# Source: gitea/charts/postgresql-ha/templates/pgpool/secrets.yaml apiVersion: v1 kind: Secret metadata: name: release-name-postgresql-ha-pgpool namespace: gitea labels: app.kubernetes.io/instance: release-name app.kubernetes.io/name: postgresql-ha app.kubernetes.io/version: 4.5.2 app.kubernetes.io/component: pgpool type: Opaque data: admin-password: "aWppbmMxMjMh" --- # Source: gitea/charts/postgresql-ha/templates/postgresql/secrets.yaml apiVersion: v1 kind: Secret metadata: name: release-name-postgresql-ha-postgresql namespace: "gitea" labels: app.kubernetes.io/instance: release-name app.kubernetes.io/name: postgresql-ha app.kubernetes.io/version: 16.3.0 app.kubernetes.io/component: postgresql type: Opaque data: postgres-password: "aWppbmMxMjMh" password: "Z2l0ZWE=" repmgr-password: "aWppbmMxMjMh" --- # Source: gitea/templates/gitea/config.yaml apiVersion: v1 kind: Secret metadata: name: release-name-gitea-inline-config namespace: gitea labels: app: gitea app.kubernetes.io/name: gitea app.kubernetes.io/instance: release-name app.kubernetes.io/version: "1.22.1" version: "1.22.1" type: Opaque stringData: _generals_: "" cache: |- ADAPTER=redis HOST=redis+cluster://:@release-name-redis-cluster-headless.gitea.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s& database: |- DB_TYPE=postgres HOST=release-name-postgresql-ha-pgpool.gitea.svc.cluster.local:5432 NAME=gitea PASSWD=gitea USER=gitea indexer: ISSUE_INDEXER_TYPE=db metrics: ENABLED=false queue: |- CONN_STR=redis+cluster://:@release-name-redis-cluster-headless.gitea.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s& TYPE=redis repository: ROOT=/data/git/gitea-repositories security: INSTALL_LOCK=true server: |- APP_DATA_PATH=/data DOMAIN=gitea.gpulive.nhncloud.com ENABLE_PPROF=false HTTP_PORT=3000 PROTOCOL=http ROOT_URL=https://gitea.gpulive.nhncloud.com SSH_DOMAIN=gitea.gpulive.nhncloud.com SSH_LISTEN_PORT=2222 SSH_PORT=22 START_SSH_SERVER=true session: |- PROVIDER=redis PROVIDER_CONFIG=redis+cluster://:@release-name-redis-cluster-headless.gitea.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s& --- # Source: gitea/templates/gitea/config.yaml apiVersion: v1 kind: Secret metadata: name: release-name-gitea namespace: gitea labels: app: gitea app.kubernetes.io/name: gitea app.kubernetes.io/instance: release-name app.kubernetes.io/version: "1.22.1" version: "1.22.1" type: Opaque stringData: assertions: | config_environment.sh: |- #!/usr/bin/env bash set -euo pipefail function env2ini::log() { printf "${1}\n" } function env2ini::read_config_to_env() { local section="${1}" local line="${2}" if [[ -z "${line}" ]]; then # skip empty line return fi # 'xargs echo -n' trims all leading/trailing whitespaces and a trailing new line local setting="$(awk -F '=' '{print $1}' <<< "${line}" | xargs echo -n)" if [[ -z "${setting}" ]]; then env2ini::log ' ! invalid setting' exit 1 fi local value='' local regex="^${setting}(\s*)=(\s*)(.*)" if [[ $line =~ $regex ]]; then value="${BASH_REMATCH[3]}" else env2ini::log ' ! invalid setting' exit 1 fi env2ini::log " + '${setting}'" if [[ -z "${section}" ]]; then export "GITEA____${setting^^}=${value}" # '^^' makes the variable content uppercase return fi local masked_section="${section//./_0X2E_}" # '//' instructs to replace all matches masked_section="${masked_section//-/_0X2D_}" export "GITEA__${masked_section^^}__${setting^^}=${value}" # '^^' makes the variable content uppercase } function env2ini::reload_preset_envs() { env2ini::log "Reloading preset envs..." while read -r line; do if [[ -z "${line}" ]]; then # skip empty line return fi # 'xargs echo -n' trims all leading/trailing whitespaces and a trailing new line local setting="$(awk -F '=' '{print $1}' <<< "${line}" | xargs echo -n)" if [[ -z "${setting}" ]]; then env2ini::log ' ! invalid setting' exit 1 fi local value='' local regex="^${setting}(\s*)=(\s*)(.*)" if [[ $line =~ $regex ]]; then value="${BASH_REMATCH[3]}" else env2ini::log ' ! invalid setting' exit 1 fi env2ini::log " + '${setting}'" export "${setting^^}=${value}" # '^^' makes the variable content uppercase done < "/tmp/existing-envs" rm /tmp/existing-envs } function env2ini::process_config_file() { local config_file="${1}" local section="$(basename "${config_file}")" if [[ $section == '_generals_' ]]; then section='' else env2ini::log " ${section}" fi while read -r line; do env2ini::read_config_to_env "${section}" "${line}" done < <(awk 1 "${config_file}") # Helm .toYaml trims the trailing new line which breaks line processing; awk 1 ... adds it back while reading } function env2ini::load_config_sources() { local path="${1}" if [[ -d "${path}" ]]; then env2ini::log "Processing $(basename "${path}")..." while read -d '' configFile; do env2ini::process_config_file "${configFile}" done < <(find "${path}" -type l -not -name '..data' -print0) env2ini::log "\n" fi } function env2ini::generate_initial_secrets() { # These environment variables will either be # - overwritten with user defined values, # - initially used to set up Gitea # Anyway, they won't harm existing app.ini files export GITEA__SECURITY__INTERNAL_TOKEN=$(gitea generate secret INTERNAL_TOKEN) export GITEA__SECURITY__SECRET_KEY=$(gitea generate secret SECRET_KEY) export GITEA__OAUTH2__JWT_SECRET=$(gitea generate secret JWT_SECRET) export GITEA__SERVER__LFS_JWT_SECRET=$(gitea generate secret LFS_JWT_SECRET) env2ini::log "...Initial secrets generated\n" } # save existing envs prior to script execution. Necessary to keep order of preexisting and custom envs env | (grep -e '^GITEA__' || [[ $? == 1 ]]) > /tmp/existing-envs # MUST BE CALLED BEFORE OTHER CONFIGURATION env2ini::generate_initial_secrets env2ini::load_config_sources '/env-to-ini-mounts/inlines/' env2ini::load_config_sources '/env-to-ini-mounts/additionals/' # load existing envs to override auto generated envs env2ini::reload_preset_envs env2ini::log "=== All configuration sources loaded ===\n" # safety to prevent rewrite of secret keys if an app.ini already exists if [ -f ${GITEA_APP_INI} ]; then env2ini::log 'An app.ini file already exists. To prevent overwriting secret keys, these settings are dropped and remain unchanged:' env2ini::log ' - security.INTERNAL_TOKEN' env2ini::log ' - security.SECRET_KEY' env2ini::log ' - oauth2.JWT_SECRET' env2ini::log ' - server.LFS_JWT_SECRET' unset GITEA__SECURITY__INTERNAL_TOKEN unset GITEA__SECURITY__SECRET_KEY unset GITEA__OAUTH2__JWT_SECRET unset GITEA__SERVER__LFS_JWT_SECRET fi environment-to-ini -o $GITEA_APP_INI --- # Source: gitea/templates/gitea/init.yaml apiVersion: v1 kind: Secret metadata: name: release-name-gitea-init namespace: gitea labels: app: gitea app.kubernetes.io/name: gitea app.kubernetes.io/instance: release-name app.kubernetes.io/version: "1.22.1" version: "1.22.1" type: Opaque stringData: configure_gpg_environment.sh: |- #!/usr/bin/env bash set -eu gpg --batch --import /raw/private.asc init_directory_structure.sh: |- #!/usr/bin/env bash set -euo pipefail set -x mkdir -p /data/git/.ssh chmod -R 700 /data/git/.ssh [ ! -d /data/gitea/conf ] && mkdir -p /data/gitea/conf # prepare temp directory structure mkdir -p "${GITEA_TEMP}" chmod ug+rwx "${GITEA_TEMP}" configure_gitea.sh: |- #!/usr/bin/env bash set -euo pipefail echo '==== BEGIN GITEA CONFIGURATION ====' { # try gitea migrate } || { # catch echo "Gitea migrate might fail due to database connection...This init-container will try again in a few seconds" exit 1 } function test_redis_connection() { local RETRY=0 local MAX=30 echo 'Wait for redis to become avialable...' until [ "${RETRY}" -ge "${MAX}" ]; do nc -vz -w2 release-name-redis-cluster-headless.gitea.svc.cluster.local 6379 && break RETRY=$[${RETRY}+1] echo "...not ready yet (${RETRY}/${MAX})" done if [ "${RETRY}" -ge "${MAX}" ]; then echo "Redis not reachable after '${MAX}' attempts!" exit 1 fi } test_redis_connection function configure_admin_user() { local full_admin_list=$(gitea admin user list --admin) local actual_user_table='' # We might have distorted output due to warning logs, so we have to detect the actual user table by its headline and trim output above that line local regex="(.*)(ID\s+Username\s+Email\s+IsActive.*)" if [[ "${full_admin_list}" =~ $regex ]]; then actual_user_table=$(echo "${BASH_REMATCH[2]}" | tail -n+2) # tail'ing to drop the table headline else # This code block should never be reached, as long as the output table header remains the same. # If this code block is reached, the regex doesn't match anymore and we probably have to adjust this script. echo "ERROR: 'configure_admin_user' was not able to determine the current list of admin users." echo " Please review the output of 'gitea admin user list --admin' shown below." echo " If you think it is an issue with the Helm Chart provisioning, file an issue at https://gitea.com/gitea/helm-chart/issues." echo "DEBUG: Output of 'gitea admin user list --admin'" echo "--" echo "${full_admin_list}" echo "--" exit 1 fi local ACCOUNT_ID=$(echo "${actual_user_table}" | grep -E "\s+${GITEA_ADMIN_USERNAME}\s+" | awk -F " " "{printf \$1}") if [[ -z "${ACCOUNT_ID}" ]]; then local -a create_args create_args=(--admin --username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}" --email "gitea@local.domain") if [[ "${GITEA_ADMIN_PASSWORD_MODE}" = initialOnlyRequireReset ]]; then create_args+=(--must-change-password=true) else create_args+=(--must-change-password=false) fi echo "No admin user '${GITEA_ADMIN_USERNAME}' found. Creating now..." gitea admin user create "${create_args[@]}" echo '...created.' else if [[ "${GITEA_ADMIN_PASSWORD_MODE}" = keepUpdated ]]; then echo "Admin account '${GITEA_ADMIN_USERNAME}' already exist. Running update to sync password..." # See https://gitea.com/gitea/helm-chart/issues/673 # --must-change-password argument was added to change-password, defaulting to true, counter to the previous behavior # which acted as if it were provided with =false. If the argument is present in this version of gitea, then we # should add it to prevent requiring frequent admin password resets. local -a change_args change_args=(--username "${GITEA_ADMIN_USERNAME}" --password "${GITEA_ADMIN_PASSWORD}") if gitea admin user change-password --help | grep -qF -- '--must-change-password'; then change_args+=(--must-change-password=false) fi gitea admin user change-password "${change_args[@]}" echo '...password sync done.' else echo "Admin account '${GITEA_ADMIN_USERNAME}' already exist, but update mode is set to '${GITEA_ADMIN_PASSWORD_MODE}'. Skipping." fi fi } configure_admin_user function configure_ldap() { echo 'no ldap configuration... skipping.' } configure_ldap function configure_oauth() { echo 'no oauth configuration... skipping.' } configure_oauth echo '==== END GITEA CONFIGURATION ===='