Author SHA1 Message Date
Renovate Bot d58bab1619 chore(deps): update dependency pnpm to v12 2026-09-06 00:04:36 +00:00
Renovate Bot e250073615 chore(deps): update workflow dependencies (minor & patch) (#184)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [docker.io/thegeeklab/git-sv](https://github.com/thegeeklab/git-sv) | container | patch | `3.0.1` → `3.0.2` |
| [volker-raschek/ah-annotations](https://github.com/volker-raschek/ah-annotations) | action | patch | `v0.2.1` → `v0.2.2` |

---

### Release Notes

<details>
<summary>thegeeklab/git-sv (docker.io/thegeeklab/git-sv)</summary>

### [`v3.0.2`](https://github.com/thegeeklab/git-sv/releases/tag/v3.0.2)

[Compare Source](https://github.com/thegeeklab/git-sv/compare/v3.0.1...v3.0.2)

#### v3.0.2 (2026-08-25)

##### Build

- **deps:** update golang version ([#&#8203;349](https://github.com/thegeeklab/git-sv/issues/349)) ([`a360b31`](https://github.com/thegeeklab/git-sv/commit/a360b31))
- **deps:** update module github.com/urfave/cli/v3 to v3.11.0 ([#&#8203;351](https://github.com/thegeeklab/git-sv/issues/351)) ([`4655693`](https://github.com/thegeeklab/git-sv/commit/4655693))
- **deps:** update golang devdeps non-major ([#&#8203;350](https://github.com/thegeeklab/git-sv/issues/350)) ([`68e6cce`](https://github.com/thegeeklab/git-sv/commit/68e6cce))
- **deps:** update ghcr.io/aquasecurity/trivy docker tag to v0.74.0 ([#&#8203;347](https://github.com/thegeeklab/git-sv/issues/347)) ([`f87d1a9`](https://github.com/thegeeklab/git-sv/commit/f87d1a9))
- **deps:** update golang patch version ([#&#8203;346](https://github.com/thegeeklab/git-sv/issues/346)) ([`b401399`](https://github.com/thegeeklab/git-sv/commit/b401399))
- **docker:** update docker.io/library/golang:1.26.5 docker digest to [`705e964`](https://github.com/thegeeklab/git-sv/commit/705e964) ([#&#8203;345](https://github.com/thegeeklab/git-sv/issues/345)) ([`157720d`](https://github.com/thegeeklab/git-sv/commit/157720d))
- **deps:** update ghcr.io/aquasecurity/trivy docker tag to v0.73.0 ([#&#8203;344](https://github.com/thegeeklab/git-sv/issues/344)) ([`f366637`](https://github.com/thegeeklab/git-sv/commit/f366637))
- fix gitsv patch categories ([`45cd763`](https://github.com/thegeeklab/git-sv/commit/45cd763))
- improve git-sv changelog sections ([`9bf518b`](https://github.com/thegeeklab/git-sv/commit/9bf518b))

</details>

<details>
<summary>volker-raschek/ah-annotations (volker-raschek/ah-annotations)</summary>

### [`v0.2.2`](https://github.com/volker-raschek/ah-annotations/compare/v0.2.1...v0.2.2)

[Compare Source](https://github.com/volker-raschek/ah-annotations/compare/v0.2.1...v0.2.2)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/184
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-09-02 18:16:40 +00:00
Renovate Bot 4269888b62 chore(deps): update lockfiles (#183)
This PR contains the following updates:

| Update | Change |
|---|---|
| lockFileMaintenance | All locks refreshed |

🔧 This Pull Request updates lock files to use the latest dependency versions.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/183
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-09-02 18:16:29 +00:00
Renovate Bot 4f4df4c08a chore(deps): update workflow dependencies (minor & patch) (#182)
This PR contains the following updates:

| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
| [alpine/helm](https://github.com/alpine-docker/helm) ([changelog](https://github.com/helm/helm)) |  | patch | `4.2.3` → `4.2.4` |  |
| [alpine/helm](https://github.com/alpine-docker/helm) ([changelog](https://github.com/helm/helm)) | container | patch | `4.2.3` → `4.2.4` |  |
| [commitlint/commitlint](https://github.com/conventional-changelog/commitlint) | container | patch | `21.2.1` → `21.2.2` |  |
| [docker.io/thegeeklab/git-sv](https://github.com/thegeeklab/git-sv) | container | patch | `3.0.0` → `3.0.1` |  |
| [https://github.com/docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) ([changelog](https://github.com/docker/setup-buildx-action/compare/bb05f3f5519dd87d3ba754cc423b652a5edd6d2c..37fe631027851001ddb9b187196cc803df7f5f0e)) | action | digest | `bb05f3f` → `37fe631` |  |
| [volker-raschek/ah-annotations](https://github.com/volker-raschek/ah-annotations) | action | patch | `v0.2.0` → `v0.2.1` | `v0.2.2` |

---

### Release Notes

<details>
<summary>conventional-changelog/commitlint (commitlint/commitlint)</summary>

### [`v21.2.2`](https://github.com/conventional-changelog/commitlint/blob/HEAD/CHANGELOG.md#2122-2026-08-13)

[Compare Source](https://github.com/conventional-changelog/commitlint/compare/v21.2.1...v21.2.2)

##### Bug Fixes

- **container:** resolve packages from TypeScript configs ([#&#8203;4914](https://github.com/conventional-changelog/commitlint/issues/4914)) ([f5712a9](https://github.com/conventional-changelog/commitlint/commit/f5712a9d216358607540e73ab4f348c237c4c224))
- **parse:** require colon after note keywords (conventional-commits-parser 7.1.2) ([#&#8203;4927](https://github.com/conventional-changelog/commitlint/issues/4927)) ([b83c515](https://github.com/conventional-changelog/commitlint/commit/b83c51569d195183c695330eeb0b4f5784e0d418)), closes [conventional-changelog/conventional-changelog#1517](https://github.com/conventional-changelog/conventional-changelog/issues/1517)
- **resolve-extends:** support Yarn Plug'n'Play ([#&#8203;4933](https://github.com/conventional-changelog/commitlint/issues/4933)) ([67ee127](https://github.com/conventional-changelog/commitlint/commit/67ee1271ea5960e774b4b956830ab4705da9040c))

</details>

<details>
<summary>thegeeklab/git-sv (docker.io/thegeeklab/git-sv)</summary>

### [`v3.0.1`](https://github.com/thegeeklab/git-sv/releases/tag/v3.0.1)

[Compare Source](https://github.com/thegeeklab/git-sv/compare/v3.0.0...v3.0.1)

#### v3.0.1 (2026-08-06)

##### Bug Fixes

- **deps:** update module github.com/go-git/go-git/v6 to v6.0.0-alpha.5 ([#&#8203;341](https://github.com/thegeeklab/git-sv/issues/341)) ([`e5767ff`](https://github.com/thegeeklab/git-sv/commit/e5767ff))

##### Others

- **docker:** update docker.io/library/golang:1.26.5 docker digest to [`2005724`](https://github.com/thegeeklab/git-sv/commit/2005724) ([#&#8203;343](https://github.com/thegeeklab/git-sv/issues/343)) ([`da8319e`](https://github.com/thegeeklab/git-sv/commit/da8319e))
- **deps:** update dependency mvdan/gofumpt to v0.11.0 ([#&#8203;342](https://github.com/thegeeklab/git-sv/issues/342)) ([`61a7494`](https://github.com/thegeeklab/git-sv/commit/61a7494))

</details>

<details>
<summary>volker-raschek/ah-annotations (volker-raschek/ah-annotations)</summary>

### [`v0.2.1`](https://github.com/volker-raschek/ah-annotations/compare/v0.2.0...v0.2.1)

[Compare Source](https://github.com/volker-raschek/ah-annotations/compare/v0.2.0...v0.2.1)

</details>

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/182
Reviewed-by: Lunny Xiao <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-08-25 21:21:26 +00:00
Lunny Xiao 9def7e2cd3 chore(build): drop AWS S3 upload from release workflow (#178)
Remove the AWS S3 upload steps from the release workflow, keeping Cloudflare R2 as the only object storage target.

- Drop the `aws credential configure` step and the AWS-specific secrets usage.
- Drop the `copy files to S3 and clear cache` step.
- The awscli install is kept because the Cloudflare R2 sync still relies on it.

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/178
Reviewed-by: DaanSelen <[email protected]>
2026-08-18 21:07:35 +00:00
Renovate Bot d4a9b9dc79 chore(deps): update lockfiles (#177)
This PR contains the following updates:

| Update | Change |
|---|---|
| lockFileMaintenance | All locks refreshed |

🔧 This Pull Request updates lock files to use the latest dependency versions.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/177
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-08-18 18:59:20 +00:00
Markus Pesch c97bf2b34c feat(ci): add ArtifactHub annotations (#179)
The following PR adds the volker-raschek/ah-annotations action. This action
reads the semantic commits between the old and new tags and uses them to
generate a changelog for ArtifactHub.

In addition, the action ensures that when pre-releases are created—for example,
v0.1.0-rc.1, v0.1.0-alpha-2, etc.—the “pre-release” annotation is added.

By default, Helm ignores pre-releases. If a user wants to install a pre-release,
they must explicitly specify this using an argument: `helm search repo gitea
--devel`.

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/179
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Markus Pesch <[email protected]>
2026-08-18 18:58:18 +00:00
daanselen 648e0b8ac3 chore: edit README accordingly 2026-08-04 16:13:41 +02:00
daanselen 3231d778dd chore: bump dind and runner 2026-08-04 16:09:26 +02:00
Renovate Bot 6e3d348a89 chore(deps): update lockfiles (#170)
This PR contains the following updates:

| Update | Change |
|---|---|
| lockFileMaintenance | All locks refreshed |

🔧 This Pull Request updates lock files to use the latest dependency versions.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/170
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-08-04 14:06:30 +00:00
Renovate Bot d57edb6005 chore(deps): update dependency helm-unittest/helm-unittest to v1.1.2 (#175)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [helm-unittest/helm-unittest](https://github.com/helm-unittest/helm-unittest) | patch | `v1.1.1` → `v1.1.2` |

---

### Release Notes

<details>
<summary>helm-unittest/helm-unittest (helm-unittest/helm-unittest)</summary>

### [`v1.1.2`](https://github.com/helm-unittest/helm-unittest/releases/tag/v1.1.2)

[Compare Source](https://github.com/helm-unittest/helm-unittest/compare/v1.1.1...v1.1.2)

**Fixes**

- Fix handling multiline block scalars in YAML (resolves [#&#8203;826](https://github.com/helm-unittest/helm-unittest/issues/826), credits [@&#8203;AruneshDwivedi](https://github.com/AruneshDwivedi))
- Fix documentSelector not working when multiple templates are used (resolves [#&#8203;781](https://github.com/helm-unittest/helm-unittest/issues/781), credits [@&#8203;twixthehero](https://github.com/twixthehero))

**Updates**

- Update packages to latest patch versions
- Update pipeline actions
- Update documentation

**Additional note**
*Due to the update of the libraries, the resourceVersion used in a fakeprovider is automatically filled, this could impact snapshots.*

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/175
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-08-04 14:04:57 +00:00
Renovate Bot 26ee25fb02 chore(deps): pin dependencies (#174)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://github.com/actions/checkout) | action | pinDigest |  → `3d3c42e` |
| [docker.io/thegeeklab/git-sv](https://github.com/thegeeklab/git-sv) | container | major | `2.1.3` → `3.0.0` |
| [https://github.com/Azure/setup-helm](https://github.com/Azure/setup-helm) | action | pinDigest |  → `9bc31f4` |
| [https://github.com/aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | action | pinDigest |  → `e6de054` |
| [https://github.com/crazy-max/ghaction-import-gpg](https://github.com/crazy-max/ghaction-import-gpg) | action | pinDigest |  → `2dc316d` |
| [https://github.com/docker/login-action](https://github.com/docker/login-action) | action | pinDigest |  → `dbcb813` |
| [https://github.com/docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | action | pinDigest |  → `bb05f3f` |
| [https://github.com/ibiqlik/action-yamllint](https://github.com/ibiqlik/action-yamllint) | action | pinDigest |  → `2576378` |
| [pnpm/action-setup](https://github.com/pnpm/action-setup) | action | pinDigest |  → `0977fd9` |

---

### Release Notes

<details>
<summary>thegeeklab/git-sv (docker.io/thegeeklab/git-sv)</summary>

### [`v3.0.0`](https://github.com/thegeeklab/git-sv/releases/tag/v3.0.0)

[Compare Source](https://github.com/thegeeklab/git-sv/compare/v2.1.3...v3.0.0)

#### v3.0.0 (2026-07-22)

##### Features

- add `retag` command ([#&#8203;339](https://github.com/thegeeklab/git-sv/issues/339)) ([`6ca1acc`](https://github.com/thegeeklab/git-sv/commit/6ca1acc))

##### Bug Fixes

- **deps:** update module github.com/urfave/cli/v3 to v3.10.1 ([#&#8203;335](https://github.com/thegeeklab/git-sv/issues/335)) ([`e1eed49`](https://github.com/thegeeklab/git-sv/commit/e1eed49))

##### Others

- **docker:** update docker.io/library/golang:1.26.5 docker digest to [`3aff665`](https://github.com/thegeeklab/git-sv/commit/3aff665) ([#&#8203;340](https://github.com/thegeeklab/git-sv/issues/340)) ([`7b26ce9`](https://github.com/thegeeklab/git-sv/commit/7b26ce9))
- **deps:** update golang patch version ([#&#8203;338](https://github.com/thegeeklab/git-sv/issues/338)) ([`9e7b538`](https://github.com/thegeeklab/git-sv/commit/9e7b538))
- **deps:** update ghcr.io/aquasecurity/trivy docker tag to v0.72.0 ([#&#8203;337](https://github.com/thegeeklab/git-sv/issues/337)) ([`fece7eb`](https://github.com/thegeeklab/git-sv/commit/fece7eb))
- drop discontinued goreportcard badge ([`1cde6e4`](https://github.com/thegeeklab/git-sv/commit/1cde6e4))
- **docker:** update docker.io/library/golang:1.26.4 docker digest to [`f96cc55`](https://github.com/thegeeklab/git-sv/commit/f96cc55) ([#&#8203;336](https://github.com/thegeeklab/git-sv/issues/336)) ([`3686e26`](https://github.com/thegeeklab/git-sv/commit/3686e26))
- **docker:** update docker.io/library/golang:1.26.4 docker digest to [`32c0e6e`](https://github.com/thegeeklab/git-sv/commit/32c0e6e) ([#&#8203;333](https://github.com/thegeeklab/git-sv/issues/333)) ([`d920969`](https://github.com/thegeeklab/git-sv/commit/d920969))
- drop `--force` from tag subcommand ([#&#8203;334](https://github.com/thegeeklab/git-sv/issues/334)) ([`2a8e1a9`](https://github.com/thegeeklab/git-sv/commit/2a8e1a9))
- **deps:** update ci tools non-major to v0.71.2 ([#&#8203;332](https://github.com/thegeeklab/git-sv/issues/332)) ([`42678cb`](https://github.com/thegeeklab/git-sv/commit/42678cb))

##### BREAKING CHANGES

- The `--force` flag of the tag subcommand was not useful and got replaced by a dedicated subcommand `retag` with [#&#8203;327](https://github.com/thegeeklab/git-sv/pull/327).

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->

Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/174
Reviewed-by: Lunny Xiao <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-08-04 14:04:38 +00:00
Lunny Xiao 5c82dc0e65 chore(build): upload release to R2 (#173)
Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/173
Reviewed-by: Zettat123 <[email protected]>
2026-07-26 05:31:50 +00:00
6537bdbd33 feat: add per-container resource configuration for runner and DinD #160 (#168)
This a correction that is forf from original work of [anders.eficode](https://gitea.com/anders.eficode) on [pull request #160](https://gitea.com/gitea/helm-actions/pulls/160)
Description of the change
Adds statefulset.dind.resources and statefulset.runner.resources as optional per-container resource overrides. When set, each takes precedence over the shared statefulset.resources for that container. When unset (default {}), statefulset.resources is used as before.

Benefits
The DinD sidecar and the runner container have very different resource profiles — DinD is memory-hungry (image layer cache, concurrent builds, image pulls) while the runner is a lightweight coordinator that is mostly idle between jobs. Separate resource limits allow right-sizing each container independently, avoiding the choice between over-provisioning the runner or under-provisioning DinD.

Possible drawbacks
None. Fully backward-compatible — both new values default to {}, causing the shared statefulset.resources fallback to apply exactly as before.

Checklist
- [x] Parameters are documented in the `values.yaml` and added to the `README.md` using [readme-generator-for-helm](https://github.com/bitnami-labs/readme-generator-for-helm)
- [x] Breaking changes are documented in the `README.md`
- [x] Helm templating unittests are added (required when changing anything in `templates` folder)
- [x] Bash unittests are added (required when changing anything in `scripts` folder)
- [x] All added template resources MUST render a namespace in metadata

---------

Co-authored-by: Le Prévost-Corvellec Arnault <[email protected]>
Co-authored-by: Anders <[email protected]>
Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/168
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Arnault_LPC <[email protected]>
2026-07-21 06:41:06 +00:00
Renovate Bot 37080c6548 chore(deps): update workflow dependencies (minor & patch) (#172)
This PR contains the following updates:

| Package | Type | Update | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|
| [alpine/helm](https://github.com/alpine-docker/helm) ([changelog](https://github.com/helm/helm)) |  | patch | `4.2.2` → `4.2.3` | ![age](https://developer.mend.io/api/mc/badges/age/docker/alpine%2fhelm/4.2.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/docker/alpine%2fhelm/4.2.2/4.2.3?slim=true) |
| [alpine/helm](https://github.com/alpine-docker/helm) ([changelog](https://github.com/helm/helm)) | container | patch | `4.2.2` → `4.2.3` | ![age](https://developer.mend.io/api/mc/badges/age/docker/alpine%2fhelm/4.2.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/docker/alpine%2fhelm/4.2.2/4.2.3?slim=true) |
| [commitlint/commitlint](https://github.com/conventional-changelog/commitlint) | container | patch | `21.2.0` → `21.2.1` | ![age](https://developer.mend.io/api/mc/badges/age/docker/commitlint%2fcommitlint/21.2.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/docker/commitlint%2fcommitlint/21.2.0/21.2.1?slim=true) |
| [markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli) | devDependencies | patch | [`0.49.0` → `0.49.1`](https://renovatebot.com/diffs/npm/markdownlint-cli/0.49.0/0.49.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/markdownlint-cli/0.49.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/markdownlint-cli/0.49.0/0.49.1?slim=true) |

---

### Release Notes

<details>
<summary>conventional-changelog/commitlint (commitlint/commitlint)</summary>

### [`v21.2.1`](https://github.com/conventional-changelog/commitlint/blob/HEAD/CHANGELOG.md#2121-2026-07-08)

[Compare Source](https://github.com/conventional-changelog/commitlint/compare/v21.2.0...v21.2.1)

**Note:** Version bump only for package [@&#8203;commitlint/root](https://github.com/commitlint/root)

</details>

<details>
<summary>igorshubovych/markdownlint-cli (markdownlint-cli)</summary>

### [`v0.49.1`](https://github.com/igorshubovych/markdownlint-cli/releases/tag/v0.49.1)

[Compare Source](https://github.com/igorshubovych/markdownlint-cli/compare/v0.49.0...v0.49.1)

- Update `markdownlint` dependency to `0.41.1`
  - Improve `MD029`
  - Fix module resolution under `webpack`
  - Update dependencies
- Update all dependencies via `Dependabot`

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJraW5kL2RlcGVuZGVuY3kiXX0=-->Reviewed-on: https://gitea.com/gitea/helm-actions/pulls/172
Reviewed-by: DaanSelen <[email protected]>
Co-authored-by: Renovate Bot <[email protected]>
2026-07-21 06:39:45 +00:00
13 changed files with 410 additions and 129 deletions
+2 -2
View File
@@ -8,12 +8,12 @@ on:
jobs:
changelog:
runs-on: ubuntu-latest
container: docker.io/thegeeklab/git-sv:2.1.3
container: docker.io/thegeeklab/git-sv:3.0.2
steps:
- name: install tools
run: |
apk add -q --update --no-cache nodejs curl jq sed
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- name: Generate upcoming changelog
+2 -2
View File
@@ -11,9 +11,9 @@ on:
jobs:
check-and-test:
runs-on: ubuntu-latest
container: commitlint/commitlint:21.2.0
container: commitlint/commitlint:21.2.2
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: check PR title
run: |
echo "${{ gitea.event.pull_request.title }}" | commitlint --config .commitlintrc.json
+17 -17
View File
@@ -7,20 +7,20 @@ on:
env:
# renovate: datasource=docker depName=alpine/helm
HELM_VERSION: "4.2.2"
HELM_VERSION: "4.2.4"
jobs:
generate-chart-publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: install Docker CLI
uses: https://github.com/docker/setup-buildx-action@v4 # Gitea
uses: https://github.com/docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4 # Gitea
#uses: docker/setup-buildx-action@v4 # Github / Act
- name: install Helm
uses: https://github.com/Azure/setup-helm@v5 # Gitea
uses: https://github.com/Azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5 # Gitea
#uses: Azure/setup-helm@v5 # Github / Act
with:
version: "${{ env.HELM_VERSION }}"
@@ -33,7 +33,7 @@ jobs:
- name: import GPG key
id: import_gpg
uses: https://github.com/crazy-max/ghaction-import-gpg@v7 # Gitea
uses: https://github.com/crazy-max/ghaction-import-gpg@2dc316deee8e90f13e1a351ab510b4d5bc0c82cd # v7 # Gitea
#uses: crazy-max/ghaction-import-gpg@v7 # Github / Act
with:
gpg_private_key: ${{ secrets.GPGSIGN_KEY }}
@@ -41,12 +41,15 @@ jobs:
fingerprint: CC64B1DB67ABBEECAB24B6455FC346329753F4B0
- name: log into Docker Hub
uses: https://github.com/docker/login-action@v4 # Gitea
uses: https://github.com/docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 # Gitea
#uses: docker/login-action@v4 # Github / Act
with:
username: ${{ secrets.DOCKER_CHARTS_USERNAME }}
password: ${{ secrets.DOCKER_CHARTS_PASSWORD }}
- name: Add Artifacthub.io annotations
uses: volker-raschek/ah-annotations@7959e52208294befed11210aef0c8e9299cc6a23 # v0.2.2
# Using helm gpg plugin as 'helm package --sign' has issues with gpg2: https://github.com/helm/helm/issues/2843
- name: package chart
run: |
@@ -67,15 +70,12 @@ jobs:
env:
TAR_OPTIONS: "--wildcards"
- name: aws credential configure
uses: https://github.com/aws-actions/configure-aws-credentials@v6 # Gitea
#uses: aws-actions/configure-aws-credentials@v6 # Github / Act
with:
aws-access-key-id: ${{ secrets.AWS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ secrets.AWS_REGION }}
- name: copy files to S3 and clear cache
if: startsWith(github.ref, 'refs/tags/')
- name: Copy files to Cloudflare R2
env:
AWS_ACCESS_KEY_ID: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.CLOUDFLARE_R2_SECRET_ACCESS_KEY }}
AWS_DEFAULT_REGION: auto
CLOUDFLARE_R2_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_R2_ACCOUNT_ID }}
CLOUDFLARE_R2_BUCKET: ${{ secrets.CLOUDFLARE_R2_BUCKET }}
run: |
aws s3 sync actions/ s3://${{ secrets.AWS_S3_BUCKET}}/charts/
aws s3 sync actions/ s3://${CLOUDFLARE_R2_BUCKET}/charts/ --endpoint-url https://${CLOUDFLARE_R2_ACCOUNT_ID}.r2.cloudflarestorage.com
+1 -1
View File
@@ -9,6 +9,6 @@ jobs:
shellcheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- run: apt update --yes && apt install --yes shellcheck
- run: find . -type f -name "*.sh" -exec shellcheck -a {} \;
+6 -6
View File
@@ -11,22 +11,22 @@ name: check-and-test
env:
# renovate: datasource=github-releases depName=helm-unittest/helm-unittest
HELM_UNITTEST_VERSION: "v1.1.1"
HELM_UNITTEST_VERSION: "v1.1.2"
jobs:
check-and-test:
runs-on: ubuntu-latest
container: alpine/helm:4.2.2
container: alpine/helm:4.2.4
steps:
- name: install tools
run: |
apk update
apk add --update bash make nodejs npm yamllint ncurses
- name: Install pnpm
uses: pnpm/action-setup@v6
uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6
with:
version: 11
- uses: actions/checkout@v7
version: 12
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: install chart dependencies
run: helm dependency build
- name: lint
@@ -49,4 +49,4 @@ jobs:
git diff --exit-code --name-only README.md
- name: yaml lint
# uses: ibiqlik/action-yamllint@v3 # Github / Act
uses: https://github.com/ibiqlik/action-yamllint@v3 # Gitea
uses: https://github.com/ibiqlik/action-yamllint@2576378a8e339169678f9939646ee3ee325e845c # v3 # Gitea
+8 -4
View File
@@ -65,14 +65,16 @@ If `.Values.statefulset.dind.rootless: true` is set, then the following will be
### Gitea Actions
For resource limit examples (runner vs DinD), see [docs/resources.md](./docs/resources.md).
| Name | Description | Value |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------ |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------ |
| `enabled` | Create a Gitea Runner StatefulSet. | `false` |
| `statefulset.replicas` | the amount of (replica) runner pods deployed | `1` |
| `statefulset.timezone` | is the timezone that will be set in the runner image | `Etc/UTC` |
| `statefulset.annotations` | Gitea Runner annotations | `{}` |
| `statefulset.labels` | Gitea Runner labels | `{}` |
| `statefulset.resources` | Gitea Runner resources | `{}` |
| `statefulset.resources` | Shared resource requests/limits for both containers. Overridden by statefulset.runner.resources and statefulset.dind.resources. See docs/resources.md. | `{}` |
| `statefulset.nodeSelector` | NodeSelector for the statefulset | `{}` |
| `statefulset.tolerations` | Tolerations for the statefulset | `[]` |
| `statefulset.affinity` | Affinity for the statefulset | `{}` |
@@ -85,10 +87,11 @@ If `.Values.statefulset.dind.rootless: true` is set, then the following will be
| `statefulset.persistence.size` | Size for persistence to store Gitea Runner data | `1Gi` |
| `statefulset.runner.registry` | image registry, e.g. gcr.io,docker.io | `docker.gitea.com` |
| `statefulset.runner.repository` | The Gitea Runner image | `runner` |
| `statefulset.runner.tag` | The Gitea Runner tag | `2.0.1` |
| `statefulset.runner.tag` | The Gitea Runner tag | `3.0.2` |
| `statefulset.runner.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `statefulset.runner.pullPolicy` | The Gitea Runner pullPolicy | `IfNotPresent` |
| `statefulset.runner.fullOverride` | Completely overrides the image registry, path/image, tag and digest. | `""` |
| `statefulset.runner.resources` | Resource requests/limits for the runner container. Takes precedence over statefulset.resources when set. | `{}` |
| `statefulset.runner.extraVolumeMounts` | Allows mounting extra volumes in the Gitea Runner container | `[]` |
| `statefulset.runner.extraEnvs` | Allows adding custom environment variables | `[]` |
| `statefulset.runner.flushCache` | whether to clear the .runner (cache) file by creating an extra init container, can slightly increase boot-up time | `false` |
@@ -97,10 +100,11 @@ If `.Values.statefulset.dind.rootless: true` is set, then the following will be
| `statefulset.dind.uid` | a field to set the running user id for the rootless dind container, so it knows where to look for the socket | `""` |
| `statefulset.dind.registry` | image registry, e.g. gcr.io,docker.io | `docker.io` |
| `statefulset.dind.repository` | The Docker-in-Docker image | `docker` |
| `statefulset.dind.tag` | The Docker-in-Docker image tag | `29.5.2-dind` |
| `statefulset.dind.tag` | The Docker-in-Docker image tag | `29.7.1-dind` |
| `statefulset.dind.digest` | Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest` | `""` |
| `statefulset.dind.fullOverride` | Completely overrides the image registry, path/image, tag and digest. | `""` |
| `statefulset.dind.pullPolicy` | The Docker-in-Docker pullPolicy | `IfNotPresent` |
| `statefulset.dind.resources` | Resource requests/limits for the DinD sidecar container. Takes precedence over statefulset.resources when set. | `{}` |
| `statefulset.dind.extraVolumeMounts` | Allows mounting extra volumes in the Docker-in-Docker container | `[]` |
| `statefulset.dind.extraEnvs` | Allows adding custom environment variables, such as `DOCKER_IPTABLES_LEGACY` | `[]` |
| `statefulset.dind.extraArgs` | Allows adding custom arguments to the Docker Daemon | `[]` |
+1
View File
@@ -1,3 +1,4 @@
# Gitea Actions Helm Chart Docs
- [Resource limits and capacity](./resources.md)
- [connectionCommandOverride explanation](./connectionCommandOverride.md)
+173
View File
@@ -0,0 +1,173 @@
# Resource limits and capacity
By default, all resource values are empty (`{}`). Without explicit limits, runner pods can consume unbounded CPU and memory on a node. This guide explains how to configure resource usage properly.
## Pod architecture
Each runner pod contains two resource-consuming containers:
| Container | Role | Helm value |
| --- | --- | --- |
| `runner` | Polls Gitea and orchestrates CI jobs | `statefulset.runner.resources` |
| `dind` | Docker-in-Docker daemon; executes job containers | `statefulset.dind.resources` |
The DinD container runs as a native sidecar (`initContainer` with `restartPolicy: Always`).
## Helm resource keys
Three values control Kubernetes resource requests and limits:
| Key | Purpose |
| --- | --- |
| `statefulset.resources` | Shared fallback applied to **both** containers when no override is set |
| `statefulset.runner.resources` | Override for the `runner` container only |
| `statefulset.dind.resources` | Override for the `dind` container only |
Precedence:
```text
statefulset.runner.resources → else statefulset.resources
statefulset.dind.resources → else statefulset.resources
```
**Recommendation:** set `statefulset.runner.resources` and `statefulset.dind.resources`
explicitly instead of relying on the shared fallback. The runner process is lightweight;
DinD and CI workloads need most of the budget.
## Example: separate runner and DinD limits
```yaml
enabled: true
giteaRootURL: https://gitea.example.com
existingSecret: runner-secret
existingSecretKey: runner-token
statefulset:
replicas: 1
runner:
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
config: |
log:
level: info
cache:
enabled: false
runner:
capacity: 1
container:
require_docker: true
docker_timeout: 300s
dind:
resources:
requests:
cpu: 500m
memory: 2Gi
limits:
cpu: 2
memory: 4Gi
```
## Two layers of limiting
Kubernetes limits and act-runner job limits serve different purposes. Use both for a robust setup.
### 1. Kubernetes limits (Helm values)
These apply to the `runner` and `dind` containers in the pod.
- **`dind` limits** cap the Docker daemon and everything it runs inside the pod (images, build caches, job containers).
- **`runner` limits** cap the act-runner process itself.
If neither is set, a runaway build can exhaust the entire node.
### 2. Per-job Docker limits (`container.options`)
CI jobs run as Docker containers spawned by act-runner through the Docker socket. They are
**not** separate Kubernetes containers. Configure per-job limits in `statefulset.runner.config`
— see [act-runner configuration](https://docs.gitea.com/usage/actions/act-runner#configuration)
and [config.example.yaml](https://gitea.com/gitea/runner/src/branch/main/internal/pkg/config/config.example.yaml).
## act-runner settings that affect resource usage
Settings such as `runner.capacity` and `container.options` live in `statefulset.runner.config`, not in the Helm resource values. Refer to the runner documentation for details:
- [act-runner configuration](https://docs.gitea.com/usage/actions/act-runner#configuration)
- [config.example.yaml](https://gitea.com/gitea/runner/src/branch/main/internal/pkg/config/config.example.yaml) in the [Gitea/runner](https://gitea.com/gitea/runner) repository
When concurrent jobs or per-job Docker limits increase expected load, size `statefulset.dind.resources` accordingly on the Helm side.
## Capacity planning
These formulas apply to the Helm resource values (`statefulset.runner.resources`, `statefulset.dind.resources`, `statefulset.replicas`):
### Per pod
```text
pod budget ≈ runner.limits + dind.limits
```
### Per node
```text
node budget ≈ (runner.limits + dind.limits) × statefulset.replicas + system overhead
```
Example with the configuration above and `replicas: 3`:
- runner: 512Mi × 3 = 1.5Gi
- dind: 4Gi × 3 = 12Gi
- total: ~13.5Gi minimum, excluding other workloads on the node
Use `statefulset.nodeSelector` and `statefulset.tolerations` to place runners on dedicated nodes when needed.
## Why not only set `statefulset.resources`?
Before chart 0.1.2, one value was copied to **both** containers. **Requests** are where it
hurts most: the scheduler reserves capacity per container, and both inherit the same numbers.
```yaml
# Only statefulset.resources — requests copied to runner AND dind:
statefulset:
resources:
requests:
cpu: 500m
memory: 2Gi # what DinD needs…
# runner also requests 500m + 2Gi → pod ~1 CPU + ~4Gi reserved (mostly wasted)
# dind requests 500m + 2Gi ✓
```
```yaml
statefulset:
resources:
requests:
cpu: 100m
memory: 256Mi # what the runner actually needs…
# runner requests 100m + 256Mi ✓
# dind requests 100m + 256Mi too → tiny slot, builds starve ✗
```
```yaml
# Separate overrides — scheduler sees the real footprint:
statefulset:
resources: {}
runner:
resources:
requests:
cpu: 100m
memory: 256Mi
dind:
resources:
requests:
cpu: 500m
memory: 2Gi
# pod requests ~600m CPU + ~2.25Gi RAM — not 1 CPU + 4Gi, nor 200m + 512Mi
```
Limits follow the same split. Unset overrides (`{}`) still fall back to `statefulset.resources`.
+57 -57
View File
@@ -13,7 +13,7 @@ importers:
version: 2.7.2
markdownlint-cli:
specifier: ^0.49.0
version: 0.49.0
version: 0.49.1
packages:
@@ -33,8 +33,8 @@ packages:
'@types/[email protected]':
resolution: {integrity: sha512-CmBKiL6NNo/OqgmMn95Fk9Whlp2mtvIv+KNpQKN2F4SjvrEesubTRWGYSg+BnWZOnlCaSTU1sMpsBOzgbYhnsA==}
ansi-regex@6.2.2:
resolution: {integrity: sha512-Bq3SmSpyFHaWjPk8If9yc6svM8c56dB5BAtW4Qbw5jHTwwXXcTLoRMkpDJp6VL0XzlWaCHTXrkFURMYmD0sLqg==}
ansi-regex@6.3.0:
resolution: {integrity: sha512-WpDfL7NO6j7tH88IDBNVdUJxDh9nmCteAVW9dsep846XdwF4naCBK+/tGLX3KJgcpgMRXCFlTM2hKGoK9FsdrQ==}
engines: {node: '>=12'}
[email protected]:
@@ -47,12 +47,12 @@ packages:
resolution: {integrity: sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==}
engines: {node: 18 || 20 || >=22}
[email protected]6:
resolution: {integrity: sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==}
[email protected]8:
resolution: {integrity: sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==}
[email protected].7:
resolution: {integrity: sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==}
engines: {node: 18 || 20 || >=22}
[email protected].9:
resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==}
engines: {node: 20 || >=22}
[email protected]:
resolution: {integrity: sha512-RpPp0asT/6ufRm//AJVwpViZbGM/MkjQFxJccQRHmISF/22NBtsHqAWmL+/pmkPWoIUJdWyeVleTl1wydHATVQ==}
@@ -144,9 +144,9 @@ packages:
[email protected]:
resolution: {integrity: sha512-k/vGaX4/Yla3WzyMCvTQOXYeIHvqOKtnqBduzTHpzpQZzAskKMhZ2K+EnBiSM9zGSoIFeMpXKxa4dYeZIQqewQ==}
ini@4.1.3:
resolution: {integrity: sha512-X7rqawQBvfdjS10YU1y1YVreA3SsLrW9dX2CewP2EbBJM4ypVNLDkO5y04gejPwKIY9lR+7r9gn3rFPt/kmWFg==}
engines: {node: ^14.17.0 || ^16.13.0 || >=18.0.0}
ini@7.0.0:
resolution: {integrity: sha512-ifK0CgjALofS5bkrcTy4RaQ9Vx2Knf/eLeIO+NaswQEpH1UblrtTSCIvN71qQDMq0PeQ/SSPojvEJp9vvvfr+w==}
engines: {node: ^22.22.2 || ^24.15.0 || >=26.0.0}
[email protected]:
resolution: {integrity: sha512-FWyyY60MeTNyeSRpkM2Iry0G9hpr7/9kD40mD/cGQEuilcZYS4okz8SN2Q6rLCJ8gbCt6fN+rC+6tMGS99LaxQ==}
@@ -160,8 +160,8 @@ packages:
[email protected]:
resolution: {integrity: sha512-DgZQp241c8oO6cA1SbTEWiXeoxV42vlcJxgH+B3hi1AiqqKruZR3ZGF8In3fj4+/y/7rHvlOZLZtgJ/4ttYGZg==}
js-yaml@4.2.0:
resolution: {integrity: sha512-ePWsvanv0DWuDRsW8dnt+R4jQ31SCRCQ7hhNcPXZPsoBZiemuZNYGf7adZdqX2D86j6rvKp3RpCxVTSb8WQlOw==}
js-yaml@5.2.3:
resolution: {integrity: sha512-n+mUVyUX5bVv7G/G2zyIHOhdxfuU1dY2NOFzTQUWiMUbFss8b57NFlgCCaggU78wSw5KVS9cllzeLyzyR+n5nw==}
hasBin: true
[email protected]:
@@ -181,24 +181,24 @@ packages:
[email protected]:
resolution: {integrity: sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==}
markdown-it@14.2.0:
resolution: {integrity: sha512-1TGiQiJVRQ3NPmZH6sx5Cfnmg6GQm9jvC1ch4TK511NjSJvjzKLzn5pPfZRNZkRPZP0HqCioSndqH8v2nRaWVQ==}
markdown-it@14.3.0:
resolution: {integrity: sha512-RCEsPjR+sr0x+AuYp601tKTkgFG4YEPLCzHST3cQ/fhlJkqAkz1L2/Qbp1j9qw5SBwQHFBoW8+hoN5xssOF0Tw==}
hasBin: true
[email protected]:
resolution: {integrity: sha512-Ezda85ToJUBhM6WGaG6veasyym+Tbs3cMAw/ZhOPqXiYsr0jgocBV3j3nx+4lk47plLlIqjwuTm/ywVI+zjJ/A==}
[email protected].0:
resolution: {integrity: sha512-vS5tWq5W91Gg33LD4pyAaXPclnz/sRvo6/RGOyDQjQ3eds2DkK6H4szUuE0M9TiRB/u/VBx1gtd9Ktrtx5WlSA==}
[email protected].1:
resolution: {integrity: sha512-qpYqJbSYf3jv57bdnFmCaZ/Wlu6IYHp2b6SOKrKBJ7OnPrDHIKmx4NERWH49QH9viTI6yO6raVDDn5nrf60VQQ==}
engines: {node: '>=22'}
hasBin: true
[email protected].0:
resolution: {integrity: sha512-xMUI3ChBuRuxuLF4ENvCZyS8z/+Jly1coUcZwErKLIB3sDj7ojpaTBa1e9YVPhSN4jGEIjYGQCldbTJS/hqS+A==}
[email protected].1:
resolution: {integrity: sha512-qHKeU2E1bdyNAT077go2FVTNXvYcktN5IHtF6XyeD1l0PClxzSp2tUApAV14ORI8DGX4H9bNKZEzelZp4qn8IA==}
engines: {node: '>=22'}
mdurl@2.0.0:
resolution: {integrity: sha512-Lf+9+2r+Tdp5wXDXC4PcIBjTDtq4UKjCPMQhKIuzpJNW0b96kVqSwW0bT7FhRSfmAiFYgP+SCRvdrDozfh0U5w==}
mdurl@2.1.0:
resolution: {integrity: sha512-1+HBaOx0zi/dQWht8rNv9MYf9qqpqL/kxI0hXImU6Y547zM6Sni8BQibt7ifgMcYtQg41ao3Ivd6cnSM86inpg==}
[email protected]:
resolution: {integrity: sha512-RDBrHEMSxVFLg6xvnXmb1Ayr2WzLAWjeSATAoxwKYJV94TeNavgoIdA0a9ytzDSVzBy2YKFK+emCPOEibLeCrg==}
@@ -275,8 +275,8 @@ packages:
[email protected]:
resolution: {integrity: sha512-zpe98Q6kvavpCr1NPVSCMebCKfD7CA2NqZ+rykeNhONIJBpc1tFKt9hucLGwha3jNTNI8lHpctWJWoimVF4PfA==}
[email protected].5:
resolution: {integrity: sha512-MULkVLfKGYDFYejP07QOurDLLQpcjk7Fw+7jXS2R2czRQzR56yHRveU5NDJEOviH+hETZKSkIk5c+T23GjFUMg==}
[email protected].6:
resolution: {integrity: sha512-vpLQEs+VLCr1nU0BXS07maYoFwlDAH0gngQuuttxIwutDFEMHq2blX+8vpgxDdK3J1PwjCJiep77OitTZ4Ll1A==}
engines: {node: 18 || 20 || >=22}
[email protected]:
@@ -298,8 +298,8 @@ packages:
resolution: {integrity: sha512-AVbw3UJ2e9bq64vSaS9Am0fje1Pa8pbGqTTsmXfaIiMpnr5DlDhfJOuLj9Sf95ZPVDAUerDfEk88MPmPe7UCQg==}
engines: {node: '>=0.10.0'}
[email protected].5:
resolution: {integrity: sha512-RvwwcruNjI1ncT5xRakeyS9Lf8lcItv34KD+aif+VH9kduAyfYBipGh12274xtenIPZ119/R9BdTBa8gAwSh0A==}
[email protected].7:
resolution: {integrity: sha512-qcJu88Q2IWqJsDD529JKMdwGm/dvInW4HvQnRwiH9JtihJvzGOscDtHE3x1pBKeUOTysQ8kVmLnJ2kJu7yhcGA==}
engines: {node: '>=12'}
[email protected]:
@@ -310,12 +310,12 @@ packages:
resolution: {integrity: sha512-PV0dzCYDNfRi1jCDbJzpW7jNNDRuCOG/jI5ctQcGKt/clZD+YcPS3yIlWuTJMmESC8aevCFmWJy5wjAFgNqN6w==}
engines: {node: '>=0.10'}
[email protected].2:
resolution: {integrity: sha512-CcfE+mYiTcKEzg0IqS08+efdnH0oJ3zV0wSUFBNrMHMuxCtXvBCLzCJHatwuXDcu/RlhjTziTo/a1ruQik6/Yg==}
[email protected].3:
resolution: {integrity: sha512-Lb7OKM9aaykzyoNiHGhSVCjZsvbyy6qDMp2vDXL+MoCfz3GfNJtHYH7uYsU3QNMyInBk++xx+EZ8xZ8Sxs5fNQ==}
hasBin: true
smol-toml@1.6.1:
resolution: {integrity: sha512-dWUG8F5sIIARXih1DTaQAX4SsiTXhInKf1buxdY9DIg4ZYPZK5nGM1VRIYmEbDbsHt7USo99xSLFu5Q1IqTmsg==}
smol-toml@1.7.2:
resolution: {integrity: sha512-pXFZ9B2WinEPzxWkMmlYE/oYx2BP+qLrE95wP8tCuK901uLSMGdCb6QSr82z+wnhXkG4+cO+OMLbZB2Cn+97zw==}
engines: {node: '>= 18'}
[email protected]:
@@ -365,7 +365,7 @@ snapshots:
'@types/[email protected]': {}
ansi-regex@6.2.2: {}
ansi-regex@6.3.0: {}
[email protected]: {}
@@ -373,12 +373,12 @@ snapshots:
[email protected]: {}
[email protected]6:
[email protected]8:
dependencies:
balanced-match: 1.0.2
concat-map: 0.0.1
[email protected].7:
[email protected].9:
dependencies:
balanced-match: 4.0.4
@@ -421,9 +421,9 @@ snapshots:
[email protected]: {}
[email protected]([email protected].5):
[email protected]([email protected].7):
optionalDependencies:
picomatch: 4.0.5
picomatch: 4.0.7
[email protected]: {}
@@ -447,7 +447,7 @@ snapshots:
[email protected]: {}
ini@4.1.3: {}
ini@7.0.0: {}
[email protected]: {}
@@ -460,7 +460,7 @@ snapshots:
[email protected]: {}
js-yaml@4.2.0:
js-yaml@5.2.3:
dependencies:
argparse: 2.0.1
@@ -478,12 +478,12 @@ snapshots:
[email protected]: {}
markdown-it@14.2.0:
markdown-it@14.3.0:
dependencies:
argparse: 2.0.1
entities: 4.5.0
linkify-it: 5.0.2
mdurl: 2.0.0
mdurl: 2.1.0
punycode.js: 2.3.1
uc.micro: 2.1.0
@@ -491,24 +491,24 @@ snapshots:
dependencies:
repeat-string: 1.6.1
[email protected].0:
[email protected].1:
dependencies:
commander: 15.0.0
deep-extend: 0.6.0
ignore: 7.0.6
js-yaml: 4.2.0
js-yaml: 5.2.3
jsonc-parser: 3.3.1
jsonpointer: 5.0.1
markdown-it: 14.2.0
markdownlint: 0.41.0
minimatch: 10.2.5
run-con: 1.3.2
smol-toml: 1.6.1
markdown-it: 14.3.0
markdownlint: 0.41.1
minimatch: 10.2.6
run-con: 1.3.3
smol-toml: 1.7.2
tinyglobby: 0.2.17
transitivePeerDependencies:
- supports-color
[email protected].0:
[email protected].1:
dependencies:
micromark: 4.0.2
micromark-core-commonmark: 2.0.3
@@ -522,7 +522,7 @@ snapshots:
transitivePeerDependencies:
- supports-color
mdurl@2.0.0: {}
mdurl@2.1.0: {}
[email protected]:
dependencies:
@@ -696,13 +696,13 @@ snapshots:
transitivePeerDependencies:
- supports-color
[email protected].5:
[email protected].6:
dependencies:
brace-expansion: 5.0.7
brace-expansion: 5.0.9
[email protected]:
dependencies:
brace-expansion: 1.1.16
brace-expansion: 1.1.18
[email protected]: {}
@@ -724,20 +724,20 @@ snapshots:
[email protected]: {}
[email protected].5: {}
[email protected].7: {}
[email protected]: {}
[email protected]: {}
[email protected].2:
[email protected].3:
dependencies:
deep-extend: 0.6.0
ini: 4.1.3
ini: 7.0.0
minimist: 1.2.8
strip-json-comments: 3.1.1
smol-toml@1.6.1: {}
smol-toml@1.7.2: {}
[email protected]:
dependencies:
@@ -746,14 +746,14 @@ snapshots:
[email protected]:
dependencies:
ansi-regex: 6.2.2
ansi-regex: 6.3.0
[email protected]: {}
[email protected]:
dependencies:
fdir: 6.5.0([email protected].5)
picomatch: 4.0.5
fdir: 6.5.0([email protected].7)
picomatch: 4.0.7
[email protected]: {}
+14
View File
@@ -116,6 +116,13 @@ Create image for the Gitea Actions Act Runner
{{ include "gitea.actions.common.image" (dict "root" . "image" .Values.statefulset.runner) }}
{{- end -}}
{{/*
Resolve resource requests/limits for the runner container.
*/}}
{{- define "gitea.actions.runner.resources" -}}
{{- toYaml (default .Values.statefulset.resources .Values.statefulset.runner.resources) -}}
{{- end -}}
{{/*
Create image for DinD
*/}}
@@ -123,6 +130,13 @@ Create image for DinD
{{ include "gitea.actions.common.image" (dict "root" . "image" .Values.statefulset.dind) }}
{{- end -}}
{{/*
Resolve resource requests/limits for the DinD container.
*/}}
{{- define "gitea.actions.dind.resources" -}}
{{- toYaml (default .Values.statefulset.resources .Values.statefulset.dind.resources) -}}
{{- end -}}
{{/*
Create image for Init
*/}}
+2 -2
View File
@@ -120,7 +120,7 @@ spec:
- /var/run/docker.sock
{{- end }}
resources:
{{- toYaml .Values.statefulset.resources | nindent 12 }}
{{- include "gitea.actions.dind.resources" . | nindent 12 }}
volumeMounts:
{{- if .Values.statefulset.dind.rootless }}
- mountPath: /run/user/{{ .Values.statefulset.dind.uid | default 1000 }}/
@@ -155,7 +155,7 @@ spec:
{{- toYaml .Values.statefulset.runner.extraEnvs | nindent 12 }}
{{- end }}
resources:
{{- toYaml .Values.statefulset.resources | nindent 12 }}
{{- include "gitea.actions.runner.resources" . | nindent 12 }}
volumeMounts:
- mountPath: /runner/config.yaml
name: runner-config
+82
View File
@@ -451,3 +451,85 @@ tests:
- equal:
path: spec.template.spec.initContainers[0].image
value: test.io/busybox:1.37.0
#
## RESOURCES
#
- it: shared statefulset.resources applies to both runner and dind containers
template: templates/statefulset.yaml
set:
enabled: true
statefulset.resources:
requests:
memory: "512Mi"
cpu: "250m"
limits:
memory: "1Gi"
asserts:
- hasDocuments:
count: 1
- equal:
path: spec.template.spec.containers[0].resources
value:
requests:
memory: "512Mi"
cpu: "250m"
limits:
memory: "1Gi"
- equal:
path: spec.template.spec.initContainers[1].resources
value:
requests:
memory: "512Mi"
cpu: "250m"
limits:
memory: "1Gi"
- it: statefulset.runner.resources overrides shared resources for runner container only
template: templates/statefulset.yaml
set:
enabled: true
statefulset.resources:
requests:
memory: "512Mi"
statefulset.runner.resources:
requests:
memory: "256Mi"
asserts:
- hasDocuments:
count: 1
- equal:
path: spec.template.spec.containers[0].resources
value:
requests:
memory: "256Mi"
- equal:
path: spec.template.spec.initContainers[1].resources
value:
requests:
memory: "512Mi"
- it: statefulset.dind.resources overrides shared resources for dind container only
template: templates/statefulset.yaml
set:
enabled: true
statefulset.resources:
requests:
memory: "512Mi"
statefulset.dind.resources:
requests:
memory: "4Gi"
asserts:
- hasDocuments:
count: 1
- equal:
path: spec.template.spec.containers[0].resources
value:
requests:
memory: "512Mi"
- equal:
path: spec.template.spec.initContainers[1].resources
value:
requests:
memory: "4Gi"
+10 -3
View File
@@ -1,12 +1,15 @@
# Configure Gitea Actions
## @section Gitea Actions
## @descriptionStart
## For resource limit examples (runner vs DinD), see [docs/resources.md](./docs/resources.md).
## @descriptionEnd
#
## @param enabled Create a Gitea Runner StatefulSet.
## @param statefulset.replicas the amount of (replica) runner pods deployed
## @param statefulset.timezone is the timezone that will be set in the runner image
## @param statefulset.annotations Gitea Runner annotations
## @param statefulset.labels Gitea Runner labels
## @param statefulset.resources Gitea Runner resources
## @param statefulset.resources Shared resource requests/limits for both containers. Overridden by statefulset.runner.resources and statefulset.dind.resources. See docs/resources.md.
## @param statefulset.nodeSelector NodeSelector for the statefulset
## @param statefulset.tolerations Tolerations for the statefulset
## @param statefulset.affinity Affinity for the statefulset
@@ -25,6 +28,7 @@
## @param statefulset.runner.digest Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`
## @param statefulset.runner.pullPolicy The Gitea Runner pullPolicy
## @param statefulset.runner.fullOverride Completely overrides the image registry, path/image, tag and digest.
## @param statefulset.runner.resources Resource requests/limits for the runner container. Takes precedence over statefulset.resources when set.
## @param statefulset.runner.extraVolumeMounts Allows mounting extra volumes in the Gitea Runner container
## @param statefulset.runner.extraEnvs Allows adding custom environment variables
## @param statefulset.runner.flushCache whether to clear the .runner (cache) file by creating an extra init container, can slightly increase boot-up time
@@ -38,6 +42,7 @@
## @param statefulset.dind.digest Image digest. Allows to pin the given image tag. Useful for having control over mutable tags like `latest`
## @param statefulset.dind.fullOverride Completely overrides the image registry, path/image, tag and digest.
## @param statefulset.dind.pullPolicy The Docker-in-Docker pullPolicy
## @param statefulset.dind.resources Resource requests/limits for the DinD sidecar container. Takes precedence over statefulset.resources when set.
## @param statefulset.dind.extraVolumeMounts Allows mounting extra volumes in the Docker-in-Docker container
## @param statefulset.dind.extraEnvs Allows adding custom environment variables, such as `DOCKER_IPTABLES_LEGACY`
## @param statefulset.dind.extraArgs Allows adding custom arguments to the Docker Daemon
@@ -71,10 +76,11 @@ statefulset:
runner:
registry: "docker.gitea.com"
repository: runner
tag: 2.0.1
tag: 3.0.2
digest: ""
pullPolicy: IfNotPresent
fullOverride: ""
resources: {}
extraVolumeMounts: []
extraEnvs:
[]
@@ -100,10 +106,11 @@ statefulset:
uid: ""
registry: "docker.io"
repository: docker
tag: 29.5.2-dind
tag: 29.7.1-dind
digest: ""
pullPolicy: IfNotPresent
fullOverride: ""
resources: {}
extraVolumeMounts: []
# If the container keeps crashing in your environment, you might have to add the `DOCKER_IPTABLES_LEGACY` environment variable.