mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 15:28:58 +00:00
fix(gateway-helm): requested changes
This commit is contained in:
@@ -1,43 +0,0 @@
|
|||||||
name: Release Gateway Docker Image
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
tags:
|
|
||||||
- "infisical-gateway/v*.*.*"
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
release-image:
|
|
||||||
name: Release Gateway Docker Image
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Extract version from tag
|
|
||||||
id: extract_version
|
|
||||||
run: echo "::set-output name=version::${GITHUB_REF_NAME#infisical-gateway/}"
|
|
||||||
|
|
||||||
- name: Checkout code
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: 🔧 Set up QEMU
|
|
||||||
uses: docker/setup-qemu-action@v1
|
|
||||||
|
|
||||||
- name: 🔧 Set up Docker Buildx
|
|
||||||
uses: docker/setup-buildx-action@v1
|
|
||||||
|
|
||||||
- name: 🐋 Login to Docker Hub
|
|
||||||
uses: docker/login-action@v1
|
|
||||||
with:
|
|
||||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
|
||||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
||||||
|
|
||||||
- name: Build and push
|
|
||||||
id: docker_build
|
|
||||||
uses: docker/build-push-action@v2
|
|
||||||
with:
|
|
||||||
context: .
|
|
||||||
push: true
|
|
||||||
platforms: linux/amd64,linux/arm64
|
|
||||||
tags: |
|
|
||||||
infisical/gateway:latest
|
|
||||||
infisical/gateway:${{ steps.extract_version.outputs.version }}
|
|
||||||
@@ -35,8 +35,16 @@ spec:
|
|||||||
securityContext:
|
securityContext:
|
||||||
{{- toYaml . | nindent 12 }}
|
{{- toYaml . | nindent 12 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
image: "infisical/cli:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
command: ["/sbin/tini", "--", "/bin/sh", "-c"]
|
||||||
|
args:
|
||||||
|
- >-
|
||||||
|
if [ -z "${TOKEN}" ]; then
|
||||||
|
echo 'ERROR: TOKEN environment variable must be set';
|
||||||
|
exit 1;
|
||||||
|
fi &&
|
||||||
|
/bin/infisical gateway --token ${TOKEN}
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: {{ .Values.secret.name }}
|
name: {{ .Values.secret.name }}
|
||||||
|
|||||||
@@ -1,13 +0,0 @@
|
|||||||
{{- if .Values.secret.create -}}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.secret.name }}
|
|
||||||
labels:
|
|
||||||
{{- include "infisical-gateway.labels" . | nindent 4 }}
|
|
||||||
type: Opaque
|
|
||||||
data:
|
|
||||||
{{- range $key, $value := .Values.secret.data }}
|
|
||||||
{{ $key }}: {{ $value | b64enc }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,18 +1,10 @@
|
|||||||
image:
|
image:
|
||||||
repository: infisical/infisical-gateway
|
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
tag: "v0.0.1"
|
tag: "0.41.1"
|
||||||
|
|
||||||
secret:
|
secret:
|
||||||
# create a new secret (if true) or use existing (if false)
|
# The secret that contains the environment variables to be used by the gateway, such as INFISICAL_API_URL and TOKEN
|
||||||
create: true
|
name: "infisical-gateway-environment"
|
||||||
# name of the secret to use/create
|
|
||||||
name: "infisical-gateway-secrets"
|
|
||||||
|
|
||||||
# Secret data (only used if create: true)
|
|
||||||
data:
|
|
||||||
TOKEN: ""
|
|
||||||
INFISICAL_API_URL: "https://app.infisical.com"
|
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
@@ -39,6 +31,7 @@ podSecurityContext:
|
|||||||
|
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsNonRoot: true
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
|
|
||||||
affinity: {}
|
affinity: {}
|
||||||
tolerations: {}
|
tolerations: {}
|
||||||
|
|||||||
Reference in New Issue
Block a user