- Fix ArgoCD Application schema: move syncOptions under syncPolicy (00-secrets.yaml) - Remove helm install --wait flag (talos-cp-2 slow node timeout issue) - Add comprehensive progress logging with timestamps to bootstrap.sh - Fix SOPS key path (/Users/rockliang/.sops/key.txt, not homelab-age.key) - Add local SOPS decryption for bootstrap secrets - Add CNPG NetworkPolicy allowing app→database connectivity - Disable Forgejo bundled dependencies (saves 66Gi storage) - Inject database credentials via deployment.env (GITEA__DATABASE__*) - Remove invalid ext4 mount options from StorageClass - Add namespace manifests with PodSecurity labels - Add encrypted forgejo-admin secret (SOPS) - Reduce forgejo-db size 50Gi→25Gi per instance - Prepare ArgoCD SOPS CMP plugin (for post-bootstrap)
102 lines
2.1 KiB
YAML
102 lines
2.1 KiB
YAML
# Forgejo Helm Values — Single Source of Truth
|
|
# Chart: https://codeberg.org/forgejo-contrib/forgejo-helm
|
|
|
|
# Disable bundled dependencies (use external CNPG + Redis instead)
|
|
postgresql-ha:
|
|
enabled: false
|
|
|
|
valkey:
|
|
enabled: false
|
|
|
|
valkey-cluster:
|
|
enabled: false
|
|
|
|
redis:
|
|
enabled: false
|
|
|
|
gitea:
|
|
admin:
|
|
existingSecret: forgejo-admin
|
|
|
|
config:
|
|
server:
|
|
DOMAIN: forgejo.riotpiao.com
|
|
ROOT_URL: https://forgejo.riotpiao.com
|
|
SSH_DOMAIN: forgejo.riotpiao.com
|
|
SSH_PORT: 22
|
|
|
|
database:
|
|
DB_TYPE: postgres
|
|
HOST: forgejo-db-rw.cicd.svc.cluster.local:5432
|
|
NAME: forgejo
|
|
# User/password injected via extraEnv (secretKeyRef doesn't work in config)
|
|
|
|
cache:
|
|
ADAPTER: redis
|
|
HOST: redis://forgejo-redis.cicd.svc.cluster.local:6379/0
|
|
|
|
session:
|
|
PROVIDER: redis
|
|
PROVIDER_CONFIG: redis://forgejo-redis.cicd.svc.cluster.local:6379/1
|
|
|
|
queue:
|
|
TYPE: redis
|
|
CONN_STR: redis://forgejo-redis.cicd.svc.cluster.local:6379/2
|
|
|
|
# Persistence (shared storage for repos)
|
|
persistence:
|
|
enabled: true
|
|
storageClass: longhorn
|
|
size: 20Gi
|
|
accessModes:
|
|
- ReadWriteOnce
|
|
|
|
# Ingress
|
|
ingress:
|
|
enabled: true
|
|
className: nginx
|
|
annotations:
|
|
cert-manager.io/cluster-issuer: letsencrypt-prod
|
|
hosts:
|
|
- host: forgejo.riotpiao.com
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
tls:
|
|
- secretName: forgejo-tls
|
|
hosts:
|
|
- forgejo.riotpiao.com
|
|
|
|
# Resources
|
|
resources:
|
|
requests:
|
|
cpu: 200m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: 1000m
|
|
memory: 2Gi
|
|
|
|
# Tolerations for control-plane
|
|
tolerations:
|
|
- key: node-role.kubernetes.io/control-plane
|
|
operator: Exists
|
|
effect: NoSchedule
|
|
|
|
# ArgoCD adoption labels
|
|
labels:
|
|
argocd.argoproj.io/instance: forgejo
|
|
|
|
# Inject database credentials via environment variables (overrides app.ini)
|
|
deployment:
|
|
env:
|
|
- name: GITEA__DATABASE__USER
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: forgejo-db-app
|
|
key: username
|
|
- name: GITEA__DATABASE__PASSWD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: forgejo-db-app
|
|
key: password
|