDAP
|
|
|
|
securityProtocol: ldaps
|
|
|
|
host: "{{ openldap_short_name | default('openldap')}}.{{ domain }}"
|
|
|
|
port: "636"
|
|
|
|
userSearchBase: "ou=users,{{ openldap_domain }}"
|
|
|
|
userFilter: "(&(objectClass=posixAccount)(uid=%s))"
|
|
|
|
emailAttribute: mail
|
|
|
|
bindDn: "uid=ldapbind,ou=services,{{ openldap_domain }}"
|
|
|
|
bindPassword: "{{ ldapbind_pass | default(ldapbind_password) }}"
|
|
|
|
|
|
|
|
config:
|
|
|
|
# APP_NAME: "Gitea: Git with a cup of tea"
|
|
|
|
RUN_MODE: prod
|
|
|
|
service:
|
|
|
|
DISABLE_REGISTRATION: true
|
|
|
|
mailer:
|
|
|
|
ENABLED: "true"
|
|
|
|
HOST: "{{ mail_short_name | default('mail') }}.{{ mail_domain | default(domain) }}:465"
|
|
|
|
IS_TLS_ENABLED: "true"
|
|
|
|
FROM: "gitea@{{ mail_domain | default(domain) }}"
|
|
|
|
USER: "{{ gitea_ldap_user | default('gitea') }}"
|
|
|
|
PASSWD: "{{ gitea_ldap_pass | default(gitea_ldap_password) }}"
|
|
|
|
MAILER_TYPE: "smtp"
|
2021-01-25 18:24:14 +00:00
|
|
|
|
|
|
|
gitea_external_db_values:
|
|
|
|
gitea:
|
|
|
|
config:
|
2021-01-25 18:04:57 +00:00
|
|
|
database:
|
|
|
|
DB_TYPE: postgres
|
|
|
|
HOST: "{{ postgres_db_team | default(namespace) }}-postgres.{{ postgres_db_namespace | default(namespace) }}.svc.cluster.local:5432"
|
|
|
|
NAME: gitea
|
|
|
|
USER: "{{ gitea_db_username | default(omit) }}"
|
|
|
|
PASSWD: "{{ gitea_db_password | default(omit) }}"
|
|
|
|
|
|
|
|
database:
|
|
|
|
builtIn:
|
|
|
|
postgresql:
|
|
|
|
enabled: false
|
2021-01-09 17:54:42 +00:00
|
|
|
|
2021-01-25 01:15:32 +00:00
|
|
|
gitea_publish_ingress_nginx_values:
|
2021-01-09 17:54:42 +00:00
|
|
|
controller:
|
|
|
|
config:
|
|
|
|
use-proxy-protocol: true
|
|
|
|
use-forward-headers: true
|
|
|
|
compute-full-forward-for: true
|
|
|
|
service:
|
|
|
|
externalTrafficPolicy: Local
|
|
|
|
|
|
|
|
gitea_ingress_nginx_default_values:
|
|
|
|
controller:
|
|
|
|
containerPort:
|
|
|
|
ssh: 22
|
|
|
|
http: 80
|
|
|
|
https: 443
|
|
|
|
publishService:
|
|
|
|
enabled: true
|
|
|
|
scope:
|
|
|
|
enabled: true
|
|
|
|
extraArgs:
|
|
|
|
tcp-services-configmap: "{{ gitea_namespace | default(namespace) }}/{{ gitea_ingress_nginx_name | default(namespace + '-gitea-ingress-nginx') }}-tcp"
|
|
|
|
service:
|
|
|
|
enabled: true
|
|
|
|
type: LoadBalancer
|
|
|
|
loadBalancerIP: "{{ gitea_loadbalancer_ip | default(omit) }}"
|
|
|
|
ports:
|
|
|
|
ssh: 22
|
|
|
|
http: 80
|
|
|
|
https: 443
|
|
|
|
targetPorts:
|
|
|
|
ssh: ssh
|
|
|
|
http: http
|
|
|
|
https: https
|
|
|
|
ingressClass: "{{ gitea_ingress_class }}"
|
|
|
|
tcp:
|
2021-01-25 18:04:57 +00:00
|
|
|
22: "{{ gitea_namespace | default(namespace) }}/{{ namespace }}-gitea-ssh:22"
|
2021-01-09 17:54:42 +00:00
|
|
|
|
|
|
|
gitea_dns_default_values:
|
|
|
|
fullnameOverride: "{{ gitea_dns_name | default(namespace + '-gitea-internal-dns') }}"
|
|
|
|
annotationFilter: "kubernetes.io/ingress.class={{ gitea_ingress_class }}"
|
|
|
|
domainFilters: ["{{ domain }}"]
|
|
|
|
provider: rfc2136
|
|
|
|
rfc2136:
|
|
|
|
host: "{{ dns_ip }}"
|
|
|
|
port: 53
|
|
|
|
zone: "{{ domain }}"
|
|
|
|
tsigSecret: "{{ k8s_tsig }}"
|
|
|
|
tsigSecretAlg: "{{ gitea_dns_tsigSecretAlg | default('hmac-sha512') }}"
|
|
|
|
tsigKeyname: "{{ gitea_dns_tsigKeyname | default('k8s') }}"
|
|
|
|
tsigAxfr: true
|
|
|
|
## Possible units [ns, us, ms, s, m, h], see more https://golang.org/pkg/time/#ParseDuration
|
|
|
|
minTTL: "30s"
|