Public Access
Provides a self-contained, containerized aptly (Debian repo manager) stack with independently releasable image and Helm chart versions. - images/: aptly-server (aptly built from source, cross-compiled) and aptly-deb-builder (nfpm + dpkg-buildpackage) container images - rootfs/: shared aptly-init/aptly-reconcile/aptly-push/aptly-pack scripts consumed identically by Compose and the Helm chart, driven by one declarative state.yaml contract - compose/: test (ephemeral, open) and production docker-compose stacks with an nginx read/auth sidecar - charts/aptly/: aptly-native Helm chart covering every security posture from fully open to authenticated read+write, Ingress and Gateway API support (usable in parallel for migration scenarios), metrics, and declarative repo/mirror/publish reconciliation via a Helm hook - .gitea/workflows/: CI (lint, template, kubeconform, E2E smoke test) plus separately tagged image (image/v*) and chart (chart/v*) releases, weekly rebuilds, and a preflight workflow validating the runner's Docker/Helm-OCI capabilities - pubkeys/: RSA chart-signing key for Helm --sign / Artifact Hub's signKey annotation (Helm can't verify Ed25519 keys) - docs/, README.md, charts/aptly/README.md: usage, security, and versioning documentation
299 lines
11 KiB
YAML
299 lines
11 KiB
YAML
{{- $fullname := include "aptly.fullname" . -}}
|
|
{{- $hasGpgSecret := or .Values.aptly.gpg.signingKey.existingSecret (and (not .Values.aptly.gpg.signingKey.existingSecret) .Values.aptly.gpg.signingKey.privateKey) -}}
|
|
{{- $gpgSecretName := .Values.aptly.gpg.signingKey.existingSecret | default (printf "%s-gpg" $fullname) -}}
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: {{ $fullname }}
|
|
labels:
|
|
{{- include "aptly.labels" . | nindent 4 }}
|
|
{{- with .Values.workload.annotations }}
|
|
annotations:
|
|
{{- toYaml . | nindent 4 }}
|
|
{{- end }}
|
|
spec:
|
|
serviceName: {{ $fullname }}
|
|
# LevelDB (aptly's database) takes an exclusive OS-level file lock — two
|
|
# writers would corrupt it. A StatefulSet with replicas=1 always terminates
|
|
# the old pod before creating its replacement, so RollingUpdate is safe
|
|
# here in a way it would not be for a Deployment on a ReadWriteOnce PVC
|
|
# (which would deadlock on a Multi-Attach error instead).
|
|
replicas: 1
|
|
podManagementPolicy: {{ .Values.workload.podManagementPolicy }}
|
|
revisionHistoryLimit: {{ .Values.workload.revisionHistoryLimit }}
|
|
updateStrategy:
|
|
type: {{ .Values.workload.updateStrategy.type }}
|
|
selector:
|
|
matchLabels:
|
|
{{- include "aptly.selectorLabels" . | nindent 6 }}
|
|
template:
|
|
metadata:
|
|
labels:
|
|
{{- include "aptly.selectorLabels" . | nindent 8 }}
|
|
{{- with .Values.workload.podLabels }}
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
annotations:
|
|
checksum/config: {{ include "aptly.config" . | sha256sum }}
|
|
checksum/nginx: {{ include "aptly.nginxConf" . | sha256sum }}
|
|
{{- with .Values.workload.podAnnotations }}
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
spec:
|
|
{{- include "aptly.imagePullSecrets" . | nindent 6 }}
|
|
terminationGracePeriodSeconds: {{ .Values.workload.terminationGracePeriodSeconds }}
|
|
securityContext:
|
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
|
{{- with .Values.nodeSelector }}
|
|
nodeSelector:
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
{{- with .Values.affinity }}
|
|
affinity:
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
{{- with .Values.tolerations }}
|
|
tolerations:
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
{{- with .Values.topologySpreadConstraints }}
|
|
topologySpreadConstraints:
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
{{- with .Values.priorityClassName }}
|
|
priorityClassName: {{ . }}
|
|
{{- end }}
|
|
initContainers:
|
|
- name: config-init
|
|
image: {{ include "aptly.image" . }}
|
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
command: ["/usr/local/bin/aptly-init"]
|
|
securityContext:
|
|
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
|
|
env:
|
|
- name: APTLY_ROOT_DIR
|
|
value: /var/lib/aptly
|
|
- name: APTLY_CONFIG_SRC
|
|
value: /etc/aptly-src/aptly.yaml
|
|
- name: APTLY_CONFIG_DST
|
|
value: /run/aptly/aptly.yaml
|
|
- name: APTLY_GPG_ENABLED
|
|
value: {{ .Values.aptly.gpg.enabled | quote }}
|
|
{{- if not .Values.security.auth.existingSecret }}
|
|
- name: APTLY_USERS_FILE
|
|
value: /etc/aptly-secrets/users
|
|
{{- else }}
|
|
- name: APTLY_HTPASSWD_SRC
|
|
value: /etc/aptly-secrets-existing/htpasswd
|
|
{{- end }}
|
|
{{- if .Values.security.auth.internalUser.enabled }}
|
|
- name: APTLY_INTERNAL_USER
|
|
value: {{ .Values.security.auth.internalUser.username | quote }}
|
|
- name: APTLY_INTERNAL_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: {{ $fullname }}-credentials
|
|
key: internal-password
|
|
{{- end }}
|
|
{{- if $hasGpgSecret }}
|
|
- name: APTLY_GPG_PRIVATE_KEY_FILE
|
|
value: /etc/aptly-gpg/privateKey
|
|
- name: APTLY_GPG_SECRET_KEYRING_FILE
|
|
value: /etc/aptly-gpg/secretKeyring
|
|
- name: APTLY_GPG_PASSPHRASE_FILE
|
|
value: /etc/aptly-gpg/passphrase
|
|
{{- end }}
|
|
{{- if .Values.aptly.gpgKeys }}
|
|
- name: APTLY_GPG_KEYS_DIR
|
|
value: /etc/aptly-gpg-keys
|
|
{{- end }}
|
|
volumeMounts:
|
|
- name: config-src
|
|
mountPath: /etc/aptly-src
|
|
readOnly: true
|
|
- name: run
|
|
mountPath: /run/aptly
|
|
- name: data
|
|
mountPath: /var/lib/aptly
|
|
{{- if not .Values.security.auth.existingSecret }}
|
|
- name: credentials
|
|
mountPath: /etc/aptly-secrets
|
|
readOnly: true
|
|
{{- else }}
|
|
- name: credentials-existing
|
|
mountPath: /etc/aptly-secrets-existing
|
|
readOnly: true
|
|
{{- end }}
|
|
{{- if $hasGpgSecret }}
|
|
- name: gpg-secret
|
|
mountPath: /etc/aptly-gpg
|
|
readOnly: true
|
|
{{- end }}
|
|
{{- if .Values.aptly.gpgKeys }}
|
|
- name: gpg-keys
|
|
mountPath: /etc/aptly-gpg-keys
|
|
readOnly: true
|
|
{{- end }}
|
|
{{- with .Values.extraInitContainers }}
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
containers:
|
|
- name: aptly
|
|
image: {{ include "aptly.image" . }}
|
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
securityContext:
|
|
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
|
|
env:
|
|
- name: APTLY_API_LISTEN
|
|
value: {{ include "aptly.apiListen" . }}
|
|
- name: APTLY_CONFIG
|
|
value: /run/aptly/aptly.yaml
|
|
- name: GNUPGHOME
|
|
value: /run/aptly/gnupg
|
|
{{- with .Values.extraEnv }}
|
|
{{- toYaml . | nindent 12 }}
|
|
{{- end }}
|
|
{{- if or .Values.aptly.existingSecretEnv .Values.extraEnvFrom }}
|
|
envFrom:
|
|
{{- range .Values.aptly.existingSecretEnv }}
|
|
- secretRef:
|
|
name: {{ . }}
|
|
{{- end }}
|
|
{{- with .Values.extraEnvFrom }}
|
|
{{- toYaml . | nindent 12 }}
|
|
{{- end }}
|
|
{{- end }}
|
|
ports:
|
|
- name: aptly
|
|
containerPort: 8080
|
|
volumeMounts:
|
|
- name: data
|
|
mountPath: /var/lib/aptly
|
|
- name: run
|
|
mountPath: /run/aptly
|
|
- name: tmp
|
|
mountPath: /tmp
|
|
{{- with .Values.extraVolumeMounts }}
|
|
{{- toYaml . | nindent 12 }}
|
|
{{- end }}
|
|
startupProbe:
|
|
httpGet: { path: /api/ready, port: aptly }
|
|
periodSeconds: {{ .Values.probes.startup.periodSeconds }}
|
|
failureThreshold: {{ .Values.probes.startup.failureThreshold }}
|
|
readinessProbe:
|
|
httpGet: { path: /api/ready, port: aptly }
|
|
periodSeconds: {{ .Values.probes.readiness.periodSeconds }}
|
|
timeoutSeconds: {{ .Values.probes.readiness.timeoutSeconds }}
|
|
failureThreshold: {{ .Values.probes.readiness.failureThreshold }}
|
|
livenessProbe:
|
|
httpGet: { path: /api/healthy, port: aptly }
|
|
periodSeconds: {{ .Values.probes.liveness.periodSeconds }}
|
|
timeoutSeconds: {{ .Values.probes.liveness.timeoutSeconds }}
|
|
failureThreshold: {{ .Values.probes.liveness.failureThreshold }}
|
|
resources:
|
|
{{- toYaml .Values.resources | nindent 12 }}
|
|
- name: nginx
|
|
image: {{ include "aptly.nginxImage" . }}
|
|
imagePullPolicy: {{ .Values.nginx.image.pullPolicy }}
|
|
securityContext:
|
|
{{- toYaml .Values.nginx.securityContext | nindent 12 }}
|
|
ports:
|
|
- name: http
|
|
containerPort: 8080
|
|
{{- if .Values.metrics.service.enabled }}
|
|
- name: metrics
|
|
containerPort: 9090
|
|
{{- end }}
|
|
volumeMounts:
|
|
- name: data
|
|
mountPath: /var/lib/aptly/public
|
|
subPath: public
|
|
readOnly: true
|
|
- name: run
|
|
mountPath: /run/aptly
|
|
readOnly: true
|
|
- name: nginx-config
|
|
mountPath: /etc/nginx/conf.d/default.conf
|
|
subPath: default.conf
|
|
readOnly: true
|
|
- name: tmp
|
|
mountPath: /tmp
|
|
- name: nginx-cache
|
|
mountPath: /var/cache/nginx
|
|
readinessProbe:
|
|
httpGet: { path: /healthz, port: http }
|
|
periodSeconds: 10
|
|
livenessProbe:
|
|
httpGet: { path: /healthz, port: http }
|
|
periodSeconds: 30
|
|
resources:
|
|
{{- toYaml .Values.nginx.resources | nindent 12 }}
|
|
{{- with .Values.extraContainers }}
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
volumes:
|
|
- name: config-src
|
|
configMap:
|
|
name: {{ $fullname }}-config
|
|
- name: nginx-config
|
|
configMap:
|
|
name: {{ $fullname }}-nginx
|
|
- name: run
|
|
emptyDir:
|
|
medium: Memory
|
|
sizeLimit: 16Mi
|
|
- name: tmp
|
|
emptyDir: {}
|
|
- name: nginx-cache
|
|
emptyDir: {}
|
|
{{- if not .Values.security.auth.existingSecret }}
|
|
- name: credentials
|
|
secret:
|
|
secretName: {{ $fullname }}-credentials
|
|
optional: true
|
|
{{- else }}
|
|
- name: credentials-existing
|
|
secret:
|
|
secretName: {{ .Values.security.auth.existingSecret }}
|
|
{{- end }}
|
|
{{- if $hasGpgSecret }}
|
|
- name: gpg-secret
|
|
secret:
|
|
secretName: {{ $gpgSecretName }}
|
|
optional: true
|
|
{{- end }}
|
|
{{- if .Values.aptly.gpgKeys }}
|
|
- name: gpg-keys
|
|
configMap:
|
|
name: {{ $fullname }}-gpg-keys
|
|
{{- end }}
|
|
{{- if not .Values.persistence.enabled }}
|
|
- name: data
|
|
emptyDir: {}
|
|
{{- else if .Values.persistence.existingClaim }}
|
|
- name: data
|
|
persistentVolumeClaim:
|
|
claimName: {{ .Values.persistence.existingClaim }}
|
|
{{- end }}
|
|
{{- with .Values.extraVolumes }}
|
|
{{- toYaml . | nindent 8 }}
|
|
{{- end }}
|
|
{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }}
|
|
volumeClaimTemplates:
|
|
- metadata:
|
|
name: data
|
|
{{- with .Values.persistence.annotations }}
|
|
annotations:
|
|
{{- toYaml . | nindent 10 }}
|
|
{{- end }}
|
|
spec:
|
|
accessModes: [{{ .Values.persistence.accessMode }}]
|
|
{{- $sc := .Values.persistence.storageClass | default .Values.global.defaultStorageClass }}
|
|
{{- if $sc }}
|
|
storageClassName: {{ $sc }}
|
|
{{- end }}
|
|
resources:
|
|
requests:
|
|
storage: {{ .Values.persistence.size }}
|
|
{{- end }}
|