feat(chart): mongodb persistence

This commit is contained in:
Grraahaam
2023-02-08 10:39:59 +01:00
parent 6f6df3e63a
commit 868011479b
6 changed files with 68 additions and 79 deletions

1
helm-charts/infisical/.gitignore vendored Normal file
View File

@@ -0,0 +1 @@
charts/

View File

@@ -0,0 +1,6 @@
dependencies:
- name: mongodb
repository: https://charts.bitnami.com/bitnami
version: 13.6.7
digest: sha256:f3a15cf01e2df1fc410b635cd7af684222d16b76d7e6a4d112883dc32b092249
generated: "2023-02-08T00:14:41.706253573+01:00"

View File

@@ -14,3 +14,9 @@ version: 0.1.13
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.17.0"
dependencies:
- name: mongodb
version: "~13.6.7"
repository: "https://charts.bitnami.com/bitnami"
condition: mongodb.enabled

View File

@@ -118,9 +118,10 @@ Create the mongodb connection string.
{{- define "infisical.mongodb.connectionString" -}}
{{- $host := include "infisical.mongodb.fullname" . -}}
{{- $port := 27017 -}}
{{- $user := "root" -}}
{{- $pass := "root" -}}
{{- $connectionString := printf "mongodb://%s:%s@%s:%d/" $user $pass $host $port -}}
{{- $user := first .Values.mongodb.auth.usernames | default "root" -}}
{{- $pass := first .Values.mongodb.auth.usernames | default "root" -}}
{{- $database := first .Values.mongodb.auth.databases | default "test" -}}
{{- $connectionString := printf "mongodb://%s:%s@%s:%d/%s" $user $pass $host $port $database -}}
{{- if .Values.mongodbConnection.externalMongoDBConnectionString -}}
{{- $connectionString = .Values.mongodbConnection.externalMongoDBConnectionString -}}
{{- end -}}

View File

@@ -1,49 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ include "infisical.mongodb.fullname" . }}
labels:
{{- include "infisical.mongodb.labels" . | nindent 4 }}
spec:
replicas: 1 # Cannot be scaled. To scale, you must set up Stateful Set
selector:
matchLabels:
{{- include "infisical.mongodb.matchLabels" . | nindent 6 }}
template:
metadata:
labels:
{{- include "infisical.mongodb.matchLabels" . | nindent 8 }}
{{- with .Values.mongodb.podAnnotations }}
annotations:
{{- toYaml . | nindent 8 }}
{{- end }}
spec:
containers:
- name: {{ template "infisical.name" . }}-{{ .Values.mongodb.name }}
image: "{{ .Values.mongodb.image.repository }}:{{ .Values.mongodb.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.mongodb.image.pullPolicy }}
ports:
- containerPort: 27017
env:
- name: MONGO_INITDB_ROOT_USERNAME
value: root
- name: MONGO_INITDB_ROOT_PASSWORD
value: root
---
apiVersion: v1
kind: Service
metadata:
name: {{ include "infisical.mongodb.fullname" . }}
labels:
{{- include "infisical.mongodb.labels" . | nindent 4 }}
{{- with .Values.mongodb.service.annotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
selector:
{{- include "infisical.mongodb.matchLabels" . | nindent 8 }}
ports:
- protocol: TCP
port: 27017
targetPort: 27017 # container port

View File

@@ -7,6 +7,7 @@ nameOverride: ""
frontend:
name: frontend
fullnameOverride: ""
podAnnotations: {}
deploymentAnnotations: {}
replicaCount: 2
@@ -14,7 +15,7 @@ frontend:
repository: infisical/frontend
pullPolicy: IfNotPresent
tag: "latest"
# kubeSecretRef: some-kube-secret-name
kubeSecretRef: ""
service:
# type of the frontend service
type: ClusterIP
@@ -24,6 +25,7 @@ frontend:
backend:
name: backend
fullnameOverride: ""
podAnnotations: {}
deploymentAnnotations: {}
replicaCount: 2
@@ -31,31 +33,56 @@ backend:
repository: infisical/backend
pullPolicy: IfNotPresent
tag: "latest"
# kubeSecretRef: some-kube-secret-name
kubeSecretRef: ""
service:
annotations: {}
mongodb:
name: mongodb
enabled: true
name: "mongodb"
fullnameOverride: "mongodb"
nameOverride: "mongodb"
podAnnotations: {}
useStatefulSet: true
architecture: "standalone"
image:
repository: mongo
pullPolicy: IfNotPresent
tag: "latest"
tag: "6.0"
service:
annotations: {}
auth:
enabled: true
usernames:
- "infisical"
passwords:
- "infisical"
databases:
- "infisical"
persistence:
enabled: true
existingClaim: ""
resourcePolicy: "keep"
accessModes: ["ReadWriteOnce"]
size: 8Gi
volumePermissions:
enabled: true
args:
- "--dbpath=/bitnami/mongodb"
# By default the backend will be connected to a Mongo instance in the cluster.
# However, it is recommended to add a managed document DB connection string because the DB instance in the cluster does not have persistence yet ( data will be deleted on next deploy).
# Learn about connection string type here https://www.mongodb.com/docs/manual/reference/connection-string/
mongodbConnection: {}
# externalMongoDBConnectionString: <>
mongodbConnection:
externalMongoDBConnectionString: ""
# externalMongoDBConnectionString: "mongodb://<user>:<pass>@<host>:<port>/<database-name>"
ingress:
enabled: true
annotations:
kubernetes.io/ingress.class: "nginx"
hostName: example.com # replace with your domain
# cert-manager.io/issuer: letsencrypt-nginx
hostName: infisical.local # replace with your domain
frontend:
path: /
pathType: Prefix
@@ -63,26 +90,23 @@ ingress:
path: /api
pathType: Prefix
tls: []
## Complete Ingress example
# ingress:
# enabled: true
# annotations:
# kubernetes.io/ingress.class: "nginx"
# cert-manager.io/issuer: letsencrypt-nginx
# hostName: k8.infisical.com
# frontend:
# path: /
# pathType: Prefix
# backend:
# path: /api
# pathType: Prefix
# tls:
# - secretName: letsencrypt-nginx
# hosts:
# - k8.infisical.com
# - secretName: letsencrypt-nginx
# hosts:
# - k8.infisical.com
frontendEnvironmentVariables: {}
backendEnvironmentVariables: {}
backendEnvironmentVariables:
# MY_ENV_VAR: my-value
# Required keys for platform encryption/decryption ops. (128-bit hex value, 32-characters hex)
# e.g. 'hexdump -vn16 -e'4/4 "%08X" 1 "\n"' /dev/urandom', 'openssl rand -hex 16' (from https://stackoverflow.com/a/34329057)
ENCRYPTION_KEY: MUST_REPLACE
# JWT (required secrets to sign JWT tokens)
JWT_SIGNUP_SECRET: MUST_REPLACE
JWT_REFRESH_SECRET: MUST_REPLACE
JWT_AUTH_SECRET: MUST_REPLACE
# Mail/SMTP (required to send emails)
SMTP_HOST: MUST_REPLACE
SMTP_NAME: MUST_REPLACE
SMTP_USERNAME: MUST_REPLACE
SMTP_PASSWORD: MUST_REPLACE