Skip to content
4 changes: 2 additions & 2 deletions helmfile.d/snippets/defaults.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,7 @@ environments:
cpu: 10m
git-server:
_rawValues: { }
enabled: true
enabled: false
resources:
requests:
cpu: 50m
Expand Down Expand Up @@ -1185,4 +1185,4 @@ environments:
authenticationLayer: keycloak
users: []
versions:
specVersion: 74
specVersion: 75
12 changes: 11 additions & 1 deletion helmfile.d/snippets/derived.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,14 @@
{{- $tlsSecretName = "otomi-byo-wildcard-cert" }}
{{- end -}}


{{- $gitValuesSource := "external" }}
{{- if contains "git-server.git-server.svc.cluster.local" $v.otomi.git.repoUrl }}
{{- /** built-in git-server */}}
{{- $gitValuesSource = "internal" }}
{{- else if contains "gitea-http.gitea.svc.cluster.local" $v.otomi.git.repoUrl }}
{{- /** Legacy Gitea values store */}}
{{- $gitValuesSource = "gitea" }}
{{- end }}

{{- $ingressClasses := $v.ingress.classes | default list }}
{{- $ingressClassNames := list $v.ingress.platformClass.className }}
Expand Down Expand Up @@ -261,6 +268,7 @@ environments:
egressGatewayName: {{ $egressGatewayName }}
egressGatewayLabel: {{ $egressGatewayLabel }}
ingressClassNames: {{- $ingressClassNames | toYaml | nindent 12 }}
gitValuesSource: {{ $gitValuesSource }}
{{- /* Hostnames the platform serves itself. auth is oauth2-proxy's own route; the bare domain must stay unclaimed too. */}}
platformHostnames:
- {{ $domainSuffix }}
Expand Down Expand Up @@ -290,6 +298,8 @@ environments:
{{- end }}
external-dns:
enabled: {{ $v.otomi.hasExternalDNS }}
git-server:
enabled: {{ or ($a | get "git-server.enabled") (eq $gitValuesSource "internal") }}
harbor: {}
keycloak:
address: {{ $keycloakBaseUrl }}
Expand Down
41 changes: 40 additions & 1 deletion src/cmd/bootstrap.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -180,9 +180,10 @@ describe('Bootstrapping values', () => {
})
})
describe('processing values', () => {
const internalRepoUrl = 'http://git-server.git-server.svc.cluster.local:3000/otomi-admin/values.git'
const externalRepoUrl = 'https://example.com/values.git'
const generatedSecrets = { gen: 'x' }
const ca = { a: 'cert' }
const mergedSecretsWithGen = merge(cloneDeep(secrets), cloneDeep(generatedSecrets))
let deps
beforeEach(() => {
deps = {
Expand Down Expand Up @@ -226,9 +227,11 @@ describe('Bootstrapping values', () => {
const res = await processValues(deps)
// mergedForDisk includes allSecrets (stripAllSecrets mock is identity, real impl strips x-secret paths)
expect(deps.writeValues).toHaveBeenNthCalledWith(1, {
apps: { 'git-server': { enabled: true } },
cluster: { name: 'bla', provider: 'dida' },
})
expect(res.originalInput).toEqual({
apps: { 'git-server': { enabled: true } },
cluster: { name: 'bla', provider: 'dida' },
})
})
Expand Down Expand Up @@ -257,6 +260,42 @@ describe('Bootstrapping values', () => {
const result = await processValues(deps)
expect(result.allSecrets).toEqual(merge(cloneDeep(ca), secrets))
})
it('should enable the internal git-server when no repo URL is given', async () => {
deps.loadYaml.mockReturnValue({ cluster: { name: 'bla', provider: 'dida' } })
const res = await processValues(deps)
expect(res.originalInput.apps['git-server'].enabled).toBe(true)
})
it('should enable the internal git-server when the repo URL points at the in-cluster git server', async () => {
deps.loadYaml.mockReturnValue({
cluster: { name: 'bla', provider: 'dida' },
otomi: { git: { repoUrl: internalRepoUrl } },
})
const res = await processValues(deps)
expect(res.originalInput.apps['git-server'].enabled).toBe(true)
})
it('should not enable the internal git-server when the repo URL is external', async () => {
deps.loadYaml.mockReturnValue({
cluster: { name: 'bla', provider: 'dida' },
otomi: { git: { repoUrl: externalRepoUrl } },
})
const res = await processValues(deps)
expect(res.originalInput.apps?.['git-server']).toBeUndefined()
})
it('should keep an explicitly disabled git-server disabled', async () => {
deps.loadYaml.mockReturnValue({
apps: { 'git-server': { enabled: false } },
})
const res = await processValues(deps)
expect(res.originalInput.apps['git-server'].enabled).toBe(false)
})
it('should keep an explicitly enabled git-server enabled', async () => {
deps.loadYaml.mockReturnValue({
apps: { 'git-server': { enabled: true } },
otomi: { git: { repoUrl: externalRepoUrl } },
})
const res = await processValues(deps)
expect(res.originalInput.apps['git-server'].enabled).toBe(true)
})
})
})
})
8 changes: 7 additions & 1 deletion src/cmd/bootstrap.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
import { existsSync } from 'fs'
import { copyFile, cp, mkdir, writeFile } from 'fs/promises'
import { cloneDeep, get, merge, pick, unset } from 'lodash'
import { cloneDeep, get, merge, pick, set, unset } from 'lodash'
import { pki } from 'node-forge'
import path from 'path'
import { bootstrapGit } from 'src/common/bootstrap'
Expand Down Expand Up @@ -118,6 +118,12 @@ export const processValues = async (
const { VALUES_INPUT } = env
d.log(`Loading app values from ${VALUES_INPUT}`)
const originalValues = (await deps.loadYaml(VALUES_INPUT)) as Record<string, any>
const repoUrl = get(originalValues, 'otomi.git.repoUrl')
const gitServerEnabled = get(originalValues, 'apps.git-server.enabled')
if ((!repoUrl || repoUrl.includes('git-server.git-server.svc.cluster.local')) && gitServerEnabled === undefined) {
// If any other Git URL is set, assume it is a Git repo external to the cluster
set(originalValues, 'apps.git-server.enabled', true)
Comment thread
merll marked this conversation as resolved.
Comment thread
CasLubbers marked this conversation as resolved.
}
Comment thread
Copilot marked this conversation as resolved.
// This part should be stored in a secret by initializeGitConfig
unset(originalValues, 'otomi.git')
const secretPaths = await deps.getSchemaSecretsPaths(Object.keys(get(originalValues, 'teamConfig', {})))
Expand Down
12 changes: 12 additions & 0 deletions src/cmd/migrate.ts
Original file line number Diff line number Diff line change
Expand Up @@ -778,6 +778,17 @@ const migrateGeneratedSecrets = async (values: Record<string, any>) => {
}
}

const deactivateGitServer = async (values: Record<string, any>) => {
const d = terminal('deactivateGitServer')
if (
values?.apps?.['git-server']?.enabled &&
!values?.otomi?.git?.repoUrl?.includes('git-server.git-server.svc.cluster.local')
) {
d.info('Disabling git-server as external Git repository is configured.')
set(values, 'apps.git-server.enabled', false)
Comment thread
merll marked this conversation as resolved.
Comment thread
merll marked this conversation as resolved.
}
}

const customMigrationFunctions: Record<string, CustomMigrationFunction> = {
valkeyAndOauth2RedisPVCMigration,
preservePvcStorageClassInRawValues,
Expand All @@ -787,6 +798,7 @@ const customMigrationFunctions: Record<string, CustomMigrationFunction> = {
removeIngressNginxValues,
removeSopsConfig,
migrateGeneratedSecrets,
deactivateGitServer,
}

/**
Expand Down
2 changes: 1 addition & 1 deletion tests/fixtures/env/settings/versions.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,4 @@ kind: AplVersion
metadata:
name: versions
spec:
specVersion: 74
specVersion: 75
3 changes: 3 additions & 0 deletions values-changes.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -55,3 +55,6 @@ changes:
additions:
- apps.keycloak.enabled: true
- otomi.oidc.authenticationLayer: keycloak
- version: 75
customFunctions:
- deactivateGitServer
4 changes: 2 additions & 2 deletions values/argocd/argocd-raw.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ resources:
data:
custom-ca-certificates.crt: {{ .Values._derived.caCert | b64enc }}
{{- end }}
{{- if contains "gitea-http.gitea.svc.cluster.local" $v.otomi.git.repoUrl }}
{{- if eq $v._derived.gitValuesSource "gitea" }}
{{- $gitSecretName = "argocd-repo-creds-gitea-internal" }}
{{- /* Additional secret specifically for external Git URL of Gitea */}}
- apiVersion: external-secrets.io/v1
Expand Down Expand Up @@ -41,7 +41,7 @@ resources:
- extract:
key: apl-git-config

{{- else if contains "git-server.git-server.svc.cluster.local" $v.otomi.git.repoUrl }}
{{- else if eq $v._derived.gitValuesSource "internal" }}
{{- $gitSecretName = "argocd-repo-creds-git-server" }}
{{- end }}
- apiVersion: external-secrets.io/v1
Expand Down
2 changes: 1 addition & 1 deletion values/team-ns/team-ns.gotmpl
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ httpRouteAnnotations: {{- $httpRoute.annotations | toYaml | nindent 2 }}

gitOps:
branch: {{ $v.otomi.git.branch }}
{{- if contains "gitea-http.gitea.svc.cluster.local" $v.otomi.git.repoUrl }}
{{- if eq $v._derived.gitValuesSource "gitea" }}
teamRepoUrl: "https://{{ $v._derived.giteaDomain }}/otomi/team-{{ $teamId }}-argocd.git"
valuesRepoUrl: "https://{{ $v._derived.giteaDomain }}/otomi/values.git"
workloadValuesRepoUrl: "https://{{ $v._derived.giteaDomain }}/otomi/values.git"
Expand Down
Loading