Two Ingresses claim forgejo.riotpiao.com and nginx honours the older chart one, so the annotation on the other never applied and OCI pushes over 1m got 413.
135 lines
3.7 KiB
YAML
135 lines
3.7 KiB
YAML
# Forgejo Helm Values — Single Source of Truth
|
|
# Chart: https://codeberg.org/forgejo-contrib/forgejo-helm
|
|
|
|
# Recreate (not RollingUpdate): the gitea data volume is a single RWO PVC. With
|
|
# RollingUpdate the new pod tries to attach the PVC while the old pod still holds
|
|
# it -> "Multi-Attach error", new pod stuck Init forever, rollout wedged. Recreate
|
|
# terminates the old pod first so the PVC detaches before the new one starts.
|
|
strategy:
|
|
type: Recreate
|
|
|
|
# Disable bundled dependencies (use external CNPG + Redis instead)
|
|
postgresql-ha:
|
|
enabled: false
|
|
|
|
valkey:
|
|
enabled: false
|
|
|
|
valkey-cluster:
|
|
enabled: false
|
|
|
|
redis:
|
|
enabled: false
|
|
|
|
# External SSH access for git over the LAN. The chart's ssh Service becomes a
|
|
# LoadBalancer with a stable IP from the Cilium homelab-pool (192.168.1.160/28,
|
|
# L2-announced) so `git clone ssh://[email protected]:2222/...` works from the
|
|
# LAN. gitea's sshd listens on 2222 in-pod; port 2222 is exposed directly to
|
|
# avoid needing privileged :22.
|
|
service:
|
|
ssh:
|
|
type: LoadBalancer
|
|
port: 2222
|
|
annotations:
|
|
lbipam.cilium.io/ips: "192.168.1.161"
|
|
|
|
gitea:
|
|
admin:
|
|
existingSecret: forgejo-admin
|
|
|
|
config:
|
|
server:
|
|
DOMAIN: forgejo.riotpiao.com
|
|
ROOT_URL: https://forgejo.riotpiao.com
|
|
# SSH clone URLs advertise git.riotpiao.com:2222 (the LoadBalancer above).
|
|
SSH_DOMAIN: git.riotpiao.com
|
|
SSH_PORT: 2222
|
|
SSH_LISTEN_PORT: 2222
|
|
|
|
database:
|
|
DB_TYPE: postgres
|
|
HOST: forgejo-db-rw.cicd.svc.cluster.local:5432
|
|
NAME: forgejo
|
|
# User/password injected via extraEnv (secretKeyRef doesn't work in config)
|
|
|
|
cache:
|
|
ADAPTER: redis
|
|
HOST: redis://forgejo-redis.cicd.svc.cluster.local:6379/0
|
|
|
|
session:
|
|
PROVIDER: redis
|
|
PROVIDER_CONFIG: redis://forgejo-redis.cicd.svc.cluster.local:6379/1
|
|
|
|
queue:
|
|
TYPE: redis
|
|
CONN_STR: redis://forgejo-redis.cicd.svc.cluster.local:6379/2
|
|
|
|
# Persistence (shared storage for repos)
|
|
persistence:
|
|
enabled: true
|
|
storageClass: longhorn
|
|
size: 20Gi
|
|
accessModes:
|
|
- ReadWriteOnce
|
|
|
|
# Ingress
|
|
ingress:
|
|
enabled: true
|
|
className: nginx
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
|
# This chart Ingress and the hand-written one in
|
|
# k8s/bootstrap/ingress/ingress.yaml both claim forgejo.riotpiao.com.
|
|
# ingress-nginx breaks the tie by oldest creationTimestamp, and the chart's
|
|
# is older, so it is the one actually serving — the annotations on the other
|
|
# have never applied. Duplicate should be removed; until then these must
|
|
# live here or they do nothing.
|
|
#
|
|
# proxy-body-size 0 is required for the OCI registry: nginx defaults to 1m,
|
|
# so any image layer above that fails the push with 413.
|
|
nginx.ingress.kubernetes.io/proxy-body-size: "0"
|
|
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
|
|
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
|
|
hosts:
|
|
- host: forgejo.riotpiao.com
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
tls:
|
|
- secretName: forgejo-tls
|
|
hosts:
|
|
- forgejo.riotpiao.com
|
|
|
|
# Resources
|
|
resources:
|
|
requests:
|
|
cpu: 200m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: 1000m
|
|
memory: 2Gi
|
|
|
|
# Tolerations for control-plane
|
|
tolerations:
|
|
- key: node-role.kubernetes.io/control-plane
|
|
operator: Exists
|
|
effect: NoSchedule
|
|
|
|
# ArgoCD adoption labels
|
|
labels:
|
|
argocd.argoproj.io/instance: forgejo
|
|
|
|
# Inject database credentials via environment variables (overrides app.ini)
|
|
deployment:
|
|
env:
|
|
- name: GITEA__DATABASE__USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: forgejo-db-app
|
|
key: username
|
|
- name: GITEA__DATABASE__PASSWD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: forgejo-db-app
|
|
key: password
|