Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions kubernetes/loculus/templates/_config-processor.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@
limits:
cpu: 500m
memory: 256Mi
{{- include "loculus.containerSecurityContext" (list "config-processor" .Values) | nindent 2 }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This makes Values a required key of the loculus.configProcessor dict — a caller that omits it fails with nil pointer evaluating interface {}.containerSecurityContext. All five current callers were updated, so this is correct today, but the contract is now implicit.

Worth documenting the expected dict keys in a comment above the define (the way _ingest-pod-spec.tpl:6-12 does), so the next person adding a caller doesn't have to discover it from a render failure.

env:
- name: LOCULUSSUB_smtpPassword
valueFrom:
Expand Down
4 changes: 4 additions & 0 deletions kubernetes/loculus/templates/_ingest-pod-spec.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -26,12 +26,14 @@ metadata:
spec:
{{- include "possiblePriorityClassName" . | nindent 2 }}
{{- include "loculus.podScheduling" . | nindent 2 }}
{{- include "loculus.podSecurityContext" (list "ingest" $Values) | nindent 2 }}
serviceAccountName: loculus-ingest-lock
restartPolicy: Never
initContainers:
- name: version-check
image: busybox
{{- include "loculus.resources" (list "ingest-init" $Values) | nindent 6 }}
{{- include "loculus.containerSecurityContext" (list "ingest-init" $Values) | nindent 6 }}
command: ['sh', '-c', '
CONFIG_VERSION=$(grep "verify_loculus_version_is:" /package/config/config.yaml | sed "s/verify_loculus_version_is: //;");
DOCKER_TAG="{{ $dockerTag }}";
Expand All @@ -50,6 +52,7 @@ spec:
subPath: config.yaml
- name: wait-for-no-other-ingest
image: alpine/kubectl:1.36.0
{{- include "loculus.containerSecurityContext" (list "ingest-init" $Values) | nindent 6 }}
command:
- sh
- -c
Expand Down Expand Up @@ -80,6 +83,7 @@ spec:
image: {{ $organismContent.ingest.image }}:{{ $dockerTag }}
imagePullPolicy: {{ $Values.imagePullPolicy }}
{{- include "loculus.resources" (list "ingest" $Values) | nindent 6 }}
{{- include "loculus.containerSecurityContext" (list "ingest" $Values) | nindent 6 }}
env:
- name: KEYCLOAK_INGEST_PASSWORD
valueFrom:
Expand Down
27 changes: 27 additions & 0 deletions kubernetes/loculus/templates/_security-context.tpl
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
{{- define "loculus.podSecurityContext" -}}
{{- $args := . -}}
{{- $componentName := index $args 0 -}}
{{- $values := index $args 1 -}}

{{- if and $values.podSecurityContext (hasKey $values.podSecurityContext $componentName) }}
securityContext:
{{ toYaml (index $values.podSecurityContext $componentName) | indent 2 }}
{{- else if and $values.podSecurityContext (hasKey $values.podSecurityContext "default") }}
securityContext:
{{ toYaml $values.podSecurityContext.default | indent 2 }}
{{- end }}
Comment on lines +6 to +12

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two things about the default fallback:

  1. No way to opt a component out. Once default is set, every component gets it and the only override is a full replacement. There's no value that disables the context for a single component — podSecurityContext.backend: {} renders securityContext: {} (harmless but not "unset"), and null fails schema validation since the $ref requires an object. If someone needs one workload (e.g. minio, database) to run without the hardened default, they currently can't express it. Consider documenting this or accepting null/false as an explicit disable.

  2. Full replace vs. merge. values.yaml documents this, but a mergeOverwrite of default with the component entry would be much less error-prone for the common "same base, one field differs" case. If full-replace is deliberate, it's worth a one-line comment here in the template too, since this is where a future reader will look.

Neither is a bug, but (1) is the one likely to be hit in practice.

{{- end }}

{{- define "loculus.containerSecurityContext" -}}
{{- $args := . -}}
{{- $componentName := index $args 0 -}}
{{- $values := index $args 1 -}}

{{- if and $values.containerSecurityContext (hasKey $values.containerSecurityContext $componentName) }}
securityContext:
{{ toYaml (index $values.containerSecurityContext $componentName) | indent 2 }}
{{- else if and $values.containerSecurityContext (hasKey $values.containerSecurityContext "default") }}
securityContext:
{{ toYaml $values.containerSecurityContext.default | indent 2 }}
{{- end }}
{{- end }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing trailing newline at EOF.

Also, the two defines are byte-identical apart from the values key. Worth collapsing into one helper to avoid the two drifting apart:

{{- define "loculus.securityContext" -}}
{{- $component := index . 0 -}}
{{- $scopeMap := index . 1 -}}
{{- if $scopeMap -}}
{{- $sc := or (index $scopeMap $component) (index $scopeMap "default") -}}
...

and call it as (list "backend" $.Values.podSecurityContext). Not blocking — the current shape does mirror loculus.resources, so keeping it is defensible.

2 changes: 2 additions & 0 deletions kubernetes/loculus/templates/autoapprove-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,11 +25,13 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "ingest" .Values) | nindent 6 }}
containers:
- name: autoapprove
image: ghcr.io/loculus-project/ingest:{{ $dockerTag }}
imagePullPolicy: {{ .Values.imagePullPolicy }}
{{- include "loculus.resources" (list "ingest" .Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "ingest" .Values) | nindent 10 }}
env:
- name: KEYCLOAK_INGEST_PASSWORD
valueFrom:
Expand Down
2 changes: 2 additions & 0 deletions kubernetes/loculus/templates/docs-preview.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,11 +23,13 @@ spec:
component: docs
spec:
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "docs" .Values) | nindent 6 }}
containers:
- name: docs
image: "ghcr.io/loculus-project/docs:{{ $dockerTag }}"
imagePullPolicy: {{ .Values.imagePullPolicy }}
{{- include "loculus.resources" (list "docs" .Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "docs" .Values) | nindent 10 }}
ports:
- containerPort: 8080

Expand Down
5 changes: 5 additions & 0 deletions kubernetes/loculus/templates/ena-submission-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ spec:
spec:
{{- include "possiblePriorityClassName" . | nindent 6 }}
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "ena-submission" .Values) | nindent 6 }}
initContainers:
- name: ena-submission-flyway
image: "ghcr.io/loculus-project/ena-submission-flyway:{{ $dockerTag }}"
Expand All @@ -33,6 +34,7 @@ spec:
limits:
cpu: 500m
memory: 256Mi
{{- include "loculus.containerSecurityContext" (list "ena-submission-flyway" $.Values) | nindent 10 }}
command: ['flyway', 'migrate']
env:
- name: FLYWAY_URL
Expand All @@ -55,6 +57,7 @@ spec:
image: "ghcr.io/loculus-project/ena-submission:{{ $dockerTag }}"
imagePullPolicy: {{ $.Values.imagePullPolicy }}
{{- include "loculus.resources" (list "ena-submission" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "ena-submission" $.Values) | nindent 10 }}
env:
- name: EXTERNAL_METADATA_UPDATER_PASSWORD
valueFrom:
Expand Down Expand Up @@ -144,12 +147,14 @@ spec:
spec:
{{- include "possiblePriorityClassName" . | nindent 10 }}
{{- include "loculus.podScheduling" . | nindent 10 }}
{{- include "loculus.podSecurityContext" (list "ena-submission-list-cronjob" $.Values) | nindent 10 }}
restartPolicy: Never
containers:
- name: ena-submission
image: "ghcr.io/loculus-project/ena-submission:{{ $dockerTag }}"
imagePullPolicy: {{ $.Values.imagePullPolicy }}
{{- include "loculus.resources" (list "ena-submission-list-cronjob" $.Values) | nindent 14 }}
{{- include "loculus.containerSecurityContext" (list "ena-submission-list-cronjob" $.Values) | nindent 14 }}
env:
- name: EXTERNAL_METADATA_UPDATER_PASSWORD
valueFrom:
Expand Down
2 changes: 2 additions & 0 deletions kubernetes/loculus/templates/ingest.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -143,11 +143,13 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "ingest-trigger" $.Values) | nindent 6 }}
restartPolicy: Never
serviceAccountName: loculus-ingest-trigger
containers:
- name: trigger
image: alpine/kubectl:1.36.0
{{- include "loculus.containerSecurityContext" (list "ingest-trigger" $.Values) | nindent 10 }}
command:
- sh
- -c
Expand Down
2 changes: 2 additions & 0 deletions kubernetes/loculus/templates/keycloak-database-standin.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ spec:
component: keycloak-database
spec:
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "keycloak-database" .Values) | nindent 6 }}
containers:
- name: loculus-keycloak-database
image: postgres:15.12
Expand All @@ -34,6 +35,7 @@ spec:
cpu: 10m
limits:
memory: "100Mi"
{{- include "loculus.containerSecurityContext" (list "keycloak-database" .Values) | nindent 10 }}
ports:
- containerPort: 5432
env:
Expand Down
7 changes: 5 additions & 2 deletions kubernetes/loculus/templates/keycloak-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,11 @@ spec:
app: loculus
component: keycloak
spec:
{{- include "possiblePriorityClassName" . | nindent 6 }}
{{- include "possiblePriorityClassName" . | nindent 6 }}
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "keycloak" .Values) | nindent 6 }}
initContainers:
{{- include "loculus.configProcessor" (dict "name" "keycloak-config" "dockerTag" $dockerTag "imagePullPolicy" .Values.imagePullPolicy) | nindent 8 }}
{{- include "loculus.configProcessor" (dict "name" "keycloak-config" "dockerTag" $dockerTag "imagePullPolicy" .Values.imagePullPolicy "Values" .Values) | nindent 8 }}
- name: keycloak-theme-prep
resources:
requests:
Expand All @@ -34,6 +35,7 @@ spec:
limits:
cpu: 500m
memory: 256Mi
{{- include "loculus.containerSecurityContext" (list "keycloak-theme-prep" $.Values) | nindent 10 }}
image: "ghcr.io/loculus-project/keycloakify:{{ $dockerTag }}"
volumeMounts:
- name: theme-volume
Expand All @@ -43,6 +45,7 @@ spec:
# TODO #1221
image: quay.io/keycloak/keycloak:23.0
{{- include "loculus.resources" (list "keycloak" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "keycloak" $.Values) | nindent 10 }}
env:
- name: REGISTRATION_TERMS_MESSAGE
value: {{ $.Values.registrationTermsMessage }}
Expand Down
4 changes: 3 additions & 1 deletion kubernetes/loculus/templates/lapis-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,13 +25,15 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "lapis" $.Values) | nindent 6 }}
initContainers:
{{- include "loculus.configProcessor" (dict "name" "lapis-silo-database-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy) | nindent 8 }}
{{- include "loculus.configProcessor" (dict "name" "lapis-silo-database-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy "Values" $.Values) | nindent 8 }}
containers:
- name: lapis
image: "{{ $.Values.images.lapis.repository }}:{{ $.Values.images.lapis.tag }}"
imagePullPolicy: "{{ $.Values.images.lapis.pullPolicy | default $.Values.imagePullPolicy }}"
{{- include "loculus.resources" (list "lapis" $.Values $key) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "lapis" $.Values) | nindent 10 }}
ports:
- containerPort: 8080
args:
Expand Down
4 changes: 3 additions & 1 deletion kubernetes/loculus/templates/loculus-backend.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,13 +23,15 @@ spec:
spec:
{{- include "possiblePriorityClassName" . | nindent 6 }}
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "backend" $.Values) | nindent 6 }}
initContainers:
{{- include "loculus.configProcessor" (dict "name" "loculus-backend-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy) | nindent 8 }}
{{- include "loculus.configProcessor" (dict "name" "loculus-backend-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy "Values" $.Values) | nindent 8 }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Indentation of this line changed from column 0 to 4 while adding the "Values" key. Harmless (the {{- trims it and nindent 8 sets the real indent), but it now matches neither keycloak-deployment.yaml:29 (column 0) nor silo-deployment.yaml:36 / lapis-deployment.yaml:30 (column 8). Same in loculus-website.yaml:28. Worth reverting to keep the diff to the functional change.

containers:
- name: backend
image: "{{ $.Values.images.backend.repository }}:{{ $.Values.images.backend.tag | default $dockerTag }}"
imagePullPolicy: "{{ $.Values.images.backend.pullPolicy | default $.Values.imagePullPolicy }}"
{{- include "loculus.resources" (list "backend" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "backend" $.Values) | nindent 10 }}
startupProbe:
httpGet:
path: "/actuator/health/liveness"
Expand Down
2 changes: 2 additions & 0 deletions kubernetes/loculus/templates/loculus-database-standin.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ spec:
component: database
spec:
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "database" .Values) | nindent 6 }}
containers:
- name: database
image: postgres:15.12
Expand All @@ -39,6 +40,7 @@ spec:
cpu: "250m"
limits:
memory: "2Gi"
{{- include "loculus.containerSecurityContext" (list "database" .Values) | nindent 8 }}
ports:
- containerPort: 5432
env:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,11 +35,13 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "preprocessing" $.Values) | nindent 6 }}
containers:
- name: preprocessing-{{ $organism }}
image: {{ $processingConfig.image}}:{{ $thisDockerTag }}
imagePullPolicy: {{ $.Values.imagePullPolicy }}
{{- include "loculus.resources" (list "preprocessing" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "preprocessing" $.Values) | nindent 10 }}
env:
- name: KEYCLOAK_PASSWORD
valueFrom:
Expand Down
4 changes: 3 additions & 1 deletion kubernetes/loculus/templates/loculus-website.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,13 +23,15 @@ spec:
spec:
{{- include "possiblePriorityClassName" . | nindent 6 }}
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "website" $.Values) | nindent 6 }}
initContainers:
{{- include "loculus.configProcessor" (dict "name" "loculus-website-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy) | nindent 8 }}
{{- include "loculus.configProcessor" (dict "name" "loculus-website-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy "Values" $.Values) | nindent 8 }}
containers:
- name: website
image: "{{ $.Values.images.website.repository }}:{{ $.Values.images.website.tag | default $dockerTag }}"
imagePullPolicy: "{{ $.Values.images.website.pullPolicy | default $.Values.imagePullPolicy }}"
{{- include "loculus.resources" (list "website" .Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "website" $.Values) | nindent 10 }}
ports:
- containerPort: 3000
volumeMounts:
Expand Down
2 changes: 2 additions & 0 deletions kubernetes/loculus/templates/minio-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ spec:
component: minio
spec:
{{- include "loculus.podScheduling" . | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "minio" $.Values) | nindent 6 }}
volumes:
- name: policy-volume
configMap:
Expand All @@ -50,6 +51,7 @@ spec:
- name: minio
image: minio/minio:latest
{{- include "loculus.resources" (list "minio" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "minio" $.Values) | nindent 10 }}
args: ["server", "/data"]
ports:
- containerPort: 9000
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,11 +23,13 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "raw-reads-processing" $.Values) | nindent 6 }}
containers:
- name: raw-reads-processing
image: "ghcr.io/loculus-project/raw-reads-processing-service:{{ $dockerTag }}"
imagePullPolicy: {{ $.Values.imagePullPolicy }}
{{- include "loculus.resources" (list "raw-reads-processing" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "raw-reads-processing" $.Values) | nindent 10 }}
args:
- raw_reads_processing
- "--config-file=/config/config.yaml"
Expand Down
5 changes: 4 additions & 1 deletion kubernetes/loculus/templates/silo-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,14 +31,16 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "silo" $.Values) | nindent 6 }}
initContainers:
{{- include "loculus.configProcessor" (dict "name" "lapis-silo-database-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy) | nindent 8 }}
{{- include "loculus.configProcessor" (dict "name" "lapis-silo-database-config" "dockerTag" $dockerTag "imagePullPolicy" $.Values.imagePullPolicy "Values" $.Values) | nindent 8 }}
containers:
- name: silo
image: "{{ $.Values.images.loculusSilo.repository }}:{{ $.Values.images.loculusSilo.tag | default $dockerTag }}"
command: ["/usr/local/bin/silo"]
imagePullPolicy: {{ $.Values.imagePullPolicy }}
{{- include "loculus.resources" (list "silo" $.Values $key) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "silo" $.Values) | nindent 10 }}
env:
- name: SPDLOG_LEVEL
value: "debug"
Expand Down Expand Up @@ -77,6 +79,7 @@ spec:
image: "{{ $.Values.images.loculusSilo.repository }}:{{ $.Values.images.loculusSilo.tag | default $dockerTag }}"
imagePullPolicy: "{{ $.Values.images.loculusSilo.pullPolicy }}"
{{- include "loculus.resources" (list "silo-importer" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "silo-importer" $.Values) | nindent 10 }}
env:
- name: BACKEND_BASE_URL
{{- if $.Values.disableBackend }}
Expand Down
3 changes: 3 additions & 0 deletions kubernetes/loculus/templates/taxonomy-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,11 @@ spec:
spec:
{{- include "possiblePriorityClassName" $ | nindent 6 }}
{{- include "loculus.podScheduling" $ | nindent 6 }}
{{- include "loculus.podSecurityContext" (list "taxonomy-service" $.Values) | nindent 6 }}
initContainers:
- name: download-taxonomy-db
image: alpine:3
{{- include "loculus.containerSecurityContext" (list "download-taxonomy-db" $.Values) | nindent 10 }}
command: ["sh", "-c"]
args:
- |
Expand All @@ -44,6 +46,7 @@ spec:
image: "ghcr.io/loculus-project/taxonomy-service:{{ $dockerTag }}"
imagePullPolicy: {{ $.Values.imagePullPolicy }}
{{- include "loculus.resources" (list "taxonomy-service" $.Values) | nindent 10 }}
{{- include "loculus.containerSecurityContext" (list "taxonomy-service" $.Values) | nindent 10 }}
args:
- taxonomy_service
- "--config-file=/config/config.yaml"
Expand Down
Loading
Loading