mirror of
https://github.com/GothenburgBitFactory/taskchampion-sync-server.git
synced 2026-08-22 14:53:45 +00:00
170 lines
4.6 KiB
YAML
170 lines
4.6 KiB
YAML
# Override the chart name used in resource names
|
|
nameOverride: ""
|
|
# Override the full resource name (takes precedence over nameOverride)
|
|
fullnameOverride: ""
|
|
|
|
# Image configuration
|
|
image:
|
|
repository: ghcr.io/gothenburgbitfactory/taskchampion-sync-server
|
|
tag: "0.7.0"
|
|
pullPolicy: IfNotPresent
|
|
pullSecrets: []
|
|
# pullSecrets expects a list of objects with a "name" key:
|
|
# pullSecrets:
|
|
# - name: my-registry-cred
|
|
|
|
# Existing secret containing client IDs (comma-separated UUIDs)
|
|
# Expected key: client-ids
|
|
clientIdSecret: ""
|
|
|
|
# Environment variables passed directly to the container
|
|
# NOTE: DATA_DIR and CONNECTION are set automatically based on backend
|
|
# To add secret/configMap references, use valueFrom:
|
|
# - name: MY_SECRET_VAR
|
|
# valueFrom:
|
|
# secretKeyRef:
|
|
# name: my-secret
|
|
# key: my-key
|
|
env:
|
|
- name: RUST_LOG
|
|
value: info
|
|
- name: LISTEN
|
|
value: "0.0.0.0:8080"
|
|
- name: CREATE_CLIENTS
|
|
value: "true"
|
|
|
|
# Service configuration
|
|
service:
|
|
type: ClusterIP
|
|
port: 8080
|
|
targetPort: 8080
|
|
|
|
# Ingress configuration
|
|
# Each host can be a string (simple) or a map with path rules:
|
|
# hosts:
|
|
# - host: app.example.com
|
|
# paths:
|
|
# - path: /
|
|
# pathType: Prefix
|
|
# - path: /api
|
|
# pathType: Exact
|
|
ingress:
|
|
enabled: false
|
|
className: ""
|
|
annotations: {}
|
|
hosts: []
|
|
tls: []
|
|
|
|
# HTTPRoute configuration (Kubernetes Gateway API)
|
|
httpRoute:
|
|
enabled: false
|
|
annotations: {}
|
|
|
|
# List of parent gateway references.
|
|
# name is required; namespace and sectionName are optional.
|
|
parentRefs: []
|
|
# parentRefs:
|
|
# - name: my-gateway
|
|
# namespace: gateway-system # optional — cross-namespace gateway reference
|
|
# sectionName: https # optional — targets a specific listener on the gateway
|
|
|
|
# List of hostnames the route applies to.
|
|
hostnames: []
|
|
# hostnames:
|
|
# - tasks.example.com
|
|
# - tasks.internal.example.com
|
|
|
|
# List of routing rules. Each rule matches a path and forwards to this chart's Service.
|
|
# When empty, falls back to the deprecated path/port fields below.
|
|
rules: []
|
|
# rules:
|
|
# - path:
|
|
# type: PathPrefix # PathPrefix or Exact
|
|
# value: /
|
|
# backendPort: 8080
|
|
|
|
# Deprecated: use parentRefs instead
|
|
gateway: ""
|
|
# Deprecated: use hostnames instead
|
|
host: ""
|
|
# Deprecated: use rules instead
|
|
path: "/"
|
|
port: 8080
|
|
|
|
# Replica configuration (only applies when postgres is enabled)
|
|
replicas:
|
|
enabled: false
|
|
count: 1
|
|
|
|
# ServiceAccount configuration
|
|
# The app does not access the Kubernetes API, so no RBAC permissions are needed.
|
|
# A dedicated ServiceAccount is created to give the pod a stable identity
|
|
# for network policies, pod security, or future RBAC.
|
|
serviceAccount:
|
|
# create specifies whether a ServiceAccount should be created
|
|
create: true
|
|
# name sets the ServiceAccount name
|
|
name: taskchampion-sync-server
|
|
|
|
# Security context for the pod
|
|
# NOTE: runAsUser and runAsGroup are intentionally unset.
|
|
# The Docker entrypoint requires root to chown the data directory and then
|
|
# drops privileges via su-exec to the taskchampion user (uid 1092).
|
|
securityContext:
|
|
fsGroup: 100
|
|
|
|
# SQLite backend configuration (mutually exclusive with postgres)
|
|
sqlite:
|
|
enabled: false
|
|
dataDir: /var/lib/taskchampion-sync-server/data
|
|
# Resource limits and requests
|
|
resources:
|
|
limits:
|
|
memory: 25Mi
|
|
cpu: 100m
|
|
requests:
|
|
# 5Mi is sufficient for the SQLite image
|
|
memory: 5Mi
|
|
cpu: 10m
|
|
existingPV: ""
|
|
emptyDir:
|
|
sizeLimit: ""
|
|
medium: ""
|
|
persistence:
|
|
enabled: true
|
|
size: 1Gi
|
|
accessMode: ReadWriteOnce
|
|
storageClass: ""
|
|
existingClaim: ""
|
|
|
|
# PostgreSQL configuration
|
|
postgres:
|
|
enabled: false
|
|
existingSecret: "" # If empty, auto-create secret; if provided, use existing
|
|
# Individual connection components for building connection string
|
|
database: taskchampion
|
|
host: postgres
|
|
port: 5432
|
|
username: user
|
|
password: ""
|
|
# SSL mode for the PostgreSQL connection.
|
|
# Use 'disable' for internal cluster connections (no TLS).
|
|
# Options: disable, allow, prefer, require, verify-ca, verify-full
|
|
sslMode: disable
|
|
initContainer:
|
|
enabled: true
|
|
image: postgres:17-alpine
|
|
imagePullPolicy: IfNotPresent
|
|
# Override the schema URL. Defaults to the official schema for this chart's appVersion.
|
|
# e.g. https://raw.githubusercontent.com/GothenburgBitFactory/taskchampion-sync-server/v0.7.0/postgres/schema.sql
|
|
schemaUrl: ""
|
|
# Resource limits and requests
|
|
resources:
|
|
limits:
|
|
memory: 100Mi
|
|
cpu: 100m
|
|
requests:
|
|
# 20Mi is the minimum for the Postgres image
|
|
memory: 20Mi
|
|
cpu: 10m
|