diff --git a/charts/incubator/wordpress/.helmignore b/charts/incubator/wordpress/.helmignore new file mode 100644 index 00000000000..77ca5567b26 --- /dev/null +++ b/charts/incubator/wordpress/.helmignore @@ -0,0 +1,30 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ +# OWNERS file for Kubernetes +OWNERS +# helm-docs templates +*.gotmpl +# docs folder +/docs +# icon +icon.png diff --git a/charts/incubator/wordpress/Chart.yaml b/charts/incubator/wordpress/Chart.yaml new file mode 100644 index 00000000000..7869f8e8875 --- /dev/null +++ b/charts/incubator/wordpress/Chart.yaml @@ -0,0 +1,34 @@ +apiVersion: v2 +appVersion: "6.1.1" +dependencies: + - name: common + repository: https://library-charts.truecharts.org + version: 11.0.3 + - condition: mariadb.enabled + name: mariadb + repository: https://charts.truecharts.org/ + version: 5.0.4 +description: The WordPress rich content management system can utilize plugins, widgets, and themes. +home: https://truecharts.org/docs/charts/incubator/wordpress +icon: https://truecharts.org/img/hotlink-ok/chart-icons/wordpress.png +keywords: + - wordpress + - cms +kubeVersion: ">=1.16.0-0" +maintainers: + - email: info@truecharts.org + name: TrueCharts + url: https://truecharts.org +name: wordpress +sources: + - https://github.com/truecharts/charts/tree/master/charts/incubator/wordpress/ + - https://hub.docker.com/_/wordpress + - https://www.wordpress.org +version: 0.0.1 +annotations: + truecharts.org/catagories: | + - website + - CMS + - Hosting + truecharts.org/SCALE-support: "true" + truecharts.org/grade: U diff --git a/charts/incubator/wordpress/README.md b/charts/incubator/wordpress/README.md new file mode 100644 index 00000000000..5aedf77dc72 --- /dev/null +++ b/charts/incubator/wordpress/README.md @@ -0,0 +1 @@ +# wordpress diff --git a/charts/incubator/wordpress/icon.png b/charts/incubator/wordpress/icon.png new file mode 100644 index 00000000000..5b3d19c0ea6 Binary files /dev/null and b/charts/incubator/wordpress/icon.png differ diff --git a/charts/incubator/wordpress/questions.yaml b/charts/incubator/wordpress/questions.yaml new file mode 100644 index 00000000000..9b53dce2b34 --- /dev/null +++ b/charts/incubator/wordpress/questions.yaml @@ -0,0 +1,247 @@ +# Include{groups} +portals: + open: +# Include{portalLink} +questions: +# Include{global} +# Include{controller} +# Include{replicas} +# Include{replica1} +# Include{controllerExpertExtraArgs} +# Include{containerConfig} + - variable: wordpress + group: App Configuration + label: WordPress Configuration + schema: + additional_attrs: true + type: dict + attrs: + - variable: user + label: User Name + description: Username for wordpress. + schema: + type: string + required: true + default: "" + - variable: pass + label: User Password + description: User Password for wordpress. + schema: + type: string + private: true + required: true + default: "" + - variable: email + label: Wordpress Email + description: WordPress application email. + schema: + type: string + required: true + default: "" + - variable: first_name + label: Wordpress First Name + description: WordPress user first name. + schema: + type: string + required: true + default: "" + - variable: last_name + label: Wordpress Last Name + description: WordPress user last name. + schema: + type: string + required: true + default: "" + - variable: blog_name + label: Wordpress Blog Name + description: WordPress blog name. + schema: + type: string + required: true + default: Truecharts Blog + - variable: smtp + group: App Configuration + label: SMTP Configuration + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: Show SMTP Settings + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: host + label: SMTP Host + schema: + type: string + default: "" + - variable: port + label: SMTP Port + schema: + type: int + default: 587 + - variable: user + label: SMTP User + schema: + type: string + default: "" + - variable: pass + label: SMTP Pass + schema: + type: string + private: true + default: "" + - variable: php-config + group: App Configuration + label: PHP Configuration + schema: + additional_attrs: true + type: dict + attrs: + - variable: PHP_ENABLE_OPCACHE + label: Enable OPCache + description: Enable OPcache for PHP scripts. + schema: + type: string + default: "yes" + - variable: PHP_EXPOSE_PHP + label: Expose PHP + description: Enables HTTP header with PHP version. + schema: + type: string + default: "" + - variable: PHP_MAX_EXECUTION_TIME + label: Max Execution Time + description: Maximum execution time for PHP scripts. + schema: + type: string + default: "" + - variable: PHP_MAX_INPUT_TIME + label: Max Input Time + description: Maximum input time for PHP scripts. + schema: + type: string + default: "" + - variable: PHP_MAX_INPUT_VARS + label: Max Input Vars + description: Maximum amount of input variables for PHP scripts. + schema: + type: string + default: "" + - variable: PHP_MEMORY_LIMIT + label: Memory Limit + description: Memory limit for PHP scripts. + schema: + type: string + default: 512M + - variable: PHP_POST_MAX_SIZE + label: Post Max Size + description: Maximum size for PHP POST requests. + schema: + type: string + default: "" + - variable: PHP_UPLOAD_MAX_FILESIZE + label: Upload Max Filesize + description: Maximum file size for PHP uploads. + schema: + type: string + default: "" +# Include{serviceRoot} + - variable: main + label: Main Service + description: The Primary service on which the healthcheck runs, often the webUI + schema: + additional_attrs: true + type: dict + attrs: +# Include{serviceSelectorLoadBalancer} +# Include{serviceSelectorExtras} + - variable: main + label: Main Service Port Configuration + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: Port + description: This port exposes the container port on the service + schema: + type: int + default: 10591 + required: true +# Include{serviceExpertRoot} + default: false +# Include{serviceExpert} +# Include{serviceList} +# Include{persistenceRoot} + - variable: config + label: App Config Storage + description: Stores the Application Config. + schema: + additional_attrs: true + type: dict + attrs: +# Include{persistenceBasic} +# Include{persistenceList} +# Include{ingressRoot} + - variable: main + label: Main Ingress + schema: + additional_attrs: true + type: dict + attrs: +# Include{ingressDefault} +# Include{ingressTLS} +# Include{ingressTraefik} +# Include{ingressList} +# Include{security} +# Include{securityContextAdvancedRoot} + - variable: privileged + label: Privileged mode + schema: + type: boolean + default: false + - variable: readOnlyRootFilesystem + label: ReadOnly Root Filesystem + schema: + type: boolean + default: false + - variable: allowPrivilegeEscalation + label: Allow Privilege Escalation + schema: + type: boolean + default: false + - variable: runAsNonRoot + label: runAsNonRoot + schema: + type: boolean + default: true +# Include{podSecurityContextRoot} + - variable: runAsUser + label: runAsUser + description: The UserID of the user running the application + schema: + type: int + default: 568 + - variable: runAsGroup + label: runAsGroup + description: The groupID this App of the user running the application + schema: + type: int + default: 0 + - variable: fsGroup + label: fsGroup + description: The group that should own ALL storage. + schema: + type: int + default: 568 +# Include{podSecurityContextAdvanced} +# Include{resources} +# Include{advanced} +# Include{addons} +# Include{codeserver} +# Include{vpn} +# Include{documentation} diff --git a/charts/incubator/wordpress/templates/_env.tpl b/charts/incubator/wordpress/templates/_env.tpl new file mode 100644 index 00000000000..62993fb546e --- /dev/null +++ b/charts/incubator/wordpress/templates/_env.tpl @@ -0,0 +1,115 @@ +{{/* Wordpress environment variables */}} +{{- define "wordpress.env" -}} + {{- $configName := printf "%s-env-config" (include "tc.common.names.fullname" .) }} + {{- $secretName := printf "%s-env-secret" (include "tc.common.names.fullname" .) }} +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ $configName }} + labels: + {{- include "tc.common.labels" . | nindent 4 }} +data: + APACHE_HTTP_PORT_NUMBER: {{ .Values.service.main.ports.main.port | quote }} + + {{/* Database */}} + WORDPRESS_DATABASE_PORT_NUMBER: "3306" + WORDPRESS_DATABASE_USER: {{ .Values.mariadb.mariadbUsername | quote }} + WORDPRESS_DATABASE_NAME: {{ .Values.mariadb.mariadbDatabase | quote }} + + {{/* Wordpress */}} + WORDPRESS_EMAIL: {{ .Values.wordpress.email | quote }} + WORDPRESS_FIRST_NAME: {{ .Values.wordpress.first_name | quote }} + WORDPRESS_LAST_NAME: {{ .Values.wordpress.last_name | quote }} + WORDPRESS_BLOG_NAME: {{ .Values.wordpress.blog_name | quote }} + + {{- if .Values.smtp.enabled }} + WORDPRESS_SMTP_HOST: {{ .Values.smtp.host | quote }} + WORDPRESS_SMTP_PORT: {{ .Values.smtp.port | quote }} + {{- end }} + + {{/* PHP */}} + {{- with .Values.wordpress.PHP_ENABLE_OPCACHE }} + PHP_ENABLE_OPCACHE: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_EXPOSE_PHP }} + PHP_EXPOSE_PHP: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_MAX_EXECUTION_TIME }} + PHP_MAX_EXECUTION_TIME: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_MAX_INPUT_TIME }} + PHP_MAX_INPUT_TIME: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_MAX_INPUT_VARS }} + PHP_MAX_INPUT_VARS: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_MEMORY_LIMIT }} + PHP_MEMORY_LIMIT: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_POST_MAX_SIZE }} + PHP_POST_MAX_SIZE: {{ . | quote }} + {{- end }} + {{- with .Values.wordpress.PHP_UPLOAD_MAX_FILESIZE }} + PHP_UPLOAD_MAX_FILESIZE: {{ . | quote }} + {{- end }} +--- +apiVersion: v1 +kind: Secret +metadata: + name: {{ $secretName }} + labels: + {{- include "tc.common.labels" . | nindent 4 }} +data: + WORDPRESS_DATABASE_HOST: {{ printf "%v-%v" .Release.Name "mariadb" | b64enc }} + WORDPRESS_DATABASE_PASSWORD: {{ .Values.mariadb.mariadbPassword | trimAll "\"" | b64enc }} + + WORDPRESS_PASSWORD: {{ .Values.wordpress.pass | quote | b64enc }} + + {{- if .Values.smtp.enabled }} + WORDPRESS_SMTP_USER: {{ .Values.smtp.user | quote | b64enc }} + WORDPRESS_SMTP_PASSWORD: {{ .Values.smtp.pass | quote | b64enc }} + {{- end }} + + {{/* Salts */}} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_AUTH_KEY: {{ index .data "WORDPRESS_AUTH_KEY" }} + {{- else }} + WORDPRESS_AUTH_KEY: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_SECURE_AUTH_KEY: {{ index .data "WORDPRESS_SECURE_AUTH_KEY" }} + {{- else }} + WORDPRESS_SECURE_AUTH_KEY: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_LOGGED_IN_KEY: {{ index .data "WORDPRESS_LOGGED_IN_KEY" }} + {{- else }} + WORDPRESS_LOGGED_IN_KEY: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_NONCE_KEY: {{ index .data "WORDPRESS_NONCE_KEY" }} + {{- else }} + WORDPRESS_NONCE_KEY: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_AUTH_SALT: {{ index .data "WORDPRESS_AUTH_SALT" }} + {{- else }} + WORDPRESS_AUTH_SALT: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_SECURE_AUTH_SALT: {{ index .data "WORDPRESS_SECURE_AUTH_SALT" }} + {{- else }} + WORDPRESS_SECURE_AUTH_SALT: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_LOGGED_IN_SALT: {{ index .data "WORDPRESS_LOGGED_IN_SALT" }} + {{- else }} + WORDPRESS_LOGGED_IN_SALT: {{ randAlphaNum 32 | b64enc }} + {{- end }} + {{- with (lookup "v1" "Secret" .Release.Namespace $secretName) }} + WORDPRESS_NONCE_SALT: {{ index .data "WORDPRESS_NONCE_SALT" }} + {{- else }} + WORDPRESS_NONCE_SALT: {{ randAlphaNum 32 | b64enc }} + {{- end }} +{{- end }} diff --git a/charts/incubator/wordpress/templates/common.yaml b/charts/incubator/wordpress/templates/common.yaml new file mode 100644 index 00000000000..14855161e4e --- /dev/null +++ b/charts/incubator/wordpress/templates/common.yaml @@ -0,0 +1,8 @@ +{{/* Make sure all variables are set properly */}} +{{- include "tc.common.loader.init" . }} + +{{/* Plausible environment variables */}} +{{- include "wordpress.env" . }} + +{{/* Render the templates */}} +{{ include "tc.common.loader.apply" . }} diff --git a/charts/incubator/wordpress/values.yaml b/charts/incubator/wordpress/values.yaml new file mode 100644 index 00000000000..cc2e091703e --- /dev/null +++ b/charts/incubator/wordpress/values.yaml @@ -0,0 +1,62 @@ +image: + repository: tccr.io/truecharts/wordpress + pullPolicy: IfNotPresent + tag: 6.1.1@sha256:e8e4080c7cdb2f1b33710fd2db137ce89847af879d7bfd44dcad1a006f70a66d + +securityContext: + readOnlyRootFilesystem: false + +podSecurityContext: + runAsGroup: 0 + +wordpress: + user: user + pass: bitnami + email: user@example.com + first_name: TrueCharts + last_name: TrueCharts + blog_name: Truecharts Blog + +smtp: + enabled: false + host: "" + port: "" + user: "" + pass: "" + +php-config: + PHP_ENABLE_OPCACHE: "yes" + PHP_EXPOSE_PHP: "" + PHP_MAX_EXECUTION_TIME: "" + PHP_MAX_INPUT_TIME: "" + PHP_MAX_INPUT_VARS: "" + PHP_MEMORY_LIMIT: 512M + PHP_POST_MAX_SIZE: "" + PHP_UPLOAD_MAX_FILESIZE: "" + +envFrom: + - configMapRef: + name: '{{ include "tc.common.names.fullname" . }}-env-config' + - secretRef: + name: '{{ include "tc.common.names.fullname" . }}-env-secret' + +service: + main: + ports: + main: + protocol: HTTP + port: 10591 + +persistence: + config: + enabled: true + mountPath: /bitnami/wordpress + +mariadb: + enabled: true + mariadbUsername: wordpress + mariadbDatabase: wordpress + existingSecret: mariadbcreds + +portal: + enabled: true