Enhance Helm chart with ServiceAccount support and configurable ports
CI / lint (push) Failing after 2s
CI / smoke-test (push) Failing after 9s
Release chart / release (release) Successful in 12s

- Updated Chart.yaml to version 0.2.0 and added annotations for changes.
- Modified release-chart.yaml to trigger releases via Gitea and handle pre-releases.
- Introduced ServiceAccount configuration in values.yaml and related templates.
- Adjusted internal container ports to prevent conflicts between nginx and aptly.
- Updated README.md and NOTES.txt to reflect new configurations and usage instructions.
This commit is contained in:
2026-08-13 12:12:30 +02:00
parent 5af33e9128
commit 1675ea9a4e
11 changed files with 140 additions and 28 deletions
+20 -7
View File
@@ -73,6 +73,19 @@ confirms it's intended.
{{- end -}}
{{- end -}}
{{/*
Resolves to the ServiceAccount name the pod should bind to: a generated or
overridden name when serviceAccount.create is true, the explicit override
when false, or "" (falls back to the namespace's "default" SA) otherwise.
*/}}
{{- define "aptly.serviceAccountName" -}}
{{- if .Values.serviceAccount.create -}}
{{- default (include "aptly.fullname" .) .Values.serviceAccount.name -}}
{{- else -}}
{{- .Values.serviceAccount.name -}}
{{- end -}}
{{- end -}}
{{- define "aptly.imagePullSecrets" -}}
{{- $secrets := concat (.Values.global.imagePullSecrets | default list) (.Values.image.pullSecrets | default list) -}}
{{- if $secrets }}
@@ -94,7 +107,7 @@ templates/statefulset.yaml (the aptly config) and templates/ingress.yaml
{{- end -}}
{{- define "aptly.apiListen" -}}
{{- if .Values.proxy.enabled -}}127.0.0.1:8080{{- else -}}0.0.0.0:8080{{- end -}}
{{- if .Values.proxy.enabled -}}127.0.0.1:{{ .Values.ports.aptly }}{{- else -}}0.0.0.0:{{ .Values.ports.aptly }}{{- end -}}
{{- end -}}
{{/*
@@ -163,7 +176,7 @@ compose/config/nginx.*.conf for the same constraint hit empirically).
{{- $sec := include "aptly.security" . | fromJson -}}
{{- $p := .Values.proxy -}}
server {
listen 8080;
listen {{ .Values.ports.nginx }};
server_name _;
client_max_body_size {{ $p.maxUploadSize }};
absolute_redirect off;
@@ -176,8 +189,8 @@ server {
{{- end }}
location = /healthz { access_log off; return 200 "ok\n"; }
location = /api/ready { access_log off; proxy_pass http://127.0.0.1:8080; }
location = /api/healthy { access_log off; proxy_pass http://127.0.0.1:8080; }
location = /api/ready { access_log off; proxy_pass http://127.0.0.1:{{ .Values.ports.aptly }}; }
location = /api/healthy { access_log off; proxy_pass http://127.0.0.1:{{ .Values.ports.aptly }}; }
{{- if $sec.w }}
location /api/ {
@@ -200,7 +213,7 @@ server {
{{- else }}
auth_basic off;
{{- end }}
proxy_pass http://127.0.0.1:8080;
proxy_pass http://127.0.0.1:{{ .Values.ports.aptly }};
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_request_buffering off;
@@ -254,9 +267,9 @@ server {
# Separate, unauthenticated listener so scraping never needs the write-path
# credentials and a ServiceMonitor never needs a basicAuth secret.
server {
listen 9090;
listen {{ .Values.ports.metrics }};
server_name _;
location = /api/metrics { proxy_pass http://127.0.0.1:8080; }
location = /api/metrics { proxy_pass http://127.0.0.1:{{ .Values.ports.aptly }}; }
location / { return 404; }
}
{{- end }}