Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
348 changes: 231 additions & 117 deletions charts/arcadedb/README.md

Large diffs are not rendered by default.

106 changes: 99 additions & 7 deletions charts/arcadedb/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -71,22 +71,37 @@ Create the name of the service account to use
{{- end }}

{{/*
Create a comma-separated list of StatefulSet pod FQDNs for the Raft HA server list.
Create a comma-separated list of StatefulSet pod FQDNs (no ports).
When HPA is enabled, the list is sized to autoscaling.maxReplicas so that
KubernetesAutoJoin can resolve any pod ordinal up to the maximum scale.
*/}}
{{- define "arcadedb.nodenames" -}}
{{- define "arcadedb.nodehosts" -}}
{{- $replicas := int .Values.replicaCount -}}
{{- if and .Values.autoscaling.enabled (gt (int .Values.autoscaling.maxReplicas) $replicas) -}}
{{- $replicas = int .Values.autoscaling.maxReplicas -}}
{{- end -}}
{{- $names := list -}}
{{- $fullname := (include "arcadedb.fullname" .) -}}
{{- $k8sSuffix := (include "arcadedb.k8sSuffix" .) -}}
{{- $rpcPort := int .Values.service.rpc.port -}}
{{- $httpPort := int .Values.service.http.port -}}
{{- range $i, $_ := until $replicas }}
{{- $names = append $names (printf "%s-%d%s:%d:%d" $fullname $i $k8sSuffix $rpcPort $httpPort) }}
{{- $names = append $names (printf "%s-%d%s" $fullname $i $k8sSuffix) }}
{{- end }}
{{- join "," $names -}}
{{- end }}

{{/*
Create the Raft HA server list: host:raftPort:httpPort per pod, plus
:priority:httpsPort when TLS is on. Declaring the ports keeps peer HTTP/HTTPS
endpoints explicit instead of relying on ArcadeDB's local-port fallback.
*/}}
{{- define "arcadedb.nodenames" -}}
{{- $ports := printf "%d:%d" (int .Values.service.rpc.port) (int .Values.service.http.port) -}}
{{- if .Values.tls.enabled -}}
{{- $ports = printf "%s:0:%d" $ports (int .Values.service.https.port) -}}
{{- end -}}
{{- $names := list -}}
{{- range $host := split "," (include "arcadedb.nodehosts" .) }}
{{- $names = append $names (printf "%s:%s" $host $ports) }}
{{- end }}
{{- join "," $names -}}
{{- end }}
Expand All @@ -98,7 +113,9 @@ Preparing a list of plugin ports to build plugin configurations.
{{- range $plugin, $config := .Values.arcadedb.plugins -}}
{{- if $config.enabled }}
{{- $port := int 0}}
{{- if eq $plugin "gremlin" }}
{{- if eq $plugin "bolt" }}
{{- $port = default 7687 $config.port }}
{{- else if eq $plugin "gremlin" }}
{{- $port = default 8182 $config.port }}
{{- else if eq $plugin "postgres" }}
{{- $port = default 5432 $config.port }}
Expand Down Expand Up @@ -141,7 +158,10 @@ Create a comma separated list of plugins to be enabled in arcadedb
{{- $plugins := list -}}
{{- $params := list -}}
{{- range $plugin, $config := (include "_arcadedb.plugin.ports" . | fromYaml) -}}
{{- if eq $plugin "gremlin" -}}
{{- if eq $plugin "bolt" -}}
{{- $plugins = append $plugins "Bolt:com.arcadedb.bolt.BoltProtocolPlugin" -}}
{{- $params = append $params (printf "-Darcadedb.bolt.port=%d" (int $config.port)) -}}
{{- else if eq $plugin "gremlin" -}}
{{- $plugins = append $plugins "GremlinServer:com.arcadedb.server.gremlin.GremlinServerPlugin" -}}
{{- $params = append $params (printf "-Darcadedb.gremlin.port=%d" (int $config.port)) -}}
{{- else if eq $plugin "postgres" -}}
Expand Down Expand Up @@ -196,6 +216,19 @@ Create service configuration for the enabled plugins
{{- end -}}
{{- end -}}

{{/*
Create network policy configuration for the enabled plugins
*/}}
{{- define "arcadedb.plugin.networkPolicy" -}}
{{- $plugins := (include "_arcadedb.plugin.ports" . | fromYaml) }}
{{- range $plugin, $config := $plugins }}
{{- if (gt (int $config.port) 0) }}
- port: {{ $config.port }}
protocol: TCP
{{- end -}}
{{- end -}}
{{- end -}}

{{/*
Observability -D JVM args (logging, OTLP metrics, tracing, readiness).
All opt-in; emits nothing when defaults are unchanged.
Expand Down Expand Up @@ -227,6 +260,65 @@ All opt-in; emits nothing when defaults are unchanged.
{{- end }}
{{- end -}}

{{/*
Name of the secret holding the TLS key store / trust store.
*/}}
{{- define "arcadedb.tls.secretName" -}}
{{- default (printf "%s-tls" (include "arcadedb.fullname" .)) .Values.tls.secretRef.name -}}
{{- end -}}

{{/*
Secret name and key holding the key store / trust store password.
Defaults to the root password secret.
*/}}
{{- define "arcadedb.tls.passwordSecretName" -}}
{{- with .Values.tls.secretRef.passwordSecret.name -}}
{{- . -}}
{{- else -}}
{{- default "arcadedb-credentials-secret" .Values.arcadedb.credentials.rootPassword.secret.name -}}
{{- end -}}
{{- end -}}

{{- define "arcadedb.tls.passwordSecretKey" -}}
{{- if .Values.tls.secretRef.passwordSecret.name -}}
{{- required "tls.secretRef.passwordSecret.key is required when tls.secretRef.passwordSecret.name is set" .Values.tls.secretRef.passwordSecret.key -}}
{{- else if .Values.arcadedb.credentials.rootPassword.secret.name -}}
{{- .Values.arcadedb.credentials.rootPassword.secret.key -}}
{{- else -}}
rootPassword
{{- end -}}
{{- end -}}

{{/*
TLS parameters. Store passwords come from the TLS_STORE_PASSWORD env var
(a secretKeyRef), so they never appear in the pod spec.
*/}}
{{- define "arcadedb.tls.parameters" -}}
{{- if .Values.tls.enabled }}
- -Darcadedb.ssl.enabled=true
- -Darcadedb.server.httpsIncomingPort={{ .Values.service.https.port }}
{{- if and (hasKey .Values.arcadedb.plugins "bolt") .Values.arcadedb.plugins.bolt.enabled }}
- -Darcadedb.bolt.ssl={{ .Values.tls.bolt }}
{{- end }}
{{- $keyStoreKey := .Values.tls.secretRef.keyStore.key }}
{{- $trustStoreKey := .Values.tls.secretRef.trustStore.key }}
{{- $trustStoreFormat := .Values.tls.secretRef.trustStore.format }}
{{- if .Values.tls.certManager.enabled }}
{{- $keyStoreKey = "keystore.p12" -}}
{{- $trustStoreFormat = "PKCS12" -}}
{{- /* cert-manager only writes truststore.p12 when the issuer returns a CA */ -}}
{{- $trustStoreKey = ternary "truststore.p12" "keystore.p12" .Values.tls.certManager.issuerProvidesCA -}}
{{- end }}
{{- if ne "JKS" $trustStoreFormat }}
- -Djavax.net.ssl.trustStoreType={{ $trustStoreFormat }}
{{- end }}
- -Darcadedb.ssl.keyStore={{ printf "%s/%s" .Values.tls.mountPath $keyStoreKey }}
- -Darcadedb.ssl.keyStorePassword=$(TLS_STORE_PASSWORD)
- -Darcadedb.ssl.trustStore={{ printf "%s/%s" .Values.tls.mountPath $trustStoreKey }}
- -Darcadedb.ssl.trustStorePassword=$(TLS_STORE_PASSWORD)
{{- end }}
{{- end -}}

{{/*
Guard: scrape discovery (ServiceMonitor or pod annotations) needs the
prometheus plugin so /prometheus is actually served.
Expand Down
47 changes: 47 additions & 0 deletions charts/arcadedb/templates/certificate.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
{{- if and .Values.tls.enabled .Values.tls.certManager.enabled }}
{{- $fullname := include "arcadedb.fullname" . }}
{{- $services := list $fullname (printf "%s-http" $fullname) }}
{{- if .Values.service.external.enabled }}
{{- $services = append $services (printf "%s-external" $fullname) }}
{{- end }}
kind: Certificate
apiVersion: cert-manager.io/v1
metadata:
name: {{ $fullname }}
labels:
{{- include "arcadedb.labels" . | nindent 4 }}
spec:
dnsNames:
{{- range $svc := $services }}
- {{ $svc }}
- {{ $svc }}.{{ $.Release.Namespace }}
- {{ $svc }}.{{ $.Release.Namespace }}.svc
- {{ $svc }}.{{ $.Release.Namespace }}.svc.cluster.local
{{- end }}
{{- range $n := split "," (include "arcadedb.nodehosts" .) }}
- {{ $n }}
{{- end }}
{{- with .Values.tls.certManager.extraDnsNames }}
{{- toYaml . | nindent 4 }}
{{- end }}
subject:
organizations:
- {{ $fullname }}
isCA: false
usages:
- server auth
- client auth
secretName: {{ include "arcadedb.tls.secretName" . }}
privateKey:
algorithm: ECDSA
size: 256
issuerRef:
kind: {{ .Values.tls.certManager.issuerRef.kind }}
name: {{ required "tls.certManager.issuerRef.name is required when tls.certManager.enabled" .Values.tls.certManager.issuerRef.name }}
keystores:
pkcs12:
create: true
passwordSecretRef:
name: {{ include "arcadedb.tls.passwordSecretName" . }}
key: {{ include "arcadedb.tls.passwordSecretKey" . }}
{{- end }}
5 changes: 5 additions & 0 deletions charts/arcadedb/templates/networkpolicy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,11 @@ spec:
- ports:
- port: {{ .Values.service.http.port }}
protocol: TCP
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.https.port }}
protocol: TCP
{{- end }}
{{- include "arcadedb.plugin.networkPolicy" . | nindent 8 }}
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
Expand Down
44 changes: 44 additions & 0 deletions charts/arcadedb/templates/service.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,12 @@ spec:
targetPort: http
protocol: TCP
name: http
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.https.port }}
targetPort: https
protocol: TCP
name: https
{{- end }}
selector:
{{- include "arcadedb.selectorLabels" . | nindent 4 }}

Expand All @@ -36,10 +42,48 @@ spec:
targetPort: http
protocol: TCP
name: http
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.https.port }}
targetPort: https
protocol: TCP
name: https
{{- end }}
- port: {{ .Values.service.rpc.port }}
targetPort: rpc
protocol: TCP
name: rpc
{{- include "arcadedb.plugin.service" . | nindent 4 }}
selector:
{{- include "arcadedb.selectorLabels" . | nindent 4 }}
{{/*
External service for exposing all protocol ports outside the cluster.
*/}}
{{- if .Values.service.external.enabled }}
{{- if ne .Values.service.http.type "ClusterIP" }}
{{- fail "service.http.type must be ClusterIP when service.external.enabled is true (the external service replaces it)" -}}
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: {{ include "arcadedb.fullname" . }}-external
labels:
{{- include "arcadedb.labels" . | nindent 4 }}
app.kubernetes.io/component: external
spec:
type: {{ .Values.service.external.type }}
ports:
- port: {{ .Values.service.http.port }}
targetPort: http
protocol: TCP
name: http
{{- if .Values.tls.enabled }}
- port: {{ .Values.service.https.port }}
targetPort: https
protocol: TCP
name: https
{{- end }}
{{- include "arcadedb.plugin.service" . | nindent 4 }}
selector:
{{- include "arcadedb.selectorLabels" . | nindent 4 }}
{{- end }}
71 changes: 65 additions & 6 deletions charts/arcadedb/templates/statefulset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,15 @@ apiVersion: apps/v1
kind: StatefulSet
metadata:
name: {{ include "arcadedb.fullname" . }}
{{- with .Values.statefulSetAnnotations }}
annotations:
{{- toYaml . | nindent 4 }}
{{- end }}
labels:
{{- include "arcadedb.labels" . | nindent 4 }}
{{- with .Values.statefulSetLabels }}
{{- toYaml . | nindent 4 }}
{{- end }}
spec:
serviceName: {{ include "arcadedb.fullname" . }}
podManagementPolicy: Parallel
Expand Down Expand Up @@ -47,6 +54,11 @@ spec:
- name: http
containerPort: {{ .Values.service.http.port }}
protocol: TCP
{{- if .Values.tls.enabled }}
- name: https
containerPort: {{ .Values.service.https.port }}
protocol: TCP
{{- end }}
- name: rpc
containerPort: {{ .Values.service.rpc.port }}
protocol: TCP
Expand All @@ -64,6 +76,7 @@ spec:
{{- end }}
- -Darcadedb.dumpConfigAtStartup=true
- -Darcadedb.server.name=$(HOSTNAME)
- -Darcadedb.server.httpIncomingPort={{ .Values.service.http.port }}
- -Darcadedb.server.rootPassword=$(rootPassword)
- -Darcadedb.server.databaseDirectory={{ .Values.arcadedb.databaseDirectory }}
- -Darcadedb.server.defaultDatabases={{ .Values.arcadedb.defaultDatabases }}
Expand All @@ -80,6 +93,7 @@ spec:
{{- end }}
{{- include "arcadedb.plugin.parameters" . | nindent 12 }}
{{- include "arcadedb.observability.args" . | nindent 12 }}
{{- include "arcadedb.tls.parameters" . | nindent 12 }}
{{- with .Values.livenessProbe }}
livenessProbe:
{{- toYaml . | nindent 12 }}
Expand All @@ -92,10 +106,27 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if .Values.arcadedb.backupConfigMap }}
- name: arcadedb-config-backup-json
mountPath: {{ .Values.arcadedb.configDirectory }}/backup.json
subPath: backup.json
readOnly: true
{{- end }}
{{- if .Values.arcadedb.mcpConfigMap }}
- name: arcadedb-config-mcp-json
mountPath: {{ .Values.arcadedb.configDirectory }}/mcp-config.json
subPath: mcp-config.json
readOnly: true
{{- end }}
{{- if .Values.tls.enabled }}
- name: tls-certs
mountPath: {{ .Values.tls.mountPath }}
readOnly: true
{{- end }}
{{- with .Values.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: HOSTNAME
valueFrom:
Expand All @@ -120,17 +151,45 @@ spec:
{{- end }}
- name: ARCADEDB_LOG_DIR
value: {{ .Values.arcadedb.logsDirectory | quote }}
{{- with .Values.arcadedb.tmpDirectory }}
- name: ARCADEDB_PID
value: {{ printf "%s/arcadedb.pid" . | quote }}
- name: XDG_CACHE_HOME
value: {{ printf "%s/.cache" . | quote }}
{{- end }}
{{- if .Values.tls.enabled }}
- name: TLS_STORE_PASSWORD
valueFrom:
secretKeyRef:
name: {{ include "arcadedb.tls.passwordSecretName" . }}
key: {{ include "arcadedb.tls.passwordSecretKey" . }}
{{- end }}
{{- with .Values.arcadedb.consoleWorkingDirectory }}
- name: ARCADEDB_SETTINGS
value: {{ printf "-Duser.dir=%s" . | quote }}
{{- end }}
{{- with .Values.arcadedb.extraEnvironment }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if .Values.arcadedb.backupConfigMap }}
- name: arcadedb-config-backup-json
configMap:
name: {{ .Values.arcadedb.backupConfigMap }}
{{- end }}
{{- if .Values.arcadedb.mcpConfigMap }}
- name: arcadedb-config-mcp-json
configMap:
name: {{ .Values.arcadedb.mcpConfigMap }}
{{- end }}
{{- if .Values.tls.enabled }}
- name: tls-certs
secret:
secretName: {{ include "arcadedb.tls.secretName" . }}
{{- end }}
{{- with .Values.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.nodeSelector }}
nodeSelector:
{{- toYaml . | nindent 8 }}
Expand Down
Loading