Replace overlay containers (#249)

* move jackett to k8s-container

* move sonarr to k8s container

* move radarr to k8s container

* move qbittorrent to k8s container

* move tautulli to k8s container

* move sabnzbd to k8s container

* nzbget

* lidarr

* bazarr

* nzbhydra

* jellyfin

* cleanup gpu mounting on common

* update common

* add gpu selector to jellyfin

* add GPU selector to Emby

* enable securityContext.runAsNonRoot
This commit is contained in:
Kjeld Schouten-Lebbing
2021-03-08 22:29:17 +01:00
committed by kjeld Schouten-Lebbing
parent e6204cdd6f
commit 34762190a3
63 changed files with 70 additions and 95 deletions

View File

@@ -42,12 +42,14 @@ class Test < ChartTest
it 'defaults to false = runAs 568' do
jq('.spec.template.spec.securityContext.runAsUser', resource('Deployment')).must_equal 568
jq('.spec.template.spec.securityContext.runAsGroup', resource('Deployment')).must_equal 568
jq('.spec.template.spec.securityContext.runAsNonRoot', resource('Deployment')).must_equal true
end
it 'can be enabled = runAs nil' do
chart.value startAsRoot: true
jq('.spec.template.spec.securityContext.runAsUser', resource('Deployment')).must_equal nil
jq('.spec.template.spec.securityContext.runAsGroup', resource('Deployment')).must_equal nil
jq('.spec.template.spec.securityContext.runAsNonRoot', resource('Deployment')).must_equal nil
end
end

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/bazarr
repository: ghcr.io/k8s-at-home/bazarr
pullPolicy: IfNotPresent
tag: version-v0.9.0.5
startAsRoot: true
tag: v0.9.3-beta.6
##
# Most other defaults are set in questions.yaml

View File

@@ -1,15 +1,13 @@
# Default values for Bazarr.
image:
repository: linuxserver/bazarr
repository: ghcr.io/k8s-at-home/bazarr
pullPolicy: IfNotPresent
tag: version-v0.9.0.5
tag: v0.9.3-beta.6
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -357,6 +357,16 @@ questions:
type: hostpath
required: true
# Specify GPU configuration
- variable: gpuConfiguration
label: "GPU Configuration"
group: "Storage and Devices"
schema:
type: dict
$ref:
- "definitions/gpuConfiguration"
attrs: []
- variable: ingress
label: ""
group: "Reverse Proxy Configuration"

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/jackett
repository: ghcr.io/k8s-at-home/jackett
pullPolicy: IfNotPresent
tag: version-v0.17.153
startAsRoot: true
tag: v0.17.656
##
# Most other defaults are set in questions.yaml

View File

@@ -1,15 +1,13 @@
# Default values for Jackett.
image:
repository: linuxserver/jackett
repository: ghcr.io/k8s-at-home/jackett
pullPolicy: IfNotPresent
tag: version-v0.16.2106
tag: v0.17.656
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/jellyfin
repository: jellyfin/jellyfin
pullPolicy: IfNotPresent
tag: version-10.6.4-1
startAsRoot: true
tag: 10.6.4
##
# Most other defaults are set in questions.yaml

View File

@@ -357,6 +357,16 @@ questions:
type: hostpath
required: true
# Specify GPU configuration
- variable: gpuConfiguration
label: "GPU Configuration"
group: "Storage and Devices"
schema:
type: dict
$ref:
- "definitions/gpuConfiguration"
attrs: []
- variable: ingress
label: ""
group: "Reverse Proxy Configuration"

View File

@@ -2,15 +2,13 @@
# Default values for jellyfin.
image:
repository: linuxserver/jellyfin
repository: jellyfin/jellyfin
pullPolicy: IfNotPresent
tag: version-10.6.4-1
tag: 10.6.4
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,12 +5,10 @@
##
image:
repository: linuxserver/lidarr
repository: ghcr.io/k8s-at-home/lidarr
pullPolicy: IfNotPresent
tag: version-0.8.0.1886
startAsRoot: true
probes:
liveness:
enabled: true

View File

@@ -1,15 +1,13 @@
# Default values for Lidarr.
image:
repository: linuxserver/lidarr
repository: ghcr.io/k8s-at-home/lidarr
pullPolicy: IfNotPresent
tag: version-0.8.0.1886
tag: v0.8.0.2082
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/nzbget
repository: ghcr.io/k8s-at-home/nzbget
pullPolicy: IfNotPresent
tag: version-v21.0
startAsRoot: true
tag: v21.0
##
# Most other defaults are set in questions.yaml

View File

@@ -1,15 +1,13 @@
# Default values for nzbget.
image:
repository: linuxserver/nzbget
repository: ghcr.io/k8s-at-home/nzbget
pullPolicy: IfNotPresent
tag: version-v21.0
tag: v21.0
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/nzbhydra2
repository: ghcr.io/k8s-at-home/nzbhydra2
pullPolicy: IfNotPresent
tag: version-v3.8.1
startAsRoot: true
tag: v3.13.0
probes:
liveness:

View File

@@ -1,15 +1,13 @@
# Default values for nzbhydra.
image:
repository: linuxserver/nzbhydra2
repository: ghcr.io/k8s-at-home/nzbhydra2
pullPolicy: IfNotPresent
tag: version-v3.8.1
tag: v3.13.0
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -7,7 +7,7 @@ version: 1.6.4
version: 2.0.0
>>>>>>> [Common] Refactor Services (#212):charts/qbittorrent/2.0.0/Chart.yaml
upstream_version: 7.2.1
appVersion: "latest"
appVersion: "auto"
description: qBittorrent is a cross-platform free and open-source BitTorrent client
type: application
deprecated: false

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/qbittorrent
repository: ghcr.io/k8s-at-home/qbittorrent
pullPolicy: IfNotPresent
tag: latest
startAsRoot: true
tag: v4.3.3
##
# Most other defaults are set in questions.yaml

View File

@@ -1,15 +1,13 @@
# Default values for qbittorrent.
image:
repository: linuxserver/qbittorrent
repository: ghcr.io/k8s-at-home/qbittorrent
pullPolicy: IfNotPresent
tag: latest
tag: v4.3.3
strategy:
type: Recreate
startAsRoot: true
env: {}
# TZ: UTC
# PUID: 1001

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/radarr
repository: ghcr.io/k8s-at-home/radarr
pullPolicy: IfNotPresent
tag: version-3.0.0.3989
startAsRoot: true
tag: v3.0.2.4552
probes:
liveness:

View File

@@ -1,15 +1,13 @@
# Default values for Radarr.
image:
repository: linuxserver/radarr
repository: ghcr.io/k8s-at-home/radarr
pullPolicy: IfNotPresent
tag: version-3.0.0.3989
tag: v3.0.2.4552
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/sabnzbd
repository: ghcr.io/k8s-at-home/sabnzbd
pullPolicy: IfNotPresent
tag: version-3.1.0
startAsRoot: true
tag: v3.2.0
##
# Most other defaults are set in questions.yaml

View File

@@ -1,15 +1,13 @@
# Default values for Sabnzbd.
image:
repository: linuxserver/sabnzbd
repository: ghcr.io/k8s-at-home/sabnzbd
pullPolicy: IfNotPresent
tag: version-3.1.0
tag: v3.2.0
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,11 +5,9 @@
##
image:
repository: linuxserver/sonarr
repository: ghcr.io/k8s-at-home/sonarr
pullPolicy: IfNotPresent
tag: version-3.0.4.993
startAsRoot: true
tag: v3.0.5.1143
probes:
liveness:

View File

@@ -1,15 +1,13 @@
# Default values for Sonarr.
image:
repository: linuxserver/sonarr
repository: ghcr.io/k8s-at-home/sonarr
pullPolicy: IfNotPresent
tag: version-3.0.4.993
tag: v3.0.5.1143
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -5,11 +5,9 @@
##
image:
repository: tautulli/tautulli
repository: ghcr.io/k8s-at-home/tautulli
pullPolicy: IfNotPresent
tag: v2.6.6
startAsRoot: true
tag: v2.6.7
##
# Most other defaults are set in questions.yaml

View File

@@ -1,15 +1,13 @@
# Default values for Tautulli.
image:
repository: tautulli/tautulli
repository: ghcr.io/k8s-at-home/tautulli
pullPolicy: IfNotPresent
tag: v2.6.6
tag: v2.6.7
strategy:
type: Recreate
startAsRoot: true
services:
main:
port:

View File

@@ -98,16 +98,12 @@ The main container included in the controller.
{{- end }}
{{- end }}
{{- include "common.controller.probes" . | nindent 2 }}
{{- with .Values.resources }}
resources:
{{- with .Values.resources }}
{{- toYaml . | nindent 4 }}
{{- end }}
{{- if and .Values.gpuConfiguration .Values.resources }}
{{- if and .Values.gpuConfiguration }}
limits:
{{- toYaml .Values.gpuConfiguration | nindent 14 }}
{{- else if .Values.gpuConfiguration }}
resources:
limits:
{{- toYaml .Values.gpuConfiguration | nindent 14 }}
{{- toYaml .Values.gpuConfiguration | nindent 6 }}
{{- end }}
{{- end -}}

View File

@@ -30,6 +30,7 @@ securityContext:
{{- if not .Values.startAsRoot }}
runAsUser: {{ .Values.PUID }}
runAsGroup: {{ .Values.PGID }}
runAsNonRoot: true
{{- end }}
{{- with .Values.podSecurityContext }}
{{- toYaml . | nindent 2 }}