diff --git a/charts/sourcegraph/CHANGELOG.md b/charts/sourcegraph/CHANGELOG.md index b1331843..e02acc1f 100644 --- a/charts/sourcegraph/CHANGELOG.md +++ b/charts/sourcegraph/CHANGELOG.md @@ -8,6 +8,7 @@ Use `**BREAKING**:` to denote a breaking change ## Unreleased +- Added `gitserver.storageAccessModes` (default `["ReadWriteOnce"]`) to allow `["ReadWriteOncePod"]`, which lets Kubernetes mount the repos volume with `-o context` on SELinux-enforcing nodes (e.g. Bottlerocket / EKS Auto Mode) instead of recursively relabeling every file on each pod start. Changing this on an existing deployment requires recreating the StatefulSet and PVC, as both fields are immutable. - Added optional `syntectServer.podDisruptionBudget` support - Added optional `searcher.podDisruptionBudget` support - Set `DEPLOY_TYPE=helm` consistently for all Sourcegraph application containers diff --git a/charts/sourcegraph/README.md b/charts/sourcegraph/README.md index cdd2a2d9..ebc3fc5a 100644 --- a/charts/sourcegraph/README.md +++ b/charts/sourcegraph/README.md @@ -132,6 +132,7 @@ In addition to the documented values, all services also support the following va | gitserver.serviceAccount.create | bool | `false` | Enable creation of ServiceAccount for `gitserver` | | gitserver.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | gitserver.sshSecret | string | `""` | Name of existing Secret that contains SSH credentials to clone repositories. It usually contains keys, such as `id_rsa` (private key) and `known_hosts`. Learn more from [documentation](https://docs.sourcegraph.com/admin/install/kubernetes/helm#using-ssh-to-clone-repositories) | +| gitserver.storageAccessModes | list | `["ReadWriteOnce"]` | Access modes for the `gitserver` PVC. Set to `["ReadWriteOncePod"]` on SELinux-enforcing nodes (e.g. Bottlerocket / EKS Auto Mode) so Kubernetes mounts the volume with `-o context` instead of recursively relabeling every file on each pod start | | gitserver.storageAnnotations | object | `{}` | Optional annotations to add to the `gitserver` PVC | | gitserver.storageSize | string | `"200Gi"` | PVC Storage Request for `gitserver` data volume | | gitserver.storageSubPath | string | `""` | Optional subPath for the `gitserver` primary data volume mount | diff --git a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml index 99d1eca7..01197c2c 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml @@ -133,7 +133,7 @@ spec: {{- end }} spec: accessModes: - - ReadWriteOnce + {{- toYaml .Values.gitserver.storageAccessModes | nindent 6 }} resources: requests: # The size of disk used to mirror your git repositories. diff --git a/charts/sourcegraph/values.yaml b/charts/sourcegraph/values.yaml index e183f5fe..d1188412 100644 --- a/charts/sourcegraph/values.yaml +++ b/charts/sourcegraph/values.yaml @@ -462,6 +462,8 @@ gitserver: create: false # -- Name of the ServiceAccount to be created or an existing ServiceAccount name: "" + # -- Access modes for the `gitserver` PVC. Set to `["ReadWriteOncePod"]` on SELinux-enforcing nodes (e.g. Bottlerocket / EKS Auto Mode) so Kubernetes mounts the volume with `-o context` instead of recursively relabeling every file on each pod start + storageAccessModes: ["ReadWriteOnce"] # -- PVC Storage Request for `gitserver` data volume storageSize: 200Gi # -- Optional subPath for the `gitserver` primary data volume mount