From 943d0ddb6981b92e95a8b7970425e0cc84911ec1 Mon Sep 17 00:00:00 2001 From: Artyom Petrosov Date: Wed, 9 Oct 2024 16:04:21 +0300 Subject: [PATCH 1/3] Helm chart support for tolerations --- .../infisical-standalone-postgres/templates/infisical.yaml | 4 ++++ helm-charts/infisical-standalone-postgres/values.yaml | 2 ++ 2 files changed, 6 insertions(+) diff --git a/helm-charts/infisical-standalone-postgres/templates/infisical.yaml b/helm-charts/infisical-standalone-postgres/templates/infisical.yaml index ac941c9b2..04856406e 100644 --- a/helm-charts/infisical-standalone-postgres/templates/infisical.yaml +++ b/helm-charts/infisical-standalone-postgres/templates/infisical.yaml @@ -29,6 +29,10 @@ spec: affinity: {{- toYaml . | nindent 8 }} {{- end }} + {{- with $infisicalValues.tolerations }} + tolerations: + {{- toYaml . | nindent 8 }} + {{- end }} {{- if $infisicalValues.image.imagePullSecrets }} imagePullSecrets: {{- toYaml $infisicalValues.image.imagePullSecrets | nindent 6 }} diff --git a/helm-charts/infisical-standalone-postgres/values.yaml b/helm-charts/infisical-standalone-postgres/values.yaml index e4c1d51b5..83e6318e0 100644 --- a/helm-charts/infisical-standalone-postgres/values.yaml +++ b/helm-charts/infisical-standalone-postgres/values.yaml @@ -49,6 +49,8 @@ infisical: # -- Node affinity settings for pod placement affinity: {} + # -- Tolerations definitions + tolerations: [] # -- Kubernetes Secret reference containing Infisical root credentials kubeSecretRef: "infisical-secrets" From 8d6bd5d537551843ab68da243d592f5b16004ec0 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard Date: Wed, 26 Mar 2025 06:27:05 +0400 Subject: [PATCH 2/3] feat(helm): tolerations & nodeSelector support --- helm-charts/infisical-standalone-postgres/CHANGELOG.md | 9 +++++++++ helm-charts/infisical-standalone-postgres/Chart.yaml | 2 +- .../templates/infisical.yaml | 4 ++++ helm-charts/infisical-standalone-postgres/values.yaml | 4 +++- 4 files changed, 17 insertions(+), 2 deletions(-) diff --git a/helm-charts/infisical-standalone-postgres/CHANGELOG.md b/helm-charts/infisical-standalone-postgres/CHANGELOG.md index 80b3d7fcc..8e2829756 100644 --- a/helm-charts/infisical-standalone-postgres/CHANGELOG.md +++ b/helm-charts/infisical-standalone-postgres/CHANGELOG.md @@ -1,3 +1,12 @@ +## 1.5.0 (March 26, 2025) + +Changes: +* Added support for Kubernetes pod scheduling customization via `nodeSelector` and `tolerations` + +Features: +* `nodeSelector`: Configure pod placement on nodes with specific labels +* `tolerations`: Enable pods to schedule on tainted nodes + ## 1.4.0 (November 06, 2024) Changes: diff --git a/helm-charts/infisical-standalone-postgres/Chart.yaml b/helm-charts/infisical-standalone-postgres/Chart.yaml index a4cbc49c7..1f7efa8da 100644 --- a/helm-charts/infisical-standalone-postgres/Chart.yaml +++ b/helm-charts/infisical-standalone-postgres/Chart.yaml @@ -7,7 +7,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 1.4.0 +version: 1.5.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm-charts/infisical-standalone-postgres/templates/infisical.yaml b/helm-charts/infisical-standalone-postgres/templates/infisical.yaml index 04856406e..66a430e14 100644 --- a/helm-charts/infisical-standalone-postgres/templates/infisical.yaml +++ b/helm-charts/infisical-standalone-postgres/templates/infisical.yaml @@ -33,6 +33,10 @@ spec: tolerations: {{- toYaml . | nindent 8 }} {{- end }} + {{- with $infisicalValues.nodeSelector }} + nodeSelector: + {{- toYaml . | nindent 8 }} + {{- end }} {{- if $infisicalValues.image.imagePullSecrets }} imagePullSecrets: {{- toYaml $infisicalValues.image.imagePullSecrets | nindent 6 }} diff --git a/helm-charts/infisical-standalone-postgres/values.yaml b/helm-charts/infisical-standalone-postgres/values.yaml index 83e6318e0..2bcd0e283 100644 --- a/helm-charts/infisical-standalone-postgres/values.yaml +++ b/helm-charts/infisical-standalone-postgres/values.yaml @@ -51,6 +51,8 @@ infisical: affinity: {} # -- Tolerations definitions tolerations: [] + # -- Node selector for pod placement + nodeSelector: {} # -- Kubernetes Secret reference containing Infisical root credentials kubeSecretRef: "infisical-secrets" @@ -129,7 +131,7 @@ redis: cluster: # -- Clustered Redis deployment enabled: false - + # -- Requires a password for Redis authentication usePassword: true From cdfec32195827638892aa91a56f63bc7ec28fa82 Mon Sep 17 00:00:00 2001 From: Daniel Hougaard Date: Wed, 26 Mar 2025 06:33:34 +0400 Subject: [PATCH 3/3] Update .infisicalignore --- .infisicalignore | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.infisicalignore b/.infisicalignore index 4c19af70c..8072078d4 100644 --- a/.infisicalignore +++ b/.infisicalignore @@ -7,3 +7,8 @@ docs/self-hosting/configuration/envars.mdx:generic-api-key:106 frontend/src/views/Project/MembersPage/components/MemberListTab/MemberRoleForm/SpecificPrivilegeSection.tsx:generic-api-key:451 docs/mint.json:generic-api-key:651 backend/src/ee/services/hsm/hsm-service.ts:generic-api-key:134 +docs/documentation/platform/audit-log-streams/audit-log-streams.mdx:generic-api-key:104 +docs/cli/commands/bootstrap.mdx:jwt:86 +docs/documentation/platform/audit-log-streams/audit-log-streams.mdx:generic-api-key:102 +docs/self-hosting/guides/automated-bootstrapping.mdx:jwt:74 +frontend/src/pages/secret-manager/SecretDashboardPage/components/SecretListView/SecretDetailSidebar.tsx:generic-api-key:72