feat: add pocket-id helm chart and argo app
This commit is contained in:
parent
e6b636198e
commit
89f98fd6c3
11 changed files with 721 additions and 0 deletions
63
k8s/argo-apps/pocket-id.yaml
Normal file
63
k8s/argo-apps/pocket-id.yaml
Normal file
|
|
@ -0,0 +1,63 @@
|
||||||
|
---
|
||||||
|
apiVersion: argoproj.io/v1alpha1
|
||||||
|
kind: Application
|
||||||
|
metadata:
|
||||||
|
name: pocket-id
|
||||||
|
namespace: argo-cd
|
||||||
|
spec:
|
||||||
|
destination:
|
||||||
|
name: ''
|
||||||
|
namespace: apps-roboces
|
||||||
|
server: https://kubernetes.default.svc
|
||||||
|
sources:
|
||||||
|
- repoURL: git.roboces.dev/catalin/fukuops
|
||||||
|
chart: pocket-id
|
||||||
|
targetRevision: 0.1.3
|
||||||
|
helm:
|
||||||
|
valuesObject:
|
||||||
|
replicaCount: 1
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
|
runAsUser: 10000
|
||||||
|
runAsGroup: 10000
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- all
|
||||||
|
service:
|
||||||
|
type: LoadBalancer
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
className: "traefik"
|
||||||
|
annotations:
|
||||||
|
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
||||||
|
traefik.ingress.kubernetes.io/router.tls: "true"
|
||||||
|
hosts:
|
||||||
|
- host: auth.roboces.dev
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 250m
|
||||||
|
memory: 256Mi
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 512Mi
|
||||||
|
persistence:
|
||||||
|
enabled: true
|
||||||
|
storageClass: "truenas-nfs-csi"
|
||||||
|
accessMode: ReadWriteMany
|
||||||
|
size: 8Gi
|
||||||
|
config:
|
||||||
|
appUrl: "https://auth.roboces.dev"
|
||||||
|
trustProxy: "true"
|
||||||
|
uiConfigDisabled: true
|
||||||
|
allowUserSignups: "disabled"
|
||||||
|
secret:
|
||||||
|
existingSecretName: pocket-id-secrets
|
||||||
|
project: roboces
|
||||||
|
syncPolicy:
|
||||||
|
automated:
|
||||||
|
prune: true
|
||||||
|
selfHeal: true
|
||||||
19
k8s/charts/pocket-id/Chart.yaml
Normal file
19
k8s/charts/pocket-id/Chart.yaml
Normal file
|
|
@ -0,0 +1,19 @@
|
||||||
|
apiVersion: v2
|
||||||
|
name: pocket-id
|
||||||
|
description: A Helm chart for Pocket ID - an open source identity provider
|
||||||
|
type: application
|
||||||
|
version: 0.1.0
|
||||||
|
appVersion: v2.13.0
|
||||||
|
keywords:
|
||||||
|
- pocket-id
|
||||||
|
- identity
|
||||||
|
- oidc
|
||||||
|
- passkey
|
||||||
|
- webauthn
|
||||||
|
sources:
|
||||||
|
- https://github.com/pocket-id/pocket-id
|
||||||
|
- https://pocket-id.org/docs
|
||||||
|
annotations:
|
||||||
|
artifacthub.io/images: "- name: pocket-id\n image: ghcr.io/pocket-id/pocket-id:v2.13.0\n"
|
||||||
|
artifacthub.io/links: "- name: source\n url: https://github.com/pocket-id/pocket-id\n\
|
||||||
|
- name: documentation\n url: https://pocket-id.org/docs\n"
|
||||||
60
k8s/charts/pocket-id/templates/_helpers.tpl
Normal file
60
k8s/charts/pocket-id/templates/_helpers.tpl
Normal file
|
|
@ -0,0 +1,60 @@
|
||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "pocket-id.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
*/}}
|
||||||
|
{{- define "pocket-id.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "pocket-id.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "pocket-id.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "pocket-id.chart" . }}
|
||||||
|
{{ include "pocket-id.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "pocket-id.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "pocket-id.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Service account name
|
||||||
|
*/}}
|
||||||
|
{{- define "pocket-id.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "pocket-id.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
208
k8s/charts/pocket-id/templates/configmap.yaml
Normal file
208
k8s/charts/pocket-id/templates/configmap.yaml
Normal file
|
|
@ -0,0 +1,208 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
data:
|
||||||
|
{{- if .Values.config.appUrl }}
|
||||||
|
APP_URL: {{ .Values.config.appUrl | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.trustProxy }}
|
||||||
|
TRUST_PROXY: {{ .Values.config.trustProxy | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.proxyProtocol }}
|
||||||
|
PROXY_PROTOCOL: {{ .Values.config.proxyProtocol | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.trustedPlatform }}
|
||||||
|
TRUSTED_PLATFORM: {{ .Values.config.trustedPlatform | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.allowInsecureCallbackUrls }}
|
||||||
|
ALLOW_INSECURE_CALLBACK_URLS: {{ .Values.config.allowInsecureCallbackUrls | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.maxmindLicenseKey }}
|
||||||
|
MAXMIND_LICENSE_KEY: {{ .Values.config.maxmindLicenseKey | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.dbConnectionString }}
|
||||||
|
DB_CONNECTION_STRING: {{ .Values.config.dbConnectionString | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.fileBackend }}
|
||||||
|
FILE_BACKEND: {{ .Values.config.fileBackend | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.uploadPath }}
|
||||||
|
UPLOAD_PATH: {{ .Values.config.uploadPath | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.logLevel }}
|
||||||
|
LOG_LEVEL: {{ .Values.config.logLevel | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.logJson }}
|
||||||
|
LOG_JSON: {{ .Values.config.logJson | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.geoliteDbPath }}
|
||||||
|
GEOLITE_DB_PATH: {{ .Values.config.geoliteDbPath | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.port }}
|
||||||
|
PORT: {{ .Values.config.port | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.host }}
|
||||||
|
HOST: {{ .Values.config.host | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.uiConfigDisabled }}
|
||||||
|
UI_CONFIG_DISABLED: {{ .Values.config.uiConfigDisabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.analyticsDisabled }}
|
||||||
|
ANALYTICS_DISABLED: {{ .Values.config.analyticsDisabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.versionCheckDisabled }}
|
||||||
|
VERSION_CHECK_DISABLED: {{ .Values.config.versionCheckDisabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.auditLogRetentionDays }}
|
||||||
|
AUDIT_LOG_RETENTION_DAYS: {{ .Values.config.auditLogRetentionDays | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.disableRateLimiting }}
|
||||||
|
DISABLE_RATE_LIMITING: {{ .Values.config.disableRateLimiting | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.appName }}
|
||||||
|
APP_NAME: {{ .Values.config.appName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.sessionDuration }}
|
||||||
|
SESSION_DURATION: {{ .Values.config.sessionDuration | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.homePageUrl }}
|
||||||
|
HOME_PAGE_URL: {{ .Values.config.homePageUrl | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.requireUserEmail }}
|
||||||
|
REQUIRE_USER_EMAIL: {{ .Values.config.requireUserEmail | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.emailsVerified }}
|
||||||
|
EMAILS_VERIFIED: {{ .Values.config.emailsVerified | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.allowOwnAccountEdit }}
|
||||||
|
ALLOW_OWN_ACCOUNT_EDIT: {{ .Values.config.allowOwnAccountEdit | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.allowUserSignups }}
|
||||||
|
ALLOW_USER_SIGNUPS: {{ .Values.config.allowUserSignups | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.signupDefaultCustomClaims }}
|
||||||
|
SIGNUP_DEFAULT_CUSTOM_CLAIMS: {{ .Values.config.signupDefaultCustomClaims | toJson | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.signupDefaultUserGroupIds }}
|
||||||
|
SIGNUP_DEFAULT_USER_GROUP_IDS: {{ .Values.config.signupDefaultUserGroupIds | toJson | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.disableAnimations }}
|
||||||
|
DISABLE_ANIMATIONS: {{ .Values.config.disableAnimations | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.accentColor }}
|
||||||
|
ACCENT_COLOR: {{ .Values.config.accentColor | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.smtpHost }}
|
||||||
|
SMTP_HOST: {{ .Values.config.smtpHost | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.smtpPort }}
|
||||||
|
SMTP_PORT: {{ .Values.config.smtpPort | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.smtpFrom }}
|
||||||
|
SMTP_FROM: {{ .Values.config.smtpFrom | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.smtpUser }}
|
||||||
|
SMTP_USER: {{ .Values.config.smtpUser | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.smtpTls }}
|
||||||
|
SMTP_TLS: {{ .Values.config.smtpTls | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.smtpSkipCertVerify }}
|
||||||
|
SMTP_SKIP_CERT_VERIFY: {{ .Values.config.smtpSkipCertVerify | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.emailLoginNotificationEnabled }}
|
||||||
|
EMAIL_LOGIN_NOTIFICATION_ENABLED: {{ .Values.config.emailLoginNotificationEnabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.emailOneTimeAccessAsAdminEnabled }}
|
||||||
|
EMAIL_ONE_TIME_ACCESS_AS_ADMIN_ENABLED: {{ .Values.config.emailOneTimeAccessAsAdminEnabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.emailApiKeyExpirationEnabled }}
|
||||||
|
EMAIL_API_KEY_EXPIRATION_ENABLED: {{ .Values.config.emailApiKeyExpirationEnabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.emailOneTimeAccessAsUnauthenticatedEnabled }}
|
||||||
|
EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED: {{ .Values.config.emailOneTimeAccessAsUnauthenticatedEnabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.emailVerificationEnabled }}
|
||||||
|
EMAIL_VERIFICATION_ENABLED: {{ .Values.config.emailVerificationEnabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapEnabled }}
|
||||||
|
LDAP_ENABLED: {{ .Values.config.ldapEnabled | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapUrl }}
|
||||||
|
LDAP_URL: {{ .Values.config.ldapUrl | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapBindDn }}
|
||||||
|
LDAP_BIND_DN: {{ .Values.config.ldapBindDn | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapBase }}
|
||||||
|
LDAP_BASE: {{ .Values.config.ldapBase | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapUserSearchFilter }}
|
||||||
|
LDAP_USER_SEARCH_FILTER: {{ .Values.config.ldapUserSearchFilter | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapUserGroupSearchFilter }}
|
||||||
|
LDAP_USER_GROUP_SEARCH_FILTER: {{ .Values.config.ldapUserGroupSearchFilter | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapSkipCertVerify }}
|
||||||
|
LDAP_SKIP_CERT_VERIFY: {{ .Values.config.ldapSkipCertVerify | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapSoftDeleteUsers }}
|
||||||
|
LDAP_SOFT_DELETE_USERS: {{ .Values.config.ldapSoftDeleteUsers | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeUserUniqueIdentifier }}
|
||||||
|
LDAP_ATTRIBUTE_USER_UNIQUE_IDENTIFIER: {{ .Values.config.ldapAttributeUserUniqueIdentifier | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeUserUsername }}
|
||||||
|
LDAP_ATTRIBUTE_USER_USERNAME: {{ .Values.config.ldapAttributeUserUsername | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeUserEmail }}
|
||||||
|
LDAP_ATTRIBUTE_USER_EMAIL: {{ .Values.config.ldapAttributeUserEmail | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeUserFirstName }}
|
||||||
|
LDAP_ATTRIBUTE_USER_FIRST_NAME: {{ .Values.config.ldapAttributeUserFirstName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeUserLastName }}
|
||||||
|
LDAP_ATTRIBUTE_USER_LAST_NAME: {{ .Values.config.ldapAttributeUserLastName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeUserProfilePicture }}
|
||||||
|
LDAP_ATTRIBUTE_USER_PROFILE_PICTURE: {{ .Values.config.ldapAttributeUserProfilePicture | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeGroupMember }}
|
||||||
|
LDAP_ATTRIBUTE_GROUP_MEMBER: {{ .Values.config.ldapAttributeGroupMember | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeGroupUniqueIdentifier }}
|
||||||
|
LDAP_ATTRIBUTE_GROUP_UNIQUE_IDENTIFIER: {{ .Values.config.ldapAttributeGroupUniqueIdentifier | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAttributeGroupName }}
|
||||||
|
LDAP_ATTRIBUTE_GROUP_NAME: {{ .Values.config.ldapAttributeGroupName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.ldapAdminGroupName }}
|
||||||
|
LDAP_ADMIN_GROUP_NAME: {{ .Values.config.ldapAdminGroupName | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.webauthnUserVerification }}
|
||||||
|
WEBAUTHN_USER_VERIFICATION: {{ .Values.config.webauthnUserVerification | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.webauthnAllowSyncedPasskeys }}
|
||||||
|
WEBAUTHN_ALLOW_SYNCED_PASSKEYS: {{ .Values.config.webauthnAllowSyncedPasskeys | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.webauthnAuthenticatorAttachment }}
|
||||||
|
WEBAUTHN_AUTHENTICATOR_ATTACHMENT: {{ .Values.config.webauthnAuthenticatorAttachment | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.cimdUrlAllowlist }}
|
||||||
|
CIMD_URL_ALLOWLIST: {{ .Values.config.cimdUrlAllowlist | toJson | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.otelTracesExporter }}
|
||||||
|
OTEL_TRACES_EXPORTER: {{ .Values.config.otelTracesExporter | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.otelMetricsExporter }}
|
||||||
|
OTEL_METRICS_EXPORTER: {{ .Values.config.otelMetricsExporter | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.otelLogsExporter }}
|
||||||
|
OTEL_LOGS_EXPORTER: {{ .Values.config.otelLogsExporter | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.config.otelExporterOtlpEndpoint }}
|
||||||
|
OTEL_EXPORTER_OTLP_ENDPOINT: {{ .Values.config.otelExporterOtlpEndpoint | quote }}
|
||||||
|
{{- end }}
|
||||||
91
k8s/charts/pocket-id/templates/deployment.yaml
Normal file
91
k8s/charts/pocket-id/templates/deployment.yaml
Normal file
|
|
@ -0,0 +1,91 @@
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
{{- if not .Values.autoscaling.enabled }}
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
{{- end }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "pocket-id.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.selectorLabels" . | nindent 8 }}
|
||||||
|
{{- with .Values.podLabels }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "pocket-id.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
envFrom:
|
||||||
|
{{- if .Values.secret.existingSecretName }}
|
||||||
|
- secretRef:
|
||||||
|
name: {{ .Values.secret.existingSecretName }}
|
||||||
|
{{- else if .Values.secret.enabled }}
|
||||||
|
- secretRef:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
{{- end }}
|
||||||
|
- configMapRef:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
{{- toYaml .Values.livenessProbe | nindent 12 }}
|
||||||
|
readinessProbe:
|
||||||
|
{{- toYaml .Values.readinessProbe | nindent 12 }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
volumeMounts:
|
||||||
|
- name: data
|
||||||
|
mountPath: /app/data
|
||||||
|
{{- if .Values.persistence.existingClaim }}
|
||||||
|
volumes:
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: {{ .Values.persistence.existingClaim }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
restartPolicy: Always
|
||||||
|
automountServiceAccountToken: {{ .Values.serviceAccount.automount }}
|
||||||
|
volumes:
|
||||||
|
{{- if .Values.persistence.existingClaim }}
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: {{ .Values.persistence.existingClaim }}
|
||||||
|
{{- else if .Values.persistence.enabled }}
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: {{ include "pocket-id.fullname" . }}
|
||||||
|
{{- end }}
|
||||||
43
k8s/charts/pocket-id/templates/ingress.yaml
Normal file
43
k8s/charts/pocket-id/templates/ingress.yaml
Normal file
|
|
@ -0,0 +1,43 @@
|
||||||
|
{{- if .Values.ingress.enabled -}}
|
||||||
|
{{- $fullName := include "pocket-id.fullname" . -}}
|
||||||
|
{{- $svcPort := .Values.service.port -}}
|
||||||
|
{{- if and .Values.ingress.className (not (hasKey .Values.ingress.annotations "kubernetes.io/ingress.class")) }}
|
||||||
|
{{- $_ := set .Values.ingress.annotations "kubernetes.io/ingress.class" .Values.ingress.className }}
|
||||||
|
{{- end }}
|
||||||
|
apiVersion: networking.k8s.io/v1
|
||||||
|
kind: Ingress
|
||||||
|
metadata:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.ingress.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
{{- if .Values.ingress.tls }}
|
||||||
|
tls:
|
||||||
|
{{- range .Values.ingress.tls }}
|
||||||
|
- hosts:
|
||||||
|
{{- range .hosts }}
|
||||||
|
- {{ . | quote }}
|
||||||
|
{{- end }}
|
||||||
|
secretName: {{ .secretName }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
rules:
|
||||||
|
{{- range .Values.ingress.hosts }}
|
||||||
|
- host: {{ .host | quote }}
|
||||||
|
http:
|
||||||
|
paths:
|
||||||
|
{{- range .paths }}
|
||||||
|
- path: {{ .path }}
|
||||||
|
pathType: {{ .pathType | default "Prefix" }}
|
||||||
|
backend:
|
||||||
|
service:
|
||||||
|
name: {{ $fullName }}
|
||||||
|
port:
|
||||||
|
number: {{ $svcPort }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
25
k8s/charts/pocket-id/templates/pvc.yaml
Normal file
25
k8s/charts/pocket-id/templates/pvc.yaml
Normal file
|
|
@ -0,0 +1,25 @@
|
||||||
|
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.persistence.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- {{ .Values.persistence.accessMode }}
|
||||||
|
{{- if .Values.persistence.storageClass }}
|
||||||
|
{{- if eq "-" .Values.persistence.storageClass }}
|
||||||
|
storageClassName: ""
|
||||||
|
{{- else }}
|
||||||
|
storageClassName: {{ .Values.persistence.storageClass | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: {{ .Values.persistence.size }}
|
||||||
|
{{- end }}
|
||||||
31
k8s/charts/pocket-id/templates/secret.yaml
Normal file
31
k8s/charts/pocket-id/templates/secret.yaml
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
{{- if and .Values.secret.enabled (not .Values.secret.existingSecretName) }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
{{- if .Values.secret.encryptionKey }}
|
||||||
|
ENCRYPTION_KEY: {{ .Values.secret.encryptionKey }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.secret.dbConnectionString }}
|
||||||
|
DB_CONNECTION_STRING: {{ .Values.secret.dbConnectionString }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.secret.smtpPassword }}
|
||||||
|
SMTP_PASSWORD: {{ .Values.secret.smtpPassword }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.secret.ldapBindPassword }}
|
||||||
|
LDAP_BIND_PASSWORD: {{ .Values.secret.ldapBindPassword }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.secret.maxmindLicenseKeyFile }}
|
||||||
|
MAXMIND_LICENSE_KEY_FILE: {{ .Values.secret.maxmindLicenseKeyFile }}
|
||||||
|
{{- end }}
|
||||||
|
{{- if .Values.secret.staticApiKey }}
|
||||||
|
STATIC_API_KEY: {{ .Values.secret.staticApiKey }}
|
||||||
|
{{- end }}
|
||||||
|
{{- range $key, $value := .Values.secret.data }}
|
||||||
|
{{ $key }}: {{ $value | quote }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
15
k8s/charts/pocket-id/templates/service.yaml
Normal file
15
k8s/charts/pocket-id/templates/service.yaml
Normal file
|
|
@ -0,0 +1,15 @@
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "pocket-id.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "pocket-id.selectorLabels" . | nindent 4 }}
|
||||||
12
k8s/charts/pocket-id/templates/serviceaccount.yaml
Normal file
12
k8s/charts/pocket-id/templates/serviceaccount.yaml
Normal file
|
|
@ -0,0 +1,12 @@
|
||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "pocket-id.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "pocket-id.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
154
k8s/charts/pocket-id/values.yaml
Normal file
154
k8s/charts/pocket-id/values.yaml
Normal file
|
|
@ -0,0 +1,154 @@
|
||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: ghcr.io/pocket-id/pocket-id
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: ""
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
podAnnotations: {}
|
||||||
|
podLabels: {}
|
||||||
|
podSecurityContext: {}
|
||||||
|
securityContext: {}
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: ClusterIP
|
||||||
|
port: 1411
|
||||||
|
|
||||||
|
ingress:
|
||||||
|
enabled: false
|
||||||
|
className: ""
|
||||||
|
annotations: {}
|
||||||
|
hosts:
|
||||||
|
- host: chart-example.local
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: Prefix
|
||||||
|
tls: []
|
||||||
|
|
||||||
|
resources: {}
|
||||||
|
|
||||||
|
livenessProbe:
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
timeoutSeconds: 5
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 3
|
||||||
|
periodSeconds: 10
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: http
|
||||||
|
|
||||||
|
readinessProbe:
|
||||||
|
initialDelaySeconds: 15
|
||||||
|
timeoutSeconds: 2
|
||||||
|
successThreshold: 1
|
||||||
|
failureThreshold: 3
|
||||||
|
periodSeconds: 10
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: http
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
tolerations: []
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
automount: true
|
||||||
|
annotations: {}
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
persistence:
|
||||||
|
enabled: true
|
||||||
|
existingClaim: ""
|
||||||
|
storageClass: ""
|
||||||
|
annotations: {}
|
||||||
|
accessMode: ReadWriteOnce
|
||||||
|
size: 8Gi
|
||||||
|
|
||||||
|
autoscaling:
|
||||||
|
enabled: false
|
||||||
|
minReplicas: 1
|
||||||
|
maxReplicas: 3
|
||||||
|
targetCPUUtilizationPercentage: 80
|
||||||
|
targetMemoryUtilizationPercentage: 80
|
||||||
|
|
||||||
|
config:
|
||||||
|
appUrl: ""
|
||||||
|
trustProxy: ""
|
||||||
|
proxyProtocol: ""
|
||||||
|
trustedPlatform: ""
|
||||||
|
allowInsecureCallbackUrls: ""
|
||||||
|
maxmindLicenseKey: ""
|
||||||
|
dbConnectionString: ""
|
||||||
|
fileBackend: "filesystem"
|
||||||
|
uploadPath: "/app/data/uploads"
|
||||||
|
logLevel: "info"
|
||||||
|
logJson: false
|
||||||
|
geoliteDbPath: "/app/data/GeoLite2-City.mmdb"
|
||||||
|
port: "1411"
|
||||||
|
host: "0.0.0.0"
|
||||||
|
uiConfigDisabled: false
|
||||||
|
analyticsDisabled: false
|
||||||
|
versionCheckDisabled: false
|
||||||
|
auditLogRetentionDays: 90
|
||||||
|
disableRateLimiting: false
|
||||||
|
appName: "Pocket ID"
|
||||||
|
sessionDuration: 60
|
||||||
|
homePageUrl: "/settings/account"
|
||||||
|
requireUserEmail: true
|
||||||
|
emailsVerified: false
|
||||||
|
allowOwnAccountEdit: true
|
||||||
|
allowUserSignups: "disabled"
|
||||||
|
signupDefaultCustomClaims: []
|
||||||
|
signupDefaultUserGroupIds: []
|
||||||
|
disableAnimations: false
|
||||||
|
accentColor: "default"
|
||||||
|
smtpHost: ""
|
||||||
|
smtpPort: ""
|
||||||
|
smtpFrom: ""
|
||||||
|
smtpUser: ""
|
||||||
|
smtpTls: "none"
|
||||||
|
smtpSkipCertVerify: false
|
||||||
|
emailLoginNotificationEnabled: false
|
||||||
|
emailOneTimeAccessAsAdminEnabled: false
|
||||||
|
emailApiKeyExpirationEnabled: false
|
||||||
|
emailOneTimeAccessAsUnauthenticatedEnabled: false
|
||||||
|
emailVerificationEnabled: false
|
||||||
|
ldapEnabled: false
|
||||||
|
ldapUrl: ""
|
||||||
|
ldapBindDn: ""
|
||||||
|
ldapBase: ""
|
||||||
|
ldapUserSearchFilter: "(objectClass=person)"
|
||||||
|
ldapUserGroupSearchFilter: "(objectClass=groupOfNames)"
|
||||||
|
ldapSkipCertVerify: false
|
||||||
|
ldapSoftDeleteUsers: false
|
||||||
|
ldapAttributeUserUniqueIdentifier: ""
|
||||||
|
ldapAttributeUserUsername: ""
|
||||||
|
ldapAttributeUserEmail: ""
|
||||||
|
ldapAttributeUserFirstName: ""
|
||||||
|
ldapAttributeUserLastName: ""
|
||||||
|
ldapAttributeUserProfilePicture: ""
|
||||||
|
ldapAttributeGroupMember: "member"
|
||||||
|
ldapAttributeGroupUniqueIdentifier: ""
|
||||||
|
ldapAttributeGroupName: ""
|
||||||
|
ldapAdminGroupName: ""
|
||||||
|
webauthnUserVerification: "required"
|
||||||
|
webauthnAllowSyncedPasskeys: true
|
||||||
|
webauthnAuthenticatorAttachment: "any"
|
||||||
|
cimdUrlAllowlist: []
|
||||||
|
otelTracesExporter: ""
|
||||||
|
otelMetricsExporter: ""
|
||||||
|
otelLogsExporter: ""
|
||||||
|
otelExporterOtlpEndpoint: ""
|
||||||
|
|
||||||
|
secret:
|
||||||
|
enabled: true
|
||||||
|
existingSecretName: ""
|
||||||
|
data: {}
|
||||||
|
encryptionKey: ""
|
||||||
|
dbConnectionString: ""
|
||||||
|
smtpPassword: ""
|
||||||
|
ldapBindPassword: ""
|
||||||
|
maxmindLicenseKeyFile: ""
|
||||||
|
staticApiKey: ""
|
||||||
Loading…
Add table
Add a link
Reference in a new issue