mirror of
https://github.com/suitenumerique/docs.git
synced 2026-09-21 17:18:12 +02:00
Yhub has a s3 persistent plugin, since now we didn't use it but we wanto to give the possibility to use it optionnaly. To enable it set the YHUB_S3_PERSISTENCE environment value to true and configure it.
1250 lines
56 KiB
YAML
1250 lines
56 KiB
YAML
# Default values for impress.
|
|
# This is a YAML-formatted file.
|
|
# Declare variables to be passed into your templates.
|
|
|
|
## @section General configuration
|
|
|
|
## @param image.repository Repository to use to pull impress's container image
|
|
## @param image.tag impress's container tag
|
|
## @param image.pullPolicy Container image pull policy
|
|
## @extra image.credentials.username Username for container registry authentication
|
|
## @extra image.credentials.password Password for container registry authentication
|
|
## @extra image.credentials.registry Registry url for which the credentials are specified
|
|
## @extra image.credentials.name Name of the generated secret for imagePullSecrets
|
|
image:
|
|
repository: lasuite/impress-backend
|
|
pullPolicy: IfNotPresent
|
|
tag: "latest"
|
|
|
|
## @param nameOverride Override the chart name
|
|
## @param fullnameOverride Override the full application name
|
|
nameOverride: ""
|
|
fullnameOverride: ""
|
|
|
|
## @skip commonEnvVars
|
|
commonEnvVars: &commonEnvVars
|
|
<<: []
|
|
|
|
## @param ingress.enabled whether to enable the Ingress or not
|
|
## @param ingress.className IngressClass to use for the Ingress
|
|
## @param ingress.host Host for the Ingress
|
|
## @param ingress.path Path to use for the Ingress
|
|
ingress:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
path: /
|
|
## @param ingress.hosts Additional host to configure for the Ingress
|
|
hosts: []
|
|
# - chart-example.local
|
|
## @param ingress.tls.enabled Whether to enable TLS for the Ingress
|
|
## @param ingress.tls.secretName Secret name for TLS config
|
|
## @skip ingress.tls.additional
|
|
## @extra ingress.tls.additional[].secretName Secret name for additional TLS config
|
|
## @extra ingress.tls.additional[].hosts[] Hosts for additional TLS config
|
|
tls:
|
|
enabled: true
|
|
secretName: null
|
|
additional: []
|
|
|
|
## @param ingress.customBackends Add custom backends to ingress
|
|
customBackends: []
|
|
|
|
## @param ingressCollaborationWS.enabled whether to enable the Ingress or not
|
|
## @param ingressCollaborationWS.className IngressClass to use for the Ingress
|
|
## @param ingressCollaborationWS.host Host for the Ingress
|
|
## @param ingressCollaborationWS.path Path to use for the Ingress
|
|
ingressCollaborationWS:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
path: /collaboration/ws/
|
|
## @param ingressCollaborationWS.hosts Additional host to configure for the Ingress
|
|
hosts: []
|
|
# - chart-example.local
|
|
## @param ingressCollaborationWS.tls.enabled Whether to enable TLS for the Ingress
|
|
## @param ingressCollaborationWS.tls.secretName Secret name for TLS config
|
|
## @skip ingressCollaborationWS.tls.additional
|
|
## @extra ingressCollaborationWS.tls.additional[].secretName Secret name for additional TLS config
|
|
## @extra ingressCollaborationWS.tls.additional[].hosts[] Hosts for additional TLS config
|
|
tls:
|
|
enabled: true
|
|
secretName: null
|
|
additional: []
|
|
|
|
## @param ingressCollaborationWS.customBackends Add custom backends to ingress
|
|
customBackends: []
|
|
|
|
## @param ingressCollaborationWS.annotations.nginx.ingress.kubernetes.io/enable-websocket
|
|
## @param ingressCollaborationWS.annotations.nginx.ingress.kubernetes.io/proxy-read-timeout
|
|
## @param ingressCollaborationWS.annotations.nginx.ingress.kubernetes.io/proxy-send-timeout
|
|
##
|
|
## No upstream-hash-by: yhub passes updates between its replicas through
|
|
## redis, so two clients editing the same document may land on different
|
|
## pods — where the y-provider it replaces needed a room to stay on one.
|
|
annotations:
|
|
nginx.ingress.kubernetes.io/enable-websocket: "true"
|
|
nginx.ingress.kubernetes.io/proxy-read-timeout: "86400"
|
|
nginx.ingress.kubernetes.io/proxy-send-timeout: "86400"
|
|
|
|
## @param ingressRedirects.enabled whether to enable the Ingress Redirects or not
|
|
## @param ingressRedirects.className IngressClass to use for the Ingress Redirects
|
|
## @param ingressRedirects.host Host for the Ingress Redirects
|
|
ingressRedirects:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
## @param ingressRedirects.tls.enabled Whether to enable TLS for the Ingress Redirects
|
|
## @param ingressRedirects.tls.secretName Secret name for TLS config
|
|
## @skip ingressRedirects.tls.additional
|
|
## @extra ingressRedirects.tls.additional[].secretName Secret name for additional TLS config
|
|
## @extra ingressRedirects.tls.additional[].hosts[] Hosts for additional TLS config
|
|
tls:
|
|
enabled: true
|
|
secretName: null
|
|
additional: []
|
|
## @param ingressRedirects.rules Rules for the Ingress Redirects
|
|
rules: []
|
|
|
|
## @param ingressCollaborationApi.enabled whether to enable the Ingress or not
|
|
## @param ingressCollaborationApi.className IngressClass to use for the Ingress
|
|
## @param ingressCollaborationApi.host Host for the Ingress
|
|
## @param ingressCollaborationApi.path Path to use for the Ingress
|
|
ingressCollaborationApi:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
## Only used when `paths` below is empty
|
|
path: /collaboration/api/
|
|
## @param ingressCollaborationApi.paths Paths to route to the collaboration server, one rule each
|
|
##
|
|
## The routes yhub serves to browsers, guarded by the same document
|
|
## authorization as the websocket. Everything it serves that is not listed
|
|
## here stays in-cluster — `create-ydoc`, `reset-connections`, `migrate`,
|
|
## `restore-ydoc` and `reset-ydoc` are called by the backend only, and
|
|
## publishing them would put document deletion and the legacy migration one
|
|
## request away from the internet.
|
|
##
|
|
## `jwks` is public on purpose: it carries the public halves of the keys
|
|
## yhub signs with, and nothing else.
|
|
paths:
|
|
- /collaboration/ydoc/
|
|
- /collaboration/jwks/
|
|
## @param ingressCollaborationApi.hosts Additional host to configure for the Ingress
|
|
hosts: []
|
|
# - chart-example.local
|
|
## @param ingressCollaborationApi.tls.enabled Whether to enable TLS for the Ingress
|
|
## @param ingressCollaborationApi.tls.secretName Secret name for TLS config
|
|
## @skip ingressCollaborationApi.tls.additional
|
|
## @extra ingressCollaborationApi.tls.additional[].secretName Secret name for additional TLS config
|
|
## @extra ingressCollaborationApi.tls.additional[].hosts[] Hosts for additional TLS config
|
|
tls:
|
|
enabled: true
|
|
secretName: null
|
|
additional: []
|
|
|
|
## @param ingressCollaborationApi.customBackends Add custom backends to ingress
|
|
customBackends: []
|
|
|
|
## @skip ingressCollaborationApi.annotations
|
|
## Same as ingressCollaborationWS: no upstream-hash-by, any yhub replica
|
|
## answers for any document.
|
|
annotations: {}
|
|
|
|
## @param ingressAdmin.enabled whether to enable the Ingress or not
|
|
## @param ingressAdmin.className IngressClass to use for the Ingress
|
|
## @param ingressAdmin.host Host for the Ingress
|
|
## @param ingressAdmin.path Path to use for the Ingress
|
|
ingressAdmin:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
path: /admin
|
|
## @param ingressAdmin.hosts Additional host to configure for the Ingress
|
|
hosts: []
|
|
# - chart-example.local
|
|
## @param ingressAdmin.tls.enabled Whether to enable TLS for the Ingress
|
|
## @param ingressAdmin.tls.secretName Secret name for TLS config
|
|
## @skip ingressAdmin.tls.additional
|
|
## @extra ingressAdmin.tls.additional[].secretName Secret name for additional TLS config
|
|
## @extra ingressAdmin.tls.additional[].hosts[] Hosts for additional TLS config
|
|
tls:
|
|
enabled: true
|
|
secretName: null
|
|
additional: []
|
|
|
|
## @param ingressMedia.enabled whether to enable the Ingress or not
|
|
## @param ingressMedia.className IngressClass to use for the Ingress
|
|
## @param ingressMedia.host Host for the Ingress
|
|
## @param ingressMedia.path Path to use for the Ingress
|
|
ingressMedia:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
path: /media/(.*)
|
|
## @param ingressMedia.hosts Additional host to configure for the Ingress
|
|
hosts: []
|
|
# - chart-example.local
|
|
## @param ingressMedia.tls.enabled Whether to enable TLS for the Ingress
|
|
## @param ingressMedia.tls.secretName Secret name for TLS config
|
|
## @skip ingressMedia.tls.additional
|
|
## @extra ingressMedia.tls.additional[].secretName Secret name for additional TLS config
|
|
## @extra ingressMedia.tls.additional[].hosts[] Hosts for additional TLS config
|
|
tls:
|
|
enabled: true
|
|
secretName: null
|
|
additional: []
|
|
|
|
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/auth-url
|
|
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/auth-response-headers
|
|
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/upstream-vhost
|
|
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/configuration-snippet
|
|
annotations:
|
|
nginx.ingress.kubernetes.io/auth-url: https://impress.example.com/api/v1.0/documents/media-auth/
|
|
nginx.ingress.kubernetes.io/auth-response-headers: "Authorization, X-Amz-Date, X-Amz-Content-SHA256"
|
|
nginx.ingress.kubernetes.io/upstream-vhost: minio.impress.svc.cluster.local:9000
|
|
nginx.ingress.kubernetes.io/configuration-snippet: |
|
|
add_header Content-Security-Policy "default-src 'none'" always;
|
|
|
|
## @param serviceMedia.host Hostname of the media storage backend (S3/MinIO) used by the media ingress
|
|
## @param serviceMedia.port Port of the media storage backend
|
|
## @param serviceMedia.annotations Annotations to add to the media ExternalName Service
|
|
serviceMedia:
|
|
host: minio.impress.svc.cluster.local
|
|
port: 9000
|
|
annotations: {}
|
|
|
|
## @section backend
|
|
|
|
backend:
|
|
## @param backend.command Override the backend container command
|
|
command: []
|
|
|
|
## @param backend.args Override the backend container args
|
|
args: []
|
|
|
|
## @param backend.replicas Amount of backend replicas
|
|
replicas: 3
|
|
|
|
## @param backend.shareProcessNamespace Enable share process namespace between containers
|
|
shareProcessNamespace: false
|
|
|
|
## @param backend.sidecars Add sidecars containers to backend deployment
|
|
sidecars: []
|
|
|
|
## @param backend.migrateJobAnnotations Annotations for the migrate job
|
|
migrateJobAnnotations: {}
|
|
|
|
## @param backend.jobs.ttlSecondsAfterFinished Period to wait before remove jobs
|
|
## @param backend.jobs.backoffLimit Numbers of jobs retries
|
|
jobs:
|
|
ttlSecondsAfterFinished: 30
|
|
backoffLimit: 2
|
|
|
|
## @param backend.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the backend container
|
|
## @param backend.securityContext.capabilities.drop List of capabilities to drop for the backend container
|
|
## @param backend.securityContext.runAsNonRoot Whether to run the backend container as a non-root user
|
|
## @param backend.securityContext.seccompProfile.type Seccomp profile type for the backend container
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- "ALL"
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
## @param backend.envVars Configure backend container environment variables
|
|
## @extra backend.envVars.BY_VALUE Example environment variable by setting value directly
|
|
## @extra backend.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra backend.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra backend.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
|
|
## @extra backend.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
|
|
## @skip backend.envVars
|
|
envVars:
|
|
<<: *commonEnvVars
|
|
|
|
## @skip backend.envFrom List of environment variables taken from Secrets or configMaps, common to backend and celery worker
|
|
envFrom: []
|
|
# envFrom:
|
|
# - secret:
|
|
# name: super-secret-user-credentials
|
|
# - configMapRef:
|
|
# name: my-environment-variables
|
|
|
|
## @extra backend.django.envVars Backend web deployment specific environment variables (not shared with celery worker)
|
|
## @skip backend.django.envVars
|
|
## @skip backend.django.envFrom List of environment variables taken from Secrets or configMaps, specific to the backend web deployment
|
|
django:
|
|
envVars: {}
|
|
envFrom: []
|
|
|
|
## @param backend.podAnnotations Annotations to add to the backend Pod
|
|
podAnnotations: {}
|
|
|
|
## @param backend.dpAnnotations Annotations to add to the backend Deployment
|
|
dpAnnotations: {}
|
|
|
|
## @param backend.service.type backend Service type
|
|
## @param backend.service.port backend Service listening port
|
|
## @param backend.service.targetPort backend container listening port
|
|
## @param backend.service.annotations Annotations to add to the backend Service
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
targetPort: 8000
|
|
annotations: {}
|
|
|
|
## @param backend.migrate.command backend migrate command
|
|
## @param backend.migrate.restartPolicy backend migrate job restart policy
|
|
migrate:
|
|
command:
|
|
- /bin/sh
|
|
- "-c"
|
|
- |
|
|
attempt=0
|
|
until output=$(python manage.py check --database default 2>&1)
|
|
do
|
|
attempt=$((attempt + 1))
|
|
echo "Database check failed (attempt $attempt), retrying in 2s:"
|
|
echo "$output"
|
|
sleep 2
|
|
done
|
|
|
|
echo "Database is ready"
|
|
|
|
python manage.py migrate --no-input
|
|
restartPolicy: Never
|
|
|
|
## @param backend.createsuperuser.command backend migrate command
|
|
## @param backend.createsuperuser.restartPolicy backend migrate job restart policy
|
|
createsuperuser:
|
|
command:
|
|
- "/bin/sh"
|
|
- "-c"
|
|
- |
|
|
attempt=0
|
|
until output=$(python manage.py check --database default 2>&1)
|
|
do
|
|
attempt=$((attempt + 1))
|
|
echo "Database check failed (attempt $attempt), retrying in 2s:"
|
|
echo "$output"
|
|
sleep 2
|
|
done
|
|
|
|
echo "Database is ready"
|
|
|
|
python manage.py createsuperuser --email $DJANGO_SUPERUSER_EMAIL --password $DJANGO_SUPERUSER_PASSWORD
|
|
restartPolicy: Never
|
|
|
|
## @extra backend.job job dedicated to run a random management command, for example after a deployment
|
|
## @param backend.job.name The name to use to describe this job
|
|
## @param backend.job.command The management command to execute
|
|
## @param backend.job.restartPolicy The restart policy for the job.
|
|
## @extra backend.job.annotations Annotations to add to the job [default: argocd.argoproj.io/hook: PostSync]
|
|
## @skip backend.job.annotations.argocd.argoproj.io/hook
|
|
job:
|
|
name: ""
|
|
command: []
|
|
restartPolicy: Never
|
|
annotations:
|
|
argocd.argoproj.io/hook: PostSync
|
|
|
|
# List of cronjob to add
|
|
# cronjobs:
|
|
# - name: reset-database
|
|
# schedule: "0 */2 * * *"
|
|
# command:
|
|
# - "/bin/sh"
|
|
# - "-c"
|
|
# - python manage.py flush --no-input
|
|
## @param backend.cronjobs Cronjob name, schedule, command
|
|
cronjobs: []
|
|
|
|
## @param backend.probes.liveness.path [nullable] Configure path for backend HTTP liveness probe
|
|
## @param backend.probes.liveness.targetPort [nullable] Configure port for backend HTTP liveness probe
|
|
## @param backend.probes.liveness.initialDelaySeconds [nullable] Configure initial delay for backend liveness probe
|
|
## @param backend.probes.liveness.timeoutSeconds [nullable] Configure timeout for backend liveness probe
|
|
## @extra backend.probes.startup.path [nullable] Configure path for backend HTTP startup probe
|
|
## @extra backend.probes.startup.targetPort [nullable] Configure port for backend HTTP startup probe
|
|
## @extra backend.probes.startup.initialDelaySeconds [nullable] Configure initial delay for backend startup probe
|
|
## @extra backend.probes.startup.timeoutSeconds [nullable] Configure timeout for backend startup probe
|
|
## @param backend.probes.readiness.path [nullable] Configure path for backend HTTP readiness probe
|
|
## @param backend.probes.readiness.targetPort [nullable] Configure port for backend HTTP readiness probe
|
|
## @param backend.probes.readiness.initialDelaySeconds [nullable] Configure initial delay for backend readiness probe
|
|
## @param backend.probes.readiness.timeoutSeconds [nullable] Configure timeout for backend readiness probe
|
|
probes:
|
|
liveness:
|
|
path: /__lbheartbeat__
|
|
initialDelaySeconds: 10
|
|
readiness:
|
|
path: /__heartbeat__
|
|
initialDelaySeconds: 10
|
|
|
|
## @param backend.resources Resource requirements for the backend container
|
|
resources: {}
|
|
|
|
## @param backend.nodeSelector Node selector for the backend Pod
|
|
nodeSelector: {}
|
|
|
|
## @param backend.tolerations Tolerations for the backend Pod
|
|
tolerations: []
|
|
|
|
## @param backend.affinity Affinity for the backend Pod
|
|
affinity: {}
|
|
|
|
## @param backend.persistence Additional volumes to create and mount on the backend. Used for debugging purposes
|
|
## @extra backend.persistence.volume-name.size Size of the additional volume
|
|
## @extra backend.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
|
|
## @extra backend.persistence.volume-name.mountPath Path where the volume should be mounted to
|
|
persistence: {}
|
|
|
|
## @param backend.extraVolumeMounts Additional volumes to mount on the backend.
|
|
extraVolumeMounts: []
|
|
|
|
## @param backend.extraVolumes Additional volumes to mount on the backend.
|
|
extraVolumes: []
|
|
|
|
## @param backend.pdb.enabled Enable pdb on backend
|
|
pdb:
|
|
enabled: true
|
|
|
|
## @param backend.serviceAccountName Optional service account name to use for backend pods
|
|
serviceAccountName: null
|
|
|
|
## @param backend.themeCustomization.enabled Enable theme customization
|
|
## @param backend.themeCustomization.file_content Content of the theme customization file. Must be a json object.
|
|
## @param backend.themeCustomization.mount_path Path where the customization file will be mounted in the backend deployment.
|
|
themeCustomization:
|
|
enabled: false
|
|
file_content: ""
|
|
mount_path: /app/impress/configuration/theme
|
|
|
|
## @param backend.celery.replicas Amount of celery replicas
|
|
## @param backend.celery.command Override the celery container command
|
|
## @param backend.celery.args Override the celery container args
|
|
## @param backend.celery.resources Resource requirements for the celery container
|
|
## @param backend.celery.probes.liveness.exec.command Override the celery container liveness probe command
|
|
## @param backend.celery.probes.liveness.initialDelaySeconds Initial delay for the celery container liveness probe
|
|
## @param backend.celery.probes.liveness.timeoutSeconds Timeout for the celery container liveness probe
|
|
## @param backend.celery.probes.readiness.exec.command Override the celery container readiness probe command
|
|
## @param backend.celery.probes.readiness.initialDelaySeconds Initial delay for the celery container readiness probe
|
|
## @param backend.celery.probes.readiness.timeoutSeconds Timeout for the celery container readiness probe
|
|
## @extra backend.celery.envVars Celery worker specific environment variables (not shared with the backend web deployment)
|
|
## @skip backend.celery.envVars
|
|
## @skip backend.celery.envFrom List of environment variables taken from Secrets or configMaps, specific to celery worker
|
|
celery:
|
|
replicas: 1
|
|
command: []
|
|
args:
|
|
[
|
|
"celery",
|
|
"-A",
|
|
"impress.celery_app",
|
|
"worker",
|
|
"-l",
|
|
"INFO",
|
|
"-n",
|
|
"impress@%h",
|
|
]
|
|
envVars: {}
|
|
envFrom: []
|
|
resources: {}
|
|
probes:
|
|
liveness:
|
|
exec:
|
|
command:
|
|
[
|
|
"/bin/sh",
|
|
"-c",
|
|
"celery -A impress.celery_app inspect ping -d impress@$HOSTNAME",
|
|
]
|
|
initialDelaySeconds: 60
|
|
timeoutSeconds: 5
|
|
readiness:
|
|
exec:
|
|
command:
|
|
[
|
|
"/bin/sh",
|
|
"-c",
|
|
"celery -A impress.celery_app inspect ping -d impress@$HOSTNAME",
|
|
]
|
|
initialDelaySeconds: 15
|
|
timeoutSeconds: 5
|
|
|
|
## @section frontend
|
|
|
|
frontend:
|
|
## @param frontend.image.repository Repository to use to pull impress's frontend container image
|
|
## @param frontend.image.tag impress's frontend container tag
|
|
## @param frontend.image.pullPolicy frontend container image pull policy
|
|
image:
|
|
repository: lasuite/impress-frontend
|
|
pullPolicy: IfNotPresent
|
|
tag: "latest"
|
|
|
|
## @param frontend.command Override the frontend container command
|
|
command: []
|
|
|
|
## @param frontend.args Override the frontend container args
|
|
args: []
|
|
|
|
## @param frontend.replicas Amount of frontend replicas
|
|
replicas: 3
|
|
|
|
## @param frontend.shareProcessNamespace Enable share process namespace between containers
|
|
shareProcessNamespace: false
|
|
|
|
## @param frontend.sidecars Add sidecars containers to frontend deployment
|
|
sidecars: []
|
|
|
|
## @param frontend.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the frontend container
|
|
## @param frontend.securityContext.capabilities.drop List of capabilities to drop for the frontend container
|
|
## @param frontend.securityContext.runAsNonRoot Whether to run the frontend container as a non-root user
|
|
## @param frontend.securityContext.seccompProfile.type Seccomp profile type for the frontend container
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- "ALL"
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
## @param frontend.envVars Configure frontend container environment variables
|
|
## @extra frontend.envVars.BY_VALUE Example environment variable by setting value directly
|
|
## @extra frontend.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra frontend.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra frontend.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
|
|
## @extra frontend.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
|
|
## @skip frontend.envVars
|
|
envVars:
|
|
<<: *commonEnvVars
|
|
|
|
## @skip frontend.envFrom List of environment variables taken from Secrets or configMaps
|
|
envFrom: []
|
|
# envFrom:
|
|
# - secret:
|
|
# name: super-secret-user-credentials
|
|
# - configMapRef:
|
|
# name: my-environment-variables
|
|
|
|
## @param frontend.podAnnotations Annotations to add to the frontend Pod
|
|
podAnnotations: {}
|
|
|
|
## @param frontend.dpAnnotations Annotations to add to the frontend Deployment
|
|
dpAnnotations: {}
|
|
|
|
## @param frontend.service.type frontend Service type
|
|
## @param frontend.service.port frontend Service listening port
|
|
## @param frontend.service.targetPort frontend container listening port
|
|
## @param frontend.service.annotations Annotations to add to the frontend Service
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
targetPort: 8080
|
|
annotations: {}
|
|
|
|
## @param frontend.probes Configure probe for frontend
|
|
## @extra frontend.probes.liveness.path Configure path for frontend HTTP liveness probe
|
|
## @extra frontend.probes.liveness.targetPort Configure port for frontend HTTP liveness probe
|
|
## @extra frontend.probes.liveness.initialDelaySeconds Configure initial delay for frontend liveness probe
|
|
## @extra frontend.probes.liveness.initialDelaySeconds Configure timeout for frontend liveness probe
|
|
## @extra frontend.probes.startup.path Configure path for frontend HTTP startup probe
|
|
## @extra frontend.probes.startup.targetPort Configure port for frontend HTTP startup probe
|
|
## @extra frontend.probes.startup.initialDelaySeconds Configure initial delay for frontend startup probe
|
|
## @extra frontend.probes.startup.initialDelaySeconds Configure timeout for frontend startup probe
|
|
## @extra frontend.probes.readiness.path Configure path for frontend HTTP readiness probe
|
|
## @extra frontend.probes.readiness.targetPort Configure port for frontend HTTP readiness probe
|
|
## @extra frontend.probes.readiness.initialDelaySeconds Configure initial delay for frontend readiness probe
|
|
## @extra frontend.probes.readiness.initialDelaySeconds Configure timeout for frontend readiness probe
|
|
probes: {}
|
|
|
|
## @param frontend.resources Resource requirements for the frontend container
|
|
resources: {}
|
|
|
|
## @param frontend.nodeSelector Node selector for the frontend Pod
|
|
nodeSelector: {}
|
|
|
|
## @param frontend.tolerations Tolerations for the frontend Pod
|
|
tolerations: []
|
|
|
|
## @param frontend.affinity Affinity for the frontend Pod
|
|
affinity: {}
|
|
|
|
## @param frontend.persistence Additional volumes to create and mount on the frontend. Used for debugging purposes
|
|
## @extra frontend.persistence.volume-name.size Size of the additional volume
|
|
## @extra frontend.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
|
|
## @extra frontend.persistence.volume-name.mountPath Path where the volume should be mounted to
|
|
persistence: {}
|
|
|
|
## @param frontend.extraVolumeMounts Additional volumes to mount on the frontend.
|
|
extraVolumeMounts: []
|
|
|
|
## @param frontend.extraVolumes Additional volumes to mount on the frontend.
|
|
extraVolumes: []
|
|
|
|
## @param frontend.pdb.enabled Enable pdb on frontend
|
|
pdb:
|
|
enabled: true
|
|
|
|
## @param frontend.serviceAccountName Optional service account name to use for frontend pods
|
|
serviceAccountName: null
|
|
|
|
## @section posthog
|
|
|
|
posthog:
|
|
## @param posthog.ingress.enabled Enable or disable the ingress resource creation
|
|
## @param posthog.ingress.className Kubernetes ingress class name to use (e.g., nginx, traefik)
|
|
## @param posthog.ingress.host Primary hostname for the ingress resource
|
|
## @param posthog.ingress.path URL path prefix for the ingress routes (e.g., /)
|
|
## @param posthog.ingress.hosts Additional hostnames array to be included in the ingress
|
|
## @param posthog.ingress.tls.enabled Enable or disable TLS/HTTPS for the ingress
|
|
## @param posthog.ingress.tls.additional Additional TLS configurations for extra hosts/certificates
|
|
## @param posthog.ingress.customBackends Custom backend service configurations for the ingress
|
|
## @param posthog.ingress.annotations Additional Kubernetes annotations to apply to the ingress
|
|
ingress:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
path: /
|
|
hosts: []
|
|
tls:
|
|
enabled: true
|
|
additional: []
|
|
|
|
customBackends: []
|
|
annotations: {}
|
|
|
|
## @param posthog.ingressAssets.enabled Enable or disable the ingress resource creation
|
|
## @param posthog.ingressAssets.className Kubernetes ingress class name to use (e.g., nginx, traefik)
|
|
## @param posthog.ingressAssets.host Primary hostname for the ingress resource
|
|
## @param posthog.ingressAssets.paths URL paths prefix for the ingress routes (e.g., /static)
|
|
## @param posthog.ingressAssets.hosts Additional hostnames array to be included in the ingress
|
|
## @param posthog.ingressAssets.tls.enabled Enable or disable TLS/HTTPS for the ingress
|
|
## @param posthog.ingressAssets.tls.additional Additional TLS configurations for extra hosts/certificates
|
|
## @param posthog.ingressAssets.customBackends Custom backend service configurations for the ingress
|
|
## @param posthog.ingressAssets.annotations Additional Kubernetes annotations to apply to the ingress
|
|
ingressAssets:
|
|
enabled: false
|
|
className: null
|
|
host: impress.example.com
|
|
paths:
|
|
- /static
|
|
- /array
|
|
hosts: []
|
|
tls:
|
|
enabled: true
|
|
additional: []
|
|
|
|
customBackends: []
|
|
annotations: {}
|
|
|
|
## @param posthog.service.type Service type (e.g. ExternalName, ClusterIP, LoadBalancer)
|
|
## @param posthog.service.externalName External service hostname when type is ExternalName
|
|
## @param posthog.service.port Port number for the service
|
|
## @param posthog.service.annotations Additional annotations to apply to the service
|
|
service:
|
|
type: ExternalName
|
|
externalName: eu.i.posthog.com
|
|
port: 443
|
|
annotations: {}
|
|
|
|
## @param posthog.assetsService.type Service type (e.g. ExternalName, ClusterIP, LoadBalancer)
|
|
## @param posthog.assetsService.externalName External service hostname when type is ExternalName
|
|
## @param posthog.assetsService.port Port number for the service
|
|
## @param posthog.assetsService.annotations Additional annotations to apply to the service
|
|
assetsService:
|
|
type: ExternalName
|
|
externalName: eu-assets.i.posthog.com
|
|
port: 443
|
|
annotations: {}
|
|
|
|
## @section yProvider
|
|
##
|
|
## The conversion service, and nothing else since the collaboration moved to
|
|
## yhub: this deployment *is* the converter the backend calls on
|
|
## `Y_PROVIDER_API_BASE_URL`, so there is no separate converter release to
|
|
## enable anymore.
|
|
yProvider:
|
|
## @param yProvider.image.repository Repository to use to pull impress's yProvider container image
|
|
## @param yProvider.image.tag impress's yProvider container tag
|
|
## @param yProvider.image.pullPolicy yProvider container image pull policy
|
|
image:
|
|
repository: lasuite/impress-y-provider
|
|
pullPolicy: IfNotPresent
|
|
tag: "latest"
|
|
|
|
## @param yProvider.command Override the yProvider container command
|
|
command: []
|
|
|
|
## @param yProvider.args Override the yProvider container args
|
|
args: []
|
|
|
|
## @param yProvider.replicas Amount of yProvider replicas
|
|
replicas: 3
|
|
|
|
## @param yProvider.shareProcessNamespace Enable share process nameyProvider between containers
|
|
shareProcessNamespace: false
|
|
|
|
## @param yProvider.sidecars Add sidecars containers to yProvider deployment
|
|
sidecars: []
|
|
|
|
## @param yProvider.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the yProvider container
|
|
## @param yProvider.securityContext.capabilities.drop List of capabilities to drop for the yProvider container
|
|
## @param yProvider.securityContext.runAsNonRoot Whether to run the yProvider container as a non-root user
|
|
## @param yProvider.securityContext.seccompProfile.type Seccomp profile type for the yProvider container
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- "ALL"
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
## @param yProvider.envVars Configure yProvider container environment variables
|
|
## @extra yProvider.envVars.BY_VALUE Example environment variable by setting value directly
|
|
## @extra yProvider.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra yProvider.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra yProvider.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
|
|
## @extra yProvider.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
|
|
## @skip yProvider.envVars
|
|
envVars:
|
|
<<: *commonEnvVars
|
|
|
|
## @skip yProvider.envFrom List of environment variables taken from Secrets or configMaps
|
|
envFrom: []
|
|
# envFrom:
|
|
# - secret:
|
|
# name: super-secret-user-credentials
|
|
# - configMapRef:
|
|
# name: my-environment-variables
|
|
|
|
## @param yProvider.podAnnotations Annotations to add to the yProvider Pod
|
|
podAnnotations: {}
|
|
|
|
## @param yProvider.dpAnnotations Annotations to add to the yProvider Deployment
|
|
dpAnnotations: {}
|
|
|
|
## @param yProvider.service.type yProvider Service type
|
|
## @param yProvider.service.port yProvider Service listening port
|
|
## @param yProvider.service.targetPort yProvider container listening port
|
|
## @param yProvider.service.annotations Annotations to add to the yProvider Service
|
|
service:
|
|
type: ClusterIP
|
|
port: 443
|
|
targetPort: 4444
|
|
annotations: {}
|
|
|
|
## @param yProvider.probes.liveness.path Configure path for yProvider HTTP liveness probe
|
|
## @param yProvider.probes.liveness.initialDelaySeconds Configure initial delay for yProvider liveness probe
|
|
## @extra yProvider.probes.liveness.targetPort Configure port for yProvider HTTP liveness probe
|
|
## @extra yProvider.probes.liveness.timeoutSeconds Configure timeout for yProvider liveness probe
|
|
## @extra yProvider.probes.startup.path Configure path for yProvider HTTP startup probe
|
|
## @extra yProvider.probes.startup.targetPort Configure port for yProvider HTTP startup probe
|
|
## @extra yProvider.probes.startup.initialDelaySeconds Configure initial delay for yProvider startup probe
|
|
## @extra yProvider.probes.startup.timeoutSeconds Configure timeout for yProvider startup probe
|
|
## @extra yProvider.probes.readiness.path Configure path for yProvider HTTP readiness probe
|
|
## @extra yProvider.probes.readiness.targetPort Configure port for yProvider HTTP readiness probe
|
|
## @extra yProvider.probes.readiness.initialDelaySeconds Configure initial delay for yProvider readiness probe
|
|
## @extra yProvider.probes.readiness.timeoutSeconds Configure timeout for yProvider readiness probe
|
|
probes:
|
|
liveness:
|
|
path: /ping
|
|
initialDelaySeconds: 10
|
|
|
|
## @param yProvider.resources Resource requirements for the yProvider container
|
|
resources: {}
|
|
|
|
## @param yProvider.nodeSelector Node selector for the yProvider Pod
|
|
nodeSelector: {}
|
|
|
|
## @param yProvider.tolerations Tolerations for the yProvider Pod
|
|
tolerations: []
|
|
|
|
## @param yProvider.affinity Affinity for the yProvider Pod
|
|
affinity: {}
|
|
|
|
## @param yProvider.persistence Additional volumes to create and mount on the yProvider. Used for debugging purposes
|
|
## @extra yProvider.persistence.volume-name.size Size of the additional volume
|
|
## @extra yProvider.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
|
|
## @extra yProvider.persistence.volume-name.mountPath Path where the volume should be mounted to
|
|
persistence: {}
|
|
|
|
## @param yProvider.extraVolumeMounts Additional volumes to mount on the yProvider.
|
|
extraVolumeMounts: []
|
|
|
|
## @param yProvider.extraVolumes Additional volumes to mount on the yProvider.
|
|
extraVolumes: []
|
|
|
|
## @param yProvider.pdb.enabled Enable pdb on yProvider
|
|
pdb:
|
|
enabled: true
|
|
|
|
## @param yProvider.serviceAccountName Optional service account name to use for yProvider pods
|
|
serviceAccountName: null
|
|
|
|
## @section JWT signing keys
|
|
##
|
|
## The services do not share a secret: each signs the calls it makes to the
|
|
## others with an RSA key of its own and publishes the public half on its JWKS
|
|
## endpoint, where the others read it. Enabling this generates those keys on
|
|
## the cluster — a job creates them once in a secret every service mounts
|
|
## read-only, and leaves them alone on the next run — and points the backend
|
|
## and the collaboration server at them. No key is ever templated into a
|
|
## manifest or written in a values file, and only that job may create the
|
|
## secret: nothing in the release can read it back through the api.
|
|
##
|
|
## Leave it disabled to keep providing the keys yourself, through
|
|
## `backend.envVars.JWT_PRIVATE_KEY_FILE` and
|
|
## `yhub.envVars.YHUB_JWT_PRIVATE_KEY_FILE` and volumes of your own — both are
|
|
## left untouched when they are set by hand, enabled or not.
|
|
jwtKeys:
|
|
## @param jwtKeys.enabled Generate the JWT signing keys of the services on the cluster
|
|
enabled: false
|
|
|
|
## @param jwtKeys.existingSecret Secret already holding the keys, generated in a secret of the chart's own when empty
|
|
##
|
|
## It has to hold the two filenames below. Naming one skips the job and the
|
|
## rights it needs, the services only mount what is there.
|
|
existingSecret: null
|
|
|
|
## @param jwtKeys.mountPath Path the keys are mounted at, in every service reading them
|
|
mountPath: /data/jwt
|
|
|
|
## @param jwtKeys.backendKeyFilename Name of the key signing the tokens the backend issues
|
|
backendKeyFilename: private.pem
|
|
|
|
## @param jwtKeys.yhubKeyFilename Name of the key signing the calls the collaboration server makes to the backend
|
|
yhubKeyFilename: yhub-private.pem
|
|
|
|
## @param jwtKeys.keySize Size, in bits, of the generated RSA keys
|
|
keySize: 2048
|
|
|
|
## @param jwtKeys.rbac.create Create the service account and the role the job needs to create the secret
|
|
##
|
|
## Turning it off means providing `jwtKeys.job.serviceAccountName` with an
|
|
## account allowed to `create` secrets and to `get` the one named above.
|
|
rbac:
|
|
create: true
|
|
|
|
## @param jwtKeys.image.repository Repository to use to pull the image generating the keys
|
|
## @param jwtKeys.image.tag Tag of the image generating the keys
|
|
## @param jwtKeys.image.pullPolicy Pull policy of the image generating the keys
|
|
##
|
|
## openssl and a shell, nothing else. Its entrypoint is openssl itself, which
|
|
## the job replaces by the script generating both keys.
|
|
image:
|
|
repository: alpine/openssl
|
|
pullPolicy: IfNotPresent
|
|
tag: "3.5.7"
|
|
|
|
## @param jwtKeys.kubectlImage.repository Repository to use to pull the image handing the keys to the secret
|
|
## @param jwtKeys.kubectlImage.tag Tag of the image handing the keys to the secret
|
|
## @param jwtKeys.kubectlImage.pullPolicy Pull policy of the image handing the keys to the secret
|
|
##
|
|
## A second image because the openssl one carries no kubectl, and reaching
|
|
## the api with what it does carry (busybox wget, which cannot be told about
|
|
## the cluster ca) would mean sending the token over an unverified
|
|
## connection.
|
|
kubectlImage:
|
|
repository: dtzar/helm-kubectl
|
|
pullPolicy: IfNotPresent
|
|
tag: "3.16.2"
|
|
|
|
## @param jwtKeys.job.podSecurityContext Pod security context of the generating job
|
|
## @param jwtKeys.job.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the job containers
|
|
## @param jwtKeys.job.securityContext.capabilities.drop List of capabilities to drop for the job containers
|
|
## @param jwtKeys.job.securityContext.runAsNonRoot Whether to run the job containers as a non-root user
|
|
## @param jwtKeys.job.securityContext.runAsUser User the job containers run as, their images declaring none
|
|
## @param jwtKeys.job.securityContext.runAsGroup Group the job containers run as
|
|
## @param jwtKeys.job.securityContext.seccompProfile.type Seccomp profile type for the job containers
|
|
## @param jwtKeys.job.restartPolicy Restart policy of the generating job
|
|
## @param jwtKeys.job.backoffLimit Numbers of generating job retries
|
|
## @param jwtKeys.job.ttlSecondsAfterFinished Period to wait before removing the generating job
|
|
## @param jwtKeys.job.generateCommand Override the command generating the keys
|
|
## @param jwtKeys.job.publishCommand Override the command creating the secret from the generated keys
|
|
## @param jwtKeys.job.annotations Annotations to add to the generating job
|
|
## @param jwtKeys.job.podAnnotations Annotations to add to the generating job Pod
|
|
## @param jwtKeys.job.resources Resource requirements for the job containers
|
|
## @param jwtKeys.job.nodeSelector Node selector for the generating job Pod
|
|
## @param jwtKeys.job.tolerations Tolerations for the generating job Pod
|
|
## @param jwtKeys.job.affinity Affinity for the generating job Pod
|
|
## @param jwtKeys.job.serviceAccountName Service account of the generating job Pod, the one created above when empty
|
|
## @skip jwtKeys.job.env
|
|
job:
|
|
podSecurityContext: {}
|
|
# neither image declares a user of its own, and kubernetes refuses to start
|
|
# a container asking for runAsNonRoot without knowing which user to run as
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- "ALL"
|
|
runAsNonRoot: true
|
|
runAsUser: 1000
|
|
runAsGroup: 1000
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
restartPolicy: Never
|
|
backoffLimit: 2
|
|
ttlSecondsAfterFinished: 30
|
|
generateCommand: []
|
|
publishCommand: []
|
|
annotations: {}
|
|
podAnnotations: {}
|
|
resources: {}
|
|
nodeSelector: {}
|
|
tolerations: []
|
|
affinity: {}
|
|
serviceAccountName: null
|
|
env: []
|
|
|
|
## @section yhub
|
|
##
|
|
## The collaboration server: it serves the whole /collaboration/ prefix, the
|
|
## websocket included, and replaces the y-provider on that role. It keeps the
|
|
## live state of a document in redis/valkey and persists it to its own
|
|
## PostgreSQL database, so it needs both — set `yhub.envVars.REDIS` and
|
|
## `yhub.envVars.POSTGRES`, there is nothing sensible to default them to.
|
|
## Disabling it sends the /collaboration/ ingresses back to the y-provider.
|
|
##
|
|
## Two buckets can be added to that list, each with a prefix of its own so that
|
|
## none of them is ambiguous — they may sit on different providers, with
|
|
## different credentials, and are read by different processes:
|
|
##
|
|
## - `LEGACY_S3_*`, turned on by `SOFT_MIGRATION`, is the legacy Django media
|
|
## bucket it reads old documents *out of*. Not the backend's `AWS_S3_*`,
|
|
## which names the same bucket for the backend's own use,
|
|
## - `YHUB_S3_*`, turned on by `YHUB_S3_PERSISTENCE`, is a bucket of its own it
|
|
## stores the document blobs *into*, instead of its PostgreSQL database.
|
|
## Read `src/yhub-server/README.md` before enabling it: a document persisted
|
|
## this way cannot be read back once the setting is removed.
|
|
yhub:
|
|
## @param yhub.enabled Enable the yhub collaboration server, its service and its init-db job
|
|
enabled: true
|
|
|
|
## @param yhub.image.repository Repository to use to pull the yhub container image
|
|
## @param yhub.image.tag yhub container tag
|
|
## @param yhub.image.pullPolicy yhub container image pull policy
|
|
image:
|
|
repository: lasuite/impress-yhub
|
|
pullPolicy: IfNotPresent
|
|
tag: "latest"
|
|
|
|
## @param yhub.command Override the yhub container command
|
|
command: []
|
|
|
|
## @param yhub.args Override the yhub container args
|
|
args: []
|
|
|
|
## @param yhub.replicas Amount of yhub replicas
|
|
## Clients editing the same document need not land on the same pod: updates
|
|
## travel through redis. Each replica also runs a worker unless the worker is
|
|
## deployed apart, see below.
|
|
replicas: 3
|
|
|
|
## @param yhub.worker.enabled Deploy the worker apart from the server, each scaling on its own
|
|
## @param yhub.worker.replicas Amount of yhub worker replicas
|
|
## @param yhub.worker.resources Resource requirements for the yhub worker container, the server ones when empty
|
|
## @param yhub.worker.podAnnotations Annotations to add to the yhub worker Pod, the server ones when empty
|
|
## @param yhub.worker.dpAnnotations Annotations to add to the yhub worker Deployment, the server ones when empty
|
|
## @param yhub.worker.nodeSelector Node selector for the yhub worker Pod, the server one when empty
|
|
## @param yhub.worker.tolerations Tolerations for the yhub worker Pod, the server ones when empty
|
|
## @param yhub.worker.affinity Affinity for the yhub worker Pod, the server one when empty
|
|
## @param yhub.worker.terminationGracePeriodSeconds Grace period given to a worker pod to finish its task, the server one when empty
|
|
## @param yhub.worker.pdb.enabled Enable pdb on the yhub worker
|
|
## @skip yhub.worker.envVars Environment variables of the worker only, on top of yhub.envVars
|
|
##
|
|
## yhub is two halves sharing nothing but redis and postgres: the server
|
|
## holds the websockets and serves the routes, the worker drains the stream
|
|
## into postgres. One process runs both by default. Enabling this splits them
|
|
## into two deployments — `YHUB_ROLE=server` and `YHUB_ROLE=worker`, the only
|
|
## difference between them — so the server scales with the connected editors
|
|
## and the worker with the write throughput.
|
|
##
|
|
## The worker binds nothing: no service, no ingress, and no probes to give it
|
|
## (its liveness is its process). Everything not named here is the server's:
|
|
## same image, same envVars, same secrets, same volumes.
|
|
##
|
|
## How much each pod chews through is `worker.envVars.YHUB_TASK_CONCURRENCY`
|
|
## (default 5, and `yhub.envVars` when the two halves share a process), the
|
|
## other half of the throughput knob `worker.replicas` is: redis hands each
|
|
## task to a single worker, so the two multiply.
|
|
worker:
|
|
enabled: false
|
|
replicas: 1
|
|
envVars: {}
|
|
resources: {}
|
|
podAnnotations: {}
|
|
dpAnnotations: {}
|
|
nodeSelector: {}
|
|
tolerations: []
|
|
affinity: {}
|
|
terminationGracePeriodSeconds: null
|
|
pdb:
|
|
enabled: true
|
|
|
|
## @param yhub.shareProcessNamespace Enable share process namespace between containers
|
|
shareProcessNamespace: false
|
|
|
|
## @param yhub.sidecars Add sidecars containers to yhub deployment
|
|
sidecars: []
|
|
|
|
## @param yhub.terminationGracePeriodSeconds Grace period given to a yhub pod to drain before it is killed
|
|
terminationGracePeriodSeconds: 60
|
|
|
|
## @param yhub.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the yhub container
|
|
## @param yhub.securityContext.capabilities.drop List of capabilities to drop for the yhub container
|
|
## @param yhub.securityContext.runAsNonRoot Whether to run the yhub container as a non-root user
|
|
## @param yhub.securityContext.runAsUser User the yhub container runs as
|
|
## @param yhub.securityContext.runAsGroup Group the yhub container runs as
|
|
## @param yhub.securityContext.seccompProfile.type Seccomp profile type for the yhub container
|
|
##
|
|
## The user is named rather than left to the image: asking for runAsNonRoot
|
|
## without it is refused outright by kubernetes ("container has runAsNonRoot
|
|
## and image will run as root") on any image that declares none — which every
|
|
## yhub image built before the un-privileged user was added to its Dockerfile
|
|
## does. 1000 is the `node` user the base image already carries.
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- "ALL"
|
|
runAsNonRoot: true
|
|
runAsUser: 1000
|
|
runAsGroup: 1000
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
## @param yhub.envVars Configure yhub container environment variables
|
|
## @extra yhub.envVars.REDIS Required, redis/valkey url holding the live document state (e.g. redis://valkey:6379/0)
|
|
## @extra yhub.envVars.POSTGRES Required, url of the yhub database, created by the init-db job (e.g. postgres://user:pass@postgres:5432/yhub)
|
|
## @extra yhub.envVars.REDIS_PREFIX Namespace of the redis keys, when the instance is shared (default: yhub)
|
|
## @extra yhub.envVars.COLLABORATION_BACKEND_BASE_URL Base url of the Docs backend, which yhub asks about users and document access rights
|
|
## @extra yhub.envVars.COLLABORATION_SERVER_ORIGIN Comma separated list of the origins allowed to open a websocket
|
|
## @extra yhub.envVars.YHUB_JWT_PRIVATE_KEY_FILE Path to the RSA private key (PEM) yhub signs its calls to the backend with, mounted from a secret
|
|
## @extra yhub.envVars.YHUB_TASK_CONCURRENCY Tasks one worker process claims at once, times the replicas running a worker (default: 5)
|
|
## @extra yhub.envVars.YHUB_TASK_DEBOUNCE_MS How long an update waits on the redis stream before a worker persists it, in ms (default: 10000)
|
|
## @extra yhub.envVars.YHUB_MIN_MESSAGE_LIFETIME_MS How long persisted updates stay replayable from redis, in ms (default: 60000)
|
|
## @extra yhub.envVars.SOFT_MIGRATION Set to "true" to seed rooms from the legacy Django/S3 document store on first access
|
|
## @extra yhub.envVars.LEGACY_S3_ENDPOINT_URL Required by SOFT_MIGRATION, endpoint of the legacy Django media bucket, without a path (e.g. https://s3.example.com)
|
|
## @extra yhub.envVars.LEGACY_S3_ACCESS_KEY_ID Required by SOFT_MIGRATION, read access to the legacy bucket (or LEGACY_S3_ACCESS_KEY_ID_FILE)
|
|
## @extra yhub.envVars.LEGACY_S3_SECRET_ACCESS_KEY Required by SOFT_MIGRATION, secret of the key above (or LEGACY_S3_SECRET_ACCESS_KEY_FILE)
|
|
## @extra yhub.envVars.LEGACY_S3_REGION_NAME Region of the legacy bucket, when its provider needs one
|
|
## @extra yhub.envVars.LEGACY_S3_BUCKET_NAME Name of the legacy Django media bucket (default: impress-media-storage)
|
|
## @extra yhub.envVars.LEGACY_S3_SIGNATURE_VERSION How the calls to the legacy bucket are signed, s3v4 or v4 (default: s3v4)
|
|
## @extra yhub.envVars.YHUB_S3_PERSISTENCE Set to "true" to store the document blobs in a bucket instead of the yhub database — read src/yhub-server/README.md first, it cannot be turned back off
|
|
## @extra yhub.envVars.YHUB_S3_ENDPOINT_URL Required by YHUB_S3_PERSISTENCE, endpoint of the bucket the blobs are stored in, without a path (e.g. https://s3.example.com)
|
|
## @extra yhub.envVars.YHUB_S3_ACCESS_KEY_ID Required by YHUB_S3_PERSISTENCE, read/write/delete access to that bucket (or YHUB_S3_ACCESS_KEY_ID_FILE)
|
|
## @extra yhub.envVars.YHUB_S3_SECRET_ACCESS_KEY Required by YHUB_S3_PERSISTENCE, secret of the key above (or YHUB_S3_SECRET_ACCESS_KEY_FILE)
|
|
## @extra yhub.envVars.YHUB_S3_BUCKET_NAME Required by YHUB_S3_PERSISTENCE, name of that bucket, created on startup when missing
|
|
## @extra yhub.envVars.YHUB_S3_REGION_NAME Region of that bucket, when its provider needs one
|
|
## @extra yhub.envVars.BY_VALUE Example environment variable by setting value directly
|
|
## @extra yhub.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra yhub.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
|
|
## @extra yhub.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
|
|
## @extra yhub.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
|
|
## @skip yhub.envVars
|
|
envVars:
|
|
<<: *commonEnvVars
|
|
|
|
## @skip yhub.envFrom List of environment variables taken from Secrets or configMaps
|
|
envFrom: []
|
|
# envFrom:
|
|
# - secret:
|
|
# name: super-secret-user-credentials
|
|
# - configMapRef:
|
|
# name: my-environment-variables
|
|
|
|
## @param yhub.podAnnotations Annotations to add to the yhub Pod
|
|
podAnnotations: {}
|
|
|
|
## @param yhub.dpAnnotations Annotations to add to the yhub Deployment
|
|
dpAnnotations: {}
|
|
|
|
## @param yhub.initDbJobAnnotations Annotations for the yhub init-db job
|
|
initDbJobAnnotations: {}
|
|
|
|
## @param yhub.jobs.ttlSecondsAfterFinished Period to wait before removing the init-db job
|
|
## @param yhub.jobs.backoffLimit Numbers of init-db job retries
|
|
jobs:
|
|
ttlSecondsAfterFinished: 30
|
|
backoffLimit: 2
|
|
|
|
## @param yhub.initDb.enabled Run the job creating and upgrading the yhub schema
|
|
## @param yhub.initDb.command Override the command creating and upgrading the yhub schema
|
|
## @param yhub.initDb.retries How many times the schema script is retried while the postgres server does not answer
|
|
## @param yhub.initDb.retryDelaySeconds Seconds between two attempts
|
|
## @param yhub.initDb.restartPolicy Restart policy of the init-db job
|
|
## @skip yhub.initDb.resources Resource requirements for the init-db container, defaults to yhub.resources
|
|
##
|
|
## The job runs in the default sync wave, next to the backend migrate job,
|
|
## and waits for its database the same way that one waits for Django's:
|
|
## nothing in this chart creates the postgres server, so it has to be given
|
|
## the time whatever does takes. The defaults below wait five minutes.
|
|
initDb:
|
|
enabled: true
|
|
command: []
|
|
retries: 60
|
|
retryDelaySeconds: 5
|
|
restartPolicy: Never
|
|
resources: {}
|
|
|
|
## @param yhub.service.type yhub Service type
|
|
## @param yhub.service.port yhub Service listening port
|
|
## @param yhub.service.targetPort yhub container listening port
|
|
## @param yhub.service.annotations Annotations to add to the yhub Service
|
|
service:
|
|
type: ClusterIP
|
|
port: 443
|
|
targetPort: 3002
|
|
annotations: {}
|
|
|
|
## @param yhub.probes.liveness.path Configure path for yhub HTTP liveness probe
|
|
## @param yhub.probes.liveness.initialDelaySeconds Configure initial delay for yhub liveness probe
|
|
## @param yhub.probes.liveness.timeoutSeconds Configure timeout for yhub liveness probe
|
|
## @param yhub.probes.readiness.path Configure path for yhub HTTP readiness probe
|
|
## @param yhub.probes.readiness.initialDelaySeconds Configure initial delay for yhub readiness probe
|
|
## @param yhub.probes.readiness.timeoutSeconds Configure timeout for yhub readiness probe
|
|
## @extra yhub.probes.liveness.targetPort Configure port for yhub HTTP liveness probe
|
|
## @extra yhub.probes.readiness.targetPort Configure port for yhub HTTP readiness probe
|
|
## @extra yhub.probes.startup.path Configure path for yhub HTTP startup probe
|
|
## @extra yhub.probes.startup.targetPort Configure port for yhub HTTP startup probe
|
|
## @extra yhub.probes.startup.initialDelaySeconds Configure initial delay for yhub startup probe
|
|
## @extra yhub.probes.startup.timeoutSeconds Configure timeout for yhub startup probe
|
|
##
|
|
## Two routes yhub serves unauthenticated, and they answer different
|
|
## questions on purpose:
|
|
##
|
|
## - `ping` returns 200 without touching anything. Being answered at all is
|
|
## the proof the http channel and the event loop are alive, which is as far
|
|
## as a liveness probe should ever go: restarting a server over a store it
|
|
## does not reach would drop the websockets it is happily serving.
|
|
## - `ready` asks postgres and redis whether they answer, and returns 503
|
|
## when either does not. That takes the pod out of the service endpoints
|
|
## and leaves its siblings serving, which is what readiness is for. Its
|
|
## timeout is above the two seconds the server itself gives each store, so
|
|
## an unreachable one is reported rather than cut off.
|
|
probes:
|
|
liveness:
|
|
path: /collaboration/ping/v1
|
|
initialDelaySeconds: 10
|
|
timeoutSeconds: 2
|
|
readiness:
|
|
path: /collaboration/ready/v1
|
|
initialDelaySeconds: 5
|
|
timeoutSeconds: 3
|
|
|
|
## @param yhub.resources Resource requirements for the yhub container
|
|
resources: {}
|
|
|
|
## @param yhub.nodeSelector Node selector for the yhub Pod
|
|
nodeSelector: {}
|
|
|
|
## @param yhub.tolerations Tolerations for the yhub Pod
|
|
tolerations: []
|
|
|
|
## @param yhub.affinity Affinity for the yhub Pod
|
|
affinity: {}
|
|
|
|
## @param yhub.persistence Additional volumes to create and mount on the yhub. Used for debugging purposes
|
|
## @extra yhub.persistence.volume-name.size Size of the additional volume
|
|
## @extra yhub.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
|
|
## @extra yhub.persistence.volume-name.mountPath Path where the volume should be mounted to
|
|
persistence: {}
|
|
|
|
## @param yhub.extraVolumeMounts Additional volumes to mount on the yhub. Mounted on the init-db job too
|
|
extraVolumeMounts: []
|
|
|
|
## @param yhub.extraVolumes Additional volumes to mount on the yhub. Mounted on the init-db job too
|
|
extraVolumes: []
|
|
|
|
## @param yhub.pdb.enabled Enable pdb on yhub
|
|
pdb:
|
|
enabled: true
|
|
|
|
## @param yhub.serviceAccountName Optional service account name to use for yhub pods
|
|
serviceAccountName: null
|
|
|
|
## @section docSpec
|
|
docSpec:
|
|
## @param docSpec.enabled Enable docSpec deployment
|
|
enabled: false
|
|
|
|
## @param docSpec.image.repository Repository to use to pull docSpec container image
|
|
## @param docSpec.image.tag docSpec container tag
|
|
## @param docSpec.image.pullPolicy docSpec container image pull policy
|
|
image:
|
|
repository: ghcr.io/docspecio/api
|
|
pullPolicy: IfNotPresent
|
|
tag: "3.0.1"
|
|
|
|
## @param docSpec.command Override the docSpec container command
|
|
command: []
|
|
|
|
## @param docSpec.args Override the docSpec container args
|
|
args: []
|
|
|
|
## @param docSpec.replicas Amount of docSpec replicas
|
|
replicas: 1
|
|
|
|
## @param docSpec.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the docSpec container
|
|
## @param docSpec.securityContext.capabilities.drop List of capabilities to drop for the docSpec container
|
|
## @param docSpec.securityContext.runAsNonRoot Whether to run the docSpec container as a non-root user
|
|
## @param docSpec.securityContext.seccompProfile.type Seccomp profile type for the docSpec container
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- "ALL"
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
## @param docSpec.envVars Configure docSpec container environment variables
|
|
envVars: {}
|
|
|
|
## @skip docSpec.envFrom List of environment variables taken from Secrets or configMaps
|
|
envFrom: []
|
|
# envFrom:
|
|
# - secret:
|
|
# name: super-secret-user-credentials
|
|
# - configMapRef:
|
|
# name: my-environment-variables
|
|
|
|
## @param docSpec.service.type docSpec Service type
|
|
## @param docSpec.service.port docSpec Service listening port
|
|
## @param docSpec.service.targetPort docSpec container listening port
|
|
service:
|
|
type: ClusterIP
|
|
port: 4000
|
|
targetPort: 4000
|
|
|
|
## @param docSpec.probes.liveness.path Configure path for docSpec HTTP liveness probe
|
|
## @param docSpec.probes.readiness.path Configure path for docSpec HTTP readiness probe
|
|
probes:
|
|
liveness:
|
|
path: /health
|
|
readiness:
|
|
path: /health
|
|
|
|
## @param docSpec.resources docSpec resources
|
|
resources: {}
|
|
|
|
## @param docSpec.nodeSelector Node selector for the docSpec Pod
|
|
nodeSelector: {}
|
|
|
|
## @param docSpec.tolerations Tolerations for the docSpec Pod
|
|
tolerations: []
|
|
|
|
## @param docSpec.affinity Affinity for the docSpec Pod
|
|
affinity: {}
|
|
|
|
## @param docSpec.extraVolumeMounts Additional volumes to mount on docSpec
|
|
extraVolumeMounts: []
|
|
|
|
## @param docSpec.extraVolumes Additional volumes to mount on docSpec
|
|
extraVolumes: []
|