mirror of
https://github.com/iflytek/skillhub.git
synced 2026-10-07 02:57:51 +00:00
fix(helm): 修正 Bitnami 依赖连线并同步应用配置
基于当前 SkillHub 运行时契约和 Bitnami 依赖命名,更新原贡献者提交的 Helm Chart 配置。 - 将 Server 正确连接到实际的 PostgreSQL 和 Redis Service 与 Secret - 支持依赖组件的 existingSecret 名称和自定义密码 key,避免安装时 lookup - 同步 S3、匿名下载、Scanner LLM、公开地址、设备认证和直接认证配置 - 将应用版本和 Chart 版本对齐当前发布版本 - 收紧 Chart 发布触发条件和手动版本选择逻辑 - 增加依赖 Service、Secret 和密码 key 的 CI 语义断言 已通过 Helm lint、九组渲染场景、kubeconform、工作流安全检查和后端应用测试套件。 Signed-off-by: lhb6540 <lhb6540@gmail.com>
This commit is contained in:
parent
2b1be5ccf8
commit
3b3905be63
11 changed files with 267 additions and 83 deletions
29
.github/workflows/pr-helm-chart.yml
vendored
29
.github/workflows/pr-helm-chart.yml
vendored
|
|
@ -4,6 +4,8 @@ on:
|
|||
pull_request:
|
||||
paths:
|
||||
- charts/skillhub/**
|
||||
- .github/workflows/pr-helm-chart.yml
|
||||
- .github/workflows/publish-chart.yml
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
|
|
@ -30,11 +32,13 @@ jobs:
|
|||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@v4
|
||||
with:
|
||||
version: latest
|
||||
version: v3.19.0
|
||||
|
||||
- name: Build dependencies
|
||||
run: helm dependency build .
|
||||
|
|
@ -121,11 +125,13 @@ jobs:
|
|||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@v4
|
||||
with:
|
||||
version: latest
|
||||
version: v3.19.0
|
||||
|
||||
- name: Build dependencies
|
||||
run: helm dependency build .
|
||||
|
|
@ -145,6 +151,25 @@ jobs:
|
|||
exit 1
|
||||
fi
|
||||
|
||||
- name: Validate default dependency wiring
|
||||
if: ${{ matrix.scenario.name == 'bitnami-default' }}
|
||||
run: |
|
||||
helm template test-release . --show-only templates/server-deployment.yaml > server.yaml
|
||||
grep -Fq 'value: test-release-postgresql' server.yaml
|
||||
grep -Fq 'value: test-release-redis-master' server.yaml
|
||||
grep -Fq 'name: test-release-postgresql' server.yaml
|
||||
grep -Fq 'name: test-release-redis' server.yaml
|
||||
grep -Fq 'key: password' server.yaml
|
||||
grep -Fq 'key: redis-password' server.yaml
|
||||
if grep -Fq 'test-release-skillhub-postgresql' server.yaml; then
|
||||
echo 'ERROR: Server references a non-existent PostgreSQL service'
|
||||
exit 1
|
||||
fi
|
||||
if grep -Fq 'test-release-skillhub-redis' server.yaml; then
|
||||
echo 'ERROR: Server references a non-existent Redis service'
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Schema validation (kubeconform)
|
||||
uses: docker://ghcr.io/yannh/kubeconform:latest
|
||||
with:
|
||||
|
|
|
|||
29
.github/workflows/publish-chart.yml
vendored
29
.github/workflows/publish-chart.yml
vendored
|
|
@ -4,6 +4,11 @@ on:
|
|||
release:
|
||||
types: [published]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
version:
|
||||
description: Chart and application version (for example, 0.2.13)
|
||||
required: true
|
||||
type: string
|
||||
|
||||
concurrency:
|
||||
group: publish-chart-${{ github.ref }}
|
||||
|
|
@ -15,6 +20,11 @@ permissions:
|
|||
|
||||
jobs:
|
||||
release:
|
||||
if: >-
|
||||
github.event_name == 'workflow_dispatch' ||
|
||||
startsWith(github.ref_name, 'v') ||
|
||||
startsWith(github.ref_name, 'chart-v') ||
|
||||
startsWith(github.ref_name, 'helm-v')
|
||||
runs-on: ubuntu-latest
|
||||
defaults:
|
||||
run:
|
||||
|
|
@ -23,11 +33,13 @@ jobs:
|
|||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@v4
|
||||
with:
|
||||
version: latest
|
||||
version: v3.19.0
|
||||
|
||||
- name: Verify dependencies
|
||||
run: helm dependency build .
|
||||
|
|
@ -38,12 +50,19 @@ jobs:
|
|||
- name: Parse version from tag
|
||||
id: ver
|
||||
run: |
|
||||
REF="${{ github.ref_name }}"
|
||||
# 兼容 v0.2.9、chart-v0.2.9、helm-v0.2.9 三种标签格式
|
||||
if [[ "$REF" =~ ^(helm|chart)-v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
|
||||
if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then
|
||||
VER="${{ inputs.version }}"
|
||||
elif [[ "${{ github.ref_name }}" =~ ^(helm|chart)-v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
|
||||
VER="${BASH_REMATCH[2]}"
|
||||
elif [[ "${{ github.ref_name }}" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then
|
||||
VER="${BASH_REMATCH[1]}"
|
||||
else
|
||||
VER="${REF#v}"
|
||||
echo "ERROR: Unsupported release tag: ${{ github.ref_name }}"
|
||||
exit 1
|
||||
fi
|
||||
if [[ ! "$VER" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
echo "ERROR: Version must use MAJOR.MINOR.PATCH format: $VER"
|
||||
exit 1
|
||||
fi
|
||||
echo "version=$VER" >> "$GITHUB_OUTPUT"
|
||||
|
||||
|
|
|
|||
|
|
@ -2,8 +2,8 @@ apiVersion: v2
|
|||
name: skillhub
|
||||
description: Self-hosted, open-source agent skill registry for enterprises.
|
||||
type: application
|
||||
version: 0.3.0
|
||||
appVersion: 0.3.0
|
||||
version: 0.1.0
|
||||
appVersion: 0.2.13
|
||||
keywords:
|
||||
- skillhub
|
||||
- ai
|
||||
|
|
|
|||
|
|
@ -24,7 +24,8 @@
|
|||
kubectl create namespace skillhub
|
||||
|
||||
helm -n skillhub upgrade -i skillhub ./charts/skillhub \
|
||||
--set bootstrapAdmin.password=your-secure-password
|
||||
--set bootstrapAdmin.password=your-secure-password \
|
||||
--set publicBaseUrl=https://skills.example.com
|
||||
```
|
||||
|
||||
### 高可用模式
|
||||
|
|
@ -55,22 +56,23 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \
|
|||
|
||||
### 使用 existingSecret
|
||||
|
||||
通过 `existingSecret` 引用已存在的 Secret 对象,避免在 values 中明文写入密码。该 Secret 必须包含以下 key:
|
||||
通过 `existingSecret` 引用已存在的 Secret 对象,避免在 values 中明文写入密码。
|
||||
内置 PostgreSQL/Redis 使用各自的 Bitnami Secret,不需要复制到该 Secret。
|
||||
|
||||
| Key | 必填 | 说明 |
|
||||
|-----|------|------|
|
||||
| `spring-datasource-url` | 是 | JDBC 连接 URL |
|
||||
| `spring-datasource-username` | 是 | 数据库用户名 |
|
||||
| `spring-datasource-password` | 是 | 数据库密码 |
|
||||
| `redis-password` | 是 | Redis 密码 |
|
||||
| `redis-sentinel-password` | 否 | Redis Sentinel 密码(sentinel 模式) |
|
||||
| `spring-datasource-password` | 使用外部 PostgreSQL 时 | 数据库密码 |
|
||||
| `redis-password` | 使用外部 Redis 时 | Redis 密码 |
|
||||
| `redis-sentinel-password` | 使用外部 Sentinel 时 | Redis Sentinel 密码 |
|
||||
| `bootstrap-admin-password` | 是 | 初始管理员密码 |
|
||||
| `skillhub-download-anon-cookie-secret` | 是 | 至少 32 字符的匿名下载 Cookie 签名密钥 |
|
||||
| `oauth2-github-client-id` | 否 | GitHub OAuth2 Client ID |
|
||||
| `oauth2-github-client-secret` | 否 | GitHub OAuth2 Client Secret |
|
||||
| `skill-scanner-llm-api-key` | 否 | Scanner LLM API Key |
|
||||
| `skill-scanner-llm-base-url` | 否 | Scanner 自定义 LLM API 地址 |
|
||||
| `skill-scanner-llm-model` | 否 | Scanner LLM 模型名称 |
|
||||
| `s3-access-key` | 否 | S3 Access Key |
|
||||
| `s3-secret-key` | 否 | S3 Secret Key |
|
||||
| `skillhub-storage-s3-access-key` | 否 | S3 Access Key |
|
||||
| `skillhub-storage-s3-secret-key` | 否 | S3 Secret Key |
|
||||
|
||||
```bash
|
||||
helm -n skillhub upgrade -i skillhub ./charts/skillhub \
|
||||
|
|
@ -137,7 +139,11 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \
|
|||
| `s3.enabled` | 启用 S3 | `false` |
|
||||
| `s3.bucket` | Bucket 名称 | `skillhub-storage` |
|
||||
| `s3.endpoint` | S3 端点 | `""` |
|
||||
| `s3.publicEndpoint` | S3 公网访问端点 | `""` |
|
||||
| `s3.region` | 区域 | `us-east-1` |
|
||||
| `s3.forcePathStyle` | 强制 path-style 访问 | `true` |
|
||||
| `s3.disableChunkedEncoding` | 禁用 aws-chunked 编码 | `false` |
|
||||
| `s3.autoCreateBucket` | 自动创建 Bucket | `false` |
|
||||
| `s3.accessKey` | Access Key | `""` |
|
||||
| `s3.secretKey` | Secret Key | `""` |
|
||||
|
||||
|
|
@ -158,6 +164,7 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \
|
|||
helm -n skillhub upgrade -i skillhub ./charts/skillhub \
|
||||
--set ingress.enabled=true \
|
||||
--set ingress.host=skills.example.com \
|
||||
--set publicBaseUrl=https://skills.example.com \
|
||||
--set ingress.tls.enabled=true \
|
||||
--set ingress.certManager.enabled=true
|
||||
```
|
||||
|
|
|
|||
|
|
@ -70,10 +70,38 @@ app.kubernetes.io/component: scanner
|
|||
app.kubernetes.io/component: scanner
|
||||
{{- end }}
|
||||
|
||||
{{- /* Bitnami PostgreSQL subchart 完整名称 */}}
|
||||
{{- define "skillhub.postgresql.fullname" -}}
|
||||
{{- if .Values.postgresql.fullnameOverride -}}
|
||||
{{- .Values.postgresql.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default "postgresql" .Values.postgresql.nameOverride -}}
|
||||
{{- if contains $name .Release.Name -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* Bitnami Redis subchart 完整名称 */}}
|
||||
{{- define "skillhub.redis.fullname" -}}
|
||||
{{- if .Values.redis.fullnameOverride -}}
|
||||
{{- .Values.redis.fullnameOverride | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- $name := default "redis" .Values.redis.nameOverride -}}
|
||||
{{- if contains $name .Release.Name -}}
|
||||
{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* PostgreSQL Host */}}
|
||||
{{- define "skillhub.postgresql.host" -}}
|
||||
{{- if .Values.postgresql.enabled -}}
|
||||
{{- $prefix := printf "%s-postgresql" (include "skillhub.fullname" .) -}}
|
||||
{{- $prefix := include "skillhub.postgresql.fullname" . -}}
|
||||
{{- if eq .Values.postgresql.architecture "replication" -}}
|
||||
{{- printf "%s-primary" $prefix -}}
|
||||
{{- else -}}
|
||||
|
|
@ -114,12 +142,17 @@ app.kubernetes.io/component: scanner
|
|||
{{- /* PostgreSQL Secret Name */}}
|
||||
{{- define "skillhub.postgresql.secretName" -}}
|
||||
{{- if .Values.postgresql.enabled -}}
|
||||
{{- printf "%s-postgresql" (include "skillhub.fullname" .) -}}
|
||||
{{- .Values.postgresql.auth.existingSecret | default (include "skillhub.postgresql.fullname" .) -}}
|
||||
{{- else -}}
|
||||
{{- include "skillhub.secretName" . -}}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* PostgreSQL 应用用户密码 Secret key */}}
|
||||
{{- define "skillhub.postgresql.passwordKey" -}}
|
||||
{{- .Values.postgresql.auth.secretKeys.userPasswordKey | default "password" -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* PostgreSQL JDBC URL */}}
|
||||
{{- define "skillhub.jdbcUrl" -}}
|
||||
{{- if .Values.postgresql.enabled -}}
|
||||
|
|
@ -135,8 +168,9 @@ app.kubernetes.io/component: scanner
|
|||
|
||||
{{- /* Redis Sentinel 节点列表(Redisson 需要具体 pod FQDN,格式: {pod}.{headless-svc}.{ns}.svc.cluster.local) */}}
|
||||
{{- define "skillhub.redis.sentinel.nodes" -}}
|
||||
{{- $prefix := printf "%s-redis-node" (include "skillhub.fullname" .) -}}
|
||||
{{- $headless := printf "%s-redis-headless" (include "skillhub.fullname" .) -}}
|
||||
{{- $fullname := include "skillhub.redis.fullname" . -}}
|
||||
{{- $prefix := printf "%s-node" $fullname -}}
|
||||
{{- $headless := printf "%s-headless" $fullname -}}
|
||||
{{- $port := include "skillhub.redis.port" . -}}
|
||||
{{- $replicas := .Values.redis.replica.replicaCount | default 3 | int -}}
|
||||
{{- $nodes := list -}}{{- range $i := until $replicas -}}{{- $nodes = append $nodes (printf "%s-%d.%s.%s.svc.cluster.local:%s" $prefix $i $headless $.Release.Namespace $port) -}}{{- end -}}{{- join "," $nodes -}}
|
||||
|
|
@ -146,9 +180,9 @@ app.kubernetes.io/component: scanner
|
|||
{{- define "skillhub.redis.host" -}}
|
||||
{{- if .Values.redis.enabled -}}
|
||||
{{- if .Values.redis.sentinel.enabled -}}
|
||||
{{- printf "%s-redis" (include "skillhub.fullname" .) -}}
|
||||
{{- include "skillhub.redis.fullname" . -}}
|
||||
{{- else -}}
|
||||
{{- printf "%s-redis-master" (include "skillhub.fullname" .) -}}
|
||||
{{- printf "%s-master" (include "skillhub.redis.fullname" .) -}}
|
||||
{{- end -}}
|
||||
{{- else -}}
|
||||
{{- .Values.externalRedis.host -}}
|
||||
|
|
@ -171,12 +205,17 @@ app.kubernetes.io/component: scanner
|
|||
{{- /* Redis Password Secret Name */}}
|
||||
{{- define "skillhub.redis.secretName" -}}
|
||||
{{- if .Values.redis.enabled -}}
|
||||
{{- printf "%s-redis" (include "skillhub.fullname" .) -}}
|
||||
{{- .Values.redis.auth.existingSecret | default (include "skillhub.redis.fullname" .) -}}
|
||||
{{- else -}}
|
||||
{{- include "skillhub.secretName" . -}}
|
||||
{{- end -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* Redis 密码 Secret key */}}
|
||||
{{- define "skillhub.redis.passwordKey" -}}
|
||||
{{- .Values.redis.auth.existingSecretPasswordKey | default "redis-password" -}}
|
||||
{{- end }}
|
||||
|
||||
{{- /* Secret 名称 */}}
|
||||
{{- define "skillhub.secretName" -}}
|
||||
{{- .Values.existingSecret | default (printf "%s-secret" (include "skillhub.fullname" .)) }}
|
||||
|
|
|
|||
|
|
@ -22,7 +22,12 @@ data:
|
|||
# S3 配置
|
||||
s3-bucket: {{ .Values.s3.bucket }}
|
||||
s3-endpoint: {{ .Values.s3.endpoint }}
|
||||
s3-public-endpoint: {{ .Values.s3.publicEndpoint }}
|
||||
s3-region: {{ .Values.s3.region }}
|
||||
s3-force-path-style: {{ .Values.s3.forcePathStyle | quote }}
|
||||
s3-disable-chunked-encoding: {{ .Values.s3.disableChunkedEncoding | quote }}
|
||||
s3-auto-create-bucket: {{ .Values.s3.autoCreateBucket | quote }}
|
||||
s3-presign-expiry: {{ .Values.s3.presignExpiry | quote }}
|
||||
{{- end }}
|
||||
|
||||
# 技能扫描器
|
||||
|
|
@ -39,3 +44,10 @@ data:
|
|||
|
||||
# Session
|
||||
session-cookie-secure: {{ .Values.session.cookieSecure | quote }}
|
||||
|
||||
# Public URL and authentication
|
||||
public-base-url: {{ .Values.publicBaseUrl | quote }}
|
||||
device-auth-verification-uri: {{ .Values.deviceAuthVerificationUri | quote }}
|
||||
auth-direct-enabled: {{ .Values.auth.direct.enabled | quote }}
|
||||
auth-direct-provider: {{ .Values.auth.direct.provider | quote }}
|
||||
builtin-skills-enabled: {{ .Values.builtinSkills.enabled | quote }}
|
||||
|
|
|
|||
|
|
@ -17,7 +17,7 @@ spec:
|
|||
labels:
|
||||
{{- include "skillhub.scanner.selectorLabels" . | nindent 8 }}
|
||||
annotations:
|
||||
checksum/config: {{ toYaml (dict "scanner" .Values.scanner) | sha256sum }}
|
||||
checksum/config: {{ toYaml (dict "scanner" .Values.scanner "secrets" .Values.secrets "existingSecret" .Values.existingSecret) | sha256sum }}
|
||||
{{- range $key, $val := .Values.scanner.podAnnotations }}
|
||||
{{ $key }}: {{ $val }}
|
||||
{{- end }}
|
||||
|
|
@ -41,6 +41,12 @@ spec:
|
|||
name: {{ include "skillhub.secretName" . }}
|
||||
key: skill-scanner-llm-api-key
|
||||
optional: true
|
||||
- name: SKILL_SCANNER_LLM_BASE_URL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: skill-scanner-llm-base-url
|
||||
optional: true
|
||||
- name: SKILL_SCANNER_LLM_MODEL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
|
|
|
|||
|
|
@ -5,10 +5,6 @@ SkillHub 应用 Secret
|
|||
*/}}
|
||||
{{- if not .Values.existingSecret }}
|
||||
{{- $secretName := include "skillhub.secretName" . }}
|
||||
{{- $postgresSecretName := include "skillhub.postgresql.secretName" . }}
|
||||
{{- $redisSecretName := include "skillhub.redis.secretName" . }}
|
||||
{{- $postgresSecret := (lookup "v1" "Secret" $.Release.Namespace $postgresSecretName) }}
|
||||
{{- $redisSecret := (lookup "v1" "Secret" $.Release.Namespace $redisSecretName) }}
|
||||
{{- $appSecret := (lookup "v1" "Secret" $.Release.Namespace $secretName) }}
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
|
|
@ -18,41 +14,18 @@ metadata:
|
|||
{{- include "skillhub.labels" . | nindent 4 }}
|
||||
type: Opaque
|
||||
stringData:
|
||||
# 数据库连接 URL
|
||||
spring-datasource-url: {{ include "skillhub.jdbcUrl" . | quote }}
|
||||
spring-datasource-username: {{ include "skillhub.postgresql.username" . | quote }}
|
||||
|
||||
# 数据库密码
|
||||
# 优先级: lookup PG Secret → externalDatabase.password → postgresql.auth.password
|
||||
{{- if and $postgresSecret (index $postgresSecret.data "password") }}
|
||||
spring-datasource-password: {{ index $postgresSecret.data "password" | b64dec | quote }}
|
||||
{{- else if not .Values.postgresql.enabled }}
|
||||
{{- if not .Values.postgresql.enabled }}
|
||||
# 外部数据库密码;内置 PostgreSQL 直接引用 Bitnami Secret
|
||||
spring-datasource-password: {{ .Values.externalDatabase.password | quote }}
|
||||
{{- else }}
|
||||
spring-datasource-password: {{ .Values.secrets.springDatasourcePassword | default .Values.postgresql.auth.password | quote }}
|
||||
{{- end }}
|
||||
|
||||
# Redis 密码
|
||||
# 优先级: lookup Redis Secret → externalRedis.password → redis.auth.password
|
||||
{{- if $redisSecret }}
|
||||
{{- if index $redisSecret.data "redis-password" }}
|
||||
redis-password: {{ index $redisSecret.data "redis-password" | b64dec | quote }}
|
||||
{{- end }}
|
||||
{{- else if not .Values.redis.enabled }}
|
||||
{{- if not .Values.redis.enabled }}
|
||||
# 外部 Redis 密码;内置 Redis 直接引用 Bitnami Secret
|
||||
redis-password: {{ .Values.externalRedis.password | default "" | quote }}
|
||||
{{- else if .Values.redis.auth.password }}
|
||||
redis-password: {{ .Values.redis.auth.password | quote }}
|
||||
{{- end }}
|
||||
|
||||
# Redis Sentinel 密码(仅 sentinel 模式下生效)
|
||||
# 优先级: lookup Bitnami Secret → sentinelPassword → auth.password → externalRedis.password
|
||||
{{- if and .Values.redis.enabled .Values.redis.sentinel.enabled }}
|
||||
{{- if and $redisSecret (index $redisSecret.data "redis-sentinel-password") }}
|
||||
redis-sentinel-password: {{ index $redisSecret.data "redis-sentinel-password" | b64dec | quote }}
|
||||
{{- else }}
|
||||
redis-sentinel-password: {{ .Values.redis.auth.sentinelPassword | default .Values.redis.auth.password | quote }}
|
||||
{{- end }}
|
||||
{{- else if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }}
|
||||
{{- if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }}
|
||||
# 外部 Sentinel 可使用独立密码
|
||||
redis-sentinel-password: {{ .Values.externalRedis.sentinel.password | default .Values.externalRedis.password | default "" | quote }}
|
||||
{{- end }}
|
||||
# Bootstrap 管理员密码
|
||||
|
|
@ -67,6 +40,17 @@ stringData:
|
|||
{{- end }}
|
||||
{{- end }}
|
||||
bootstrap-admin-password: {{ $baPwd | quote }}
|
||||
|
||||
# 匿名下载限流 Cookie 签名密钥
|
||||
{{- $downloadSecret := .Values.secrets.downloadAnonCookieSecret | default "" }}
|
||||
{{- if and (not $downloadSecret) $appSecret }}
|
||||
{{- $downloadSecret = index $appSecret.data "skillhub-download-anon-cookie-secret" | default "" | b64dec }}
|
||||
{{- end }}
|
||||
{{- if not $downloadSecret }}
|
||||
{{- $downloadSecret = randAlphaNum 48 }}
|
||||
{{- end }}
|
||||
skillhub-download-anon-cookie-secret: {{ $downloadSecret | quote }}
|
||||
|
||||
# OAuth2 GitHub (optional)
|
||||
{{- if .Values.secrets.oauth2GithubClientId }}
|
||||
oauth2-github-client-id: {{ .Values.secrets.oauth2GithubClientId | quote }}
|
||||
|
|
@ -79,15 +63,18 @@ stringData:
|
|||
{{- if .Values.secrets.scannerLlmApiKey }}
|
||||
skill-scanner-llm-api-key: {{ .Values.secrets.scannerLlmApiKey | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.secrets.scannerLlmBaseUrl }}
|
||||
skill-scanner-llm-base-url: {{ .Values.secrets.scannerLlmBaseUrl | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.secrets.scannerLlmModel }}
|
||||
skill-scanner-llm-model: {{ .Values.secrets.scannerLlmModel | quote }}
|
||||
{{- end }}
|
||||
|
||||
# S3 配置 (optional)
|
||||
{{- if .Values.s3.accessKey }}
|
||||
s3-access-key: {{ .Values.s3.accessKey | quote }}
|
||||
skillhub-storage-s3-access-key: {{ .Values.s3.accessKey | quote }}
|
||||
{{- end }}
|
||||
{{- if .Values.s3.secretKey }}
|
||||
s3-secret-key: {{ .Values.s3.secretKey | quote }}
|
||||
skillhub-storage-s3-secret-key: {{ .Values.s3.secretKey | quote }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
|
|
|||
|
|
@ -69,20 +69,19 @@ spec:
|
|||
|
||||
# Database
|
||||
- name: SPRING_DATASOURCE_URL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: spring-datasource-url
|
||||
value: {{ include "skillhub.jdbcUrl" . | quote }}
|
||||
- name: SPRING_DATASOURCE_USERNAME
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: spring-datasource-username
|
||||
value: {{ include "skillhub.postgresql.username" . | quote }}
|
||||
- name: SPRING_DATASOURCE_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
{{- if .Values.postgresql.enabled }}
|
||||
name: {{ include "skillhub.postgresql.secretName" . }}
|
||||
key: {{ include "skillhub.postgresql.passwordKey" . }}
|
||||
{{- else }}
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: spring-datasource-password
|
||||
{{- end }}
|
||||
|
||||
# Redis
|
||||
{{- if and .Values.redis.enabled .Values.redis.sentinel.enabled }}
|
||||
|
|
@ -112,19 +111,24 @@ spec:
|
|||
- name: SPRING_DATA_REDIS_SENTINEL_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
{{- if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }}
|
||||
key: redis-sentinel-password
|
||||
{{- if .Values.redis.enabled }}
|
||||
name: {{ include "skillhub.redis.secretName" . }}
|
||||
key: {{ include "skillhub.redis.passwordKey" . }}
|
||||
{{- else }}
|
||||
key: redis-password
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: redis-sentinel-password
|
||||
{{- end }}
|
||||
optional: true
|
||||
{{- else if or .Values.redis.enabled .Values.externalRedis.password }}
|
||||
- name: SPRING_DATA_REDIS_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
{{- if .Values.redis.enabled }}
|
||||
name: {{ include "skillhub.redis.secretName" . }}
|
||||
{{- else }}
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: redis-password
|
||||
{{- end }}
|
||||
key: {{ if .Values.redis.enabled }}{{ include "skillhub.redis.passwordKey" . }}{{ else }}redis-password{{ end }}
|
||||
optional: true
|
||||
{{- end }}
|
||||
|
||||
|
|
@ -141,32 +145,57 @@ spec:
|
|||
key: skillhub-storage-provider
|
||||
|
||||
{{- if .Values.s3.enabled }}
|
||||
- name: SKILLHUB_S3_BUCKET
|
||||
- name: SKILLHUB_STORAGE_S3_BUCKET
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-bucket
|
||||
- name: SKILLHUB_S3_ENDPOINT
|
||||
- name: SKILLHUB_STORAGE_S3_ENDPOINT
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-endpoint
|
||||
- name: SKILLHUB_S3_REGION
|
||||
- name: SKILLHUB_STORAGE_S3_PUBLIC_ENDPOINT
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-public-endpoint
|
||||
- name: SKILLHUB_STORAGE_S3_REGION
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-region
|
||||
- name: SKILLHUB_S3_ACCESS_KEY
|
||||
- name: SKILLHUB_STORAGE_S3_FORCE_PATH_STYLE
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-force-path-style
|
||||
- name: SKILLHUB_STORAGE_S3_DISABLE_CHUNKED_ENCODING
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-disable-chunked-encoding
|
||||
- name: SKILLHUB_STORAGE_S3_AUTO_CREATE_BUCKET
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-auto-create-bucket
|
||||
- name: SKILLHUB_STORAGE_S3_PRESIGN_EXPIRY
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: s3-presign-expiry
|
||||
- name: SKILLHUB_STORAGE_S3_ACCESS_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: s3-access-key
|
||||
key: skillhub-storage-s3-access-key
|
||||
optional: true
|
||||
- name: SKILLHUB_S3_SECRET_KEY
|
||||
- name: SKILLHUB_STORAGE_S3_SECRET_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: s3-secret-key
|
||||
key: skillhub-storage-s3-secret-key
|
||||
optional: true
|
||||
{{- end }}
|
||||
|
||||
|
|
@ -194,6 +223,33 @@ spec:
|
|||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: session-cookie-secure
|
||||
|
||||
# Public URL and authentication
|
||||
- name: SKILLHUB_PUBLIC_BASE_URL
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: public-base-url
|
||||
- name: DEVICE_AUTH_VERIFICATION_URI
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: device-auth-verification-uri
|
||||
- name: SKILLHUB_AUTH_DIRECT_ENABLED
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: auth-direct-enabled
|
||||
- name: SKILLHUB_BUILTIN_SKILLS_ENABLED
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: builtin-skills-enabled
|
||||
- name: SKILLHUB_DOWNLOAD_ANON_COOKIE_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: {{ include "skillhub.secretName" . }}
|
||||
key: skillhub-download-anon-cookie-secret
|
||||
|
||||
# Bootstrap Admin
|
||||
- name: BOOTSTRAP_ADMIN_ENABLED
|
||||
valueFrom:
|
||||
|
|
|
|||
|
|
@ -16,7 +16,7 @@ spec:
|
|||
labels:
|
||||
{{- include "skillhub.web.selectorLabels" . | nindent 8 }}
|
||||
annotations:
|
||||
checksum/config: {{ toYaml (dict "web" .Values.web) | sha256sum }}
|
||||
checksum/config: {{ toYaml (dict "web" .Values.web "publicBaseUrl" .Values.publicBaseUrl "auth" .Values.auth) | sha256sum }}
|
||||
{{- range $key, $val := .Values.web.podAnnotations }}
|
||||
{{ $key }}: {{ $val }}
|
||||
{{- end }}
|
||||
|
|
@ -33,6 +33,21 @@ spec:
|
|||
env:
|
||||
- name: SKILLHUB_API_UPSTREAM
|
||||
value: http://{{ include "skillhub.fullname" . }}-server:{{ .Values.server.service.port }}
|
||||
- name: SKILLHUB_PUBLIC_BASE_URL
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: public-base-url
|
||||
- name: SKILLHUB_WEB_AUTH_DIRECT_ENABLED
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: auth-direct-enabled
|
||||
- name: SKILLHUB_WEB_AUTH_DIRECT_PROVIDER
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: {{ include "skillhub.fullname" . }}-config
|
||||
key: auth-direct-provider
|
||||
{{- with .Values.web.extraEnv }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
|
|
|
|||
|
|
@ -13,6 +13,18 @@ images:
|
|||
nameOverride: ""
|
||||
fullnameOverride: ""
|
||||
|
||||
# 浏览器、CLI 和 OAuth 回调访问的公开地址(不带末尾斜杠)
|
||||
publicBaseUrl: ""
|
||||
deviceAuthVerificationUri: ""
|
||||
|
||||
auth:
|
||||
direct:
|
||||
enabled: true
|
||||
provider: local
|
||||
|
||||
builtinSkills:
|
||||
enabled: true
|
||||
|
||||
# ============================================================================
|
||||
# Ingress 配置
|
||||
# ============================================================================
|
||||
|
|
@ -37,7 +49,12 @@ s3:
|
|||
enabled: false
|
||||
bucket: skillhub-storage
|
||||
endpoint: ""
|
||||
publicEndpoint: ""
|
||||
region: us-east-1
|
||||
forcePathStyle: true
|
||||
disableChunkedEncoding: false
|
||||
autoCreateBucket: false
|
||||
presignExpiry: PT10M
|
||||
accessKey: ""
|
||||
secretKey: ""
|
||||
|
||||
|
|
@ -69,11 +86,12 @@ springProfilesActive: docker
|
|||
existingSecret: ""
|
||||
|
||||
secrets:
|
||||
springDatasourcePassword: ""
|
||||
bootstrapAdminPassword: ""
|
||||
downloadAnonCookieSecret: ""
|
||||
oauth2GithubClientId: ""
|
||||
oauth2GithubClientSecret: ""
|
||||
scannerLlmApiKey: ""
|
||||
scannerLlmBaseUrl: ""
|
||||
scannerLlmModel: ""
|
||||
|
||||
# ============================================================================
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue