A new cluster directory rather than edits to k8s-admin-prd-ase1, so no homelab value is ever reused for GCP by accident. Charts are the ones already vendored here (gitea 12.7.0, argo-cd 7.7.23, cert-manager v1.20.1); only the values are new. Verified with helm template. What differs from the homelab, and why: - gitea: storageClass standard-rwo, and Recreate for a different reason than the homelab's LevelDB lock — three nodes and a ReadWriteOnce disk mean a rolling update's new pod waits forever on Multi-Attach. The admin password comes from a Secret created at bootstrap instead of the chart's published default, which would otherwise be live on a public IP. Registration is disabled and webhooks are limited to private ranges, for the same reason. - argocd: single ingress host (no Tailscale), and the homelab's Ingress health override is dropped, since Contour writes real load balancer status here. server and repoServer autoscale 1-3 on CPU; the chart omits replicas when autoscaling is on, so the HPA and ArgoCD's own self-management do not fight over the count. Memory is deliberately not a scaling metric: Go does not return memory promptly, so a memory target scales up and never back down. - cert-manager: written fresh, not copied. The homelab file was never adapted from the fleet — it pulls from a private Meesho registry and pins pods to a node pool that does not exist here. The chart's own values.yaml carries that registry too, so imageRegistry and imageNamespace are overridden back to upstream's quay.io/jetstack. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LEsTefWWifp4ikvhHF5s6N
76 lines
2.5 KiB
YAML
76 lines
2.5 KiB
YAML
gitea:
|
|
# GKE counterpart of helm-overrides/k8s-admin-prd-ase1/gitea — same
|
|
# SQLite/no-cache shape, with what differs on GKE called out inline.
|
|
#
|
|
# Installed once by hand with `helm install gitea` (release "gitea",
|
|
# namespace "gitea"), then adopted by ArgoCD via the nameOverride in
|
|
# devops-infra-argo-config-gcp's values file. Gitea has to exist before
|
|
# ArgoCD can read anything, since both config repos live inside it.
|
|
|
|
# Recreate for a different reason than the homelab's LevelDB lock: on
|
|
# three nodes with a ReadWriteOnce persistent disk, the chart's default
|
|
# RollingUpdate (maxUnavailable: 0) starts the new pod first, and if it
|
|
# lands on another node it waits forever on Multi-Attach.
|
|
strategy:
|
|
type: Recreate
|
|
|
|
persistence:
|
|
size: 10Gi
|
|
# GKE's default class (pd-balanced), in place of the homelab's
|
|
# local-path. Counts against the project's 250GB SSD quota.
|
|
storageClass: standard-rwo
|
|
|
|
postgresql:
|
|
enabled: false
|
|
postgresql-ha:
|
|
enabled: false
|
|
valkey:
|
|
enabled: false
|
|
valkey-cluster:
|
|
enabled: false
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 300Mi
|
|
limits:
|
|
memory: 500Mi
|
|
|
|
gitea:
|
|
config:
|
|
database:
|
|
DB_TYPE: sqlite3
|
|
actions:
|
|
ENABLED: true
|
|
server:
|
|
ROOT_URL: http://gitea.35.238.248.203.nip.io/
|
|
service:
|
|
# The homelab sat on a LAN; this Gitea is on a public IP. Open
|
|
# registration would let anyone on the internet create an account.
|
|
DISABLE_REGISTRATION: true
|
|
security:
|
|
# The homelab allowed "*" because every host was on a private LAN.
|
|
# Here "*" would also allow webhooks to the node metadata server,
|
|
# so this is narrowed to private ranges — which still covers every
|
|
# in-cluster Service (Jenkins included) reached over cluster DNS.
|
|
ALLOWED_HOST_LIST: private
|
|
admin:
|
|
username: gitadmin
|
|
# Created by hand with kubectl at bootstrap, because Vault and ESO
|
|
# are not running yet. Same Secret name as the homelab so the
|
|
# ExternalSecret (secretstores/gitea-admin-credentials.yaml) can take
|
|
# it over unchanged once Vault is up.
|
|
existingSecret: gitea-admin-credentials
|
|
email: "admin@local.lab"
|
|
|
|
# Contour does not exist yet at bootstrap — the Ingress just sits unused
|
|
# until ArgoCD installs it. One host only: no Tailscale on GKE.
|
|
ingress:
|
|
enabled: true
|
|
className: contour
|
|
hosts:
|
|
- host: gitea.35.238.248.203.nip.io
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|