# Forgejo Helm Values — Single Source of Truth # Chart: https://codeberg.org/forgejo-contrib/forgejo-helm # Recreate (not RollingUpdate): the gitea data volume is a single RWO PVC. With # RollingUpdate the new pod tries to attach the PVC while the old pod still holds # it -> "Multi-Attach error", new pod stuck Init forever, rollout wedged. Recreate # terminates the old pod first so the PVC detaches before the new one starts. strategy: type: Recreate # Disable bundled dependencies (use external CNPG + Redis instead) postgresql-ha: enabled: false valkey: enabled: false valkey-cluster: enabled: false redis: enabled: false # External SSH access for git over the LAN. The chart's ssh Service becomes a # LoadBalancer with a stable IP from the Cilium homelab-pool (192.168.1.160/28, # L2-announced) so `git clone ssh://git@git.riotpiao.com:2222/...` works from the # LAN. gitea's sshd listens on 2222 in-pod; port 2222 is exposed directly to # avoid needing privileged :22. service: ssh: type: LoadBalancer port: 2222 annotations: lbipam.cilium.io/ips: "192.168.1.161" gitea: admin: existingSecret: forgejo-admin config: server: DOMAIN: forgejo.riotpiao.com ROOT_URL: https://forgejo.riotpiao.com # SSH clone URLs advertise git.riotpiao.com:2222 (the LoadBalancer above). SSH_DOMAIN: git.riotpiao.com SSH_PORT: 2222 SSH_LISTEN_PORT: 2222 database: DB_TYPE: postgres HOST: forgejo-db-rw.cicd.svc.cluster.local:5432 NAME: forgejo # User/password injected via extraEnv (secretKeyRef doesn't work in config) cache: ADAPTER: redis HOST: redis://forgejo-redis.cicd.svc.cluster.local:6379/0 session: PROVIDER: redis PROVIDER_CONFIG: redis://forgejo-redis.cicd.svc.cluster.local:6379/1 queue: TYPE: redis CONN_STR: redis://forgejo-redis.cicd.svc.cluster.local:6379/2 # Actions must be enabled globally, not just per-repo. Without this section # app.ini carries no [actions] block at all and Forgejo never *creates* a # workflow run — the API returns total_count: 0 for every repo even though # each repo reports has_actions: true, the workflow file is on the default # branch, and forgejo-runner has registered successfully with label # [docker]. Registration does not require the dispatcher, so a healthy- # looking runner sitting at "[poller 0] launched" with zero task pickups is # the symptom of this being off, not of a bad workflow or a label mismatch. # # DEFAULT_ACTIONS_URL is left at its default (https://code.forgejo.org), # which is where `uses: actions/checkout@v4` and friends resolve from. That # requires egress from the runner; if it is ever blocked, pin the actions to # local copies rather than turning this off. actions: ENABLED: true # Persistence (shared storage for repos) persistence: enabled: true storageClass: longhorn size: 20Gi accessModes: - ReadWriteOnce # Ingress ingress: enabled: true className: nginx annotations: cert-manager.io/cluster-issuer: letsencrypt-prod # This chart Ingress and the hand-written one in # k8s/bootstrap/ingress/ingress.yaml both claim forgejo.riotpiao.com. # ingress-nginx breaks the tie by oldest creationTimestamp, and the chart's # is older, so it is the one actually serving — the annotations on the other # have never applied. Duplicate should be removed; until then these must # live here or they do nothing. # # proxy-body-size 0 is required for the OCI registry: nginx defaults to 1m, # so any image layer above that fails the push with 413. nginx.ingress.kubernetes.io/proxy-body-size: "0" nginx.ingress.kubernetes.io/proxy-read-timeout: "3600" nginx.ingress.kubernetes.io/proxy-send-timeout: "3600" hosts: - host: forgejo.riotpiao.com paths: - path: / pathType: Prefix tls: - secretName: forgejo-tls hosts: - forgejo.riotpiao.com # Resources resources: requests: cpu: 200m memory: 512Mi limits: cpu: 1000m memory: 2Gi # Tolerations for control-plane tolerations: - key: node-role.kubernetes.io/control-plane operator: Exists effect: NoSchedule # ArgoCD adoption labels labels: argocd.argoproj.io/instance: forgejo # Inject database credentials via environment variables (overrides app.ini) deployment: env: - name: GITEA__DATABASE__USER valueFrom: secretKeyRef: name: forgejo-db-app key: username - name: GITEA__DATABASE__PASSWD valueFrom: secretKeyRef: name: forgejo-db-app key: password