From df70f4e1ecdb376d6675ddb9ec192c240411f5c2 Mon Sep 17 00:00:00 2001 From: Marcos Bjoerkelund Date: Fri, 9 Oct 2020 17:42:43 +0200 Subject: [PATCH] [bitnami/prestashop] New major version: bump mariadb and standarizations (#3949) * [bitnami/prestashop] New major version: bump mariadb and standarizations * More standarizations * reset drupal change * fixes * fix template -> include * implement readme changes from #3874 * fix redmine typo * fix certificate location * [bitnami/prestashop] Update components versions Signed-off-by: Bitnami Containers Co-authored-by: Bitnami Containers --- bitnami/prestashop/Chart.yaml | 2 +- bitnami/prestashop/README.md | 207 +++++++++++++++---- bitnami/prestashop/requirements.lock | 8 +- bitnami/prestashop/requirements.yaml | 4 +- bitnami/prestashop/templates/NOTES.txt | 33 ++- bitnami/prestashop/templates/_helpers.tpl | 81 +++++++- bitnami/prestashop/templates/deployment.yaml | 138 +++++++++---- bitnami/prestashop/templates/ingress.yaml | 38 ++-- bitnami/prestashop/templates/pvc.yaml | 2 +- bitnami/prestashop/templates/svc.yaml | 19 +- bitnami/prestashop/values.yaml | 188 +++++++++++++---- 11 files changed, 563 insertions(+), 157 deletions(-) diff --git a/bitnami/prestashop/Chart.yaml b/bitnami/prestashop/Chart.yaml index 8530e93f6..96b7ac4a9 100644 --- a/bitnami/prestashop/Chart.yaml +++ b/bitnami/prestashop/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v1 name: prestashop -version: 10.0.2 +version: 11.0.0 appVersion: 1.7.6-8 description: A popular open source ecommerce solution. Professional tools are easily accessible to increase online sales including instant guest checkout, abandoned cart reminders and automated Email marketing. keywords: diff --git a/bitnami/prestashop/README.md b/bitnami/prestashop/README.md index 52ee600e6..990de5b5b 100644 --- a/bitnami/prestashop/README.md +++ b/bitnami/prestashop/README.md @@ -62,14 +62,14 @@ The following table lists the configurable parameters of the PrestaShop chart an | Parameter | Description | Default | |---------------------|------------------------------------------------------------------------------|---------------------------------------------------------| -| `image.registry` | PrestaShop image registry | `docker.io` | -| `image.repository` | PrestaShop Image name | `bitnami/prestashop` | -| `image.tag` | PrestaShop Image tag | `{TAG_NAME}` | -| `image.pullPolicy` | PrestaShop image pull policy | `IfNotPresent` | +| `image.registry` | PrestaShop image registry | `docker.io` | +| `image.repository` | PrestaShop Image name | `bitnami/prestashop` | +| `image.tag` | PrestaShop Image tag | `{TAG_NAME}` | +| `image.pullPolicy` | PrestaShop image pull policy | `IfNotPresent` | | `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | | `image.debug` | Specify if debug logs should be enabled | `false` | -| `nameOverride` | String to partially override prestashop.fullname template | `nil` | -| `fullnameOverride` | String to fully override prestashop.fullname template | `nil` | +| `nameOverride` | String to partially override prestashop.fullname template | `nil` | +| `fullnameOverride` | String to fully override prestashop.fullname template | `nil` | | `commonLabels` | Labels to add to all deployed objects | `nil` | | `commonAnnotations` | Annotations to add to all deployed objects | `[]` | | `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template). | `nil` | @@ -82,6 +82,8 @@ The following table lists the configurable parameters of the PrestaShop chart an | `allowEmptyPassword` | Allow DB blank passwords | `yes` | | `args` | Override default container args (useful when using custom images) | `nil` | | `command` | Override default container command (useful when using custom images) | `nil` | +| `containerPorts.http` | Sets http port inside NGINX container | `8080` | +| `containerPorts.https` | Sets https port inside NGINX container | `8443` | | `containerSecurityContext.enabled` | Enable PrestaShop containers' Security Context | `true` | | `containerSecurityContext.runAsUser` | PrestaShop containers' Security Context | `1001` | | `customLivenessProbe` | Override default liveness probe | `nil` | @@ -95,6 +97,10 @@ The following table lists the configurable parameters of the PrestaShop chart an | `initContainers` | Add additional init containers to the pod (evaluated as a template) | `nil` | | `lifecycleHooks` | LifecycleHook to set additional configuration at startup Evaluated as a template | `` | | `livenessProbe` | Liveness probe configuration | `Check values.yaml file` | +| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | +| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | +| `nodeSelector` | Node labels for pod assignment | `{}` (The value is evaluated as a template) | | `prestashopHost` | PrestaShop host to create application URLs (when ingress, it will be ignored) | `nil` | | `prestashopUsername` | User of the application | `user@example.com` | | `prestashopPassword` | Application password | _random 10 character long alphanumeric string_ | @@ -104,14 +110,15 @@ The following table lists the configurable parameters of the PrestaShop chart an | `prestashopCookieCheckIP` | Whether to check the cookie's IP address or not | `no` | | `prestashopCountry` | Default country of the store | `us` | | `prestashopLanguage` | Default language of the store (iso code) | `en` | -| `prestashopSkipInstall` | Skip PrestaShop installation wizard (`no` / `yes`) | `no` | -| `nodeSelector` | Node labels for pod assignment | `{}` (The value is evaluated as a template) | +| `prestashopSkipInstall` | Skip PrestaShop installation wizard (`no` / `yes`) | `false` | | `persistence.accessMode` | PVC Access Mode for PrestaShop volume | `ReadWriteOnce` | | `persistence.enabled` | Enable persistence using PVC | `true` | | `persistence.existingClaim` | An Existing PVC name | `nil` | | `persistence.hostPath` | Host mount path for PrestaShop volume | `nil` (will not mount to a host path) | | `persistence.size` | PVC Storage Request for PrestaShop volume | `8Gi` | | `persistence.storageClass` | PVC Storage Class for PrestaShop volume | `nil` (uses alpha storage class annotation) | +| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | | `podAnnotations` | Pod annotations | `{}` | | `podLabels` | Add additional labels to the pod (evaluated as a template) | `nil` | | `podSecurityContext.enabled` | Enable PrestaShop pods' Security Context | `true` | @@ -133,8 +140,8 @@ The following table lists the configurable parameters of the PrestaShop chart an | Parameter | Description | Default | |----------------------------------|---------------------------------------|--------------------| | `service.type` | Kubernetes Service type | `LoadBalancer` | -| `service.port` | Service HTTP port | `8080` | -| `service.httpsPort` | Service HTTPS port | `8443` | +| `service.port` | Service HTTP port | `80` | +| `service.httpsPort` | Service HTTPS port | `443` | | `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | | `service.nodePorts.http` | Kubernetes http node port | `""` | | `service.nodePorts.https` | Kubernetes https node port | `""` | @@ -152,25 +159,37 @@ The following table lists the configurable parameters of the PrestaShop chart an ### Database parameters -| Parameter | Description | Default | -|--------------------------------------------|------------------------------------------|------------------------------------------------| -| `mariadb.enabled` | Whether to use the MariaDB chart | `true` | -| `mariadb.rootUser.password` | MariaDB admin password | `nil` | -| `mariadb.db.name` | Database name to create | `bitnami_prestashop` | -| `mariadb.db.user` | Database user to create | `bn_prestashop` | -| `mariadb.db.password` | Password for the database | _random 10 character long alphanumeric string_ | -| `mariadb.replication.enabled` | MariaDB replication enabled | `false` | -| `mariadb.master.persistence.enabled` | Enable database persistence using PVC | `true` | -| `mariadb.master.persistence.accessMode` | Database Persistent Volume Access Modes | `ReadWriteOnce` | -| `mariadb.master.persistence.size` | Database Persistent Volume Size | `8Gi` | -| `mariadb.master.persistence.existingClaim` | Enable persistence using an existing PVC | `nil` | -| `mariadb.master.persistence.storageClass` | PVC Storage Class | `nil` (uses alpha storage class annotation) | -| `mariadb.master.persistence.hostPath` | Host mount path for MariaDB volume | `nil` (will not mount to a host path) | -| `externalDatabase.user` | Existing username in the external db | `bn_prestashop` | -| `externalDatabase.password` | Password for the above username | `nil` | -| `externalDatabase.database` | Name of the existing database | `bitnami_prestashop` | -| `externalDatabase.host` | Host of the existing database | `nil` | -| `externalDatabase.port` | Port of the existing database | `3306` | +| Parameter | Description | Default | +|---------------------------------------------|------------------------------------------------------------------------------------------|------------------------------------------------| +| `mariadb.enabled` | Whether to use the MariaDB chart | `true` | +| `mariadb.architecture` | MariaDB architecture (`standalone` or `replication`) | `standalone` | +| `mariadb.auth.rootPassword` | Password for the MariaDB `root` user | _random 10 character alphanumeric string_ | +| `mariadb.auth.database` | Database name to create | `bitnami_prestashop` | +| `mariadb.auth.username` | Database user to create | `bn_prestashop` | +| `mariadb.auth.password` | Password for the database | _random 10 character long alphanumeric string_ | +| `mariadb.primary.persistence.enabled` | Enable database persistence using PVC | `true` | +| `mariadb.primary.persistence.existingClaim` | Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas | `nil` | +| `mariadb.primary.persistence.accessModes` | Database Persistent Volume Access Modes | `[ReadWriteOnce]` | +| `mariadb.primary.persistence.size` | Database Persistent Volume Size | `8Gi` | +| `mariadb.primary.persistence.hostPath` | Set path in case you want to use local host path volumes (not recommended in production) | `nil` | +| `mariadb.primary.persistence.storageClass` | MariaDB primary persistent volume storage Class | `nil` | +| `externalDatabase.user` | Existing username in the external db | `bn_prestashop` | +| `externalDatabase.password` | Password for the above username | `""` | +| `externalDatabase.database` | Name of the existing database | `bitnami_prestashop` | +| `externalDatabase.host` | Host of the existing database | `nil` | +| `externalDatabase.port` | Port of the existing database | `3306` | + +### Volume Permissions parameters + +| Parameter | Description | Default | +|------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------| +| `volumePermissions.enabled` | Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) | `false` | +| `volumePermissions.image.registry` | Init container volume-permissions image registry | `docker.io` | +| `volumePermissions.image.repository` | Init container volume-permissions image name | `bitnami/minideb` | +| `volumePermissions.image.tag` | Init container volume-permissions image tag | `buster` | +| `volumePermissions.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | +| `volumePermissions.image.pullPolicy` | Init container volume-permissions image pull policy | `Always` | +| `volumePermissions.resources` | Init container resource requests/limit | `nil` | ### Metrics parameters @@ -185,6 +204,28 @@ The following table lists the configurable parameters of the PrestaShop chart an | `metrics.podAnnotations` | Additional annotations for Metrics exporter pod | `{prometheus.io/scrape: "true", prometheus.io/port: "9117"}` | | `metrics.resources` | Exporter resource requests/limit | {} | +### Certificate injection parameters + +| Parameter | Description | Default | +|------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------| +| `certificates.customCertificate.certificateSecret` | Secret containing the certificate and key to add | `""` | +| `certificates.customCertificate.chainSecret.name` | Name of the secret containing the certificate chain | `""` | +| `certificates.customCertificate.chainSecret.key` | Key of the certificate chain file inside the secret | `""` | +| `certificates.customCertificate.certificateLocation` | Location in the container to store the certificate | `/etc/ssl/certs/ssl-cert-snakeoil.pem` | +| `certificates.customCertificate.keyLocation` | Location in the container to store the private key | `/etc/ssl/private/ssl-cert-snakeoil.key` | +| `certificates.customCertificate.chainLocation` | Location in the container to store the certificate chain | `/etc/ssl/certs/chain.pem` | +| `certificates.customCAs` | Defines a list of secrets to import into the container trust store | `[]` | +| `certificates.image.registry` | Container sidecar registry | `docker.io` | +| `certificates.image.repository` | Container sidecar image | `bitnami/minideb` | +| `certificates.image.tag` | Container sidecar image tag | `buster` | +| `certificates.image.pullPolicy` | Container sidecar image pull policy | `IfNotPresent` | +| `certificates.image.pullSecrets` | Container sidecar image pull secrets | `image.pullSecrets` | +| `certificates.args` | Override default container args (useful when using custom images) | `nil` | +| `certificates.command` | Override default container command (useful when using custom images) | `nil` | +| `certificates.extraEnvVars` | Container sidecar extra environment variables (eg proxy) | `[]` | +| `certificates.extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | +| `certificates.extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | + The above parameters map to the env variables defined in [bitnami/prestashop](http://github.com/bitnami/bitnami-docker-prestashop). For more information please refer to the [bitnami/prestashop](http://github.com/bitnami/bitnami-docker-prestashop) image documentation. > **Note**: @@ -205,7 +246,7 @@ Specify each parameter using the `--set key=value[,key=value]` argument to `helm ```console $ helm install my-release \ - --set prestashopUsername=admin,prestashopPassword=password,mariadb.mariadbRootPassword=secretpassword \ + --set prestashopUsername=admin,prestashopPassword=password,mariadb.auth.rootPassword=secretpassword \ bitnami/prestashop ``` @@ -227,6 +268,30 @@ It is strongly recommended to use immutable tags in a production environment. Th Bitnami will release a new chart updating its containers if a new version of the main container, significant changes, or critical vulnerabilities exist. +### Image + +The `image` parameter allows specifying which image will be pulled for the chart. + +#### Private registry + +If you configure the `image` value to one in a private registry, you will need to [specify an image pull secret](https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod). + +1. Manually create image pull secret(s) in the namespace. See [this YAML example reference](https://kubernetes.io/docs/concepts/containers/images/#creating-a-secret-with-a-docker-config). Consult your image registry's documentation about getting the appropriate secret. +1. Note that the `imagePullSecrets` configuration value cannot currently be passed to helm using the `--set` parameter, so you must supply these using a `values.yaml` file, such as: + +```yaml +imagePullSecrets: + - name: SECRET_NAME +``` + +1. Install the chart + +### Setting Pod's affinity + +This chart allows you to set your custom affinity using the `affinity` paremeter. Find more infomation about Pod's affinity in the [kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity). + +As an alternative, you can use of the preset configurations for pod affinity, pod anti-affinity, and node affinity available at the [bitnami/common](https://github.com/bitnami/charts/tree/master/bitnami/common#affinities) chart. To do so, set the `podAffinityPreset`, `podAntiAffinityPreset`, or `nodeAffinityPreset` parameters. + ## Persistence The [Bitnami PrestaShop](https://github.com/bitnami/bitnami-docker-prestashop) image stores the PrestaShop data and configurations at the `/bitnami/prestashop` path of the container. @@ -234,6 +299,35 @@ The [Bitnami PrestaShop](https://github.com/bitnami/bitnami-docker-prestashop) i Persistent Volume Claims are used to keep the data across deployments. This is known to work in GCE, AWS, and minikube. See the [Parameters](#parameters) section to configure the PVC or to disable persistence. +### Existing PersistentVolumeClaim + +1. Create the PersistentVolume +1. Create the PersistentVolumeClaim +1. Install the chart + +```bash +$ helm install my-release --set persistence.existingClaim=PVC_NAME bitnami/prestashop +``` + +### Host path + +#### System compatibility + +- The local filesystem accessibility to a container in a pod with `hostPath` has been tested on OSX/MacOS with xhyve, and Linux with VirtualBox. +- Windows has not been tested with the supported VM drivers. Minikube does however officially support [Mounting Host Folders](https://github.com/kubernetes/minikube/blob/master/docs/host_folder_mount.md) per pod. Or you may manually sync your container whenever host files are changed with tools like [docker-sync](https://github.com/EugenMayer/docker-sync) or [docker-bg-sync](https://github.com/cweagans/docker-bg-sync). + +#### Mounting steps + +1. The specified `hostPath` directory must already exist (create one if it does not). +1. Install the chart + + ```bash + $ helm install my-release --set persistence.hostPath=/PATH/TO/HOST/MOUNT bitnami/prestashop + ``` + + This will mount the `prestashop-data` volume into the `hostPath` directory. The site data will be persisted if the mount path contains valid data, else the site data will be initialized at first launch. +1. Because the container cannot control the host machine's directory permissions, you must set the PrestaShop file directory permissions yourself and disable or clear PrestaShop cache. + ## Troubleshooting ### SSL @@ -241,15 +335,56 @@ See the [Parameters](#parameters) section to configure the PVC or to disable per One needs to explicitly turn on SSL in the Prestashop administration panel, else a `302` redirect to `http` scheme is returned on any page of the site by default. To enable SSL on all pages, follow these steps: - - Browse to the administration panel and log in. - - Click “Shop Parameters” in the left navigation panel. - - Set the option “Enable SSL” to “Yes”. - - Click the “Save” button. - - Set the (now enabled) option “Enable SSL on all pages” to “Yes”. - - Click the “Save” button. + +- Browse to the administration panel and log in. +- Click “Shop Parameters” in the left navigation panel. +- Set the option “Enable SSL” to “Yes”. +- Click the “Save” button. +- Set the (now enabled) option “Enable SSL on all pages” to “Yes”. +- Click the “Save” button. ## Upgrading +### To 11.0.0 + +MariaDB dependency version was bumped to a new major version that introduces several incompatilibites. Therefore, backwards compatibility is not guaranteed unless an external database is used. Check [MariaDB Upgrading Notes](https://github.com/bitnami/charts/tree/master/bitnami/mariadb#to-800) for more information. + +To upgrade to `11.0.0`, you have two alternatives: + +- Install a new Prestashop chart, and migrate your Prestashop site using backup/restore using any [Backup and Restore tool from Prestashop marketplace](https://addons.prestashop.com/en/search?search_query=backup&). +- Reuse the PVC used to hold the MariaDB data on your previous release. To do so, follow the instructions below (the following example assumes that the release name is `prestashop`): + +Obtain the credentials and the name of the PVC used to hold the MariaDB data on your current release: + +```console +export PRESTASHOP_PASSWORD=$(kubectl get secret --namespace default prestashop -o jsonpath="{.data.prestashop-password}" | base64 --decode) +export MARIADB_ROOT_PASSWORD=$(kubectl get secret --namespace default prestashop-mariadb -o jsonpath="{.data.mariadb-root-password}" | base64 --decode) +export MARIADB_PASSWORD=$(kubectl get secret --namespace default prestashop-mariadb -o jsonpath="{.data.mariadb-password}" | base64 --decode) +export MARIADB_PVC=$(kubectl get pvc -l app.kubernetes.io/instance=prestashop,app.kubernetes.io/name=mariadb,app.kubernetes.io/component=primary -o jsonpath="{.items[0].metadata.name}") +``` + +Upgrade your release (maintaining the version) disabling MariaDB and scaling Prestashop replicas to 0: + +```console +$ helm upgrade prestashop bitnami/prestashop --set prestashopPassword=$PRESTASHOP_PASSWORD --set replicaCount=0 --set mariadb.enabled=false --version 10.0.0 +``` + +Finally, upgrade you release to 11.0.0 reusing the existing PVC, and enabling back MariaDB: + +```console +$ helm upgrade prestashop bitnami/prestashop --set mariadb.primary.persistence.existingClaim=$MARIADB_PVC --set mariadb.auth.rootPassword=$MARIADB_ROOT_PASSWORD --set mariadb.auth.password=$MARIADB_PASSWORD --set prestashopPassword=$PRESTASHOP_PASSWORD +``` + +You should see the lines below in MariaDB container logs: + +```console +$ kubectl logs $(kubectl get pods -l app.kubernetes.io/instance=prestashop,app.kubernetes.io/name=mariadb,app.kubernetes.io/component=primary -o jsonpath="{.items[0].metadata.name}") +... +mariadb 12:13:24.98 INFO ==> Using persisted data +mariadb 12:13:25.01 INFO ==> Running mysql_upgrade +... +``` + ### To 10.0.0 The [Bitnami PrestaShop](https://github.com/bitnami/bitnami-docker-prestashop) image was updated to support and enable the "non-root" user approach diff --git a/bitnami/prestashop/requirements.lock b/bitnami/prestashop/requirements.lock index 9a31e3f86..2d07a2ff2 100644 --- a/bitnami/prestashop/requirements.lock +++ b/bitnami/prestashop/requirements.lock @@ -1,9 +1,9 @@ dependencies: - name: mariadb repository: https://charts.bitnami.com/bitnami - version: 7.10.2 + version: 8.0.3 - name: common repository: https://charts.bitnami.com/bitnami - version: 0.7.1 -digest: sha256:69d52756d54f7f7b91b7f6ea62f495dd8dfbe64865a66a8961e5dbabb6ac6b05 -generated: "2020-09-22T16:31:57.783305769+02:00" + version: 0.8.1 +digest: sha256:7d3df66c4694180b3eaccdae065d1f0e666bea8501a668e9410bedf0f64e965c +generated: "2020-10-08T14:15:02.139604908+02:00" diff --git a/bitnami/prestashop/requirements.yaml b/bitnami/prestashop/requirements.yaml index c8c5ed43d..b7c74cf1a 100644 --- a/bitnami/prestashop/requirements.yaml +++ b/bitnami/prestashop/requirements.yaml @@ -1,8 +1,10 @@ dependencies: - name: mariadb - version: 7.x.x + version: 8.x.x repository: https://charts.bitnami.com/bitnami condition: mariadb.enabled - name: common version: 0.x.x repository: https://charts.bitnami.com/bitnami + tags: + - bitnami-common diff --git a/bitnami/prestashop/templates/NOTES.txt b/bitnami/prestashop/templates/NOTES.txt index eade89282..585eecf15 100644 --- a/bitnami/prestashop/templates/NOTES.txt +++ b/bitnami/prestashop/templates/NOTES.txt @@ -10,30 +10,28 @@ host. To configure PrestaShop with the URL of your service: 1. Get the PrestaShop URL by running: - {{- if contains "NodePort" .Values.service.type }} + {{- if eq .Values.service.type "NodePort" }} export APP_PORT=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "common.names.fullname" . }} -o jsonpath="{.spec.ports[0].nodePort}") export APP_HOST=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - {{- else if contains "LoadBalancer" .Values.service.type }} + {{- else if eq .Values.service.type "LoadBalancer" }} NOTE: It may take a few minutes for the LoadBalancer IP to be available. Watch the status with: 'kubectl get svc --namespace {{ .Release.Namespace }} -w {{ include "common.names.fullname" . }}' export APP_HOST=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "common.names.fullname" . }} --template "{{ "{{ range (index .status.loadBalancer.ingress 0) }}{{ . }}{{ end }}" }}") export APP_PASSWORD=$(kubectl get secret --namespace {{ .Release.Namespace }} {{ template "prestashop.secretName" . }} -o jsonpath="{.data.prestashop-password}" | base64 --decode) - {{- if .Values.mariadb.mariadbRootPassword }} - export DATABASE_ROOT_PASSWORD=$(kubectl get secret --namespace {{ .Release.Namespace }} {{ template "prestashop.mariadb.fullname" . }} -o jsonpath="{.data.mariadb-root-password}" | base64 --decode) + export DATABASE_ROOT_PASSWORD=$(kubectl get secret --namespace {{ .Release.Namespace }} {{ template "prestashop.databaseSecretName" . }} -o jsonpath="{.data.mariadb-root-password}" | base64 --decode) {{- end }} - {{- end }} - export APP_DATABASE_PASSWORD=$(kubectl get secret --namespace {{ .Release.Namespace }} {{ template "prestashop.mariadb.fullname" . }} -o jsonpath="{.data.mariadb-password}" | base64 --decode) + export APP_DATABASE_PASSWORD=$(kubectl get secret --namespace {{ .Release.Namespace }} {{ template "prestashop.databaseSecretName" . }} -o jsonpath="{.data.mariadb-password}" | base64 --decode) 2. Complete your PrestaShop deployment by running: {{- if .Values.mariadb.enabled }} helm upgrade {{ .Release.Name }} bitnami/{{ .Chart.Name }} \ - --set prestashopHost=$APP_HOST,prestashopPassword=$APP_PASSWORD{{ if .Values.mariadb.mariadbRootPassword }},mariadb.mariadbRootPassword=$DATABASE_ROOT_PASSWORD{{ end }},mariadb.db.password=$APP_DATABASE_PASSWORD{{- if .Values.global }}{{- if .Values.global.imagePullSecrets }},global.imagePullSecrets={{ .Values.global.imagePullSecrets }}{{- end }}{{- end }} + --set prestashopHost=$APP_HOST,prestashopPassword=$APP_PASSWORD,mariadb.auth.rootPassword=$DATABASE_ROOT_PASSWORD,mariadb.auth.password=$APP_DATABASE_PASSWORD{{- if .Values.global }}{{- if .Values.global.imagePullSecrets }},global.imagePullSecrets={{ .Values.global.imagePullSecrets }}{{- end }}{{- end }} {{- else }} ## PLEASE UPDATE THE EXTERNAL DATABASE CONNECTION PARAMETERS IN THE FOLLOWING COMMAND AS NEEDED ## @@ -79,9 +77,9 @@ host. To configure PrestaShop to use and external database host: 1. Complete your PrestaShop deployment by running: -{{- if contains "NodePort" .Values.service.type }} +{{- if eq .Values.service.type "NodePort" }} export APP_HOST=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") -{{- else if contains "LoadBalancer" .Values.service.type }} +{{- else if eq .Values.service.type "LoadBalancer" }} NOTE: It may take a few minutes for the LoadBalancer IP to be available. Watch the status with: 'kubectl get svc --namespace {{ .Release.Namespace }} -w {{ include "common.names.fullname" . }}' @@ -99,4 +97,19 @@ host. To configure PrestaShop to use and external database host: --set prestashopPassword=$APP_PASSWORD,prestashopHost=$APP_HOST,service.type={{ .Values.service.type }},mariadb.enabled=false{{- if not (empty .Values.externalDatabase.user) }},externalDatabase.user={{ .Values.externalDatabase.user }}{{- end }}{{- if not (empty .Values.externalDatabase.password) }},externalDatabase.password={{ .Values.externalDatabase.password }}{{- end }}{{- if not (empty .Values.externalDatabase.database) }},externalDatabase.database={{ .Values.externalDatabase.database }}{{- end }},externalDatabase.host=YOUR_EXTERNAL_DATABASE_HOST{{- if .Values.global }}{{- if .Values.global.imagePullSecrets }},global.imagePullSecrets={{ .Values.global.imagePullSecrets }}{{- end }}{{- end }} {{- end }} -{{- include "prestashop.checkRollingTags" . }} +{{- include "common.warnings.rollingTag" .Values.image }} +{{- include "common.warnings.rollingTag" .Values.metrics.image }} + +{{- $passwordValidationErrors := list -}} +{{- if not .Values.existingSecret -}} + {{- $secretName := include "prestashop.secretName" . -}} + {{- $requiredPrestashopPassword := dict "valueKey" "prestashopPassword" "secret" $secretName "field" "prestashop-password" "context" $ -}} + {{- $requiredPrestashopPasswordError := include "common.validations.values.single.empty" $requiredPrestashopPassword -}} + {{- $passwordValidationErrors = append $passwordValidationErrors $requiredPrestashopPasswordError -}} +{{- end -}} + +{{- $mariadbSecretName := include "prestashop.databaseSecretName" . -}} +{{- $mariadbPasswordValidationErrors := include "common.validations.values.mariadb.passwords" (dict "secret" $mariadbSecretName "subchart" true "context" $) -}} +{{- $passwordValidationErrors = append $passwordValidationErrors $mariadbPasswordValidationErrors -}} + +{{- include "common.errors.upgrade.passwords.empty" (dict "validationErrors" $passwordValidationErrors "context" $) -}} diff --git a/bitnami/prestashop/templates/_helpers.tpl b/bitnami/prestashop/templates/_helpers.tpl index 03f34f8df..e7d9219a6 100644 --- a/bitnami/prestashop/templates/_helpers.tpl +++ b/bitnami/prestashop/templates/_helpers.tpl @@ -25,7 +25,7 @@ When using Ingress, it will be set to the Ingress hostname. */}} {{- define "prestashop.host" -}} {{- if .Values.ingress.enabled }} -{{- $host := (index .Values.ingress.hosts 0).name | default "" -}} +{{- $host := .Values.ingress.hostname | default "" -}} {{- default (include "prestashop.serviceIP" .) $host -}} {{- else -}} {{- $host := index .Values (printf "%sHost" .Chart.Name) | default "" -}} @@ -34,7 +34,14 @@ When using Ingress, it will be set to the Ingress hostname. {{- end -}} {{/* -Return the proper Prestashop image name +Return the proper certificate image name +*/}} +{{- define "certificates.image" -}} +{{- include "common.images.image" ( dict "imageRoot" .Values.certificates.image "global" .Values.global ) -}} +{{- end -}} + +{{/* +Return the proper PrestaShop image name */}} {{- define "prestashop.image" -}} {{- include "common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) -}} @@ -47,11 +54,18 @@ Return the proper image name (for the metrics image) {{- include "common.images.image" (dict "imageRoot" .Values.metrics.image "global" .Values.global) -}} {{- end -}} +{{/* +Return the proper image name (for the init container volume-permissions image) +*/}} +{{- define "prestashop.volumePermissions.image" -}} +{{- include "common.images.image" ( dict "imageRoot" .Values.volumePermissions.image "global" .Values.global ) -}} +{{- end -}} + {{/* Return the proper Docker Image Registry Secret Names */}} {{- define "prestashop.imagePullSecrets" -}} -{{- include "common.images.pullSecrets" (dict "images" (list .Values.image .Values.metrics.image) "global" .Values.global) -}} +{{- include "common.images.pullSecrets" (dict "images" (list .Values.image .Values.metrics.image .Values.volumePermissions.image .Values.certificates.image) "global" .Values.global) -}} {{- end -}} {{/* @@ -69,9 +83,62 @@ PrestaShop credential secret name {{- end -}} {{/* -Check if there are rolling tags in the images +Return the MariaDB Hostname */}} -{{- define "prestashop.checkRollingTags" -}} -{{- include "common.warnings.rollingTag" .Values.image -}} -{{- include "common.warnings.rollingTag" .Values.metrics.image -}} +{{- define "prestashop.databaseHost" -}} +{{- if .Values.mariadb.enabled }} + {{- if eq .Values.mariadb.architecture "replication" }} + {{- printf "%s-%s" (include "prestashop.mariadb.fullname" .) "primary" | trunc 63 | trimSuffix "-" -}} + {{- else -}} + {{- printf "%s" (include "prestashop.mariadb.fullname" .) -}} + {{- end -}} +{{- else -}} + {{- printf "%s" .Values.externalDatabase.host -}} +{{- end -}} +{{- end -}} + +{{/* +Return the MariaDB Port +*/}} +{{- define "prestashop.databasePort" -}} +{{- if .Values.mariadb.enabled }} + {{- printf "3306" -}} +{{- else -}} + {{- printf "%d" (.Values.externalDatabase.port | int ) -}} +{{- end -}} +{{- end -}} + +{{/* +Return the MariaDB Database Name +*/}} +{{- define "prestashop.databaseName" -}} +{{- if .Values.mariadb.enabled }} + {{- printf "%s" .Values.mariadb.auth.database -}} +{{- else -}} + {{- printf "%s" .Values.externalDatabase.database -}} +{{- end -}} +{{- end -}} + +{{/* +Return the MariaDB User +*/}} +{{- define "prestashop.databaseUser" -}} +{{- if .Values.mariadb.enabled }} + {{- printf "%s" .Values.mariadb.auth.username -}} +{{- else -}} + {{- printf "%s" .Values.externalDatabase.user -}} +{{- end -}} +{{- end -}} + +{{/* +Return the MariaDB Secret Name +*/}} +{{- define "prestashop.databaseSecretName" -}} +{{- if .Values.mariadb.enabled }} + {{- printf "%s" (include "prestashop.mariadb.fullname" .) -}} +{{- else if .Values.externalDatabase.existingSecret -}} + {{- printf "%s" .Values.externalDatabase.existingSecret -}} +{{- else -}} + {{- printf "%s-%s" .Release.Name "externaldb" -}} +{{- end -}} {{- end -}} diff --git a/bitnami/prestashop/templates/deployment.yaml b/bitnami/prestashop/templates/deployment.yaml index 25fa683ec..6437bbfc8 100644 --- a/bitnami/prestashop/templates/deployment.yaml +++ b/bitnami/prestashop/templates/deployment.yaml @@ -27,12 +27,12 @@ spec: {{- include "common.tplvalues.render" (dict "value" .Values.podLabels "context" $) | nindent 8 }} {{- end }} annotations: - {{- if .Values.podAnnotations }} - {{- toYaml .Values.podAnnotations | nindent 8 }} - {{- end }} - {{- if .Values.metrics.podAnnotations }} - {{- toYaml .Values.metrics.podAnnotations | nindent 8 }} - {{- end }} + {{- if .Values.podAnnotations }} + {{- include "common.tplvalues.render" (dict "value" .Values.podAnnotations "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.metrics.podAnnotations }} + {{- include "common.tplvalues.render" (dict "value" .Values.metrics.podAnnotations "context" $) | nindent 8 }} + {{- end }} spec: {{- include "prestashop.imagePullSecrets" . | nindent 6 }} {{- if .Values.podSecurityContext.enabled }} @@ -40,6 +40,11 @@ spec: {{- end }} {{- if .Values.affinity }} affinity: {{- include "common.tplvalues.render" (dict "value" .Values.affinity "context" $) | nindent 8 }} + {{- else }} + affinity: + podAffinity: {{- include "common.affinities.pods" (dict "type" .Values.podAffinityPreset "context" $) | nindent 10 }} + podAntiAffinity: {{- include "common.affinities.pods" (dict "type" .Values.podAntiAffinityPreset "context" $) | nindent 10 }} + nodeAffinity: {{- include "common.affinities.nodes" (dict "type" .Values.nodeAffinityPreset.type "key" .Values.nodeAffinityPreset.key "values" .Values.nodeAffinityPreset.values) | nindent 10 }} {{- end }} {{- if .Values.nodeSelector }} nodeSelector: {{- include "common.tplvalues.render" (dict "value" .Values.nodeSelector "context" $) | nindent 8 }} @@ -51,6 +56,77 @@ spec: - ip: "127.0.0.1" hostnames: - "status.localhost" + initContainers: {{- include "common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }} + {{- if and .Values.volumePermissions.enabled .Values.persistence.enabled }} + - name: volume-permissions + image: {{ include "prestashop.volumePermissions.image" . }} + imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} + command: + - sh + - -c + - | + mkdir -p "/bitnami/prestashop" + chown -R "{{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.podSecurityContext.fsGroup }}" "/bitnami/prestashop" + securityContext: + runAsUser: 0 + {{- if .Values.volumePermissions.resources }} + resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: prestashop-data + mountPath: /bitnami/prestashop + subPath: prestashop + {{- end }} + {{- if .Values.certificates.customCAs }} + - name: certificates + image: {{ template "certificates.image" . }} + imagePullPolicy: {{ default .Values.image.pullPolicy .Values.certificates.image.pullPolicy }} + imagePullSecrets: + {{- range (default .Values.image.pullSecrets .Values.certificates.image.pullSecrets) }} + - name: {{ . }} + {{- end }} + command: + {{- if .Values.certificates.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.certificates.command "context" $) | nindent 12 }} + {{- else if .Values.certificates.customCertificate.certificateSecret }} + - sh + - -c + - if command -v apk >/dev/null; then apk add --no-cache ca-certificates openssl && update-ca-certificates; + else apt-get update && apt-get install -y ca-certificates openssl; fi + {{- else }} + - sh + - -c + - if command -v apk >/dev/null; then apk add --no-cache ca-certificates openssl && update-ca-certificates; + else apt-get update && apt-get install -y ca-certificates openssl; fi + && openssl req -new -x509 -days 3650 -nodes -sha256 + -subj "/CN=$(hostname)" -addext "subjectAltName = DNS:$(hostname)" + -out {{ .Values.certificates.customCertificate.certificateLocation }} + -keyout {{ .Values.certificates.customCertificate.keyLocation }} -extensions v3_req + {{- end }} + {{- if .Values.certificates.args }} + args: {{- include "common.tplvalues.render" (dict "value" .Values.certificates.args "context" $) | nindent 12 }} + {{- end }} + env: {{- include "common.tplvalues.render" (dict "value" .Values.certificates.extraEnvVars "context" $) | nindent 12 }} + envFrom: + {{- if .Values.certificates.extraEnvVarsCM }} + - configMapRef: + name: {{ include "common.tplvalues.render" (dict "value" .Values.certificates.extraEnvVarsCM "context" $) }} + {{- end }} + {{- if .Values.certificates.extraEnvVarsSecret }} + - secretRef: + name: {{ include "common.tplvalues.render" (dict "value" .Values.certificates.extraEnvVarsSecret "context" $) }} + {{- end }} + volumeMounts: + - name: etc-ssl-certs + mountPath: /etc/ssl/certs + readOnly: false + - name: etc-ssl-private + mountPath: /etc/ssl/private + readOnly: false + - name: custom-ca-certificates + mountPath: /usr/local/share/ca-certificates + readOnly: true + {{- end }} containers: - name: {{ include "common.names.fullname" . }} image: {{ template "prestashop.image" . }} @@ -68,7 +144,7 @@ spec: - name: BITNAMI_DEBUG value: {{ ternary "true" "false" .Values.image.debug | quote }} - name: ALLOW_EMPTY_PASSWORD - value: {{ .Values.allowEmptyPassword | quote }} + value: {{ ternary "yes" "no" .Values.allowEmptyPassword | quote }} - name: APACHE_HTTP_PORT_NUMBER value: {{ .Values.containerPorts.http | quote }} - name: APACHE_HTTPS_PORT_NUMBER @@ -85,36 +161,22 @@ spec: - name: PRESTASHOP_LANGUAGE value: {{ .Values.prestashopLanguage | quote }} {{- end }} - {{- if .Values.mariadb.enabled }} - - name: MARIADB_HOST - value: {{ template "prestashop.mariadb.fullname" . }} - - name: MARIADB_PORT_NUMBER - value: "3306" + - name: PRESTASHOP_DATABASE_HOST + value: {{ include "prestashop.databaseHost" . | quote }} + - name: PRESTASHOP_DATABASE_PORT_NUMBER + value: {{ include "prestashop.databasePort" . | quote }} - name: PRESTASHOP_DATABASE_NAME - value: {{ .Values.mariadb.db.name | quote }} + value: {{ include "prestashop.databaseName" . | quote }} - name: PRESTASHOP_DATABASE_USER - value: {{ .Values.mariadb.db.user | quote }} + value: {{ include "prestashop.databaseUser" . | quote }} - name: PRESTASHOP_DATABASE_PASSWORD valueFrom: secretKeyRef: - name: {{ template "prestashop.mariadb.fullname" . }} + name: {{ include "prestashop.databaseSecretName" . }} key: mariadb-password - {{- else }} - - name: MARIADB_HOST - value: {{ .Values.externalDatabase.host | quote }} - - name: MARIADB_PORT_NUMBER - value: {{ .Values.externalDatabase.port | quote }} - - name: PRESTASHOP_DATABASE_NAME - value: {{ .Values.externalDatabase.database | quote }} - - name: PRESTASHOP_DATABASE_USER - value: {{ .Values.externalDatabase.user | quote }} - - name: PRESTASHOP_DATABASE_PASSWORD - valueFrom: - secretKeyRef: - name: "{{ include "common.names.fullname" . }}-externaldb" - key: db-password - {{- end }} - {{- $port:=.Values.service.port | toString }} + - name: PRESTASHOP_SKIP_BOOTSTRAP + value: {{ ternary "yes" "no" .Values.prestashopSkipInstall | quote }} + {{- $port:=.Values.service.port | toString }} - name: PRESTASHOP_HOST value: "{{ include "prestashop.host" . }}{{- if ne $port "80" }}:{{ .Values.service.port }}{{ end }}" - name: PRESTASHOP_USERNAME @@ -206,7 +268,7 @@ spec: readinessProbe: {{- include "common.tplvalues.render" (dict "value" .Values.customReadinessProbe "context" $) | nindent 12 }} {{- end }} {{- if .Values.resources }} - resources: {{ toYaml .Values.resources | nindent 12 }} + resources: {{- toYaml .Values.resources | nindent 12 }} {{- end }} volumeMounts: - name: prestashop-data @@ -219,7 +281,7 @@ spec: - name: metrics image: {{ template "prestashop.metrics.image" . }} imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} - command: [ '/bin/apache_exporter', '--scrape_uri', 'http://status.localhost:80/server-status/?auto'] + command: [ '/bin/apache_exporter', '--scrape_uri', 'http://status.localhost:{{ .Values.containerPorts.http }}/server-status/?auto' ] ports: - name: metrics containerPort: 9117 @@ -235,7 +297,7 @@ spec: port: metrics initialDelaySeconds: 5 timeoutSeconds: 1 - resources: {{ toYaml .Values.metrics.resources | nindent 12 }} + resources: {{- toYaml .Values.metrics.resources | nindent 12 }} {{- end }} {{- if .Values.sidecars }} {{- include "common.tplvalues.render" (dict "value" .Values.sidecars "context" $) | nindent 8 }} @@ -244,11 +306,11 @@ spec: - name: prestashop-data {{- if .Values.persistence.enabled }} persistentVolumeClaim: - claimName: {{ if .Values.persistence.existingClaim }}{{ .Values.persistence.existingClaim }}{{- else }}{{ include "common.names.fullname" . }}-prestashop{{- end }} + claimName: {{ .Values.persistence.existingClaim | default (printf "%s-prestashop" (include "common.names.fullname" .)) }} {{- else }} emptyDir: {} {{- end }} - {{- if .Values.extraVolumes }} - {{- include "common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }} - {{- end }} + {{- if .Values.extraVolumes }} + {{- include "common.tplvalues.render" (dict "value" .Values.extraVolumes "context" $) | nindent 8 }} + {{- end }} {{- end -}} diff --git a/bitnami/prestashop/templates/ingress.yaml b/bitnami/prestashop/templates/ingress.yaml index 3b5518fce..33a440c8a 100644 --- a/bitnami/prestashop/templates/ingress.yaml +++ b/bitnami/prestashop/templates/ingress.yaml @@ -14,28 +14,30 @@ metadata: {{- if .Values.commonAnnotations }} {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} {{- end }} - {{- if .certManager }} + {{- if .Values.ingress.certManager }} kubernetes.io/tls-acme: "true" {{- end }} spec: rules: - - host: {{ .Values.ingress.hostname }} - http: - paths: - - path: {{ default "/" .path }} - backend: - serviceName: "{{ include "common.names.fullname" $ }}" - servicePort: http - {{- range .Values.ingress.hosts }} - - host: {{ .name }} - http: - paths: - - path: {{ default "/" .path }} - backend: - serviceName: "{{ include "common.names.fullname" $ }}" - servicePort: http - {{- end }} - {{- if .tls }} + {{- if .Values.ingress.hostname }} + - host: {{ .Values.ingress.hostname }} + http: + paths: + - path: / + backend: + serviceName: "{{ include "common.names.fullname" $ }}" + servicePort: http + {{- end }} + {{- range .Values.ingress.hosts }} + - host: {{ .name }} + http: + paths: + - path: {{ default "/" .path }} + backend: + serviceName: "{{ include "common.names.fullname" $ }}" + servicePort: http + {{- end }} + {{- if .Values.ingress.tls }} tls: {{- toYaml .Values.ingress.tls | nindent 4 }} {{- end }} {{- end }} diff --git a/bitnami/prestashop/templates/pvc.yaml b/bitnami/prestashop/templates/pvc.yaml index 23bd99451..1052939a8 100644 --- a/bitnami/prestashop/templates/pvc.yaml +++ b/bitnami/prestashop/templates/pvc.yaml @@ -1,4 +1,4 @@ -{{- if .Values.persistence.enabled -}} +{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) -}} kind: PersistentVolumeClaim apiVersion: v1 metadata: diff --git a/bitnami/prestashop/templates/svc.yaml b/bitnami/prestashop/templates/svc.yaml index a2dd90be4..a680ddf16 100644 --- a/bitnami/prestashop/templates/svc.yaml +++ b/bitnami/prestashop/templates/svc.yaml @@ -11,23 +11,34 @@ metadata: {{- end }} spec: type: {{ .Values.service.type }} - {{- if (and (eq .Values.service.type "LoadBalancer") (not (empty .Values.service.loadBalancerIP))) }} + sessionAffinity: {{ default "None" .Values.service.sessionAffinity }} + {{- if and .Values.service.clusterIP (eq .Values.service.type "ClusterIP") }} + clusterIP: {{ .Values.service.clusterIP }} + {{- end }} + {{- if and .Values.service.loadBalancerIP (eq .Values.service.type "LoadBalancer") }} loadBalancerIP: {{ .Values.service.loadBalancerIP }} {{- end }} - {{- if (or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort")) }} + {{- if and (eq .Values.service.type "LoadBalancer") .Values.service.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.service.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + {{- if or (eq .Values.service.type "LoadBalancer") (eq .Values.service.type "NodePort") }} externalTrafficPolicy: {{ .Values.service.externalTrafficPolicy | quote }} {{- end }} ports: - name: http port: {{ .Values.service.port }} targetPort: http - {{- if (and (eq .Values.service.type "NodePort") (not (empty .Values.service.nodePorts.http)))}} + {{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.http)) }} nodePort: {{ .Values.service.nodePorts.http }} + {{- else if eq .Values.service.type "ClusterIP" }} + nodePort: null {{- end }} - name: https port: {{ .Values.service.httpsPort }} targetPort: https - {{- if (and (eq .Values.service.type "NodePort") (not (empty .Values.service.nodePorts.https)))}} + {{- if and (or (eq .Values.service.type "NodePort") (eq .Values.service.type "LoadBalancer")) (not (empty .Values.service.nodePorts.https)) }} nodePort: {{ .Values.service.nodePorts.https }} + {{- else if eq .Values.service.type "ClusterIP" }} + nodePort: null {{- end }} selector: {{- include "common.labels.matchLabels" . | nindent 4 }} diff --git a/bitnami/prestashop/values.yaml b/bitnami/prestashop/values.yaml index eaf72cd98..e098c9b8b 100644 --- a/bitnami/prestashop/values.yaml +++ b/bitnami/prestashop/values.yaml @@ -14,7 +14,7 @@ image: registry: docker.io repository: bitnami/prestashop - tag: 1.7.6-8-debian-10-r4 + tag: 1.7.6-8-debian-10-r15 ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images @@ -27,7 +27,7 @@ image: pullSecrets: # - myRegistryKeySecretName ## Set to true if you would like to see extra information on logs - ## ref: https://github.com/bitnami/minideb-extras/#turn-on-bash-debugging + ## ref: https://github.com/bitnami/minideb-extras/#turn-on-bash-debugging ## debug: false @@ -43,6 +43,11 @@ fullnameOverride: ## replicaCount: 1 +## Skip PrestaShop installation wizard. Useful for migrations and restoring from SQL dump +## ref: https://github.com/bitnami/bitnami-docker-prestashop#configuration +## +prestashopSkipInstall: false + ## PrestaShop host to create application URLs ## ref: https://github.com/bitnami/bitnami-docker-prestashop#configuration ## @@ -92,7 +97,7 @@ prestashopLanguage: "en" ## Set to `yes` to allow the container to be started with blank passwords ## ref: https://github.com/bitnami/bitnami-docker-prestashop#environment-variables ## -allowEmptyPassword: "yes" +allowEmptyPassword: true ## Container command (using container default if not set) ## @@ -199,38 +204,30 @@ mariadb: ## Whether to deploy a mariadb server to satisfy the applications database requirements. To use an external database set this to false and configure the externalDatabase parameters ## enabled: true - ## Tag for the Bitnami MariaDB image to use - ## ref: https://github.com/bitnami/bitnami-docker-mariadb - ## - image: - registry: docker.io - repository: bitnami/mariadb - tag: 10.1.46-debian-10-r47 - ## Disable MariaDB replication - ## - replication: - enabled: false - ## Create a database and a database user - ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run + ## MariaDB architecture. Allowed values: standalone or replication ## - db: - name: bitnami_prestashop - user: bn_prestashop - ## If the password is not specified, mariadb will generate a random password + architecture: standalone + + ## MariaDB Authentication parameters + ## + auth: + ## MariaDB root password + ## ref: https://github.com/bitnami/bitnami-docker-mariadb#setting-the-root-password-on-first-run ## + rootPassword: "" + ## MariaDB custom user and database + ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-on-first-run + ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run + ## + database: bitnami_prestashop + username: bn_prestashop password: "" - ## MariaDB admin password - ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#setting-the-root-password-on-first-run - ## - rootUser: - password: "" - - ## Enable persistence using Persistent Volume Claims - ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ - ## - master: + primary: + ## Enable persistence using Persistent Volume Claims + ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ + ## persistence: enabled: true ## mariadb data Persistent Volume Storage Class @@ -241,7 +238,7 @@ mariadb: ## GKE, AWS & OpenStack) ## storageClass: - accessMode: + accessModes: - ReadWriteOnce size: 8Gi ## Set path in case you want to use local host path volumes (not recommended in production) @@ -266,9 +263,13 @@ service: port: 80 # HTTPS Port httpsPort: 443 + ## clusterIP: "" + ## Control hosts connecting to "LoadBalancer" only + ## loadBalancerSourceRanges: + ## - 0.0.0.0/0 ## loadBalancerIP for the PrestaShop Service (optional, cloud specific) ## ref: http://kubernetes.io/docs/user-guide/services/#type-loadbalancer - ## loadBalancerIP + ## loadBalancerIP: ## ## nodePorts: ## http: @@ -279,7 +280,7 @@ service: ## Enable client source IP preservation ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip ## - externalTrafficPolicy: Local + externalTrafficPolicy: Cluster ## Configure the ingress resource that allows you to access the ## PrestaShop installation. Set up the URL @@ -350,7 +351,7 @@ sessionAffinity: "None" ## persistence: enabled: true - ## Prestashop Data Persistent Volume Storage Class + ## PrestaShop Data Persistent Volume Storage Class ## If defined, storageClassName: ## If set to "-", storageClassName: "", which disables dynamic provisioning ## If undefined (the default) or set to null, no storageClassName spec is @@ -372,15 +373,50 @@ persistence: ## # existingClaim: - ## If defined, the drupal-data volume will mount to the specified hostPath. + ## If defined, the prestashop-data volume will mount to the specified hostPath. ## Requires persistence.enabled: true ## Requires persistence.existingClaim: nil|false ## Default: nil. ## hostPath: +## Pod affinity preset +## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity +## Allowed values: soft, hard +## +podAffinityPreset: "" + +## Pod anti-affinity preset +## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity +## Allowed values: soft, hard +## +podAntiAffinityPreset: soft + +## Node affinity preset +## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity +## Allowed values: soft, hard +## +nodeAffinityPreset: + ## Node affinity type + ## Allowed values: soft, hard + ## + type: "" + ## Node label key to match + ## E.g. + ## key: "kubernetes.io/e2e-az-name" + ## + key: "" + ## Node label values to match + ## E.g. + ## values: + ## - e2e-az1 + ## - e2e-az2 + ## + values: [] + ## Affinity for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity +## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set ## affinity: {} @@ -397,6 +433,40 @@ resources: memory: 512Mi cpu: 300m +## Init containers parameters: +## volumePermissions: Change the owner and group of the persistent volume mountpoint to runAsUser:fsGroup values from the securityContext section. +## +volumePermissions: + enabled: false + image: + registry: docker.io + repository: bitnami/minideb + tag: buster + pullPolicy: Always + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## + pullSecrets: [] + ## - myRegistryKeySecretName + ## Init containers' resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## + resources: + ## We usually recommend not to specify default resources and to leave this as a conscious + ## choice for the user. This also increases chances charts run on environments with little + ## resources, such as Minikube. If you do want to specify resources, uncomment the following + ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. + ## + limits: {} + ## cpu: 100m + ## memory: 128Mi + ## + requests: {} + ## cpu: 100m + ## memory: 128Mi + ## + ## Configure Pods Security Context ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod ## @@ -412,7 +482,7 @@ containerSecurityContext: runAsUser: 1001 ## Configure extra options for liveness and readiness probes -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes livenessProbe: enabled: true path: /login @@ -459,7 +529,7 @@ metrics: image: registry: docker.io repository: bitnami/apache-exporter - tag: 0.8.0-debian-10-r167 + tag: 0.8.0-debian-10-r178 pullPolicy: IfNotPresent ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. @@ -477,6 +547,50 @@ metrics: prometheus.io/scrape: "true" prometheus.io/port: "9117" +# Add custom certificates and certificate authorities to PrestaShop container +certificates: + customCertificate: + certificateSecret: "" + chainSecret: {} + # name: secret-name + # key: secret-key + certificateLocation: /etc/ssl/certs/ssl-cert-snakeoil.pem + keyLocation: /etc/ssl/private/ssl-cert-snakeoil.key + chainLocation: /etc/ssl/certs/mychain.pem + customCAs: [] + ## Override container command + ## + command: + ## Override container args + ## + args: + # - secret: custom-CA + # - secret: more-custom-CAs + ## An array to add extra env vars + ## + extraEnvVars: [] + + ## ConfigMap with extra environment variables + ## + extraEnvVarsCM: + + ## Secret with extra environment variables + ## + extraEnvVarsSecret: + + image: + registry: docker.io + repository: bitnami/minideb + tag: buster + ## Specify a imagePullPolicy + ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' + ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images + ## + pullPolicy: IfNotPresent + # pullPolicy: + pullSecrets: [] + # - myRegistryKeySecretName + ## Array with extra yaml to deploy with the chart. Evaluated as a template ## extraDeploy: []