Skip to content

feat: add DOI Helm chart - #41

Merged
jburke-cadc merged 3 commits into
opencadc:mainfrom
WenbinWL:DOI-deploy
Jul 29, 2026
Merged

jburke-cadc merged 3 commits into
opencadc:mainfrom
WenbinWL:DOI-deploy

Conversation

@WenbinWL

Copy link
Copy Markdown
Contributor

Summary

Add a Helm chart for the DOI service under doi/helm, following the
co-located chart structure used by citation/helm.

This replaces the earlier approach of adding the DOI chart to the centralized
deployments repository.

What changed

  • Add a self-contained DOI Helm chart under doi/helm
  • Add Kubernetes resources for:
    • Deployment
    • Service
    • optional Ingress
    • ServiceAccount
    • ConfigMap
    • Helm connectivity test
  • Render non-sensitive DOI and Tomcat configuration into a ConfigMap
  • Support references to externally managed DataCite credentials and
    certificate Secrets
  • Merge runtime configuration into the /config directory expected by the
    DOI container
  • Configure startup, readiness, and liveness probes using the DOI availability
    endpoint
  • Add example deployment values
  • Document Helm validation and installation in doi/README.md

Container image

The default image reference currently follows the existing Citation registry
pattern:

bucket.canfar.net/doi:1.2.0

Current deployment information still required

The existing DOI service runs in Docker Swarm. Before deploying this chart to Keel, the following must be confirmed from that deployment:

  • Active container image repository, tag, digest, and architecture
  • Current runtime configuration files and values
  • Current certificate and credential filenames and mount paths
  • Approved Kubernetes Secret provisioning method
  • External hostname and Ingress configuration
  • Handling of the X-Client-Certificate header
  • Target namespace and image pull credentials
  • Resource and security-context requirements

No credential values, private keys, or environment-specific Secrets are included in this PR.

@at88mph at88mph left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just some restructuring, please. Usually I would say to start with helm create <name>, which provides a good scaffold file. This is fine, but just needs a few changes.

Comment thread doi/helm/values.yaml Outdated
securityContext: {}

deployment:
hostname: example.org

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rely on the ingress (or httpRoute) configuration for the hostname. Remove this.

Comment thread doi/helm/values.yaml Outdated

securityContext: {}

deployment:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The deployment object is an old way of doing it that we started in the Science Platform. It's not necessary and adds an extra layer for no reason. Use the citation/helm chart as an example of how to structure the values.yaml file. As such, replace deployment/doi with just a top level object called application.

Comment thread doi/helm/values.yaml Outdated

deployment:
hostname: example.org
doi:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See my deployment comment above.

Comment thread doi/helm/values.yaml
- path: /doi
pathType: Prefix
tls: []

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add support for the httpRoute object, like the citation/helm Chart. This allows us to upgrade to the Kubernetes Gateway soon.

@at88mph at88mph left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Almost there, one more thing. In order to support cookies, this service needs to load the RsaSignaturePub.key file, which is an internal public key used to validate the cookie value from the browser. It's a bespoke system, unfortunately, but needs to be supported. That key will likely be put into a Secret.

See the Storage UI Helm Chart for an example of how to do that. It can just replicated from there for the most part:
https://github.com/opencadc/deployments/blob/main/helm/applications/storage-ui/values.yaml#L40

@jburke-cadc
jburke-cadc merged commit 5d372d0 into opencadc:main Jul 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants