diff --git a/helm-charts/infisical/.gitignore b/helm-charts/infisical/.gitignore new file mode 100644 index 000000000..711a39c54 --- /dev/null +++ b/helm-charts/infisical/.gitignore @@ -0,0 +1 @@ +charts/ \ No newline at end of file diff --git a/helm-charts/infisical/Chart.lock b/helm-charts/infisical/Chart.lock new file mode 100644 index 000000000..633998bc2 --- /dev/null +++ b/helm-charts/infisical/Chart.lock @@ -0,0 +1,6 @@ +dependencies: +- name: mongodb + repository: https://charts.bitnami.com/bitnami + version: 13.6.7 +digest: sha256:f3a15cf01e2df1fc410b635cd7af684222d16b76d7e6a4d112883dc32b092249 +generated: "2023-02-08T00:14:41.706253573+01:00" diff --git a/helm-charts/infisical/Chart.yaml b/helm-charts/infisical/Chart.yaml index fe65e3b11..54ee708fd 100644 --- a/helm-charts/infisical/Chart.yaml +++ b/helm-charts/infisical/Chart.yaml @@ -14,3 +14,9 @@ version: 0.1.13 # follow Semantic Versioning. They should reflect the version the application is using. # It is recommended to use it with quotes. appVersion: "1.17.0" + +dependencies: + - name: mongodb + version: "~13.6.7" + repository: "https://charts.bitnami.com/bitnami" + condition: mongodb.enabled \ No newline at end of file diff --git a/helm-charts/infisical/templates/_helpers.tpl b/helm-charts/infisical/templates/_helpers.tpl index d0ceb0641..f10e44c56 100644 --- a/helm-charts/infisical/templates/_helpers.tpl +++ b/helm-charts/infisical/templates/_helpers.tpl @@ -118,9 +118,10 @@ Create the mongodb connection string. {{- define "infisical.mongodb.connectionString" -}} {{- $host := include "infisical.mongodb.fullname" . -}} {{- $port := 27017 -}} -{{- $user := "root" -}} -{{- $pass := "root" -}} -{{- $connectionString := printf "mongodb://%s:%s@%s:%d/" $user $pass $host $port -}} +{{- $user := first .Values.mongodb.auth.usernames | default "root" -}} +{{- $pass := first .Values.mongodb.auth.usernames | default "root" -}} +{{- $database := first .Values.mongodb.auth.databases | default "test" -}} +{{- $connectionString := printf "mongodb://%s:%s@%s:%d/%s" $user $pass $host $port $database -}} {{- if .Values.mongodbConnection.externalMongoDBConnectionString -}} {{- $connectionString = .Values.mongodbConnection.externalMongoDBConnectionString -}} {{- end -}} diff --git a/helm-charts/infisical/templates/mongodb-deployment.yaml b/helm-charts/infisical/templates/mongodb-deployment.yaml deleted file mode 100644 index c9a4b13a8..000000000 --- a/helm-charts/infisical/templates/mongodb-deployment.yaml +++ /dev/null @@ -1,49 +0,0 @@ -apiVersion: apps/v1 -kind: Deployment -metadata: - name: {{ include "infisical.mongodb.fullname" . }} - labels: - {{- include "infisical.mongodb.labels" . | nindent 4 }} -spec: - replicas: 1 # Cannot be scaled. To scale, you must set up Stateful Set - selector: - matchLabels: - {{- include "infisical.mongodb.matchLabels" . | nindent 6 }} - template: - metadata: - labels: - {{- include "infisical.mongodb.matchLabels" . | nindent 8 }} - {{- with .Values.mongodb.podAnnotations }} - annotations: - {{- toYaml . | nindent 8 }} - {{- end }} - spec: - containers: - - name: {{ template "infisical.name" . }}-{{ .Values.mongodb.name }} - image: "{{ .Values.mongodb.image.repository }}:{{ .Values.mongodb.image.tag | default .Chart.AppVersion }}" - imagePullPolicy: {{ .Values.mongodb.image.pullPolicy }} - ports: - - containerPort: 27017 - env: - - name: MONGO_INITDB_ROOT_USERNAME - value: root - - name: MONGO_INITDB_ROOT_PASSWORD - value: root ---- -apiVersion: v1 -kind: Service -metadata: - name: {{ include "infisical.mongodb.fullname" . }} - labels: - {{- include "infisical.mongodb.labels" . | nindent 4 }} - {{- with .Values.mongodb.service.annotations }} - annotations: - {{- toYaml . | nindent 4 }} - {{- end }} -spec: - selector: - {{- include "infisical.mongodb.matchLabels" . | nindent 8 }} - ports: - - protocol: TCP - port: 27017 - targetPort: 27017 # container port diff --git a/helm-charts/infisical/values.yaml b/helm-charts/infisical/values.yaml index 9ed7ef9dc..946bd92c4 100644 --- a/helm-charts/infisical/values.yaml +++ b/helm-charts/infisical/values.yaml @@ -7,6 +7,7 @@ nameOverride: "" frontend: name: frontend + fullnameOverride: "" podAnnotations: {} deploymentAnnotations: {} replicaCount: 2 @@ -14,7 +15,7 @@ frontend: repository: infisical/frontend pullPolicy: IfNotPresent tag: "latest" - # kubeSecretRef: some-kube-secret-name + kubeSecretRef: "" service: # type of the frontend service type: ClusterIP @@ -24,6 +25,7 @@ frontend: backend: name: backend + fullnameOverride: "" podAnnotations: {} deploymentAnnotations: {} replicaCount: 2 @@ -31,31 +33,56 @@ backend: repository: infisical/backend pullPolicy: IfNotPresent tag: "latest" - # kubeSecretRef: some-kube-secret-name + kubeSecretRef: "" service: annotations: {} mongodb: - name: mongodb + enabled: true + name: "mongodb" + fullnameOverride: "mongodb" + nameOverride: "mongodb" podAnnotations: {} + useStatefulSet: true + architecture: "standalone" image: repository: mongo pullPolicy: IfNotPresent - tag: "latest" + tag: "6.0" service: annotations: {} + auth: + enabled: true + usernames: + - "infisical" + passwords: + - "infisical" + databases: + - "infisical" + persistence: + enabled: true + existingClaim: "" + resourcePolicy: "keep" + accessModes: ["ReadWriteOnce"] + size: 8Gi + volumePermissions: + enabled: true + args: + - "--dbpath=/bitnami/mongodb" # By default the backend will be connected to a Mongo instance in the cluster. # However, it is recommended to add a managed document DB connection string because the DB instance in the cluster does not have persistence yet ( data will be deleted on next deploy). # Learn about connection string type here https://www.mongodb.com/docs/manual/reference/connection-string/ -mongodbConnection: {} - # externalMongoDBConnectionString: <> +mongodbConnection: + externalMongoDBConnectionString: "" + # externalMongoDBConnectionString: "mongodb://:@:/" ingress: enabled: true annotations: kubernetes.io/ingress.class: "nginx" - hostName: example.com # replace with your domain + # cert-manager.io/issuer: letsencrypt-nginx + hostName: infisical.local # replace with your domain frontend: path: / pathType: Prefix @@ -63,26 +90,23 @@ ingress: path: /api pathType: Prefix tls: [] - - -## Complete Ingress example -# ingress: -# enabled: true -# annotations: -# kubernetes.io/ingress.class: "nginx" -# cert-manager.io/issuer: letsencrypt-nginx -# hostName: k8.infisical.com -# frontend: -# path: / -# pathType: Prefix -# backend: -# path: /api -# pathType: Prefix -# tls: -# - secretName: letsencrypt-nginx -# hosts: -# - k8.infisical.com + # - secretName: letsencrypt-nginx + # hosts: + # - k8.infisical.com frontendEnvironmentVariables: {} -backendEnvironmentVariables: {} +backendEnvironmentVariables: + # MY_ENV_VAR: my-value + # Required keys for platform encryption/decryption ops. (128-bit hex value, 32-characters hex) + # e.g. 'hexdump -vn16 -e'4/4 "%08X" 1 "\n"' /dev/urandom', 'openssl rand -hex 16' (from https://stackoverflow.com/a/34329057) + ENCRYPTION_KEY: MUST_REPLACE + # JWT (required secrets to sign JWT tokens) + JWT_SIGNUP_SECRET: MUST_REPLACE + JWT_REFRESH_SECRET: MUST_REPLACE + JWT_AUTH_SECRET: MUST_REPLACE + # Mail/SMTP (required to send emails) + SMTP_HOST: MUST_REPLACE + SMTP_NAME: MUST_REPLACE + SMTP_USERNAME: MUST_REPLACE + SMTP_PASSWORD: MUST_REPLACE \ No newline at end of file