mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat(chart): mongodb persistence
This commit is contained in:
1
helm-charts/infisical/.gitignore
vendored
Normal file
1
helm-charts/infisical/.gitignore
vendored
Normal file
@@ -0,0 +1 @@
|
||||
charts/
|
||||
6
helm-charts/infisical/Chart.lock
Normal file
6
helm-charts/infisical/Chart.lock
Normal file
@@ -0,0 +1,6 @@
|
||||
dependencies:
|
||||
- name: mongodb
|
||||
repository: https://charts.bitnami.com/bitnami
|
||||
version: 13.6.7
|
||||
digest: sha256:f3a15cf01e2df1fc410b635cd7af684222d16b76d7e6a4d112883dc32b092249
|
||||
generated: "2023-02-08T00:14:41.706253573+01:00"
|
||||
@@ -14,3 +14,9 @@ version: 0.1.13
|
||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||
# It is recommended to use it with quotes.
|
||||
appVersion: "1.17.0"
|
||||
|
||||
dependencies:
|
||||
- name: mongodb
|
||||
version: "~13.6.7"
|
||||
repository: "https://charts.bitnami.com/bitnami"
|
||||
condition: mongodb.enabled
|
||||
@@ -118,9 +118,10 @@ Create the mongodb connection string.
|
||||
{{- define "infisical.mongodb.connectionString" -}}
|
||||
{{- $host := include "infisical.mongodb.fullname" . -}}
|
||||
{{- $port := 27017 -}}
|
||||
{{- $user := "root" -}}
|
||||
{{- $pass := "root" -}}
|
||||
{{- $connectionString := printf "mongodb://%s:%s@%s:%d/" $user $pass $host $port -}}
|
||||
{{- $user := first .Values.mongodb.auth.usernames | default "root" -}}
|
||||
{{- $pass := first .Values.mongodb.auth.usernames | default "root" -}}
|
||||
{{- $database := first .Values.mongodb.auth.databases | default "test" -}}
|
||||
{{- $connectionString := printf "mongodb://%s:%s@%s:%d/%s" $user $pass $host $port $database -}}
|
||||
{{- if .Values.mongodbConnection.externalMongoDBConnectionString -}}
|
||||
{{- $connectionString = .Values.mongodbConnection.externalMongoDBConnectionString -}}
|
||||
{{- end -}}
|
||||
|
||||
@@ -1,49 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: {{ include "infisical.mongodb.fullname" . }}
|
||||
labels:
|
||||
{{- include "infisical.mongodb.labels" . | nindent 4 }}
|
||||
spec:
|
||||
replicas: 1 # Cannot be scaled. To scale, you must set up Stateful Set
|
||||
selector:
|
||||
matchLabels:
|
||||
{{- include "infisical.mongodb.matchLabels" . | nindent 6 }}
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
{{- include "infisical.mongodb.matchLabels" . | nindent 8 }}
|
||||
{{- with .Values.mongodb.podAnnotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
containers:
|
||||
- name: {{ template "infisical.name" . }}-{{ .Values.mongodb.name }}
|
||||
image: "{{ .Values.mongodb.image.repository }}:{{ .Values.mongodb.image.tag | default .Chart.AppVersion }}"
|
||||
imagePullPolicy: {{ .Values.mongodb.image.pullPolicy }}
|
||||
ports:
|
||||
- containerPort: 27017
|
||||
env:
|
||||
- name: MONGO_INITDB_ROOT_USERNAME
|
||||
value: root
|
||||
- name: MONGO_INITDB_ROOT_PASSWORD
|
||||
value: root
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: {{ include "infisical.mongodb.fullname" . }}
|
||||
labels:
|
||||
{{- include "infisical.mongodb.labels" . | nindent 4 }}
|
||||
{{- with .Values.mongodb.service.annotations }}
|
||||
annotations:
|
||||
{{- toYaml . | nindent 4 }}
|
||||
{{- end }}
|
||||
spec:
|
||||
selector:
|
||||
{{- include "infisical.mongodb.matchLabels" . | nindent 8 }}
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 27017
|
||||
targetPort: 27017 # container port
|
||||
@@ -7,6 +7,7 @@ nameOverride: ""
|
||||
|
||||
frontend:
|
||||
name: frontend
|
||||
fullnameOverride: ""
|
||||
podAnnotations: {}
|
||||
deploymentAnnotations: {}
|
||||
replicaCount: 2
|
||||
@@ -14,7 +15,7 @@ frontend:
|
||||
repository: infisical/frontend
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "latest"
|
||||
# kubeSecretRef: some-kube-secret-name
|
||||
kubeSecretRef: ""
|
||||
service:
|
||||
# type of the frontend service
|
||||
type: ClusterIP
|
||||
@@ -24,6 +25,7 @@ frontend:
|
||||
|
||||
backend:
|
||||
name: backend
|
||||
fullnameOverride: ""
|
||||
podAnnotations: {}
|
||||
deploymentAnnotations: {}
|
||||
replicaCount: 2
|
||||
@@ -31,31 +33,56 @@ backend:
|
||||
repository: infisical/backend
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "latest"
|
||||
# kubeSecretRef: some-kube-secret-name
|
||||
kubeSecretRef: ""
|
||||
service:
|
||||
annotations: {}
|
||||
|
||||
mongodb:
|
||||
name: mongodb
|
||||
enabled: true
|
||||
name: "mongodb"
|
||||
fullnameOverride: "mongodb"
|
||||
nameOverride: "mongodb"
|
||||
podAnnotations: {}
|
||||
useStatefulSet: true
|
||||
architecture: "standalone"
|
||||
image:
|
||||
repository: mongo
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "latest"
|
||||
tag: "6.0"
|
||||
service:
|
||||
annotations: {}
|
||||
auth:
|
||||
enabled: true
|
||||
usernames:
|
||||
- "infisical"
|
||||
passwords:
|
||||
- "infisical"
|
||||
databases:
|
||||
- "infisical"
|
||||
persistence:
|
||||
enabled: true
|
||||
existingClaim: ""
|
||||
resourcePolicy: "keep"
|
||||
accessModes: ["ReadWriteOnce"]
|
||||
size: 8Gi
|
||||
volumePermissions:
|
||||
enabled: true
|
||||
args:
|
||||
- "--dbpath=/bitnami/mongodb"
|
||||
|
||||
# By default the backend will be connected to a Mongo instance in the cluster.
|
||||
# However, it is recommended to add a managed document DB connection string because the DB instance in the cluster does not have persistence yet ( data will be deleted on next deploy).
|
||||
# Learn about connection string type here https://www.mongodb.com/docs/manual/reference/connection-string/
|
||||
mongodbConnection: {}
|
||||
# externalMongoDBConnectionString: <>
|
||||
mongodbConnection:
|
||||
externalMongoDBConnectionString: ""
|
||||
# externalMongoDBConnectionString: "mongodb://<user>:<pass>@<host>:<port>/<database-name>"
|
||||
|
||||
ingress:
|
||||
enabled: true
|
||||
annotations:
|
||||
kubernetes.io/ingress.class: "nginx"
|
||||
hostName: example.com # replace with your domain
|
||||
# cert-manager.io/issuer: letsencrypt-nginx
|
||||
hostName: infisical.local # replace with your domain
|
||||
frontend:
|
||||
path: /
|
||||
pathType: Prefix
|
||||
@@ -63,26 +90,23 @@ ingress:
|
||||
path: /api
|
||||
pathType: Prefix
|
||||
tls: []
|
||||
|
||||
|
||||
## Complete Ingress example
|
||||
# ingress:
|
||||
# enabled: true
|
||||
# annotations:
|
||||
# kubernetes.io/ingress.class: "nginx"
|
||||
# cert-manager.io/issuer: letsencrypt-nginx
|
||||
# hostName: k8.infisical.com
|
||||
# frontend:
|
||||
# path: /
|
||||
# pathType: Prefix
|
||||
# backend:
|
||||
# path: /api
|
||||
# pathType: Prefix
|
||||
# tls:
|
||||
# - secretName: letsencrypt-nginx
|
||||
# hosts:
|
||||
# - k8.infisical.com
|
||||
# - secretName: letsencrypt-nginx
|
||||
# hosts:
|
||||
# - k8.infisical.com
|
||||
|
||||
frontendEnvironmentVariables: {}
|
||||
|
||||
backendEnvironmentVariables: {}
|
||||
backendEnvironmentVariables:
|
||||
# MY_ENV_VAR: my-value
|
||||
# Required keys for platform encryption/decryption ops. (128-bit hex value, 32-characters hex)
|
||||
# e.g. 'hexdump -vn16 -e'4/4 "%08X" 1 "\n"' /dev/urandom', 'openssl rand -hex 16' (from https://stackoverflow.com/a/34329057)
|
||||
ENCRYPTION_KEY: MUST_REPLACE
|
||||
# JWT (required secrets to sign JWT tokens)
|
||||
JWT_SIGNUP_SECRET: MUST_REPLACE
|
||||
JWT_REFRESH_SECRET: MUST_REPLACE
|
||||
JWT_AUTH_SECRET: MUST_REPLACE
|
||||
# Mail/SMTP (required to send emails)
|
||||
SMTP_HOST: MUST_REPLACE
|
||||
SMTP_NAME: MUST_REPLACE
|
||||
SMTP_USERNAME: MUST_REPLACE
|
||||
SMTP_PASSWORD: MUST_REPLACE
|
||||
Reference in New Issue
Block a user