mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(helm): ensure coder can be deployed in a non-default namespace (#16579)
Added namespace to all resources in the helm chart and added tests to ensure that coder can be deployed in non-default namespaces, as specified via the namespace flag in the helm command. Ways to verify this: - current state: ```bash $ helm template my-coder coder -n coder --version 2.19.0 --repo https://helm.coder.com/v2 | yq '.metadata.namespace' null --- null --- null --- null --- null ``` - fixed state when checking out this PR: ```bash $ helm template my-coder ./helm/coder -n coder --set coder.image.tag=latest | yq '.metadata.namespace' coder --- coder --- coder --- coder --- coder ``` Change-Id: Ib66d4be9bcc4984dfe15709362e1fe0dcd3e847f Signed-off-by: Thomas Kosiewski <tk@coder.com>
This commit is contained in:
+31
-33
@@ -14,6 +14,7 @@
|
||||
writeShellScriptBin,
|
||||
writeText,
|
||||
writeTextFile,
|
||||
writeTextDir,
|
||||
cacert,
|
||||
storeDir ? builtins.storeDir,
|
||||
pigz,
|
||||
@@ -45,6 +46,33 @@ let
|
||||
ln -s ${bashInteractive}/bin/bash $out/bin/bash
|
||||
'';
|
||||
|
||||
etcNixConf = writeTextDir "etc/nix/nix.conf" ''
|
||||
experimental-features = nix-command flakes
|
||||
'';
|
||||
|
||||
etcPamdSudoFile = writeText "pam-sudo" ''
|
||||
# Allow root to bypass authentication (optional)
|
||||
auth sufficient pam_rootok.so
|
||||
|
||||
# For all users, always allow auth
|
||||
auth sufficient pam_permit.so
|
||||
|
||||
# Do not perform any account management checks
|
||||
account sufficient pam_permit.so
|
||||
|
||||
# No password management here (only needed if you are changing passwords)
|
||||
# password requisite pam_unix.so nullok yescrypt
|
||||
|
||||
# Keep session logging if desired
|
||||
session required pam_unix.so
|
||||
'';
|
||||
|
||||
etcPamdSudo = runCommand "etc-pamd-sudo" { } ''
|
||||
mkdir -p $out/etc/pam.d/
|
||||
ln -s ${etcPamdSudoFile} $out/etc/pam.d/sudo
|
||||
ln -s ${etcPamdSudoFile} $out/etc/pam.d/su
|
||||
'';
|
||||
|
||||
compressors = {
|
||||
none = {
|
||||
ext = "";
|
||||
@@ -130,42 +158,11 @@ let
|
||||
''}
|
||||
'';
|
||||
|
||||
nixConfFile = writeText "nix-conf" ''
|
||||
experimental-features = nix-command flakes
|
||||
'';
|
||||
|
||||
etcNixConf = runCommand "etc-nix-conf" { } ''
|
||||
mkdir -p $out/etc/nix/
|
||||
ln -s ${nixConfFile} $out/etc/nix/nix.conf
|
||||
'';
|
||||
|
||||
sudoersFile = writeText "sudoers" ''
|
||||
etcSudoers = writeTextDir "etc/sudoers" ''
|
||||
root ALL=(ALL) ALL
|
||||
${toString uname} ALL=(ALL) NOPASSWD:ALL
|
||||
'';
|
||||
|
||||
etcSudoers = runCommand "etc-sudoers" { } ''
|
||||
mkdir -p $out/etc/
|
||||
cp ${sudoersFile} $out/etc/sudoers
|
||||
chmod 440 $out/etc/sudoers
|
||||
'';
|
||||
|
||||
pamSudoFile = writeText "pam-sudo" ''
|
||||
auth sufficient pam_rootok.so
|
||||
auth required pam_permit.so
|
||||
account required pam_permit.so
|
||||
session required pam_permit.so
|
||||
session optional pam_xauth.so
|
||||
'';
|
||||
|
||||
etcPamSudo = runCommand "etc-pam-sudo" { } ''
|
||||
mkdir -p $out/etc/pam.d/
|
||||
cp ${pamSudoFile} $out/etc/pam.d/sudo
|
||||
|
||||
# We can’t chown in a sandbox, but that’s okay for Nix store.
|
||||
chmod 644 $out/etc/pam.d/sudo
|
||||
'';
|
||||
|
||||
# Add our Docker init script
|
||||
dockerInit = writeTextFile {
|
||||
name = "initd-docker";
|
||||
@@ -273,7 +270,7 @@ let
|
||||
caCertificates
|
||||
etcNixConf
|
||||
etcSudoers
|
||||
etcPamSudo
|
||||
etcPamdSudo
|
||||
(fakeNss.override {
|
||||
# Allows programs to look up the build user's home directory
|
||||
# https://github.com/NixOS/nix/blob/ffe155abd36366a870482625543f9bf924a58281/src/libstore/build/local-derivation-goal.cc#L906-L910
|
||||
@@ -333,6 +330,7 @@ let
|
||||
chmod 4755 ./usr/bin/sudo
|
||||
|
||||
chown root:root ./etc/pam.d/sudo
|
||||
chown root:root ./etc/pam.d/su
|
||||
chown root:root ./etc/sudoers
|
||||
|
||||
# Create /var/run and chown it so docker command
|
||||
|
||||
Reference in New Issue
Block a user