# Source: gitea/charts/postgresql-ha/templates/pgpool/deployment.yaml apiVersion: apps/v1 kind: Deployment metadata: name: release-name-postgresql-ha-pgpool namespace: gitea labels: app.kubernetes.io/instance: release-name app.kubernetes.io/name: postgresql-ha app.kubernetes.io/version: 4.5.2 app.kubernetes.io/component: pgpool spec: replicas: 1 selector: matchLabels: app.kubernetes.io/instance: release-name app.kubernetes.io/name: postgresql-ha app.kubernetes.io/component: pgpool template: metadata: labels: app.kubernetes.io/instance: release-name app.kubernetes.io/name: postgresql-ha app.kubernetes.io/version: 4.5.2 app.kubernetes.io/component: pgpool spec: nodeSelector: nodegroup: nd automountServiceAccountToken: false affinity: podAffinity: podAntiAffinity: preferredDuringSchedulingIgnoredDuringExecution: - podAffinityTerm: labelSelector: matchLabels: app.kubernetes.io/instance: release-name app.kubernetes.io/name: postgresql-ha app.kubernetes.io/component: pgpool topologyKey: kubernetes.io/hostname weight: 1 nodeAffinity: securityContext: fsGroup: 1001 fsGroupChangePolicy: Always supplementalGroups: [] sysctls: [] serviceAccountName: release-name-postgresql-ha # Auxiliary vars to populate environment variables containers: - name: pgpool image: docker.io/bitnami/pgpool:4.5.2-debian-12-r2 imagePullPolicy: "IfNotPresent" securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL privileged: false readOnlyRootFilesystem: true runAsGroup: 1001 runAsNonRoot: true runAsUser: 1001 seccompProfile: type: RuntimeDefault env: - name: BITNAMI_DEBUG value: "false" - name: PGPOOL_BACKEND_NODES value: 0:release-name-postgresql-ha-postgresql-0.release-name-postgresql-ha-postgresql-headless:5432,1:release-name-postgresql-ha-postgresql-1.release-name-postgresql-ha-postgresql-headless:5432,2:release-name-postgresql-ha-postgresql-2.release-name-postgresql-ha-postgresql-headless:5432, - name: PGPOOL_SR_CHECK_USER value: "repmgr" - name: PGPOOL_SR_CHECK_PASSWORD valueFrom: secretKeyRef: name: release-name-postgresql-ha-postgresql key: repmgr-password - name: PGPOOL_SR_CHECK_DATABASE value: "postgres" - name: PGPOOL_ENABLE_LDAP value: "no" - name: PGPOOL_POSTGRES_USERNAME value: "gitea" - name: PGPOOL_POSTGRES_PASSWORD valueFrom: secretKeyRef: name: release-name-postgresql-ha-postgresql key: password - name: PGPOOL_ADMIN_USERNAME value: "admin" - name: PGPOOL_ADMIN_PASSWORD valueFrom: secretKeyRef: name: release-name-postgresql-ha-pgpool key: admin-password - name: PGPOOL_AUTHENTICATION_METHOD value: "scram-sha-256" - name: PGPOOL_ENABLE_LOAD_BALANCING value: "yes" - name: PGPOOL_DISABLE_LOAD_BALANCE_ON_WRITE value: "transaction" - name: PGPOOL_ENABLE_LOG_CONNECTIONS value: "no" - name: PGPOOL_ENABLE_LOG_HOSTNAME value: "yes" - name: PGPOOL_ENABLE_LOG_PER_NODE_STATEMENT value: "no" - name: PGPOOL_RESERVED_CONNECTIONS value: '1' - name: PGPOOL_CHILD_LIFE_TIME value: "" - name: PGPOOL_ENABLE_TLS value: "no" - name: PGPOOL_HEALTH_CHECK_PSQL_TIMEOUT value: "6" envFrom: ports: - name: postgresql containerPort: 5432 protocol: TCP livenessProbe: failureThreshold: 5 initialDelaySeconds: 30 periodSeconds: 10 successThreshold: 1 timeoutSeconds: 5 exec: command: - /opt/bitnami/scripts/pgpool/healthcheck.sh readinessProbe: failureThreshold: 5 initialDelaySeconds: 5 periodSeconds: 5 successThreshold: 1 timeoutSeconds: 5 exec: command: - bash - -ec - PGPASSWORD=${PGPOOL_POSTGRES_PASSWORD} psql -U "gitea" -d "gitea" -h /opt/bitnami/pgpool/tmp -tA -c "SELECT 1" >/dev/null resources: limits: cpu: 375m ephemeral-storage: 2Gi memory: 384Mi requests: cpu: 250m ephemeral-storage: 50Mi memory: 256Mi volumeMounts: - name: empty-dir mountPath: /tmp subPath: tmp-dir - name: empty-dir mountPath: /opt/bitnami/pgpool/etc subPath: app-etc-dir - name: empty-dir mountPath: /opt/bitnami/pgpool/conf subPath: app-conf-dir - name: empty-dir mountPath: /opt/bitnami/pgpool/tmp subPath: app-tmp-dir - name: empty-dir mountPath: /opt/bitnami/pgpool/logs subPath: app-logs-dir volumes: - name: empty-dir emptyDir: {} --- # Source: gitea/templates/gitea/deployment.yaml apiVersion: apps/v1 kind: Deployment metadata: name: release-name-gitea namespace: gitea annotations: labels: app: gitea app.kubernetes.io/name: gitea app.kubernetes.io/instance: release-name app.kubernetes.io/version: "1.22.1" version: "1.22.1" spec: replicas: 1 strategy: type: RollingUpdate rollingUpdate: maxUnavailable: 0 maxSurge: 100% selector: matchLabels: app.kubernetes.io/name: gitea app.kubernetes.io/instance: release-name template: metadata: annotations: checksum/config: 00fd8064076a446a896870db4974c6590fcf51561cf391547e559011465a57d8 labels: app: gitea app.kubernetes.io/name: gitea app.kubernetes.io/instance: release-name app.kubernetes.io/version: "1.22.1" version: "1.22.1" spec: nodeSelector: nodegroup: nd securityContext: fsGroup: 1000 initContainers: - name: init-directories image: "gitea/gitea:1.22.1-rootless" imagePullPolicy: IfNotPresent command: ["/usr/sbin/init_directory_structure.sh"] env: - name: GITEA_APP_INI value: /data/gitea/conf/app.ini - name: GITEA_CUSTOM value: /data/gitea - name: GITEA_WORK_DIR value: /data - name: GITEA_TEMP value: /tmp/gitea volumeMounts: - name: init mountPath: /usr/sbin - name: temp mountPath: /tmp - name: data mountPath: /data securityContext: {} resources: limits: {} requests: cpu: 100m memory: 128Mi - name: init-app-ini image: "gitea/gitea:1.22.1-rootless" imagePullPolicy: IfNotPresent command: ["/usr/sbin/config_environment.sh"] env: - name: GITEA_APP_INI value: /data/gitea/conf/app.ini - name: GITEA_CUSTOM value: /data/gitea - name: GITEA_WORK_DIR value: /data - name: GITEA_TEMP value: /tmp/gitea volumeMounts: - name: config mountPath: /usr/sbin - name: temp mountPath: /tmp - name: data mountPath: /data - name: inline-config-sources mountPath: /env-to-ini-mounts/inlines/ securityContext: {} resources: limits: {} requests: cpu: 100m memory: 128Mi - name: configure-gitea image: "gitea/gitea:1.22.1-rootless" command: ["/usr/sbin/configure_gitea.sh"] imagePullPolicy: IfNotPresent securityContext: runAsUser: 1000 env: - name: GITEA_APP_INI value: /data/gitea/conf/app.ini - name: GITEA_CUSTOM value: /data/gitea - name: GITEA_WORK_DIR value: /data - name: GITEA_TEMP value: /tmp/gitea - name: HOME value: /data/gitea/git - name: GITEA_ADMIN_USERNAME value: "gitea_admin" - name: GITEA_ADMIN_PASSWORD value: "nhn!@#123" # sdjo - name: GITEA_ADMIN_PASSWORD_MODE value: keepUpdated volumeMounts: - name: init mountPath: /usr/sbin - name: temp mountPath: /tmp - name: data mountPath: /data resources: limits: {} requests: cpu: 100m memory: 128Mi terminationGracePeriodSeconds: 60 containers: - name: gitea image: "gitea/gitea:1.22.1-rootless" imagePullPolicy: IfNotPresent env: # SSH Port values have to be set here as well for openssh configuration - name: SSH_LISTEN_PORT value: "2222" - name: SSH_PORT value: "22" - name: GITEA_APP_INI value: /data/gitea/conf/app.ini - name: GITEA_CUSTOM value: /data/gitea - name: GITEA_WORK_DIR value: /data - name: GITEA_TEMP value: /tmp/gitea - name: TMPDIR value: /tmp/gitea - name: HOME value: /data/gitea/git ports: - name: ssh containerPort: 2222 - name: http containerPort: 3000 livenessProbe: failureThreshold: 10 initialDelaySeconds: 200 periodSeconds: 10 successThreshold: 1 tcpSocket: port: http timeoutSeconds: 1 readinessProbe: failureThreshold: 3 initialDelaySeconds: 5 periodSeconds: 10 successThreshold: 1 tcpSocket: port: http timeoutSeconds: 1 resources: {} securityContext: {} volumeMounts: - name: temp mountPath: /tmp - name: data mountPath: /data volumes: - name: init secret: secretName: release-name-gitea-init defaultMode: 110 - name: config secret: secretName: release-name-gitea defaultMode: 110 - name: inline-config-sources secret: secretName: release-name-gitea-inline-config - name: temp emptyDir: {} - name: data hostPath: path: /data/gitea-shared-storage type: DirectoryOrCreate