From ba2dde21df95e165e862967bc430399bf6f61d93 Mon Sep 17 00:00:00 2001 From: BryanFRD Date: Sat, 3 Oct 2026 13:10:19 +0200 Subject: [PATCH 1/2] ci: publish the image and the chart as Stashden, still tagging roxycloud-api Signed-off-by: BryanFRD --- .github/workflows/chart.yml | 8 +-- .github/workflows/ci.yml | 8 +-- .github/workflows/image.yml | 11 ++-- deploy/helm/roxycloud/templates/_helpers.tpl | 41 -------------- .../helm/{roxycloud => stashden}/.helmignore | 0 .../helm/{roxycloud => stashden}/Chart.yaml | 4 +- deploy/helm/{roxycloud => stashden}/README.md | 55 +++++++++++++------ .../templates/NOTES.txt | 4 +- deploy/helm/stashden/templates/_helpers.tpl | 41 ++++++++++++++ .../templates/deployment.yaml | 20 +++---- .../templates/ingress.yaml | 6 +- .../templates/pvc.yaml | 4 +- .../templates/secret.yaml | 4 +- .../templates/service.yaml | 6 +- .../helm/{roxycloud => stashden}/values.yaml | 2 +- ferrflow.json | 2 +- 16 files changed, 119 insertions(+), 97 deletions(-) delete mode 100644 deploy/helm/roxycloud/templates/_helpers.tpl rename deploy/helm/{roxycloud => stashden}/.helmignore (100%) rename deploy/helm/{roxycloud => stashden}/Chart.yaml (65%) rename deploy/helm/{roxycloud => stashden}/README.md (69%) rename deploy/helm/{roxycloud => stashden}/templates/NOTES.txt (87%) create mode 100644 deploy/helm/stashden/templates/_helpers.tpl rename deploy/helm/{roxycloud => stashden}/templates/deployment.yaml (90%) rename deploy/helm/{roxycloud => stashden}/templates/ingress.yaml (85%) rename deploy/helm/{roxycloud => stashden}/templates/pvc.yaml (84%) rename deploy/helm/{roxycloud => stashden}/templates/secret.yaml (93%) rename deploy/helm/{roxycloud => stashden}/templates/service.yaml (57%) rename deploy/helm/{roxycloud => stashden}/values.yaml (97%) diff --git a/.github/workflows/chart.yml b/.github/workflows/chart.yml index e0bac1d..76bb124 100644 --- a/.github/workflows/chart.yml +++ b/.github/workflows/chart.yml @@ -19,7 +19,7 @@ permissions: env: REGISTRY: oci://ghcr.io/ferrlabs/charts - CHART: ghcr.io/ferrlabs/charts/roxycloud + CHART: ghcr.io/ferrlabs/charts/stashden jobs: publish: @@ -47,8 +47,8 @@ jobs: helm registry login ghcr.io -u "$REGISTRY_USER" --password-stdin <<< "$GITHUB_TOKEN" cosign login ghcr.io -u "$REGISTRY_USER" --password-stdin <<< "$GITHUB_TOKEN" - helm package deploy/helm/roxycloud --version "$VERSION" --app-version "$VERSION" - helm push "roxycloud-${VERSION}.tgz" "$REGISTRY" 2>&1 | tee push.log + helm package deploy/helm/stashden --version "$VERSION" --app-version "$VERSION" + helm push "stashden-${VERSION}.tgz" "$REGISTRY" 2>&1 | tee push.log DIGEST=$(grep -oE 'sha256:[0-9a-f]{64}' push.log | head -1) if [ -z "$DIGEST" ]; then @@ -58,4 +58,4 @@ jobs: cosign sign --yes "${CHART}@${DIGEST}" - echo "Pushed and signed \`${REGISTRY}/roxycloud:${VERSION}\` at \`${DIGEST}\`" >> "$GITHUB_STEP_SUMMARY" + echo "Pushed and signed \`${REGISTRY}/stashden:${VERSION}\` at \`${DIGEST}\`" >> "$GITHUB_STEP_SUMMARY" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6e966de..61d89cb 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -94,11 +94,11 @@ jobs: - uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5 - name: A chart that does not render is worse than no chart run: | - helm lint deploy/helm/roxycloud --set database.url=x --set jwt.secret=y + helm lint deploy/helm/stashden --set database.url=x --set jwt.secret=y curl -fsSL https://github.com/yannh/kubeconform/releases/download/v0.7.0/kubeconform-linux-amd64.tar.gz | tar -xz -C /usr/local/bin kubeconform - helm template roxycloud deploy/helm/roxycloud --set database.url=postgres://u:p@db/roxycloud --set jwt.secret=secret --set ingress.enabled=true --set ingress.host=roxycloud.example --set ingress.tls.enabled=true --set ingress.tls.secretName=roxycloud-tls | kubeconform -strict -summary - helm template roxycloud deploy/helm/roxycloud --set database.existingSecret=roxycloud-database --set jwt.existingSecret=roxycloud-jwt --set persistence.enabled=false --set config.blobSweepIntervalSeconds=0 | kubeconform -strict -summary - helm template roxycloud deploy/helm/roxycloud --set database.url=postgres://u:p@db/roxycloud --set jwt.secret=secret --set blobs.backend=s3 --set blobs.s3.bucket=roxycloud --set blobs.s3.existingSecret=roxycloud-s3 --set replicaCount=3 | kubeconform -strict -summary + helm template stashden deploy/helm/stashden --set database.url=postgres://u:p@db/roxycloud --set jwt.secret=secret --set ingress.enabled=true --set ingress.host=roxycloud.example --set ingress.tls.enabled=true --set ingress.tls.secretName=roxycloud-tls | kubeconform -strict -summary + helm template stashden deploy/helm/stashden --set database.existingSecret=roxycloud-database --set jwt.existingSecret=roxycloud-jwt --set persistence.enabled=false --set config.blobSweepIntervalSeconds=0 | kubeconform -strict -summary + helm template stashden deploy/helm/stashden --set database.url=postgres://u:p@db/roxycloud --set jwt.secret=secret --set blobs.backend=s3 --set blobs.s3.bucket=roxycloud --set blobs.s3.existingSecret=roxycloud-s3 --set replicaCount=3 | kubeconform -strict -summary compose: runs-on: ubuntu-latest diff --git a/.github/workflows/image.yml b/.github/workflows/image.yml index e830b8d..4a00a80 100644 --- a/.github/workflows/image.yml +++ b/.github/workflows/image.yml @@ -26,7 +26,8 @@ on: type: boolean env: - IMAGE: ghcr.io/ferrlabs/roxycloud-api + IMAGE: ghcr.io/ferrlabs/stashden-api + LEGACY_IMAGE: ghcr.io/ferrlabs/roxycloud-api jobs: build: @@ -67,8 +68,8 @@ jobs: file: deploy/Dockerfile platforms: ${{ matrix.platform }} labels: | - org.opencontainers.image.title=roxycloud-api - org.opencontainers.image.description=The RoxyCloud API + org.opencontainers.image.title=stashden-api + org.opencontainers.image.description=The Stashden API org.opencontainers.image.source=${{ github.server_url }}/${{ github.repository }} org.opencontainers.image.revision=${{ steps.source.outputs.sha }} org.opencontainers.image.version=${{ inputs.version }} @@ -118,7 +119,9 @@ jobs: - id: meta uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 with: - images: ${{ env.IMAGE }} + images: | + ${{ env.IMAGE }} + ${{ env.LEGACY_IMAGE }} tags: | type=semver,pattern={{version}},value=v${{ inputs.version }} type=semver,pattern={{major}}.{{minor}},value=v${{ inputs.version }} diff --git a/deploy/helm/roxycloud/templates/_helpers.tpl b/deploy/helm/roxycloud/templates/_helpers.tpl deleted file mode 100644 index fc3e499..0000000 --- a/deploy/helm/roxycloud/templates/_helpers.tpl +++ /dev/null @@ -1,41 +0,0 @@ -{{- define "roxycloud.name" -}} -{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} -{{- end }} - -{{- define "roxycloud.fullname" -}} -{{- if .Values.fullnameOverride }} -{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} -{{- else if contains (include "roxycloud.name" .) .Release.Name }} -{{- .Release.Name | trunc 63 | trimSuffix "-" }} -{{- else }} -{{- printf "%s-%s" .Release.Name (include "roxycloud.name" .) | trunc 63 | trimSuffix "-" }} -{{- end }} -{{- end }} - -{{- define "roxycloud.labels" -}} -helm.sh/chart: {{ printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} -{{ include "roxycloud.selectorLabels" . }} -app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} -app.kubernetes.io/managed-by: {{ .Release.Service }} -{{- end }} - -{{- define "roxycloud.selectorLabels" -}} -app.kubernetes.io/name: {{ include "roxycloud.name" . }} -app.kubernetes.io/instance: {{ .Release.Name }} -{{- end }} - -{{- define "roxycloud.databaseSecret" -}} -{{- default (include "roxycloud.fullname" .) .Values.database.existingSecret }} -{{- end }} - -{{- define "roxycloud.jwtSecret" -}} -{{- default (include "roxycloud.fullname" .) .Values.jwt.existingSecret }} -{{- end }} - -{{- define "roxycloud.claimName" -}} -{{- default (include "roxycloud.fullname" .) .Values.persistence.existingClaim }} -{{- end }} - -{{- define "roxycloud.s3Secret" -}} -{{- .Values.blobs.s3.existingSecret | default (include "roxycloud.fullname" .) -}} -{{- end -}} diff --git a/deploy/helm/roxycloud/.helmignore b/deploy/helm/stashden/.helmignore similarity index 100% rename from deploy/helm/roxycloud/.helmignore rename to deploy/helm/stashden/.helmignore diff --git a/deploy/helm/roxycloud/Chart.yaml b/deploy/helm/stashden/Chart.yaml similarity index 65% rename from deploy/helm/roxycloud/Chart.yaml rename to deploy/helm/stashden/Chart.yaml index bc84217..3bd6595 100644 --- a/deploy/helm/roxycloud/Chart.yaml +++ b/deploy/helm/stashden/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v2 -name: roxycloud -description: RoxyCloud API, the server behind the web app, the desktop shell and folder sync +name: stashden +description: Stashden API, the server behind the web app, the desktop shell and folder sync type: application version: 0.32.0 appVersion: "0.32.0" diff --git a/deploy/helm/roxycloud/README.md b/deploy/helm/stashden/README.md similarity index 69% rename from deploy/helm/roxycloud/README.md rename to deploy/helm/stashden/README.md index 7675324..c3749e0 100644 --- a/deploy/helm/roxycloud/README.md +++ b/deploy/helm/stashden/README.md @@ -1,6 +1,6 @@ -# RoxyCloud chart +# Stashden chart -Deploys the RoxyCloud API: one replica, one volume for the blobs, and a Secret for the two values +Deploys the Stashden API: one replica, one volume for the blobs, and a Secret for the two values it will not start without. ## What it does not do @@ -16,35 +16,37 @@ by default. Point `ingress.host` at it and the app and the API are both there. ## The image -`ghcr.io/ferrlabs/roxycloud-api` is published by the release workflow, for `linux/amd64` and -`linux/arm64`, tagged with the exact version, the minor line and `latest`. The chart pins the exact +`ghcr.io/ferrlabs/stashden-api` is published by the release workflow, for `linux/amd64` and +`linux/arm64`, tagged with the exact version, the minor line and `latest`. The same image is still +pushed to `ghcr.io/ferrlabs/roxycloud-api`, the name it had before the project became Stashden, for +anyone who has not switched yet. The chart pins the exact version through `appVersion`, so an upgrade moves the image and the chart together. Building your own is still one command, which is what you want for a fork or an unreleased commit: ```bash -docker build -f deploy/Dockerfile -t your.registry/roxycloud-api:0.13.0 . -docker push your.registry/roxycloud-api:0.13.0 +docker build -f deploy/Dockerfile -t your.registry/stashden-api:0.13.0 . +docker push your.registry/stashden-api:0.13.0 ``` ## Installing -Each release publishes this chart to `oci://ghcr.io/ferrlabs/charts/roxycloud` under the release +Each release publishes this chart to `oci://ghcr.io/ferrlabs/charts/stashden` under the release version, signed with cosign by the release workflow. Add `--version` to pin one instead of taking the latest: ```bash -helm install roxycloud oci://ghcr.io/ferrlabs/charts/roxycloud \ - --set database.url='postgres://roxycloud:password@postgres/roxycloud' \ +helm install stashden oci://ghcr.io/ferrlabs/charts/stashden \ + --set database.url='postgres://stashden:password@postgres/stashden' \ --set jwt.secret="$(openssl rand -hex 32)" ``` From a checkout, with an image you built yourself: ```bash -helm install roxycloud deploy/helm/roxycloud \ - --set image.repository=your.registry/roxycloud-api \ - --set database.url='postgres://roxycloud:password@postgres/roxycloud' \ +helm install stashden deploy/helm/stashden \ + --set image.repository=your.registry/stashden-api \ + --set database.url='postgres://stashden:password@postgres/stashden' \ --set jwt.secret="$(openssl rand -hex 32)" \ --set bootstrapAdmin.email=you@example.com \ --set bootstrapAdmin.password='at least twelve characters' @@ -55,16 +57,31 @@ in External Secrets or a sealed secret: ```yaml database: - existingSecret: roxycloud-database + existingSecret: stashden-database existingSecretKey: url jwt: - existingSecret: roxycloud-jwt + existingSecret: stashden-jwt existingSecretKey: secret ``` The bootstrap administrator is created once, on a database with no accounts, and ignored after that. Rotating `jwt.secret` invalidates every session token in circulation. +## Upgrading from the roxycloud chart + +The chart was called `roxycloud` before the project became Stashden, and the chart name is part of +every resource name and of the Deployment's selector, which Kubernetes does not let an upgrade +change. A release installed from the old chart keeps its names by setting `nameOverride`: + +```bash +helm upgrade roxycloud oci://ghcr.io/ferrlabs/charts/stashden \ + --reuse-values --set nameOverride=roxycloud +``` + +Without it, the upgrade fails on the selector, and a fresh install beside it would create an empty +claim instead of using the one that holds the blobs. The image moves to `stashden-api` on its own, +since the chart's default now points there and it is the same image. + ## One replica `replicas` is not a value. The blob store is a directory, the claim is `ReadWriteOnce`, and two pods @@ -79,7 +96,7 @@ over a kept claim means telling the chart to adopt it rather than create a secon ```yaml persistence: - existingClaim: roxycloud + existingClaim: stashden ``` Turn `persistence.retain` off if you would rather uninstall took the data with it. Nothing else in @@ -89,7 +106,7 @@ this chart is capable of deleting the blob store. | Value | Default | Purpose | |---|---|---| -| `image.repository` | `ghcr.io/ferrlabs/roxycloud-api` | Image to run | +| `image.repository` | `ghcr.io/ferrlabs/stashden-api` | Image to run | | `image.tag` | chart `appVersion` | Tag to run | | `database.url` | none | Postgres connection string, required unless `database.existingSecret` is set | | `database.existingSecret` | none | Secret already holding the connection string | @@ -118,10 +135,12 @@ this chart is capable of deleting the blob store. | `ingress.tls.enabled` | `false` | Serve the host over TLS | | `ingress.tls.secretName` | none | Required when TLS is on | | `resources` | none | Container requests and limits | +| `nameOverride` | chart name | Name used for the resources and the `app.kubernetes.io/name` label | +| `fullnameOverride` | none | Full resource name, overriding the release and chart names | ## Checking a change to the chart ```bash -helm lint deploy/helm/roxycloud --set database.url=x --set jwt.secret=y -helm template roxycloud deploy/helm/roxycloud --set database.url=x --set jwt.secret=y | kubeconform -strict -summary +helm lint deploy/helm/stashden --set database.url=x --set jwt.secret=y +helm template stashden deploy/helm/stashden --set database.url=x --set jwt.secret=y | kubeconform -strict -summary ``` diff --git a/deploy/helm/roxycloud/templates/NOTES.txt b/deploy/helm/stashden/templates/NOTES.txt similarity index 87% rename from deploy/helm/roxycloud/templates/NOTES.txt rename to deploy/helm/stashden/templates/NOTES.txt index 6adbce8..0e3dd90 100644 --- a/deploy/helm/roxycloud/templates/NOTES.txt +++ b/deploy/helm/stashden/templates/NOTES.txt @@ -1,4 +1,4 @@ -{{ .Chart.Name }} {{ .Chart.AppVersion }} is installed as {{ include "roxycloud.fullname" . }}. +{{ .Chart.Name }} {{ .Chart.AppVersion }} is installed as {{ include "stashden.fullname" . }}. The API answers on port {{ .Values.service.port }}. {{- if .Values.ingress.enabled }} @@ -7,7 +7,7 @@ It is reachable at http{{ if .Values.ingress.tls.enabled }}s{{ end }}://{{ .Valu Nothing exposes it yet. To look at it from your machine: - kubectl --namespace {{ .Release.Namespace }} port-forward svc/{{ include "roxycloud.fullname" . }} {{ .Values.service.port }}:{{ .Values.service.port }} + kubectl --namespace {{ .Release.Namespace }} port-forward svc/{{ include "stashden.fullname" . }} {{ .Values.service.port }}:{{ .Values.service.port }} curl http://localhost:{{ .Values.service.port }}/health {{- end }} {{- if not .Values.bootstrapAdmin.email }} diff --git a/deploy/helm/stashden/templates/_helpers.tpl b/deploy/helm/stashden/templates/_helpers.tpl new file mode 100644 index 0000000..5e0b85b --- /dev/null +++ b/deploy/helm/stashden/templates/_helpers.tpl @@ -0,0 +1,41 @@ +{{- define "stashden.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{- define "stashden.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else if contains (include "stashden.name" .) .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name (include "stashden.name" .) | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} + +{{- define "stashden.labels" -}} +helm.sh/chart: {{ printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{ include "stashden.selectorLabels" . }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{- define "stashden.selectorLabels" -}} +app.kubernetes.io/name: {{ include "stashden.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{- define "stashden.databaseSecret" -}} +{{- default (include "stashden.fullname" .) .Values.database.existingSecret }} +{{- end }} + +{{- define "stashden.jwtSecret" -}} +{{- default (include "stashden.fullname" .) .Values.jwt.existingSecret }} +{{- end }} + +{{- define "stashden.claimName" -}} +{{- default (include "stashden.fullname" .) .Values.persistence.existingClaim }} +{{- end }} + +{{- define "stashden.s3Secret" -}} +{{- .Values.blobs.s3.existingSecret | default (include "stashden.fullname" .) -}} +{{- end -}} diff --git a/deploy/helm/roxycloud/templates/deployment.yaml b/deploy/helm/stashden/templates/deployment.yaml similarity index 90% rename from deploy/helm/roxycloud/templates/deployment.yaml rename to deploy/helm/stashden/templates/deployment.yaml index 5611113..9329197 100644 --- a/deploy/helm/roxycloud/templates/deployment.yaml +++ b/deploy/helm/stashden/templates/deployment.yaml @@ -1,9 +1,9 @@ apiVersion: apps/v1 kind: Deployment metadata: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} labels: - {{- include "roxycloud.labels" . | nindent 4 }} + {{- include "stashden.labels" . | nindent 4 }} {{- $local := eq .Values.blobs.backend "local" }} {{- if and $local (gt (int .Values.replicaCount) 1) }} {{- fail "blobs.backend=local puts the blobs in one pod's volume, so a second replica would serve half the files; set blobs.backend=s3 to run more than one" }} @@ -19,7 +19,7 @@ spec: {{- end }} selector: matchLabels: - {{- include "roxycloud.selectorLabels" . | nindent 6 }} + {{- include "stashden.selectorLabels" . | nindent 6 }} template: metadata: annotations: @@ -28,7 +28,7 @@ spec: {{- toYaml . | nindent 8 }} {{- end }} labels: - {{- include "roxycloud.selectorLabels" . | nindent 8 }} + {{- include "stashden.selectorLabels" . | nindent 8 }} spec: {{- with .Values.imagePullSecrets }} imagePullSecrets: @@ -79,24 +79,24 @@ spec: - name: S3_ACCESS_KEY_ID valueFrom: secretKeyRef: - name: {{ include "roxycloud.s3Secret" . }} + name: {{ include "stashden.s3Secret" . }} key: {{ .Values.blobs.s3.accessKeyIdKey }} - name: S3_SECRET_ACCESS_KEY valueFrom: secretKeyRef: - name: {{ include "roxycloud.s3Secret" . }} + name: {{ include "stashden.s3Secret" . }} key: {{ .Values.blobs.s3.secretAccessKeyKey }} {{- end }} {{- end }} - name: DATABASE_URL valueFrom: secretKeyRef: - name: {{ include "roxycloud.databaseSecret" . }} + name: {{ include "stashden.databaseSecret" . }} key: {{ .Values.database.existingSecretKey }} - name: JWT_SECRET valueFrom: secretKeyRef: - name: {{ include "roxycloud.jwtSecret" . }} + name: {{ include "stashden.jwtSecret" . }} key: {{ .Values.jwt.existingSecretKey }} {{- with .Values.config.corsAllowedOrigins }} - name: CORS_ALLOWED_ORIGINS @@ -127,7 +127,7 @@ spec: - name: BOOTSTRAP_ADMIN_PASSWORD valueFrom: secretKeyRef: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} key: bootstrap-admin-password {{- end }} livenessProbe: @@ -160,7 +160,7 @@ spec: - name: blobs {{- if .Values.persistence.enabled }} persistentVolumeClaim: - claimName: {{ include "roxycloud.claimName" . }} + claimName: {{ include "stashden.claimName" . }} {{- else }} emptyDir: {} {{- end }} diff --git a/deploy/helm/roxycloud/templates/ingress.yaml b/deploy/helm/stashden/templates/ingress.yaml similarity index 85% rename from deploy/helm/roxycloud/templates/ingress.yaml rename to deploy/helm/stashden/templates/ingress.yaml index a9a6e49..51bba17 100644 --- a/deploy/helm/roxycloud/templates/ingress.yaml +++ b/deploy/helm/stashden/templates/ingress.yaml @@ -5,9 +5,9 @@ apiVersion: networking.k8s.io/v1 kind: Ingress metadata: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} labels: - {{- include "roxycloud.labels" . | nindent 4 }} + {{- include "stashden.labels" . | nindent 4 }} {{- with .Values.ingress.annotations }} annotations: {{- toYaml . | nindent 4 }} @@ -30,7 +30,7 @@ spec: pathType: Prefix backend: service: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} port: number: {{ .Values.service.port }} {{- end }} diff --git a/deploy/helm/roxycloud/templates/pvc.yaml b/deploy/helm/stashden/templates/pvc.yaml similarity index 84% rename from deploy/helm/roxycloud/templates/pvc.yaml rename to deploy/helm/stashden/templates/pvc.yaml index 8032d00..6376dff 100644 --- a/deploy/helm/roxycloud/templates/pvc.yaml +++ b/deploy/helm/stashden/templates/pvc.yaml @@ -2,9 +2,9 @@ apiVersion: v1 kind: PersistentVolumeClaim metadata: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} labels: - {{- include "roxycloud.labels" . | nindent 4 }} + {{- include "stashden.labels" . | nindent 4 }} {{- if .Values.persistence.retain }} annotations: helm.sh/resource-policy: keep diff --git a/deploy/helm/roxycloud/templates/secret.yaml b/deploy/helm/stashden/templates/secret.yaml similarity index 93% rename from deploy/helm/roxycloud/templates/secret.yaml rename to deploy/helm/stashden/templates/secret.yaml index b96e3f9..a008102 100644 --- a/deploy/helm/roxycloud/templates/secret.yaml +++ b/deploy/helm/stashden/templates/secret.yaml @@ -5,9 +5,9 @@ apiVersion: v1 kind: Secret metadata: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} labels: - {{- include "roxycloud.labels" . | nindent 4 }} + {{- include "stashden.labels" . | nindent 4 }} type: Opaque stringData: {{- if $ownsDatabase }} diff --git a/deploy/helm/roxycloud/templates/service.yaml b/deploy/helm/stashden/templates/service.yaml similarity index 57% rename from deploy/helm/roxycloud/templates/service.yaml rename to deploy/helm/stashden/templates/service.yaml index 8a976fd..837bf66 100644 --- a/deploy/helm/roxycloud/templates/service.yaml +++ b/deploy/helm/stashden/templates/service.yaml @@ -1,9 +1,9 @@ apiVersion: v1 kind: Service metadata: - name: {{ include "roxycloud.fullname" . }} + name: {{ include "stashden.fullname" . }} labels: - {{- include "roxycloud.labels" . | nindent 4 }} + {{- include "stashden.labels" . | nindent 4 }} spec: type: {{ .Values.service.type }} ports: @@ -12,4 +12,4 @@ spec: protocol: TCP name: http selector: - {{- include "roxycloud.selectorLabels" . | nindent 4 }} + {{- include "stashden.selectorLabels" . | nindent 4 }} diff --git a/deploy/helm/roxycloud/values.yaml b/deploy/helm/stashden/values.yaml similarity index 97% rename from deploy/helm/roxycloud/values.yaml rename to deploy/helm/stashden/values.yaml index 7d7bdb1..07b83fe 100644 --- a/deploy/helm/roxycloud/values.yaml +++ b/deploy/helm/stashden/values.yaml @@ -1,5 +1,5 @@ image: - repository: ghcr.io/ferrlabs/roxycloud-api + repository: ghcr.io/ferrlabs/stashden-api # Defaults to the chart's appVersion. tag: "" pullPolicy: IfNotPresent diff --git a/ferrflow.json b/ferrflow.json index 0804b41..ebacb14 100644 --- a/ferrflow.json +++ b/ferrflow.json @@ -15,7 +15,7 @@ { "path": "app/tauri.conf.json", "format": "json" }, { "path": "web/package.json", "format": "json" }, { "path": "site/package.json", "format": "json" }, - { "path": "deploy/helm/roxycloud/Chart.yaml", "format": "helm" } + { "path": "deploy/helm/stashden/Chart.yaml", "format": "helm" } ], "hooks": { "postBump": "cargo update --workspace" From 2c138ba620358a681ec018429015d3db4f35370c Mon Sep 17 00:00:00 2001 From: BryanFRD Date: Sat, 3 Oct 2026 13:56:14 +0200 Subject: [PATCH 2/2] docs: point the README at the stashden chart and image Signed-off-by: BryanFRD --- README.md | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index be41389..5c71c5b 100644 --- a/README.md +++ b/README.md @@ -183,16 +183,17 @@ second deployment and no CORS to configure. Hosting the bundle elsewhere still w `STASHDEN_API_URL` pointing at the API, serve it however you like, and name its origin in `CORS_ALLOWED_ORIGINS`. -On Kubernetes, `deploy/helm/roxycloud` deploys the API against a database you already run, with a +On Kubernetes, `deploy/helm/stashden` deploys the API against a database you already run, with a volume for the blobs and an optional ingress. It does not bundle Postgres. It serves the web app, -since the image carries it. `deploy/helm/roxycloud/README.md` has the values and the reasoning. +since the image carries it. `deploy/helm/stashden/README.md` has the values and the reasoning, and +what a release installed from the former `roxycloud` chart needs to upgrade. ```bash -helm install roxycloud oci://ghcr.io/ferrlabs/charts/roxycloud --set database.url='postgres://roxycloud:password@postgres/roxycloud' --set jwt.secret="$(openssl rand -hex 32)" +helm install stashden oci://ghcr.io/ferrlabs/charts/stashden --set database.url='postgres://stashden:password@postgres/stashden' --set jwt.secret="$(openssl rand -hex 32)" ``` -The release workflow publishes the chart to `oci://ghcr.io/ferrlabs/charts/roxycloud` and the image -to `ghcr.io/ferrlabs/roxycloud-api`, for amd64 and arm64, both under the release version, so the +The release workflow publishes the chart to `oci://ghcr.io/ferrlabs/charts/stashden` and the image +to `ghcr.io/ferrlabs/stashden-api`, for amd64 and arm64, both under the release version, so the chart's default image needs no override. ## Endpoints