Bläddra i källkod

vaultwarden - migrate storage section (#1766)

* vaultwarden - migrate storage section

* remove test file open

* optimize

* remove empty lines

* fix logic

* restore immutable flag
Stavros Kois 1 år sedan
förälder
incheckning
6c35baa25c

+ 3 - 3
library/ix-dev/community/vaultwarden/Chart.lock

@@ -1,6 +1,6 @@
 dependencies:
 - name: common
   repository: file://../../../common
-  version: 1.2.2
-digest: sha256:fb077cb81f6acecd5c9e6adc22a18e156f780cd78f27198cdb47810f95364b56
-generated: "2023-11-09T15:45:15.689857509+02:00"
+  version: 1.2.3
+digest: sha256:e6ff49b06bf5d4d159e505ae6d153f36cd46170bb519caf90462cd5caebfd0fb
+generated: "2023-11-20T09:34:08.912493488+02:00"

+ 3 - 3
library/ix-dev/community/vaultwarden/Chart.yaml

@@ -3,9 +3,9 @@ description: Alternative implementation of the Bitwarden server API written in R
 annotations:
   title: Vaultwarden
 type: application
-version: 1.0.29
+version: 1.1.0
 apiVersion: v2
-appVersion: 1.30.0
+appVersion: 1.30.1
 kubeVersion: '>=1.16.0-0'
 maintainers:
   - name: truenas
@@ -14,7 +14,7 @@ maintainers:
 dependencies:
   - name: common
     repository: file://../../../common
-    version: 1.2.2
+    version: 1.2.3
 home: https://github.com/dani-garcia/vaultwarden
 icon: https://media.sys.truenas.net/apps/vaultwarden/icons/icon.png
 sources:

BIN
library/ix-dev/community/vaultwarden/charts/common-1.2.2.tgz


BIN
library/ix-dev/community/vaultwarden/charts/common-1.2.3.tgz


+ 3 - 6
library/ix-dev/community/vaultwarden/ci/additional-env-values.yaml

@@ -1,13 +1,10 @@
 vaultwardenStorage:
   data:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/data
+    type: pvc
   pgData:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgData
+    type: pvc
   pgBackup:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgBackup
+    type: emptyDir
 
 vaultwardenConfig:
   additionalEnvs:

+ 3 - 6
library/ix-dev/community/vaultwarden/ci/admin-values.yaml

@@ -1,13 +1,10 @@
 vaultwardenStorage:
   data:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/data
+    type: pvc
   pgData:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgData
+    type: pvc
   pgBackup:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgBackup
+    type: emptyDir
 
 vaultwardenConfig:
   adminToken: "super-long-secret-password"

+ 3 - 6
library/ix-dev/community/vaultwarden/ci/basic-values.yaml

@@ -1,10 +1,7 @@
 vaultwardenStorage:
   data:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/data
+    type: pvc
   pgData:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgData
+    type: pvc
   pgBackup:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgBackup
+    type: emptyDir

+ 3 - 6
library/ix-dev/community/vaultwarden/ci/https-values.yaml

@@ -1,13 +1,10 @@
 vaultwardenStorage:
   data:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/data
+    type: pvc
   pgData:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgData
+    type: pvc
   pgBackup:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgBackup
+    type: emptyDir
 
 vaultwardenNetwork:
   certificateID: 1

+ 3 - 6
library/ix-dev/community/vaultwarden/ci/other-user-values.yaml

@@ -1,13 +1,10 @@
 vaultwardenStorage:
   data:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/data
+    type: pvc
   pgData:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgData
+    type: pvc
   pgBackup:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgBackup
+    type: emptyDir
 
 vaultwardenRunAs:
   user: 1000

+ 3 - 6
library/ix-dev/community/vaultwarden/ci/ws-disabled-values.yaml

@@ -1,13 +1,10 @@
 vaultwardenStorage:
   data:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/data
+    type: pvc
   pgData:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgData
+    type: pvc
   pgBackup:
-    type: hostPath
-    hostPath: /mnt/{{ .Release.Name }}/pgBackup
+    type: emptyDir
 
 vaultwardenNetwork:
   wsEnabled: false

+ 34 - 8
library/ix-dev/community/vaultwarden/migrations/migrate

@@ -4,18 +4,44 @@ import os
 import sys
 
 
-def migrate(values):
-    storageKey = 'vaultwardenStorage'
-    storages = ['data', 'pgData', 'pgData']
+def storage_migrate(storage):
+    delete_keys = []
+    if storage['type'] == 'hostPath':
+        # Check if the key exists, if not we have already migrated
+        if not storage.get('hostPath'):
+            return storage
 
+        storage['hostPathConfig'] = {'hostPath': storage['hostPath']}
+        delete_keys.append('hostPath')
 
-    for storage in storages:
-        check_val = values.get(storageKey, {}).get(storage, {})
-        if not isinstance(check_val, dict) or not check_val or check_val.get('type', 'hostPath') == 'hostPath':
-            continue
+    elif storage['type'] == 'ixVolume':
+        # Check if the key exists, if not we have already migrated
+        if not storage.get('datasetName'):
+            return storage
+
+        storage['ixVolumeConfig'] = {'datasetName': storage['datasetName']}
+        delete_keys.append('datasetName')
+
+        # Clean up for some older versions.
+        if storage.get('hostPath'):
+            delete_keys.append('hostPath')
+
+    for key in delete_keys:
+        storage.pop(key, None)
 
-        values[storageKey][storage] = {key: value for key, value in check_val.items() if key != 'hostPath'}
+    return storage
+
+
+def migrate(values):
+    storage_key = 'vaultwardenStorage'
+    storages = ['data', 'pgData', 'pgBackup']
+
+    for storage in storages:
+        check_val = values.get(storage_key, {}).get(storage, {})
+        if not isinstance(check_val, dict) or not check_val:
+            raise Exception(f'Storage section {storage} is malformed')
 
+        values[storage_key][storage] = storage_migrate(check_val)
 
     return values
 

+ 319 - 36
library/ix-dev/community/vaultwarden/questions.yaml

@@ -182,24 +182,65 @@ questions:
                       description: Host Path (Path that already exists on the system)
                     - value: ixVolume
                       description: ixVolume (Dataset created automatically by the system)
-              - variable: datasetName
-                label: Dataset Name
+              - variable: ixVolumeConfig
+                label: ixVolume Configuration
+                description: The configuration for the ixVolume dataset.
                 schema:
-                  type: string
+                  type: dict
                   show_if: [["type", "=", "ixVolume"]]
-                  required: true
-                  hidden: true
-                  immutable: true
-                  default: data
                   $ref:
                     - "normalize/ixVolume"
-              - variable: hostPath
-                label: Host Path
+                  attrs:
+                    - variable: aclEnable
+                      label: Enable ACL
+                      description: Enable ACL for the dataset.
+                      schema:
+                        type: boolean
+                        default: false
+                    - variable: datasetName
+                      label: Dataset Name
+                      description: The name of the dataset to use for storage.
+                      schema:
+                        type: string
+                        required: true
+                        immutable: true
+                        hidden: true
+                        default: "data"
+                    - variable: aclEntries
+                      label: ACL Configuration
+                      schema:
+                        type: dict
+                        show_if: [["aclEnable", "=", true]]
+                        attrs: []
+              - variable: hostPathConfig
+                label: hostPathConfig
                 schema:
-                  type: hostpath
+                  type: dict
                   show_if: [["type", "=", "hostPath"]]
-                  immutable: true
-                  required: true
+                  attrs:
+                    - variable: aclEnable
+                      label: Enable ACL
+                      description: Enable ACL for the dataset.
+                      schema:
+                        type: boolean
+                        default: false
+                    - variable: acl
+                      label: ACL Configuration
+                      schema:
+                        type: dict
+                        show_if: [["aclEnable", "=", true]]
+                        attrs: []
+                        $ref:
+                          - "normalize/acl"
+                    - variable: hostPath
+                      label: Host Path
+                      description: The host path to use for storage.
+                      schema:
+                        type: hostpath
+                        show_if: [["aclEnable", "=", false]]
+                        immutable: true
+                        required: true
+
         - variable: pgData
           label: Vaultwarden Postgres Data Storage
           description: The path to store Vaultwarden Postgres Data.
@@ -221,24 +262,73 @@ questions:
                       description: Host Path (Path that already exists on the system)
                     - value: ixVolume
                       description: ixVolume (Dataset created automatically by the system)
-              - variable: datasetName
-                label: Dataset Name
+              - variable: ixVolumeConfig
+                label: ixVolume Configuration
+                description: The configuration for the ixVolume dataset.
                 schema:
-                  type: string
-                  show_if: [["type", "=", "ixVolume"]]
-                  required: true
+                  type: dict
+                  # Nothing to show for the user
                   hidden: true
-                  immutable: true
-                  default: pgData
+                  show_if: [["type", "=", "ixVolume"]]
                   $ref:
                     - "normalize/ixVolume"
-              - variable: hostPath
-                label: Host Path
+                  attrs:
+                    - variable: aclEnable
+                      label: Enable ACL
+                      description: Enable ACL for the dataset.
+                      schema:
+                        type: boolean
+                        # Postgres does a CHMOD at startup
+                        # Which fails with ACL
+                        hidden: true
+                        default: false
+                    - variable: datasetName
+                      label: Dataset Name
+                      description: The name of the dataset to use for storage.
+                      schema:
+                        type: string
+                        required: true
+                        immutable: true
+                        hidden: true
+                        default: "pgData"
+                    - variable: aclEntries
+                      label: ACL Configuration
+                      schema:
+                        type: dict
+                        show_if: [["aclEnable", "=", true]]
+                        attrs: []
+              - variable: hostPathConfig
+                label: hostPathConfig
                 schema:
-                  type: hostpath
+                  type: dict
                   show_if: [["type", "=", "hostPath"]]
-                  immutable: true
-                  required: true
+                  attrs:
+                    - variable: aclEnable
+                      label: Enable ACL
+                      description: Enable ACL for the dataset.
+                      schema:
+                        type: boolean
+                        # Postgres does a CHMOD at startup
+                        # Which fails with ACL
+                        hidden: true
+                        default: false
+                    - variable: acl
+                      label: ACL Configuration
+                      schema:
+                        type: dict
+                        show_if: [["aclEnable", "=", true]]
+                        attrs: []
+                        $ref:
+                          - "normalize/acl"
+                    - variable: hostPath
+                      label: Host Path
+                      description: The host path to use for storage.
+                      schema:
+                        type: hostpath
+                        show_if: [["aclEnable", "=", false]]
+                        immutable: true
+                        required: true
+
         - variable: pgBackup
           label: Vaultwarden Postgres Backup Storage
           description: The path to store Vaultwarden Postgres Backup.
@@ -260,24 +350,217 @@ questions:
                       description: Host Path (Path that already exists on the system)
                     - value: ixVolume
                       description: ixVolume (Dataset created automatically by the system)
-              - variable: datasetName
-                label: Dataset Name
+              - variable: ixVolumeConfig
+                label: ixVolume Configuration
+                description: The configuration for the ixVolume dataset.
                 schema:
-                  type: string
-                  show_if: [["type", "=", "ixVolume"]]
-                  required: true
+                  type: dict
+                  # Nothing to show for the user
                   hidden: true
-                  immutable: true
-                  default: pgBackup
+                  show_if: [["type", "=", "ixVolume"]]
                   $ref:
                     - "normalize/ixVolume"
-              - variable: hostPath
-                label: Host Path
+                  attrs:
+                    - variable: aclEnable
+                      label: Enable ACL
+                      description: Enable ACL for the dataset.
+                      schema:
+                        type: boolean
+                        # Postgres does a CHMOD at startup
+                        # Which fails with ACL
+                        hidden: true
+                        default: false
+                    - variable: datasetName
+                      label: Dataset Name
+                      description: The name of the dataset to use for storage.
+                      schema:
+                        type: string
+                        required: true
+                        immutable: true
+                        hidden: true
+                        default: "pgBackup"
+                    - variable: aclEntries
+                      label: ACL Configuration
+                      schema:
+                        type: dict
+                        show_if: [["aclEnable", "=", true]]
+                        attrs: []
+              - variable: hostPathConfig
+                label: hostPathConfig
                 schema:
-                  type: hostpath
+                  type: dict
                   show_if: [["type", "=", "hostPath"]]
-                  immutable: true
-                  required: true
+                  attrs:
+                    - variable: aclEnable
+                      label: Enable ACL
+                      description: Enable ACL for the dataset.
+                      schema:
+                        type: boolean
+                        # Postgres does a CHMOD at startup
+                        # Which fails with ACL
+                        hidden: true
+                        default: false
+                    - variable: acl
+                      label: ACL Configuration
+                      schema:
+                        type: dict
+                        show_if: [["aclEnable", "=", true]]
+                        attrs: []
+                        $ref:
+                          - "normalize/acl"
+                    - variable: hostPath
+                      label: Host Path
+                      description: The host path to use for storage.
+                      schema:
+                        type: hostpath
+                        show_if: [["aclEnable", "=", false]]
+                        immutable: true
+                        required: true
+
+        - variable: additionalStorages
+          label: Additional Storage
+          description: Additional storage for Vaultwarden.
+          schema:
+            type: list
+            default: []
+            items:
+              - variable: storageEntry
+                label: Storage Entry
+                schema:
+                  type: dict
+                  attrs:
+                    - variable: type
+                      label: Type
+                      description: |
+                        ixVolume: Is dataset created automatically by the system.</br>
+                        Host Path: Is a path that already exists on the system.</br>
+                        SMB Share: Is a SMB share that is mounted to a persistent volume claim.
+                      schema:
+                        type: string
+                        required: true
+                        default: "ixVolume"
+                        immutable: true
+                        enum:
+                          - value: "hostPath"
+                            description: Host Path (Path that already exists on the system)
+                          - value: "ixVolume"
+                            description: ixVolume (Dataset created automatically by the system)
+                          - value: "smb-pv-pvc"
+                            description: SMB Share (Mounts a persistent volume claim to a SMB share)
+                    - variable: readOnly
+                      label: Read Only
+                      description: Mount the volume as read only.
+                      schema:
+                        type: boolean
+                        default: false
+                    - variable: mountPath
+                      label: Mount Path
+                      description: The path inside the container to mount the storage.
+                      schema:
+                        type: path
+                        required: true
+                    - variable: hostPathConfig
+                      label: hostPathConfig
+                      schema:
+                        type: dict
+                        show_if: [["type", "=", "hostPath"]]
+                        attrs:
+                          - variable: aclEnable
+                            label: Enable ACL
+                            description: Enable ACL for the dataset.
+                            schema:
+                              type: boolean
+                              default: false
+                          - variable: acl
+                            label: ACL Configuration
+                            schema:
+                              type: dict
+                              show_if: [["aclEnable", "=", true]]
+                              attrs: []
+                              $ref:
+                                - "normalize/acl"
+                          - variable: hostPath
+                            label: Host Path
+                            description: The host path to use for storage.
+                            schema:
+                              type: hostpath
+                              show_if: [["aclEnable", "=", false]]
+                              immutable: true
+                              required: true
+                    - variable: ixVolumeConfig
+                      label: ixVolume Configuration
+                      description: The configuration for the ixVolume dataset.
+                      schema:
+                        type: dict
+                        show_if: [["type", "=", "ixVolume"]]
+                        $ref:
+                          - "normalize/ixVolume"
+                        attrs:
+                          - variable: aclEnable
+                            label: Enable ACL
+                            description: Enable ACL for the dataset.
+                            schema:
+                              type: boolean
+                              default: false
+                          - variable: datasetName
+                            label: Dataset Name
+                            description: The name of the dataset to use for storage.
+                            schema:
+                              type: string
+                              required: true
+                              immutable: true
+                              default: "storage_entry"
+                          - variable: aclEntries
+                            label: ACL Configuration
+                            schema:
+                              type: dict
+                              show_if: [["aclEnable", "=", true]]
+                              attrs: []
+                    - variable: smbConfig
+                      label: SMB Share Configuration
+                      description: The configuration for the SMB Share.
+                      schema:
+                        type: dict
+                        show_if: [["type", "=", "smb-pv-pvc"]]
+                        attrs:
+                          - variable: server
+                            label: Server
+                            description: The server for the SMB share.
+                            schema:
+                              type: string
+                              required: true
+                          - variable: share
+                            label: Share
+                            description: The share name for the SMB share.
+                            schema:
+                              type: string
+                              required: true
+                          - variable: domain
+                            label: Domain (Optional)
+                            description: The domain for the SMB share.
+                            schema:
+                              type: string
+                          - variable: username
+                            label: Username
+                            description: The username for the SMB share.
+                            schema:
+                              type: string
+                              required: true
+                          - variable: password
+                            label: Password
+                            description: The password for the SMB share.
+                            schema:
+                              type: string
+                              required: true
+                              private: true
+                          - variable: size
+                            label: Size (in Gi)
+                            description: The size of the volume quota.
+                            schema:
+                              type: int
+                              required: true
+                              min: 1
+                              default: 1
 
   - variable: resources
     label: ""

+ 2 - 0
library/ix-dev/community/vaultwarden/templates/_postgres.tpl

@@ -7,6 +7,8 @@ workload:
 service:
   {{- include "ix.v1.common.app.postgresService" $ | nindent 2 }}
 
+{{- include "vaultwarden.storage.ci.migration" (dict "storage" .Values.vaultwardenStorage.pgData) }}
+{{- include "vaultwarden.storage.ci.migration" (dict "storage" .Values.vaultwardenStorage.pgBackup) }}
 {{/* Persistence */}}
 persistence:
   {{- include "ix.v1.common.app.postgresPersistence"

+ 23 - 9
library/ix-dev/community/vaultwarden/templates/_vaultwarden.tpl

@@ -55,10 +55,6 @@ workload:
               type: exec
               command: /healthcheck.sh
       initContainers:
-      {{- include "ix.v1.common.app.permissions" (dict "containerName" "01-permissions"
-                                                        "UID" .Values.vaultwardenRunAs.user
-                                                        "GID" .Values.vaultwardenRunAs.group
-                                                        "type" "install") | nindent 8 }}
       {{- include "ix.v1.common.app.postgresWait" (dict "name" "postgres-wait"
                                                         "secretName" "postgres-creds") | nindent 8 }}
 
@@ -86,15 +82,22 @@ service:
 persistence:
   data:
     enabled: true
-    type: {{ .Values.vaultwardenStorage.data.type }}
-    datasetName: {{ .Values.vaultwardenStorage.data.datasetName | default "" }}
-    hostPath: {{ .Values.vaultwardenStorage.data.hostPath | default "" }}
+    {{- include "vaultwarden.storage.ci.migration" (dict "storage" .Values.vaultwardenStorage.data) }}
+    {{- include "ix.v1.common.app.storageOptions" (dict "storage" .Values.vaultwardenStorage.data) | nindent 4 }}
     targetSelector:
       vaultwarden:
         vaultwarden:
           mountPath: /data
-        01-permissions:
-          mountPath: /mnt/directories/data
+
+  {{- range $idx, $storage := .Values.vaultwardenStorage.additionalStorages }}
+  {{ printf "vaultwarden-%v:" (int $idx) }}
+    enabled: true
+    {{- include "ix.v1.common.app.storageOptions" (dict "storage" $storage) | nindent 4 }}
+    targetSelector:
+      vaultwarden:
+        vaultwarden:
+          mountPath: {{ $storage.mountPath }}
+  {{- end }}
 
   {{- if .Values.vaultwardenNetwork.certificateID }}
   cert:
@@ -119,3 +122,14 @@ scaleCertificate:
     id: {{ .Values.vaultwardenNetwork.certificateID }}
     {{- end -}}
 {{- end -}}
+
+
+{{/* TODO: Remove on the next version bump, eg 1.1.0+ */}}
+{{- define "vaultwarden.storage.ci.migration" -}}
+  {{- $storage := .storage -}}
+
+  {{- if $storage.hostPath -}}
+    {{- $_ := set $storage "hostPathConfig" dict -}}
+    {{- $_ := set $storage.hostPathConfig "hostPath" $storage.hostPath -}}
+  {{- end -}}
+{{- end -}}

+ 8 - 4
library/ix-dev/community/vaultwarden/values.yaml

@@ -1,7 +1,7 @@
 image:
   repository: vaultwarden/server
   pullPolicy: IfNotPresent
-  tag: 1.30.0
+  tag: 1.30.1
 
 resources:
   limits:
@@ -27,13 +27,17 @@ vaultwardenRunAs:
 vaultwardenStorage:
   data:
     type: ixVolume
-    datasetName: data
+    ixVolumeConfig:
+      datasetName: data
   pgData:
     type: ixVolume
-    datasetName: pgData
+    ixVolumeConfig:
+      datasetName: pgData
   pgBackup:
     type: ixVolume
-    datasetName: pgBackup
+    ixVolumeConfig:
+      datasetName: pgBackup
+  additionalStorages: []
 
 notes:
   custom: |