# Forgejo Helm Values — Single Source of Truth # Chart: https://codeberg.org/forgejo-contrib/forgejo-helm # Disable bundled dependencies (use external CNPG + Redis instead) postgresql-ha: enabled: false valkey: enabled: false valkey-cluster: enabled: false redis: enabled: false # External SSH access for git over the LAN. The chart's ssh Service becomes a # LoadBalancer with a stable IP from the Cilium homelab-pool (192.168.1.160/28, # L2-announced) so `git clone ssh://git@git.riotpiao.com:2222/...` works from the # LAN. gitea's sshd listens on 2222 in-pod; port 2222 is exposed directly to # avoid needing privileged :22. service: ssh: type: LoadBalancer port: 2222 annotations: lbipam.cilium.io/ips: "192.168.1.161" gitea: admin: existingSecret: forgejo-admin config: server: DOMAIN: forgejo.riotpiao.com ROOT_URL: https://forgejo.riotpiao.com # SSH clone URLs advertise git.riotpiao.com:2222 (the LoadBalancer above). SSH_DOMAIN: git.riotpiao.com SSH_PORT: 2222 SSH_LISTEN_PORT: 2222 database: DB_TYPE: postgres HOST: forgejo-db-rw.cicd.svc.cluster.local:5432 NAME: forgejo # User/password injected via extraEnv (secretKeyRef doesn't work in config) cache: ADAPTER: redis HOST: redis://forgejo-redis.cicd.svc.cluster.local:6379/0 session: PROVIDER: redis PROVIDER_CONFIG: redis://forgejo-redis.cicd.svc.cluster.local:6379/1 queue: TYPE: redis CONN_STR: redis://forgejo-redis.cicd.svc.cluster.local:6379/2 # Persistence (shared storage for repos) persistence: enabled: true storageClass: longhorn size: 20Gi accessModes: - ReadWriteOnce # Ingress ingress: enabled: true className: nginx annotations: cert-manager.io/cluster-issuer: letsencrypt-prod hosts: - host: forgejo.riotpiao.com paths: - path: / pathType: Prefix tls: - secretName: forgejo-tls hosts: - forgejo.riotpiao.com # Resources resources: requests: cpu: 200m memory: 512Mi limits: cpu: 1000m memory: 2Gi # Tolerations for control-plane tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists effect: NoSchedule # ArgoCD adoption labels labels: argocd.argoproj.io/instance: forgejo # Inject database credentials via environment variables (overrides app.ini) deployment: env: - name: GITEA__DATABASE__USER valueFrom: secretKeyRef: name: forgejo-db-app key: username - name: GITEA__DATABASE__PASSWD valueFrom: secretKeyRef: name: forgejo-db-app key: password