# k8s/security/ci-cd/forgejo-values.yaml # Forgejo deployed via the gitea-charts/gitea Helm chart with image override, # as an ArgoCD Application with an inline Helm source (k8s/argocd/apps/forgejo.yaml). # Admin password set via --set at install time (FORGEJO_ADMIN_PASSWORD in .env). # DB: CNPG (k8s/data/ddb-cluster.yaml + forgejo-database.yaml), not SQLite. # Cache/session/queue: dedicated Redis (forgejo-redis.yaml), not in-memory — # required once replicaCount > 1, since in-memory state isn't shared across pods. # # Chart docs: https://gitea.com/gitea/helm-chart # ── Image (Forgejo replaces Gitea — drop-in compatible) ────────────────────── image: repository: codeberg.org/forgejo/forgejo tag: "13" # pin exact release — check codeberg.org/forgejo/forgejo/releases pullPolicy: IfNotPresent # ── Bootstrap admin (provisioned by a post-install Job inside the chart) ────── gitea: admin: username: rock email: locartrock@gmail.com # password: injected via helmfile --set (FORGEJO_ADMIN_PASSWORD from .env) config: server: PROTOCOL: http # nginx ingress handles TLS; pod serves plain HTTP DOMAIN: forgejo.riotpiao.com ROOT_URL: https://forgejo.riotpiao.com/ HTTP_PORT: 3000 START_SSH_SERVER: true SSH_DOMAIN: forgejo.riotpiao.com SSH_PORT: 2222 SSH_LISTEN_PORT: 2222 database: DB_TYPE: postgres HOST: ddb-cluster-rw.ddb.svc:5432 NAME: forgejo USER: app repository: ROOT: /data/git actions: ENABLED: true packages: ENABLED: true # built-in OCI registry metrics: ENABLED: true # Prometheus at /metrics service: DISABLE_REGISTRATION: true # no self-signup; Authentik OAuth2 auto-creates accounts oauth2: ENABLED: true PROVIDER: openidconnect OPENID_CONNECT_DISCOVERY_URL: https://authentik.riotpiao.com/application/o/forgejo/.well-known/openid-configuration CLIENT_ID: forgejo AUTO_DISCOVER_URL: https://authentik.riotpiao.com/application/o/forgejo/.well-known/openid-configuration cache: ADAPTER: redis HOST: redis://forgejo-redis.cicd.svc:6379/0 session: PROVIDER: redis PROVIDER_CONFIG: redis://forgejo-redis.cicd.svc:6379/1 queue: TYPE: redis CONN_STR: redis://forgejo-redis.cicd.svc:6379/2 metrics: enabled: true serviceMonitor: enabled: true # kube-prometheus-stack discovers ServiceMonitors cluster-wide # ── Persistence (Longhorn RWX — git repo data shared across replicas) ──────── persistence: enabled: true storageClass: longhorn size: 20Gi accessModes: - ReadWriteMany # ── Replicas ────────────────────────────────────────────────────────────────── # Postgres (CNPG) + Redis (session/cache/queue) + RWX storage means replicas # no longer need to serialize on a single pod like the old SQLite setup did. replicaCount: 2 # ── Deployment strategy ──────────────────────────────────────────────────────── deployment: strategy: type: RollingUpdate env: - name: SSL_CERT_DIR value: /homelab-ca - name: GITEA__database__PASSWD valueFrom: secretKeyRef: name: ddb-cluster-app key: password # ── Cert / CA auto-reload ───────────────────────────────────────────────────── # nginx serves the wildcard-tls cert — Forgejo itself never reads a TLS secret. # The only reload trigger is homelab-ca: if the root CA rotates, the mounted # ConfigMap changes and Forgejo must restart to pick up the new CA bundle for OIDC. podAnnotations: configmap.reloader.stakater.com/reload: "homelab-ca" # ── Services (Cilium LB-IPAM pins both to 192.168.1.165) ───────────────────── service: http: type: LoadBalancer port: 3000 targetPort: 3000 annotations: io.cilium/lb-ipam-ips: "192.168.1.165" io.cilium/lb-ipam-sharing-key: "forgejo" ssh: type: LoadBalancer port: 2222 targetPort: 2222 annotations: io.cilium/lb-ipam-ips: "192.168.1.165" io.cilium/lb-ipam-sharing-key: "forgejo" # ── Resources ───────────────────────────────────────────────────────────────── resources: requests: cpu: 250m memory: 512Mi limits: cpu: "1" memory: 1Gi # ── Node resilience ─────────────────────────────────────────────────────────── tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists effect: NoSchedule # ── CA trust ───────────────────────────────────────────────────────────────── # Go reads SSL_CERT_DIR as an additional cert directory ON TOP OF the default # cert files (ca-certificates.crt stays intact — no init container needed). # Setting SSL_CERT_DIR=/homelab-ca makes Go also read homelab-ca.crt from there, # trusting both the standard Mozilla bundle and our homelab CA. # Required for OIDC: Forgejo fetches Authentik's discovery endpoint which # presents a cert signed by homelab-ca. extraVolumes: - name: homelab-ca configMap: name: homelab-ca extraVolumeMounts: - name: homelab-ca mountPath: /homelab-ca readOnly: true # ── Ingress: disabled — rule lives in k8s/ingress/ingress.yaml ─────────────── ingress: enabled: false # ── Bundled databases + cache: all disabled — SQLite + memory is the chosen backend ── postgresql: enabled: false postgresql-ha: enabled: false mysql: enabled: false redis-cluster: enabled: false # 6-node cluster is overkill for single-replica SQLite Forgejo # ── Act runner subchart: disabled — managed by the forgejo-runner helmfile release act_runner: enabled: false