{"id":43968,"date":"2023-06-25T13:20:46","date_gmt":"2023-03-01T00:00:40","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/"},"modified":"2024-04-30T10:37:57","modified_gmt":"2024-04-30T02:37:57","slug":"%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/","title":{"rendered":"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd"},"content":{"rendered":"<h1>\u9996\u5148<\/h1>\n<p>\u5728\u516c\u5f0f\u7684GitLab Helm Chart\u4e2d\uff0c\u5b58\u5728\u65e0\u6cd5\u4f7f\u7528\u76f8\u5bf9URL\u7684\u9650\u5236\u3002<br \/>\n\u672c\u6b21\u5c06\u5bf9Helm Chart\u7684\u5185\u5bb9\u8fdb\u884c\u90e8\u5206\u4fee\u6539\uff0c\u4ee5\u5b9e\u73b0\u76f8\u5bf9URL\u7684\u529f\u80fd\u3002<br \/>\n\u6211\u4eec\u5c06\u5728AWS\u73af\u5883\u4e2d\u8fdb\u884c\u9a8c\u8bc1\u3002<\/p>\n<h1>\u73af\u5883\u4fe1\u606f<\/h1>\n<p>EKS 1.16<br \/>\nHelm 2.14.3<br \/>\nHelmfile 0.122.0<br \/>\nGitLab Helm Chart 2.3.7<br \/>\nkube2iam Helm Chart 2.5.0<br \/>\nALB Ingress Controller Helm Chart 0.1.11<br \/>\nNGINX Ingress Controller Helm Chart 1.39.0<\/p>\n<p>EKS 1.16<br \/>\nHelm 2.14.3<br \/>\nHelmfile 0.122.0<br \/>\nGitLab Helm\u56fe2.3.7<br \/>\nkube2iam Helm\u56fe2.5.0<br \/>\nALB Ingress Controller Helm\u56fe0.1.11<br \/>\nNGINX Ingress Controller Helm\u56fe1.39.0<\/p>\n<h1>\u64cd\u4f5c\u6b65\u9aa4<\/h1>\n<p>\u5047\u8bbe\u5df2\u7ecf\u521b\u5efa\u4e86EKS\u3001S3\u3001RDS\u3001ALB Ingress Controller\u548c\u7528\u4e8eS3\u8bbf\u95ee\u7684IAM\u89d2\u8272\u3002\u6709\u5173GitLab\u548cS3\u7684\u534f\u4f5c\uff0c\u8bf7\u53c2\u8003\u6b64\u5904\u3002\u6709\u5173ALB Ingress Controller\u548cNGINX Ingress Controller\u7684\u7ec4\u5408\uff0c\u8bf7\u53c2\u8003\u6b64\u5904\u3002<\/p>\n<h2>\u90e8\u7f72\u5fc5\u8981\u7684Kubernetes\u8d44\u6e90<\/h2>\n<p>\u4f7f\u7528Helmfile\u90e8\u7f72kube2iam\u3001ALB Ingress Controller\u548cNGINX Ingress Controller\u3002<br \/>\n\u9009\u62e9\u4f7f\u7528NGINX Ingress Controller\u7684\u539f\u56e0\u662f\u4e3a\u4e86\u8fdb\u884c\u57fa\u4e8erewrite target\u7684\u91cd\u5b9a\u5411\u5904\u7406\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">repositories<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">stable<\/span>\r\n    <span class=\"na\">url<\/span><span class=\"pi\">:<\/span> <span class=\"s\">https:\/\/kubernetes-charts.storage.googleapis.com<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">incubator<\/span>\r\n    <span class=\"na\">url<\/span><span class=\"pi\">:<\/span> <span class=\"s\">https:\/\/kubernetes-charts-incubator.storage.googleapis.com<\/span>\r\n\r\n<span class=\"na\">releases<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kube2iam<\/span>\r\n    <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kube-system<\/span>\r\n    <span class=\"na\">chart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">stable\/kube2iam<\/span>\r\n    <span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s\">2.5.0<\/span>\r\n    <span class=\"na\">values<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">host<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">iptables<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n          <span class=\"na\">interface<\/span><span class=\"pi\">:<\/span> <span class=\"s\">eni+<\/span>\r\n        <span class=\"na\">extraArgs<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">auto-discover-base-arn<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">\"<\/span>\r\n        <span class=\"na\">rbac<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">create<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">aws-alb-ingress-controller<\/span>\r\n    <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kube-system<\/span>\r\n    <span class=\"na\">chart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">incubator\/aws-alb-ingress-controller<\/span>\r\n    <span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s\">0.1.11<\/span>\r\n    <span class=\"na\">values<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">clusterName<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-cluster<\/span>\r\n        <span class=\"na\">autoDiscoverAwsRegion<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n        <span class=\"na\">autoDiscoverAwsVpcID<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n        <span class=\"na\">podAnnotations<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"s\">iam.amazonaws.com\/role<\/span><span class=\"pi\">:<\/span> <span class=\"s\">aws-alb-ingress-controller<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">nginx-ingress<\/span>\r\n    <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kube-system<\/span>\r\n    <span class=\"na\">chart<\/span><span class=\"pi\">:<\/span> <span class=\"s\">stable\/nginx-ingress<\/span>\r\n    <span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s\">1.39.0<\/span>\r\n    <span class=\"na\">values<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">controller<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">service<\/span><span class=\"pi\">:<\/span>\r\n            <span class=\"na\">type<\/span><span class=\"pi\">:<\/span> <span class=\"s\">NodePort<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"gp\">$<\/span> helmfile apply <span class=\"nt\">-f<\/span> .\/helmfile.yaml\r\n<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u521b\u5efa\u4e00\u4e2aIngress\uff0c\u4ee5\u5c06ALB\u8def\u7531\u5230NGINX Ingress Controller\u3002<br \/>\n\u786e\u4fdd\u6240\u6709\u8bf7\u6c42\u90fd\u901a\u8fc7\u8be5\u8def\u7531\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">extensions\/v1beta1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Ingress<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">annotations<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s\">alb.ingress.kubernetes.io\/scheme<\/span><span class=\"pi\">:<\/span> <span class=\"s\">internet-facing<\/span>\r\n    <span class=\"s\">kubernetes.io\/ingress.class<\/span><span class=\"pi\">:<\/span> <span class=\"s\">alb<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">alb-ingress<\/span>\r\n  <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">kube-system<\/span>\r\n<span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">rules<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"pi\">-<\/span> <span class=\"na\">http<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">paths<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"pi\">-<\/span> <span class=\"na\">backend<\/span><span class=\"pi\">:<\/span>\r\n          <span class=\"na\">serviceName<\/span><span class=\"pi\">:<\/span> <span class=\"s\">nginx-ingress-controller<\/span>\r\n          <span class=\"na\">servicePort<\/span><span class=\"pi\">:<\/span> <span class=\"m\">80<\/span>\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"gp\">$<\/span> kubectl apply <span class=\"nt\">-f<\/span> .\/alb-ingress.yaml\r\n<\/code><\/pre>\n<h2>\u7f16\u8f91GitLab Helm Chart<\/h2>\n<p>\u56e0\u4e3a\u9700\u8981\u4fee\u6539templates\u6587\u4ef6\u7684\u5185\u5bb9\uff0c\u6240\u4ee5\u8bf7\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u5728\u672c\u5730\u51c6\u5907Helm Chart\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"gp\">$<\/span> helm fetch gitlab\/gitlab <span class=\"nt\">--version<\/span> 2.3.7\r\n<\/code><\/pre>\n<h3>\u6a21\u677f<\/h3>\n<p>\u9996\u5148\uff0c\u6211\u5011\u9700\u8981\u7de8\u8f2f Ingress\u3002<br \/>\n\u7531\u65bc\u9700\u8981\u652f\u6301 assets\uff0c\u5426\u5247\u7121\u6cd5\u8f09\u5165 CSS \u7b49\u8cc7\u6e90\uff0c\u6211\u5011\u5c07\u901a\u904e Ingress \u7684\u91cd\u5beb\u76ee\u6a19\uff0c\u5c07 \/gitlab\/assets \u91cd\u65b0\u5c0e\u5411\u5230 \/assets\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">{{-<\/span> if .Values.enabled -}}\r\n<span class=\"err\">{{-<\/span> if eq (include \"gitlab.ingress.enabled\" $) \"true\" -}}\r\n<span class=\"err\">{{-<\/span> $gitlabHostname := include \"gitlab.gitlab.hostname\" . -}}\r\n<span class=\"err\">{{-<\/span> $tlsSecret := include \"unicorn.tlsSecret\" . -}}\r\n<span class=\"p\">apiVersion: extensions\/v1beta1\r\nkind: Ingress\r\nmetadata:\r\n<\/span>  name: {{ template \"fullname\" . }}\r\n  namespace: {{ $.Release.Namespace }}\r\n  labels:\r\n<span class=\"err\">{{<\/span> include \"gitlab.standardLabels\" . | indent 4 }}\r\n  annotations:\r\n    kubernetes.io\/ingress.class: \"{{ template \"gitlab.ingressclass\" . }}\"\r\n    kubernetes.io\/ingress.provider: nginx\r\n    nginx.ingress.kubernetes.io\/proxy-body-size: {{ .Values.ingress.proxyBodySize | quote }}\r\n    nginx.ingress.kubernetes.io\/proxy-read-timeout: {{ .Values.ingress.proxyReadTimeout | quote }}\r\n    nginx.ingress.kubernetes.io\/proxy-connect-timeout: {{ .Values.ingress.proxyConnectTimeout | quote }}\r\n    {{ include \"gitlab.certmanager_annotations\" . }}\r\n  {{- range $key, $value := merge .Values.ingress.annotations .Values.global.ingress.annotations }}\r\n    {{ $key }}: {{ $value | quote }}\r\n  {{- end }}\r\n<span class=\"p\">spec:\r\n<\/span>  rules:\r\n    - host: {{ $gitlabHostname }}\r\n      http:\r\n        paths:\r\n<span class=\"gd\">-         - path: \/\r\n<\/span><span class=\"gi\">+         - path: \/gitlab\r\n<\/span>            backend:\r\n              serviceName: {{ template \"fullname\" . }}\r\n              servicePort: {{ .Values.service.workhorseExternalPort }}\r\n<span class=\"gd\">-         - path: \/admin\/sidekiq\r\n<\/span><span class=\"gi\">+         - path: \/gitlab\/admin\/sidekiq\r\n<\/span>            backend:\r\n              serviceName: {{ template \"fullname\" . }}\r\n              servicePort: {{ .Values.service.externalPort }}\r\n<span class=\"gi\">+         - path: \/assets\r\n+           backend:\r\n+             serviceName: {{ template \"fullname\" . }}\r\n+             servicePort: {{ .Values.service.workhorseExternalPort }}\r\n<\/span>  {{- if (and $tlsSecret (eq (include \"gitlab.ingress.tls.enabled\" $) \"true\" )) }}\r\n  tls:\r\n    - hosts:\r\n      - {{ $gitlabHostname }}\r\n      secretName: {{ $tlsSecret }}\r\n  {{- else }}\r\n  tls: []\r\n  {{- end }}\r\n<span class=\"gi\">+ ---\r\n+ apiVersion: extensions\/v1beta1\r\n+ kind: Ingress\r\n+ metadata:\r\n+   name: {{ template \"fullname\" . }}-assets\r\n+   namespace: {{ $.Release.Namespace }}\r\n+   annotations:\r\n+     nginx.ingress.kubernetes.io\/rewrite-target: \/assets\/$1\r\n+     {{ include \"gitlab.certmanager_annotations\" . }}\r\n+   {{- range $key, $value := merge .Values.ingress.annotations .Values.global.ingress.annotations }}\r\n+     {{ $key }}: {{ $value | quote }}\r\n+   {{- end }}\r\n+ spec:\r\n+   rules:\r\n+     - host: {{ $gitlabHostname }}\r\n+       http:\r\n+         paths:\r\n+           - path: \/gitlab\/assets\/(.*)\r\n+             backend:\r\n+               serviceName: {{ template \"fullname\" . }}\r\n+               servicePort: {{ .Values.service.workhorseExternalPort }}\r\n<\/span><span class=\"err\">{{-<\/span> end -}}\r\n<span class=\"err\">{{-<\/span> end -}}\r\n<\/code><\/pre>\n<p>\u6211\u4f1a\u5728unicorn\u7684ConfigMap\u4e2d\u653e\u7f6e\u4e00\u4e2a\u7528\u4e8e\u5728GitLab\u4e0a\u8bbf\u95ee\u7684\u914d\u7f6e\u8bbe\u7f6e\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">{{-<\/span> if .Values.enabled -}}\r\n<span class=\"p\">apiVersion: v1\r\nkind: ConfigMap\r\nmetadata:\r\n<\/span>  name: {{ template \"fullname\" . }}\r\n  namespace: {{ $.Release.Namespace }}\r\n  labels:\r\n<span class=\"err\">{{<\/span> include \"gitlab.standardLabels\" . | indent 4 }}\r\n<span class=\"p\">data:\r\n<\/span>  installation_type: |\r\n    gitlab-helm-chart\r\n  database.yml.erb: |\r\n    production:\r\n      adapter: postgresql\r\n      encoding: unicode\r\n      database: {{ template \"gitlab.psql.database\" . }}\r\n      pool: 10\r\n      username: {{ template \"gitlab.psql.username\" . }}\r\n      password: \"&lt;%= File.read(\"\/etc\/gitlab\/postgres\/psql-password\").strip.dump[1..-2] %&gt;\"\r\n      host: {{ template \"gitlab.psql.host\" . }}\r\n      port: {{ template \"gitlab.psql.port\" . }}\r\n      prepared_statements: {{ template \"gitlab.psql.preparedStatements\" . }}\r\n      # load_balancing:\r\n      #   hosts:\r\n      #     - host1.example.com\r\n      #     - host2.example.com\r\n<span class=\"err\">{{-<\/span> include \"gitlab.psql.ssl.config\" . | indent 6 }}\r\n  smtp_settings.rb: |\r\n<span class=\"err\">{{<\/span> include \"gitlab.smtp_settings\" . | indent 4 }}\r\n  resque.yml.erb: |\r\n    production:\r\n      # Redis (single instance)\r\n      url: {{ template \"gitlab.redis.url\" . }}\r\n      id:\r\n  unicorn.rb: |\r\n    # This file should be equivalent to `unicorn.rb` from:\r\n    # * gitlab-foss: https:\/\/gitlab.com\/gitlab-org\/gitlab-foss\/blob\/master\/config\/unicorn.rb.example\r\n    # * omnibus: https:\/\/gitlab.com\/gitlab-org\/omnibus-gitlab\/blob\/master\/files\/gitlab-cookbooks\/gitlab\/templates\/default\/unicorn.rb.erb\r\n    worker_processes {{ .Values.workerProcesses }}\r\n    working_directory \"\/srv\/gitlab\"\r\n    listen \"0.0.0.0:{{ .Values.service.internalPort }}\", :tcp_nopush =&gt; true\r\n    timeout {{ .Values.workerTimeout }}\r\n    pid \"\/home\/git\/unicorn.pid\"\r\n    preload_app true\r\n\r\n    require_relative \"\/srv\/gitlab\/lib\/gitlab\/cluster\/lifecycle_events\"\r\n\r\n    before_exec do |server|\r\n      # Signal application hooks that we're about to restart\r\n      Gitlab::Cluster::LifecycleEvents.do_master_restart\r\n    end\r\n\r\n    run_once = true\r\n    before_fork do |server, worker|\r\n      if run_once\r\n        # There is a difference between Puma and Unicorn:\r\n        # - Puma calls before_fork once when booting up master process\r\n        # - Unicorn runs before_fork whenever new work is spawned\r\n        # To unify this behavior we call before_fork only once (we use\r\n        # this callback for deleting Prometheus files so for our purposes\r\n        # it makes sense to align behavior with Puma)\r\n        run_once = false\r\n\r\n        # Signal application hooks that we're about to fork\r\n        Gitlab::Cluster::LifecycleEvents.do_before_fork\r\n      end\r\n\r\n      # The following is only recommended for memory\/DB-constrained\r\n      # installations.  It is not needed if your system can house\r\n      # twice as many worker_processes as you have configured.\r\n      #\r\n      # This allows a new master process to incrementally\r\n      # phase out the old master process with SIGTTOU to avoid a\r\n      # thundering herd (especially in the \"preload_app false\" case)\r\n      # when doing a transparent upgrade.  The last worker spawned\r\n      # will then kill off the old master process with a SIGQUIT.\r\n      old_pid = \"#{server.config[:pid]}.oldbin\"\r\n      if old_pid != server.pid\r\n        begin\r\n          sig = (worker.nr + 1) &gt;= server.worker_processes ? :QUIT : :TTOU\r\n          Process.kill(sig, File.read(old_pid).to_i)\r\n        rescue Errno::ENOENT, Errno::ESRCH\r\n        end\r\n      end\r\n      #\r\n      # Throttle the master from forking too quickly by sleeping.  Due\r\n      # to the implementation of standard Unix signal handlers, this\r\n      # helps (but does not completely) prevent identical, repeated signals\r\n      # from being lost when the receiving process is busy.\r\n      # sleep 1\r\n    end\r\n\r\n    after_fork do |server, worker|\r\n      # Signal application hooks of worker start\r\n      Gitlab::Cluster::LifecycleEvents.do_worker_start\r\n\r\n      # per-process listener ports for debugging\/admin\/migrations\r\n      # addr = \"127.0.0.1:#{9293 + worker.nr}\"\r\n      # server.listen(addr, :tries =&gt; -1, :delay =&gt; 5, :tcp_nopush =&gt; true)\r\n    end\r\n\r\n    ENV['GITLAB_UNICORN_MEMORY_MIN'] = ({{ int .Values.memory.min }} * 1 &lt;&lt; 20).to_s\r\n    ENV['GITLAB_UNICORN_MEMORY_MAX'] = ({{ int .Values.memory.max }} * 1 &lt;&lt; 20).to_s\r\n<span class=\"gi\">+   ENV['RAILS_RELATIVE_URL_ROOT'] = \"\/gitlab\"\r\n<\/span>\r\n  gitlab.yml.erb: |\r\n    production: &amp;base\r\n      gitlab:\r\n        host: {{ template \"gitlab.gitlab.hostname\" . }}\r\n        https: {{ hasPrefix \"https:\/\/\" (include \"gitlab.gitlab.url\" .) }}\r\n<span class=\"gi\">+       relative_url_root: \/gitlab\r\n<\/span>        {{- with .Values.global.hosts.ssh }}\r\n        ssh_host: {{ . | quote }}\r\n        {{- end }}\r\n        {{- with .Values.global.appConfig }}\r\n        impersonation_enabled: {{ .enableImpersonation }}\r\n        usage_ping_enabled: {{ eq .enableUsagePing true }}\r\n        default_can_create_group: {{ eq .defaultCanCreateGroup true }}\r\n        username_changing_enabled: {{ eq .usernameChangingEnabled true }}\r\n        issue_closing_pattern: {{ .issueClosingPattern | quote }}\r\n        default_theme: {{ .defaultTheme }}\r\n        {{- include \"gitlab.appConfig.defaultProjectsFeatures.configuration\" $ | nindent 8 }}\r\n        webhook_timeout: {{ .webhookTimeout }}\r\n        {{- end }}\r\n        trusted_proxies:\r\n        {{- if .Values.trusted_proxies }}\r\n<span class=\"err\">{{<\/span> toYaml .Values.trusted_proxies | indent 10 }}\r\n        {{- end }}\r\n        time_zone: {{ .Values.global.time_zone | quote }}\r\n        email_from: {{ template \"gitlab.email.from\" . }}\r\n        email_display_name: {{ .Values.global.email.display_name | quote }}\r\n        email_reply_to: {{ template \"gitlab.email.reply_to\" . }}\r\n        email_subject_suffix: {{ .Values.global.email.subject_suffix | quote }}\r\n      {{- with .Values.global.appConfig }}\r\n      {{- if eq .incomingEmail.enabled true }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.incoming_email\" . | indent 6 }}\r\n      {{- end }}\r\n      {{- include \"gitlab.appConfig.cronJobs\" . | nindent 6 }}\r\n      gravatar:\r\n        plain_url: {{ .gravatar.plainUrl }}\r\n        ssl_url: {{ .gravatar.sslUrl }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.extra\" . | indent 6 }}\r\n      {{- end }}\r\n      {{- include \"gitlab.appConfig.artifacts.configuration\" (dict \"config\" $.Values.global.appConfig.artifacts \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.lfs.configuration\" (dict \"config\" $.Values.global.appConfig.lfs \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.uploads.configuration\" (dict \"config\" $.Values.global.appConfig.uploads \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.packages.configuration\" (dict \"config\" $.Values.global.appConfig.packages \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.external_diffs.configuration\" (dict \"config\" $.Values.global.appConfig.externalDiffs \"context\" $) | nindent 6 }}\r\n      pages:\r\n        enabled: false\r\n      mattermost:\r\n        enabled: false\r\n      gitlab_ci:\r\n      {{- include \"gitlab.appConfig.ldap.configuration\" $ | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.omniauth.configuration\" $ | nindent 6 }}\r\n      kerberos:\r\n        enabled: false\r\n      shared:\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.gitaly\" . | indent 6 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.repositories\" . | indent 6 }}\r\n      backup:\r\n        path: \"tmp\/backups\"   # Relative paths are relative to Rails.root (default: tmp\/backups\/)\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.shell\" . | indent 6 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.shell.ssh_port\" . | indent 8 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.shell.secret_file\" . | indent 8 }}\r\n      workhorse:\r\n        secret_file: \/etc\/gitlab\/gitlab-workhorse\/secret\r\n      git:\r\n        bin_path: \/usr\/bin\/git\r\n      webpack:\r\n      monitoring:\r\n        ip_whitelist:\r\n          {{- if kindIs \"array\" .Values.monitoring.ipWhitelist }}\r\n          {{ toYaml .Values.monitoring.ipWhitelist | nindent 10 | trim }}\r\n          {{- end }}\r\n        sidekiq_exporter:\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.rackAttack\" . | indent 6 }}\r\n      ## Registry Integration\r\n      {{- include \"gitlab.appConfig.registry.configuration\" $ | nindent 6 }}\r\n  configure: |\r\n    {{- include \"gitlab.scripts.configure.secrets\" (dict) | nindent 4 -}}\r\n    {{- include \"gitlab.psql.ssl.initScript\" . | nindent 4 }}\r\n<span class=\"gi\">+ relative_url.rb: |\r\n+   Rails.application.configure do\r\n+     config.relative_url_root = \"\/gitlab\"\r\n+   end\r\n<\/span><span class=\"p\">---\r\napiVersion: v1\r\nkind: ConfigMap\r\nmetadata:\r\n<\/span>  name: {{.Release.Name }}-workhorse-config\r\n  namespace: {{ $.Release.Namespace }}\r\n  labels:\r\n<span class=\"err\">{{<\/span> include \"gitlab.standardLabels\" . | indent 4 }}\r\n<span class=\"p\">data:\r\n<\/span>  installation_type: |\r\n    gitlab-helm-chart\r\n  workhorse-config.toml.erb: |\r\n    [redis]\r\n    URL = \"{{ template \"gitlab.redis.scheme\" . }}:\/\/{{ template \"gitlab.redis.host\" . }}:{{ template \"gitlab.redis.port\" . }}\"\r\n    {{- if .Values.global.redis.password.enabled }}\r\n    Password = \"&lt;%= File.read(\"\/etc\/gitlab\/redis\/password\").strip.dump[1..-2] %&gt;\"\r\n    {{- end }}\r\n  configure: |\r\n      set -e\r\n      mkdir -p \/init-secrets-workhorse\/gitlab-workhorse\r\n      cp -v -r -L \/init-config\/gitlab-workhorse\/secret \/init-secrets-workhorse\/gitlab-workhorse\/secret\r\n      {{- if .Values.global.redis.password.enabled }}\r\n      mkdir -p \/init-secrets-workhorse\/redis\r\n      cp -v -r -L \/init-config\/redis\/password \/init-secrets-workhorse\/redis\/\r\n      {{- end }}\r\n<span class=\"err\">#<\/span> Leave this here - This line denotes end of block to the parser.\r\n<span class=\"err\">{{-<\/span> end }}\r\n<\/code><\/pre>\n<p>\u4e3a\u4e86\u5c06\u65b0\u6587\u4ef6\u6dfb\u52a0\u5230Unicorn Deployment\u4e2d\u8fdb\u884c\u6302\u8f7d\uff0c\u9700\u8981\u8fdb\u884c\u76f8\u5e94\u7684\u914d\u7f6e\u3002<br \/>\n\u540c\u65f6\uff0c\u901a\u8fc7\u4f7f\u7528\u76f8\u5bf9\u8def\u5f84\uff0c\u53ef\u4ee5\u5220\u9664\u76f8\u5173\u90e8\u5206\uff0c\u4ee5\u907f\u514dliveness\u548creadiness\u5931\u8d25\u3002<br \/>\n\u6dfb\u52a0\/tmp\u662f\u4e3a\u4e86\u5728GitLab CI\u6267\u884c\u65f6\uff0c\u786e\u4fddS3\u4e0a\u4f20artifacts\u4e0d\u4f1a\u5931\u8d25\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">{{-<\/span> if .Values.enabled }}\r\n<span class=\"p\">apiVersion: apps\/v1\r\nkind: Deployment\r\nmetadata:\r\n<\/span>  name: {{ template \"fullname\" . }}\r\n  namespace: {{ $.Release.Namespace }}\r\n  labels:\r\n<span class=\"err\">{{<\/span> include \"gitlab.standardLabels\" . | indent 4 }}\r\n<span class=\"p\">spec:\r\n<\/span>  {{- if .Values.global.operator.enabled }}\r\n  paused: true\r\n  {{- end }}\r\n  replicas: {{ .Values.replicaCount }}\r\n  selector:\r\n    matchLabels:\r\n      app: {{ template \"name\" . }}\r\n      release: {{ .Release.Name }}\r\n  template:\r\n    metadata:\r\n      labels:\r\n        app: {{ template \"name\" . }}\r\n        release: {{ .Release.Name }}\r\n      annotations:\r\n        checksum\/config: {{ include (print $.Template.BasePath \"\/configmap.yml\") . | sha256sum }}\r\n        cluster-autoscaler.kubernetes.io\/safe-to-evict: \"true\"\r\n      {{- range $key, $value := .Values.annotations }}\r\n        {{ $key }}: {{ $value | quote }}\r\n      {{- end }}\r\n<span class=\"err\">{{-<\/span> if .Values.metrics.enabled }}\r\n<span class=\"err\">{{<\/span> toYaml .Values.metrics.annotations | indent 8 }}\r\n<span class=\"err\">{{-<\/span> end }}\r\n    spec:\r\n      {{- if .Values.tolerations }}\r\n      tolerations:\r\n<span class=\"err\">{{<\/span> toYaml .Values.tolerations | indent 8 }}\r\n      {{- end }}\r\n      securityContext:\r\n        runAsUser: 1000\r\n        fsGroup: 1000\r\n      {{- if eq (default .Values.global.antiAffinity .Values.antiAffinity) \"hard\" }}\r\n      affinity:\r\n        podAntiAffinity:\r\n          requiredDuringSchedulingIgnoredDuringExecution:\r\n            - topologyKey: \"kubernetes.io\/hostname\"\r\n              labelSelector:\r\n                matchLabels:\r\n                  app: {{ template \"name\" . }}\r\n                  release: {{ .Release.Name }}\r\n      {{- else if eq (default .Values.global.antiAffinity .Values.antiAffinity) \"soft\" }}\r\n      affinity:\r\n        podAntiAffinity:\r\n          preferredDuringSchedulingIgnoredDuringExecution:\r\n          - weight: 1\r\n            podAffinityTerm:\r\n              topologyKey: kubernetes.io\/hostname\r\n              labelSelector:\r\n                matchLabels:\r\n                  app: {{ template \"name\" . }}\r\n                  release: {{ .Release.Name }}\r\n      {{- end }}\r\n      initContainers:\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraInitContainers\" . | indent 8 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.certificates.initContainer\" . | indent 8 }}\r\n        - name: configure\r\n          command: ['sh']\r\n          args: [ '-c', 'sh -x \/config-unicorn\/configure ; sh -x \/config-workhorse\/configure']\r\n          image: {{ .Values.init.image }}:{{ .Values.init.tag }}\r\n          volumeMounts:\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraVolumeMounts\" . | indent 10 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.psql.ssl.volumeMount\" . | indent 10 }}\r\n          - name: unicorn-config\r\n            mountPath: \/config-unicorn\r\n            readOnly: true\r\n          - name: workhorse-config\r\n            mountPath: \/config-workhorse\r\n            readOnly: true\r\n          - name: init-unicorn-secrets\r\n            mountPath: \/init-config\r\n            readOnly: true\r\n          - name: unicorn-secrets\r\n            mountPath: \/init-secrets\r\n            readOnly: false\r\n          - name: workhorse-secrets\r\n            mountPath: \/init-secrets-workhorse\r\n            readOnly: false\r\n          resources:\r\n<span class=\"err\">{{<\/span> toYaml .Values.init.resources | indent 12 }}\r\n        - name: dependencies\r\n          image: \"{{ coalesce .Values.image.repository (include \"image.repository\" .) }}:{{ coalesce .Values.image.tag (include \"gitlab.versionTag\" . ) }}\"\r\n          {{ template \"gitlab.imagePullPolicy\" . }}\r\n          args:\r\n            - \/scripts\/wait-for-deps\r\n          env:\r\n<span class=\"err\">{{-<\/span> if .Values.global.operator.enabled }}\r\n            - name: BYPASS_SCHEMA_VERSION\r\n              value: 'true'\r\n<span class=\"err\">{{-<\/span> end }}\r\n            - name: GITALY_FEATURE_DEFAULT_ON\r\n              value: \"1\"\r\n            - name: CONFIG_TEMPLATE_DIRECTORY\r\n              value: '\/var\/opt\/gitlab\/templates'\r\n            - name: CONFIG_DIRECTORY\r\n              value: '\/srv\/gitlab\/config'\r\n            - name: WORKHORSE_ARCHIVE_CACHE_DISABLED\r\n              value: \"1\"\r\n          volumeMounts:\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraVolumeMounts\" . | indent 12 }}\r\n            - name: unicorn-config\r\n              mountPath: '\/var\/opt\/gitlab\/templates'\r\n            - name: unicorn-secrets\r\n              mountPath: '\/etc\/gitlab'\r\n              readOnly: true\r\n          resources:\r\n<span class=\"err\">{{<\/span> toYaml .Values.init.resources | indent 12 }}\r\n<span class=\"err\">{{-<\/span> include \"pullsecrets\" .Values.image | indent 6}}\r\n      containers:\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraContainers\" . | indent 8 }}\r\n        - name: {{ .Chart.Name }}\r\n          image: \"{{ coalesce .Values.image.repository (include \"image.repository\" .) }}:{{ coalesce .Values.image.tag (include \"gitlab.versionTag\" . ) }}\"\r\n          {{ template \"gitlab.imagePullPolicy\" . }}\r\n          ports:\r\n            - containerPort: {{ .Values.service.internalPort }}\r\n              name: unicorn\r\n          env:\r\n            - name: GITALY_FEATURE_DEFAULT_ON\r\n              value: \"1\"\r\n            - name: CONFIG_TEMPLATE_DIRECTORY\r\n              value: '\/var\/opt\/gitlab\/templates'\r\n            - name: CONFIG_DIRECTORY\r\n              value: '\/srv\/gitlab\/config'\r\n<span class=\"err\">{{-<\/span> if .Values.metrics.enabled }}\r\n            - name: prometheus_multiproc_dir\r\n              value: \/metrics\r\n<span class=\"err\">{{-<\/span> end }}\r\n<span class=\"err\">{{-<\/span> if .Values.workhorse.sentryDSN }}\r\n            - name: GITLAB_WORKHORSE_SENTRY_DSN\r\n              value: {{ .Values.workhorse.sentryDSN }}\r\n<span class=\"err\">{{-<\/span> end }}\r\n          volumeMounts:\r\n<span class=\"err\">{{-<\/span> if .Values.metrics.enabled }}\r\n            - name: unicorn-metrics\r\n              mountPath: '\/metrics'\r\n<span class=\"err\">{{-<\/span> end }}\r\n            - name: unicorn-config\r\n              mountPath: '\/var\/opt\/gitlab\/templates'\r\n            - name: unicorn-secrets\r\n              mountPath: '\/etc\/gitlab'\r\n              readOnly: true\r\n            - name: unicorn-secrets\r\n              mountPath: \/srv\/gitlab\/config\/secrets.yml\r\n              subPath: rails-secrets\/secrets.yml\r\n            - name: unicorn-config\r\n              mountPath: '\/srv\/gitlab\/config\/initializers\/smtp_settings.rb'\r\n              subPath: smtp_settings.rb\r\n<span class=\"gi\">+           - name: unicorn-config\r\n+             mountPath: '\/srv\/gitlab\/config\/initializers\/relative_url.rb'\r\n+             subPath: relative_url.rb\r\n<\/span>            - name: unicorn-config\r\n              mountPath: '\/srv\/gitlab\/INSTALLATION_TYPE'\r\n              subPath: installation_type\r\n            - name: shared-upload-directory\r\n              mountPath: \/srv\/gitlab\/public\/uploads\/tmp\r\n              readOnly: false\r\n            - name: shared-artifact-directory\r\n              mountPath: \/srv\/gitlab\/shared\r\n              readOnly: false\r\n<span class=\"gi\">+           - name: shared-tmp\r\n+             mountPath: '\/tmp'\r\n+             readOnly: false\r\n<\/span><span class=\"err\">{{<\/span> include \"gitlab.certificates.volumeMount\" . | indent 12 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraVolumeMounts\" . | indent 12 }}\r\n<span class=\"gd\">-         livenessProbe:\r\n-           exec:\r\n-             command:\r\n-             - \/scripts\/healthcheck\r\n-           initialDelaySeconds: 20\r\n-           timeoutSeconds: 30\r\n-           periodSeconds: 60\r\n-         readinessProbe:\r\n-           exec:\r\n-             command:\r\n-             - \/scripts\/healthcheck\r\n-           timeoutSeconds: 2\r\n<\/span>          lifecycle:\r\n            preStop:\r\n              exec:\r\n                command: [\"\/bin\/bash\", \"-c\", \"pkill -SIGQUIT -f 'unicorn master'\"]\r\n          resources:\r\n<span class=\"err\">{{<\/span> toYaml .Values.resources | indent 12 }}\r\n        - name: gitlab-workhorse\r\n          image: \"{{ coalesce .Values.workhorse.image (include \"workhorse.repository\" .) }}:{{ coalesce .Values.workhorse.tag (include \"gitlab.versionTag\" . ) }}\"\r\n          {{ template \"gitlab.imagePullPolicy\" . }}\r\n          ports:\r\n            - containerPort: {{ .Values.service.workhorseInternalPort }}\r\n              name: workhorse\r\n          env:\r\n            - name: GITLAB_WORKHORSE_EXTRA_ARGS\r\n              value: {{ .Values.workhorse.extraArgs | quote }}\r\n            - name: GITLAB_WORKHORSE_LISTEN_PORT\r\n              value: {{ default 8181 .Values.service.workhorseInternalPort | int | quote }}\r\n            - name: CONFIG_TEMPLATE_DIRECTORY\r\n              value: '\/var\/opt\/gitlab\/templates'\r\n            - name: CONFIG_DIRECTORY\r\n              value: '\/srv\/gitlab\/config'\r\n          volumeMounts:\r\n            - name: workhorse-config\r\n              mountPath: '\/var\/opt\/gitlab\/templates'\r\n            - name: workhorse-secrets\r\n              mountPath: '\/etc\/gitlab'\r\n              readOnly: true\r\n            - name: shared-upload-directory\r\n              mountPath: \/srv\/gitlab\/public\/uploads\/tmp\r\n              readOnly: false\r\n            - name: shared-artifact-directory\r\n              mountPath: \/srv\/gitlab\/shared\r\n              readOnly: false\r\n<span class=\"gi\">+           - name: shared-tmp\r\n+             mountPath: '\/tmp'\r\n+             readOnly: false\r\n<\/span><span class=\"err\">{{<\/span> include \"gitlab.certificates.volumeMount\" . | indent 12 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraVolumeMounts\" . | indent 12 }}\r\n<span class=\"gd\">-         livenessProbe:\r\n-           exec:\r\n-             command:\r\n-             - \/scripts\/healthcheck\r\n-           initialDelaySeconds: 20\r\n-           timeoutSeconds: 30\r\n-           periodSeconds: 60\r\n-         readinessProbe:\r\n-           exec:\r\n-             command:\r\n-             - \/scripts\/healthcheck\r\n-           timeoutSeconds: 2\r\n<\/span>          resources:\r\n<span class=\"err\">{{<\/span> toYaml .Values.workhorse.resources | indent 12 }}\r\n      volumes:\r\n<span class=\"err\">{{<\/span> include \"gitlab.extraVolumes\" . | indent 6 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.psql.ssl.volume\" . | indent 6 }}\r\n<span class=\"err\">{{-<\/span> if .Values.metrics.enabled }}\r\n      - name: unicorn-metrics\r\n        emptyDir:\r\n          medium: \"Memory\"\r\n<span class=\"err\">{{-<\/span> end }}\r\n      - name: unicorn-config\r\n        configMap:\r\n          name: {{ template \"fullname\" . }}\r\n      - name: workhorse-config\r\n        configMap:\r\n            name: {{ .Release.Name }}-workhorse-config\r\n      - name: init-unicorn-secrets\r\n        projected:\r\n          defaultMode: 0400\r\n          sources:\r\n          - secret:\r\n              name: {{ template \"gitlab.rails-secrets.secret\" . }}\r\n              items:\r\n                - key: secrets.yml\r\n                  path: rails-secrets\/secrets.yml\r\n          - secret:\r\n              name: {{ template \"gitlab.gitlab-shell.authToken.secret\" . }}\r\n              items:\r\n                - key: {{ template \"gitlab.gitlab-shell.authToken.key\" . }}\r\n                  path: shell\/.gitlab_shell_secret\r\n          - secret:\r\n              name: {{ template \"gitlab.gitaly.authToken.secret\" . }}\r\n              items:\r\n                - key: {{ template \"gitlab.gitaly.authToken.key\" . }}\r\n                  path: gitaly\/gitaly_token\r\n          {{- if .Values.global.redis.password.enabled }}\r\n          - secret:\r\n              name: {{ template \"gitlab.redis.password.secret\" . }}\r\n              items:\r\n                - key: {{ template \"gitlab.redis.password.key\" . }}\r\n                  path: redis\/password\r\n          {{- end }}\r\n          - secret:\r\n              name: {{ template \"gitlab.psql.password.secret\" . }}\r\n              items:\r\n                - key: {{ template \"gitlab.psql.password.key\" . }}\r\n                  path: postgres\/psql-password\r\n          - secret:\r\n              name: {{ template \"gitlab.registry.certificate.secret\" . }}\r\n              items:\r\n                - key: registry-auth.key\r\n                  path: registry\/gitlab-registry.key\r\n          - secret:\r\n              name: {{ template \"gitlab.workhorse.secret\" . }}\r\n              items:\r\n                - key: {{ template \"gitlab.workhorse.key\" . }}\r\n                  path: gitlab-workhorse\/secret\r\n          {{- include \"gitlab.minio.mountSecrets\" $ | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.objectStorage.mountSecrets\" (dict \"name\" \"artifacts\" \"config\" $.Values.global.appConfig.artifacts) | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.objectStorage.mountSecrets\" (dict \"name\" \"lfs\" \"config\" $.Values.global.appConfig.lfs) | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.objectStorage.mountSecrets\" (dict \"name\" \"uploads\" \"config\" $.Values.global.appConfig.uploads) | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.objectStorage.mountSecrets\" (dict \"name\" \"packages\" \"config\" $.Values.global.appConfig.packages) | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.objectStorage.mountSecrets\" (dict \"name\" \"external_diffs\" \"config\" $.Values.global.appConfig.externalDiffs) | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.ldap.servers.mountSecrets\" $ | nindent 10 }}\r\n          {{- include \"gitlab.appConfig.omniauth.mountSecrets\" $ | nindent 10 }}\r\n          {{- if and $.Values.global.smtp.enabled $.Values.global.smtp.authentication }}\r\n          - secret:\r\n              name: {{ .Values.global.smtp.password.secret | required \"Missing required secret containing the SMTP password. Make sure to set `global.smtp.password.secret`\" }}\r\n              items:\r\n                - key: {{ .Values.global.smtp.password.key }}\r\n                  path: smtp\/smtp-password\r\n          {{- end }}\r\n      - name: unicorn-secrets\r\n        emptyDir:\r\n          medium: \"Memory\"\r\n      - name: workhorse-secrets\r\n        emptyDir:\r\n          medium: \"Memory\"\r\n      - name: shared-upload-directory\r\n        emptyDir: {}\r\n      - name: shared-artifact-directory\r\n        emptyDir: {}\r\n<span class=\"gi\">+     - name: shared-tmp\r\n+       emptyDir: {}\r\n<\/span><span class=\"err\">{{<\/span> include \"gitlab.certificates.volumes\" . | indent 6 }}\r\n    {{- if .Values.nodeSelector }}\r\n      nodeSelector:\r\n<span class=\"err\">{{<\/span> toYaml .Values.nodeSelector | indent 8 }}\r\n    {{- end }}\r\n<span class=\"err\">{{-<\/span> end }}\r\n<\/code><\/pre>\n<p>\u5c06\u76f8\u540c\u7684\u76f8\u5bf9\u8def\u5f84\u914d\u7f6e\u653e\u5165sidekiq\u7684ConfigMap\u4e2d\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">{{-<\/span> if .Values.enabled -}}\r\n<span class=\"p\">apiVersion: v1\r\nkind: ConfigMap\r\nmetadata:\r\n<\/span>  name: {{ template \"fullname\" . }}\r\n  namespace: {{ $.Release.Namespace }}\r\n  labels:\r\n<span class=\"err\">{{<\/span> include \"gitlab.standardLabels\" . | indent 4 }}\r\n<span class=\"p\">data:\r\n<\/span>  installation_type: |\r\n    gitlab-helm-chart\r\n  database.yml.erb: |\r\n    production:\r\n      adapter: postgresql\r\n      encoding: unicode\r\n      database: {{ template \"gitlab.psql.database\" . }}\r\n      pool: 10\r\n      username: {{ template \"gitlab.psql.username\" . }}\r\n      password: \"&lt;%= File.read(\"\/etc\/gitlab\/postgres\/psql-password\").strip.dump[1..-2] %&gt;\"\r\n      host: {{ template \"gitlab.psql.host\" . }}\r\n      port: {{ template \"gitlab.psql.port\" . }}\r\n      prepared_statements: {{ template \"gitlab.psql.preparedStatements\" . }}\r\n      # load_balancing:\r\n      #   hosts:\r\n      #     - host1.example.com\r\n      #     - host2.example.com\r\n<span class=\"err\">{{-<\/span> include \"gitlab.psql.ssl.config\" . | indent 6 }}\r\n  smtp_settings.rb: |\r\n<span class=\"err\">{{<\/span> include \"gitlab.smtp_settings\" . | indent 4 }}\r\n  resque.yml.erb: |\r\n    production:\r\n      # Redis (single instance)\r\n      url: {{ template \"gitlab.redis.url\" . }}\r\n      id:\r\n  gitlab.yml.erb: |\r\n    production: &amp;base\r\n      gitlab:\r\n        host: {{ template \"gitlab.gitlab.hostname\" . }}\r\n        https: {{ hasPrefix \"https:\/\/\" (include \"gitlab.gitlab.url\" .) }}\r\n<span class=\"gi\">+       relative_url_root: \/gitlab\r\n<\/span>        {{- with .Values.global.hosts.ssh }}\r\n        ssh_host: {{ . | quote }}\r\n        {{- end }}\r\n        {{- with .Values.global.appConfig }}\r\n        impersonation_enabled: {{ .enableImpersonation }}\r\n        usage_ping_enabled: {{ eq .enableUsagePing true }}\r\n        default_can_create_group: {{ eq .defaultCanCreateGroup true }}\r\n        username_changing_enabled: {{ eq .usernameChangingEnabled true }}\r\n        issue_closing_pattern: {{ .issueClosingPattern | quote }}\r\n        default_theme: {{ .defaultTheme }}\r\n        {{- include \"gitlab.appConfig.defaultProjectsFeatures.configuration\" $ | nindent 8 }}\r\n        webhook_timeout: {{ .webhookTimeout }}\r\n        {{- end }}\r\n        trusted_proxies:\r\n        {{- if .Values.trusted_proxies }}\r\n<span class=\"err\">{{<\/span> toYaml .Values.trusted_proxies | indent 10 }}\r\n        {{- end }}\r\n        time_zone: {{ .Values.global.time_zone | quote }}\r\n        email_from: {{ template \"gitlab.email.from\" . }}\r\n        email_display_name: {{ .Values.global.email.display_name | quote }}\r\n        email_reply_to: {{ template \"gitlab.email.reply_to\" . }}\r\n        email_subject_suffix: {{ .Values.global.email.subject_suffix | quote }}\r\n      {{- with .Values.global.appConfig }}\r\n      {{- if eq .incomingEmail.enabled true }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.incoming_email\" . | indent 6 }}\r\n      {{- end }}\r\n      gravatar:\r\n        plain_url: {{ .gravatar.plainUrl }}\r\n        ssl_url: {{ .gravatar.sslUrl }}\r\n      {{- include \"gitlab.appConfig.cronJobs\" . | nindent 6 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.extra\" . | indent 6 }}\r\n      {{- end }}\r\n      {{- include \"gitlab.appConfig.artifacts.configuration\" (dict \"config\" $.Values.global.appConfig.artifacts \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.lfs.configuration\" (dict \"config\" $.Values.global.appConfig.lfs \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.uploads.configuration\" (dict \"config\" $.Values.global.appConfig.uploads \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.packages.configuration\" (dict \"config\" $.Values.global.appConfig.packages \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.external_diffs.configuration\" (dict \"config\" $.Values.global.appConfig.externalDiffs \"context\" $) | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.pseudonymizer.configuration\" $ | nindent 6 }}\r\n      pages:\r\n        enabled: false\r\n      mattermost:\r\n        enabled: false\r\n      ## Registry Integration\r\n      {{- include \"gitlab.appConfig.registry.configuration\" $ | nindent 6 }}\r\n      gitlab_ci:\r\n      {{- include \"gitlab.appConfig.ldap.configuration\" $ | nindent 6 }}\r\n      {{- include \"gitlab.appConfig.omniauth.configuration\" $ | nindent 6 }}\r\n      kerberos:\r\n        enabled: false\r\n      shared:\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.gitaly\" . | indent 6 }}\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.repositories\" . | indent 6 }}\r\n      backup:\r\n        path: \"tmp\/backups\"   # Relative paths are relative to Rails.root (default: tmp\/backups\/)\r\n<span class=\"err\">{{<\/span> include \"gitlab.appConfig.shell\" . | indent 6 }}\r\n      workhorse:\r\n      git:\r\n        bin_path: \/usr\/bin\/git\r\n      webpack:\r\n      monitoring:\r\n        ip_whitelist:\r\n          - 127.0.0.0\/8\r\n        sidekiq_exporter:\r\n<span class=\"err\">{{-<\/span> if .Values.metrics.enabled }}\r\n          enabled: true\r\n          address: 0.0.0.0\r\n          port: {{ .Values.metrics.port }}\r\n<span class=\"err\">{{-<\/span> end }}\r\n  configure: |\r\n    {{- include \"gitlab.scripts.configure.secrets\" (dict \"required\" \"gitaly registry postgres rails-secrets\") | nindent 4 -}}\r\n    {{- include \"gitlab.psql.ssl.initScript\" . | nindent 4 }}\r\n<span class=\"err\">#<\/span> Leave this here - This line denotes end of block to the parser.\r\n<span class=\"err\">{{-<\/span> end }}\r\n<\/code><\/pre>\n<p>\u5728gitaly\u7684ConfigMap\u4e2d\u6dfb\u52a0\u76f8\u5bf9\u8def\u5f84\u7684\u8bbe\u7f6e\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"err\">{{-<\/span> if .Values.enabled -}}\r\n<span class=\"p\">apiVersion: v1\r\nkind: ConfigMap\r\nmetadata:\r\n<\/span>  name: {{ template \"fullname\" . }}\r\n  namespace: {{ $.Release.Namespace }}\r\n  labels:\r\n<span class=\"err\">{{<\/span> include \"gitlab.standardLabels\" . | indent 4 }}\r\n<span class=\"p\">data:\r\n<\/span>  configure: |\r\n    set -e\r\n    mkdir -p \/init-secrets\/gitaly \/init-secrets\/shell\r\n    cp -v -r -L \/init-config\/.gitlab_shell_secret  \/init-secrets\/shell\/.gitlab_shell_secret\r\n    cp -v -r -L \/init-config\/gitaly_token  \/init-secrets\/gitaly\/gitaly_token\r\n    {{- if .Values.global.redis.password.enabled }}\r\n    mkdir -p \/init-secrets\/redis\r\n    cp -v -r -L \/init-config\/redis_password  \/init-secrets\/redis\/redis_password\r\n    {{- end }}\r\n  config.toml.erb: |\r\n    # The directory where Gitaly's executables are stored\r\n    bin_dir = \"\/usr\/local\/bin\"\r\n\r\n    # listen on a TCP socket. This is insecure (no authentication)\r\n    listen_addr = \"0.0.0.0:8075\"\r\n\r\n    # If metrics collection is enabled, inform gitaly about that\r\n    {{- if .Values.metrics.enabled }}\r\n    prometheus_listen_addr = \"localhost:{{ .Values.metrics.metricsPort }}\"\r\n    {{- end }}\r\n\r\n    &lt;% @storages = [ {{- range (coalesce .Values.internal.names .Values.global.gitaly.internal.names) }} {{ . | quote }}, {{- end }} ] %&gt;\r\n    &lt;% @index=`echo ${HOSTNAME##*-}`.to_i %&gt;\r\n    &lt;% if @storages.length &gt; @index %&gt;\r\n    [[storage]]\r\n    name = \"&lt;%= @storages[@index] %&gt;\"\r\n    path = \"\/home\/git\/repositories\"\r\n    &lt;% else %&gt;\r\n    &lt;% raise Exception, \"Storage for node #{@index} is not present in the storageNames array. Did you use kubectl to scale up ? You need to solely use helm for this purpose\" %&gt;\r\n    &lt;% end %&gt;\r\n\r\n    [logging]\r\n    {{- with .Values.logging }}\r\n    {{- if .level }}\r\n    level = \"{{ .level }}\"\r\n    {{- end }}\r\n    {{- if .format }}\r\n    format = \"{{ .format }}\"\r\n    {{- end }}\r\n    {{- if .sentryDsn }}\r\n    sentry_dsn = \"{{ .sentryDsn }}\"\r\n    {{- end }}\r\n    {{- if .rubySentryDsn }}\r\n    ruby_sentry_dsn = \"{{ .rubySentryDsn }}\"\r\n    {{- end }}\r\n    {{- if .sentryEnvironment }}\r\n    sentry_environment = \"{{ .sentryEnvironment }}\"\r\n    {{- end }}\r\n    {{- end }}\r\n\r\n    {{- if .Values.prometheus.grpcLatencyBuckets }}\r\n    [prometheus]\r\n    grpc_latency_buckets = {{ .Values.prometheus.grpcLatencyBuckets }}\r\n    {{- end }}\r\n\r\n    [auth]\r\n    token = \"&lt;%= File.read('\/etc\/gitlab-secrets\/gitaly\/gitaly_token').strip.dump[1..-2] %&gt;\"\r\n\r\n    [git]\r\n    {{- with .Values.git }}\r\n    {{- if .catFileCacheSize }}\r\n    catfile_cache_size = {{ .catFileCacheSize }}\r\n    {{- end }}\r\n    {{- end }}\r\n\r\n    [gitaly-ruby]\r\n    # The directory where gitaly-ruby is installed\r\n    dir = \"\/srv\/gitaly-ruby\"\r\n    {{- with .Values.ruby }}\r\n    {{- if .maxRss }}\r\n    max_rss = {{ .maxRss }}\r\n    {{- end }}\r\n    {{- if .gracefulRestartTimeout }}\r\n    graceful_restart_timeout = \"{{ .gracefulRestartTimeout }}\"\r\n    {{- end }}\r\n    {{- if .restartDelay }}\r\n    restart_delay = \"{{ .restartDelay }}\"\r\n    {{- end }}\r\n    {{- if .numWorkers }}\r\n    num_workers = {{ .numWorkers }}\r\n    {{- end }}\r\n    {{- end }}\r\n\r\n    [gitlab-shell]\r\n    # The directory where gitlab-shell is installed\r\n    dir = \"\/srv\/gitlab-shell\"\r\n\r\n    {{- if .Values.shell.concurrency }}\r\n    {{- range .Values.shell.concurrency }}\r\n    {{- if and .rpc .maxPerRepo }}\r\n    [[concurrency]]\r\n    rpc = \"{{ .rpc }}\"\r\n    max_per_repo = {{ .maxPerRepo }}\r\n    {{- end }}\r\n    {{- end }}\r\n    {{- end }}\r\n\r\n  shell-config.yml.erb: |\r\n    # GitLab user. git by default\r\n    user: git\r\n\r\n    # Url to gitlab instance. Used for api calls. Should end with a slash.\r\n<span class=\"gd\">-   gitlab_url: \"http:\/\/{{ template \"gitlab.unicorn.host\" . }}:{{ default 8080 .Values.unicorn.port }}\/\"\r\n<\/span><span class=\"gi\">+   gitlab_url: \"http:\/\/{{ template \"gitlab.unicorn.host\" . }}:{{ default 8080 .Values.unicorn.port }}\/gitlab\/\"\r\n<\/span>\r\n    secret_file: \/etc\/gitlab-secrets\/shell\/.gitlab_shell_secret\r\n\r\n    http_settings:\r\n      self_signed_cert: false\r\n\r\n    # File used as authorized_keys for gitlab user\r\n    auth_file: \"\/home\/git\/.ssh\/authorized_keys\"\r\n\r\n    # Redis settings used for pushing commit notices to gitlab\r\n    redis:\r\n      host: {{ template \"gitlab.redis.host\" . }}\r\n      port: {{ template \"gitlab.redis.port\" . }}\r\n      {{- if .Values.global.redis.password.enabled }}\r\n      pass: \"&lt;%= File.read(\"\/etc\/gitlab-secrets\/redis\/redis_password\").strip.dump[1..-2] %&gt;\"\r\n      {{- end }}\r\n      database: nil\r\n      namespace: resque:gitlab\r\n\r\n    # Log file.\r\n    # Default is gitlab-shell.log in the root directory.\r\n    log_file: \"\/var\/log\/gitaly\/gitlab-shell.log\"\r\n\r\n    # Log level. INFO by default\r\n    log_level: INFO\r\n\r\n    # Audit usernames.\r\n    # Set to true to see real usernames in the logs instead of key ids, which is easier to follow, but\r\n    # incurs an extra API call on every gitlab-shell command.\r\n    audit_usernames: false\r\n<span class=\"err\">#<\/span> Leave this here - This line denotes end of block to the parser.\r\n<span class=\"err\">{{-<\/span> end }}\r\n<\/code><\/pre>\n<h3>\u4ef7\u503c\u89c2 (ji\u00e0 zh\u00ed )<\/h3>\n<p>XXXXXXXXXX.ap-northeast-1.elb.amazonaws.com\u662fALB\u7684\u7ec8\u7aef\u8282\u70b9\uff0cYYYYYYYYYY.ap-northeast-1.rds.amazonaws.com\u662fRDS\u7684\u7ec8\u7aef\u8282\u70b9\u3002<br \/>\nIngress\u4f1a\u52a0\u8f7d\u5230NGINX Ingress Controller\u4e2d\u3002<br \/>\nIAM\u89d2\u8272\u662f\u9884\u5148\u521b\u5efa\u7684\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"na\">global<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">edition<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ce<\/span>\r\n  <span class=\"na\">hosts<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">https<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n    <span class=\"na\">gitlab<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">XXXXXXXXXX.ap-northeast-1.elb.amazonaws.com<\/span>\r\n      <span class=\"na\">https<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n  <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">configureCertmanager<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n    <span class=\"na\">tls<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n  <span class=\"na\">psql<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">password<\/span><span class=\"pi\">:<\/span> \r\n      <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-postgresql<\/span>\r\n      <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">password<\/span>\r\n    <span class=\"na\">host<\/span><span class=\"pi\">:<\/span> <span class=\"s\">YYYYYYYYYY.ap-northeast-1.rds.amazonaws.com<\/span>\r\n    <span class=\"na\">port<\/span><span class=\"pi\">:<\/span> <span class=\"m\">5432<\/span>\r\n    <span class=\"na\">username<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab<\/span>\r\n    <span class=\"na\">database<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlabhq_production<\/span>\r\n  <span class=\"na\">minio<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n  <span class=\"na\">appConfig<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">lfs<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-lfs<\/span>\r\n      <span class=\"na\">connection<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-rails-storage<\/span>\r\n        <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">connection<\/span>\r\n    <span class=\"na\">artifacts<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-artifacts<\/span>\r\n      <span class=\"na\">connection<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-rails-storage<\/span>\r\n        <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">connection<\/span>\r\n    <span class=\"na\">uploads<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-uploads<\/span>\r\n      <span class=\"na\">connection<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-rails-storage<\/span>\r\n        <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">connection<\/span>\r\n    <span class=\"na\">packages<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-packages<\/span>\r\n      <span class=\"na\">connection<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-rails-storage<\/span>\r\n        <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">connection<\/span>\r\n    <span class=\"na\">externalDiffs<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-mr-diffs<\/span>\r\n      <span class=\"na\">connection<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-rails-storage<\/span>\r\n        <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">connection<\/span>\r\n    <span class=\"na\">pseudonymizer<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">configMap<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-pseudo<\/span>\r\n      <span class=\"na\">connection<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">gitlab-rails-storage<\/span>\r\n        <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">connection<\/span>\r\n    <span class=\"na\">backups<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">bucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-backups<\/span>\r\n      <span class=\"na\">tmpBucket<\/span><span class=\"pi\">:<\/span> <span class=\"s\">test-gitlab-tmp<\/span>\r\n  <span class=\"na\">time_zone<\/span><span class=\"pi\">:<\/span> <span class=\"s\">Tokyo<\/span>\r\n<span class=\"na\">upgradeCheck<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">certmanager<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">install<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">nginx-ingress<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">prometheus<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">install<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">postgresql<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">install<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">gitlab-runner<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">install<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">registry<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">minReplicas<\/span><span class=\"pi\">:<\/span> <span class=\"m\">1<\/span>\r\n  <span class=\"na\">storage<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">secret<\/span><span class=\"pi\">:<\/span> <span class=\"s\">registry-storage<\/span>\r\n    <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">config<\/span>\r\n  <span class=\"na\">annotations<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"s\">iam.amazonaws.com\/role<\/span><span class=\"pi\">:<\/span> <span class=\"s\">s3-full-access-role<\/span>\r\n  <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<span class=\"na\">gitlab<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">gitlab-shell<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n  <span class=\"na\">gitlab-exporter<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n  <span class=\"na\">unicorn<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">annotations<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"s\">iam.amazonaws.com\/role<\/span><span class=\"pi\">:<\/span> <span class=\"s\">s3-full-access-role<\/span>\r\n    <span class=\"na\">ingress<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">true<\/span>\r\n      <span class=\"na\">annotations<\/span><span class=\"pi\">:<\/span>\r\n        <span class=\"s\">kubernetes.io\/ingress.class<\/span><span class=\"pi\">:<\/span> <span class=\"s\">nginx<\/span>\r\n  <span class=\"na\">sidekiq<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">annotations<\/span><span class=\"pi\">:<\/span>\r\n      <span class=\"s\">iam.amazonaws.com\/role<\/span><span class=\"pi\">:<\/span> <span class=\"s\">s3-full-access-role<\/span>\r\n  <span class=\"na\">task-runner<\/span><span class=\"pi\">:<\/span>\r\n    <span class=\"na\">enabled<\/span><span class=\"pi\">:<\/span> <span class=\"no\">false<\/span>\r\n<\/code><\/pre>\n<h2>GitLab\u7684\u90e8\u7f72<\/h2>\n<p>\u4f7f\u7528\u4ee5\u4e0b\u547d\u4ee4\u90e8\u7f72GitLab\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"gp\">$<\/span> helm <span class=\"nb\">install<\/span> \u00a5\r\n<span class=\"go\">  --name test-gitlab \u00a5\r\n  --namespace test \u00a5\r\n  --values .\/gitlab\/my-values.yaml \u00a5\r\n  .\/gitlab \r\n<\/span><\/code><\/pre>\n<h1>\u786e\u8ba4<\/h1>\n<p>\u6211\u53ef\u4ee5\u8bbf\u95eeGitLab\u5e76\u786e\u8ba4\u6ca1\u6709\u4efb\u4f55\u95ee\u9898\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d562c37434c4406cd88c6\/35-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2020-09-21 18.29.22.png\" \/><\/div>\n<p>\u5982\u679c\u90e8\u7f72GitLab Runner\uff0c\u4e5f\u53ef\u4ee5\u6267\u884cGitLab CI\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d562c37434c4406cd88c6\/37-0.png\" alt=\"\u30b9\u30af\u30ea\u30fc\u30f3\u30b7\u30e7\u30c3\u30c8 2020-09-21 18.31.51.png\" \/><\/div>\n<h1>\u603b\u7ed3<\/h1>\n<p>\u6211\u5df2\u7ecf\u786e\u8ba4\u5728\u4f7f\u7528Helm\u5728EKS\u4e0a\u90e8\u7f72GitLab\u65f6\u53ef\u4ee5\u4f7f\u7528\u76f8\u5bf9URL\u3002<br \/>\n\u5173\u4e8eassets\uff0c\u6211\u5c1d\u8bd5\u5bfb\u627e\u4e0d\u901a\u8fc7NGINX Ingress Controller\u7684rewrite target\u6765\u89e3\u51b3\u7684\u65b9\u6cd5\uff0c\u4f46\u5f88\u5feb\u53d1\u73b0\u8fd9\u6837\u5904\u7406\u53ef\u80fd\u4f1a\u5f88\u56f0\u96be\u3002<br \/>\n\u7531\u4e8e\u5728\u8fd9\u6b21\u5904\u7406\u4e2d\u9700\u8981\u66f4\u6539\u6a21\u677f\u7684\u5185\u5bb9\uff0c\u56e0\u6b64\u8bf7\u6ce8\u610f\u5728\u7248\u672c\u5347\u7ea7\u65f6\u9700\u8981\u76f8\u5e94\u5730\u8fdb\u884c\u8c03\u6574\u3002<\/p>\n<h1>\u5728\u4e2d\u56fd, \u8bf7\u63d0\u4f9b\u4ee5\u4e0b\u4fe1\u606f\u7684\u53e6\u4e00\u79cd\u8868\u8fbe\u65b9\u5f0f\u3002<\/h1>\n<p>\u4ee5\u4e0b\u662f\u81ea\u7136\u4e2d\u6587\u7684\u540c\u4e49\u8868\u8fbe\uff0c\u4ec5\u9700\u8981\u4e00\u79cd\u9009\u9879\uff1a<br \/>\n&#8211; GitLab\u95ee\u9898406\u7684\u94fe\u63a5\uff1ahttps:\/\/gitlab.com\/gitlab-org\/charts\/gitlab\/-\/issues\/406<br \/>\n&#8211; GitLab\u76f8\u5bf9URL\u5b89\u88c5\u6587\u6863\uff1ahttps:\/\/docs.gitlab.com\/ee\/install\/relative_url.html<br \/>\n&#8211; GitLab\u95ee\u98981647\u7684\u94fe\u63a5\uff1ahttps:\/\/gitlab.com\/gitlab-org\/charts\/gitlab\/-\/issues\/1647<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u9996\u5148 \u5728\u516c\u5f0f\u7684GitLab Helm Chart\u4e2d\uff0c\u5b58\u5728\u65e0\u6cd5\u4f7f\u7528\u76f8\u5bf9URL\u7684\u9650\u5236\u3002 \u672c\u6b21\u5c06\u5bf9Helm Char [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-43968","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5728gitlab-helm-chart\u4e2d\u4f7f\u76f8\u5c0durl\u6210\u70ba\u53ef\u80fd\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd\" \/>\n<meta property=\"og:description\" content=\"\u9996\u5148 \u5728\u516c\u5f0f\u7684GitLab Helm Chart\u4e2d\uff0c\u5b58\u5728\u65e0\u6cd5\u4f7f\u7528\u76f8\u5bf9URL\u7684\u9650\u5236\u3002 \u672c\u6b21\u5c06\u5bf9Helm Char [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u5728gitlab-helm-chart\u4e2d\u4f7f\u76f8\u5c0durl\u6210\u70ba\u53ef\u80fd\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-01T00:00:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-30T02:37:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d562c37434c4406cd88c6\/35-0.png\" \/>\n<meta name=\"author\" content=\"\u6587, \u7fd4\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6587, \u7fd4\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"20 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/\",\"name\":\"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-03-01T00:00:40+00:00\",\"dateModified\":\"2024-04-30T02:37:57+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c\",\"name\":\"\u6587, \u7fd4\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g\",\"caption\":\"\u6587, \u7fd4\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/wenxiang\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u5728gitlab-helm-chart\u4e2d\u4f7f\u76f8\u5c0durl\u6210\u70ba\u53ef\u80fd\/","og_locale":"zh_CN","og_type":"article","og_title":"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd","og_description":"\u9996\u5148 \u5728\u516c\u5f0f\u7684GitLab Helm Chart\u4e2d\uff0c\u5b58\u5728\u65e0\u6cd5\u4f7f\u7528\u76f8\u5bf9URL\u7684\u9650\u5236\u3002 \u672c\u6b21\u5c06\u5bf9Helm Char [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u5728gitlab-helm-chart\u4e2d\u4f7f\u76f8\u5c0durl\u6210\u70ba\u53ef\u80fd\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-03-01T00:00:40+00:00","article_modified_time":"2024-04-30T02:37:57+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d562c37434c4406cd88c6\/35-0.png"}],"author":"\u6587, \u7fd4","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6587, \u7fd4","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"20 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/","name":"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-03-01T00:00:40+00:00","dateModified":"2024-04-30T02:37:57+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u5728GitLab Helm Chart\u4e2d\u4f7f\u76f8\u5c0dURL\u6210\u70ba\u53ef\u80fd"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c","name":"\u6587, \u7fd4","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g","caption":"\u6587, \u7fd4"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/wenxiang\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e5%9c%a8gitlab-helm-chart%e4%b8%ad%e4%bd%bf%e7%9b%b8%e5%b0%8durl%e6%88%90%e7%82%ba%e5%8f%af%e8%83%bd\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/43968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=43968"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/43968\/revisions"}],"predecessor-version":[{"id":91402,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/43968\/revisions\/91402"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=43968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=43968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=43968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}