From 9a8b1eb01aed3cf2e710431fbdec59479030c798 Mon Sep 17 00:00:00 2001 From: GeorgeRaven Date: Wed, 27 Dec 2023 00:09:06 +0000 Subject: [PATCH] Added foundry to charts --- charts/foundryvtt/.helmignore | 23 ++++++ charts/foundryvtt/Chart.yaml | 29 ++++++++ .../templates/foundryvtt.sealed.yaml | 18 +++++ charts/foundryvtt/values.yaml | 53 ++++++++++++++ .../infrastructure/templates/foundryvtt.yaml | 71 +++++++++++++++++++ 5 files changed, 194 insertions(+) create mode 100644 charts/foundryvtt/.helmignore create mode 100644 charts/foundryvtt/Chart.yaml create mode 100644 charts/foundryvtt/templates/foundryvtt.sealed.yaml create mode 100644 charts/foundryvtt/values.yaml create mode 100644 charts/infrastructure/templates/foundryvtt.yaml diff --git a/charts/foundryvtt/.helmignore b/charts/foundryvtt/.helmignore new file mode 100644 index 00000000..0e8a0eb3 --- /dev/null +++ b/charts/foundryvtt/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/foundryvtt/Chart.yaml b/charts/foundryvtt/Chart.yaml new file mode 100644 index 00000000..7b8950ab --- /dev/null +++ b/charts/foundryvtt/Chart.yaml @@ -0,0 +1,29 @@ +apiVersion: v2 +name: foundryvtt +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "11.315.0" + +dependencies: +- name: foundryvtt + version: 0.1.0 + repository: "https://gitlab.com/api/v4/projects/53366175/packages/helm/stable" diff --git a/charts/foundryvtt/templates/foundryvtt.sealed.yaml b/charts/foundryvtt/templates/foundryvtt.sealed.yaml new file mode 100644 index 00000000..e7850178 --- /dev/null +++ b/charts/foundryvtt/templates/foundryvtt.sealed.yaml @@ -0,0 +1,18 @@ +--- +apiVersion: bitnami.com/v1alpha1 +kind: SealedSecret +metadata: + creationTimestamp: null + name: foundryvtt + namespace: foundryvtt +spec: + encryptedData: + adminPassword: AgBAhSAHn05HXBz5Kwt2FG6dsoO9nC8QNjZxp7GoC2NvXbBpKZyLs0EwT7hk+bnzLFWKDG5FJ60gCO0mHNSDkLM+pujFh9qNix/TmDXPFT1BIroJYcxFom1UHV2RcMhBhAvEBVyoK/a734ZYeie/Z+j1+IFgt+xfDS1D+xTaoXkq8xpp8KgE/+v5eGkZ539bkjGSyYJzrmZm9ZKMVqGLSJJfLCBKZehvBliwP3e5slzgD1rA1LTIHFegYxIQHsvx/G1Xjs839I6l8mBHE6Bdr2YohgvSXSU/21GQbR+1+czeV9/dZJZiD98KOlyY1M+TITxSCzJ9iB/14ppUFQ7MFxZW+PPY+ZsuLw3JZH8wHFlkz+77I/nJQ2X97nHAXY6WNUuDOd2+v+xhtEdMQNicO55dLF/KID2tj3gNLlm7oedWWcohA/DEbuNU7FBGJ3OWWf7Y0j3oboVNC5xuCVDUj0EclzGLe0HXOEv36JAgedrbQS/rUS1t5LAyL8yBtIFOfONP/UyzAI9jVadm0FHZKadC7WVDMdRhhtFpdttN81XYtvTLFkiUqIbUCH1BF5HhZGv42kcVOyby7CRNxsvERTUKI1L7nEgMtx8sXwcamC4wZK++PzKujGwH2bdVapNeYArLs0P5hK10gCV3BOBfqDnogVrZSNIR4u3/wqE9KY1BamUIEA6ewzrs9ZIwtfeHx3U/uzSHsGK2AFmb + foundryPassword: AgBjxss3Xme+C8wgp8+RcpQ33Gb66TmUBLNV5il2tellCjnj16FI3pobf/BhxR2EKa3wn4qDcQ8qimO7r0pjJyX/utq7T5wYixcCxngybG6WSLJSEXqkJhSTiY0D79oh5eV+VDQi5pYLVLlY7i6+Vzo19LVIUwhHJeCOaQiWPpogOhXmHtwcgdkzgXgpFRozYhq8yKZY68cxnANJQwGEKnFiV4m3IpkFMdT6WoQdWnhy8SvgmjpmWz54fmE8tnoEoUVJmaGBO1yq0qojXvoEzmhAP89sXcTZBgC4hacxZ0tQzKlf6h9CXgB6cmTTCfgN6C+kFJ0+DGY+0bW1E5wa7ZKxO8i23xzNPZhXZTTa6N1w3m7wxzU7yJ0QHp8eq1MQ7V2bwpVS28bKL0tsiIK4F1z6N79JbW96HHrWQo77N2oBSymJ/ti2iuKYDc2U7EBWEMt+kr8kvFr+eK13h2RqwCnotOsLMRlVSCaUxyWVngb74wDhNII49uLhehuluyYcePDn53N8Qk8bHGcrqcC3dgfnpor4h4MqLlaIzTa6QevU47gKf1YZIllLTj8mNpFMIJZuBjReFykFR3ybgwJNgRTke9tDM9TZzjl5HEe+YWP6nve2ju/Ct2r2XFvZUGHyc9nlyEfT3kftnHVvi23ql37n6onbIOS44rMjxGlSKIjKBtgN0hVLJ1DVB1zvRHMxQkfA+CBtzWJivCLnhF7Omh21eYnNnMen3OE= + foundryUsername: AgBHVAq7ulmjwnGCqRvZZBYFb/dVvWLVQYQa4T8r0sM87Q8k+Isr9N3EpBAK0wnmS/Ip6iJ1tdx7TVN2FZGD4D+PSGu1eiZEp6IpQUlOeLtbm5EBZZfh4cN8qsIC5ucFGoEh2mBGoM/HePjvtPUuhgDHO22vJF/vIfUBDU3s0gy5kJZjKViK6TeoVT65FM574+f/f+ZMjl3qW3LyldTHA6RYhnGHytNmcSv/Z5juEh5FVftYQ7yZL2cycoKZmlfltE4knBrGlq5hlu7JNeegd3PH8xrAe2d75uhpXdGs9wYfFQ+5z/dDYyLFpTrVNql87CNbuovYR8omPMSyX2Q/cpns30kphR8Vng1oDnOMJv6XE60CSCqQnYLyCPWVgjKJiCs05qXo018BD2MrG/EVSqHBvRi5glip4p05Q9vtPNWmjqDmPW4WUJojCtfeDxu+9CCQsbNsoYxvHgJ4cXskAn6Lj8ByKYpLjn7k9FBspu+fdZHxQZVT1Toc0ijzLD+Ki/oXTMZtvZvA7QATmVmOLd5/Z+QvegLovuta0j3FDJkXh9ymAzNxxEkIl0V4UQlGG8wtRzYIMRAuriipnx2u4L1y6UH1cksY5y6A/DBa//lCi9oSPnswFqJ2Dh09n38/5w64DXiJFZsN/25ejRXHTcK9+D8aeKtHTEMF421FvadM8h76ede/lIqVa55LAvnN5KxWSDCuvKZkQsNZkA/VU9ZooL/PkPVOg7CzX7MXQck3 + template: + metadata: + creationTimestamp: null + name: foundryvtt + namespace: foundryvtt + type: Opaque diff --git a/charts/foundryvtt/values.yaml b/charts/foundryvtt/values.yaml new file mode 100644 index 00000000..7ab31a6c --- /dev/null +++ b/charts/foundryvtt/values.yaml @@ -0,0 +1,53 @@ +foundryvtt: + + ## @param env [array] Raw helm environment variable settings for static or dynamic values + env: + - name: FOUNDRY_IP_DISCOVERY + value: "false" + - name: FOUNDRY_HOSTNAME + value: "dnd.deepcypher.me" + - name: FOUNDRY_LOCAL_HOSTNAME + value: "dnd.deepcypher.me" + - name: FOUNDRY_MINIFY_STATIC_FILES + value: "true" + - name: FOUNDRY_UPNP + value: "false" + + ingress: + ## @param ingress.enabled [string] Enable ingress + enabled: true + ## @param ingress.className [string] Ingress class + className: "" + ## @param ingress.annotations [object] Ingress annotations + annotations: {} + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: "true" + ## @param ingress.hosts [array] Ingress hosts + hosts: + - host: dnd.deepcypher.me + paths: + - path: / + pathType: ImplementationSpecific + ## @param ingress.tls [array] Ingress TLS + tls: + - secretName: dnd-tls + hosts: + - dnd.deepcypher.me + + persistence: + ## @param persistence.enabled [string] If true use persistent volume else use emptyDir + enabled: true + ## @param persistence.generatePVC [string] Generate PVC or use existing one does nothing if persistence.enabled is false + generatePVC: true + ## @param persistence.storageClass [string] Storage class + storageClass: "" + ## @param persistence.annotations [object] Annotations + annotations: {} + ## @param persistence.labels [object] Labels + labels: {} + ## @param persistence.accessModes [array] Access modes + accessModes: [ReadWriteOnce] + ## @param persistence.existingClaim [string] Manually managed PVC name to use + existingClaim: "" + ## @param persistence.size [string] Size of the storage for the DB and assets + size: 50Gi diff --git a/charts/infrastructure/templates/foundryvtt.yaml b/charts/infrastructure/templates/foundryvtt.yaml new file mode 100644 index 00000000..47a0ce8a --- /dev/null +++ b/charts/infrastructure/templates/foundryvtt.yaml @@ -0,0 +1,71 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: foundryvtt + namespace: argocd + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + destination: + name: '' + namespace: foundryvtt + server: 'https://kubernetes.default.svc' + source: + path: charts/foundryvtt + repoURL: 'https://gitlab.com/deepcypher/dc-kc.git' + targetRevision: HEAD + #helm: + # values: | + #project: foundryvtt + project: default + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true + - ApplyOutOfSyncOnly=true +--- +apiVersion: argoproj.io/v1alpha1 +kind: AppProject +metadata: + name: foundryvtt + namespace: argocd + # Finalizer that ensures that project is not deleted until it is not referenced by any application + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + description: Infra-level project to isolate foundryvtt + # Allow manifests to deploy from any Git repos + sourceRepos: + - '*' + # Only permit applications to deploy to the guestbook namespace in the same cluster + destinations: + - namespace: foundryvtt + server: https://kubernetes.default.svc + # Deny all cluster-scoped resources from being created, except for Namespace + clusterResourceWhitelist: + - group: '' + kind: Namespace + # Allow all namespaced-scoped resources to be created, except for ResourceQuota, LimitRange, NetworkPolicy + namespaceResourceBlacklist: + - group: '' + kind: ResourceQuota + - group: '' + kind: LimitRange + #- group: '' + # kind: NetworkPolicy + # # Deny all namespaced-scoped resources from being created, except for Deployment and StatefulSet + # namespaceResourceWhitelist: + # - group: 'apps' + # kind: Deployment + # - group: 'apps' + # kind: StatefulSet + roles: + # A role which provides read-only access to all applications in the project + - name: read-only + description: Read-only privileges to foundryvtt + policies: + - p, proj:my-project:read-only, applications, get, foundryvtt/*, allow + groups: + - my-oidc-group