From e4373a8747ea3e3222572de98934358a7e32bb30 Mon Sep 17 00:00:00 2001 From: erikfuego Date: Wed, 22 Mar 2023 21:28:26 -0400 Subject: [PATCH 01/14] updated securityContext to include all values from values.yaml --- templates/deployment.yaml | 8 +++----- values.yaml | 1 - 2 files changed, 3 insertions(+), 6 deletions(-) diff --git a/templates/deployment.yaml b/templates/deployment.yaml index 6d2ff0e5..043fd4a5 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -42,11 +42,9 @@ spec: {{- if .Values.priorityClassName }} priorityClassName: "{{ .Values.priorityClassName }}" {{- end }} - {{- if .Values.securityContext.enabled }} - securityContext: - fsGroup: {{ .Values.securityContext.fsGroup }} - runAsUser: {{ .Values.securityContext.runAsUser }} - {{- end }} + {{- if .Values.securityContext }} + securityContext: {{ toYaml .Values.securityContext | indent 8 }} + {{- end }} {{- with .Values.initContainers }} initContainers: {{- toYaml . | nindent 8 }} diff --git a/values.yaml b/values.yaml index 7f9c5588..a5e2d6ec 100644 --- a/values.yaml +++ b/values.yaml @@ -153,7 +153,6 @@ configData: threshold: 3 securityContext: - enabled: true runAsUser: 1000 fsGroup: 1000 From b91518dbaff83526c5126792702477f60cfbf35f Mon Sep 17 00:00:00 2001 From: erikfuego Date: Wed, 22 Mar 2023 23:14:54 -0400 Subject: [PATCH 02/14] . --- templates/deployment.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/deployment.yaml b/templates/deployment.yaml index 043fd4a5..093b9739 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -43,7 +43,7 @@ spec: priorityClassName: "{{ .Values.priorityClassName }}" {{- end }} {{- if .Values.securityContext }} - securityContext: {{ toYaml .Values.securityContext | indent 8 }} + securityContext: {{ toYaml .Values.securityContext | nindent 8 }} {{- end }} {{- with .Values.initContainers }} initContainers: From a277e5d090d3aff2d9474f5123da0fb246a5ce43 Mon Sep 17 00:00:00 2001 From: erikfuego Date: Fri, 24 Mar 2023 12:09:25 -0400 Subject: [PATCH 03/14] updated cronjob.yaml securityContext --- templates/cronjob.yaml | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/templates/cronjob.yaml b/templates/cronjob.yaml index 3a04680d..1127393b 100644 --- a/templates/cronjob.yaml +++ b/templates/cronjob.yaml @@ -37,10 +37,8 @@ spec: {{- if .Values.priorityClassName }} priorityClassName: "{{ .Values.priorityClassName }}" {{- end }} - {{- if .Values.securityContext.enabled }} - securityContext: - fsGroup: {{ .Values.securityContext.fsGroup }} - runAsUser: {{ .Values.securityContext.runAsUser }} + {{- if .Values.securityContext }} + securityContext: {{ toYaml .Values.securityContext | nindent 12 }} {{- end }} containers: - name: {{ .Chart.Name }} From 533551b9e31defdfdbb911737e576775b78725d3 Mon Sep 17 00:00:00 2001 From: erikfuego Date: Fri, 24 Mar 2023 12:25:03 -0400 Subject: [PATCH 04/14] added securityContext to containers --- templates/cronjob.yaml | 3 +++ templates/deployment.yaml | 3 +++ 2 files changed, 6 insertions(+) diff --git a/templates/cronjob.yaml b/templates/cronjob.yaml index 1127393b..8ab5aa53 100644 --- a/templates/cronjob.yaml +++ b/templates/cronjob.yaml @@ -50,6 +50,9 @@ spec: - --delete-untagged={{ .Values.garbageCollect.deleteUntagged }} - /etc/docker/registry/config.yml env: {{ include "docker-registry.envs" . | nindent 16 }} + {{- if .Values.securityContext }} + securityContext: {{ toYaml .Values.securityContext | nindent 16 }} + {{- end }} volumeMounts: {{ include "docker-registry.volumeMounts" . | nindent 16 }} restartPolicy: OnFailure {{- if .Values.nodeSelector }} diff --git a/templates/deployment.yaml b/templates/deployment.yaml index 093b9739..65939416 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -80,6 +80,9 @@ spec: port: 5000 resources: {{ toYaml .Values.resources | nindent 12 }} env: {{ include "docker-registry.envs" . | nindent 12 }} + {{- if .Values.securityContext }} + securityContext: {{ toYaml .Values.securityContext | nindent 12 }} + {{- end }} volumeMounts: {{ include "docker-registry.volumeMounts" . | nindent 12 }} {{- if .Values.nodeSelector }} nodeSelector: {{ toYaml .Values.nodeSelector | nindent 8 }} From ca801de42735f6cd28551c6454bba3cd5ccd49ac Mon Sep 17 00:00:00 2001 From: erikfuego Date: Fri, 24 Mar 2023 15:09:06 -0400 Subject: [PATCH 05/14] added secretRef to secret.yaml --- templates/secret.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/templates/secret.yaml b/templates/secret.yaml index 6265dc84..4f4a1778 100644 --- a/templates/secret.yaml +++ b/templates/secret.yaml @@ -26,8 +26,11 @@ data: azureContainer: {{ .Values.secrets.azure.container | b64enc | quote }} {{- end }} {{- else if eq .Values.storage "s3" }} + {{- if and .Values.secrets.s3.secretRef }} + secretRef: {{ .Values.secrets.s3.secretRef }} + {{- end }} {{- if and .Values.secrets.s3.secretKey .Values.secrets.s3.accessKey }} - s3AccessKey: {{ .Values.secrets.s3.accessKey | b64enc | quote }} + s3AccessKey: {{ .Values.secrets.s3.secretKey | b64enc | quote }} s3SecretKey: {{ .Values.secrets.s3.secretKey | b64enc | quote }} {{- end }} {{- else if eq .Values.storage "swift" }} From a1ef866d1060cee221b1dd2d39e870bb3ea6373c Mon Sep 17 00:00:00 2001 From: erikfuego Date: Fri, 24 Mar 2023 15:21:44 -0400 Subject: [PATCH 06/14] added base64end to secretRef --- templates/secret.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/secret.yaml b/templates/secret.yaml index 4f4a1778..2cb9e766 100644 --- a/templates/secret.yaml +++ b/templates/secret.yaml @@ -27,7 +27,7 @@ data: {{- end }} {{- else if eq .Values.storage "s3" }} {{- if and .Values.secrets.s3.secretRef }} - secretRef: {{ .Values.secrets.s3.secretRef }} + secretRef: {{ .Values.secrets.s3.secretRef | b64enc | quote }} {{- end }} {{- if and .Values.secrets.s3.secretKey .Values.secrets.s3.accessKey }} s3AccessKey: {{ .Values.secrets.s3.secretKey | b64enc | quote }} From bc507bdcd5cb2167addfe3a3d0c486c0c7af2ded Mon Sep 17 00:00:00 2001 From: erikfuego Date: Fri, 24 Mar 2023 15:48:57 -0400 Subject: [PATCH 07/14] bug --- templates/secret.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/secret.yaml b/templates/secret.yaml index 2cb9e766..7d50ec6f 100644 --- a/templates/secret.yaml +++ b/templates/secret.yaml @@ -30,7 +30,7 @@ data: secretRef: {{ .Values.secrets.s3.secretRef | b64enc | quote }} {{- end }} {{- if and .Values.secrets.s3.secretKey .Values.secrets.s3.accessKey }} - s3AccessKey: {{ .Values.secrets.s3.secretKey | b64enc | quote }} + s3AccessKey: {{ .Values.secrets.s3.accessKey | b64enc | quote }} s3SecretKey: {{ .Values.secrets.s3.secretKey | b64enc | quote }} {{- end }} {{- else if eq .Values.storage "swift" }} From eae3454c77d37576cecb8301772826c3631cc279 Mon Sep 17 00:00:00 2001 From: erikfuego Date: Fri, 24 Mar 2023 20:17:34 -0400 Subject: [PATCH 08/14] specified a containerSecurityContext for containers --- templates/cronjob.yaml | 2 +- templates/deployment.yaml | 2 +- values.yaml | 1 - 3 files changed, 2 insertions(+), 3 deletions(-) diff --git a/templates/cronjob.yaml b/templates/cronjob.yaml index 8ab5aa53..4f071928 100644 --- a/templates/cronjob.yaml +++ b/templates/cronjob.yaml @@ -51,7 +51,7 @@ spec: - /etc/docker/registry/config.yml env: {{ include "docker-registry.envs" . | nindent 16 }} {{- if .Values.securityContext }} - securityContext: {{ toYaml .Values.securityContext | nindent 16 }} + securityContext: {{ toYaml .Values.containerSecurityContext | nindent 16 }} {{- end }} volumeMounts: {{ include "docker-registry.volumeMounts" . | nindent 16 }} restartPolicy: OnFailure diff --git a/templates/deployment.yaml b/templates/deployment.yaml index 65939416..cc160f95 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -81,7 +81,7 @@ spec: resources: {{ toYaml .Values.resources | nindent 12 }} env: {{ include "docker-registry.envs" . | nindent 12 }} {{- if .Values.securityContext }} - securityContext: {{ toYaml .Values.securityContext | nindent 12 }} + securityContext: {{ toYaml .Values.containerSecurityContext | nindent 12 }} {{- end }} volumeMounts: {{ include "docker-registry.volumeMounts" . | nindent 12 }} {{- if .Values.nodeSelector }} diff --git a/values.yaml b/values.yaml index a5e2d6ec..7fa28b24 100644 --- a/values.yaml +++ b/values.yaml @@ -154,7 +154,6 @@ configData: securityContext: runAsUser: 1000 - fsGroup: 1000 priorityClassName: "" From 57e4a02d5ad4a4b4567365176b6b12a1f51d8d41 Mon Sep 17 00:00:00 2001 From: Tarun Chinmai Sekar Date: Mon, 24 Apr 2023 17:41:22 -0400 Subject: [PATCH 09/14] allow specifying the override for accesskey and secretkey names --- templates/_helpers.tpl | 4 ++-- values.yaml | 2 ++ 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/templates/_helpers.tpl b/templates/_helpers.tpl index d9d7531b..1cd5269a 100644 --- a/templates/_helpers.tpl +++ b/templates/_helpers.tpl @@ -75,12 +75,12 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this valueFrom: secretKeyRef: name: {{ if .Values.secrets.s3.secretRef }}{{ .Values.secrets.s3.secretRef }}{{ else }}{{ template "docker-registry.fullname" . }}-secret{{ end }} - key: s3AccessKey + key: {{ if .Values.secrets.s3.accessKeyName }}{{ .Values.secrets.s3.accessKeyName }}{{ else }} s3AccessKey {{ end }} - name: REGISTRY_STORAGE_S3_SECRETKEY valueFrom: secretKeyRef: name: {{ if .Values.secrets.s3.secretRef }}{{ .Values.secrets.s3.secretRef }}{{ else }}{{ template "docker-registry.fullname" . }}-secret{{ end }} - key: s3SecretKey + key: {{ if .Values.secrets.s3.secretKeyName}}{{ .Values.secrets.s3.secretKeyName}}{{ else }} s3SecretKey {{ end }} {{- end -}} {{- if .Values.s3.regionEndpoint }} diff --git a/values.yaml b/values.yaml index 7fa28b24..5fed0098 100644 --- a/values.yaml +++ b/values.yaml @@ -85,6 +85,8 @@ secrets: # Use a secretRef with keys (accessKey, secretKey) for secrets stored outside the chart # s3: # secretRef: "" +# secretKeyName: "" # defaults to s3SecretKey if not specified +# accessKeyName: "" # defaults to s3AccessKey if not specified # accessKey: "" # secretKey: "" # Secrets for Swift username and password From 97864101fbdead27752c4d19f1f10381c8a6d89e Mon Sep 17 00:00:00 2001 From: Scott Rager Date: Wed, 23 Aug 2023 14:26:08 -0500 Subject: [PATCH 10/14] Adds more s3-related parameters --- templates/_helpers.tpl | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/templates/_helpers.tpl b/templates/_helpers.tpl index 1cd5269a..f1d27895 100644 --- a/templates/_helpers.tpl +++ b/templates/_helpers.tpl @@ -103,6 +103,31 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this value: {{ .Values.s3.secure | quote }} {{- end -}} +{{- if .Values.s3.chunksize }} +- name: REGISTRY_STORAGE_S3_CHUNKSIZE + value: {{ .Values.s3.chunksize | quote }} +{{- end -}} + +{{- if .Values.s3.multipartcopychunksize }} +- name: REGISTRY_STORAGE_S3_MULTIPARTCOPYCHUNKSIZE + value: {{ .Values.s3.multipartcopychunksize | quote }} +{{- end -}} + +{{- if .Values.s3.multipartcopymaxconcurrency }} +- name: REGISTRY_STORAGE_S3_MULTIPARTCOPYMAXCONCURRENCY + value: {{ .Values.s3.multipartcopymaxconcurrency | quote }} +{{- end -}} + +{{- if .Values.s3.multipartcopythresholdsize }} +- name: REGISTRY_STORAGE_S3_MULTIPARTCOPYTHRESHOLDSIZE + value: {{ .Values.s3.multipartcopythresholdsize | quote }} +{{- end -}} + +{{- if .Values.redirect }} +- name: REGISTRY_STORAGE_REDIRECT + value: {{ .Values.redirect | quote }} +{{- end -}} + {{- else if eq .Values.storage "swift" }} - name: REGISTRY_STORAGE_SWIFT_AUTHURL value: {{ required ".Values.swift.authurl is required" .Values.swift.authurl }} From e71e90c5354774f1c2c482523748ccd736492c95 Mon Sep 17 00:00:00 2001 From: Scott Rager Date: Wed, 23 Aug 2023 14:40:37 -0500 Subject: [PATCH 11/14] Fix redirect parameter --- templates/_helpers.tpl | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/templates/_helpers.tpl b/templates/_helpers.tpl index f1d27895..5b58999b 100644 --- a/templates/_helpers.tpl +++ b/templates/_helpers.tpl @@ -123,9 +123,9 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this value: {{ .Values.s3.multipartcopythresholdsize | quote }} {{- end -}} -{{- if .Values.redirect }} -- name: REGISTRY_STORAGE_REDIRECT - value: {{ .Values.redirect | quote }} +{{- if .Values.redirect.disable }} +- name: REGISTRY_STORAGE_REDIRECT_DISABLE + value: {{ .Values.redirect.disable | quote }} {{- end -}} {{- else if eq .Values.storage "swift" }} From bb0ebe3f8528215bfd0d021a62ce1c4c59ad49d0 Mon Sep 17 00:00:00 2001 From: Scott Rager Date: Wed, 23 Aug 2023 14:50:59 -0500 Subject: [PATCH 12/14] Add default values for new parameters --- values.yaml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/values.yaml b/values.yaml index 5fed0098..7a7837cd 100644 --- a/values.yaml +++ b/values.yaml @@ -102,6 +102,13 @@ secrets: # rootdirectory: /object/prefix # encrypt: false # secure: true +# chunksize: 5242880 +# multipartcopychunksize: 33554432 +# multipartcopymaxconcurrency: 100 +# multipartcopythresholdsize: 33554432 + +# redirect: +# disable: false # Options for swift storage type: # swift: From 765f3623daf5721ca6b662410e2eee5c617c643b Mon Sep 17 00:00:00 2001 From: Scott Rager Date: Wed, 23 Aug 2023 14:53:18 -0500 Subject: [PATCH 13/14] Remove redirect parameter --- templates/_helpers.tpl | 5 ----- values.yaml | 3 --- 2 files changed, 8 deletions(-) diff --git a/templates/_helpers.tpl b/templates/_helpers.tpl index 5b58999b..07bd86b7 100644 --- a/templates/_helpers.tpl +++ b/templates/_helpers.tpl @@ -123,11 +123,6 @@ We truncate at 63 chars because some Kubernetes name fields are limited to this value: {{ .Values.s3.multipartcopythresholdsize | quote }} {{- end -}} -{{- if .Values.redirect.disable }} -- name: REGISTRY_STORAGE_REDIRECT_DISABLE - value: {{ .Values.redirect.disable | quote }} -{{- end -}} - {{- else if eq .Values.storage "swift" }} - name: REGISTRY_STORAGE_SWIFT_AUTHURL value: {{ required ".Values.swift.authurl is required" .Values.swift.authurl }} diff --git a/values.yaml b/values.yaml index 7a7837cd..7cee2fec 100644 --- a/values.yaml +++ b/values.yaml @@ -107,9 +107,6 @@ secrets: # multipartcopymaxconcurrency: 100 # multipartcopythresholdsize: 33554432 -# redirect: -# disable: false - # Options for swift storage type: # swift: # authurl: http://swift.example.com/ From 3662b2e6f71368e0b937b10bc5928bcd0da727fc Mon Sep 17 00:00:00 2001 From: Glenn Pratt Date: Tue, 22 Sep 2026 15:11:23 -0700 Subject: [PATCH 14/14] ci: publish Helm chart to GHCR on kpp prerelease tags --- .github/workflows/publish-chart.yaml | 43 ++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 .github/workflows/publish-chart.yaml diff --git a/.github/workflows/publish-chart.yaml b/.github/workflows/publish-chart.yaml new file mode 100644 index 00000000..d002fe20 --- /dev/null +++ b/.github/workflows/publish-chart.yaml @@ -0,0 +1,43 @@ +name: Publish Helm Chart to GHCR + +on: + push: + tags: + - '*-kpp*' + - 'v*-kpp*' + +jobs: + publish: + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Install Helm + uses: azure/setup-helm@v4 + + - name: Package and Push to GHCR + env: + HELM_EXPERIMENTAL_OCI: 1 + run: | + # GHCR requires repository and owner names to be strictly lowercase + OWNER=$(echo "${{ github.repository_owner }}" | tr '[:upper:]' '[:lower:]') + TAG="${{ github.ref_name }}" + + # Strip optional leading 'v' to get valid SemVer (e.g. v2.2.2-kpp-2023-08-24 -> 2.2.2-kpp-2023-08-24) + VERSION="${TAG#v}" + + echo "Packaging chart version: ${VERSION}" + mkdir -p dist + helm package . --version "${VERSION}" --destination dist/ + + # Log in to GHCR + echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u "${{ github.actor }}" --password-stdin + + # Push to GHCR + PKG=$(find dist -name "*.tgz" | head -n 1) + echo "Pushing ${PKG} to oci://ghcr.io/${OWNER}..." + helm push "${PKG}" "oci://ghcr.io/${OWNER}"