add flame to community applications (#1578)

* add `flame` to `community` applications

* fix secCtx

* mroe perms

* add ui

* remove extra word
This commit is contained in:
Stavros Kois
2023-09-28 18:14:32 +03:00
committed by GitHub
parent d38b8b79ec
commit 1910172b63
21 changed files with 502 additions and 0 deletions

View File

@@ -0,0 +1,6 @@
dependencies:
- name: common
repository: file://../../../common
version: 1.1.1
digest: sha256:a7dbe3e4d42dbcd4325776e5e01a1d630c7f185f79e7ebf22b1b9cc80f56eed7
generated: "2023-09-26T17:46:33.418912325+03:00"

View File

@@ -0,0 +1,25 @@
name: flame
description: Flame is a self-hosted start page for your server.
annotations:
title: Flame
type: application
version: 1.0.0
apiVersion: v2
appVersion: 2.3.1
kubeVersion: '>=1.16.0-0'
maintainers:
- name: truenas
url: https://www.truenas.com/
email: dev@ixsystems.com
dependencies:
- name: common
repository: file://../../../common
version: 1.1.1
home: https://github.com/pawelmalak/flame
icon: https://raw.githubusercontent.com/pawelmalak/flame/master/client/public/icons/favicon.ico
sources:
- https://hub.docker.com/r/pawelmalak/flame
- https://github.com/truenas/charts/tree/master/library/ix-dev/community/flame
- https://github.com/pawelmalak/flame
keywords:
- startpage

View File

@@ -0,0 +1,3 @@
# Flame
[Flame](https://github.com/pawelmalak/flame) is a self-hosted start page for your server.

View File

@@ -0,0 +1,3 @@
# Flame
[Flame](https://github.com/pawelmalak/flame) is a self-hosted start page for your server.

Binary file not shown.

View File

@@ -0,0 +1,10 @@
flameConfig:
password: password
flameNetwork:
webPort: 31000
flameStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/data

View File

@@ -0,0 +1,17 @@
flameConfig:
password: password
flameNetwork:
webPort: 31000
flameStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/data
additionalStorages:
- type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/data1
mountPath: /data1
- type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/data2
mountPath: /data2

View File

@@ -0,0 +1,11 @@
flameConfig:
password: password
flameNetwork:
webPort: 30000
hostNetwork: true
flameStorage:
data:
type: hostPath
hostPath: /mnt/{{ .Release.Namespace }}/data

View File

@@ -0,0 +1,7 @@
icon_url: https://raw.githubusercontent.com/pawelmalak/flame/master/client/public/icons/favicon.ico
categories:
- productivity
screenshots:
- https://github.com/pawelmalak/flame/raw/master/.github/home.png
tags:
- startpage

View File

@@ -0,0 +1,14 @@
runAsContext:
- userName: root
groupName: root
gid: 0
uid: 0
description: Flame runs as a root user.
capabilities:
- name: CHOWN
description: Flame is able to chown files.
- name: FOWNER
description: Flame is able to bypass permission checks.
- name: DAC_OVERRIDE
description: Flame is able to bypass permission checks.
hostMounts: []

View File

@@ -0,0 +1,218 @@
groups:
- name: Flame Configuration
description: Configure Flame
- name: User and Group Configuration
description: Configure User and Group for Flame
- name: Network Configuration
description: Configure Network for Flame
- name: Storage Configuration
description: Configure Storage for Flame
- name: Resources Configuration
description: Configure Resources for Flame
portals:
web_portal:
protocols:
- "$kubernetes-resource_configmap_portal_protocol"
host:
- "$kubernetes-resource_configmap_portal_host"
ports:
- "$kubernetes-resource_configmap_portal_port"
path: "$kubernetes-resource_configmap_portal_path"
questions:
- variable: flameConfig
label: ""
group: Flame Configuration
schema:
type: dict
attrs:
- variable: password
label: Password
description: The password to use for Flame.
schema:
type: string
default: ""
private: true
required: true
- variable: additionalEnvs
label: Additional Environment Variables
description: Configure additional environment variables for Flame.
schema:
type: list
default: []
items:
- variable: env
label: Environment Variable
schema:
type: dict
attrs:
- variable: name
label: Name
schema:
type: string
required: true
- variable: value
label: Value
schema:
type: string
required: true
- variable: flameNetwork
label: ""
group: Network Configuration
schema:
type: dict
attrs:
- variable: webPort
label: Web Port
description: The port for the Flame Web UI.
schema:
type: int
default: 30082
min: 9000
max: 65535
required: true
- variable: hostNetwork
label: Host Network
description: |
Bind to the host network. It's recommended to keep this disabled.</br>
schema:
type: boolean
default: false
- variable: flameStorage
label: ""
group: Storage Configuration
schema:
type: dict
attrs:
- variable: data
label: Flame Data Storage
description: The path to store Flame Data.
schema:
type: dict
attrs:
- variable: type
label: Type
description: |
ixVolume: Is dataset created automatically by the system.</br>
Host Path: Is a path that already exists on the system.
schema:
type: string
required: true
default: "ixVolume"
enum:
- value: "hostPath"
description: Host Path (Path that already exists on the system)
- value: "ixVolume"
description: ixVolume (Dataset created automatically by the system)
- variable: datasetName
label: Dataset Name
schema:
type: string
show_if: [["type", "=", "ixVolume"]]
required: true
hidden: true
immutable: true
default: "data"
$ref:
- "normalize/ixVolume"
- variable: hostPath
label: Host Path
schema:
type: hostpath
show_if: [["type", "=", "hostPath"]]
immutable: true
required: true
- variable: additionalStorages
label: Additional Storage
description: Additional storage for Flame.
schema:
type: list
default: []
items:
- variable: storageEntry
label: Storage Entry
schema:
type: dict
attrs:
- variable: type
label: Type
description: |
ixVolume: Is dataset created automatically by the system.</br>
Host Path: Is a path that already exists on the system.
schema:
type: string
required: true
default: "ixVolume"
enum:
- value: "hostPath"
description: Host Path (Path that already exists on the system)
- value: "ixVolume"
description: ixVolume (Dataset created automatically by the system)
- variable: mountPath
label: Mount Path
description: The path inside the container to mount the storage.
schema:
type: path
required: true
- variable: hostPath
label: Host Path
description: The host path to use for storage.
schema:
type: hostpath
show_if: [["type", "=", "hostPath"]]
required: true
- variable: datasetName
label: Dataset Name
description: The name of the dataset to use for storage.
schema:
type: string
show_if: [["type", "=", "ixVolume"]]
required: true
immutable: true
default: "storage_entry"
$ref:
- "normalize/ixVolume"
- variable: resources
group: Resources Configuration
label: ""
schema:
type: dict
attrs:
- variable: limits
label: Limits
schema:
type: dict
attrs:
- variable: cpu
label: CPU
description: CPU limit for Flame.
schema:
type: string
max_length: 6
valid_chars: '^(0\.[1-9]|[1-9][0-9]*)(\.[0-9]|m?)$'
valid_chars_error: |
Valid CPU limit formats are</br>
- Plain Integer - eg. 1</br>
- Float - eg. 0.5</br>
- Milicpu - eg. 500m
default: "4000m"
required: true
- variable: memory
label: Memory
description: Memory limit for Flame.
schema:
type: string
max_length: 12
valid_chars: '^[1-9][0-9]*([EPTGMK]i?|e[0-9]+)?$'
valid_chars_error: |
Valid Memory limit formats are</br>
- Suffixed with E/P/T/G/M/K - eg. 1G</br>
- Suffixed with Ei/Pi/Ti/Gi/Mi/Ki - eg. 1Gi</br>
- Plain Integer in bytes - eg. 1024</br>
- Exponent - eg. 134e6
default: "8Gi"
required: true

View File

@@ -0,0 +1 @@
{{ include "ix.v1.common.lib.chart.notes" $ }}

View File

@@ -0,0 +1,8 @@
{{- define "flame.configuration" -}}
secret:
flame-config:
enabled: true
data:
PORT: {{ .Values.flameNetwork.webPort | quote }}
PASSWORD: {{ .Values.flameConfig.password | quote }}
{{- end -}}

View File

@@ -0,0 +1,51 @@
{{- define "flame.workload" -}}
workload:
flame:
enabled: true
primary: true
type: Deployment
podSpec:
hostNetwork: {{ .Values.flameNetwork.hostNetwork }}
containers:
flame:
enabled: true
primary: true
imageSelector: image
securityContext:
# FIXME: https://github.com/pawelmalak/flame/pull/356
runAsUser: 0
runAsGroup: 0
runAsNonRoot: false
readOnlyRootFilesystem: false
capabilities:
add:
- CHOWN
- DAC_OVERRIDE
- FOWNER
envFrom:
- secretRef:
name: flame-config
{{ with .Values.flameConfig.additionalEnvs }}
envList:
{{ range $env := . }}
- name: {{ $env.name }}
value: {{ $env.value }}
{{ end }}
{{ end }}
probes:
liveness:
enabled: true
type: http
port: {{ .Values.flameNetwork.webPort }}
path: /
readiness:
enabled: true
type: http
port: {{ .Values.flameNetwork.webPort }}
path: /
startup:
enabled: true
type: http
port: {{ .Values.flameNetwork.webPort }}
path: /
{{- end -}}

View File

@@ -0,0 +1,34 @@
{{- define "flame.persistence" -}}
persistence:
data:
enabled: true
type: {{ .Values.flameStorage.data.type }}
datasetName: {{ .Values.flameStorage.data.datasetName | default "" }}
hostPath: {{ .Values.flameStorage.data.hostPath | default "" }}
targetSelector:
flame:
flame:
mountPath: /app/data
01-permissions:
mountPath: /mnt/directories/data
tmp:
enabled: true
type: emptyDir
targetSelector:
flame:
flame:
mountPath: /tmp
{{- range $idx, $storage := .Values.flameStorage.additionalStorages }}
{{ printf "flame-%v" (int $idx) }}:
enabled: true
type: {{ $storage.type }}
datasetName: {{ $storage.datasetName | default "" }}
hostPath: {{ $storage.hostPath | default "" }}
targetSelector:
flame:
flame:
mountPath: {{ $storage.mountPath }}
01-permissions:
mountPath: /mnt/directories{{ $storage.mountPath }}
{{- end }}
{{- end -}}

View File

@@ -0,0 +1,12 @@
{{- define "flame.portal" -}}
---
apiVersion: v1
kind: ConfigMap
metadata:
name: portal
data:
path: "/"
port: {{ .Values.flameNetwork.webPort | quote }}
protocol: http
host: $node_ip
{{- end -}}

View File

@@ -0,0 +1,15 @@
{{- define "flame.service" -}}
service:
flame:
enabled: true
primary: true
type: NodePort
targetSelector: flame
ports:
webui:
enabled: true
primary: true
port: {{ .Values.flameNetwork.webPort }}
nodePort: {{ .Values.flameNetwork.webPort }}
targetSelector: flame
{{- end -}}

View File

@@ -0,0 +1,12 @@
{{- include "ix.v1.common.loader.init" . -}}
{{/* Merge the templates with Values */}}
{{- $_ := mustMergeOverwrite .Values (include "flame.configuration" $ | fromYaml) -}}
{{- $_ := mustMergeOverwrite .Values (include "flame.service" $ | fromYaml) -}}
{{- $_ := mustMergeOverwrite .Values (include "flame.persistence" $ | fromYaml) -}}
{{- $_ := mustMergeOverwrite .Values (include "flame.workload" $ | fromYaml) -}}
{{/* Create the configmap for portal manually*/}}
{{- include "flame.portal" $ -}}
{{- include "ix.v1.common.loader.apply" . -}}

View File

@@ -0,0 +1 @@
{"filename": "values.yaml", "keys": ["image"]}

View File

@@ -0,0 +1,31 @@
#!/usr/bin/python3
import json
import re
import sys
from catalog_update.upgrade_strategy import semantic_versioning
RE_STABLE_VERSION = re.compile(r'\d+\.\d+\.\d+')
def newer_mapping(image_tags):
key = list(image_tags.keys())[0]
tags = {t: t for t in image_tags[key] if RE_STABLE_VERSION.fullmatch(t)}
version = semantic_versioning(list(tags))
if not version:
return {}
return {
'tags': {key: tags[version]},
'app_version': version,
}
if __name__ == '__main__':
try:
versions_json = json.loads(sys.stdin.read())
except ValueError:
raise ValueError('Invalid json specified')
print(json.dumps(newer_mapping(versions_json)))

View File

@@ -0,0 +1,23 @@
image:
repository: pawelmalak/flame
pullPolicy: IfNotPresent
tag: 2.3.1
resources:
limits:
cpu: 4000m
memory: 8Gi
flameConfig:
password: ''
additionalEnvs: []
flameNetwork:
webPort: 30082
hostNetwork: false
flameStorage:
data:
type: ixVolume
datasetName: data
additionalStorages: []