diff --git a/.github/workflows/pr-helm-chart.yml b/.github/workflows/pr-helm-chart.yml index b1c38d37..37787c14 100644 --- a/.github/workflows/pr-helm-chart.yml +++ b/.github/workflows/pr-helm-chart.yml @@ -4,6 +4,8 @@ on: pull_request: paths: - charts/skillhub/** + - .github/workflows/pr-helm-chart.yml + - .github/workflows/publish-chart.yml types: - opened - synchronize @@ -30,11 +32,13 @@ jobs: steps: - name: Check out repository uses: actions/checkout@v4 + with: + persist-credentials: false - name: Set up Helm uses: azure/setup-helm@v4 with: - version: latest + version: v3.19.0 - name: Build dependencies run: helm dependency build . @@ -121,11 +125,13 @@ jobs: steps: - name: Check out repository uses: actions/checkout@v4 + with: + persist-credentials: false - name: Set up Helm uses: azure/setup-helm@v4 with: - version: latest + version: v3.19.0 - name: Build dependencies run: helm dependency build . @@ -145,6 +151,25 @@ jobs: exit 1 fi + - name: Validate default dependency wiring + if: ${{ matrix.scenario.name == 'bitnami-default' }} + run: | + helm template test-release . --show-only templates/server-deployment.yaml > server.yaml + grep -Fq 'value: test-release-postgresql' server.yaml + grep -Fq 'value: test-release-redis-master' server.yaml + grep -Fq 'name: test-release-postgresql' server.yaml + grep -Fq 'name: test-release-redis' server.yaml + grep -Fq 'key: password' server.yaml + grep -Fq 'key: redis-password' server.yaml + if grep -Fq 'test-release-skillhub-postgresql' server.yaml; then + echo 'ERROR: Server references a non-existent PostgreSQL service' + exit 1 + fi + if grep -Fq 'test-release-skillhub-redis' server.yaml; then + echo 'ERROR: Server references a non-existent Redis service' + exit 1 + fi + - name: Schema validation (kubeconform) uses: docker://ghcr.io/yannh/kubeconform:latest with: diff --git a/.github/workflows/publish-chart.yml b/.github/workflows/publish-chart.yml index 1e4994ae..13fdf039 100644 --- a/.github/workflows/publish-chart.yml +++ b/.github/workflows/publish-chart.yml @@ -4,6 +4,11 @@ on: release: types: [published] workflow_dispatch: + inputs: + version: + description: Chart and application version (for example, 0.2.13) + required: true + type: string concurrency: group: publish-chart-${{ github.ref }} @@ -15,6 +20,11 @@ permissions: jobs: release: + if: >- + github.event_name == 'workflow_dispatch' || + startsWith(github.ref_name, 'v') || + startsWith(github.ref_name, 'chart-v') || + startsWith(github.ref_name, 'helm-v') runs-on: ubuntu-latest defaults: run: @@ -23,11 +33,13 @@ jobs: steps: - name: Check out repository uses: actions/checkout@v4 + with: + persist-credentials: false - name: Set up Helm uses: azure/setup-helm@v4 with: - version: latest + version: v3.19.0 - name: Verify dependencies run: helm dependency build . @@ -38,12 +50,19 @@ jobs: - name: Parse version from tag id: ver run: | - REF="${{ github.ref_name }}" - # 兼容 v0.2.9、chart-v0.2.9、helm-v0.2.9 三种标签格式 - if [[ "$REF" =~ ^(helm|chart)-v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then + if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then + VER="${{ inputs.version }}" + elif [[ "${{ github.ref_name }}" =~ ^(helm|chart)-v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then VER="${BASH_REMATCH[2]}" + elif [[ "${{ github.ref_name }}" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)$ ]]; then + VER="${BASH_REMATCH[1]}" else - VER="${REF#v}" + echo "ERROR: Unsupported release tag: ${{ github.ref_name }}" + exit 1 + fi + if [[ ! "$VER" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then + echo "ERROR: Version must use MAJOR.MINOR.PATCH format: $VER" + exit 1 fi echo "version=$VER" >> "$GITHUB_OUTPUT" diff --git a/charts/skillhub/Chart.yaml b/charts/skillhub/Chart.yaml index ce981b6a..60ba84c2 100644 --- a/charts/skillhub/Chart.yaml +++ b/charts/skillhub/Chart.yaml @@ -2,8 +2,8 @@ apiVersion: v2 name: skillhub description: Self-hosted, open-source agent skill registry for enterprises. type: application -version: 0.3.0 -appVersion: 0.3.0 +version: 0.1.0 +appVersion: 0.2.13 keywords: - skillhub - ai diff --git a/charts/skillhub/README.md b/charts/skillhub/README.md index 19fcefc3..47f8339b 100644 --- a/charts/skillhub/README.md +++ b/charts/skillhub/README.md @@ -24,7 +24,8 @@ kubectl create namespace skillhub helm -n skillhub upgrade -i skillhub ./charts/skillhub \ - --set bootstrapAdmin.password=your-secure-password + --set bootstrapAdmin.password=your-secure-password \ + --set publicBaseUrl=https://skills.example.com ``` ### 高可用模式 @@ -55,22 +56,23 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \ ### 使用 existingSecret -通过 `existingSecret` 引用已存在的 Secret 对象,避免在 values 中明文写入密码。该 Secret 必须包含以下 key: +通过 `existingSecret` 引用已存在的 Secret 对象,避免在 values 中明文写入密码。 +内置 PostgreSQL/Redis 使用各自的 Bitnami Secret,不需要复制到该 Secret。 | Key | 必填 | 说明 | |-----|------|------| -| `spring-datasource-url` | 是 | JDBC 连接 URL | -| `spring-datasource-username` | 是 | 数据库用户名 | -| `spring-datasource-password` | 是 | 数据库密码 | -| `redis-password` | 是 | Redis 密码 | -| `redis-sentinel-password` | 否 | Redis Sentinel 密码(sentinel 模式) | +| `spring-datasource-password` | 使用外部 PostgreSQL 时 | 数据库密码 | +| `redis-password` | 使用外部 Redis 时 | Redis 密码 | +| `redis-sentinel-password` | 使用外部 Sentinel 时 | Redis Sentinel 密码 | | `bootstrap-admin-password` | 是 | 初始管理员密码 | +| `skillhub-download-anon-cookie-secret` | 是 | 至少 32 字符的匿名下载 Cookie 签名密钥 | | `oauth2-github-client-id` | 否 | GitHub OAuth2 Client ID | | `oauth2-github-client-secret` | 否 | GitHub OAuth2 Client Secret | | `skill-scanner-llm-api-key` | 否 | Scanner LLM API Key | +| `skill-scanner-llm-base-url` | 否 | Scanner 自定义 LLM API 地址 | | `skill-scanner-llm-model` | 否 | Scanner LLM 模型名称 | -| `s3-access-key` | 否 | S3 Access Key | -| `s3-secret-key` | 否 | S3 Secret Key | +| `skillhub-storage-s3-access-key` | 否 | S3 Access Key | +| `skillhub-storage-s3-secret-key` | 否 | S3 Secret Key | ```bash helm -n skillhub upgrade -i skillhub ./charts/skillhub \ @@ -137,7 +139,11 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \ | `s3.enabled` | 启用 S3 | `false` | | `s3.bucket` | Bucket 名称 | `skillhub-storage` | | `s3.endpoint` | S3 端点 | `""` | +| `s3.publicEndpoint` | S3 公网访问端点 | `""` | | `s3.region` | 区域 | `us-east-1` | +| `s3.forcePathStyle` | 强制 path-style 访问 | `true` | +| `s3.disableChunkedEncoding` | 禁用 aws-chunked 编码 | `false` | +| `s3.autoCreateBucket` | 自动创建 Bucket | `false` | | `s3.accessKey` | Access Key | `""` | | `s3.secretKey` | Secret Key | `""` | @@ -158,6 +164,7 @@ helm -n skillhub upgrade -i skillhub ./charts/skillhub \ helm -n skillhub upgrade -i skillhub ./charts/skillhub \ --set ingress.enabled=true \ --set ingress.host=skills.example.com \ + --set publicBaseUrl=https://skills.example.com \ --set ingress.tls.enabled=true \ --set ingress.certManager.enabled=true ``` diff --git a/charts/skillhub/templates/_helpers.tpl b/charts/skillhub/templates/_helpers.tpl index 7315f3b4..4331d770 100644 --- a/charts/skillhub/templates/_helpers.tpl +++ b/charts/skillhub/templates/_helpers.tpl @@ -70,10 +70,38 @@ app.kubernetes.io/component: scanner app.kubernetes.io/component: scanner {{- end }} +{{- /* Bitnami PostgreSQL subchart 完整名称 */}} +{{- define "skillhub.postgresql.fullname" -}} +{{- if .Values.postgresql.fullnameOverride -}} +{{- .Values.postgresql.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- $name := default "postgresql" .Values.postgresql.nameOverride -}} +{{- if contains $name .Release.Name -}} +{{- .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} +{{- end }} + +{{- /* Bitnami Redis subchart 完整名称 */}} +{{- define "skillhub.redis.fullname" -}} +{{- if .Values.redis.fullnameOverride -}} +{{- .Values.redis.fullnameOverride | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- $name := default "redis" .Values.redis.nameOverride -}} +{{- if contains $name .Release.Name -}} +{{- .Release.Name | trunc 63 | trimSuffix "-" -}} +{{- else -}} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} +{{- end -}} +{{- end -}} +{{- end }} + {{- /* PostgreSQL Host */}} {{- define "skillhub.postgresql.host" -}} {{- if .Values.postgresql.enabled -}} -{{- $prefix := printf "%s-postgresql" (include "skillhub.fullname" .) -}} +{{- $prefix := include "skillhub.postgresql.fullname" . -}} {{- if eq .Values.postgresql.architecture "replication" -}} {{- printf "%s-primary" $prefix -}} {{- else -}} @@ -114,12 +142,17 @@ app.kubernetes.io/component: scanner {{- /* PostgreSQL Secret Name */}} {{- define "skillhub.postgresql.secretName" -}} {{- if .Values.postgresql.enabled -}} -{{- printf "%s-postgresql" (include "skillhub.fullname" .) -}} +{{- .Values.postgresql.auth.existingSecret | default (include "skillhub.postgresql.fullname" .) -}} {{- else -}} {{- include "skillhub.secretName" . -}} {{- end -}} {{- end }} +{{- /* PostgreSQL 应用用户密码 Secret key */}} +{{- define "skillhub.postgresql.passwordKey" -}} +{{- .Values.postgresql.auth.secretKeys.userPasswordKey | default "password" -}} +{{- end }} + {{- /* PostgreSQL JDBC URL */}} {{- define "skillhub.jdbcUrl" -}} {{- if .Values.postgresql.enabled -}} @@ -135,8 +168,9 @@ app.kubernetes.io/component: scanner {{- /* Redis Sentinel 节点列表(Redisson 需要具体 pod FQDN,格式: {pod}.{headless-svc}.{ns}.svc.cluster.local) */}} {{- define "skillhub.redis.sentinel.nodes" -}} -{{- $prefix := printf "%s-redis-node" (include "skillhub.fullname" .) -}} -{{- $headless := printf "%s-redis-headless" (include "skillhub.fullname" .) -}} +{{- $fullname := include "skillhub.redis.fullname" . -}} +{{- $prefix := printf "%s-node" $fullname -}} +{{- $headless := printf "%s-headless" $fullname -}} {{- $port := include "skillhub.redis.port" . -}} {{- $replicas := .Values.redis.replica.replicaCount | default 3 | int -}} {{- $nodes := list -}}{{- range $i := until $replicas -}}{{- $nodes = append $nodes (printf "%s-%d.%s.%s.svc.cluster.local:%s" $prefix $i $headless $.Release.Namespace $port) -}}{{- end -}}{{- join "," $nodes -}} @@ -146,9 +180,9 @@ app.kubernetes.io/component: scanner {{- define "skillhub.redis.host" -}} {{- if .Values.redis.enabled -}} {{- if .Values.redis.sentinel.enabled -}} -{{- printf "%s-redis" (include "skillhub.fullname" .) -}} +{{- include "skillhub.redis.fullname" . -}} {{- else -}} -{{- printf "%s-redis-master" (include "skillhub.fullname" .) -}} +{{- printf "%s-master" (include "skillhub.redis.fullname" .) -}} {{- end -}} {{- else -}} {{- .Values.externalRedis.host -}} @@ -171,12 +205,17 @@ app.kubernetes.io/component: scanner {{- /* Redis Password Secret Name */}} {{- define "skillhub.redis.secretName" -}} {{- if .Values.redis.enabled -}} -{{- printf "%s-redis" (include "skillhub.fullname" .) -}} +{{- .Values.redis.auth.existingSecret | default (include "skillhub.redis.fullname" .) -}} {{- else -}} {{- include "skillhub.secretName" . -}} {{- end -}} {{- end }} +{{- /* Redis 密码 Secret key */}} +{{- define "skillhub.redis.passwordKey" -}} +{{- .Values.redis.auth.existingSecretPasswordKey | default "redis-password" -}} +{{- end }} + {{- /* Secret 名称 */}} {{- define "skillhub.secretName" -}} {{- .Values.existingSecret | default (printf "%s-secret" (include "skillhub.fullname" .)) }} diff --git a/charts/skillhub/templates/configmap.yaml b/charts/skillhub/templates/configmap.yaml index aee9b16c..66ca9f32 100644 --- a/charts/skillhub/templates/configmap.yaml +++ b/charts/skillhub/templates/configmap.yaml @@ -22,7 +22,12 @@ data: # S3 配置 s3-bucket: {{ .Values.s3.bucket }} s3-endpoint: {{ .Values.s3.endpoint }} + s3-public-endpoint: {{ .Values.s3.publicEndpoint }} s3-region: {{ .Values.s3.region }} + s3-force-path-style: {{ .Values.s3.forcePathStyle | quote }} + s3-disable-chunked-encoding: {{ .Values.s3.disableChunkedEncoding | quote }} + s3-auto-create-bucket: {{ .Values.s3.autoCreateBucket | quote }} + s3-presign-expiry: {{ .Values.s3.presignExpiry | quote }} {{- end }} # 技能扫描器 @@ -39,3 +44,10 @@ data: # Session session-cookie-secure: {{ .Values.session.cookieSecure | quote }} + + # Public URL and authentication + public-base-url: {{ .Values.publicBaseUrl | quote }} + device-auth-verification-uri: {{ .Values.deviceAuthVerificationUri | quote }} + auth-direct-enabled: {{ .Values.auth.direct.enabled | quote }} + auth-direct-provider: {{ .Values.auth.direct.provider | quote }} + builtin-skills-enabled: {{ .Values.builtinSkills.enabled | quote }} diff --git a/charts/skillhub/templates/scanner-deployment.yaml b/charts/skillhub/templates/scanner-deployment.yaml index 5e466c39..b511465e 100644 --- a/charts/skillhub/templates/scanner-deployment.yaml +++ b/charts/skillhub/templates/scanner-deployment.yaml @@ -17,7 +17,7 @@ spec: labels: {{- include "skillhub.scanner.selectorLabels" . | nindent 8 }} annotations: - checksum/config: {{ toYaml (dict "scanner" .Values.scanner) | sha256sum }} + checksum/config: {{ toYaml (dict "scanner" .Values.scanner "secrets" .Values.secrets "existingSecret" .Values.existingSecret) | sha256sum }} {{- range $key, $val := .Values.scanner.podAnnotations }} {{ $key }}: {{ $val }} {{- end }} @@ -41,6 +41,12 @@ spec: name: {{ include "skillhub.secretName" . }} key: skill-scanner-llm-api-key optional: true + - name: SKILL_SCANNER_LLM_BASE_URL + valueFrom: + secretKeyRef: + name: {{ include "skillhub.secretName" . }} + key: skill-scanner-llm-base-url + optional: true - name: SKILL_SCANNER_LLM_MODEL valueFrom: secretKeyRef: diff --git a/charts/skillhub/templates/secret.yaml b/charts/skillhub/templates/secret.yaml index 648fd9e7..8e28c911 100644 --- a/charts/skillhub/templates/secret.yaml +++ b/charts/skillhub/templates/secret.yaml @@ -5,10 +5,6 @@ SkillHub 应用 Secret */}} {{- if not .Values.existingSecret }} {{- $secretName := include "skillhub.secretName" . }} -{{- $postgresSecretName := include "skillhub.postgresql.secretName" . }} -{{- $redisSecretName := include "skillhub.redis.secretName" . }} -{{- $postgresSecret := (lookup "v1" "Secret" $.Release.Namespace $postgresSecretName) }} -{{- $redisSecret := (lookup "v1" "Secret" $.Release.Namespace $redisSecretName) }} {{- $appSecret := (lookup "v1" "Secret" $.Release.Namespace $secretName) }} apiVersion: v1 kind: Secret @@ -18,41 +14,18 @@ metadata: {{- include "skillhub.labels" . | nindent 4 }} type: Opaque stringData: - # 数据库连接 URL - spring-datasource-url: {{ include "skillhub.jdbcUrl" . | quote }} - spring-datasource-username: {{ include "skillhub.postgresql.username" . | quote }} - - # 数据库密码 - # 优先级: lookup PG Secret → externalDatabase.password → postgresql.auth.password - {{- if and $postgresSecret (index $postgresSecret.data "password") }} - spring-datasource-password: {{ index $postgresSecret.data "password" | b64dec | quote }} - {{- else if not .Values.postgresql.enabled }} + {{- if not .Values.postgresql.enabled }} + # 外部数据库密码;内置 PostgreSQL 直接引用 Bitnami Secret spring-datasource-password: {{ .Values.externalDatabase.password | quote }} - {{- else }} - spring-datasource-password: {{ .Values.secrets.springDatasourcePassword | default .Values.postgresql.auth.password | quote }} {{- end }} - # Redis 密码 - # 优先级: lookup Redis Secret → externalRedis.password → redis.auth.password - {{- if $redisSecret }} - {{- if index $redisSecret.data "redis-password" }} - redis-password: {{ index $redisSecret.data "redis-password" | b64dec | quote }} - {{- end }} - {{- else if not .Values.redis.enabled }} + {{- if not .Values.redis.enabled }} + # 外部 Redis 密码;内置 Redis 直接引用 Bitnami Secret redis-password: {{ .Values.externalRedis.password | default "" | quote }} - {{- else if .Values.redis.auth.password }} - redis-password: {{ .Values.redis.auth.password | quote }} {{- end }} - # Redis Sentinel 密码(仅 sentinel 模式下生效) - # 优先级: lookup Bitnami Secret → sentinelPassword → auth.password → externalRedis.password - {{- if and .Values.redis.enabled .Values.redis.sentinel.enabled }} - {{- if and $redisSecret (index $redisSecret.data "redis-sentinel-password") }} - redis-sentinel-password: {{ index $redisSecret.data "redis-sentinel-password" | b64dec | quote }} - {{- else }} - redis-sentinel-password: {{ .Values.redis.auth.sentinelPassword | default .Values.redis.auth.password | quote }} - {{- end }} - {{- else if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }} + {{- if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }} + # 外部 Sentinel 可使用独立密码 redis-sentinel-password: {{ .Values.externalRedis.sentinel.password | default .Values.externalRedis.password | default "" | quote }} {{- end }} # Bootstrap 管理员密码 @@ -67,6 +40,17 @@ stringData: {{- end }} {{- end }} bootstrap-admin-password: {{ $baPwd | quote }} + + # 匿名下载限流 Cookie 签名密钥 + {{- $downloadSecret := .Values.secrets.downloadAnonCookieSecret | default "" }} + {{- if and (not $downloadSecret) $appSecret }} + {{- $downloadSecret = index $appSecret.data "skillhub-download-anon-cookie-secret" | default "" | b64dec }} + {{- end }} + {{- if not $downloadSecret }} + {{- $downloadSecret = randAlphaNum 48 }} + {{- end }} + skillhub-download-anon-cookie-secret: {{ $downloadSecret | quote }} + # OAuth2 GitHub (optional) {{- if .Values.secrets.oauth2GithubClientId }} oauth2-github-client-id: {{ .Values.secrets.oauth2GithubClientId | quote }} @@ -79,15 +63,18 @@ stringData: {{- if .Values.secrets.scannerLlmApiKey }} skill-scanner-llm-api-key: {{ .Values.secrets.scannerLlmApiKey | quote }} {{- end }} + {{- if .Values.secrets.scannerLlmBaseUrl }} + skill-scanner-llm-base-url: {{ .Values.secrets.scannerLlmBaseUrl | quote }} + {{- end }} {{- if .Values.secrets.scannerLlmModel }} skill-scanner-llm-model: {{ .Values.secrets.scannerLlmModel | quote }} {{- end }} # S3 配置 (optional) {{- if .Values.s3.accessKey }} - s3-access-key: {{ .Values.s3.accessKey | quote }} + skillhub-storage-s3-access-key: {{ .Values.s3.accessKey | quote }} {{- end }} {{- if .Values.s3.secretKey }} - s3-secret-key: {{ .Values.s3.secretKey | quote }} + skillhub-storage-s3-secret-key: {{ .Values.s3.secretKey | quote }} {{- end }} {{- end }} diff --git a/charts/skillhub/templates/server-deployment.yaml b/charts/skillhub/templates/server-deployment.yaml index 2363efe2..26345f3d 100644 --- a/charts/skillhub/templates/server-deployment.yaml +++ b/charts/skillhub/templates/server-deployment.yaml @@ -69,20 +69,19 @@ spec: # Database - name: SPRING_DATASOURCE_URL - valueFrom: - secretKeyRef: - name: {{ include "skillhub.secretName" . }} - key: spring-datasource-url + value: {{ include "skillhub.jdbcUrl" . | quote }} - name: SPRING_DATASOURCE_USERNAME - valueFrom: - secretKeyRef: - name: {{ include "skillhub.secretName" . }} - key: spring-datasource-username + value: {{ include "skillhub.postgresql.username" . | quote }} - name: SPRING_DATASOURCE_PASSWORD valueFrom: secretKeyRef: + {{- if .Values.postgresql.enabled }} + name: {{ include "skillhub.postgresql.secretName" . }} + key: {{ include "skillhub.postgresql.passwordKey" . }} + {{- else }} name: {{ include "skillhub.secretName" . }} key: spring-datasource-password + {{- end }} # Redis {{- if and .Values.redis.enabled .Values.redis.sentinel.enabled }} @@ -112,19 +111,24 @@ spec: - name: SPRING_DATA_REDIS_SENTINEL_PASSWORD valueFrom: secretKeyRef: - name: {{ include "skillhub.secretName" . }} - {{- if and (not .Values.redis.enabled) .Values.externalRedis.sentinel.enabled }} - key: redis-sentinel-password + {{- if .Values.redis.enabled }} + name: {{ include "skillhub.redis.secretName" . }} + key: {{ include "skillhub.redis.passwordKey" . }} {{- else }} - key: redis-password + name: {{ include "skillhub.secretName" . }} + key: redis-sentinel-password {{- end }} optional: true {{- else if or .Values.redis.enabled .Values.externalRedis.password }} - name: SPRING_DATA_REDIS_PASSWORD valueFrom: secretKeyRef: + {{- if .Values.redis.enabled }} + name: {{ include "skillhub.redis.secretName" . }} + {{- else }} name: {{ include "skillhub.secretName" . }} - key: redis-password + {{- end }} + key: {{ if .Values.redis.enabled }}{{ include "skillhub.redis.passwordKey" . }}{{ else }}redis-password{{ end }} optional: true {{- end }} @@ -141,32 +145,57 @@ spec: key: skillhub-storage-provider {{- if .Values.s3.enabled }} - - name: SKILLHUB_S3_BUCKET + - name: SKILLHUB_STORAGE_S3_BUCKET valueFrom: configMapKeyRef: name: {{ include "skillhub.fullname" . }}-config key: s3-bucket - - name: SKILLHUB_S3_ENDPOINT + - name: SKILLHUB_STORAGE_S3_ENDPOINT valueFrom: configMapKeyRef: name: {{ include "skillhub.fullname" . }}-config key: s3-endpoint - - name: SKILLHUB_S3_REGION + - name: SKILLHUB_STORAGE_S3_PUBLIC_ENDPOINT + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: s3-public-endpoint + - name: SKILLHUB_STORAGE_S3_REGION valueFrom: configMapKeyRef: name: {{ include "skillhub.fullname" . }}-config key: s3-region - - name: SKILLHUB_S3_ACCESS_KEY + - name: SKILLHUB_STORAGE_S3_FORCE_PATH_STYLE + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: s3-force-path-style + - name: SKILLHUB_STORAGE_S3_DISABLE_CHUNKED_ENCODING + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: s3-disable-chunked-encoding + - name: SKILLHUB_STORAGE_S3_AUTO_CREATE_BUCKET + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: s3-auto-create-bucket + - name: SKILLHUB_STORAGE_S3_PRESIGN_EXPIRY + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: s3-presign-expiry + - name: SKILLHUB_STORAGE_S3_ACCESS_KEY valueFrom: secretKeyRef: name: {{ include "skillhub.secretName" . }} - key: s3-access-key + key: skillhub-storage-s3-access-key optional: true - - name: SKILLHUB_S3_SECRET_KEY + - name: SKILLHUB_STORAGE_S3_SECRET_KEY valueFrom: secretKeyRef: name: {{ include "skillhub.secretName" . }} - key: s3-secret-key + key: skillhub-storage-s3-secret-key optional: true {{- end }} @@ -194,6 +223,33 @@ spec: name: {{ include "skillhub.fullname" . }}-config key: session-cookie-secure + # Public URL and authentication + - name: SKILLHUB_PUBLIC_BASE_URL + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: public-base-url + - name: DEVICE_AUTH_VERIFICATION_URI + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: device-auth-verification-uri + - name: SKILLHUB_AUTH_DIRECT_ENABLED + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: auth-direct-enabled + - name: SKILLHUB_BUILTIN_SKILLS_ENABLED + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: builtin-skills-enabled + - name: SKILLHUB_DOWNLOAD_ANON_COOKIE_SECRET + valueFrom: + secretKeyRef: + name: {{ include "skillhub.secretName" . }} + key: skillhub-download-anon-cookie-secret + # Bootstrap Admin - name: BOOTSTRAP_ADMIN_ENABLED valueFrom: diff --git a/charts/skillhub/templates/web-deployment.yaml b/charts/skillhub/templates/web-deployment.yaml index 7392a398..bdbb3e75 100644 --- a/charts/skillhub/templates/web-deployment.yaml +++ b/charts/skillhub/templates/web-deployment.yaml @@ -16,7 +16,7 @@ spec: labels: {{- include "skillhub.web.selectorLabels" . | nindent 8 }} annotations: - checksum/config: {{ toYaml (dict "web" .Values.web) | sha256sum }} + checksum/config: {{ toYaml (dict "web" .Values.web "publicBaseUrl" .Values.publicBaseUrl "auth" .Values.auth) | sha256sum }} {{- range $key, $val := .Values.web.podAnnotations }} {{ $key }}: {{ $val }} {{- end }} @@ -33,6 +33,21 @@ spec: env: - name: SKILLHUB_API_UPSTREAM value: http://{{ include "skillhub.fullname" . }}-server:{{ .Values.server.service.port }} + - name: SKILLHUB_PUBLIC_BASE_URL + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: public-base-url + - name: SKILLHUB_WEB_AUTH_DIRECT_ENABLED + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: auth-direct-enabled + - name: SKILLHUB_WEB_AUTH_DIRECT_PROVIDER + valueFrom: + configMapKeyRef: + name: {{ include "skillhub.fullname" . }}-config + key: auth-direct-provider {{- with .Values.web.extraEnv }} {{- toYaml . | nindent 12 }} {{- end }} diff --git a/charts/skillhub/values.yaml b/charts/skillhub/values.yaml index 3fb16248..42f8ea3b 100644 --- a/charts/skillhub/values.yaml +++ b/charts/skillhub/values.yaml @@ -13,6 +13,18 @@ images: nameOverride: "" fullnameOverride: "" +# 浏览器、CLI 和 OAuth 回调访问的公开地址(不带末尾斜杠) +publicBaseUrl: "" +deviceAuthVerificationUri: "" + +auth: + direct: + enabled: true + provider: local + +builtinSkills: + enabled: true + # ============================================================================ # Ingress 配置 # ============================================================================ @@ -37,7 +49,12 @@ s3: enabled: false bucket: skillhub-storage endpoint: "" + publicEndpoint: "" region: us-east-1 + forcePathStyle: true + disableChunkedEncoding: false + autoCreateBucket: false + presignExpiry: PT10M accessKey: "" secretKey: "" @@ -69,11 +86,12 @@ springProfilesActive: docker existingSecret: "" secrets: - springDatasourcePassword: "" bootstrapAdminPassword: "" + downloadAnonCookieSecret: "" oauth2GithubClientId: "" oauth2GithubClientSecret: "" scannerLlmApiKey: "" + scannerLlmBaseUrl: "" scannerLlmModel: "" # ============================================================================