fix(helm): 修正 Bitnami 依赖连线并同步应用配置

基于当前 SkillHub 运行时契约和 Bitnami 依赖命名,更新原贡献者提交的 Helm Chart 配置。

- 将 Server 正确连接到实际的 PostgreSQL 和 Redis Service 与 Secret
- 支持依赖组件的 existingSecret 名称和自定义密码 key,避免安装时 lookup
- 同步 S3、匿名下载、Scanner LLM、公开地址、设备认证和直接认证配置
- 将应用版本和 Chart 版本对齐当前发布版本
- 收紧 Chart 发布触发条件和手动版本选择逻辑
- 增加依赖 Service、Secret 和密码 key 的 CI 语义断言

已通过 Helm lint、九组渲染场景、kubeconform、工作流安全检查和后端应用测试套件。

Signed-off-by: lhb6540 <lhb6540@gmail.com>
This commit is contained in:
lhb6540 2026-07-14 14:42:38 +08:00
parent 2b1be5ccf8
commit 3b3905be63
11 changed files with 267 additions and 83 deletions

View file

@ -4,6 +4,8 @@ on:
pull_request:
paths:
- charts/skillhub/**
- .github/workflows/pr-helm-chart.yml
- .github/workflows/publish-chart.yml
types:
- opened
- synchronize
@ -30,11 +32,13 @@ jobs:
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
persist-credentials: false
- name: Set up Helm
uses: azure/setup-helm@v4
with:
version: latest
version: v3.19.0
- name: Build dependencies
run: helm dependency build .
@ -121,11 +125,13 @@ jobs:
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
persist-credentials: false
- name: Set up Helm
uses: azure/setup-helm@v4
with:
version: latest
version: v3.19.0
- name: Build dependencies
run: helm dependency build .
@ -145,6 +151,25 @@ jobs:
exit 1
fi
- name: Validate default dependency wiring
if: ${{ matrix.scenario.name == 'bitnami-default' }}
run: |
helm template test-release . --show-only templates/server-deployment.yaml > server.yaml
grep -Fq 'value: test-release-postgresql' server.yaml
grep -Fq 'value: test-release-redis-master' server.yaml
grep -Fq 'name: test-release-postgresql' server.yaml
grep -Fq 'name: test-release-redis' server.yaml
grep -Fq 'key: password' server.yaml
grep -Fq 'key: redis-password' server.yaml
if grep -Fq 'test-release-skillhub-postgresql' server.yaml; then
echo 'ERROR: Server references a non-existent PostgreSQL service'
exit 1
fi
if grep -Fq 'test-release-skillhub-redis' server.yaml; then
echo 'ERROR: Server references a non-existent Redis service'
exit 1
fi
- name: Schema validation (kubeconform)
uses: docker://ghcr.io/yannh/kubeconform:latest
with:

View file

@ -4,6 +4,11 @@ on:
release:
types: [published]
workflow_dispatch:
inputs:
version:
description: Chart and application version (for example, 0.2.13)
required: true
type: string
concurrency:
group: publish-chart-${{ github.ref }}
@ -15,6 +20,11 @@ permissions:
jobs:
release:
if: >-
github.event_name == 'workflow_dispatch' ||
startsWith(github.ref_name, 'v') ||
startsWith(github.ref_name, 'chart-v') ||
startsWith(github.ref_name, 'helm-v')
runs-on: ubuntu-latest
defaults:
run:
@ -23,11 +33,13 @@ jobs:
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
persist-credentials: false
- name: Set up Helm
uses: azure/setup-helm@v4
with:
version: latest
version: v3.19.0
- name: Verify dependencies
run: helm dependency build .
@ -38,12 +50,19 @@ jobs:
- name: Parse version from tag
id: ver
run: |
REF="${{ github.ref_name }}"
# 兼容 v0.2.9、chart-v0.2.9、helm-v0.2.9 三种标签格式
if [[ "$REF" =~ ^(helm|chart)-v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then
VER="${{ inputs.version }}"
elif [[ "${{ github.ref_name }}" =~ ^(helm|chart)-v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
VER="${BASH_REMATCH[2]}"
elif [[ "${{ github.ref_name }}" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
VER="${BASH_REMATCH[1]}"
else
VER="${REF#v}"
echo "ERROR: Unsupported release tag: ${{ github.ref_name }}"
exit 1
fi
if [[ ! "$VER" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "ERROR: Version must use MAJOR.MINOR.PATCH format: $VER"
exit 1
fi
echo "version=$VER" >> "$GITHUB_OUTPUT"

View file

@ -2,8 +2,8 @@ apiVersion: v2
name: skillhub
description: Self-hosted, open-source agent skill registry for enterprises.
type: application
version: 0.3.0
appVersion: 0.3.0
version: 0.1.0
appVersion: 0.2.13
keywords:
- skillhub
- ai

View file

@ -24,7 +24,8 @@
kubectl create namespace skillhub
helm -n skillhub upgrade -i skillhub ./charts/skillhub \
--set bootstrapAdmin.password=your-secure-password
--set bootstrapAdmin.password=your-secure-password \
--set publicBaseUrl=https://skills.example.com
```
### 高可用模式
@ -55,22 +56,23 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \
### 使用 existingSecret
通过 `existingSecret` 引用已存在的 Secret 对象,避免在 values 中明文写入密码。该 Secret 必须包含以下 key:
通过 `existingSecret` 引用已存在的 Secret 对象,避免在 values 中明文写入密码。
内置 PostgreSQL/Redis 使用各自的 Bitnami Secret,不需要复制到该 Secret。
| Key | 必填 | 说明 |
|-----|------|------|
| `spring-datasource-url` | 是 | JDBC 连接 URL |
| `spring-datasource-username` | 是 | 数据库用户名 |
| `spring-datasource-password` | 是 | 数据库密码 |
| `redis-password` | 是 | Redis 密码 |
| `redis-sentinel-password` | 否 | Redis Sentinel 密码(sentinel 模式) |
| `spring-datasource-password` | 使用外部 PostgreSQL 时 | 数据库密码 |
| `redis-password` | 使用外部 Redis 时 | Redis 密码 |
| `redis-sentinel-password` | 使用外部 Sentinel 时 | Redis Sentinel 密码 |
| `bootstrap-admin-password` | 是 | 初始管理员密码 |
| `skillhub-download-anon-cookie-secret` | 是 | 至少 32 字符的匿名下载 Cookie 签名密钥 |
| `oauth2-github-client-id` | 否 | GitHub OAuth2 Client ID |
| `oauth2-github-client-secret` | 否 | GitHub OAuth2 Client Secret |
| `skill-scanner-llm-api-key` | 否 | Scanner LLM API Key |
| `skill-scanner-llm-base-url` | 否 | Scanner 自定义 LLM API 地址 |
| `skill-scanner-llm-model` | 否 | Scanner LLM 模型名称 |
| `s3-access-key` | 否 | S3 Access Key |
| `s3-secret-key` | 否 | S3 Secret Key |
| `skillhub-storage-s3-access-key` | 否 | S3 Access Key |
| `skillhub-storage-s3-secret-key` | 否 | S3 Secret Key |
```bash
helm -n skillhub upgrade -i skillhub ./charts/skillhub \
@ -137,7 +139,11 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \
| `s3.enabled` | 启用 S3 | `false` |
| `s3.bucket` | Bucket 名称 | `skillhub-storage` |
| `s3.endpoint` | S3 端点 | `""` |
| `s3.publicEndpoint` | S3 公网访问端点 | `""` |
| `s3.region` | 区域 | `us-east-1` |
| `s3.forcePathStyle` | 强制 path-style 访问 | `true` |
| `s3.disableChunkedEncoding` | 禁用 aws-chunked 编码 | `false` |
| `s3.autoCreateBucket` | 自动创建 Bucket | `false` |
| `s3.accessKey` | Access Key | `""` |
| `s3.secretKey` | Secret Key | `""` |
@ -158,6 +164,7 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \
helm -n skillhub upgrade -i skillhub ./charts/skillhub \
--set ingress.enabled=true \
--set ingress.host=skills.example.com \
--set publicBaseUrl=https://skills.example.com \
--set ingress.tls.enabled=true \
--set ingress.certManager.enabled=true
```

View file

@ -70,10 +70,38 @@ app.kubernetes.io/component: scanner
app.kubernetes.io/component: scanner
{{- end }}
{{- /* Bitnami PostgreSQL subchart 完整名称 */}}
{{- define "skillhub.postgresql.fullname" -}}
{{- if .Values.postgresql.fullnameOverride -}}
{{- .Values.postgresql.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default "postgresql" .Values.postgresql.nameOverride -}}
{{- if contains $name .Release.Name -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- end }}
{{- /* Bitnami Redis subchart 完整名称 */}}
{{- define "skillhub.redis.fullname" -}}
{{- if .Values.redis.fullnameOverride -}}
{{- .Values.redis.fullnameOverride | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- $name := default "redis" .Values.redis.nameOverride -}}
{{- if contains $name .Release.Name -}}
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
{{- else -}}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- end }}
{{- /* PostgreSQL Host */}}
{{- define "skillhub.postgresql.host" -}}
{{- if .Values.postgresql.enabled -}}
{{- $prefix := printf "%s-postgresql" (include "skillhub.fullname" .) -}}
{{- $prefix := include "skillhub.postgresql.fullname" . -}}
{{- if eq .Values.postgresql.architecture "replication" -}}
{{- printf "%s-primary" $prefix -}}
{{- else -}}
@ -114,12 +142,17 @@ app.kubernetes.io/component: scanner
{{- /* PostgreSQL Secret Name */}}
{{- define "skillhub.postgresql.secretName" -}}
{{- if .Values.postgresql.enabled -}}
{{- printf "%s-postgresql" (include "skillhub.fullname" .) -}}
{{- .Values.postgresql.auth.existingSecret | default (include "skillhub.postgresql.fullname" .) -}}
{{- else -}}
{{- include "skillhub.secretName" . -}}
{{- end -}}
{{- end }}
{{- /* PostgreSQL 应用用户密码 Secret key */}}
{{- define "skillhub.postgresql.passwordKey" -}}
{{- .Values.postgresql.auth.secretKeys.userPasswordKey | default "password" -}}
{{- end }}
{{- /* PostgreSQL JDBC URL */}}
{{- define "skillhub.jdbcUrl" -}}
{{- if .Values.postgresql.enabled -}}
@ -135,8 +168,9 @@ app.kubernetes.io/component: scanner
{{- /* Redis Sentinel 节点列表(Redisson 需要具体 pod FQDN,格式: {pod}.{headless-svc}.{ns}.svc.cluster.local) */}}
{{- define "skillhub.redis.sentinel.nodes" -}}
{{- $prefix := printf "%s-redis-node" (include "skillhub.fullname" .) -}}
{{- $headless := printf "%s-redis-headless" (include "skillhub.fullname" .) -}}
{{- $fullname := include "skillhub.redis.fullname" . -}}
{{- $prefix := printf "%s-node" $fullname -}}
{{- $headless := printf "%s-headless" $fullname -}}
{{- $port := include "skillhub.redis.port" . -}}
{{- $replicas := .Values.redis.replica.replicaCount | default 3 | int -}}
{{- $nodes := list -}}{{- range $i := until $replicas -}}{{- $nodes = append $nodes (printf "%s-%d.%s.%s.svc.cluster.local:%s" $prefix $i $headless $.Release.Namespace $port) -}}{{- end -}}{{- join "," $nodes -}}
@ -146,9 +180,9 @@ app.kubernetes.io/component: scanner
{{- define "skillhub.redis.host" -}}
{{- if .Values.redis.enabled -}}
{{- if .Values.redis.sentinel.enabled -}}
{{- printf "%s-redis" (include "skillhub.fullname" .) -}}
{{- include "skillhub.redis.fullname" . -}}
{{- else -}}
{{- printf "%s-redis-master" (include "skillhub.fullname" .) -}}
{{- printf "%s-master" (include "skillhub.redis.fullname" .) -}}
{{- end -}}
{{- else -}}
{{- .Values.externalRedis.host -}}
@ -171,12 +205,17 @@ app.kubernetes.io/component: scanner
{{- /* Redis Password Secret Name */}}
{{- define "skillhub.redis.secretName" -}}
{{- if .Values.redis.enabled -}}
{{- printf "%s-redis" (include "skillhub.fullname" .) -}}
{{- .Values.redis.auth.existingSecret | default (include "skillhub.redis.fullname" .) -}}
{{- else -}}
{{- include "skillhub.secretName" . -}}
{{- end -}}
{{- end }}
{{- /* Redis 密码 Secret key */}}
{{- define "skillhub.redis.passwordKey" -}}
{{- .Values.redis.auth.existingSecretPasswordKey | default "redis-password" -}}
{{- end }}
{{- /* Secret 名称 */}}
{{- define "skillhub.secretName" -}}
{{- .Values.existingSecret | default (printf "%s-secret" (include "skillhub.fullname" .)) }}

View file

@ -22,7 +22,12 @@ data:
# S3 配置
s3-bucket: {{ .Values.s3.bucket }}
s3-endpoint: {{ .Values.s3.endpoint }}
s3-public-endpoint: {{ .Values.s3.publicEndpoint }}
s3-region: {{ .Values.s3.region }}
s3-force-path-style: {{ .Values.s3.forcePathStyle | quote }}
s3-disable-chunked-encoding: {{ .Values.s3.disableChunkedEncoding | quote }}
s3-auto-create-bucket: {{ .Values.s3.autoCreateBucket | quote }}
s3-presign-expiry: {{ .Values.s3.presignExpiry | quote }}
{{- end }}
# 技能扫描器
@ -39,3 +44,10 @@ data:
# Session
session-cookie-secure: {{ .Values.session.cookieSecure | quote }}
# Public URL and authentication
public-base-url: {{ .Values.publicBaseUrl | quote }}
device-auth-verification-uri: {{ .Values.deviceAuthVerificationUri | quote }}
auth-direct-enabled: {{ .Values.auth.direct.enabled | quote }}
auth-direct-provider: {{ .Values.auth.direct.provider | quote }}
builtin-skills-enabled: {{ .Values.builtinSkills.enabled | quote }}

View file

@ -17,7 +17,7 @@ spec:
labels:
{{- include "skillhub.scanner.selectorLabels" . | nindent 8 }}
annotations:
checksum/config: {{ toYaml (dict "scanner" .Values.scanner) | sha256sum }}
checksum/config: {{ toYaml (dict "scanner" .Values.scanner "secrets" .Values.secrets "existingSecret" .Values.existingSecret) | sha256sum }}
{{- range $key, $val := .Values.scanner.podAnnotations }}
{{ $key }}: {{ $val }}
{{- end }}
@ -41,6 +41,12 @@ spec:
name: {{ include "skillhub.secretName" . }}
key: skill-scanner-llm-api-key
optional: true
- name: SKILL_SCANNER_LLM_BASE_URL
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
key: skill-scanner-llm-base-url
optional: true
- name: SKILL_SCANNER_LLM_MODEL
valueFrom:
secretKeyRef:

View file

@ -5,10 +5,6 @@ SkillHub 应用 Secret
*/}}
{{- if not .Values.existingSecret }}
{{- $secretName := include "skillhub.secretName" . }}
{{- $postgresSecretName := include "skillhub.postgresql.secretName" . }}
{{- $redisSecretName := include "skillhub.redis.secretName" . }}
{{- $postgresSecret := (lookup "v1" "Secret" $.Release.Namespace $postgresSecretName) }}
{{- $redisSecret := (lookup "v1" "Secret" $.Release.Namespace $redisSecretName) }}
{{- $appSecret := (lookup "v1" "Secret" $.Release.Namespace $secretName) }}
apiVersion: v1
kind: Secret
@ -18,41 +14,18 @@ metadata:
{{- include "skillhub.labels" . | nindent 4 }}
type: Opaque
stringData:
# 数据库连接 URL
spring-datasource-url: {{ include "skillhub.jdbcUrl" . | quote }}
spring-datasource-username: {{ include "skillhub.postgresql.username" . | quote }}
# 数据库密码
# 优先级: lookup PG Secret → externalDatabase.password → postgresql.auth.password
{{- if and $postgresSecret (index $postgresSecret.data "password") }}
spring-datasource-password: {{ index $postgresSecret.data "password" | b64dec | quote }}
{{- else if not .Values.postgresql.enabled }}
{{- if not .Values.postgresql.enabled }}
# 外部数据库密码;内置 PostgreSQL 直接引用 Bitnami Secret
spring-datasource-password: {{ .Values.externalDatabase.password | quote }}
{{- else }}
spring-datasource-password: {{ .Values.secrets.springDatasourcePassword | default .Values.postgresql.auth.password | quote }}
{{- end }}
# Redis 密码
# 优先级: lookup Redis Secret → externalRedis.password → redis.auth.password
{{- if $redisSecret }}
{{- if index $redisSecret.data "redis-password" }}
redis-password: {{ index $redisSecret.data "redis-password" | b64dec | quote }}
{{- end }}
{{- else if not .Values.redis.enabled }}
{{- if not .Values.redis.enabled }}
# 外部 Redis 密码;内置 Redis 直接引用 Bitnami Secret
redis-password: {{ .Values.externalRedis.password | default "" | quote }}
{{- else if .Values.redis.auth.password }}
redis-password: {{ .Values.redis.auth.password | quote }}
{{- end }}
# Redis Sentinel 密码(仅 sentinel 模式下生效)
# 优先级: lookup Bitnami Secret → sentinelPassword → auth.password → externalRedis.password
{{- if and .Values.redis.enabled .Values.redis.sentinel.enabled }}
{{- if and $redisSecret (index $redisSecret.data "redis-sentinel-password") }}
redis-sentinel-password: {{ index $redisSecret.data "redis-sentinel-password" | b64dec | quote }}
{{- else }}
redis-sentinel-password: {{ .Values.redis.auth.sentinelPassword | default .Values.redis.auth.password | quote }}
{{- end }}
{{- else if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }}
{{- if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }}
# 外部 Sentinel 可使用独立密码
redis-sentinel-password: {{ .Values.externalRedis.sentinel.password | default .Values.externalRedis.password | default "" | quote }}
{{- end }}
# Bootstrap 管理员密码
@ -67,6 +40,17 @@ stringData:
{{- end }}
{{- end }}
bootstrap-admin-password: {{ $baPwd | quote }}
# 匿名下载限流 Cookie 签名密钥
{{- $downloadSecret := .Values.secrets.downloadAnonCookieSecret | default "" }}
{{- if and (not $downloadSecret) $appSecret }}
{{- $downloadSecret = index $appSecret.data "skillhub-download-anon-cookie-secret" | default "" | b64dec }}
{{- end }}
{{- if not $downloadSecret }}
{{- $downloadSecret = randAlphaNum 48 }}
{{- end }}
skillhub-download-anon-cookie-secret: {{ $downloadSecret | quote }}
# OAuth2 GitHub (optional)
{{- if .Values.secrets.oauth2GithubClientId }}
oauth2-github-client-id: {{ .Values.secrets.oauth2GithubClientId | quote }}
@ -79,15 +63,18 @@ stringData:
{{- if .Values.secrets.scannerLlmApiKey }}
skill-scanner-llm-api-key: {{ .Values.secrets.scannerLlmApiKey | quote }}
{{- end }}
{{- if .Values.secrets.scannerLlmBaseUrl }}
skill-scanner-llm-base-url: {{ .Values.secrets.scannerLlmBaseUrl | quote }}
{{- end }}
{{- if .Values.secrets.scannerLlmModel }}
skill-scanner-llm-model: {{ .Values.secrets.scannerLlmModel | quote }}
{{- end }}
# S3 配置 (optional)
{{- if .Values.s3.accessKey }}
s3-access-key: {{ .Values.s3.accessKey | quote }}
skillhub-storage-s3-access-key: {{ .Values.s3.accessKey | quote }}
{{- end }}
{{- if .Values.s3.secretKey }}
s3-secret-key: {{ .Values.s3.secretKey | quote }}
skillhub-storage-s3-secret-key: {{ .Values.s3.secretKey | quote }}
{{- end }}
{{- end }}

View file

@ -69,20 +69,19 @@ spec:
# Database
- name: SPRING_DATASOURCE_URL
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
key: spring-datasource-url
value: {{ include "skillhub.jdbcUrl" . | quote }}
- name: SPRING_DATASOURCE_USERNAME
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
key: spring-datasource-username
value: {{ include "skillhub.postgresql.username" . | quote }}
- name: SPRING_DATASOURCE_PASSWORD
valueFrom:
secretKeyRef:
{{- if .Values.postgresql.enabled }}
name: {{ include "skillhub.postgresql.secretName" . }}
key: {{ include "skillhub.postgresql.passwordKey" . }}
{{- else }}
name: {{ include "skillhub.secretName" . }}
key: spring-datasource-password
{{- end }}
# Redis
{{- if and .Values.redis.enabled .Values.redis.sentinel.enabled }}
@ -112,19 +111,24 @@ spec:
- name: SPRING_DATA_REDIS_SENTINEL_PASSWORD
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
{{- if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }}
key: redis-sentinel-password
{{- if .Values.redis.enabled }}
name: {{ include "skillhub.redis.secretName" . }}
key: {{ include "skillhub.redis.passwordKey" . }}
{{- else }}
key: redis-password
name: {{ include "skillhub.secretName" . }}
key: redis-sentinel-password
{{- end }}
optional: true
{{- else if or .Values.redis.enabled .Values.externalRedis.password }}
- name: SPRING_DATA_REDIS_PASSWORD
valueFrom:
secretKeyRef:
{{- if .Values.redis.enabled }}
name: {{ include "skillhub.redis.secretName" . }}
{{- else }}
name: {{ include "skillhub.secretName" . }}
key: redis-password
{{- end }}
key: {{ if .Values.redis.enabled }}{{ include "skillhub.redis.passwordKey" . }}{{ else }}redis-password{{ end }}
optional: true
{{- end }}
@ -141,32 +145,57 @@ spec:
key: skillhub-storage-provider
{{- if .Values.s3.enabled }}
- name: SKILLHUB_S3_BUCKET
- name: SKILLHUB_STORAGE_S3_BUCKET
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-bucket
- name: SKILLHUB_S3_ENDPOINT
- name: SKILLHUB_STORAGE_S3_ENDPOINT
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-endpoint
- name: SKILLHUB_S3_REGION
- name: SKILLHUB_STORAGE_S3_PUBLIC_ENDPOINT
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-public-endpoint
- name: SKILLHUB_STORAGE_S3_REGION
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-region
- name: SKILLHUB_S3_ACCESS_KEY
- name: SKILLHUB_STORAGE_S3_FORCE_PATH_STYLE
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-force-path-style
- name: SKILLHUB_STORAGE_S3_DISABLE_CHUNKED_ENCODING
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-disable-chunked-encoding
- name: SKILLHUB_STORAGE_S3_AUTO_CREATE_BUCKET
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-auto-create-bucket
- name: SKILLHUB_STORAGE_S3_PRESIGN_EXPIRY
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: s3-presign-expiry
- name: SKILLHUB_STORAGE_S3_ACCESS_KEY
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
key: s3-access-key
key: skillhub-storage-s3-access-key
optional: true
- name: SKILLHUB_S3_SECRET_KEY
- name: SKILLHUB_STORAGE_S3_SECRET_KEY
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
key: s3-secret-key
key: skillhub-storage-s3-secret-key
optional: true
{{- end }}
@ -194,6 +223,33 @@ spec:
name: {{ include "skillhub.fullname" . }}-config
key: session-cookie-secure
# Public URL and authentication
- name: SKILLHUB_PUBLIC_BASE_URL
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: public-base-url
- name: DEVICE_AUTH_VERIFICATION_URI
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: device-auth-verification-uri
- name: SKILLHUB_AUTH_DIRECT_ENABLED
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: auth-direct-enabled
- name: SKILLHUB_BUILTIN_SKILLS_ENABLED
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: builtin-skills-enabled
- name: SKILLHUB_DOWNLOAD_ANON_COOKIE_SECRET
valueFrom:
secretKeyRef:
name: {{ include "skillhub.secretName" . }}
key: skillhub-download-anon-cookie-secret
# Bootstrap Admin
- name: BOOTSTRAP_ADMIN_ENABLED
valueFrom:

View file

@ -16,7 +16,7 @@ spec:
labels:
{{- include "skillhub.web.selectorLabels" . | nindent 8 }}
annotations:
checksum/config: {{ toYaml (dict "web" .Values.web) | sha256sum }}
checksum/config: {{ toYaml (dict "web" .Values.web "publicBaseUrl" .Values.publicBaseUrl "auth" .Values.auth) | sha256sum }}
{{- range $key, $val := .Values.web.podAnnotations }}
{{ $key }}: {{ $val }}
{{- end }}
@ -33,6 +33,21 @@ spec:
env:
- name: SKILLHUB_API_UPSTREAM
value: http://{{ include "skillhub.fullname" . }}-server:{{ .Values.server.service.port }}
- name: SKILLHUB_PUBLIC_BASE_URL
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: public-base-url
- name: SKILLHUB_WEB_AUTH_DIRECT_ENABLED
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: auth-direct-enabled
- name: SKILLHUB_WEB_AUTH_DIRECT_PROVIDER
valueFrom:
configMapKeyRef:
name: {{ include "skillhub.fullname" . }}-config
key: auth-direct-provider
{{- with .Values.web.extraEnv }}
{{- toYaml . | nindent 12 }}
{{- end }}

View file

@ -13,6 +13,18 @@ images:
nameOverride: ""
fullnameOverride: ""
# 浏览器、CLI 和 OAuth 回调访问的公开地址(不带末尾斜杠)
publicBaseUrl: ""
deviceAuthVerificationUri: ""
auth:
direct:
enabled: true
provider: local
builtinSkills:
enabled: true
# ============================================================================
# Ingress 配置
# ============================================================================
@ -37,7 +49,12 @@ s3:
enabled: false
bucket: skillhub-storage
endpoint: ""
publicEndpoint: ""
region: us-east-1
forcePathStyle: true
disableChunkedEncoding: false
autoCreateBucket: false
presignExpiry: PT10M
accessKey: ""
secretKey: ""
@ -69,11 +86,12 @@ springProfilesActive: docker
existingSecret: ""
secrets:
springDatasourcePassword: ""
bootstrapAdminPassword: ""
downloadAnonCookieSecret: ""
oauth2GithubClientId: ""
oauth2GithubClientSecret: ""
scannerLlmApiKey: ""
scannerLlmBaseUrl: ""
scannerLlmModel: ""
# ============================================================================