From 8030104c02b044a88ba3ef5897dc3b81f75c7d25 Mon Sep 17 00:00:00 2001 From: Maidul Islam Date: Mon, 14 Aug 2023 15:02:22 -0400 Subject: [PATCH] update helm read me with redis config details --- helm-charts/infisical/README.md | 75 ++++++++++---------- helm-charts/infisical/templates/_helpers.tpl | 30 -------- helm-charts/infisical/values.yaml | 15 ++-- 3 files changed, 49 insertions(+), 71 deletions(-) diff --git a/helm-charts/infisical/README.md b/helm-charts/infisical/README.md index e614d9600..de001d4f7 100644 --- a/helm-charts/infisical/README.md +++ b/helm-charts/infisical/README.md @@ -7,6 +7,7 @@ This is the Infisical application Helm chart. This chart includes the following | `frontend` | Infisical's Web UI | | `backend` | Infisical's API | | `mongodb` | Infisical's database | +| `redis` | Infisical's cache service | | `mailhog` | Infisical's development SMTP server | ## Installation @@ -58,7 +59,6 @@ kubectl get secrets -n \ | `nameOverride` | Override release name | `""` | | `fullnameOverride` | Override release fullname | `""` | - ### Infisical frontend parameters | Name | Description | Value | @@ -78,41 +78,41 @@ kubectl get secrets -n \ | `frontend.service.nodePort` | Backend service nodePort (used if above type is `NodePort`) | `""` | | `frontendEnvironmentVariables.SITE_URL` | Absolute URL including the protocol (e.g. https://app.infisical.com) | `infisical.local` | - ### Infisical backend parameters -| Name | Description | Value | -| ------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------- | -| `backend.enabled` | Enable backend | `true` | -| `backend.name` | Backend name | `backend` | -| `backend.fullnameOverride` | Backend fullnameOverride | `""` | -| `backend.podAnnotations` | Backend pod annotations | `{}` | -| `backend.deploymentAnnotations` | Backend deployment annotations | `{}` | -| `backend.replicaCount` | Backend replica count | `2` | -| `backend.image.repository` | Backend image repository | `infisical/backend` | -| `backend.image.tag` | Backend image tag | `latest` | -| `backend.image.pullPolicy` | Backend image pullPolicy | `IfNotPresent` | -| `backend.kubeSecretRef` | Backend secret resource reference name (containing required [backend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) | `""` | -| `backend.service.annotations` | Backend service annotations | `{}` | -| `backend.service.type` | Backend service type | `ClusterIP` | -| `backend.service.nodePort` | Backend service nodePort (used if above type is `NodePort`) | `""` | -| `backendEnvironmentVariables.ENCRYPTION_KEY` | **Required** Backend encryption key (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | -| `backendEnvironmentVariables.JWT_SIGNUP_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | -| `backendEnvironmentVariables.JWT_REFRESH_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | -| `backendEnvironmentVariables.JWT_AUTH_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | -| `backendEnvironmentVariables.JWT_SERVICE_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | -| `backendEnvironmentVariables.JWT_MFA_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | -| `backendEnvironmentVariables.SMTP_HOST` | **Required** Hostname to connect to for establishing SMTP connections | `""` | -| `backendEnvironmentVariables.SMTP_PORT` | Port to connect to for establishing SMTP connections | `587` | -| `backendEnvironmentVariables.SMTP_SECURE` | If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported | `false` | -| `backendEnvironmentVariables.SMTP_FROM_NAME` | Name label to be used in From field (e.g. Infisical) | `Infisical` | -| `backendEnvironmentVariables.SMTP_FROM_ADDRESS` | **Required** Email address to be used for sending emails (e.g. dev@infisical.com) | `""` | -| `backendEnvironmentVariables.SMTP_USERNAME` | **Required** Credential to connect to host (e.g. team@infisical.com) | `""` | -| `backendEnvironmentVariables.SMTP_PASSWORD` | **Required** Credential to connect to host | `""` | -| `backendEnvironmentVariables.SITE_URL` | Absolute URL including the protocol (e.g. https://app.infisical.com) | `infisical.local` | -| `backendEnvironmentVariables.INVITE_ONLY_SIGNUP` | To disable account creation from the login page (invites only) | `false` | -| `backendEnvironmentVariables.MONGO_URL` | MongoDB connection string (external or internal)
Leave it empty for auto-generated connection string | `""` | - +| Name | Description | Value | +| ------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- | +| `backend.enabled` | Enable backend | `true` | +| `backend.name` | Backend name | `backend` | +| `backend.fullnameOverride` | Backend fullnameOverride | `""` | +| `backend.podAnnotations` | Backend pod annotations | `{}` | +| `backend.deploymentAnnotations` | Backend deployment annotations | `{}` | +| `backend.replicaCount` | Backend replica count | `2` | +| `backend.image.repository` | Backend image repository | `infisical/backend` | +| `backend.image.tag` | Backend image tag | `latest` | +| `backend.image.pullPolicy` | Backend image pullPolicy | `IfNotPresent` | +| `backend.kubeSecretRef` | Backend secret resource reference name (containing required [backend configuration variables](https://infisical.com/docs/self-hosting/configuration/envars)) | `""` | +| `backend.service.annotations` | Backend service annotations | `{}` | +| `backend.service.type` | Backend service type | `ClusterIP` | +| `backend.service.nodePort` | Backend service nodePort (used if above type is `NodePort`) | `""` | +| `backendEnvironmentVariables.ENCRYPTION_KEY` | **Required** Backend encryption key (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.JWT_SIGNUP_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.JWT_REFRESH_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.JWT_AUTH_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.JWT_SERVICE_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.JWT_MFA_SECRET` | **Required** Secrets to sign JWT tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.JWT_PROVIDER_AUTH_SECRET` | **Required** Secrets to sign JWT OAuth tokens (128-bit hex value, 32-characters hex, [example](https://stackoverflow.com/a/34329057))
auto-generated variable (if not provided, and not found in an existing secret) | `""` | +| `backendEnvironmentVariables.SMTP_HOST` | **Required** Hostname to connect to for establishing SMTP connections | `""` | +| `backendEnvironmentVariables.SMTP_PORT` | Port to connect to for establishing SMTP connections | `587` | +| `backendEnvironmentVariables.SMTP_SECURE` | If true, use TLS when connecting to host. If false, TLS will be used if STARTTLS is supported | `false` | +| `backendEnvironmentVariables.SMTP_FROM_NAME` | Name label to be used in From field (e.g. Infisical) | `Infisical` | +| `backendEnvironmentVariables.SMTP_FROM_ADDRESS` | **Required** Email address to be used for sending emails (e.g. dev@infisical.com) | `""` | +| `backendEnvironmentVariables.SMTP_USERNAME` | **Required** Credential to connect to host (e.g. team@infisical.com) | `""` | +| `backendEnvironmentVariables.SMTP_PASSWORD` | **Required** Credential to connect to host | `""` | +| `backendEnvironmentVariables.SITE_URL` | Absolute URL including the protocol (e.g. https://app.infisical.com) | `infisical.local` | +| `backendEnvironmentVariables.INVITE_ONLY_SIGNUP` | To disable account creation from the login page (invites only) | `false` | +| `backendEnvironmentVariables.MONGO_URL` | MongoDB connection string (external or internal)
Leave it empty for auto-generated connection string | `""` | +| `backendEnvironmentVariables.REDIS_URL` | | `redis://redis-master:6379` | ### MongoDB(®) parameters @@ -154,18 +154,17 @@ kubectl get secrets -n \ | `mongodb.persistence.size` | Persistent storage request size | `8Gi` | | `mongodbConnection.externalMongoDBConnectionString` | Deprecated :warning: External MongoDB connection string
Use backendEnvironmentVariables.MONGO_URL instead | `""` | - ### Ingress parameters | Name | Description | Value | | -------------------------- | ------------------------------------------------------------------------ | ------- | | `ingress.enabled` | Enable ingress | `true` | | `ingress.ingressClassName` | Ingress class name | `nginx` | +| `ingress.nginx.enabled` | Ingress controller | `false` | | `ingress.annotations` | Ingress annotations | `{}` | | `ingress.hostName` | Ingress hostname (your custom domain name, e.g. `infisical.example.org`) | `""` | | `ingress.tls` | Ingress TLS hosts (matching above hostName) | `[]` | - ### Mailhog parameters | Name | Description | Value | @@ -184,6 +183,10 @@ kubectl get secrets -n \ | `mailhog.ingress.labels` | Ingress labels | `{}` | | `mailhog.ingress.hosts[0].host` | Mailhog host | `mailhog.infisical.local` | +### Redis parameters + + + ## Persistence diff --git a/helm-charts/infisical/templates/_helpers.tpl b/helm-charts/infisical/templates/_helpers.tpl index 35ef85be1..11c2c24e3 100644 --- a/helm-charts/infisical/templates/_helpers.tpl +++ b/helm-charts/infisical/templates/_helpers.tpl @@ -126,33 +126,3 @@ Create the mongodb connection string. {{- if .Values.mongodbConnection.externalMongoDBConnectionString -}} {{- $connectionString = .Values.mongodbConnection.externalMongoDBConnectionString -}} {{- end -}} -{{- printf "%s" $connectionString -}} -{{- end -}} - - -{{/* -Create a fully qualified redis name. -We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). -*/}} -{{- define "infisical.redis.fullname" -}} -{{- if .Values.redis.fullnameOverride -}} -{{- .Values.redis.fullnameOverride | trunc 63 | trimSuffix "-" -}} -{{- else -}} -{{- $name := default .Chart.Name .Values.nameOverride -}} -{{- if contains $name .Release.Name -}} -{{- printf "%s-%s" .Release.Name .Values.redis.name | trunc 63 | trimSuffix "-" -}} -{{- else -}} -{{- printf "%s-%s-%s" .Release.Name $name .Values.redis.name | trunc 63 | trimSuffix "-" -}} -{{- end -}} -{{- end -}} -{{- end -}} - -{{/* -Create the redis connection string. -*/}} -{{- define "infisical.redis.connectionString" -}} -{{- $host := include "infisical.redis.fullname" . -}} -{{- $pass := .Values.redis.auth.password | default "root" -}} -{{- $connectionString := printf "redis://redis:%s@%s:6379" $pass $host -}} -{{- printf "%s" $connectionString -}} -{{- end -}} \ No newline at end of file diff --git a/helm-charts/infisical/values.yaml b/helm-charts/infisical/values.yaml index c5437340b..1ffbc318f 100644 --- a/helm-charts/infisical/values.yaml +++ b/helm-charts/infisical/values.yaml @@ -170,7 +170,8 @@ backendEnvironmentVariables: MONGO_URL: "" ## @param backendEnvironmentVariables.REDIS_URL - REDIS_URL: "" + ## By default, the backend will use the Redis that is auto deployed along with Infisical + REDIS_URL: "redis://redis-master:6379" ## @section MongoDB(®) parameters ## Documentation : https://github.com/bitnami/charts/blob/main/bitnami/mongodb/values.yaml @@ -422,12 +423,16 @@ mailhog: paths: - path: "/" pathType: Prefix + +## @section Redis parameters +## Documentation : https://github.com/bitnami/charts/tree/main/bitnami/redis#parameters +## +## @skip redis +## redis: name: "redis" fullnameOverride: "redis" - usePassword: true enabled: true - cluster: - enabled: false + architecture: standalone auth: - password: "mysecretpassword" + enabled: false