Browse Source

Helm Chart Security Enhancements and Feature Additions (#1211)

* Update Squidex Helm chart to version 1.0.4 with appVersion 7.18.0. Enhanced values.yaml with new parameters for deployment strategy, autoscaling, and network policies. Adjusted service port to 8080 and added support for pod disruption budgets. Introduced Horizontal Pod Autoscaler and NetworkPolicy templates for improved resource management and security.

* Enhance Squidex Helm chart README with additional configuration parameters for deployment strategy, autoscaling, pod disruption budgets, affinity, scheduling, ingress, and security context. Updated service port to 8080 and included detailed descriptions for new settings to improve user guidance.

* Update Squidex Helm chart configuration to include optional security contexts for pods and containers. Added commented annotations for ingress settings in values.yaml to enhance user customization options.

* Enhance Squidex Helm chart by adding optional parameters for topology spread constraints and priority class name in values.yaml. Update deployment template to conditionally include these settings, improving deployment flexibility and customization.

* Fix the values.yaml file to allow the README generator to run.

* Update Squidex Helm chart to change default service account name to an empty string in values.yaml and README.md for improved flexibility.

* Update Squidex Helm chart version to 2.0.1 for compatibility with appVersion 7.18.0.

* docs: update README to reflect change from 'skip' to 'param' for priorityClassName, topologySpreadConstraints, annotations, resources, and labels

* Update Squidex Helm chart to increase default replica count from 1 to 3 in both README.md and values.yaml.
pull/1218/head
Sina Darbouy 1 year ago
committed by GitHub
parent
commit
bf60028b42
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 2
      helm/squidex7/Chart.yaml
  2. 51
      helm/squidex7/README.md
  3. 5
      helm/squidex7/templates/_helpers.tpl
  4. 23
      helm/squidex7/templates/deployment-worker.yaml
  5. 30
      helm/squidex7/templates/deployment.yaml
  6. 14
      helm/squidex7/templates/hpa.yaml
  7. 2
      helm/squidex7/templates/ingress.yaml
  8. 19
      helm/squidex7/templates/networkpolicy.yaml
  9. 20
      helm/squidex7/templates/pdb.yaml
  10. 2
      helm/squidex7/templates/service.yaml
  11. 160
      helm/squidex7/values.yaml

2
helm/squidex7/Chart.yaml

@ -5,7 +5,7 @@ name: squidex7
icon: https://raw.githubusercontent.com/Squidex/squidex/master/media/logo-squared.png
description: Squidex CMS v7.0 and newer
version: 2.0.0
version: 2.0.1
appVersion: "7.18.0"
home: https://squidex.io/

51
helm/squidex7/README.md

@ -46,17 +46,34 @@ The command removes all the Kubernetes components associated with the chart and
### Global parameters
| Name | Description | Value |
| -------------------------- | ------------------------------ | ----------------- |
| `service.type` | Kubernetes Service type | `ClusterIP` |
| `service.port` | Kubernetes Service port | `80` |
| `deployment.replicaCount` | Number of instances. | `1` |
| `image.repository` | Squidex image registry | `squidex/squidex` |
| `image.pullPolicy` | Squidex image pull policy | `IfNotPresent` |
| `runAsNonRoot` | | `false` |
| `ingress.enabled` | True to deploy an ingress | `true` |
| `ingress.ingressClassName` | The ingress class. | `nginx` |
| `ingress.hostName` | The host name for the ingress. | `squidex.local` |
| Name | Description | Value |
| -------------------------------------------------- | ------------------------------------------------------------------- | ----------------- |
| `nameOverride` | Override the name of the application. | `squidex` |
| `labels` | Labels to add to the deployment | `{}` |
| `service.type` | Kubernetes Service type | `ClusterIP` |
| `service.port` | Kubernetes Service port | `8080` |
| `deployment.replicaCount` | Number of replicas (ignored if autoscaling enabled) | `3` |
| `deployment.worker.replicaCount` | Number of worker instances | `1` |
| `deployment.revisionHistoryLimit` | Number of revision history | `2` |
| `deployment.serviceAccountName` | Name of the service account to use | `""` |
| `deployment.strategy.type` | Deployment strategy type | `RollingUpdate` |
| `deployment.strategy.rollingUpdate.maxSurge` | Maximum number of pods that can be created above the desired amount | `1` |
| `deployment.strategy.rollingUpdate.maxUnavailable` | Maximum number of unavailable pods during update | `0` |
| `deployment.restartPolicy` | Pod restart policy | `Always` |
| `deployment.annotations` | Annotations to add to the deployment | `nil` |
| `deployment.command` | Command to run in the container | `nil` |
| `deployment.args` | Arguments to pass to the container | `nil` |
| `networkPolicy.enabled` | Enable network policies | `true` |
| `image.repository` | Squidex image registry | `squidex/squidex` |
| `image.pullPolicy` | Squidex image pull policy | `IfNotPresent` |
| `resources` | Resource requests and limits | `{}` |
| `topologySpreadConstraints` | Topology spread constraints for pod scheduling | `[]` |
| `priorityClassName` | Priority class name for the pod | `nil` |
| `runAsNonRoot` | Run container as non-root user. | `true` |
| `ingress.enabled` | True to deploy an ingress | `true` |
| `ingress.ingressClassName` | The ingress class. | `nginx` |
| `ingress.annotations` | Ingress annotations | `{}` |
| `ingress.hostName` | The host name for the ingress. | `squidex.local` |
### Squidex parameters
@ -90,7 +107,7 @@ The command removes all the Kubernetes components associated with the chart and
| `env.LOGGING__APPLICATIONINSIGHTS__CONNECTIONSTRING` | The connection string to application insights. | `nil` |
| `env.LOGGING__COLORS` | Use colors in the console output. | `false` |
| `env.LOGGING__HUMAN` | Setting the flag to true, enables well formatteds json logs. | `false` |
| `env.LOGGING__LEVEL` | Trace, Debug, Information, Warning, Error, Fatal | `INFORMATION` |
| `env.LOGGING__LEVEL` | Trace, Debug, Information, Warning, Error, Fatal | `Warning` |
| `env.LOGGING__LOGREQUESTS` | Set to false to disable logging of http requests. | `true` |
| `env.LOGGING__OTLP__ENABLED` | True, to enable OpenTelemetry Protocol integration | `false` |
| `env.LOGGING__OLTP__ENDPOINT` | The endpoint to the agent | `nil` |
@ -101,7 +118,13 @@ The command removes all the Kubernetes components associated with the chart and
| `env.STORE__MONGODB__CONTENTDATABASE` | The name of the database for content items. | `SquidexContent` |
| `env.URLS__BASEURL` | Set the base url of your application, to generate correct urls in background process. | `https://squidex.local/` |
| `env.URLS__ENFORCEHTTPS` | Set it to true to redirect the user from http to https permanently | `false` |
| `env.ASPNETCORE_URLS` | An override to ensure that kestrel starts on a non-privileged port | `http://+:80` |
| `env.ASPNETCORE_URLS` | An override to ensure that kestrel starts on a non-privileged port | `http://+:8080` |
| `autoscaling.enabled` | Enable autoscaling for the deployment | `true` |
| `autoscaling.maxReplicas` | Maximum number of replicas | `6` |
| `autoscaling.minReplicas` | Minimum number of replicas | `3` |
| `autoscaling.targetCPUUtilizationPercentage` | Target CPU utilization percentage | `85` |
| `podDisruptionBudget.minAvailable` | Minimum number of available pods | `1` |
| `podDisruptionBudget.unhealthyPodEvictionPolicy` | Policy for evicting unhealthy pods | `AlwaysAllow` |
### MongoDB parameters
@ -124,4 +147,4 @@ Parameters are generated with: https://github.com/bitnami-labs/readme-generator-
## Support
Use the support forum to get help: https://support.squidex.io
Use the support forum to get help: https://support.squidex.io

5
helm/squidex7/templates/_helpers.tpl

@ -19,7 +19,8 @@ app.kubernetes.io/version: {{ .Values.selectors.version | quote }}
helm.sh/chart: {{ include "squidex.chart" . }}
app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- if .Values.labels }}
{{- toYaml .Values.labels | nindent 4 }}
{{- "\n" -}}
{{- toYaml .Values.labels }}
{{- end -}}
{{- end -}}
@ -70,4 +71,4 @@ If release name contains chart name it will be used as a full name.
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
{{- end -}}
{{- end -}}
{{- end -}}
{{- end -}}

23
helm/squidex7/templates/deployment-worker.yaml

@ -6,7 +6,10 @@ metadata:
{{- include "squidex.labels" . | indent 4 }}
app.kubernetes.io/role: worker
spec:
replicas: 1
replicas: {{ .Values.deployment.worker.replicaCount }}
revisionHistoryLimit: {{ .Values.deployment.revisionHistoryLimit }}
strategy:
{{- toYaml .Values.deployment.strategy | nindent 4 }}
selector:
matchLabels:
{{- include "squidex.selectors" . | indent 6 }}
@ -16,6 +19,10 @@ spec:
labels:
{{- include "squidex.selectors" . | indent 8 }}
app.kubernetes.io/role: worker
{{- if .Values.deployment.annotations }}
annotations:
{{- toYaml .Values.deployment.annotations | nindent 8 }}
{{- end }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
@ -25,6 +32,7 @@ spec:
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
{{- end }}
restartPolicy: {{ .Values.deployment.restartPolicy }}
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}"
@ -33,9 +41,17 @@ spec:
securityContext:
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
{{- end }}
{{- if .Values.deployment.command }}
command:
{{- toYaml .Values.deployment.command | nindent 12 }}
{{- end }}
{{- if .Values.deployment.args }}
args:
{{- toYaml .Values.deployment.args | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 80
containerPort: 8080
protocol: TCP
livenessProbe:
httpGet:
@ -58,7 +74,6 @@ spec:
value: {{ $val | quote }}
{{- end }}
{{- end }}
- name: CLUSTERING__WORKER
value: "true"
@ -85,4 +100,4 @@ spec:
{{- toYaml .Values.tolerations | nindent 8 }}
{{- if (.Values.deployment.serviceAccountName) }}
serviceAccountName: {{ .Values.deployment.serviceAccountName}}
{{- end }}
{{- end }}

30
helm/squidex7/templates/deployment.yaml

@ -6,7 +6,12 @@ metadata:
{{- include "squidex.labels" . | indent 4 }}
app.kubernetes.io/role: api
spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.deployment.replicaCount }}
{{- end }}
revisionHistoryLimit: {{ .Values.deployment.revisionHistoryLimit }}
strategy:
{{- toYaml .Values.deployment.strategy | nindent 4 }}
selector:
matchLabels:
{{- include "squidex.selectors" . | indent 6 }}
@ -16,6 +21,10 @@ spec:
labels:
{{- include "squidex.selectors" . | indent 8 }}
app.kubernetes.io/role: api
{{- if .Values.deployment.annotations }}
annotations:
{{- toYaml .Values.deployment.annotations | nindent 8 }}
{{- end }}
spec:
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
@ -25,6 +34,10 @@ spec:
securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }}
{{- end }}
restartPolicy: {{ .Values.deployment.restartPolicy }}
{{- if .Values.priorityClassName }}
priorityClassName: {{ .Values.priorityClassName }}
{{- end }}
containers:
- name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}"
@ -33,9 +46,17 @@ spec:
securityContext:
{{- toYaml .Values.containerSecurityContext | nindent 12 }}
{{- end }}
{{- if .Values.deployment.command }}
command:
{{- toYaml .Values.deployment.command | nindent 12 }}
{{- end }}
{{- if .Values.deployment.args }}
args:
{{- toYaml .Values.deployment.args | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 80
containerPort: 8080
protocol: TCP
livenessProbe:
httpGet:
@ -58,7 +79,6 @@ spec:
value: {{ $val | quote }}
{{- end }}
{{- end }}
- name: CLUSTERING__WORKER
value: "false"
@ -81,8 +101,12 @@ spec:
{{- toYaml .Values.nodeSelector | nindent 8 }}
affinity:
{{- toYaml .Values.affinity | nindent 8 }}
{{- if .Values.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml .Values.topologySpreadConstraints | nindent 8 }}
{{- end }}
tolerations:
{{- toYaml .Values.tolerations | nindent 8 }}
{{- if (.Values.deployment.serviceAccountName) }}
serviceAccountName: {{ .Values.deployment.serviceAccountName}}
{{- end }}
{{- end }}

14
helm/squidex7/templates/hpa.yaml

@ -0,0 +1,14 @@
{{- if .Values.autoscaling.enabled }}
apiVersion: autoscaling/v1
kind: HorizontalPodAutoscaler
metadata:
name: {{ include "squidex.fullname" . }}
spec:
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
minReplicas: {{ .Values.autoscaling.minReplicas }}
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: {{ include "squidex.fullname" . }}
targetCPUUtilizationPercentage: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
{{- end }}

2
helm/squidex7/templates/ingress.yaml

@ -34,4 +34,4 @@ spec:
name: {{ $fullName }}
port:
number: {{ .Values.service.port }}
{{- end -}}
{{- end -}}

19
helm/squidex7/templates/networkpolicy.yaml

@ -0,0 +1,19 @@
{{- if .Values.networkPolicy.enabled }}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-{{ include "squidex.fullname" . }}
labels:
{{- include "squidex.labels" . | indent 4 }}
spec:
podSelector:
matchLabels:
{{- include "squidex.selectors" . | indent 6 }}
policyTypes:
- Ingress
- Egress
ingress:
{{- toYaml .Values.networkPolicy.ingressRules | nindent 4 }}
egress:
{{- toYaml .Values.networkPolicy.egressRules | nindent 4 }}
{{- end }}

20
helm/squidex7/templates/pdb.yaml

@ -0,0 +1,20 @@
{{- if .Values.podDisruptionBudget }}
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: {{ include "squidex.fullname" . }}
labels:
{{- include "squidex.labels" . | indent 4 }}
spec:
{{- if .Values.podDisruptionBudget.minAvailable }}
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
{{- end }}
{{- if .Values.podDisruptionBudget.maxUnavailable }}
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
{{- end }}
unhealthyPodEvictionPolicy: {{ .Values.podDisruptionBudget.unhealthyPodEvictionPolicy }}
selector:
matchLabels:
{{- include "squidex.selectors" . | indent 6 }}
app.kubernetes.io/role: api
{{- end }}

2
helm/squidex7/templates/service.yaml

@ -14,4 +14,4 @@ spec:
name: http
selector:
{{- include "squidex.selectors" . | indent 4 }}
app.kubernetes.io/role: api
app.kubernetes.io/role: api

160
helm/squidex7/values.yaml

@ -1,18 +1,85 @@
## @section Global parameters
## @skip labels
## @param nameOverride Override the name of the application.
nameOverride: "squidex"
## @param labels [object] Labels to add to the deployment
labels:
# custom: "custom"
service:
## @param service.type Kubernetes Service type
##
type: ClusterIP
## @param service.port Kubernetes Service port
##
port: 80
port: 8080
deployment:
## @param deployment.replicaCount Number of instances.
##
replicaCount: 1
## @param deployment.replicaCount Number of replicas (ignored if autoscaling enabled)
replicaCount: 3
worker:
## @param deployment.worker.replicaCount Number of worker instances
replicaCount: 1 # only one worker supported
## @param deployment.revisionHistoryLimit [default: 2] Number of revision history
revisionHistoryLimit: 2
## @param deployment.serviceAccountName Name of the service account to use
serviceAccountName: ""
## @param deployment.strategy.type Deployment strategy type
strategy:
type: RollingUpdate
## @param deployment.strategy.rollingUpdate.maxSurge Maximum number of pods that can be created above the desired amount
rollingUpdate:
maxSurge: 1
## @param deployment.strategy.rollingUpdate.maxUnavailable Maximum number of unavailable pods during update
maxUnavailable: 0
## @param deployment.restartPolicy Pod restart policy
restartPolicy: Always
## @param deployment.annotations Annotations to add to the deployment
annotations:
# vault.hashicorp.com/agent-pre-populate-only: "true"
# vault.hashicorp.com/agent-limits-cpu: 50m
# vault.hashicorp.com/agent-limits-mem: 64Mi
# vault.hashicorp.com/agent-requests-cpu: 10m
# vault.hashicorp.com/agent-requests-mem: 16Mi
## @param deployment.command Command to run in the container
command:
# - sh
# - -c
## @param deployment.args Arguments to pass to the container
args:
# - 'dotnet Squidex.dll'
## @param networkPolicy.enabled Enable network policies
networkPolicy:
enabled: true
## @skip networkPolicy.ingressRules
ingressRules:
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: ingress-nginx
- podSelector:
matchLabels:
app.kubernetes.io/instance: ingress-nginx
ports:
- port: 8080
protocol: TCP
## @skip networkPolicy.egressRules
egressRules:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
podSelector:
matchLabels:
k8s-app: kube-dns
ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
selectors:
## @skip selectors.component
##
@ -31,21 +98,56 @@ image:
##
pullPolicy: IfNotPresent
## @skip resources
resources: { }
## @param resources [object] Resource requests and limits
resources:
limits:
memory: "1Gi"
requests:
cpu: "200m"
memory: "512Mi"
## @skip nodeSelector
nodeSelector: { }
## @skip tolerations
tolerations: [ ]
## @skip affinity
affinity: { }
affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchLabels:
app.kubernetes.io/instance: squidex
app.kubernetes.io/component: squidex
topologyKey: kubernetes.io/hostname
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: kubernetes.io/arch
operator: In
values:
- amd64
- arm64
## @param topologySpreadConstraints [array] Topology spread constraints for pod scheduling
topologySpreadConstraints:
# - maxSkew: 1
# topologyKey: kubernetes.io/hostname
# whenUnsatisfiable: DoNotSchedule
# labelSelector:
# matchLabels:
# app.kubernetes.io/instance: squidex
# app.kubernetes.io/component: squidex
## @param priorityClassName [nullable] Priority class name for the pod
priorityClassName:
## @skip clusterSuffix
clusterSuffix: cluster.local
## @param runAsNonRoot
## Set to true to run Squidex as nonroot. Defaults to false for backwards compatibility.
runAsNonRoot: false
## @param runAsNonRoot Run container as non-root user.
runAsNonRoot: true
## @skip podSecurityContext - object - optional
## You can modify the security context used to run PODS in the cluster
@ -63,6 +165,7 @@ podSecurityContext:
## @skip containerSecurityContext - object - optional
## You can modify the security context used to run CONTAINERS in the cluster
## For information regarding which settings are required per policy see: https://kubernetes.io/docs/concepts/security/pod-security-standards/
## readOnlyRootFilesystem: true not supported becasue of backup and restore process
## An example that follows the Restricted profile is described below:
#
containerSecurityContext:
@ -84,10 +187,15 @@ ingress:
enabled: true
## @param ingress.ingressClassName The ingress class.
ingressClassName: nginx
## Squidex Ingress annotations
# annotations:
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
## @param ingress.annotations [object] Ingress annotations
annotations:
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/proxy-body-size: 50m
nginx.ingress.kubernetes.io/proxy-buffer-size: 128k
nginx.ingress.kubernetes.io/proxy-buffers: 4 256k
nginx.ingress.kubernetes.io/proxy-busy-buffers-size: 256k
nginx.ingress.kubernetes.io/ssl-redirect: 'true'
## @param ingress.hostName The host name for the ingress.
##
hostName: squidex.local
@ -119,7 +227,7 @@ env:
IDENTITY__ADMINPASSWORD: ""
## @param env.IDENTITY__ADMINRECREATE Recreate the admin if it does not exist or the password does not match
##
IDENTITY__ADMINRECREATE: false #
IDENTITY__ADMINRECREATE: false
## @param env.IDENTITY__ALLOWPASSWORDAUTH Enable password auth. Set this to false if you want to disable local login, leaving only 3rd party login options
##
IDENTITY__ALLOWPASSWORDAUTH: "true"
@ -205,7 +313,7 @@ env:
LOGGING__HUMAN: false
## @param env.LOGGING__LEVEL Trace, Debug, Information, Warning, Error, Fatal
##
LOGGING__LEVEL: INFORMATION
LOGGING__LEVEL: Warning
## @param env.LOGGING__LOGREQUESTS Set to false to disable logging of http requests.
##
LOGGING__LOGREQUESTS: true
@ -247,7 +355,23 @@ env:
## @param env.ASPNETCORE_URLS An override to ensure that kestrel starts on a non-privileged port
##
ASPNETCORE_URLS: http://+:80
ASPNETCORE_URLS: http://+:8080
## @param autoscaling.enabled Enable autoscaling for the deployment
autoscaling:
enabled: true
## @param autoscaling.maxReplicas Maximum number of replicas
maxReplicas: 6
## @param autoscaling.minReplicas Minimum number of replicas
minReplicas: 3
## @param autoscaling.targetCPUUtilizationPercentage Target CPU utilization percentage
targetCPUUtilizationPercentage: 85
## @param podDisruptionBudget.minAvailable Minimum number of available pods
podDisruptionBudget:
minAvailable: 1
## @param podDisruptionBudget.unhealthyPodEvictionPolicy Policy for evicting unhealthy pods
unhealthyPodEvictionPolicy: AlwaysAllow
## @section MongoDB parameters
mongodb:

Loading…
Cancel
Save