diff --git a/packages/twenty-docker/helm/twenty/templates/_helpers.tpl b/packages/twenty-docker/helm/twenty/templates/_helpers.tpl index 661fb67c252..71f7553357a 100644 --- a/packages/twenty-docker/helm/twenty/templates/_helpers.tpl +++ b/packages/twenty-docker/helm/twenty/templates/_helpers.tpl @@ -89,6 +89,15 @@ password {{- end -}} {{- end -}} +{{/* Check if using external secret for redis password */}} +{{- define "twenty.redis.useExternalSecret" -}} +{{- if and (not .Values.redisInternal.enabled) .Values.redis.external.secretName .Values.redis.external.passwordKey -}} +true +{{- else -}} +false +{{- end -}} +{{- end -}} + {{/* Compose Redis URL */}} {{- define "twenty.redisUrl" -}} {{- if .Values.server.env.REDIS_URL -}} @@ -99,7 +108,16 @@ password {{- else -}} {{- $host := .Values.redis.external.host | default "redis" -}} {{- $port := .Values.redis.external.port | default 6379 -}} -{{- printf "redis://%s:%v" $host $port -}} +{{- if or (eq (include "twenty.redis.useExternalSecret" .) "true") (.Values.redis.external.password) -}} +{{- $auth := "$(REDIS_PASSWORD)@" -}} +{{- printf "redis://%s%s:%v" $auth $host $port -}} +{{- else if .Values.redis.external.password -}} +{{- $auth := "$(REDIS_PASSWORD)@" -}} +{{- printf "redis://%s%s:%v" $auth $host $port -}} +{{- else -}} +{{- $auth := "" -}} +{{- printf "redis://%s%s:%v" $auth $host $port -}} +{{- end -}} {{- end -}} {{- end -}} diff --git a/packages/twenty-docker/helm/twenty/templates/deployment-server.yaml b/packages/twenty-docker/helm/twenty/templates/deployment-server.yaml index d2b4f154710..8bf8ed7428d 100644 --- a/packages/twenty-docker/helm/twenty/templates/deployment-server.yaml +++ b/packages/twenty-docker/helm/twenty/templates/deployment-server.yaml @@ -83,16 +83,16 @@ spec: psql -h {{ include "twenty.fullname" . }}-db -p 5432 -U postgres -d postgres -v db="${DBNAME}" -Atc "SELECT 1 FROM pg_database WHERE datname = :'db'" | grep -q 1 || \ psql -h {{ include "twenty.fullname" . }}-db -p 5432 -U postgres -d postgres -v db="${DBNAME}" -c 'CREATE DATABASE :"db";' echo "Creating app user ${APP_USER} if it doesn't exist..." - psql -h {{ include "twenty.fullname" . }}-db -p 5432 -U postgres -d postgres -v app_user="${APP_USER}" -v app_password="${APP_PASSWORD}" <<'EOSQL' - DO - $do$ - BEGIN - IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = :'app_user') THEN - EXECUTE format('CREATE USER %I WITH PASSWORD %L', :'app_user', :'app_password'); - END IF; - END - $do$; - EOSQL + psql -h {{ include "twenty.fullname" . }}-db -p 5432 -U postgres -d postgres -v app_user="${APP_USER}" -v app_password="${APP_PASSWORD}" <<'EOSQL' + DO + $do$ + BEGIN + IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = :'app_user') THEN + EXECUTE format('CREATE USER %I WITH PASSWORD %L', :'app_user', :'app_password'); + END IF; + END + $do$; + EOSQL echo "Creating core schema and granting permissions..." psql -h {{ include "twenty.fullname" . }}-db -p 5432 -U postgres -d "${DBNAME}" -v app_user="${APP_USER}" -c 'CREATE SCHEMA IF NOT EXISTS core' psql -h {{ include "twenty.fullname" . }}-db -p 5432 -U postgres -d "${DBNAME}" -v db="${DBNAME}" -v app_user="${APP_USER}" -c 'GRANT ALL PRIVILEGES ON DATABASE :"db" TO :"app_user";' @@ -107,7 +107,7 @@ spec: echo "Database ${DBNAME} is ready." {{- end }} - name: run-migrations - {{- $img := include "twenty.server.image" . }} + {{- $img := include "twenty.server.image" . }} image: {{ include "twenty.image.repository" $img }}:{{ include "twenty.image.tag" $img }} imagePullPolicy: {{ include "twenty.image.pullPolicy" $img }} command: @@ -116,7 +116,7 @@ spec: - >- npx -y typeorm migration:run -d dist/database/typeorm/core/core.datasource env: - {{- if eq (include "twenty.db.useExternalSecret" .) "true" }} + {{- if eq (include "twenty.db.useExternalSecret" .) "true" }} - name: DB_PASSWORD valueFrom: secretKeyRef: @@ -124,22 +124,22 @@ spec: key: {{ include "twenty.dbPassword.secretKey" . }} - name: PG_DATABASE_URL value: {{ include "twenty.dbUrl.template" . | quote }} - {{- else }} + {{- else }} - name: PG_DATABASE_URL valueFrom: secretKeyRef: name: {{ include "twenty.dbUrl.secretName" . }} key: url - {{- end }} + {{- end }} containers: - name: server - {{- $img := include "twenty.server.image" . }} + {{- $img := include "twenty.server.image" . }} image: {{ include "twenty.image.repository" $img }}:{{ include "twenty.image.tag" $img }} imagePullPolicy: {{ include "twenty.image.pullPolicy" $img }} env: - name: SERVER_URL value: {{ include "twenty.serverUrl" . | quote }} - {{- if eq (include "twenty.db.useExternalSecret" .) "true" }} + {{- if eq (include "twenty.db.useExternalSecret" .) "true" }} - name: DB_PASSWORD valueFrom: secretKeyRef: @@ -147,13 +147,23 @@ spec: key: {{ include "twenty.dbPassword.secretKey" . }} - name: PG_DATABASE_URL value: {{ include "twenty.dbUrl.template" . | quote }} - {{- else }} + {{- else }} - name: PG_DATABASE_URL valueFrom: secretKeyRef: name: {{ include "twenty.dbUrl.secretName" . }} key: url - {{- end }} + {{- end }} + {{- if eq (include "twenty.redis.useExternalSecret" .) "true" }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ .Values.redis.external.secretName }} + key: {{ .Values.redis.external.passwordKey }} + {{- else if .Values.redis.external.password }} + - name: REDIS_PASSWORD + value: {{ .Values.redis.external.password | quote }} + {{- end }} - name: REDIS_URL value: {{ include "twenty.redisUrl" . | quote }} - name: SIGN_IN_PREFILLED @@ -169,10 +179,10 @@ spec: secretKeyRef: name: {{ include "twenty.secret.tokens.name" . }} key: accessToken - {{- $storageEnv := (include "twenty.storageEnv" .) }} - {{- if $storageEnv }} - {{ $storageEnv | nindent 12 }} - {{- end }} + {{- $storageEnv := (include "twenty.storageEnv" .) }} + {{- if $storageEnv }} + {{ $storageEnv | nindent 12 }} + {{- end }} ports: - name: http-tcp containerPort: {{ include "twenty.server.containerPort" . }} @@ -194,23 +204,23 @@ spec: timeoutSeconds: 5 failureThreshold: 5 resources: - {{- toYaml .Values.server.resources | nindent 12 }} + {{- toYaml .Values.server.resources | nindent 12 }} volumeMounts: - {{- if .Values.server.dockerDataPersistence.enabled }} + {{- if .Values.server.dockerDataPersistence.enabled }} - name: docker-data mountPath: /app/docker-data - {{- end }} - {{- if .Values.server.persistence.enabled }} + {{- end }} + {{- if .Values.server.persistence.enabled }} - name: server-data mountPath: /app/packages/twenty-server/.local-storage - {{- end }} - {{- with .Values.server.extraVolumeMounts }} - {{- toYaml . | nindent 12 }} - {{- end }} - {{- if .Values.server.stdin }} + {{- end }} + {{- with .Values.server.extraVolumeMounts }} + {{- toYaml . | nindent 12 }} + {{- end }} + {{- if .Values.server.stdin }} stdin: {{ .Values.server.stdin }} - {{- end }} - {{- if .Values.server.tty }} + {{- end }} + {{- if .Values.server.tty }} tty: {{ .Values.server.tty }} - {{- end }} -{{- end }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/packages/twenty-docker/helm/twenty/templates/deployment-worker.yaml b/packages/twenty-docker/helm/twenty/templates/deployment-worker.yaml index dc47d13a08b..fb9a43bda8c 100644 --- a/packages/twenty-docker/helm/twenty/templates/deployment-worker.yaml +++ b/packages/twenty-docker/helm/twenty/templates/deployment-worker.yaml @@ -67,6 +67,16 @@ spec: name: {{ include "twenty.dbUrl.secretName" . }} key: url {{- end }} + {{- if eq (include "twenty.redis.useExternalSecret" .) "true" }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ .Values.redis.external.secretName }} + key: {{ .Values.redis.external.passwordKey }} + {{- else if .Values.redis.external.password }} + - name: REDIS_PASSWORD + value: {{ .Values.redis.external.password | quote }} + {{- end }} - name: REDIS_URL value: {{ include "twenty.redisUrl" . | quote }} - name: STORAGE_TYPE