Author SHA1 Message Date
f.weber f345f469da Add ArtifactHub repository metadata and improve Helm chart configuration
CI / lint (push) Failing after 3s
Release chart / release (release) Successful in 9s
CI / smoke-test (push) Failing after 5s
- Introduced artifacthub-repo.yml for ownership verification on ArtifactHub.
- Updated release-chart.yaml to publish the ArtifactHub metadata as an OCI artifact.
- Bumped chart version to 0.2.2 and added relevant changes to Chart.yaml.
- Enhanced job-reconcile.yaml by adding a writable /tmp directory for the reconcile job.
2026-08-13 12:42:41 +02:00
f.weber a08ed898e8 Update Helm chart version and modify probes to use exec for readiness and liveness checks
CI / lint (push) Failing after 3s
CI / smoke-test (push) Failing after 5s
Release chart / release (release) Successful in 6s
2026-08-13 12:30:17 +02:00
5 changed files with 42 additions and 10 deletions
+20
View File
@@ -25,6 +25,10 @@ name: Release chart
# generic OCI artifacts, and a chart sharing the exact repository path with
# the container image of the same name makes the package listing/type
# ambiguous. A distinct `charts/` path keeps the two package kinds apart.
#
# Also pushes charts/aptly/artifacthub-repo.yml as a companion OCI artifact
# (tag `artifacthub.io`) on every run, proving ownership of this repository
# to ArtifactHub — see the "Publish ArtifactHub repository metadata" step.
on:
release:
types: [published]
@@ -104,6 +108,22 @@ jobs:
--username "${{ secrets.REGISTRY_USER }}" --password-stdin
helm push "aptly-${{ steps.version.outputs.version }}.tgz" oci://git.morlana.online/f.weber/charts
# Publishes charts/aptly/artifacthub-repo.yml as its own OCI artifact
# (tag `artifacthub.io`) next to the chart — this is how ArtifactHub
# verifies ownership of an OCI-based Helm repository; there's no
# index.yaml it could otherwise crawl a metadata file out of. Uses the
# same registry credentials as the chart push above, nothing
# ArtifactHub-specific is needed (ArtifactHub has no publish API to
# authenticate against — it only reads the registry).
- uses: oras-project/setup-oras@v1
- name: Publish ArtifactHub repository metadata (ownership verification)
run: |
echo "${{ secrets.REGISTRY_TOKEN }}" | oras login git.morlana.online \
--username "${{ secrets.REGISTRY_USER }}" --password-stdin
oras push git.morlana.online/f.weber/charts/aptly:artifacthub.io \
--config /dev/null:application/vnd.cncf.artifacthub.config.v1+yaml \
charts/aptly/artifacthub-repo.yml:application/vnd.cncf.artifacthub.repository-metadata.layer.v1.yaml
- name: Attach chart artifacts to the Gitea release
uses: softprops/action-gh-release@v2
with:
+3 -7
View File
@@ -5,7 +5,7 @@ description: >-
an nginx read/auth sidecar, a fully aptly-native values API, and declarative
repo/mirror/publish state reconciled via a Helm hook.
type: application
version: 0.2.0
version: 0.2.2
appVersion: "1.6.3-1"
home: https://git.morlana.online/f.weber/aptly-containerized
sources:
@@ -33,10 +33,6 @@ annotations:
url: https://git.morlana.online/f.weber/aptly-containerized/raw/branch/main/pubkeys/chart-signing.asc
artifacthub.io/changes: |
- kind: added
description: Configurable ServiceAccount (serviceAccount.create/name/annotations/automountServiceAccountToken), defaulting to a dedicated ServiceAccount per release.
- kind: added
description: Configurable internal container ports (ports.aptly/nginx/metrics).
description: Repository ownership verification for ArtifactHub (charts/aptly/artifacthub-repo.yml), published as a companion OCI artifact by release-chart.yaml.
- kind: fixed
description: nginx and aptly no longer both listen on port 8080 inside the same pod, which made nginx fail to start with "address already in use". nginx now defaults to 8081 internally; external service.port is unchanged.
- kind: changed
description: Chart releases are now triggered by publishing a Gitea Release (instead of a bare tag push), so pre-releases can be flagged for ArtifactHub.
description: The reconcile Job's container had readOnlyRootFilesystem but no writable /tmp, so its own API client's scratch files failed to write ("Read-only file system") and every reconcile call died with a misleading "connection" error. A /tmp emptyDir is now mounted there too, matching the aptly/nginx containers in the StatefulSet.
+6
View File
@@ -0,0 +1,6 @@
repositoryID: "1ed468a7-7886-48ad-8835-369bc8a06bc5"
owners:
- name: Morlana
email: contact@morlana.net
- name: Florian Weber
email: f.weber@flweber.me
@@ -75,10 +75,14 @@ spec:
mountPath: /state.yaml
subPath: state.yaml
readOnly: true
- name: tmp
mountPath: /tmp
resources:
{{- toYaml .Values.reconcile.resources | nindent 12 }}
volumes:
- name: state
configMap:
name: {{ $fullname }}-state
- name: tmp
emptyDir: {}
{{- end }}
+9 -3
View File
@@ -180,17 +180,23 @@ spec:
{{- with .Values.extraVolumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
# exec, not httpGet: aptly listens on 127.0.0.1 only (see
# aptly.apiListen) when proxy.enabled=true, but kubelet's httpGet
# probes connect to the POD IP, not localhost — that dials a
# loopback-only listener from outside and gets "connection
# refused". exec runs curl inside this container's own netns,
# where 127.0.0.1 is correct in either proxy mode.
startupProbe:
httpGet: { path: /api/ready, port: aptly }
exec: { command: ["curl", "-fsS", "http://127.0.0.1:{{ .Values.ports.aptly }}/api/ready"] }
periodSeconds: {{ .Values.probes.startup.periodSeconds }}
failureThreshold: {{ .Values.probes.startup.failureThreshold }}
readinessProbe:
httpGet: { path: /api/ready, port: aptly }
exec: { command: ["curl", "-fsS", "http://127.0.0.1:{{ .Values.ports.aptly }}/api/ready"] }
periodSeconds: {{ .Values.probes.readiness.periodSeconds }}
timeoutSeconds: {{ .Values.probes.readiness.timeoutSeconds }}
failureThreshold: {{ .Values.probes.readiness.failureThreshold }}
livenessProbe:
httpGet: { path: /api/healthy, port: aptly }
exec: { command: ["curl", "-fsS", "http://127.0.0.1:{{ .Values.ports.aptly }}/api/healthy"] }
periodSeconds: {{ .Values.probes.liveness.periodSeconds }}
timeoutSeconds: {{ .Values.probes.liveness.timeoutSeconds }}
failureThreshold: {{ .Values.probes.liveness.failureThreshold }}