mirror of
https://github.com/shadoll/helm-charts.git
synced 2026-08-28 03:27:08 +00:00
feat: Add support for HA secrets management with init container and configuration options
This commit is contained in:
@@ -25,8 +25,30 @@ spec:
|
||||
hostNetwork: true
|
||||
dnsPolicy: ClusterFirstWithHostNet
|
||||
{{- end }}
|
||||
{{- if .Values.postgres.enabled }}
|
||||
{{- if or .Values.postgres.enabled .Values.haSecrets.enabled }}
|
||||
initContainers:
|
||||
{{- if .Values.haSecrets.enabled }}
|
||||
- name: init-secrets
|
||||
image: busybox:latest
|
||||
command:
|
||||
- /bin/sh
|
||||
- -c
|
||||
- |
|
||||
# Build secrets.yaml from mounted K8s secret
|
||||
echo "# Managed by Helm - do not edit manually" > /config/secrets.yaml
|
||||
for f in /ha-secrets/*; do
|
||||
key=$(basename "$f")
|
||||
val=$(cat "$f")
|
||||
echo "$key: \"$val\"" >> /config/secrets.yaml
|
||||
done
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
- name: ha-secrets
|
||||
mountPath: /ha-secrets
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- if .Values.postgres.enabled }}
|
||||
- name: init-recorder
|
||||
image: busybox:latest
|
||||
command:
|
||||
@@ -55,6 +77,7 @@ spec:
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: {{ .Chart.Name }}
|
||||
@@ -101,6 +124,11 @@ spec:
|
||||
path: {{ .Values.persistence.media.hostPath }}
|
||||
type: DirectoryOrCreate
|
||||
{{- end }}
|
||||
{{- if .Values.haSecrets.enabled }}
|
||||
- name: ha-secrets
|
||||
secret:
|
||||
secretName: {{ .Values.haSecrets.existingSecret }}
|
||||
{{- end }}
|
||||
{{- with .Values.nodeSelector }}
|
||||
nodeSelector:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
|
||||
@@ -60,6 +60,11 @@ persistence:
|
||||
hostPath: /srv/data/home-assistant/media
|
||||
mountPath: /media
|
||||
|
||||
haSecrets:
|
||||
enabled: false
|
||||
# K8s Secret containing key-value pairs to write as /config/secrets.yaml
|
||||
existingSecret: ""
|
||||
|
||||
postgres:
|
||||
enabled: false
|
||||
host: postgres-tcp.postgres.svc.cluster.local
|
||||
|
||||
Reference in New Issue
Block a user