269 lines
5.0 KiB
YAML
269 lines
5.0 KiB
YAML
replicaCount: 1
|
|
|
|
image:
|
|
repository: ghcr.io/gramps-project/grampsweb
|
|
tag: latest
|
|
pullPolicy: Always
|
|
pullSecrets: []
|
|
|
|
nameOverride: ""
|
|
fullnameOverride: ""
|
|
|
|
serviceAccount:
|
|
create: true
|
|
name: ""
|
|
annotations: {}
|
|
automountServiceAccountToken: false
|
|
|
|
podAnnotations: {}
|
|
podLabels: {}
|
|
podSecurityContext: {}
|
|
securityContext: {}
|
|
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
|
|
ingress:
|
|
enabled: false
|
|
nameOverride: ""
|
|
className: ""
|
|
annotations: {}
|
|
hosts:
|
|
- host: gramps.example.com
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
tls: []
|
|
|
|
config:
|
|
tree: "Family Tree"
|
|
baseUrl: http://localhost:5000
|
|
timezone: UTC
|
|
databaseBackend: postgresql
|
|
userDatabaseUri: sqlite:////app/users/users.sqlite
|
|
userDatabaseUriSecret:
|
|
existingSecret: ""
|
|
key: user-database-uri
|
|
searchIndexDatabaseUri: sqlite:////app/indexdir/search_index.db
|
|
searchIndexDatabaseUriSecret:
|
|
existingSecret: ""
|
|
key: search-index-database-uri
|
|
extraEnv: []
|
|
|
|
appSecret:
|
|
# The chart creates and preserves a random secret when existingSecret is empty.
|
|
existingSecret: ""
|
|
existingSecretKey: secret-key
|
|
value: ""
|
|
|
|
database:
|
|
# Used only when postgresql.enabled=false. Bundled credentials are configured
|
|
# below under postgresql.auth.
|
|
host: ""
|
|
port: 5432
|
|
username: gramps
|
|
database: gramps
|
|
auth:
|
|
existingSecret: ""
|
|
existingSecretKey: password
|
|
password: ""
|
|
|
|
cache:
|
|
# Used only when valkey.enabled=false. Bundled credentials are configured
|
|
# below under valkey.auth.
|
|
host: ""
|
|
port: 6379
|
|
brokerDatabase: 0
|
|
resultDatabase: 1
|
|
rateLimitDatabase: 2
|
|
auth:
|
|
enabled: true
|
|
existingSecret: ""
|
|
existingSecretKey: valkey-password
|
|
password: ""
|
|
|
|
oidc:
|
|
enabled: false
|
|
issuer: ""
|
|
clientId: ""
|
|
clientSecret:
|
|
existingSecret: ""
|
|
existingSecretKey: oidc-client-secret
|
|
value: ""
|
|
name: OIDC
|
|
scopes: openid email profile
|
|
usernameClaim: preferred_username
|
|
openidConfigUrl: ""
|
|
disableLocalAuth: false
|
|
autoRedirect: false
|
|
roleClaim: groups
|
|
groups:
|
|
admin: ""
|
|
owner: ""
|
|
editor: ""
|
|
contributor: ""
|
|
member: ""
|
|
guest: ""
|
|
|
|
s3:
|
|
enabled: false
|
|
mediaBaseDir: ""
|
|
region: ""
|
|
endpointUrl: ""
|
|
auth:
|
|
existingSecret: ""
|
|
accessKeyIdKey: aws-access-key-id
|
|
secretAccessKeyKey: aws-secret-access-key
|
|
accessKeyId: ""
|
|
secretAccessKey: ""
|
|
|
|
email:
|
|
enabled: false
|
|
host: ""
|
|
port: 587
|
|
useTls: true
|
|
defaultFromEmail: ""
|
|
username: ""
|
|
auth:
|
|
existingSecret: ""
|
|
passwordKey: smtp-password
|
|
password: ""
|
|
|
|
persistence:
|
|
enabled: true
|
|
existingClaim: ""
|
|
storageClass: ""
|
|
accessModes:
|
|
- ReadWriteMany
|
|
size: 10Gi
|
|
annotations:
|
|
helm.sh/resource-policy: keep
|
|
|
|
worker:
|
|
enabled: true
|
|
replicaCount: 1
|
|
nameOverride: ""
|
|
concurrency: 2
|
|
startupProbe:
|
|
enabled: true
|
|
exec:
|
|
command:
|
|
- sh
|
|
- -ec
|
|
- celery -A gramps_webapi.celery inspect ping --destination "celery@${HOSTNAME}" --timeout 5
|
|
periodSeconds: 10
|
|
timeoutSeconds: 10
|
|
failureThreshold: 30
|
|
readinessProbe:
|
|
enabled: true
|
|
exec:
|
|
command:
|
|
- sh
|
|
- -ec
|
|
- celery -A gramps_webapi.celery inspect ping --destination "celery@${HOSTNAME}" --timeout 5
|
|
periodSeconds: 15
|
|
timeoutSeconds: 10
|
|
failureThreshold: 2
|
|
livenessProbe:
|
|
enabled: true
|
|
exec:
|
|
command:
|
|
- sh
|
|
- -ec
|
|
- celery -A gramps_webapi.celery inspect ping --destination "celery@${HOSTNAME}" --timeout 5
|
|
periodSeconds: 30
|
|
timeoutSeconds: 10
|
|
failureThreshold: 6
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "2"
|
|
memory: 2Gi
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 1Gi
|
|
|
|
livenessProbe:
|
|
enabled: true
|
|
httpGet:
|
|
path: /ready
|
|
port: http
|
|
initialDelaySeconds: 15
|
|
timeoutSeconds: 5
|
|
readinessProbe:
|
|
enabled: true
|
|
# Also verifies PostgreSQL authentication/querying and a Valkey PING.
|
|
deep: true
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 15
|
|
timeoutSeconds: 10
|
|
failureThreshold: 2
|
|
startupProbe:
|
|
enabled: true
|
|
httpGet:
|
|
path: /ready
|
|
port: http
|
|
failureThreshold: 30
|
|
periodSeconds: 5
|
|
|
|
nodeSelector: {}
|
|
tolerations: []
|
|
affinity: {}
|
|
|
|
postgresql:
|
|
enabled: true
|
|
auth:
|
|
username: gramps
|
|
database: gramps
|
|
password: ""
|
|
existingSecret: ""
|
|
secretKeys:
|
|
adminPasswordKey: postgres-password
|
|
userPasswordKey: password
|
|
primary:
|
|
startupProbe:
|
|
enabled: true
|
|
timeoutSeconds: 5
|
|
failureThreshold: 30
|
|
persistence:
|
|
enabled: true
|
|
size: 8Gi
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 256Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 2Gi
|
|
|
|
valkey:
|
|
enabled: true
|
|
architecture: standalone
|
|
auth:
|
|
enabled: true
|
|
password: ""
|
|
existingSecret: ""
|
|
existingSecretPasswordKey: valkey-password
|
|
primary:
|
|
startupProbe:
|
|
enabled: true
|
|
failureThreshold: 30
|
|
persistence:
|
|
enabled: true
|
|
size: 1Gi
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 64Mi
|
|
limits:
|
|
cpu: 500m
|
|
memory: 512Mi
|