diff --git a/charts/sourcegraph/CHANGELOG.md b/charts/sourcegraph/CHANGELOG.md index 225a58de..a03f9e09 100644 --- a/charts/sourcegraph/CHANGELOG.md +++ b/charts/sourcegraph/CHANGELOG.md @@ -8,6 +8,7 @@ Use `**BREAKING**:` to denote a breaking change ## Unreleased +- Added `gitserver.storageAccessModes` (default `["ReadWriteOnce"]`) to allow `["ReadWriteOncePod"]`, which lets Kubernetes mount the repos volume with `-o context` on SELinux-enforcing nodes (e.g. Bottlerocket / EKS Auto Mode) instead of recursively relabeling every file on each pod start. Changing this on an existing deployment requires recreating the StatefulSet and PVC, as both fields are immutable. - Added configurable pre-shutdown pauses, graceful-shutdown timeouts, and termination grace periods for application services - Added optional `syntectServer.podDisruptionBudget` support - Added optional `searcher.podDisruptionBudget` support diff --git a/charts/sourcegraph/README.md b/charts/sourcegraph/README.md index 87023952..bfb8e2ad 100644 --- a/charts/sourcegraph/README.md +++ b/charts/sourcegraph/README.md @@ -135,6 +135,7 @@ In addition to the documented values, all services also support the following va | gitserver.serviceAccount.create | bool | `false` | Enable creation of ServiceAccount for `gitserver` | | gitserver.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | gitserver.sshSecret | string | `""` | Name of existing Secret that contains SSH credentials to clone repositories. It usually contains keys, such as `id_rsa` (private key) and `known_hosts`. Learn more from [documentation](https://docs.sourcegraph.com/admin/install/kubernetes/helm#using-ssh-to-clone-repositories) | +| gitserver.storageAccessModes | list | `["ReadWriteOnce"]` | Access modes for the `gitserver` PVC. Set to `["ReadWriteOncePod"]` on SELinux-enforcing nodes (e.g. Bottlerocket / EKS Auto Mode) so Kubernetes mounts the volume with `-o context` instead of recursively relabeling every file on each pod start | | gitserver.storageAnnotations | object | `{}` | Optional annotations to add to the `gitserver` PVC | | gitserver.storageSize | string | `"200Gi"` | PVC Storage Request for `gitserver` data volume | | gitserver.storageSubPath | string | `""` | Optional subPath for the `gitserver` primary data volume mount | diff --git a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml index 3e093ce5..432f7170 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml @@ -135,7 +135,7 @@ spec: {{- end }} spec: accessModes: - - ReadWriteOnce + {{- toYaml .Values.gitserver.storageAccessModes | nindent 6 }} resources: requests: # The size of disk used to mirror your git repositories. diff --git a/charts/sourcegraph/tests/gitserverStorageAccessModes_test.yaml b/charts/sourcegraph/tests/gitserverStorageAccessModes_test.yaml new file mode 100644 index 00000000..6c465f0b --- /dev/null +++ b/charts/sourcegraph/tests/gitserverStorageAccessModes_test.yaml @@ -0,0 +1,57 @@ +suite: gitserver storageAccessModes +templates: +- gitserver/gitserver.StatefulSet.yaml +release: + name: sourcegraph + namespace: sourcegraph +tests: +- it: should default gitserver PVC accessModes to ReadWriteOnce + asserts: + - equal: + path: spec.volumeClaimTemplates[0].spec.accessModes + value: + - ReadWriteOnce +- it: should render gitserver PVC accessModes from gitserver.storageAccessModes + set: + gitserver: + storageAccessModes: + - ReadWriteOncePod + asserts: + - equal: + path: spec.volumeClaimTemplates[0].spec.accessModes + value: + - ReadWriteOncePod +- it: should render multiple gitserver PVC accessModes when several are set + set: + gitserver: + storageAccessModes: + - ReadWriteOnce + - ReadOnlyMany + asserts: + - equal: + path: spec.volumeClaimTemplates[0].spec.accessModes + value: + - ReadWriteOnce + - ReadOnlyMany +- it: should keep the rest of the gitserver volumeClaimTemplate intact when overriding accessModes + set: + gitserver: + storageAccessModes: + - ReadWriteOncePod + storageSize: 500Gi + storageAnnotations: + example.com/annotation: value + asserts: + - equal: + path: spec.volumeClaimTemplates[0].metadata.name + value: repos + - equal: + path: spec.volumeClaimTemplates[0].metadata.annotations["example.com/annotation"] + value: value + - equal: + path: spec.volumeClaimTemplates[0].spec.accessModes + value: + - ReadWriteOncePod + - equal: + path: spec.volumeClaimTemplates[0].spec.resources.requests.storage + value: 500Gi diff --git a/charts/sourcegraph/values.yaml b/charts/sourcegraph/values.yaml index db31d856..2fa34c96 100644 --- a/charts/sourcegraph/values.yaml +++ b/charts/sourcegraph/values.yaml @@ -472,6 +472,8 @@ gitserver: create: false # -- Name of the ServiceAccount to be created or an existing ServiceAccount name: "" + # -- Access modes for the `gitserver` PVC. Set to `["ReadWriteOncePod"]` on SELinux-enforcing nodes (e.g. Bottlerocket / EKS Auto Mode) so Kubernetes mounts the volume with `-o context` instead of recursively relabeling every file on each pod start + storageAccessModes: ["ReadWriteOnce"] # -- PVC Storage Request for `gitserver` data volume storageSize: 200Gi # -- Optional subPath for the `gitserver` primary data volume mount