feat: add DOI Helm chart - #41
Conversation
at88mph
left a comment
There was a problem hiding this comment.
Just some restructuring, please. Usually I would say to start with helm create <name>, which provides a good scaffold file. This is fine, but just needs a few changes.
| securityContext: {} | ||
|
|
||
| deployment: | ||
| hostname: example.org |
There was a problem hiding this comment.
Rely on the ingress (or httpRoute) configuration for the hostname. Remove this.
|
|
||
| securityContext: {} | ||
|
|
||
| deployment: |
There was a problem hiding this comment.
The deployment object is an old way of doing it that we started in the Science Platform. It's not necessary and adds an extra layer for no reason. Use the citation/helm chart as an example of how to structure the values.yaml file. As such, replace deployment/doi with just a top level object called application.
|
|
||
| deployment: | ||
| hostname: example.org | ||
| doi: |
There was a problem hiding this comment.
See my deployment comment above.
| - path: /doi | ||
| pathType: Prefix | ||
| tls: [] | ||
|
|
There was a problem hiding this comment.
Add support for the httpRoute object, like the citation/helm Chart. This allows us to upgrade to the Kubernetes Gateway soon.
at88mph
left a comment
There was a problem hiding this comment.
Almost there, one more thing. In order to support cookies, this service needs to load the RsaSignaturePub.key file, which is an internal public key used to validate the cookie value from the browser. It's a bespoke system, unfortunately, but needs to be supported. That key will likely be put into a Secret.
See the Storage UI Helm Chart for an example of how to do that. It can just replicated from there for the most part:
https://github.com/opencadc/deployments/blob/main/helm/applications/storage-ui/values.yaml#L40
Summary
Add a Helm chart for the DOI service under
doi/helm, following theco-located chart structure used by
citation/helm.This replaces the earlier approach of adding the DOI chart to the centralized
deploymentsrepository.What changed
doi/helmcertificate Secrets
/configdirectory expected by theDOI container
endpoint
doi/README.mdContainer image
The default image reference currently follows the existing Citation registry
pattern:
Current deployment information still required
The existing DOI service runs in Docker Swarm. Before deploying this chart to Keel, the following must be confirmed from that deployment:
X-Client-CertificateheaderNo credential values, private keys, or environment-specific Secrets are included in this PR.