From 232ba7da0e35d6f910c1744782015f8e889bfb04 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9bastien=20Huss?= Date: Tue, 12 Sep 2023 16:54:28 +0200 Subject: [PATCH] fix --- apps/nextcloud/index.yaml | 210 +++++++++++++++++----------------- apps/nextcloud/ingress.tf | 2 +- apps/nextcloud/middlewares.tf | 15 +++ 3 files changed, 121 insertions(+), 106 deletions(-) diff --git a/apps/nextcloud/index.yaml b/apps/nextcloud/index.yaml index 3e8b2b4..1fcc499 100644 --- a/apps/nextcloud/index.yaml +++ b/apps/nextcloud/index.yaml @@ -6,6 +6,36 @@ metadata: name: nextcloud description: null options: + openid-name: + default: vynil + examples: + - vynil + type: string + postgres: + default: + replicas: 1 + storage: 5Gi + version: '14' + examples: + - replicas: 1 + storage: 5Gi + version: '14' + properties: + replicas: + default: 1 + type: integer + storage: + default: 5Gi + type: string + version: + default: '14' + type: string + type: object + issuer: + default: letsencrypt-prod + examples: + - letsencrypt-prod + type: string images: default: collabora: @@ -169,59 +199,21 @@ options: type: string type: object type: object - redis: - default: - exporter: - enabled: true - image: quay.io/opstree/redis-exporter:v1.44.0 - image: quay.io/opstree/redis:v7.0.5 - storage: 2Gi - examples: - - exporter: - enabled: true - image: quay.io/opstree/redis-exporter:v1.44.0 - image: quay.io/opstree/redis:v7.0.5 - storage: 2Gi - properties: - exporter: - default: - enabled: true - image: quay.io/opstree/redis-exporter:v1.44.0 - properties: - enabled: - default: true - type: boolean - image: - default: quay.io/opstree/redis-exporter:v1.44.0 - type: string - type: object - image: - default: quay.io/opstree/redis:v7.0.5 - type: string - storage: - default: 2Gi - type: string - type: object - admin: - default: - name: nextcloud_admin - examples: - - name: nextcloud_admin - properties: - name: - default: nextcloud_admin - type: string - type: object - sub-domain: - default: files - examples: - - files - type: string domain: default: your-company examples: - your-company type: string + domain-name: + default: your_company.com + examples: + - your_company.com + type: string + ingress-class: + default: traefik + examples: + - traefik + type: string apps: default: audioplayer: false @@ -312,50 +304,6 @@ options: default: true type: boolean type: object - storage: - default: - accessMode: ReadWriteOnce - size: 10Gi - examples: - - accessMode: ReadWriteOnce - size: 10Gi - properties: - accessMode: - default: ReadWriteOnce - enum: - - ReadWriteOnce - - ReadOnlyMany - - ReadWriteMany - type: string - size: - default: 10Gi - type: string - type: object - domain-name: - default: your_company.com - examples: - - your_company.com - type: string - postgres: - default: - replicas: 1 - storage: 5Gi - version: '14' - examples: - - replicas: 1 - storage: 5Gi - version: '14' - properties: - replicas: - default: 1 - type: integer - storage: - default: 5Gi - type: string - version: - default: '14' - type: string - type: object hpa: default: avg-cpu: 50 @@ -376,16 +324,6 @@ options: default: 1 type: integer type: object - ingress-class: - default: traefik - examples: - - traefik - type: string - openid-name: - default: vynil - examples: - - vynil - type: string backups: default: enable: false @@ -492,11 +430,73 @@ options: default: false type: boolean type: object - issuer: - default: letsencrypt-prod + admin: + default: + name: nextcloud_admin examples: - - letsencrypt-prod + - name: nextcloud_admin + properties: + name: + default: nextcloud_admin + type: string + type: object + storage: + default: + accessMode: ReadWriteOnce + size: 10Gi + examples: + - accessMode: ReadWriteOnce + size: 10Gi + properties: + accessMode: + default: ReadWriteOnce + enum: + - ReadWriteOnce + - ReadOnlyMany + - ReadWriteMany + type: string + size: + default: 10Gi + type: string + type: object + sub-domain: + default: files + examples: + - files type: string + redis: + default: + exporter: + enabled: true + image: quay.io/opstree/redis-exporter:v1.44.0 + image: quay.io/opstree/redis:v7.0.5 + storage: 2Gi + examples: + - exporter: + enabled: true + image: quay.io/opstree/redis-exporter:v1.44.0 + image: quay.io/opstree/redis:v7.0.5 + storage: 2Gi + properties: + exporter: + default: + enabled: true + image: quay.io/opstree/redis-exporter:v1.44.0 + properties: + enabled: + default: true + type: boolean + image: + default: quay.io/opstree/redis-exporter:v1.44.0 + type: string + type: object + image: + default: quay.io/opstree/redis:v7.0.5 + type: string + storage: + default: 2Gi + type: string + type: object dependencies: - dist: null category: share diff --git a/apps/nextcloud/ingress.tf b/apps/nextcloud/ingress.tf index 00545b4..09b5a32 100644 --- a/apps/nextcloud/ingress.tf +++ b/apps/nextcloud/ingress.tf @@ -1,6 +1,6 @@ locals { dns-names = [local.dns-name] - middlewares = ["${var.instance}-https","${var.instance}-redirectdav","${var.instance}-redirectindex"] + middlewares = ["${var.instance}-https","${var.instance}-sslenforce","${var.instance}-redirectdav","${var.instance}-redirectindex"] service = { "name" = "${var.component}" "port" = { diff --git a/apps/nextcloud/middlewares.tf b/apps/nextcloud/middlewares.tf index 3b2bf23..500d2e2 100644 --- a/apps/nextcloud/middlewares.tf +++ b/apps/nextcloud/middlewares.tf @@ -28,3 +28,18 @@ spec: replacement: "https://$${1}/index.php/.well-known/$${2}" EOF } + +resource "kubectl_manifest" "sslenforce" { + yaml_body = <<-EOF +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: "${var.instance}-sslenforce" + namespace: "${var.namespace}" + labels: ${jsonencode(local.common-labels)} +spec: + headers: + stsSeconds: 15552000 + stsIncludeSubdomains: true + EOF +}