Files
lasuite-docs/src/helm/impress/values.yaml
T
Manuel RaynaudandAnthony LC a6be60bfc3 (yhub) allow optional usage of s3 persistent plugin
Yhub has a s3 persistent plugin, since now we didn't use it but we wanto
to give the possibility to use it optionnaly. To enable it set the
YHUB_S3_PERSISTENCE environment value to true and configure it.
2026-09-01 15:31:34 +02:00

1250 lines
56 KiB
YAML

# Default values for impress.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
## @section General configuration
## @param image.repository Repository to use to pull impress's container image
## @param image.tag impress's container tag
## @param image.pullPolicy Container image pull policy
## @extra image.credentials.username Username for container registry authentication
## @extra image.credentials.password Password for container registry authentication
## @extra image.credentials.registry Registry url for which the credentials are specified
## @extra image.credentials.name Name of the generated secret for imagePullSecrets
image:
repository: lasuite/impress-backend
pullPolicy: IfNotPresent
tag: "latest"
## @param nameOverride Override the chart name
## @param fullnameOverride Override the full application name
nameOverride: ""
fullnameOverride: ""
## @skip commonEnvVars
commonEnvVars: &commonEnvVars
<<: []
## @param ingress.enabled whether to enable the Ingress or not
## @param ingress.className IngressClass to use for the Ingress
## @param ingress.host Host for the Ingress
## @param ingress.path Path to use for the Ingress
ingress:
enabled: false
className: null
host: impress.example.com
path: /
## @param ingress.hosts Additional host to configure for the Ingress
hosts: []
# - chart-example.local
## @param ingress.tls.enabled Whether to enable TLS for the Ingress
## @param ingress.tls.secretName Secret name for TLS config
## @skip ingress.tls.additional
## @extra ingress.tls.additional[].secretName Secret name for additional TLS config
## @extra ingress.tls.additional[].hosts[] Hosts for additional TLS config
tls:
enabled: true
secretName: null
additional: []
## @param ingress.customBackends Add custom backends to ingress
customBackends: []
## @param ingressCollaborationWS.enabled whether to enable the Ingress or not
## @param ingressCollaborationWS.className IngressClass to use for the Ingress
## @param ingressCollaborationWS.host Host for the Ingress
## @param ingressCollaborationWS.path Path to use for the Ingress
ingressCollaborationWS:
enabled: false
className: null
host: impress.example.com
path: /collaboration/ws/
## @param ingressCollaborationWS.hosts Additional host to configure for the Ingress
hosts: []
# - chart-example.local
## @param ingressCollaborationWS.tls.enabled Whether to enable TLS for the Ingress
## @param ingressCollaborationWS.tls.secretName Secret name for TLS config
## @skip ingressCollaborationWS.tls.additional
## @extra ingressCollaborationWS.tls.additional[].secretName Secret name for additional TLS config
## @extra ingressCollaborationWS.tls.additional[].hosts[] Hosts for additional TLS config
tls:
enabled: true
secretName: null
additional: []
## @param ingressCollaborationWS.customBackends Add custom backends to ingress
customBackends: []
## @param ingressCollaborationWS.annotations.nginx.ingress.kubernetes.io/enable-websocket
## @param ingressCollaborationWS.annotations.nginx.ingress.kubernetes.io/proxy-read-timeout
## @param ingressCollaborationWS.annotations.nginx.ingress.kubernetes.io/proxy-send-timeout
##
## No upstream-hash-by: yhub passes updates between its replicas through
## redis, so two clients editing the same document may land on different
## pods — where the y-provider it replaces needed a room to stay on one.
annotations:
nginx.ingress.kubernetes.io/enable-websocket: "true"
nginx.ingress.kubernetes.io/proxy-read-timeout: "86400"
nginx.ingress.kubernetes.io/proxy-send-timeout: "86400"
## @param ingressRedirects.enabled whether to enable the Ingress Redirects or not
## @param ingressRedirects.className IngressClass to use for the Ingress Redirects
## @param ingressRedirects.host Host for the Ingress Redirects
ingressRedirects:
enabled: false
className: null
host: impress.example.com
## @param ingressRedirects.tls.enabled Whether to enable TLS for the Ingress Redirects
## @param ingressRedirects.tls.secretName Secret name for TLS config
## @skip ingressRedirects.tls.additional
## @extra ingressRedirects.tls.additional[].secretName Secret name for additional TLS config
## @extra ingressRedirects.tls.additional[].hosts[] Hosts for additional TLS config
tls:
enabled: true
secretName: null
additional: []
## @param ingressRedirects.rules Rules for the Ingress Redirects
rules: []
## @param ingressCollaborationApi.enabled whether to enable the Ingress or not
## @param ingressCollaborationApi.className IngressClass to use for the Ingress
## @param ingressCollaborationApi.host Host for the Ingress
## @param ingressCollaborationApi.path Path to use for the Ingress
ingressCollaborationApi:
enabled: false
className: null
host: impress.example.com
## Only used when `paths` below is empty
path: /collaboration/api/
## @param ingressCollaborationApi.paths Paths to route to the collaboration server, one rule each
##
## The routes yhub serves to browsers, guarded by the same document
## authorization as the websocket. Everything it serves that is not listed
## here stays in-cluster — `create-ydoc`, `reset-connections`, `migrate`,
## `restore-ydoc` and `reset-ydoc` are called by the backend only, and
## publishing them would put document deletion and the legacy migration one
## request away from the internet.
##
## `jwks` is public on purpose: it carries the public halves of the keys
## yhub signs with, and nothing else.
paths:
- /collaboration/ydoc/
- /collaboration/jwks/
## @param ingressCollaborationApi.hosts Additional host to configure for the Ingress
hosts: []
# - chart-example.local
## @param ingressCollaborationApi.tls.enabled Whether to enable TLS for the Ingress
## @param ingressCollaborationApi.tls.secretName Secret name for TLS config
## @skip ingressCollaborationApi.tls.additional
## @extra ingressCollaborationApi.tls.additional[].secretName Secret name for additional TLS config
## @extra ingressCollaborationApi.tls.additional[].hosts[] Hosts for additional TLS config
tls:
enabled: true
secretName: null
additional: []
## @param ingressCollaborationApi.customBackends Add custom backends to ingress
customBackends: []
## @skip ingressCollaborationApi.annotations
## Same as ingressCollaborationWS: no upstream-hash-by, any yhub replica
## answers for any document.
annotations: {}
## @param ingressAdmin.enabled whether to enable the Ingress or not
## @param ingressAdmin.className IngressClass to use for the Ingress
## @param ingressAdmin.host Host for the Ingress
## @param ingressAdmin.path Path to use for the Ingress
ingressAdmin:
enabled: false
className: null
host: impress.example.com
path: /admin
## @param ingressAdmin.hosts Additional host to configure for the Ingress
hosts: []
# - chart-example.local
## @param ingressAdmin.tls.enabled Whether to enable TLS for the Ingress
## @param ingressAdmin.tls.secretName Secret name for TLS config
## @skip ingressAdmin.tls.additional
## @extra ingressAdmin.tls.additional[].secretName Secret name for additional TLS config
## @extra ingressAdmin.tls.additional[].hosts[] Hosts for additional TLS config
tls:
enabled: true
secretName: null
additional: []
## @param ingressMedia.enabled whether to enable the Ingress or not
## @param ingressMedia.className IngressClass to use for the Ingress
## @param ingressMedia.host Host for the Ingress
## @param ingressMedia.path Path to use for the Ingress
ingressMedia:
enabled: false
className: null
host: impress.example.com
path: /media/(.*)
## @param ingressMedia.hosts Additional host to configure for the Ingress
hosts: []
# - chart-example.local
## @param ingressMedia.tls.enabled Whether to enable TLS for the Ingress
## @param ingressMedia.tls.secretName Secret name for TLS config
## @skip ingressMedia.tls.additional
## @extra ingressMedia.tls.additional[].secretName Secret name for additional TLS config
## @extra ingressMedia.tls.additional[].hosts[] Hosts for additional TLS config
tls:
enabled: true
secretName: null
additional: []
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/auth-url
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/auth-response-headers
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/upstream-vhost
## @param ingressMedia.annotations.nginx.ingress.kubernetes.io/configuration-snippet
annotations:
nginx.ingress.kubernetes.io/auth-url: https://impress.example.com/api/v1.0/documents/media-auth/
nginx.ingress.kubernetes.io/auth-response-headers: "Authorization, X-Amz-Date, X-Amz-Content-SHA256"
nginx.ingress.kubernetes.io/upstream-vhost: minio.impress.svc.cluster.local:9000
nginx.ingress.kubernetes.io/configuration-snippet: |
add_header Content-Security-Policy "default-src 'none'" always;
## @param serviceMedia.host Hostname of the media storage backend (S3/MinIO) used by the media ingress
## @param serviceMedia.port Port of the media storage backend
## @param serviceMedia.annotations Annotations to add to the media ExternalName Service
serviceMedia:
host: minio.impress.svc.cluster.local
port: 9000
annotations: {}
## @section backend
backend:
## @param backend.command Override the backend container command
command: []
## @param backend.args Override the backend container args
args: []
## @param backend.replicas Amount of backend replicas
replicas: 3
## @param backend.shareProcessNamespace Enable share process namespace between containers
shareProcessNamespace: false
## @param backend.sidecars Add sidecars containers to backend deployment
sidecars: []
## @param backend.migrateJobAnnotations Annotations for the migrate job
migrateJobAnnotations: {}
## @param backend.jobs.ttlSecondsAfterFinished Period to wait before remove jobs
## @param backend.jobs.backoffLimit Numbers of jobs retries
jobs:
ttlSecondsAfterFinished: 30
backoffLimit: 2
## @param backend.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the backend container
## @param backend.securityContext.capabilities.drop List of capabilities to drop for the backend container
## @param backend.securityContext.runAsNonRoot Whether to run the backend container as a non-root user
## @param backend.securityContext.seccompProfile.type Seccomp profile type for the backend container
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
## @param backend.envVars Configure backend container environment variables
## @extra backend.envVars.BY_VALUE Example environment variable by setting value directly
## @extra backend.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
## @extra backend.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
## @extra backend.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
## @extra backend.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
## @skip backend.envVars
envVars:
<<: *commonEnvVars
## @skip backend.envFrom List of environment variables taken from Secrets or configMaps, common to backend and celery worker
envFrom: []
# envFrom:
# - secret:
# name: super-secret-user-credentials
# - configMapRef:
# name: my-environment-variables
## @extra backend.django.envVars Backend web deployment specific environment variables (not shared with celery worker)
## @skip backend.django.envVars
## @skip backend.django.envFrom List of environment variables taken from Secrets or configMaps, specific to the backend web deployment
django:
envVars: {}
envFrom: []
## @param backend.podAnnotations Annotations to add to the backend Pod
podAnnotations: {}
## @param backend.dpAnnotations Annotations to add to the backend Deployment
dpAnnotations: {}
## @param backend.service.type backend Service type
## @param backend.service.port backend Service listening port
## @param backend.service.targetPort backend container listening port
## @param backend.service.annotations Annotations to add to the backend Service
service:
type: ClusterIP
port: 80
targetPort: 8000
annotations: {}
## @param backend.migrate.command backend migrate command
## @param backend.migrate.restartPolicy backend migrate job restart policy
migrate:
command:
- /bin/sh
- "-c"
- |
attempt=0
until output=$(python manage.py check --database default 2>&1)
do
attempt=$((attempt + 1))
echo "Database check failed (attempt $attempt), retrying in 2s:"
echo "$output"
sleep 2
done
echo "Database is ready"
python manage.py migrate --no-input
restartPolicy: Never
## @param backend.createsuperuser.command backend migrate command
## @param backend.createsuperuser.restartPolicy backend migrate job restart policy
createsuperuser:
command:
- "/bin/sh"
- "-c"
- |
attempt=0
until output=$(python manage.py check --database default 2>&1)
do
attempt=$((attempt + 1))
echo "Database check failed (attempt $attempt), retrying in 2s:"
echo "$output"
sleep 2
done
echo "Database is ready"
python manage.py createsuperuser --email $DJANGO_SUPERUSER_EMAIL --password $DJANGO_SUPERUSER_PASSWORD
restartPolicy: Never
## @extra backend.job job dedicated to run a random management command, for example after a deployment
## @param backend.job.name The name to use to describe this job
## @param backend.job.command The management command to execute
## @param backend.job.restartPolicy The restart policy for the job.
## @extra backend.job.annotations Annotations to add to the job [default: argocd.argoproj.io/hook: PostSync]
## @skip backend.job.annotations.argocd.argoproj.io/hook
job:
name: ""
command: []
restartPolicy: Never
annotations:
argocd.argoproj.io/hook: PostSync
# List of cronjob to add
# cronjobs:
# - name: reset-database
# schedule: "0 */2 * * *"
# command:
# - "/bin/sh"
# - "-c"
# - python manage.py flush --no-input
## @param backend.cronjobs Cronjob name, schedule, command
cronjobs: []
## @param backend.probes.liveness.path [nullable] Configure path for backend HTTP liveness probe
## @param backend.probes.liveness.targetPort [nullable] Configure port for backend HTTP liveness probe
## @param backend.probes.liveness.initialDelaySeconds [nullable] Configure initial delay for backend liveness probe
## @param backend.probes.liveness.timeoutSeconds [nullable] Configure timeout for backend liveness probe
## @extra backend.probes.startup.path [nullable] Configure path for backend HTTP startup probe
## @extra backend.probes.startup.targetPort [nullable] Configure port for backend HTTP startup probe
## @extra backend.probes.startup.initialDelaySeconds [nullable] Configure initial delay for backend startup probe
## @extra backend.probes.startup.timeoutSeconds [nullable] Configure timeout for backend startup probe
## @param backend.probes.readiness.path [nullable] Configure path for backend HTTP readiness probe
## @param backend.probes.readiness.targetPort [nullable] Configure port for backend HTTP readiness probe
## @param backend.probes.readiness.initialDelaySeconds [nullable] Configure initial delay for backend readiness probe
## @param backend.probes.readiness.timeoutSeconds [nullable] Configure timeout for backend readiness probe
probes:
liveness:
path: /__lbheartbeat__
initialDelaySeconds: 10
readiness:
path: /__heartbeat__
initialDelaySeconds: 10
## @param backend.resources Resource requirements for the backend container
resources: {}
## @param backend.nodeSelector Node selector for the backend Pod
nodeSelector: {}
## @param backend.tolerations Tolerations for the backend Pod
tolerations: []
## @param backend.affinity Affinity for the backend Pod
affinity: {}
## @param backend.persistence Additional volumes to create and mount on the backend. Used for debugging purposes
## @extra backend.persistence.volume-name.size Size of the additional volume
## @extra backend.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
## @extra backend.persistence.volume-name.mountPath Path where the volume should be mounted to
persistence: {}
## @param backend.extraVolumeMounts Additional volumes to mount on the backend.
extraVolumeMounts: []
## @param backend.extraVolumes Additional volumes to mount on the backend.
extraVolumes: []
## @param backend.pdb.enabled Enable pdb on backend
pdb:
enabled: true
## @param backend.serviceAccountName Optional service account name to use for backend pods
serviceAccountName: null
## @param backend.themeCustomization.enabled Enable theme customization
## @param backend.themeCustomization.file_content Content of the theme customization file. Must be a json object.
## @param backend.themeCustomization.mount_path Path where the customization file will be mounted in the backend deployment.
themeCustomization:
enabled: false
file_content: ""
mount_path: /app/impress/configuration/theme
## @param backend.celery.replicas Amount of celery replicas
## @param backend.celery.command Override the celery container command
## @param backend.celery.args Override the celery container args
## @param backend.celery.resources Resource requirements for the celery container
## @param backend.celery.probes.liveness.exec.command Override the celery container liveness probe command
## @param backend.celery.probes.liveness.initialDelaySeconds Initial delay for the celery container liveness probe
## @param backend.celery.probes.liveness.timeoutSeconds Timeout for the celery container liveness probe
## @param backend.celery.probes.readiness.exec.command Override the celery container readiness probe command
## @param backend.celery.probes.readiness.initialDelaySeconds Initial delay for the celery container readiness probe
## @param backend.celery.probes.readiness.timeoutSeconds Timeout for the celery container readiness probe
## @extra backend.celery.envVars Celery worker specific environment variables (not shared with the backend web deployment)
## @skip backend.celery.envVars
## @skip backend.celery.envFrom List of environment variables taken from Secrets or configMaps, specific to celery worker
celery:
replicas: 1
command: []
args:
[
"celery",
"-A",
"impress.celery_app",
"worker",
"-l",
"INFO",
"-n",
"impress@%h",
]
envVars: {}
envFrom: []
resources: {}
probes:
liveness:
exec:
command:
[
"/bin/sh",
"-c",
"celery -A impress.celery_app inspect ping -d impress@$HOSTNAME",
]
initialDelaySeconds: 60
timeoutSeconds: 5
readiness:
exec:
command:
[
"/bin/sh",
"-c",
"celery -A impress.celery_app inspect ping -d impress@$HOSTNAME",
]
initialDelaySeconds: 15
timeoutSeconds: 5
## @section frontend
frontend:
## @param frontend.image.repository Repository to use to pull impress's frontend container image
## @param frontend.image.tag impress's frontend container tag
## @param frontend.image.pullPolicy frontend container image pull policy
image:
repository: lasuite/impress-frontend
pullPolicy: IfNotPresent
tag: "latest"
## @param frontend.command Override the frontend container command
command: []
## @param frontend.args Override the frontend container args
args: []
## @param frontend.replicas Amount of frontend replicas
replicas: 3
## @param frontend.shareProcessNamespace Enable share process namespace between containers
shareProcessNamespace: false
## @param frontend.sidecars Add sidecars containers to frontend deployment
sidecars: []
## @param frontend.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the frontend container
## @param frontend.securityContext.capabilities.drop List of capabilities to drop for the frontend container
## @param frontend.securityContext.runAsNonRoot Whether to run the frontend container as a non-root user
## @param frontend.securityContext.seccompProfile.type Seccomp profile type for the frontend container
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
## @param frontend.envVars Configure frontend container environment variables
## @extra frontend.envVars.BY_VALUE Example environment variable by setting value directly
## @extra frontend.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
## @extra frontend.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
## @extra frontend.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
## @extra frontend.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
## @skip frontend.envVars
envVars:
<<: *commonEnvVars
## @skip frontend.envFrom List of environment variables taken from Secrets or configMaps
envFrom: []
# envFrom:
# - secret:
# name: super-secret-user-credentials
# - configMapRef:
# name: my-environment-variables
## @param frontend.podAnnotations Annotations to add to the frontend Pod
podAnnotations: {}
## @param frontend.dpAnnotations Annotations to add to the frontend Deployment
dpAnnotations: {}
## @param frontend.service.type frontend Service type
## @param frontend.service.port frontend Service listening port
## @param frontend.service.targetPort frontend container listening port
## @param frontend.service.annotations Annotations to add to the frontend Service
service:
type: ClusterIP
port: 80
targetPort: 8080
annotations: {}
## @param frontend.probes Configure probe for frontend
## @extra frontend.probes.liveness.path Configure path for frontend HTTP liveness probe
## @extra frontend.probes.liveness.targetPort Configure port for frontend HTTP liveness probe
## @extra frontend.probes.liveness.initialDelaySeconds Configure initial delay for frontend liveness probe
## @extra frontend.probes.liveness.initialDelaySeconds Configure timeout for frontend liveness probe
## @extra frontend.probes.startup.path Configure path for frontend HTTP startup probe
## @extra frontend.probes.startup.targetPort Configure port for frontend HTTP startup probe
## @extra frontend.probes.startup.initialDelaySeconds Configure initial delay for frontend startup probe
## @extra frontend.probes.startup.initialDelaySeconds Configure timeout for frontend startup probe
## @extra frontend.probes.readiness.path Configure path for frontend HTTP readiness probe
## @extra frontend.probes.readiness.targetPort Configure port for frontend HTTP readiness probe
## @extra frontend.probes.readiness.initialDelaySeconds Configure initial delay for frontend readiness probe
## @extra frontend.probes.readiness.initialDelaySeconds Configure timeout for frontend readiness probe
probes: {}
## @param frontend.resources Resource requirements for the frontend container
resources: {}
## @param frontend.nodeSelector Node selector for the frontend Pod
nodeSelector: {}
## @param frontend.tolerations Tolerations for the frontend Pod
tolerations: []
## @param frontend.affinity Affinity for the frontend Pod
affinity: {}
## @param frontend.persistence Additional volumes to create and mount on the frontend. Used for debugging purposes
## @extra frontend.persistence.volume-name.size Size of the additional volume
## @extra frontend.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
## @extra frontend.persistence.volume-name.mountPath Path where the volume should be mounted to
persistence: {}
## @param frontend.extraVolumeMounts Additional volumes to mount on the frontend.
extraVolumeMounts: []
## @param frontend.extraVolumes Additional volumes to mount on the frontend.
extraVolumes: []
## @param frontend.pdb.enabled Enable pdb on frontend
pdb:
enabled: true
## @param frontend.serviceAccountName Optional service account name to use for frontend pods
serviceAccountName: null
## @section posthog
posthog:
## @param posthog.ingress.enabled Enable or disable the ingress resource creation
## @param posthog.ingress.className Kubernetes ingress class name to use (e.g., nginx, traefik)
## @param posthog.ingress.host Primary hostname for the ingress resource
## @param posthog.ingress.path URL path prefix for the ingress routes (e.g., /)
## @param posthog.ingress.hosts Additional hostnames array to be included in the ingress
## @param posthog.ingress.tls.enabled Enable or disable TLS/HTTPS for the ingress
## @param posthog.ingress.tls.additional Additional TLS configurations for extra hosts/certificates
## @param posthog.ingress.customBackends Custom backend service configurations for the ingress
## @param posthog.ingress.annotations Additional Kubernetes annotations to apply to the ingress
ingress:
enabled: false
className: null
host: impress.example.com
path: /
hosts: []
tls:
enabled: true
additional: []
customBackends: []
annotations: {}
## @param posthog.ingressAssets.enabled Enable or disable the ingress resource creation
## @param posthog.ingressAssets.className Kubernetes ingress class name to use (e.g., nginx, traefik)
## @param posthog.ingressAssets.host Primary hostname for the ingress resource
## @param posthog.ingressAssets.paths URL paths prefix for the ingress routes (e.g., /static)
## @param posthog.ingressAssets.hosts Additional hostnames array to be included in the ingress
## @param posthog.ingressAssets.tls.enabled Enable or disable TLS/HTTPS for the ingress
## @param posthog.ingressAssets.tls.additional Additional TLS configurations for extra hosts/certificates
## @param posthog.ingressAssets.customBackends Custom backend service configurations for the ingress
## @param posthog.ingressAssets.annotations Additional Kubernetes annotations to apply to the ingress
ingressAssets:
enabled: false
className: null
host: impress.example.com
paths:
- /static
- /array
hosts: []
tls:
enabled: true
additional: []
customBackends: []
annotations: {}
## @param posthog.service.type Service type (e.g. ExternalName, ClusterIP, LoadBalancer)
## @param posthog.service.externalName External service hostname when type is ExternalName
## @param posthog.service.port Port number for the service
## @param posthog.service.annotations Additional annotations to apply to the service
service:
type: ExternalName
externalName: eu.i.posthog.com
port: 443
annotations: {}
## @param posthog.assetsService.type Service type (e.g. ExternalName, ClusterIP, LoadBalancer)
## @param posthog.assetsService.externalName External service hostname when type is ExternalName
## @param posthog.assetsService.port Port number for the service
## @param posthog.assetsService.annotations Additional annotations to apply to the service
assetsService:
type: ExternalName
externalName: eu-assets.i.posthog.com
port: 443
annotations: {}
## @section yProvider
##
## The conversion service, and nothing else since the collaboration moved to
## yhub: this deployment *is* the converter the backend calls on
## `Y_PROVIDER_API_BASE_URL`, so there is no separate converter release to
## enable anymore.
yProvider:
## @param yProvider.image.repository Repository to use to pull impress's yProvider container image
## @param yProvider.image.tag impress's yProvider container tag
## @param yProvider.image.pullPolicy yProvider container image pull policy
image:
repository: lasuite/impress-y-provider
pullPolicy: IfNotPresent
tag: "latest"
## @param yProvider.command Override the yProvider container command
command: []
## @param yProvider.args Override the yProvider container args
args: []
## @param yProvider.replicas Amount of yProvider replicas
replicas: 3
## @param yProvider.shareProcessNamespace Enable share process nameyProvider between containers
shareProcessNamespace: false
## @param yProvider.sidecars Add sidecars containers to yProvider deployment
sidecars: []
## @param yProvider.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the yProvider container
## @param yProvider.securityContext.capabilities.drop List of capabilities to drop for the yProvider container
## @param yProvider.securityContext.runAsNonRoot Whether to run the yProvider container as a non-root user
## @param yProvider.securityContext.seccompProfile.type Seccomp profile type for the yProvider container
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
## @param yProvider.envVars Configure yProvider container environment variables
## @extra yProvider.envVars.BY_VALUE Example environment variable by setting value directly
## @extra yProvider.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
## @extra yProvider.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
## @extra yProvider.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
## @extra yProvider.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
## @skip yProvider.envVars
envVars:
<<: *commonEnvVars
## @skip yProvider.envFrom List of environment variables taken from Secrets or configMaps
envFrom: []
# envFrom:
# - secret:
# name: super-secret-user-credentials
# - configMapRef:
# name: my-environment-variables
## @param yProvider.podAnnotations Annotations to add to the yProvider Pod
podAnnotations: {}
## @param yProvider.dpAnnotations Annotations to add to the yProvider Deployment
dpAnnotations: {}
## @param yProvider.service.type yProvider Service type
## @param yProvider.service.port yProvider Service listening port
## @param yProvider.service.targetPort yProvider container listening port
## @param yProvider.service.annotations Annotations to add to the yProvider Service
service:
type: ClusterIP
port: 443
targetPort: 4444
annotations: {}
## @param yProvider.probes.liveness.path Configure path for yProvider HTTP liveness probe
## @param yProvider.probes.liveness.initialDelaySeconds Configure initial delay for yProvider liveness probe
## @extra yProvider.probes.liveness.targetPort Configure port for yProvider HTTP liveness probe
## @extra yProvider.probes.liveness.timeoutSeconds Configure timeout for yProvider liveness probe
## @extra yProvider.probes.startup.path Configure path for yProvider HTTP startup probe
## @extra yProvider.probes.startup.targetPort Configure port for yProvider HTTP startup probe
## @extra yProvider.probes.startup.initialDelaySeconds Configure initial delay for yProvider startup probe
## @extra yProvider.probes.startup.timeoutSeconds Configure timeout for yProvider startup probe
## @extra yProvider.probes.readiness.path Configure path for yProvider HTTP readiness probe
## @extra yProvider.probes.readiness.targetPort Configure port for yProvider HTTP readiness probe
## @extra yProvider.probes.readiness.initialDelaySeconds Configure initial delay for yProvider readiness probe
## @extra yProvider.probes.readiness.timeoutSeconds Configure timeout for yProvider readiness probe
probes:
liveness:
path: /ping
initialDelaySeconds: 10
## @param yProvider.resources Resource requirements for the yProvider container
resources: {}
## @param yProvider.nodeSelector Node selector for the yProvider Pod
nodeSelector: {}
## @param yProvider.tolerations Tolerations for the yProvider Pod
tolerations: []
## @param yProvider.affinity Affinity for the yProvider Pod
affinity: {}
## @param yProvider.persistence Additional volumes to create and mount on the yProvider. Used for debugging purposes
## @extra yProvider.persistence.volume-name.size Size of the additional volume
## @extra yProvider.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
## @extra yProvider.persistence.volume-name.mountPath Path where the volume should be mounted to
persistence: {}
## @param yProvider.extraVolumeMounts Additional volumes to mount on the yProvider.
extraVolumeMounts: []
## @param yProvider.extraVolumes Additional volumes to mount on the yProvider.
extraVolumes: []
## @param yProvider.pdb.enabled Enable pdb on yProvider
pdb:
enabled: true
## @param yProvider.serviceAccountName Optional service account name to use for yProvider pods
serviceAccountName: null
## @section JWT signing keys
##
## The services do not share a secret: each signs the calls it makes to the
## others with an RSA key of its own and publishes the public half on its JWKS
## endpoint, where the others read it. Enabling this generates those keys on
## the cluster — a job creates them once in a secret every service mounts
## read-only, and leaves them alone on the next run — and points the backend
## and the collaboration server at them. No key is ever templated into a
## manifest or written in a values file, and only that job may create the
## secret: nothing in the release can read it back through the api.
##
## Leave it disabled to keep providing the keys yourself, through
## `backend.envVars.JWT_PRIVATE_KEY_FILE` and
## `yhub.envVars.YHUB_JWT_PRIVATE_KEY_FILE` and volumes of your own — both are
## left untouched when they are set by hand, enabled or not.
jwtKeys:
## @param jwtKeys.enabled Generate the JWT signing keys of the services on the cluster
enabled: false
## @param jwtKeys.existingSecret Secret already holding the keys, generated in a secret of the chart's own when empty
##
## It has to hold the two filenames below. Naming one skips the job and the
## rights it needs, the services only mount what is there.
existingSecret: null
## @param jwtKeys.mountPath Path the keys are mounted at, in every service reading them
mountPath: /data/jwt
## @param jwtKeys.backendKeyFilename Name of the key signing the tokens the backend issues
backendKeyFilename: private.pem
## @param jwtKeys.yhubKeyFilename Name of the key signing the calls the collaboration server makes to the backend
yhubKeyFilename: yhub-private.pem
## @param jwtKeys.keySize Size, in bits, of the generated RSA keys
keySize: 2048
## @param jwtKeys.rbac.create Create the service account and the role the job needs to create the secret
##
## Turning it off means providing `jwtKeys.job.serviceAccountName` with an
## account allowed to `create` secrets and to `get` the one named above.
rbac:
create: true
## @param jwtKeys.image.repository Repository to use to pull the image generating the keys
## @param jwtKeys.image.tag Tag of the image generating the keys
## @param jwtKeys.image.pullPolicy Pull policy of the image generating the keys
##
## openssl and a shell, nothing else. Its entrypoint is openssl itself, which
## the job replaces by the script generating both keys.
image:
repository: alpine/openssl
pullPolicy: IfNotPresent
tag: "3.5.7"
## @param jwtKeys.kubectlImage.repository Repository to use to pull the image handing the keys to the secret
## @param jwtKeys.kubectlImage.tag Tag of the image handing the keys to the secret
## @param jwtKeys.kubectlImage.pullPolicy Pull policy of the image handing the keys to the secret
##
## A second image because the openssl one carries no kubectl, and reaching
## the api with what it does carry (busybox wget, which cannot be told about
## the cluster ca) would mean sending the token over an unverified
## connection.
kubectlImage:
repository: dtzar/helm-kubectl
pullPolicy: IfNotPresent
tag: "3.16.2"
## @param jwtKeys.job.podSecurityContext Pod security context of the generating job
## @param jwtKeys.job.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the job containers
## @param jwtKeys.job.securityContext.capabilities.drop List of capabilities to drop for the job containers
## @param jwtKeys.job.securityContext.runAsNonRoot Whether to run the job containers as a non-root user
## @param jwtKeys.job.securityContext.runAsUser User the job containers run as, their images declaring none
## @param jwtKeys.job.securityContext.runAsGroup Group the job containers run as
## @param jwtKeys.job.securityContext.seccompProfile.type Seccomp profile type for the job containers
## @param jwtKeys.job.restartPolicy Restart policy of the generating job
## @param jwtKeys.job.backoffLimit Numbers of generating job retries
## @param jwtKeys.job.ttlSecondsAfterFinished Period to wait before removing the generating job
## @param jwtKeys.job.generateCommand Override the command generating the keys
## @param jwtKeys.job.publishCommand Override the command creating the secret from the generated keys
## @param jwtKeys.job.annotations Annotations to add to the generating job
## @param jwtKeys.job.podAnnotations Annotations to add to the generating job Pod
## @param jwtKeys.job.resources Resource requirements for the job containers
## @param jwtKeys.job.nodeSelector Node selector for the generating job Pod
## @param jwtKeys.job.tolerations Tolerations for the generating job Pod
## @param jwtKeys.job.affinity Affinity for the generating job Pod
## @param jwtKeys.job.serviceAccountName Service account of the generating job Pod, the one created above when empty
## @skip jwtKeys.job.env
job:
podSecurityContext: {}
# neither image declares a user of its own, and kubernetes refuses to start
# a container asking for runAsNonRoot without knowing which user to run as
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
seccompProfile:
type: RuntimeDefault
restartPolicy: Never
backoffLimit: 2
ttlSecondsAfterFinished: 30
generateCommand: []
publishCommand: []
annotations: {}
podAnnotations: {}
resources: {}
nodeSelector: {}
tolerations: []
affinity: {}
serviceAccountName: null
env: []
## @section yhub
##
## The collaboration server: it serves the whole /collaboration/ prefix, the
## websocket included, and replaces the y-provider on that role. It keeps the
## live state of a document in redis/valkey and persists it to its own
## PostgreSQL database, so it needs both — set `yhub.envVars.REDIS` and
## `yhub.envVars.POSTGRES`, there is nothing sensible to default them to.
## Disabling it sends the /collaboration/ ingresses back to the y-provider.
##
## Two buckets can be added to that list, each with a prefix of its own so that
## none of them is ambiguous — they may sit on different providers, with
## different credentials, and are read by different processes:
##
## - `LEGACY_S3_*`, turned on by `SOFT_MIGRATION`, is the legacy Django media
## bucket it reads old documents *out of*. Not the backend's `AWS_S3_*`,
## which names the same bucket for the backend's own use,
## - `YHUB_S3_*`, turned on by `YHUB_S3_PERSISTENCE`, is a bucket of its own it
## stores the document blobs *into*, instead of its PostgreSQL database.
## Read `src/yhub-server/README.md` before enabling it: a document persisted
## this way cannot be read back once the setting is removed.
yhub:
## @param yhub.enabled Enable the yhub collaboration server, its service and its init-db job
enabled: true
## @param yhub.image.repository Repository to use to pull the yhub container image
## @param yhub.image.tag yhub container tag
## @param yhub.image.pullPolicy yhub container image pull policy
image:
repository: lasuite/impress-yhub
pullPolicy: IfNotPresent
tag: "latest"
## @param yhub.command Override the yhub container command
command: []
## @param yhub.args Override the yhub container args
args: []
## @param yhub.replicas Amount of yhub replicas
## Clients editing the same document need not land on the same pod: updates
## travel through redis. Each replica also runs a worker unless the worker is
## deployed apart, see below.
replicas: 3
## @param yhub.worker.enabled Deploy the worker apart from the server, each scaling on its own
## @param yhub.worker.replicas Amount of yhub worker replicas
## @param yhub.worker.resources Resource requirements for the yhub worker container, the server ones when empty
## @param yhub.worker.podAnnotations Annotations to add to the yhub worker Pod, the server ones when empty
## @param yhub.worker.dpAnnotations Annotations to add to the yhub worker Deployment, the server ones when empty
## @param yhub.worker.nodeSelector Node selector for the yhub worker Pod, the server one when empty
## @param yhub.worker.tolerations Tolerations for the yhub worker Pod, the server ones when empty
## @param yhub.worker.affinity Affinity for the yhub worker Pod, the server one when empty
## @param yhub.worker.terminationGracePeriodSeconds Grace period given to a worker pod to finish its task, the server one when empty
## @param yhub.worker.pdb.enabled Enable pdb on the yhub worker
## @skip yhub.worker.envVars Environment variables of the worker only, on top of yhub.envVars
##
## yhub is two halves sharing nothing but redis and postgres: the server
## holds the websockets and serves the routes, the worker drains the stream
## into postgres. One process runs both by default. Enabling this splits them
## into two deployments — `YHUB_ROLE=server` and `YHUB_ROLE=worker`, the only
## difference between them — so the server scales with the connected editors
## and the worker with the write throughput.
##
## The worker binds nothing: no service, no ingress, and no probes to give it
## (its liveness is its process). Everything not named here is the server's:
## same image, same envVars, same secrets, same volumes.
##
## How much each pod chews through is `worker.envVars.YHUB_TASK_CONCURRENCY`
## (default 5, and `yhub.envVars` when the two halves share a process), the
## other half of the throughput knob `worker.replicas` is: redis hands each
## task to a single worker, so the two multiply.
worker:
enabled: false
replicas: 1
envVars: {}
resources: {}
podAnnotations: {}
dpAnnotations: {}
nodeSelector: {}
tolerations: []
affinity: {}
terminationGracePeriodSeconds: null
pdb:
enabled: true
## @param yhub.shareProcessNamespace Enable share process namespace between containers
shareProcessNamespace: false
## @param yhub.sidecars Add sidecars containers to yhub deployment
sidecars: []
## @param yhub.terminationGracePeriodSeconds Grace period given to a yhub pod to drain before it is killed
terminationGracePeriodSeconds: 60
## @param yhub.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the yhub container
## @param yhub.securityContext.capabilities.drop List of capabilities to drop for the yhub container
## @param yhub.securityContext.runAsNonRoot Whether to run the yhub container as a non-root user
## @param yhub.securityContext.runAsUser User the yhub container runs as
## @param yhub.securityContext.runAsGroup Group the yhub container runs as
## @param yhub.securityContext.seccompProfile.type Seccomp profile type for the yhub container
##
## The user is named rather than left to the image: asking for runAsNonRoot
## without it is refused outright by kubernetes ("container has runAsNonRoot
## and image will run as root") on any image that declares none — which every
## yhub image built before the un-privileged user was added to its Dockerfile
## does. 1000 is the `node` user the base image already carries.
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
seccompProfile:
type: RuntimeDefault
## @param yhub.envVars Configure yhub container environment variables
## @extra yhub.envVars.REDIS Required, redis/valkey url holding the live document state (e.g. redis://valkey:6379/0)
## @extra yhub.envVars.POSTGRES Required, url of the yhub database, created by the init-db job (e.g. postgres://user:pass@postgres:5432/yhub)
## @extra yhub.envVars.REDIS_PREFIX Namespace of the redis keys, when the instance is shared (default: yhub)
## @extra yhub.envVars.COLLABORATION_BACKEND_BASE_URL Base url of the Docs backend, which yhub asks about users and document access rights
## @extra yhub.envVars.COLLABORATION_SERVER_ORIGIN Comma separated list of the origins allowed to open a websocket
## @extra yhub.envVars.YHUB_JWT_PRIVATE_KEY_FILE Path to the RSA private key (PEM) yhub signs its calls to the backend with, mounted from a secret
## @extra yhub.envVars.YHUB_TASK_CONCURRENCY Tasks one worker process claims at once, times the replicas running a worker (default: 5)
## @extra yhub.envVars.YHUB_TASK_DEBOUNCE_MS How long an update waits on the redis stream before a worker persists it, in ms (default: 10000)
## @extra yhub.envVars.YHUB_MIN_MESSAGE_LIFETIME_MS How long persisted updates stay replayable from redis, in ms (default: 60000)
## @extra yhub.envVars.SOFT_MIGRATION Set to "true" to seed rooms from the legacy Django/S3 document store on first access
## @extra yhub.envVars.LEGACY_S3_ENDPOINT_URL Required by SOFT_MIGRATION, endpoint of the legacy Django media bucket, without a path (e.g. https://s3.example.com)
## @extra yhub.envVars.LEGACY_S3_ACCESS_KEY_ID Required by SOFT_MIGRATION, read access to the legacy bucket (or LEGACY_S3_ACCESS_KEY_ID_FILE)
## @extra yhub.envVars.LEGACY_S3_SECRET_ACCESS_KEY Required by SOFT_MIGRATION, secret of the key above (or LEGACY_S3_SECRET_ACCESS_KEY_FILE)
## @extra yhub.envVars.LEGACY_S3_REGION_NAME Region of the legacy bucket, when its provider needs one
## @extra yhub.envVars.LEGACY_S3_BUCKET_NAME Name of the legacy Django media bucket (default: impress-media-storage)
## @extra yhub.envVars.LEGACY_S3_SIGNATURE_VERSION How the calls to the legacy bucket are signed, s3v4 or v4 (default: s3v4)
## @extra yhub.envVars.YHUB_S3_PERSISTENCE Set to "true" to store the document blobs in a bucket instead of the yhub database — read src/yhub-server/README.md first, it cannot be turned back off
## @extra yhub.envVars.YHUB_S3_ENDPOINT_URL Required by YHUB_S3_PERSISTENCE, endpoint of the bucket the blobs are stored in, without a path (e.g. https://s3.example.com)
## @extra yhub.envVars.YHUB_S3_ACCESS_KEY_ID Required by YHUB_S3_PERSISTENCE, read/write/delete access to that bucket (or YHUB_S3_ACCESS_KEY_ID_FILE)
## @extra yhub.envVars.YHUB_S3_SECRET_ACCESS_KEY Required by YHUB_S3_PERSISTENCE, secret of the key above (or YHUB_S3_SECRET_ACCESS_KEY_FILE)
## @extra yhub.envVars.YHUB_S3_BUCKET_NAME Required by YHUB_S3_PERSISTENCE, name of that bucket, created on startup when missing
## @extra yhub.envVars.YHUB_S3_REGION_NAME Region of that bucket, when its provider needs one
## @extra yhub.envVars.BY_VALUE Example environment variable by setting value directly
## @extra yhub.envVars.FROM_CONFIGMAP.configMapKeyRef.name Name of a ConfigMap when configuring env vars from a ConfigMap
## @extra yhub.envVars.FROM_CONFIGMAP.configMapKeyRef.key Key within a ConfigMap when configuring env vars from a ConfigMap
## @extra yhub.envVars.FROM_SECRET.secretKeyRef.name Name of a Secret when configuring env vars from a Secret
## @extra yhub.envVars.FROM_SECRET.secretKeyRef.key Key within a Secret when configuring env vars from a Secret
## @skip yhub.envVars
envVars:
<<: *commonEnvVars
## @skip yhub.envFrom List of environment variables taken from Secrets or configMaps
envFrom: []
# envFrom:
# - secret:
# name: super-secret-user-credentials
# - configMapRef:
# name: my-environment-variables
## @param yhub.podAnnotations Annotations to add to the yhub Pod
podAnnotations: {}
## @param yhub.dpAnnotations Annotations to add to the yhub Deployment
dpAnnotations: {}
## @param yhub.initDbJobAnnotations Annotations for the yhub init-db job
initDbJobAnnotations: {}
## @param yhub.jobs.ttlSecondsAfterFinished Period to wait before removing the init-db job
## @param yhub.jobs.backoffLimit Numbers of init-db job retries
jobs:
ttlSecondsAfterFinished: 30
backoffLimit: 2
## @param yhub.initDb.enabled Run the job creating and upgrading the yhub schema
## @param yhub.initDb.command Override the command creating and upgrading the yhub schema
## @param yhub.initDb.retries How many times the schema script is retried while the postgres server does not answer
## @param yhub.initDb.retryDelaySeconds Seconds between two attempts
## @param yhub.initDb.restartPolicy Restart policy of the init-db job
## @skip yhub.initDb.resources Resource requirements for the init-db container, defaults to yhub.resources
##
## The job runs in the default sync wave, next to the backend migrate job,
## and waits for its database the same way that one waits for Django's:
## nothing in this chart creates the postgres server, so it has to be given
## the time whatever does takes. The defaults below wait five minutes.
initDb:
enabled: true
command: []
retries: 60
retryDelaySeconds: 5
restartPolicy: Never
resources: {}
## @param yhub.service.type yhub Service type
## @param yhub.service.port yhub Service listening port
## @param yhub.service.targetPort yhub container listening port
## @param yhub.service.annotations Annotations to add to the yhub Service
service:
type: ClusterIP
port: 443
targetPort: 3002
annotations: {}
## @param yhub.probes.liveness.path Configure path for yhub HTTP liveness probe
## @param yhub.probes.liveness.initialDelaySeconds Configure initial delay for yhub liveness probe
## @param yhub.probes.liveness.timeoutSeconds Configure timeout for yhub liveness probe
## @param yhub.probes.readiness.path Configure path for yhub HTTP readiness probe
## @param yhub.probes.readiness.initialDelaySeconds Configure initial delay for yhub readiness probe
## @param yhub.probes.readiness.timeoutSeconds Configure timeout for yhub readiness probe
## @extra yhub.probes.liveness.targetPort Configure port for yhub HTTP liveness probe
## @extra yhub.probes.readiness.targetPort Configure port for yhub HTTP readiness probe
## @extra yhub.probes.startup.path Configure path for yhub HTTP startup probe
## @extra yhub.probes.startup.targetPort Configure port for yhub HTTP startup probe
## @extra yhub.probes.startup.initialDelaySeconds Configure initial delay for yhub startup probe
## @extra yhub.probes.startup.timeoutSeconds Configure timeout for yhub startup probe
##
## Two routes yhub serves unauthenticated, and they answer different
## questions on purpose:
##
## - `ping` returns 200 without touching anything. Being answered at all is
## the proof the http channel and the event loop are alive, which is as far
## as a liveness probe should ever go: restarting a server over a store it
## does not reach would drop the websockets it is happily serving.
## - `ready` asks postgres and redis whether they answer, and returns 503
## when either does not. That takes the pod out of the service endpoints
## and leaves its siblings serving, which is what readiness is for. Its
## timeout is above the two seconds the server itself gives each store, so
## an unreachable one is reported rather than cut off.
probes:
liveness:
path: /collaboration/ping/v1
initialDelaySeconds: 10
timeoutSeconds: 2
readiness:
path: /collaboration/ready/v1
initialDelaySeconds: 5
timeoutSeconds: 3
## @param yhub.resources Resource requirements for the yhub container
resources: {}
## @param yhub.nodeSelector Node selector for the yhub Pod
nodeSelector: {}
## @param yhub.tolerations Tolerations for the yhub Pod
tolerations: []
## @param yhub.affinity Affinity for the yhub Pod
affinity: {}
## @param yhub.persistence Additional volumes to create and mount on the yhub. Used for debugging purposes
## @extra yhub.persistence.volume-name.size Size of the additional volume
## @extra yhub.persistence.volume-name.type Type of the additional volume, persistentVolumeClaim or emptyDir
## @extra yhub.persistence.volume-name.mountPath Path where the volume should be mounted to
persistence: {}
## @param yhub.extraVolumeMounts Additional volumes to mount on the yhub. Mounted on the init-db job too
extraVolumeMounts: []
## @param yhub.extraVolumes Additional volumes to mount on the yhub. Mounted on the init-db job too
extraVolumes: []
## @param yhub.pdb.enabled Enable pdb on yhub
pdb:
enabled: true
## @param yhub.serviceAccountName Optional service account name to use for yhub pods
serviceAccountName: null
## @section docSpec
docSpec:
## @param docSpec.enabled Enable docSpec deployment
enabled: false
## @param docSpec.image.repository Repository to use to pull docSpec container image
## @param docSpec.image.tag docSpec container tag
## @param docSpec.image.pullPolicy docSpec container image pull policy
image:
repository: ghcr.io/docspecio/api
pullPolicy: IfNotPresent
tag: "3.0.1"
## @param docSpec.command Override the docSpec container command
command: []
## @param docSpec.args Override the docSpec container args
args: []
## @param docSpec.replicas Amount of docSpec replicas
replicas: 1
## @param docSpec.securityContext.allowPrivilegeEscalation Whether to allow privilege escalation for the docSpec container
## @param docSpec.securityContext.capabilities.drop List of capabilities to drop for the docSpec container
## @param docSpec.securityContext.runAsNonRoot Whether to run the docSpec container as a non-root user
## @param docSpec.securityContext.seccompProfile.type Seccomp profile type for the docSpec container
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- "ALL"
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
## @param docSpec.envVars Configure docSpec container environment variables
envVars: {}
## @skip docSpec.envFrom List of environment variables taken from Secrets or configMaps
envFrom: []
# envFrom:
# - secret:
# name: super-secret-user-credentials
# - configMapRef:
# name: my-environment-variables
## @param docSpec.service.type docSpec Service type
## @param docSpec.service.port docSpec Service listening port
## @param docSpec.service.targetPort docSpec container listening port
service:
type: ClusterIP
port: 4000
targetPort: 4000
## @param docSpec.probes.liveness.path Configure path for docSpec HTTP liveness probe
## @param docSpec.probes.readiness.path Configure path for docSpec HTTP readiness probe
probes:
liveness:
path: /health
readiness:
path: /health
## @param docSpec.resources docSpec resources
resources: {}
## @param docSpec.nodeSelector Node selector for the docSpec Pod
nodeSelector: {}
## @param docSpec.tolerations Tolerations for the docSpec Pod
tolerations: []
## @param docSpec.affinity Affinity for the docSpec Pod
affinity: {}
## @param docSpec.extraVolumeMounts Additional volumes to mount on docSpec
extraVolumeMounts: []
## @param docSpec.extraVolumes Additional volumes to mount on docSpec
extraVolumes: []