From eef72a4237d3e8354eba7cdec9a222a1ce2cd4af Mon Sep 17 00:00:00 2001 From: Warren Gifford Date: Wed, 15 Oct 2025 18:31:32 +0000 Subject: [PATCH 1/6] release_patch: v6.9.0 {"version":"v6.9.0","inputs":"server=v6.9.0","type":"patch"} --- charts/sourcegraph-executor/dind/Chart.yaml | 4 +- charts/sourcegraph-executor/dind/README.md | 4 +- charts/sourcegraph-executor/dind/values.yaml | 4 +- charts/sourcegraph-executor/k8s/Chart.yaml | 4 +- charts/sourcegraph-executor/k8s/README.md | 4 +- charts/sourcegraph-executor/k8s/values.yaml | 4 +- charts/sourcegraph-migrator/Chart.yaml | 4 +- charts/sourcegraph-migrator/README.md | 8 +-- charts/sourcegraph-migrator/values.yaml | 4 +- charts/sourcegraph/Chart.yaml | 4 +- charts/sourcegraph/README.md | 52 +++++++++---------- .../sourcegraph/examples/subchart/Chart.yaml | 4 +- charts/sourcegraph/values.yaml | 52 +++++++++---------- 13 files changed, 76 insertions(+), 76 deletions(-) diff --git a/charts/sourcegraph-executor/dind/Chart.yaml b/charts/sourcegraph-executor/dind/Chart.yaml index 537f5b5d..40ff7ca5 100644 --- a/charts/sourcegraph-executor/dind/Chart.yaml +++ b/charts/sourcegraph-executor/dind/Chart.yaml @@ -5,7 +5,7 @@ icon: https://sourcegraph.com/favicon.ico type: application # Chart version, separate from Sourcegraph -version: "5.11.0" +version: "6.9.0" # Version of Sourcegraph release -appVersion: "5.11.0" +appVersion: "6.9.0" diff --git a/charts/sourcegraph-executor/dind/README.md b/charts/sourcegraph-executor/dind/README.md index 71555791..11cc694d 100644 --- a/charts/sourcegraph-executor/dind/README.md +++ b/charts/sourcegraph-executor/dind/README.md @@ -60,7 +60,7 @@ In addition to the documented values, the `executor` and `private-docker-registr | executor.env.EXECUTOR_FRONTEND_URL | object | `{"value":""}` | The external URL of the Sourcegraph instance. Required. | | executor.env.EXECUTOR_QUEUE_NAME | object | `{"value":""}` | The name of the queue to pull jobs from to. Possible values: batches and codeintel. **Either this or EXECUTOR_QUEUE_NAMES is required.** | | executor.env.EXECUTOR_QUEUE_NAMES | object | `{"value":""}` | The comma-separated list of names of multiple queues to pull jobs from to. Possible values: batches and codeintel. **Either this or EXECUTOR_QUEUE_NAME is required.** | -| executor.image.defaultTag | string | `"6.0.0@sha256:0be94a7c91f8273db10fdf46718c6596340ab2acc570e7b85353806e67a27508"` | | +| executor.image.defaultTag | string | `"6.9.0@sha256:e74432300474cbb5de6cd5af2db8029a444491cbbb54bb066b070ac1110ce649"` | | | executor.image.name | string | `"executor"` | | | executor.replicaCount | int | `1` | | | privateDockerRegistry.enabled | bool | `true` | Whether to deploy the private registry. Only one registry is needed when deploying multiple executors. More information: https://docs.sourcegraph.com/admin/executors/deploy_executors#using-private-registries | @@ -71,7 +71,7 @@ In addition to the documented values, the `executor` and `private-docker-registr | sourcegraph.affinity | object | `{}` | Affinity, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add a global label to all resources | diff --git a/charts/sourcegraph-executor/dind/values.yaml b/charts/sourcegraph-executor/dind/values.yaml index bd2c345d..3fad6872 100644 --- a/charts/sourcegraph-executor/dind/values.yaml +++ b/charts/sourcegraph-executor/dind/values.yaml @@ -8,7 +8,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: index.docker.io/sourcegraph + repository: us-docker.pkg.dev/sourcegraph-images/internal # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials @@ -55,7 +55,7 @@ storageClass: executor: enabled: true image: - defaultTag: 6.0.0@sha256:0be94a7c91f8273db10fdf46718c6596340ab2acc570e7b85353806e67a27508 + defaultTag: 6.9.0@sha256:e74432300474cbb5de6cd5af2db8029a444491cbbb54bb066b070ac1110ce649 name: "executor" replicaCount: 1 env: diff --git a/charts/sourcegraph-executor/k8s/Chart.yaml b/charts/sourcegraph-executor/k8s/Chart.yaml index 9dae46f9..1e534b56 100644 --- a/charts/sourcegraph-executor/k8s/Chart.yaml +++ b/charts/sourcegraph-executor/k8s/Chart.yaml @@ -5,7 +5,7 @@ icon: https://sourcegraph.com/favicon.ico type: application # Chart version, separate from Sourcegraph -version: "5.11.0" +version: "6.9.0" # Version of Sourcegraph release -appVersion: "5.11.0" +appVersion: "6.9.0" diff --git a/charts/sourcegraph-executor/k8s/README.md b/charts/sourcegraph-executor/k8s/README.md index 4258c745..223c1d28 100644 --- a/charts/sourcegraph-executor/k8s/README.md +++ b/charts/sourcegraph-executor/k8s/README.md @@ -61,7 +61,7 @@ In addition to the documented values, the `executor` and `private-docker-registr | executor.frontendExistingSecret | string | `""` | Name of existing k8s Secret to use for frontend password The name of the secret must match `executor.name`, i.e., the name of the helm release used to deploy the helm chart. The k8s Secret must contain the key `EXECUTOR_FRONTEND_PASSWORD` matching the site config `executors.accessToken` value. `executor.frontendPassword` is ignored if this is enabled. | | executor.frontendPassword | string | `""` | The shared secret configured in the Sourcegraph instance site config under executors.accessToken. Required if `executor.frontendExistingSecret`` is not configured. | | executor.frontendUrl | string | `""` | The external URL of the Sourcegraph instance. Required. **Recommended:** set to the internal service endpoint (e.g. `http://sourcegraph-frontend.sourcegraph.svc.cluster.local:30080` if Sourcegraph is deployed in the `sourcegraph` namespace). This will avoid unnecessary network charges as traffic will stay within the local network. | -| executor.image.defaultTag | string | `"6.0.0@sha256:6dc771a0c281a41ef676213f2f84a63d99045cf2e58d43022554a8022070ed65"` | | +| executor.image.defaultTag | string | `"6.9.0@sha256:bb8b3f759052ed02318b1cffd4731ff431f74fbc3f4c9dc13316928283daa1e8"` | | | executor.image.name | string | `"executor-kubernetes"` | | | executor.kubeconfigPath | string | `""` | The path to the kubeconfig file. If not specified, the in-cluster config is used. | | executor.kubernetesJob.deadline | string | `"1200"` | The number of seconds after which a Kubernetes job will be terminated. | @@ -99,7 +99,7 @@ In addition to the documented values, the `executor` and `private-docker-registr | sourcegraph.affinity | object | `{}` | Affinity, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add a global label to all resources | diff --git a/charts/sourcegraph-executor/k8s/values.yaml b/charts/sourcegraph-executor/k8s/values.yaml index 11af2cb4..61883ee9 100644 --- a/charts/sourcegraph-executor/k8s/values.yaml +++ b/charts/sourcegraph-executor/k8s/values.yaml @@ -8,7 +8,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: index.docker.io/sourcegraph + repository: us-docker.pkg.dev/sourcegraph-images/internal # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials @@ -59,7 +59,7 @@ executor: configureRbac: true replicas: 1 image: - defaultTag: 6.0.0@sha256:6dc771a0c281a41ef676213f2f84a63d99045cf2e58d43022554a8022070ed65 + defaultTag: 6.9.0@sha256:bb8b3f759052ed02318b1cffd4731ff431f74fbc3f4c9dc13316928283daa1e8 name: "executor-kubernetes" resources: limits: diff --git a/charts/sourcegraph-migrator/Chart.yaml b/charts/sourcegraph-migrator/Chart.yaml index 9ad6613d..2a6c3e6c 100644 --- a/charts/sourcegraph-migrator/Chart.yaml +++ b/charts/sourcegraph-migrator/Chart.yaml @@ -5,7 +5,7 @@ icon: https://sourcegraph.com/favicon.ico type: application # Chart version, separate from Sourcegraph -version: "5.11.0" +version: "6.9.0" # Version of Sourcegraph release -appVersion: "5.11.0" +appVersion: "6.9.0" diff --git a/charts/sourcegraph-migrator/README.md b/charts/sourcegraph-migrator/README.md index cad56823..e8139340 100644 --- a/charts/sourcegraph-migrator/README.md +++ b/charts/sourcegraph-migrator/README.md @@ -42,7 +42,7 @@ You should consult the list of available [migrator commands]. Below is some exam - Perform initial migrations against external PostgreSQL databases prior to the Sourcegraph deployment ```sh -helm upgrade --install -f --version 5.11.0 sg-migrator sourcegraph/sourcegraph-migrator +helm upgrade --install -f --version 6.9.0 sg-migrator sourcegraph/sourcegraph-migrator ``` ### Add a migration log entry @@ -52,7 +52,7 @@ helm upgrade --install -f --version 5.11.0 sg-migrator Add an entry to the migration log after a site administrator has explicitly applied the contents of a migration file, learn more about troubleshooting a [dirty database]. ```sh -helm upgrade --install -f --set "migrator.args={add-log,-db=frontend,-version=1528395834}" --version 5.11.0 sg-migrator sourcegraph/sourcegraph-migrator +helm upgrade --install -f --set "migrator.args={add-log,-db=frontend,-version=1528395834}" --version 6.9.0 sg-migrator sourcegraph/sourcegraph-migrator ``` ## Rendering manifests for kubectl deployment @@ -80,7 +80,7 @@ In addition to the documented values, the `migrator` service also supports the f | migrator.args | list | `["up","-db=all"]` | Override default `migrator` container args Available commands can be found at https://docs.sourcegraph.com/admin/how-to/manual_database_migrations | | migrator.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `migrator` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | migrator.env | object | `{}` | Environment variables for the `migrator` container | -| migrator.image.defaultTag | string | `"6.0.0@sha256:ec295eb0b743da6bf56777ca6524972267a5c442b0288095e2fe12fce38ebacc"` | Docker image tag for the `migrator` image | +| migrator.image.defaultTag | string | `"6.9.0@sha256:b1fc02b83e36fc213307043568d6ceb6fa1eb52e2041001d60e8ba70ba0c0353"` | Docker image tag for the `migrator` image | | migrator.image.name | string | `"migrator"` | Docker image name for the `migrator` image | | migrator.resources | object | `{"limits":{"cpu":"500m","memory":"100M"},"requests":{"cpu":"100m","memory":"50M"}}` | Resource requests & limits for the `migrator` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | pgsql.auth.existingSecret | string | `""` | Name of existing secret to use for pgsql credentials This should match the setting in the sourcegraph chart values | @@ -88,7 +88,7 @@ In addition to the documented values, the `migrator` service also supports the f | sourcegraph.affinity | object | `{}` | Affinity, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add a global label to all resources | diff --git a/charts/sourcegraph-migrator/values.yaml b/charts/sourcegraph-migrator/values.yaml index 20f30df7..a5454274 100644 --- a/charts/sourcegraph-migrator/values.yaml +++ b/charts/sourcegraph-migrator/values.yaml @@ -8,7 +8,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: index.docker.io/sourcegraph + repository: us-docker.pkg.dev/sourcegraph-images/internal # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials @@ -102,7 +102,7 @@ pgsql: migrator: image: # -- Docker image tag for the `migrator` image - defaultTag: 6.0.0@sha256:ec295eb0b743da6bf56777ca6524972267a5c442b0288095e2fe12fce38ebacc + defaultTag: 6.9.0@sha256:b1fc02b83e36fc213307043568d6ceb6fa1eb52e2041001d60e8ba70ba0c0353 # -- Docker image name for the `migrator` image name: "migrator" # -- Environment variables for the `migrator` container diff --git a/charts/sourcegraph/Chart.yaml b/charts/sourcegraph/Chart.yaml index 898e9e67..52e9528f 100644 --- a/charts/sourcegraph/Chart.yaml +++ b/charts/sourcegraph/Chart.yaml @@ -5,7 +5,7 @@ icon: https://sourcegraph.com/favicon.ico type: application # Chart version, separate from Sourcegraph -version: "5.11.0" +version: "6.9.0" # Version of Sourcegraph release -appVersion: "5.11.0" +appVersion: "6.9.0" diff --git a/charts/sourcegraph/README.md b/charts/sourcegraph/README.md index 5e917aa7..fba7fd22 100644 --- a/charts/sourcegraph/README.md +++ b/charts/sourcegraph/README.md @@ -28,12 +28,12 @@ In addition to the documented values, all services also support the following va | Key | Type | Default | Description | |-----|------|---------|-------------| | alpine.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":999,"runAsUser":999}` | Security context for the `alpine` initContainer, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| alpine.image.defaultTag | string | `"6.0.0@sha256:c4705ccf969e262ee3916719ecc7c0fb5e606dd954278ac07ac1d052e4e490df"` | Docker image tag for the `alpine` image | +| alpine.image.defaultTag | string | `"6.9.0@sha256:47ddeb68cfdb767949b4e7f6e2306fa20a1ee5a2619efbe56bf06cb5a62e7729"` | Docker image tag for the `alpine` image | | alpine.image.name | string | `"alpine-3.14"` | Docker image name for the `alpine` image | | alpine.resources | object | `{"limits":{"cpu":"10m","memory":"50Mi"},"requests":{"cpu":"10m","memory":"50Mi"}}` | Resource requests & limits for the `alpine` initContainer, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | blobstore.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"runAsGroup":101,"runAsUser":100}` | Security context for the `blobstore` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | blobstore.enabled | bool | `true` | Enable `blobstore` (S3 compatible storage) | -| blobstore.image.defaultTag | string | `"6.0.0@sha256:82caab40f920282069c84e0e4ca503857926e934c67fb022f6d93823b4ea98b5"` | Docker image tag for the `blobstore` image | +| blobstore.image.defaultTag | string | `"6.9.0@sha256:1a989ff6a1ce41ca7b5e438a97f950fe178379d429bd6b9a399fd698687b1a21"` | Docker image tag for the `blobstore` image | | blobstore.image.name | string | `"blobstore"` | Docker image name for the `blobstore` image | | blobstore.name | string | `"blobstore"` | Name used by resources. Does not affect service names or PVCs. | | blobstore.podSecurityContext | object | `{"fsGroup":101,"fsGroupChangePolicy":"OnRootMismatch","runAsGroup":101,"runAsUser":100}` | Security context for the `blobstore` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -43,7 +43,7 @@ In addition to the documented values, all services also support the following va | blobstore.storageSize | string | `"100Gi"` | PVC Storage Request for `blobstore` data volume | | cadvisor.containerSecurityContext | object | `{"privileged":true}` | Security context for the `cadvisor` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | cadvisor.enabled | bool | `true` | Enable `cadvisor` | -| cadvisor.image.defaultTag | string | `"6.0.0@sha256:48082a2822a727e22c556ae2c3bae5f5bf4528c7b462efc3c085271ee5145be8"` | Docker image tag for the `cadvisor` image | +| cadvisor.image.defaultTag | string | `"6.9.0@sha256:e7d919b8670d2db6fc49f5d33e7d30589e7bef0cfb3d0b41c83253a65c1d981b"` | Docker image tag for the `cadvisor` image | | cadvisor.image.name | string | `"cadvisor"` | Docker image name for the `cadvisor` image | | cadvisor.name | string | `"cadvisor"` | Name used by resources. Does not affect service names or PVCs. | | cadvisor.podSecurityPolicy.enabled | bool | `false` | Enable [PodSecurityPolicy](https://kubernetes.io/docs/concepts/policy/pod-security-policy/) for `cadvisor` pods | @@ -62,7 +62,7 @@ In addition to the documented values, all services also support the following va | codeInsightsDB.enabled | bool | `true` | Enable `codeinsights-db` PostgreSQL server | | codeInsightsDB.env | object | `{}` | Environment variables for the `codeinsights-db` container | | codeInsightsDB.existingConfig | string | `""` | Name of existing ConfigMap for `codeinsights-db`. It must contain a `postgresql.conf` key. | -| codeInsightsDB.image.defaultTag | string | `"6.0.0@sha256:24263ff136f8cc328d63808982beb4a109461da30b522b63d2867a4e708713c9"` | Docker image tag for the `codeinsights-db` image | +| codeInsightsDB.image.defaultTag | string | `"6.9.0@sha256:c1e207ca75c8ad2eb3dffc68c73448b7b43b373e051a95b65c8a80f5a34ff3fc"` | Docker image tag for the `codeinsights-db` image | | codeInsightsDB.image.name | string | `"postgresql-16-codeinsights"` | Docker image name for the `codeinsights-db` image | | codeInsightsDB.init.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":70,"runAsUser":70}` | Security context for the `alpine` initContainer, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | codeInsightsDB.name | string | `"codeinsights-db"` | Name used by resources. Does not affect service names or PVCs. | @@ -83,7 +83,7 @@ In addition to the documented values, all services also support the following va | codeIntelDB.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":999,"runAsUser":999}` | Security context for the `codeintel-db` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | codeIntelDB.enabled | bool | `true` | Enable `codeintel-db` PostgreSQL server | | codeIntelDB.existingConfig | string | `""` | Name of existing ConfigMap for `codeintel-db`. It must contain a `postgresql.conf` key | -| codeIntelDB.image.defaultTag | string | `"6.0.0@sha256:224a2604331cb73809f466394c5b4f3ca95bf6a5a140cb75820dfe67301074bb"` | Docker image tag for the `codeintel-db` image | +| codeIntelDB.image.defaultTag | string | `"6.9.0@sha256:5bf4140044f524232fb025be3405e4e4c438f7fb125a8195cf46b7d44ebec920"` | Docker image tag for the `codeintel-db` image | | codeIntelDB.image.name | string | `"postgresql-16"` | Docker image name for the `codeintel-db` image | | codeIntelDB.name | string | `"codeintel-db"` | Name used by resources. Does not affect service names or PVCs. | | codeIntelDB.podSecurityContext | object | `{"fsGroup":999,"fsGroupChangePolicy":"OnRootMismatch","runAsUser":999}` | Security context for the `codeintel-db` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -96,7 +96,7 @@ In addition to the documented values, all services also support the following va | frontend.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `frontend` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | frontend.createRoleBinding | bool | `true` | Disable the roleBinding resource for deployment environments blocking RBAC, ex. OpenShift's default "secure" SCC | | frontend.env | object | the chart will add some default environment values | Environment variables for the `frontend` container | -| frontend.image.defaultTag | string | `"6.0.0@sha256:d4f21178096da5fdb3804099ae9de2e050b06e859a327aa79452b1ea2f3ede0a"` | Docker image tag for the `frontend` image | +| frontend.image.defaultTag | string | `"6.9.0@sha256:963e13089f94770ae9d96f761ec7c48015641a535f89606918d443df036e8d03"` | Docker image tag for the `frontend` image | | frontend.image.name | string | `"frontend"` | Docker image name for the `frontend` image | | frontend.ingress.annotations | object | `{"kubernetes.io/ingress.class":"nginx","nginx.ingress.kubernetes.io/proxy-body-size":"150m"}` | Annotations for the Sourcegraph server ingress. For example, securing ingress with TLS provided by [cert-manager](https://cert-manager.io/docs/usage/ingress/) | | frontend.ingress.annotations."kubernetes.io/ingress.class" | string | `"nginx"` | [Deprecated annotation](https://kubernetes.io/docs/concepts/services-networking/ingress/#deprecated-annotation) for specifing the IngressClass in Kubernetes 1.17 and earlier. If you are using Kubernetes 1.18+, use `ingressClassName` instead and set an override value of `null` for this annotation. | @@ -112,7 +112,7 @@ In addition to the documented values, all services also support the following va | frontend.serviceAccount.create | bool | `true` | Enable creation of ServiceAccount for `frontend` | | frontend.serviceAccount.name | string | `"sourcegraph-frontend"` | Name of the ServiceAccount to be created or an existing ServiceAccount | | gitserver.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `gitserver` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| gitserver.image.defaultTag | string | `"6.0.0@sha256:aec9bf6993c243a283109104cd7c44be3c85680b77e3e8be0c5fba8f01a3bd35"` | Docker image tag for the `gitserver` image | +| gitserver.image.defaultTag | string | `"6.9.0@sha256:51fb917535ab4a4fdc1770ae70c2b6751e454ff4c53fc8ed3aefbb1917560083"` | Docker image tag for the `gitserver` image | | gitserver.image.name | string | `"gitserver"` | Docker image name for the `gitserver` image | | gitserver.name | string | `"gitserver"` | Name used by resources. Does not affect service names or PVCs. | | gitserver.podSecurityContext | object | `{"fsGroup":101,"fsGroupChangePolicy":"OnRootMismatch","runAsGroup":101,"runAsUser":100}` | Security context for the `gitserver` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -133,7 +133,7 @@ In addition to the documented values, all services also support the following va | grafana.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":472,"runAsUser":472}` | Security context for the `grafana` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | grafana.enabled | bool | `true` | Enable `grafana` dashboard (recommended) | | grafana.existingConfig | string | `""` | Name of existing ConfigMap for `grafana`. It must contain a `datasources.yml` key. | -| grafana.image.defaultTag | string | `"6.0.0@sha256:e40236d0143d0735ff87374afce95b878b8cde448ef65cfdc7008056a03097e8"` | Docker image tag for the `grafana` image | +| grafana.image.defaultTag | string | `"6.9.0@sha256:52e1a6b845ccb1584f56bcbc6c517eedbec0d955aad64ee9a8ce3c5859a07b4b"` | Docker image tag for the `grafana` image | | grafana.image.name | string | `"grafana"` | Docker image name for the `grafana` image | | grafana.name | string | `"grafana"` | Name used by resources. Does not affect service names or PVCs. | | grafana.podSecurityContext | object | `{"fsGroup":472,"fsGroupChangePolicy":"OnRootMismatch","runAsGroup":472,"runAsUser":472}` | Security context for the `grafana` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -142,7 +142,7 @@ In addition to the documented values, all services also support the following va | grafana.serviceAccount.name | string | `"grafana"` | Name of the ServiceAccount to be created or an existing ServiceAccount | | grafana.storageSize | string | `"2Gi"` | PVC Storage Request for `grafana` data volume | | indexedSearch.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `zoekt-webserver` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| indexedSearch.image.defaultTag | string | `"6.0.0@sha256:99038e0ec9bef930030c118d774fcdcd67d7fe57ad4c80d216703a4d29d64323"` | Docker image tag for the `zoekt-webserver` image | +| indexedSearch.image.defaultTag | string | `"6.9.0@sha256:ce9ba39d31bc36e2473e92c55339df45cd2ec80ea713fc73c340c5cc2af0e935"` | Docker image tag for the `zoekt-webserver` image | | indexedSearch.image.name | string | `"indexed-searcher"` | Docker image name for the `zoekt-webserver` image | | indexedSearch.name | string | `"indexed-search"` | Name used by resources. Does not affect service names or PVCs. | | indexedSearch.podSecurityContext | object | `{"fsGroup":101,"fsGroupChangePolicy":"OnRootMismatch"}` | Security context for the `indexed-search` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -152,7 +152,7 @@ In addition to the documented values, all services also support the following va | indexedSearch.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | indexedSearch.storageSize | string | `"200Gi"` | PVC Storage Request for `indexed-search` data volume The size of disk to used for search indexes. This should typically be gitserver disk size multipled by the number of gitserver shards. | | indexedSearchIndexer.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `zoekt-indexserver` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| indexedSearchIndexer.image.defaultTag | string | `"6.0.0@sha256:11539e07040b85045a9aa07f970aa310066e240dc28e6c9627653ee2bc6e0b91"` | Docker image tag for the `zoekt-indexserver` image | +| indexedSearchIndexer.image.defaultTag | string | `"6.9.0@sha256:4fe5b168a89504f1e889389dd9e99b1be7d25b1f0284e77ce11c7da80748a8b2"` | Docker image tag for the `zoekt-indexserver` image | | indexedSearchIndexer.image.name | string | `"search-indexer"` | Docker image name for the `zoekt-indexserver` image | | indexedSearchIndexer.resources | object | `{"limits":{"cpu":"8","memory":"8G"},"requests":{"cpu":"4","memory":"4G"}}` | Resource requests & limits for the `zoekt-indexserver` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) zoekt-indexserver is CPU bound. The more CPU you allocate to it, the lower lag between a new commit and it being indexed for search. | | jaeger.args | list | `["--memory.max-traces=20000","--sampling.strategies-file=/etc/jaeger/sampling_strategies.json","--collector.otlp.enabled","--collector.otlp.grpc.host-port=:4320","--collector.otlp.http.host-port=:4321"]` | Default args passed to the `jaeger` binary | @@ -162,7 +162,7 @@ In addition to the documented values, all services also support the following va | jaeger.collector.serviceType | string | "ClusterIP" | Kubernetes service type of jaeger `collector` service, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types) | | jaeger.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `jaeger` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | jaeger.enabled | bool | `false` | Enable `jaeger` | -| jaeger.image.defaultTag | string | `"6.0.0@sha256:79548aa11d7e2e6bf3e2012fb9e046df12ba5c5410bc24ec8f4d7cbb880336b9"` | Docker image tag for the `jaeger` image | +| jaeger.image.defaultTag | string | `"6.9.0@sha256:96ddedeecc32e35d5b2e1d05ed04c716c24d9ac3f72fbaa2bccc8618a9c933a3"` | Docker image tag for the `jaeger` image | | jaeger.image.name | string | `"jaeger-all-in-one"` | Docker image name for the `jaeger` image | | jaeger.name | string | `"jaeger"` | Name used by resources. Does not affect service names or PVCs. | | jaeger.podSecurityContext | object | `{}` | Security context for the `jaeger` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -177,14 +177,14 @@ In addition to the documented values, all services also support the following va | migrator.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `migrator` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | migrator.enabled | bool | `true` | Enable [migrator](https://docs.sourcegraph.com/admin/how-to/manual_database_migrations) initContainer in `frontend` deployment to perform database migration | | migrator.env | object | `{}` | Environment variables for the `migrator` container | -| migrator.image.defaultTag | string | `"6.0.0@sha256:ec295eb0b743da6bf56777ca6524972267a5c442b0288095e2fe12fce38ebacc"` | Docker image tag for the `migrator` image | +| migrator.image.defaultTag | string | `"6.9.0@sha256:b1fc02b83e36fc213307043568d6ceb6fa1eb52e2041001d60e8ba70ba0c0353"` | Docker image tag for the `migrator` image | | migrator.image.name | string | `"migrator"` | Docker image name for the `migrator` image | | migrator.resources | object | `{"limits":{"cpu":"500m","memory":"100M"},"requests":{"cpu":"100m","memory":"50M"}}` | Resource requests & limits for the `migrator` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | nodeExporter.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":65534,"runAsUser":65534}` | Security context for the `node-exporter` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | nodeExporter.enabled | bool | `true` | Enable `node-exporter` | | nodeExporter.extraArgs | list | `[]` | | | nodeExporter.hostPID | bool | `true` | | -| nodeExporter.image.defaultTag | string | `"6.0.0@sha256:099c2e4fb8eacdda82d2d4798591808ded7ad3dc5e6ed514535e0b8e7223ed06"` | Docker image tag for the `node-exporter` image | +| nodeExporter.image.defaultTag | string | `"6.9.0@sha256:7be0055e06ec4167899d69b0df27fc2e51ecce5a7607c81a48b3ebb2c69b1e27"` | Docker image tag for the `node-exporter` image | | nodeExporter.image.name | string | `"node-exporter"` | Docker image name for the `node-exporter` image | | nodeExporter.name | string | `"node-exporter"` | Name used by resources. Does not affect service names or PVCs. | | nodeExporter.podSecurityContext | object | `{"fsGroup":65534,"runAsGroup":65534,"runAsNonRoot":true,"runAsUser":65534}` | Security context for the `node-exporter` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -214,7 +214,7 @@ In addition to the documented values, all services also support the following va | openTelemetry.gateway.resources | object | `{"limits":{"cpu":"3","memory":"3Gi"},"requests":{"cpu":"1","memory":"1Gi"}}` | Resource requests & limits for the `otel-collector` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | openTelemetry.gateway.serviceAccount.create | bool | `false` | Enable creation of ServiceAccount for `otel-collector` | | openTelemetry.gateway.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | -| openTelemetry.image.defaultTag | string | `"6.0.0@sha256:ef3e61a4f0a624523ecdee57d8b7757436c2389e0cf12401b4764d19c826ff8a"` | Docker image tag for the `otel-collector` image | +| openTelemetry.image.defaultTag | string | `"6.9.0@sha256:fd2c847df65da33d622ac09754e09dd3603017cdcd9c43df180c0a499f27230d"` | Docker image tag for the `otel-collector` image | | openTelemetry.image.name | string | `"opentelemetry-collector"` | Docker image name for the `otel-collector` image | | pgsql.additionalConfig | string | `""` | Additional PostgreSQL configuration. This will override or extend our default configuration. Notes: This is expecting a multiline string. Learn more from our [recommended PostgreSQL configuration](https://docs.sourcegraph.com/admin/config/postgres-conf) and [PostgreSQL documentation](https://www.postgresql.org/docs/12/config-setting.html) | | pgsql.auth.database | string | `"sg"` | Sets postgres database name | @@ -227,7 +227,7 @@ In addition to the documented values, all services also support the following va | pgsql.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":999,"runAsUser":999}` | Security context for the `pgsql` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | pgsql.enabled | bool | `true` | Enable `pgsql` PostgreSQL server | | pgsql.existingConfig | string | `""` | Name of existing ConfigMap for `pgsql`. It must contain a `postgresql.conf` key | -| pgsql.image.defaultTag | string | `"6.0.0@sha256:224a2604331cb73809f466394c5b4f3ca95bf6a5a140cb75820dfe67301074bb"` | Docker image tag for the `pgsql` image | +| pgsql.image.defaultTag | string | `"6.9.0@sha256:5bf4140044f524232fb025be3405e4e4c438f7fb125a8195cf46b7d44ebec920"` | Docker image tag for the `pgsql` image | | pgsql.image.name | string | `"postgresql-16"` | Docker image name for the `pgsql` image | | pgsql.name | string | `"pgsql"` | Name used by resources. Does not affect service names or PVCs. | | pgsql.podSecurityContext | object | `{"fsGroup":999,"fsGroupChangePolicy":"OnRootMismatch","runAsGroup":999,"runAsUser":999}` | Security context for the `pgsql` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -236,12 +236,12 @@ In addition to the documented values, all services also support the following va | pgsql.serviceAccount.create | bool | `false` | Enable creation of ServiceAccount for `pgsql` | | pgsql.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | pgsql.storageSize | string | `"200Gi"` | PVC Storage Request for `pgsql` data volume | -| postgresExporter.image.defaultTag | string | `"6.0.0@sha256:685a18f482e4a71a54e15814ffd6b8cd62844f6af056a81f7ec0ba5cf23fce27"` | Docker image tag for the `pgsql-exporter` image | +| postgresExporter.image.defaultTag | string | `"6.9.0@sha256:31a6a30dc78e4fcf990762d9ed819e8a67722b75bca6f943e922889b9a78e580"` | Docker image tag for the `pgsql-exporter` image | | postgresExporter.image.name | string | `"postgres_exporter"` | Docker image name for the `pgsql-exporter` image | | postgresExporter.resources | object | `{"limits":{"cpu":"10m","memory":"50Mi"},"requests":{"cpu":"10m","memory":"50Mi"}}` | Resource requests & limits for the `pgsql-exporter` sidecar container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | preciseCodeIntel.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `precise-code-intel-worker` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | preciseCodeIntel.env | object | `{"NUM_WORKERS":{"value":"4"}}` | Environment variables for the `precise-code-intel-worker` container | -| preciseCodeIntel.image.defaultTag | string | `"6.0.0@sha256:3a72cf893cb25731d4636593c544c91781d925d867417416255e56debc27ed37"` | Docker image tag for the `precise-code-intel-worker` image | +| preciseCodeIntel.image.defaultTag | string | `"6.9.0@sha256:8cdb8689c8c7100f6fc1b7ed7c8fbd2f055aee85ccf8a35eee46bd3545f1472c"` | Docker image tag for the `precise-code-intel-worker` image | | preciseCodeIntel.image.name | string | `"precise-code-intel-worker"` | Docker image name for the `precise-code-intel-worker` image | | preciseCodeIntel.name | string | `"precise-code-intel-worker"` | Name used by resources. Does not affect service names or PVCs. | | preciseCodeIntel.podSecurityContext | object | `{}` | Security context for the `precise-code-intel-worker` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -254,7 +254,7 @@ In addition to the documented values, all services also support the following va | prometheus.createRoleBinding | bool | `true` | Disable the creation of a RoleBinding object, for customers who block all RBAC resource creation | | prometheus.enabled | bool | `true` | Enable `prometheus` (recommended) | | prometheus.existingConfig | string | `""` | Name of existing ConfigMap for `pgsql`. It must contain a `prometheus.yml` key | -| prometheus.image.defaultTag | string | `"6.0.0@sha256:86a315720fd9813d9ef9746d92e637bc20cd9ebd90da78d8cc6906062252891f"` | Docker image tag for the `prometheus` image | +| prometheus.image.defaultTag | string | `"6.9.0@sha256:f9b456110b2755214ec6767196f4971742f22c4f9fbe25326328f11041a4fc5d"` | Docker image tag for the `prometheus` image | | prometheus.image.name | string | `"prometheus"` | Docker image name for the `prometheus` image | | prometheus.name | string | `"prometheus"` | Name used by resources. Does not affect service names or PVCs. | | prometheus.podSecurityContext | object | `{"fsGroup":100,"fsGroupChangePolicy":"OnRootMismatch"}` | Security context for the `prometheus` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -267,7 +267,7 @@ In addition to the documented values, all services also support the following va | redisCache.connection.existingSecret | string | `""` | Name of existing secret to use for Redis endpoint The secret must contain the key `endpoint` and should follow IANA specification learn more from the [Helm docs](https://docs.sourcegraph.com/admin/install/kubernetes/helm#using-external-redis-instances) | | redisCache.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":999}` | Security context for the `redis-cache` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | redisCache.enabled | bool | `true` | Enable `redis-cache` Redis server | -| redisCache.image.defaultTag | string | `"6.0.0@sha256:40ea19e8944b93e05d7697c808969fe0c81a014a56245f3a97b645aa34a9ab78"` | Docker image tag for the `redis-cache` image | +| redisCache.image.defaultTag | string | `"6.9.0@sha256:440ed87b7dd2ecb19e0a94edfdd345b47265b302916499189af4fff7d38e57de"` | Docker image tag for the `redis-cache` image | | redisCache.image.name | string | `"redis-cache"` | Docker image name for the `redis-cache` image | | redisCache.name | string | `"redis-cache"` | Name used by resources. Does not affect service names or PVCs. | | redisCache.podSecurityContext | object | `{"fsGroup":1000,"fsGroupChangePolicy":"OnRootMismatch"}` | Security context for the `redis-cache` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -276,14 +276,14 @@ In addition to the documented values, all services also support the following va | redisCache.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | redisCache.storageSize | string | `"100Gi"` | PVC Storage Request for `redis-cache` data volume | | redisExporter.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":999}` | Security context for the `redis-exporter` sidecar container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| redisExporter.image.defaultTag | string | `"6.0.0@sha256:b2ec48fc6adef31f36d525170138dec303c1c0c20c530d659f1fb7c6c54698af"` | Docker image tag for the `redis-exporter` image | +| redisExporter.image.defaultTag | string | `"6.9.0@sha256:81d0be46fa9bf4f9d1cb8d02db33addebaec987981e9093680fd85492445672c"` | Docker image tag for the `redis-exporter` image | | redisExporter.image.name | string | `"redis_exporter"` | Docker image name for the `redis-exporter` image | | redisExporter.resources | object | `{"limits":{"cpu":"10m","memory":"100Mi"},"requests":{"cpu":"10m","memory":"100Mi"}}` | Resource requests & limits for the `redis-exporter` sidecar container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | redisStore.connection.endpoint | string | `"redis-store:6379"` | Endpoint to use for redis-store. Supports either host:port or IANA specification | | redisStore.connection.existingSecret | string | `""` | Name of existing secret to use for Redis endpoint The secret must contain the key `endpoint` and should follow IANA specification learn more from the [Helm docs](https://docs.sourcegraph.com/admin/install/kubernetes/helm#using-external-redis-instances) | | redisStore.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":999}` | Security context for the `redis-store` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | redisStore.enabled | bool | `true` | Enable `redis-store` Redis server | -| redisStore.image.defaultTag | string | `"6.0.0@sha256:39f3b27d993652c202c1f892df83e1a3e8e8ea5ae58291f79ad14b56672ab8be"` | Docker image tag for the `redis-store` image | +| redisStore.image.defaultTag | string | `"6.9.0@sha256:535438c49584762906039c63b22871e9c0f40dedbef060283a94db588cfd65cd"` | Docker image tag for the `redis-store` image | | redisStore.image.name | string | `"redis-store"` | Docker image name for the `redis-store` image | | redisStore.name | string | `"redis-store"` | Name used by resources. Does not affect service names or PVCs. | | redisStore.podSecurityContext | object | `{"fsGroup":1000,"fsGroupChangePolicy":"OnRootMismatch"}` | Security context for the `redis-store` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -292,7 +292,7 @@ In addition to the documented values, all services also support the following va | redisStore.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | redisStore.storageSize | string | `"100Gi"` | PVC Storage Request for `redis-store` data volume | | searcher.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `searcher` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| searcher.image.defaultTag | string | `"6.0.0@sha256:c7508abda2202d4a33400ce23a95dd8d59fe6220d85d7fbee6fb186c55931336"` | Docker image tag for the `searcher` image | +| searcher.image.defaultTag | string | `"6.9.0@sha256:2b4686138a72143c7c9c69f844d82fac6401f4cf61b0f42847f59a789e5faa58"` | Docker image tag for the `searcher` image | | searcher.image.name | string | `"searcher"` | Docker image name for the `searcher` image | | searcher.name | string | `"searcher"` | Name used by resources. Does not affect service names or PVCs. | | searcher.podSecurityContext | object | `{"fsGroup":101,"fsGroupChangePolicy":"OnRootMismatch","runAsUser":100}` | Security context for the `searcher` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -306,7 +306,7 @@ In addition to the documented values, all services also support the following va | sourcegraph.disableKubernetesSecrets | bool | `false` | Disable the creation of Kubernetes secrets objects | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add extra labels to all resources | @@ -326,7 +326,7 @@ In addition to the documented values, all services also support the following va | storageClass.type | string | `"pd-ssd"` | Value of `type` key in storageClass `parameters`, consult your cloud provider persistent storage documentation | | syntacticCodeIntel.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `syntactic-code-intel-worker` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | syntacticCodeIntel.enabled | bool | `false` | | -| syntacticCodeIntel.image.defaultTag | string | `"6.0.0@sha256:50bdeb38b196f0fc21404969016bf8263f78144292e905867e93480f66c8251c"` | Docker image tag for the `syntactic-code-intel-worker` image | +| syntacticCodeIntel.image.defaultTag | string | `"6.9.0@sha256:7e18db4367e4317bad7dcb2fac5aac58f3ce5cf6d8bfdf1d4337a54b13e32667"` | Docker image tag for the `syntactic-code-intel-worker` image | | syntacticCodeIntel.image.name | string | `"syntactic-code-intel-worker"` | Docker image name for the `syntactic-code-intel-worker` image | | syntacticCodeIntel.name | string | `"syntactic-code-intel-worker"` | Name used by resources. Does not affect service names or PVCs. | | syntacticCodeIntel.podSecurityContext | object | `{}` | Security context for the `syntactic-code-intel-worker` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -336,7 +336,7 @@ In addition to the documented values, all services also support the following va | syntacticCodeIntel.serviceAccount.create | bool | `false` | Enable creation of ServiceAccount for `syntactic-code-intel-worker` | | syntacticCodeIntel.serviceAccount.name | string | `""` | Name of the ServiceAccount to be created or an existing ServiceAccount | | syntectServer.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `syntect-server` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | -| syntectServer.image.defaultTag | string | `"6.0.0@sha256:1e35f77690222a76724b45f2305b838c40c35201e60b0f619b3fe8499504ff60"` | Docker image tag for the `syntect-server` image | +| syntectServer.image.defaultTag | string | `"6.9.0@sha256:b14ed68537dacd5ee4e61ca2374835213324df186961cf095ed0393377ad3bb6"` | Docker image tag for the `syntect-server` image | | syntectServer.image.name | string | `"syntax-highlighter"` | Docker image name for the `syntect-server` image | | syntectServer.name | string | `"syntect-server"` | Name used by resources. Does not affect service names or PVCs. | | syntectServer.podSecurityContext | object | `{}` | Security context for the `syntect-server` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | @@ -347,7 +347,7 @@ In addition to the documented values, all services also support the following va | worker.blocklist | list | `[]` | List of jobs to block globally If replicas are configured, use this values to block jobs instead of manually setting WORKER_JOB_BLOCKLIST | | worker.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":101,"runAsUser":100}` | Security context for the `worker` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) | | worker.env | object | `{}` | Environment variables for the `worker` container | -| worker.image.defaultTag | string | `"6.0.0@sha256:4892c5aa107d4384f811afcf1980e0fb2cb8beb5585a15adcb64353a2d8abf5a"` | Docker image tag for the `worker` image | +| worker.image.defaultTag | string | `"6.9.0@sha256:bc905262022303262f4c6836b377502b88aa02f15280037ae0d44d96ea55409a"` | Docker image tag for the `worker` image | | worker.image.name | string | `"worker"` | Docker image name for the `worker` image | | worker.name | string | `"worker"` | Name used by resources. Does not affect service names or PVCs. | | worker.podSecurityContext | object | `{}` | Security context for the `worker` pod, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod) | diff --git a/charts/sourcegraph/examples/subchart/Chart.yaml b/charts/sourcegraph/examples/subchart/Chart.yaml index 437f9b00..7994fd1d 100644 --- a/charts/sourcegraph/examples/subchart/Chart.yaml +++ b/charts/sourcegraph/examples/subchart/Chart.yaml @@ -2,10 +2,10 @@ apiVersion: v2 name: sourcegraph-subchart description: Customer-owned chart that inherits from Sourcegraph type: application -version: "5.11.0" +version: "6.9.0" dependencies: - name: sourcegraph alias: sg # Optional, allows a custom name to be used - version: "5.11.0" + version: "6.9.0" repository: "https://sourcegraph.github.io/deploy-sourcegraph-helm" diff --git a/charts/sourcegraph/values.yaml b/charts/sourcegraph/values.yaml index 84bfb841..15485557 100644 --- a/charts/sourcegraph/values.yaml +++ b/charts/sourcegraph/values.yaml @@ -9,7 +9,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: index.docker.io/sourcegraph + repository: us-docker.pkg.dev/sourcegraph-images/internal # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials @@ -88,7 +88,7 @@ sourcegraph: alpine: # Used in init containers image: # -- Docker image tag for the `alpine` image - defaultTag: 6.0.0@sha256:c4705ccf969e262ee3916719ecc7c0fb5e606dd954278ac07ac1d052e4e490df + defaultTag: 6.9.0@sha256:47ddeb68cfdb767949b4e7f6e2306fa20a1ee5a2619efbe56bf06cb5a62e7729 # -- Docker image name for the `alpine` image name: "alpine-3.14" # -- Security context for the `alpine` initContainer, @@ -113,7 +113,7 @@ cadvisor: enabled: true image: # -- Docker image tag for the `cadvisor` image - defaultTag: 6.0.0@sha256:48082a2822a727e22c556ae2c3bae5f5bf4528c7b462efc3c085271ee5145be8 + defaultTag: 6.9.0@sha256:e7d919b8670d2db6fc49f5d33e7d30589e7bef0cfb3d0b41c83253a65c1d981b # -- Docker image name for the `cadvisor` image name: "cadvisor" # -- Name used by resources. Does not affect service names or PVCs. @@ -178,7 +178,7 @@ codeInsightsDB: additionalConfig: "" image: # -- Docker image tag for the `codeinsights-db` image - defaultTag: 6.0.0@sha256:24263ff136f8cc328d63808982beb4a109461da30b522b63d2867a4e708713c9 + defaultTag: 6.9.0@sha256:c1e207ca75c8ad2eb3dffc68c73448b7b43b373e051a95b65c8a80f5a34ff3fc # -- Docker image name for the `codeinsights-db` image name: "postgresql-16-codeinsights" # -- Security context for the `codeinsights-db` container, @@ -251,7 +251,7 @@ codeIntelDB: additionalConfig: "" image: # -- Docker image tag for the `codeintel-db` image - defaultTag: 6.0.0@sha256:224a2604331cb73809f466394c5b4f3ca95bf6a5a140cb75820dfe67301074bb + defaultTag: 6.9.0@sha256:5bf4140044f524232fb025be3405e4e4c438f7fb125a8195cf46b7d44ebec920 # -- Docker image name for the `codeintel-db` image name: "postgresql-16" # -- Security context for the `codeintel-db` container, @@ -302,7 +302,7 @@ frontend: value: http://prometheus:30090 image: # -- Docker image tag for the `frontend` image - defaultTag: 6.0.0@sha256:d4f21178096da5fdb3804099ae9de2e050b06e859a327aa79452b1ea2f3ede0a + defaultTag: 6.9.0@sha256:963e13089f94770ae9d96f761ec7c48015641a535f89606918d443df036e8d03 # -- Docker image name for the `frontend` image name: "frontend" ingress: @@ -362,7 +362,7 @@ migrator: enabled: true image: # -- Docker image tag for the `migrator` image - defaultTag: 6.0.0@sha256:ec295eb0b743da6bf56777ca6524972267a5c442b0288095e2fe12fce38ebacc + defaultTag: 6.9.0@sha256:b1fc02b83e36fc213307043568d6ceb6fa1eb52e2041001d60e8ba70ba0c0353 # -- Docker image name for the `migrator` image name: "migrator" # -- Environment variables for the `migrator` container @@ -387,7 +387,7 @@ migrator: gitserver: image: # -- Docker image tag for the `gitserver` image - defaultTag: 6.0.0@sha256:aec9bf6993c243a283109104cd7c44be3c85680b77e3e8be0c5fba8f01a3bd35 + defaultTag: 6.9.0@sha256:51fb917535ab4a4fdc1770ae70c2b6751e454ff4c53fc8ed3aefbb1917560083 # -- Docker image name for the `gitserver` image name: "gitserver" # -- Name of existing Secret that contains SSH credentials to clone repositories. @@ -455,7 +455,7 @@ grafana: existingConfig: "" # Name of an existing configmap image: # -- Docker image tag for the `grafana` image - defaultTag: 6.0.0@sha256:e40236d0143d0735ff87374afce95b878b8cde448ef65cfdc7008056a03097e8 + defaultTag: 6.9.0@sha256:52e1a6b845ccb1584f56bcbc6c517eedbec0d955aad64ee9a8ce3c5859a07b4b # -- Docker image name for the `grafana` image name: "grafana" # -- Security context for the `grafana` container, @@ -494,7 +494,7 @@ grafana: indexedSearch: image: # -- Docker image tag for the `zoekt-webserver` image - defaultTag: 6.0.0@sha256:99038e0ec9bef930030c118d774fcdcd67d7fe57ad4c80d216703a4d29d64323 + defaultTag: 6.9.0@sha256:ce9ba39d31bc36e2473e92c55339df45cd2ec80ea713fc73c340c5cc2af0e935 # -- Docker image name for the `zoekt-webserver` image name: "indexed-searcher" # -- Security context for the `zoekt-webserver` container, @@ -535,7 +535,7 @@ indexedSearch: indexedSearchIndexer: image: # -- Docker image tag for the `zoekt-indexserver` image - defaultTag: 6.0.0@sha256:11539e07040b85045a9aa07f970aa310066e240dc28e6c9627653ee2bc6e0b91 + defaultTag: 6.9.0@sha256:4fe5b168a89504f1e889389dd9e99b1be7d25b1f0284e77ce11c7da80748a8b2 # -- Docker image name for the `zoekt-indexserver` image name: "search-indexer" # -- Security context for the `zoekt-indexserver` container, @@ -562,7 +562,7 @@ blobstore: enabled: true image: # -- Docker image tag for the `blobstore` image - defaultTag: 6.0.0@sha256:82caab40f920282069c84e0e4ca503857926e934c67fb022f6d93823b4ea98b5 + defaultTag: 6.9.0@sha256:1a989ff6a1ce41ca7b5e438a97f950fe178379d429bd6b9a399fd698687b1a21 # -- Docker image name for the `blobstore` image name: "blobstore" # -- Security context for the `blobstore` container, @@ -601,7 +601,7 @@ openTelemetry: enabled: true image: # -- Docker image tag for the `otel-collector` image - defaultTag: 6.0.0@sha256:ef3e61a4f0a624523ecdee57d8b7757436c2389e0cf12401b4764d19c826ff8a + defaultTag: 6.9.0@sha256:fd2c847df65da33d622ac09754e09dd3603017cdcd9c43df180c0a499f27230d # -- Docker image name for the `otel-collector` image name: "opentelemetry-collector" gateway: @@ -668,7 +668,7 @@ nodeExporter: enabled: true image: # -- Docker image tag for the `node-exporter` image - defaultTag: 6.0.0@sha256:099c2e4fb8eacdda82d2d4798591808ded7ad3dc5e6ed514535e0b8e7223ed06 + defaultTag: 6.9.0@sha256:7be0055e06ec4167899d69b0df27fc2e51ecce5a7607c81a48b3ebb2c69b1e27 # -- Docker image name for the `node-exporter` image name: "node-exporter" # -- Name used by resources. Does not affect service names or PVCs. @@ -739,7 +739,7 @@ pgsql: additionalConfig: "" image: # -- Docker image tag for the `pgsql` image - defaultTag: 6.0.0@sha256:224a2604331cb73809f466394c5b4f3ca95bf6a5a140cb75820dfe67301074bb + defaultTag: 6.9.0@sha256:5bf4140044f524232fb025be3405e4e4c438f7fb125a8195cf46b7d44ebec920 # -- Docker image name for the `pgsql` image name: "postgresql-16" # -- Security context for the `pgsql` container, @@ -781,7 +781,7 @@ pgsql: postgresExporter: image: # -- Docker image tag for the `pgsql-exporter` image - defaultTag: 6.0.0@sha256:685a18f482e4a71a54e15814ffd6b8cd62844f6af056a81f7ec0ba5cf23fce27 + defaultTag: 6.9.0@sha256:31a6a30dc78e4fcf990762d9ed819e8a67722b75bca6f943e922889b9a78e580 # -- Docker image name for the `pgsql-exporter` image name: "postgres_exporter" # -- Resource requests & limits for the `pgsql-exporter` sidecar container, @@ -801,7 +801,7 @@ syntacticCodeIntel: workerPort: 3188 image: # -- Docker image tag for the `syntactic-code-intel-worker` image - defaultTag: 6.0.0@sha256:50bdeb38b196f0fc21404969016bf8263f78144292e905867e93480f66c8251c + defaultTag: 6.9.0@sha256:7e18db4367e4317bad7dcb2fac5aac58f3ce5cf6d8bfdf1d4337a54b13e32667 # -- Docker image name for the `syntactic-code-intel-worker` image name: "syntactic-code-intel-worker" # -- Security context for the `syntactic-code-intel-worker` container, @@ -840,7 +840,7 @@ preciseCodeIntel: value: "4" image: # -- Docker image tag for the `precise-code-intel-worker` image - defaultTag: 6.0.0@sha256:3a72cf893cb25731d4636593c544c91781d925d867417416255e56debc27ed37 + defaultTag: 6.9.0@sha256:8cdb8689c8c7100f6fc1b7ed7c8fbd2f055aee85ccf8a35eee46bd3545f1472c # -- Docker image name for the `precise-code-intel-worker` image name: "precise-code-intel-worker" # -- Security context for the `precise-code-intel-worker` container, @@ -879,7 +879,7 @@ prometheus: existingConfig: "" # Name of an existing configmap image: # -- Docker image tag for the `prometheus` image - defaultTag: 6.0.0@sha256:86a315720fd9813d9ef9746d92e637bc20cd9ebd90da78d8cc6906062252891f + defaultTag: 6.9.0@sha256:f9b456110b2755214ec6767196f4971742f22c4f9fbe25326328f11041a4fc5d # -- Docker image name for the `prometheus` image name: "prometheus" # -- Security context for the `prometheus` container, @@ -931,7 +931,7 @@ redisCache: enabled: true image: # -- Docker image tag for the `redis-cache` image - defaultTag: 6.0.0@sha256:40ea19e8944b93e05d7697c808969fe0c81a014a56245f3a97b645aa34a9ab78 + defaultTag: 6.9.0@sha256:440ed87b7dd2ecb19e0a94edfdd345b47265b302916499189af4fff7d38e57de # -- Docker image name for the `redis-cache` image name: "redis-cache" connection: @@ -975,7 +975,7 @@ redisCache: redisExporter: image: # -- Docker image tag for the `redis-exporter` image - defaultTag: 6.0.0@sha256:b2ec48fc6adef31f36d525170138dec303c1c0c20c530d659f1fb7c6c54698af + defaultTag: 6.9.0@sha256:81d0be46fa9bf4f9d1cb8d02db33addebaec987981e9093680fd85492445672c # -- Docker image name for the `redis-exporter` image name: "redis_exporter" # -- Security context for the `redis-exporter` sidecar container, @@ -1007,7 +1007,7 @@ redisStore: endpoint: "redis-store:6379" image: # -- Docker image tag for the `redis-store` image - defaultTag: 6.0.0@sha256:39f3b27d993652c202c1f892df83e1a3e8e8ea5ae58291f79ad14b56672ab8be + defaultTag: 6.9.0@sha256:535438c49584762906039c63b22871e9c0f40dedbef060283a94db588cfd65cd # -- Docker image name for the `redis-store` image name: "redis-store" # -- Security context for the `redis-store` container, @@ -1044,7 +1044,7 @@ redisStore: searcher: image: # -- Docker image tag for the `searcher` image - defaultTag: 6.0.0@sha256:c7508abda2202d4a33400ce23a95dd8d59fe6220d85d7fbee6fb186c55931336 + defaultTag: 6.9.0@sha256:2b4686138a72143c7c9c69f844d82fac6401f4cf61b0f42847f59a789e5faa58 # -- Docker image name for the `searcher` image name: "searcher" # -- Security context for the `searcher` container, @@ -1105,7 +1105,7 @@ storageClass: syntectServer: image: # -- Docker image tag for the `syntect-server` image - defaultTag: 6.0.0@sha256:1e35f77690222a76724b45f2305b838c40c35201e60b0f619b3fe8499504ff60 + defaultTag: 6.9.0@sha256:b14ed68537dacd5ee4e61ca2374835213324df186961cf095ed0393377ad3bb6 # -- Docker image name for the `syntect-server` image name: "syntax-highlighter" # -- Security context for the `syntect-server` container, @@ -1153,7 +1153,7 @@ jaeger: enabled: false image: # -- Docker image tag for the `jaeger` image - defaultTag: 6.0.0@sha256:79548aa11d7e2e6bf3e2012fb9e046df12ba5c5410bc24ec8f4d7cbb880336b9 + defaultTag: 6.9.0@sha256:96ddedeecc32e35d5b2e1d05ed04c716c24d9ac3f72fbaa2bccc8618a9c933a3 # -- Docker image name for the `jaeger` image name: "jaeger-all-in-one" # -- Name used by resources. Does not affect service names or PVCs. @@ -1208,7 +1208,7 @@ jaeger: worker: image: # -- Docker image tag for the `worker` image - defaultTag: 6.0.0@sha256:4892c5aa107d4384f811afcf1980e0fb2cb8beb5585a15adcb64353a2d8abf5a + defaultTag: 6.9.0@sha256:bc905262022303262f4c6836b377502b88aa02f15280037ae0d44d96ea55409a # -- Docker image name for the `worker` image name: "worker" # -- Security context for the `worker` container, From 179a5f2301c8a11a0ece430258ea20bd39d24639 Mon Sep 17 00:00:00 2001 From: Warren Gifford Date: Wed, 15 Oct 2025 19:46:41 +0000 Subject: [PATCH 2/6] promote-release: v6.9.0 {"version":"v6.9.0","inputs":"server=6.9.0","type":"patch"} --- charts/sourcegraph-executor/dind/README.md | 2 +- charts/sourcegraph-executor/dind/values.yaml | 2 +- charts/sourcegraph-executor/k8s/README.md | 2 +- charts/sourcegraph-executor/k8s/values.yaml | 2 +- charts/sourcegraph-migrator/README.md | 2 +- charts/sourcegraph-migrator/values.yaml | 2 +- charts/sourcegraph/README.md | 2 +- charts/sourcegraph/values.yaml | 2 +- 8 files changed, 8 insertions(+), 8 deletions(-) diff --git a/charts/sourcegraph-executor/dind/README.md b/charts/sourcegraph-executor/dind/README.md index 11cc694d..8a27a212 100644 --- a/charts/sourcegraph-executor/dind/README.md +++ b/charts/sourcegraph-executor/dind/README.md @@ -71,7 +71,7 @@ In addition to the documented values, the `executor` and `private-docker-registr | sourcegraph.affinity | object | `{}` | Affinity, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add a global label to all resources | diff --git a/charts/sourcegraph-executor/dind/values.yaml b/charts/sourcegraph-executor/dind/values.yaml index 3fad6872..386eb4ad 100644 --- a/charts/sourcegraph-executor/dind/values.yaml +++ b/charts/sourcegraph-executor/dind/values.yaml @@ -8,7 +8,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: us-docker.pkg.dev/sourcegraph-images/internal + repository: index.docker.io/sourcegraph # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials diff --git a/charts/sourcegraph-executor/k8s/README.md b/charts/sourcegraph-executor/k8s/README.md index 223c1d28..2232e3e7 100644 --- a/charts/sourcegraph-executor/k8s/README.md +++ b/charts/sourcegraph-executor/k8s/README.md @@ -99,7 +99,7 @@ In addition to the documented values, the `executor` and `private-docker-registr | sourcegraph.affinity | object | `{}` | Affinity, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add a global label to all resources | diff --git a/charts/sourcegraph-executor/k8s/values.yaml b/charts/sourcegraph-executor/k8s/values.yaml index 61883ee9..6fd736dc 100644 --- a/charts/sourcegraph-executor/k8s/values.yaml +++ b/charts/sourcegraph-executor/k8s/values.yaml @@ -8,7 +8,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: us-docker.pkg.dev/sourcegraph-images/internal + repository: index.docker.io/sourcegraph # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials diff --git a/charts/sourcegraph-migrator/README.md b/charts/sourcegraph-migrator/README.md index e8139340..6eb360de 100644 --- a/charts/sourcegraph-migrator/README.md +++ b/charts/sourcegraph-migrator/README.md @@ -88,7 +88,7 @@ In addition to the documented values, the `migrator` service also supports the f | sourcegraph.affinity | object | `{}` | Affinity, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity) | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add a global label to all resources | diff --git a/charts/sourcegraph-migrator/values.yaml b/charts/sourcegraph-migrator/values.yaml index a5454274..1df4edfb 100644 --- a/charts/sourcegraph-migrator/values.yaml +++ b/charts/sourcegraph-migrator/values.yaml @@ -8,7 +8,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: us-docker.pkg.dev/sourcegraph-images/internal + repository: index.docker.io/sourcegraph # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials diff --git a/charts/sourcegraph/README.md b/charts/sourcegraph/README.md index fba7fd22..f690afce 100644 --- a/charts/sourcegraph/README.md +++ b/charts/sourcegraph/README.md @@ -306,7 +306,7 @@ In addition to the documented values, all services also support the following va | sourcegraph.disableKubernetesSecrets | bool | `false` | Disable the creation of Kubernetes secrets objects | | sourcegraph.image.defaultTag | string | `"{{ .Chart.AppVersion }}"` | Global docker image tag | | sourcegraph.image.pullPolicy | string | `"IfNotPresent"` | Global docker image pull policy | -| sourcegraph.image.repository | string | `"us-docker.pkg.dev/sourcegraph-images/internal"` | Global docker image registry or prefix | +| sourcegraph.image.repository | string | `"index.docker.io/sourcegraph"` | Global docker image registry or prefix | | sourcegraph.image.useGlobalTagAsDefault | bool | `false` | When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags | | sourcegraph.imagePullSecrets | list | `[]` | Mount named secrets containing docker credentials | | sourcegraph.labels | object | `{}` | Add extra labels to all resources | diff --git a/charts/sourcegraph/values.yaml b/charts/sourcegraph/values.yaml index 15485557..25ed284d 100644 --- a/charts/sourcegraph/values.yaml +++ b/charts/sourcegraph/values.yaml @@ -9,7 +9,7 @@ sourcegraph: # -- Global docker image pull policy pullPolicy: IfNotPresent # -- Global docker image registry or prefix - repository: us-docker.pkg.dev/sourcegraph-images/internal + repository: index.docker.io/sourcegraph # -- When set to true, sourcegraph.image.defaultTag is used as the default defaultTag for all services, instead of service-specific default defaultTags useGlobalTagAsDefault: false # -- Mount named secrets containing docker credentials From cdf4a34d810a76441ad6dfeea8d90627fc4d8757 Mon Sep 17 00:00:00 2001 From: Marc LeBlanc Date: Thu, 16 Oct 2025 17:11:04 -0600 Subject: [PATCH 3/6] Testing changes on top of v6.9.0 --- .../frontend/sourcegraph-frontend-internal.Service.yaml | 4 ++-- .../templates/frontend/sourcegraph-frontend.Deployment.yaml | 2 +- .../sourcegraph/templates/gitserver/gitserver.Service.yaml | 6 +++--- .../templates/gitserver/gitserver.StatefulSet.yaml | 6 +++--- 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/charts/sourcegraph/templates/frontend/sourcegraph-frontend-internal.Service.yaml b/charts/sourcegraph/templates/frontend/sourcegraph-frontend-internal.Service.yaml index 9da16a6b..a9368c19 100644 --- a/charts/sourcegraph/templates/frontend/sourcegraph-frontend-internal.Service.yaml +++ b/charts/sourcegraph/templates/frontend/sourcegraph-frontend-internal.Service.yaml @@ -15,9 +15,9 @@ metadata: name: sourcegraph-frontend-internal spec: ports: - - name: http-internal + - name: grpc-internal port: 80 - targetPort: http-internal + targetPort: grpc-internal selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: sourcegraph-frontend diff --git a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml index e2dad382..f6c564a7 100644 --- a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml +++ b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml @@ -122,7 +122,7 @@ spec: - containerPort: 3080 name: http - containerPort: 3090 - name: http-internal + name: grpc-internal - containerPort: 6060 name: debug {{- if not .Values.sourcegraph.localDevMode }} diff --git a/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml b/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml index f4997a96..209b715f 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml @@ -21,9 +21,9 @@ metadata: spec: clusterIP: None ports: - - name: unused - port: 10811 - targetPort: 10811 + - name: grpc + port: 3178 + targetPort: 3178 selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: gitserver diff --git a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml index cb856118..265b91d9 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml @@ -61,17 +61,17 @@ spec: # pod because of a failed liveness probe, we give it 2 minutes to start up. startupProbe: tcpSocket: - port: rpc + port: grpc failureThreshold: 120 periodSeconds: 1 livenessProbe: initialDelaySeconds: 5 tcpSocket: - port: rpc + port: grpc timeoutSeconds: 5 ports: - containerPort: 3178 - name: rpc + name: grpc {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.gitserver.resources | nindent 10 }} From dfac77bb3528fe0353bce7877dd2f8763ad8435b Mon Sep 17 00:00:00 2001 From: Marc LeBlanc Date: Wed, 22 Oct 2025 16:10:25 -0600 Subject: [PATCH 4/6] Fixing other ports also affected Closed unused port Fixed formatting Updated tests --- .../private-docker-registry.Deployment.yaml | 8 +++---- .../private-docker-registry.Service.yaml | 4 ++-- charts/sourcegraph/README.md | 2 +- charts/sourcegraph/templates/_helpers.tpl | 2 +- .../blobstore/blobstore.Deployment.yaml | 8 +++---- .../blobstore/blobstore.Service.yaml | 4 ++-- .../sourcegraph-frontend.Deployment.yaml | 12 +++++----- .../gitserver/gitserver.Service.yaml | 2 +- .../indexed-search.IndexerService.yaml | 5 ++-- .../indexed-search.Service.yaml | 4 +++- .../indexed-search.StatefulSet.yaml | 2 +- .../jaeger/jaeger-collector.Service.yaml | 12 ++++------ .../jaeger/jaeger-query.Service.yaml | 4 ++-- .../templates/jaeger/jaeger.Deployment.yaml | 11 +++++---- .../otel-collector/otel-agent.DaemonSet.yaml | 18 +++++++------- .../otel-collector.Deployment.yaml | 16 ++++++------- .../otel-collector.Service.yaml | 10 ++++---- .../prometheus/prometheus.Deployment.yaml | 6 ++--- .../templates/searcher/searcher.Service.yaml | 4 ++-- .../searcher/searcher.StatefulSet.yaml | 4 ++-- .../tests/otelAgentHostPort_test.yaml | 24 +++++++++---------- charts/sourcegraph/values.yaml | 17 ++++++------- 22 files changed, 91 insertions(+), 88 deletions(-) diff --git a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml index eba01538..2380bbcd 100644 --- a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml +++ b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml @@ -47,19 +47,19 @@ spec: - name: REGISTRY_PROXY_REMOTEURL value: http://registry-1.docker.io ports: - - containerPort: 5000 - name: registry + - name: http-registry + containerPort: 5000 livenessProbe: httpGet: path: / - port: registry + port: http-registry scheme: HTTP initialDelaySeconds: 5 timeoutSeconds: 5 readinessProbe: httpGet: path: / - port: registry + port: http-registry scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 diff --git a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml index 35ff507b..85d2866a 100644 --- a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml +++ b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml @@ -13,10 +13,10 @@ metadata: name: private-docker-registry spec: ports: - - name: http + - name: http-registry port: 5000 protocol: TCP - targetPort: 5000 + targetPort: http-registry selector: app: private-docker-registry type: ClusterIP diff --git a/charts/sourcegraph/README.md b/charts/sourcegraph/README.md index f690afce..ae60e6e9 100644 --- a/charts/sourcegraph/README.md +++ b/charts/sourcegraph/README.md @@ -195,7 +195,7 @@ In addition to the documented values, all services also support the following va | openTelemetry.agent.containerSecurityContext.allowPrivilegeEscalation | bool | `false` | | | openTelemetry.agent.containerSecurityContext.runAsGroup | int | `101` | | | openTelemetry.agent.containerSecurityContext.runAsUser | int | `100` | | -| openTelemetry.agent.hostPorts | object | `{"otlpGrpc":4317,"otlpHttp":4318,"zpages":55679}` | Resource requests & limits for the `otel-agent` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | +| openTelemetry.agent.hostPorts | object | `{"grpcOtlp":4317,"httpOtlp":4318,"httpZpages":55679}` | Resource requests & limits for the `otel-agent` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) | | openTelemetry.agent.name | string | `"otel-agent"` | Name used by resources. Does not affect service names or PVCs. | | openTelemetry.agent.resources.limits.cpu | string | `"500m"` | | | openTelemetry.agent.resources.limits.memory | string | `"500Mi"` | | diff --git a/charts/sourcegraph/templates/_helpers.tpl b/charts/sourcegraph/templates/_helpers.tpl index caf8f0b5..c1671edd 100644 --- a/charts/sourcegraph/templates/_helpers.tpl +++ b/charts/sourcegraph/templates/_helpers.tpl @@ -175,7 +175,7 @@ app.kubernetes.io/name: jaeger fieldRef: fieldPath: status.hostIP - name: OTEL_EXPORTER_OTLP_ENDPOINT - value: http://$(OTEL_AGENT_HOST):{{ toYaml .Values.openTelemetry.agent.hostPorts.otlpGrpc }} + value: http://$(OTEL_AGENT_HOST):{{ toYaml .Values.openTelemetry.agent.hostPorts.grpcOtlp }} {{- end }} {{- end }} diff --git a/charts/sourcegraph/templates/blobstore/blobstore.Deployment.yaml b/charts/sourcegraph/templates/blobstore/blobstore.Deployment.yaml index 25dae8f3..08c87d9d 100644 --- a/charts/sourcegraph/templates/blobstore/blobstore.Deployment.yaml +++ b/charts/sourcegraph/templates/blobstore/blobstore.Deployment.yaml @@ -55,19 +55,19 @@ spec: args: {{- default (list "") .Values.blobstore.args | toYaml | nindent 8 }} terminationMessagePolicy: FallbackToLogsOnError ports: - - containerPort: 9000 - name: blobstore + - name: http + containerPort: 9000 livenessProbe: httpGet: path: / - port: blobstore + port: http scheme: HTTP initialDelaySeconds: 60 timeoutSeconds: 5 readinessProbe: httpGet: path: / - port: blobstore + port: http scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 diff --git a/charts/sourcegraph/templates/blobstore/blobstore.Service.yaml b/charts/sourcegraph/templates/blobstore/blobstore.Service.yaml index 81493aac..f5ca88cd 100644 --- a/charts/sourcegraph/templates/blobstore/blobstore.Service.yaml +++ b/charts/sourcegraph/templates/blobstore/blobstore.Service.yaml @@ -16,9 +16,9 @@ metadata: name: blobstore spec: ports: - - name: blobstore + - name: http port: 9000 - targetPort: blobstore + targetPort: http selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: blobstore diff --git a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml index f6c564a7..4a0b950a 100644 --- a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml +++ b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml @@ -119,12 +119,12 @@ spec: periodSeconds: 5 timeoutSeconds: 5 ports: - - containerPort: 3080 - name: http - - containerPort: 3090 - name: grpc-internal - - containerPort: 6060 - name: debug + - name: debug + containerPort: 6060 + - name: grpc-internal + containerPort: 3090 + - name: http + containerPort: 3080 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.frontend.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml b/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml index 209b715f..c6f7cf66 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml @@ -23,7 +23,7 @@ spec: ports: - name: grpc port: 3178 - targetPort: 3178 + targetPort: grpc selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: gitserver diff --git a/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml b/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml index 98fa5cf2..1d399267 100644 --- a/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml +++ b/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml @@ -20,8 +20,9 @@ metadata: spec: clusterIP: None ports: - - port: 6072 - targetPort: 6072 + - name: http-indexer + port: 6072 + targetPort: http-indexer selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: indexed-search diff --git a/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml b/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml index fe6da198..9acb970b 100644 --- a/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml +++ b/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml @@ -20,7 +20,9 @@ metadata: spec: clusterIP: None ports: - - port: 6070 + - name: http + port: 6070 + targetPort: http selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: indexed-search diff --git a/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml b/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml index 67933633..8eb57075 100644 --- a/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml +++ b/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml @@ -99,7 +99,7 @@ spec: {{- end }} ports: - containerPort: 6072 - name: index-http + name: http-indexer {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.indexedSearchIndexer.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml b/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml index 192b744d..baae9de2 100644 --- a/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml +++ b/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml @@ -17,18 +17,14 @@ metadata: name: {{ default "jaeger-collector" .Values.jaeger.collector.name }} spec: ports: - - name: jaeger-collector-tchannel - port: 14267 - protocol: TCP - targetPort: 14267 - - name: jaeger-collector-http + - name: http-jaeger-collector port: 4321 protocol: TCP - targetPort: 4321 - - name: jaeger-collector-grpc + targetPort: http-jaeger-collector + - name: grpc-jaeger-collector port: 4320 protocol: TCP - targetPort: 4320 + targetPort: grpc-jaeger-collector selector: {{- include "sourcegraph.jaeger.selectorLabels" . | nindent 4 }} app.kubernetes.io/instance: {{ .Release.Name }} diff --git a/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml b/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml index 5bb6701f..0e7ca9c2 100644 --- a/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml +++ b/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml @@ -17,10 +17,10 @@ metadata: name: {{ default "jaeger-query" .Values.jaeger.query.name }} spec: ports: - - name: query-http + - name: http-query port: 16686 protocol: TCP - targetPort: 16686 + targetPort: http-query selector: {{- include "sourcegraph.jaeger.selectorLabels" . | nindent 4 }} app.kubernetes.io/instance: {{ .Release.Name }} diff --git a/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml b/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml index 3733b57c..3a45374e 100644 --- a/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml +++ b/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml @@ -68,13 +68,16 @@ spec: protocol: UDP - containerPort: 5778 protocol: TCP - - containerPort: 16686 - protocol: TCP - containerPort: 14250 protocol: TCP - - containerPort: 4320 + - name: grpc-jaeger-collector + containerPort: 4320 + protocol: TCP + - name: http-jaeger-collector + containerPort: 4321 protocol: TCP - - containerPort: 4321 + - name: http-query + containerPort: 16686 protocol: TCP readinessProbe: httpGet: diff --git a/charts/sourcegraph/templates/otel-collector/otel-agent.DaemonSet.yaml b/charts/sourcegraph/templates/otel-collector/otel-agent.DaemonSet.yaml index ca03f26f..3efd5b1c 100644 --- a/charts/sourcegraph/templates/otel-collector/otel-agent.DaemonSet.yaml +++ b/charts/sourcegraph/templates/otel-collector/otel-agent.DaemonSet.yaml @@ -69,15 +69,15 @@ spec: path: / port: 13133 ports: - - containerPort: 55679 - hostPort: {{ toYaml .Values.openTelemetry.agent.hostPorts.zpages }} - name: zpages - - containerPort: 4317 - hostPort: {{ toYaml .Values.openTelemetry.agent.hostPorts.otlpGrpc }} - name: otlp-grpc - - containerPort: 4318 - hostPort: {{ toYaml .Values.openTelemetry.agent.hostPorts.otlpHttp }} - name: otlp-http + - name: grpc-otlp + containerPort: 4317 + hostPort: {{ toYaml .Values.openTelemetry.agent.hostPorts.grpcOtlp }} + - name: http-otlp + containerPort: 4318 + hostPort: {{ toYaml .Values.openTelemetry.agent.hostPorts.httpOtlp }} + - name: http-zpages + containerPort: 55679 + hostPort: {{ toYaml .Values.openTelemetry.agent.hostPorts.httpZpages }} volumeMounts: - name: config mountPath: /etc/otel-agent diff --git a/charts/sourcegraph/templates/otel-collector/otel-collector.Deployment.yaml b/charts/sourcegraph/templates/otel-collector/otel-collector.Deployment.yaml index 9b3f6da2..47896c1b 100644 --- a/charts/sourcegraph/templates/otel-collector/otel-collector.Deployment.yaml +++ b/charts/sourcegraph/templates/otel-collector/otel-collector.Deployment.yaml @@ -85,14 +85,14 @@ spec: path: / port: 13133 ports: - - containerPort: 55679 - name: zpages - - containerPort: 4317 - name: otlp-grpc - - containerPort: 4318 - name: otlp-http - - containerPort: 8888 - name: metrics + - name: grpc-otlp + containerPort: 4317 + - name: http-otlp + containerPort: 4318 + - name: http-metrics + containerPort: 8888 + - name: http-zpages + containerPort: 55679 volumeMounts: {{- if .Values.openTelemetry.gateway.config.traces.exporters }} - name: config diff --git a/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml b/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml index 27d503c7..764d8ca9 100644 --- a/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml +++ b/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml @@ -18,15 +18,15 @@ metadata: app.kubernetes.io/component: otel-collector spec: ports: - - name: otlp-grpc + - name: grpc-otlp port: 4317 protocol: TCP - targetPort: 4317 - - name: otlp-http + targetPort: grpc-otlp + - name: http-otlp port: 4318 protocol: TCP - targetPort: 4318 - - name: metrics # Default endpoint for querying metrics. + targetPort: http-otlp + - name: http-metrics port: 8888 selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} diff --git a/charts/sourcegraph/templates/prometheus/prometheus.Deployment.yaml b/charts/sourcegraph/templates/prometheus/prometheus.Deployment.yaml index 027024e6..c35fa2d2 100644 --- a/charts/sourcegraph/templates/prometheus/prometheus.Deployment.yaml +++ b/charts/sourcegraph/templates/prometheus/prometheus.Deployment.yaml @@ -60,13 +60,13 @@ spec: readinessProbe: httpGet: path: /-/ready - port: 9090 + port: http timeoutSeconds: 3 failureThreshold: 120 periodSeconds: 5 ports: - - containerPort: 9090 - name: http + - name: http + containerPort: 9090 volumeMounts: - mountPath: /prometheus name: data diff --git a/charts/sourcegraph/templates/searcher/searcher.Service.yaml b/charts/sourcegraph/templates/searcher/searcher.Service.yaml index fa4a0828..fe6af6c0 100644 --- a/charts/sourcegraph/templates/searcher/searcher.Service.yaml +++ b/charts/sourcegraph/templates/searcher/searcher.Service.yaml @@ -18,9 +18,9 @@ metadata: spec: clusterIP: None ports: - - name: http + - name: grpc port: 3181 - targetPort: http + targetPort: grpc - name: debug port: 6060 targetPort: debug diff --git a/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml b/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml index 327aefc9..89017dea 100644 --- a/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml +++ b/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml @@ -85,14 +85,14 @@ spec: terminationMessagePolicy: FallbackToLogsOnError ports: - containerPort: 3181 - name: http + name: grpc - containerPort: 6060 name: debug readinessProbe: failureThreshold: 3 httpGet: path: /healthz - port: http + port: grpc scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 diff --git a/charts/sourcegraph/tests/otelAgentHostPort_test.yaml b/charts/sourcegraph/tests/otelAgentHostPort_test.yaml index 06cdd0d3..0d4b0056 100644 --- a/charts/sourcegraph/tests/otelAgentHostPort_test.yaml +++ b/charts/sourcegraph/tests/otelAgentHostPort_test.yaml @@ -9,19 +9,19 @@ tests: content: containerPort: 55679 hostPort: 55679 - name: zpages + name: http-zpages - contains: path: spec.template.spec.containers[0].ports content: containerPort: 4317 hostPort: 4317 - name: otlp-grpc + name: grpc-otlp - contains: path: spec.template.spec.containers[0].ports content: containerPort: 4318 hostPort: 4318 - name: otlp-http + name: http-otlp - it: should render the agent endpoint with the default gRPC host port template: searcher/searcher.StatefulSet.yaml asserts: @@ -36,37 +36,37 @@ tests: openTelemetry: agent: hostPorts: - otlpGrpc: 4319 - otlpHttp: 4320 - zpages: 55680 + grpcOtlp: 4319 + httpOtlp: 4320 + httpZpages: 55680 asserts: - contains: path: spec.template.spec.containers[0].ports content: containerPort: 55679 hostPort: 55680 - name: zpages + name: http-zpages - contains: path: spec.template.spec.containers[0].ports content: containerPort: 4317 hostPort: 4319 - name: otlp-grpc + name: grpc-otlp - contains: path: spec.template.spec.containers[0].ports content: containerPort: 4318 hostPort: 4320 - name: otlp-http + name: http-otlp - it: should render the agent endpoint with the custom gRPC host port template: searcher/searcher.StatefulSet.yaml set: openTelemetry: agent: hostPorts: - otlpGrpc: 4319 - otlpHttp: 4320 - zpages: 55680 + grpcOtlp: 4319 + httpOtlp: 4320 + httpZpages: 55680 asserts: - contains: path: spec.template.spec.containers[0].env diff --git a/charts/sourcegraph/values.yaml b/charts/sourcegraph/values.yaml index 25ed284d..a0462c06 100644 --- a/charts/sourcegraph/values.yaml +++ b/charts/sourcegraph/values.yaml @@ -85,7 +85,8 @@ sourcegraph: # # Toggle deployment of applications on/off. Applies to databases and third-party applications # enabled: true -alpine: # Used in init containers +alpine: + # Used in init containers image: # -- Docker image tag for the `alpine` image defaultTag: 6.9.0@sha256:47ddeb68cfdb767949b4e7f6e2306fa20a1ee5a2619efbe56bf06cb5a62e7729 @@ -167,7 +168,7 @@ codeInsightsDB: # -- Sets codeinsights-db port port: "5432" # -- Sets codeinsights-db SSL mode - sslmode: "disable" # set to "require" to enable SSL + sslmode: "disable" # set to "require" to enable SSL # -- Environment variables for the `codeinsights-db` container env: {} # -- Name of existing ConfigMap for `codeinsights-db`. It must contain a `postgresql.conf` key. @@ -242,7 +243,7 @@ codeIntelDB: # -- Sets codeintel-db port port: "5432" # -- Sets codeintel-db SSL mode - sslmode: "disable" # set to "require" to enable SSL + sslmode: "disable" # set to "require" to enable SSL # -- Name of existing ConfigMap for `codeintel-db`. It must contain a `postgresql.conf` key existingConfig: "" # -- Additional PostgreSQL configuration. This will override or extend our default configuration. @@ -643,9 +644,9 @@ openTelemetry: # -- Resource requests & limits for the `otel-agent` container, # learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) hostPorts: - otlpGrpc: 4317 - otlpHttp: 4318 - zpages: 55679 + grpcOtlp: 4317 + httpOtlp: 4318 + httpZpages: 55679 resources: limits: cpu: "500m" @@ -730,9 +731,9 @@ pgsql: # -- Sets postgres port port: "5432" # -- Sets postgres SSL mode - sslmode: "disable" # set to "require" to enable SSL + sslmode: "disable" # set to "require" to enable SSL # -- Name of existing ConfigMap for `pgsql`. It must contain a `postgresql.conf` key - existingConfig: "" # Name of an existing configmap + existingConfig: "" # Name of an existing configmap # -- Additional PostgreSQL configuration. This will override or extend our default configuration. # Notes: This is expecting a multiline string. # Learn more from our [recommended PostgreSQL configuration](https://docs.sourcegraph.com/admin/config/postgres-conf) and [PostgreSQL documentation](https://www.postgresql.org/docs/12/config-setting.html) From a0a11225caddf421583d5298caa74dea269260ef Mon Sep 17 00:00:00 2001 From: Marc LeBlanc Date: Thu, 23 Oct 2025 17:37:24 -0600 Subject: [PATCH 5/6] Fix port names, Prometheus scraping annotations, add ports where used --- .../executor/executor.Deployment.yaml | 8 ++++---- .../templates/executor/executor.Service.yaml | 4 ++-- .../private-docker-registry.Deployment.yaml | 6 +++--- .../private-docker-registry.Service.yaml | 4 ++-- .../k8s/templates/executor.Deployment.yaml | 4 ++-- .../k8s/templates/executor.Service.yaml | 4 ++-- charts/sourcegraph/templates/_worker.tpl | 18 +++++++++--------- .../templates/cadvisor/cadvisor.DaemonSet.yaml | 2 +- .../codeinsights-db.Service.yaml | 3 +++ .../codeinsights-db.StatefulSet.yaml | 13 ++++++++----- .../codeintel-db/codeintel-db.Service.yaml | 3 +++ .../codeintel-db/codeintel-db.StatefulSet.yaml | 13 ++++++++----- .../sourcegraph-frontend.Deployment.yaml | 8 ++++---- .../frontend/sourcegraph-frontend.Service.yaml | 3 +++ .../templates/gitserver/gitserver.Service.yaml | 3 +++ .../gitserver/gitserver.StatefulSet.yaml | 6 ++++-- .../templates/grafana/grafana.StatefulSet.yaml | 4 ++-- .../indexed-search.IndexerService.yaml | 2 +- .../indexed-search/indexed-search.Service.yaml | 2 +- .../indexed-search.StatefulSet.yaml | 8 ++++---- .../jaeger/jaeger-collector.Service.yaml | 8 ++++---- .../templates/jaeger/jaeger-query.Service.yaml | 4 ++-- .../templates/jaeger/jaeger.Deployment.yaml | 10 +++++----- .../node-exporter/node-exporter.Service.yaml | 2 +- .../otel-collector/otel-collector.Service.yaml | 9 +++++---- .../templates/pgsql/pgsql.Service.yaml | 3 +++ .../templates/pgsql/pgsql.StatefulSet.yaml | 13 ++++++++----- .../precise-code-intel/worker.Deployment.yaml | 12 ++++++------ .../precise-code-intel/worker.Service.yaml | 4 ++-- .../redis/redis-cache.Deployment.yaml | 8 ++++---- .../redis/redis-store.Deployment.yaml | 8 ++++---- .../templates/searcher/searcher.Service.yaml | 4 ++-- .../searcher/searcher.StatefulSet.yaml | 8 ++++---- .../worker.Deployment.yaml | 10 +++++----- .../syntactic-code-intel/worker.Service.yaml | 4 ++-- .../syntect-server.Deployment.yaml | 6 ++++-- .../syntect-server/syntect-server.Service.yaml | 3 +++ .../worker/worker-executors.Service.yaml | 4 ++-- .../templates/worker/worker.Service.yaml | 4 ++-- 39 files changed, 137 insertions(+), 105 deletions(-) diff --git a/charts/sourcegraph-executor/dind/templates/executor/executor.Deployment.yaml b/charts/sourcegraph-executor/dind/templates/executor/executor.Deployment.yaml index ab058fab..9570283d 100644 --- a/charts/sourcegraph-executor/dind/templates/executor/executor.Deployment.yaml +++ b/charts/sourcegraph-executor/dind/templates/executor/executor.Deployment.yaml @@ -51,20 +51,20 @@ spec: livenessProbe: httpGet: path: /healthz - port: debug + port: http-debug scheme: HTTP initialDelaySeconds: 60 timeoutSeconds: 5 readinessProbe: httpGet: path: /ready - port: debug + port: http-debug scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 ports: - - containerPort: 6060 - name: debug + - name: http-debug + containerPort: 6060 terminationMessagePolicy: FallbackToLogsOnError env: {{- range $name, $item := .Values.executor.env }} diff --git a/charts/sourcegraph-executor/dind/templates/executor/executor.Service.yaml b/charts/sourcegraph-executor/dind/templates/executor/executor.Service.yaml index 579af804..970de1a9 100644 --- a/charts/sourcegraph-executor/dind/templates/executor/executor.Service.yaml +++ b/charts/sourcegraph-executor/dind/templates/executor/executor.Service.yaml @@ -16,9 +16,9 @@ metadata: name: executor spec: ports: - - name: debug + - name: http-debug port: 6060 - targetPort: debug + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: {{include "executor.name" . }} diff --git a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml index 2380bbcd..257dae57 100644 --- a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml +++ b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Deployment.yaml @@ -47,19 +47,19 @@ spec: - name: REGISTRY_PROXY_REMOTEURL value: http://registry-1.docker.io ports: - - name: http-registry + - name: http containerPort: 5000 livenessProbe: httpGet: path: / - port: http-registry + port: http scheme: HTTP initialDelaySeconds: 5 timeoutSeconds: 5 readinessProbe: httpGet: path: / - port: http-registry + port: http scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 diff --git a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml index 85d2866a..356293ca 100644 --- a/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml +++ b/charts/sourcegraph-executor/dind/templates/private-docker-registry/private-docker-registry.Service.yaml @@ -13,10 +13,10 @@ metadata: name: private-docker-registry spec: ports: - - name: http-registry + - name: http port: 5000 protocol: TCP - targetPort: http-registry + targetPort: http selector: app: private-docker-registry type: ClusterIP diff --git a/charts/sourcegraph-executor/k8s/templates/executor.Deployment.yaml b/charts/sourcegraph-executor/k8s/templates/executor.Deployment.yaml index 635798c3..dd33bdf9 100644 --- a/charts/sourcegraph-executor/k8s/templates/executor.Deployment.yaml +++ b/charts/sourcegraph-executor/k8s/templates/executor.Deployment.yaml @@ -55,8 +55,8 @@ spec: securityContext: privileged: {{ .Values.executor.securityContext.privileged }} ports: - - containerPort: 6060 - name: debug + - name: http-debug + containerPort: 6060 envFrom: - configMapRef: name: {{ include "executor.name" . }} diff --git a/charts/sourcegraph-executor/k8s/templates/executor.Service.yaml b/charts/sourcegraph-executor/k8s/templates/executor.Service.yaml index e7b3c58b..33d841b3 100644 --- a/charts/sourcegraph-executor/k8s/templates/executor.Service.yaml +++ b/charts/sourcegraph-executor/k8s/templates/executor.Service.yaml @@ -13,9 +13,9 @@ metadata: name: {{ include "executor.name" . }} spec: ports: - - name: debug + - name: http-debug port: 6060 - targetPort: debug + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: {{ include "executor.name" . }} diff --git a/charts/sourcegraph/templates/_worker.tpl b/charts/sourcegraph/templates/_worker.tpl index b824cc82..73c4b64a 100644 --- a/charts/sourcegraph/templates/_worker.tpl +++ b/charts/sourcegraph/templates/_worker.tpl @@ -1,7 +1,7 @@ {{- define "sourcegraph.worker" -}} {{- $top := index . 0 }} {{- $suffix := index . 1 -}} -{{- $allowlist := index . 2 -}} +{{- $allowlist := index . 2 -}} {{- $blocklist := index . 3 -}} {{- $resources := index . 4 -}} @@ -100,24 +100,24 @@ spec: livenessProbe: httpGet: path: /healthz - port: debug + port: http-debug scheme: HTTP initialDelaySeconds: 60 timeoutSeconds: 5 readinessProbe: httpGet: path: /ready - port: debug + port: http-debug scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 ports: - - containerPort: 3189 - name: http - - containerPort: 6060 - name: debug - - containerPort: 6996 - name: prom + - name: http + containerPort: 3189 + - name: http-debug + containerPort: 6060 + - name: http-debug-exec + containerPort: 6996 {{- if not $top.Values.sourcegraph.localDevMode }} resources: {{- toYaml $resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/cadvisor/cadvisor.DaemonSet.yaml b/charts/sourcegraph/templates/cadvisor/cadvisor.DaemonSet.yaml index fe3b65ad..40508fc6 100644 --- a/charts/sourcegraph/templates/cadvisor/cadvisor.DaemonSet.yaml +++ b/charts/sourcegraph/templates/cadvisor/cadvisor.DaemonSet.yaml @@ -22,9 +22,9 @@ spec: metadata: annotations: description: Collects and exports container metrics. + kubectl.kubernetes.io/default-container: cadvisor prometheus.io/port: "48080" sourcegraph.prometheus/scrape: "true" - kubectl.kubernetes.io/default-container: cadvisor {{- if .Values.sourcegraph.podAnnotations }} {{- toYaml .Values.sourcegraph.podAnnotations | nindent 8 }} {{- end }} diff --git a/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.Service.yaml b/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.Service.yaml index 8ad06da0..e071a6af 100644 --- a/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.Service.yaml +++ b/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.Service.yaml @@ -18,6 +18,9 @@ metadata: name: codeinsights-db spec: ports: + - name: http-metrics + port: 9187 + targetPort: http-metrics - name: codeinsights-db port: 5432 targetPort: codeinsights-db diff --git a/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.StatefulSet.yaml b/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.StatefulSet.yaml index eda2bcd6..d56a02a8 100644 --- a/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.StatefulSet.yaml +++ b/charts/sourcegraph/templates/codeinsights-db/codeinsights-db.StatefulSet.yaml @@ -79,8 +79,8 @@ spec: value: "/conf" terminationMessagePolicy: FallbackToLogsOnError ports: - - containerPort: 5432 - name: codeinsights-db + - name: codeinsights-db + containerPort: 5432 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.codeInsightsDB.resources | nindent 10 }} @@ -97,7 +97,8 @@ spec: {{- if .Values.codeInsightsDB.extraVolumeMounts }} {{- toYaml .Values.codeInsightsDB.extraVolumeMounts | nindent 8 }} {{- end }} - - env: + - name: pgsql-exporter + env: {{- include "sourcegraph.dataSource" (list . "codeInsightsDB" ) | nindent 8 }} {{- range $name, $item := .Values.codeInsightsDB.postgresExporter.env}} - name: {{ $name }} @@ -106,14 +107,16 @@ spec: - name: PG_EXPORTER_EXTEND_QUERY_PATH value: /config/code_insights_queries.yaml image: {{ include "sourcegraph.image" (list . "postgresExporter") }} - terminationMessagePolicy: FallbackToLogsOnError - name: pgsql-exporter + ports: + - name: http-metrics + containerPort: 9187 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.postgresExporter.resources | nindent 10 }} {{- end }} securityContext: {{- toYaml .Values.postgresExporter.containerSecurityContext | nindent 10 }} + terminationMessagePolicy: FallbackToLogsOnError {{- if .Values.codeInsightsDB.extraContainers }} {{- toYaml .Values.codeInsightsDB.extraContainers | nindent 6 }} {{- end }} diff --git a/charts/sourcegraph/templates/codeintel-db/codeintel-db.Service.yaml b/charts/sourcegraph/templates/codeintel-db/codeintel-db.Service.yaml index fbce429a..d2d9c445 100644 --- a/charts/sourcegraph/templates/codeintel-db/codeintel-db.Service.yaml +++ b/charts/sourcegraph/templates/codeintel-db/codeintel-db.Service.yaml @@ -18,6 +18,9 @@ metadata: name: codeintel-db spec: ports: + - name: http-metrics + port: 9187 + targetPort: http-metrics - name: pgsql port: 5432 targetPort: pgsql diff --git a/charts/sourcegraph/templates/codeintel-db/codeintel-db.StatefulSet.yaml b/charts/sourcegraph/templates/codeintel-db/codeintel-db.StatefulSet.yaml index 6ad34e74..accb0b3f 100644 --- a/charts/sourcegraph/templates/codeintel-db/codeintel-db.StatefulSet.yaml +++ b/charts/sourcegraph/templates/codeintel-db/codeintel-db.StatefulSet.yaml @@ -90,8 +90,8 @@ spec: failureThreshold: 360 periodSeconds: 10 ports: - - containerPort: 5432 - name: pgsql + - name: pgsql + containerPort: 5432 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.codeIntelDB.resources | nindent 10 }} @@ -111,7 +111,8 @@ spec: {{- if .Values.codeIntelDB.extraContainers }} {{- toYaml .Values.codeIntelDB.extraContainers | nindent 6 }} {{- end }} - - env: + - name: pgsql-exporter + env: {{- include "sourcegraph.dataSource" (list . "codeIntelDB" ) | nindent 8 }} {{- range $name, $item := .Values.codeIntelDB.postgresExporter.env}} - name: {{ $name }} @@ -120,14 +121,16 @@ spec: - name: PG_EXPORTER_EXTEND_QUERY_PATH value: /config/code_intel_queries.yaml image: {{ include "sourcegraph.image" (list . "postgresExporter") }} - terminationMessagePolicy: FallbackToLogsOnError - name: pgsql-exporter + ports: + - name: http-metrics + containerPort: 9187 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.postgresExporter.resources | nindent 10 }} {{- end }} securityContext: {{- toYaml .Values.postgresExporter.containerSecurityContext | nindent 10 }} + terminationMessagePolicy: FallbackToLogsOnError terminationGracePeriodSeconds: 120 securityContext: {{- toYaml .Values.codeIntelDB.podSecurityContext | nindent 8 }} diff --git a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml index 4a0b950a..dd8f31a7 100644 --- a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml +++ b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Deployment.yaml @@ -107,24 +107,24 @@ spec: livenessProbe: httpGet: path: /healthz - port: debug + port: http-debug scheme: HTTP initialDelaySeconds: 300 timeoutSeconds: 5 readinessProbe: httpGet: path: /ready - port: debug + port: http-debug scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 ports: - - name: debug - containerPort: 6060 - name: grpc-internal containerPort: 3090 - name: http containerPort: 3080 + - name: http-debug + containerPort: 6060 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.frontend.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Service.yaml b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Service.yaml index 826319de..1d64e7f2 100644 --- a/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Service.yaml +++ b/charts/sourcegraph/templates/frontend/sourcegraph-frontend.Service.yaml @@ -20,6 +20,9 @@ spec: - name: http port: 30080 targetPort: http + - name: http-debug + port: 6060 + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: sourcegraph-frontend diff --git a/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml b/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml index c6f7cf66..16e4aecc 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.Service.yaml @@ -24,6 +24,9 @@ spec: - name: grpc port: 3178 targetPort: grpc + - name: http-debug + port: 6060 + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: gitserver diff --git a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml index 265b91d9..9620df24 100644 --- a/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml +++ b/charts/sourcegraph/templates/gitserver/gitserver.StatefulSet.yaml @@ -70,8 +70,10 @@ spec: port: grpc timeoutSeconds: 5 ports: - - containerPort: 3178 - name: grpc + - name: grpc + containerPort: 3178 + - name: http-debug + containerPort: 6060 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.gitserver.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/grafana/grafana.StatefulSet.yaml b/charts/sourcegraph/templates/grafana/grafana.StatefulSet.yaml index 4d748bd0..da569d02 100644 --- a/charts/sourcegraph/templates/grafana/grafana.StatefulSet.yaml +++ b/charts/sourcegraph/templates/grafana/grafana.StatefulSet.yaml @@ -60,8 +60,8 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - containerPort: 3370 - name: http + - name: http + containerPort: 3370 volumeMounts: - mountPath: /var/lib/grafana name: grafana-data diff --git a/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml b/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml index 1d399267..db1ec5f7 100644 --- a/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml +++ b/charts/sourcegraph/templates/indexed-search/indexed-search.IndexerService.yaml @@ -4,8 +4,8 @@ metadata: annotations: description: Headless service that provides a stable network identity for the indexed-search stateful set. - sourcegraph.prometheus/scrape: "true" prometheus.io/port: "6072" + sourcegraph.prometheus/scrape: "true" {{- if .Values.indexedSearch.serviceAnnotations }} {{- toYaml .Values.indexedSearch.serviceAnnotations | nindent 4 }} {{- end }} diff --git a/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml b/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml index 9acb970b..4f53adbb 100644 --- a/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml +++ b/charts/sourcegraph/templates/indexed-search/indexed-search.Service.yaml @@ -4,8 +4,8 @@ metadata: annotations: description: Headless service that provides a stable network identity for the indexed-search stateful set. - sourcegraph.prometheus/scrape: "true" prometheus.io/port: "6070" + sourcegraph.prometheus/scrape: "true" {{- if .Values.indexedSearch.serviceAnnotations }} {{- toYaml .Values.indexedSearch.serviceAnnotations | nindent 4 }} {{- end }} diff --git a/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml b/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml index 8eb57075..1673444d 100644 --- a/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml +++ b/charts/sourcegraph/templates/indexed-search/indexed-search.StatefulSet.yaml @@ -61,8 +61,8 @@ spec: value: "false" {{- end }} ports: - - containerPort: 6070 - name: http + - name: http + containerPort: 6070 readinessProbe: failureThreshold: 3 httpGet: @@ -98,8 +98,8 @@ spec: value: "false" {{- end }} ports: - - containerPort: 6072 - name: http-indexer + - name: http-indexer + containerPort: 6072 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.indexedSearchIndexer.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml b/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml index baae9de2..7e6ac14b 100644 --- a/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml +++ b/charts/sourcegraph/templates/jaeger/jaeger-collector.Service.yaml @@ -17,14 +17,14 @@ metadata: name: {{ default "jaeger-collector" .Values.jaeger.collector.name }} spec: ports: - - name: http-jaeger-collector + - name: http-collector port: 4321 protocol: TCP - targetPort: http-jaeger-collector - - name: grpc-jaeger-collector + targetPort: http-collector + - name: grpc-collector port: 4320 protocol: TCP - targetPort: grpc-jaeger-collector + targetPort: grpc-collector selector: {{- include "sourcegraph.jaeger.selectorLabels" . | nindent 4 }} app.kubernetes.io/instance: {{ .Release.Name }} diff --git a/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml b/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml index 0e7ca9c2..223e9209 100644 --- a/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml +++ b/charts/sourcegraph/templates/jaeger/jaeger-query.Service.yaml @@ -17,10 +17,10 @@ metadata: name: {{ default "jaeger-query" .Values.jaeger.query.name }} spec: ports: - - name: http-query + - name: http port: 16686 protocol: TCP - targetPort: http-query + targetPort: http selector: {{- include "sourcegraph.jaeger.selectorLabels" . | nindent 4 }} app.kubernetes.io/instance: {{ .Release.Name }} diff --git a/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml b/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml index 3a45374e..39a766da 100644 --- a/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml +++ b/charts/sourcegraph/templates/jaeger/jaeger.Deployment.yaml @@ -27,9 +27,9 @@ spec: template: metadata: annotations: - prometheus.io/scrape: "true" - prometheus.io/port: "16686" kubectl.kubernetes.io/default-container: jaeger + prometheus.io/port: "16686" + sourcegraph.prometheus/scrape: "true" {{- if .Values.sourcegraph.podAnnotations }} {{- toYaml .Values.sourcegraph.podAnnotations | nindent 8 }} {{- end }} @@ -70,13 +70,13 @@ spec: protocol: TCP - containerPort: 14250 protocol: TCP - - name: grpc-jaeger-collector + - name: grpc-collector containerPort: 4320 protocol: TCP - - name: http-jaeger-collector + - name: http-collector containerPort: 4321 protocol: TCP - - name: http-query + - name: http containerPort: 16686 protocol: TCP readinessProbe: diff --git a/charts/sourcegraph/templates/node-exporter/node-exporter.Service.yaml b/charts/sourcegraph/templates/node-exporter/node-exporter.Service.yaml index aa33cd9d..ce747c46 100644 --- a/charts/sourcegraph/templates/node-exporter/node-exporter.Service.yaml +++ b/charts/sourcegraph/templates/node-exporter/node-exporter.Service.yaml @@ -4,9 +4,9 @@ kind: Service metadata: annotations: description: Prometheus exporter for hardware and OS metrics. - url: https://github.com/prometheus/node_exporter prometheus.io/port: "9100" sourcegraph.prometheus/scrape: "true" + url: https://github.com/prometheus/node_exporter {{- if .Values.nodeExporter.serviceAnnotations }} {{- toYaml .Values.nodeExporter.serviceAnnotations | nindent 4 }} {{- end }} diff --git a/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml b/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml index 764d8ca9..bed2bd0f 100644 --- a/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml +++ b/charts/sourcegraph/templates/otel-collector/otel-collector.Service.yaml @@ -4,11 +4,11 @@ kind: Service metadata: name: otel-collector annotations: + prometheus.io/port: "8888" + sourcegraph.prometheus/scrape: "true" {{- if .Values.openTelemetry.gateway.serviceAnnotations }} {{- toYaml .Values.openTelemetry.gateway.serviceAnnotations | nindent 4 }} {{- end }} - sourcegraph.prometheus/scrape: "true" - prometheus.io/port: "8888" labels: {{- include "sourcegraph.labels" . | nindent 4 }} {{- if .Values.openTelemetry.gateway.serviceLabels }} @@ -22,12 +22,13 @@ spec: port: 4317 protocol: TCP targetPort: grpc-otlp + - name: http-metrics + port: 8888 + targetPort: http-metrics - name: http-otlp port: 4318 protocol: TCP targetPort: http-otlp - - name: http-metrics - port: 8888 selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: otel-collector diff --git a/charts/sourcegraph/templates/pgsql/pgsql.Service.yaml b/charts/sourcegraph/templates/pgsql/pgsql.Service.yaml index 139b7a08..284d0348 100644 --- a/charts/sourcegraph/templates/pgsql/pgsql.Service.yaml +++ b/charts/sourcegraph/templates/pgsql/pgsql.Service.yaml @@ -18,6 +18,9 @@ metadata: name: pgsql spec: ports: + - name: http-metrics + port: 9187 + targetPort: http-metrics - name: pgsql port: 5432 targetPort: pgsql diff --git a/charts/sourcegraph/templates/pgsql/pgsql.StatefulSet.yaml b/charts/sourcegraph/templates/pgsql/pgsql.StatefulSet.yaml index 48a1f0f1..2e6727af 100644 --- a/charts/sourcegraph/templates/pgsql/pgsql.StatefulSet.yaml +++ b/charts/sourcegraph/templates/pgsql/pgsql.StatefulSet.yaml @@ -90,8 +90,8 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - containerPort: 5432 - name: pgsql + - name: pgsql + containerPort: 5432 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.pgsql.resources | nindent 10 }} @@ -113,7 +113,8 @@ spec: {{- if .Values.pgsql.extraContainers }} {{- toYaml .Values.pgsql.extraContainers | nindent 6 }} {{- end }} - - env: + - name: pgsql-exporter + env: {{- include "sourcegraph.dataSource" (list . "pgsql" ) | nindent 8 }} {{- range $name, $item := .Values.pgsql.postgresExporter.env}} - name: {{ $name }} @@ -122,14 +123,16 @@ spec: - name: PG_EXPORTER_EXTEND_QUERY_PATH value: /config/queries.yaml image: {{ include "sourcegraph.image" (list . "postgresExporter") }} - terminationMessagePolicy: FallbackToLogsOnError - name: pgsql-exporter + ports: + - name: http-metrics + containerPort: 9187 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.postgresExporter.resources | nindent 10 }} {{- end }} securityContext: {{- toYaml .Values.postgresExporter.containerSecurityContext | nindent 10 }} + terminationMessagePolicy: FallbackToLogsOnError terminationGracePeriodSeconds: 120 securityContext: {{- toYaml .Values.pgsql.podSecurityContext | nindent 8 }} diff --git a/charts/sourcegraph/templates/precise-code-intel/worker.Deployment.yaml b/charts/sourcegraph/templates/precise-code-intel/worker.Deployment.yaml index 8815c85a..18cba342 100644 --- a/charts/sourcegraph/templates/precise-code-intel/worker.Deployment.yaml +++ b/charts/sourcegraph/templates/precise-code-intel/worker.Deployment.yaml @@ -73,22 +73,22 @@ spec: livenessProbe: httpGet: path: /healthz - port: debug + port: http-debug scheme: HTTP initialDelaySeconds: 60 timeoutSeconds: 5 readinessProbe: httpGet: path: /ready - port: debug + port: http-debug scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 ports: - - containerPort: 3188 - name: http - - containerPort: 6060 - name: debug + - name: http + containerPort: 3188 + - name: http-debug + containerPort: 6060 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.preciseCodeIntel.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/precise-code-intel/worker.Service.yaml b/charts/sourcegraph/templates/precise-code-intel/worker.Service.yaml index 836158fb..12572c2e 100644 --- a/charts/sourcegraph/templates/precise-code-intel/worker.Service.yaml +++ b/charts/sourcegraph/templates/precise-code-intel/worker.Service.yaml @@ -20,9 +20,9 @@ spec: - name: http port: 3188 targetPort: http - - name: debug + - name: http-debug port: 6060 - targetPort: debug + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: precise-code-intel-worker diff --git a/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml b/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml index da11dbcd..4d6eb515 100644 --- a/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml +++ b/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml @@ -86,8 +86,8 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - containerPort: 6379 - name: redis + - name: redis + containerPort: 6379 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.redisCache.resources | nindent 10 }} @@ -110,8 +110,8 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - containerPort: 9121 - name: redisexp + - name: redisexp + containerPort: 9121 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.redisExporter.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml b/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml index f9ff22a7..958f0aeb 100644 --- a/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml +++ b/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml @@ -85,8 +85,8 @@ spec: exit 1 fi ports: - - containerPort: 6379 - name: redis + - name: redis + containerPort: 6379 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.redisStore.resources | nindent 10 }} @@ -109,8 +109,8 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - containerPort: 9121 - name: redisexp + - name: redisexp + containerPort: 9121 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.redisExporter.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/searcher/searcher.Service.yaml b/charts/sourcegraph/templates/searcher/searcher.Service.yaml index fe6af6c0..185307a4 100644 --- a/charts/sourcegraph/templates/searcher/searcher.Service.yaml +++ b/charts/sourcegraph/templates/searcher/searcher.Service.yaml @@ -21,9 +21,9 @@ spec: - name: grpc port: 3181 targetPort: grpc - - name: debug + - name: http-debug port: 6060 - targetPort: debug + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: searcher diff --git a/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml b/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml index 89017dea..6770c804 100644 --- a/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml +++ b/charts/sourcegraph/templates/searcher/searcher.StatefulSet.yaml @@ -84,10 +84,10 @@ spec: imagePullPolicy: {{ .Values.sourcegraph.image.pullPolicy }} terminationMessagePolicy: FallbackToLogsOnError ports: - - containerPort: 3181 - name: grpc - - containerPort: 6060 - name: debug + - name: grpc + containerPort: 3181 + - name: http-debug + containerPort: 6060 readinessProbe: failureThreshold: 3 httpGet: diff --git a/charts/sourcegraph/templates/syntactic-code-intel/worker.Deployment.yaml b/charts/sourcegraph/templates/syntactic-code-intel/worker.Deployment.yaml index 88b08fd4..a32afdaf 100644 --- a/charts/sourcegraph/templates/syntactic-code-intel/worker.Deployment.yaml +++ b/charts/sourcegraph/templates/syntactic-code-intel/worker.Deployment.yaml @@ -83,15 +83,15 @@ spec: readinessProbe: httpGet: path: /ready - port: debug + port: http-debug scheme: HTTP periodSeconds: 5 timeoutSeconds: 5 ports: - - containerPort: {{ .Values.syntacticCodeIntel.properties.workerPort }} - name: http - - containerPort: 6060 - name: debug + - name: http + containerPort: {{ .Values.syntacticCodeIntel.properties.workerPort }} + - name: http-debug + containerPort: 6060 {{- if not .Values.sourcegraph.localDevMode }} resources: {{- toYaml .Values.syntacticCodeIntel.resources | nindent 10 }} diff --git a/charts/sourcegraph/templates/syntactic-code-intel/worker.Service.yaml b/charts/sourcegraph/templates/syntactic-code-intel/worker.Service.yaml index 82ff0d9f..14b51336 100644 --- a/charts/sourcegraph/templates/syntactic-code-intel/worker.Service.yaml +++ b/charts/sourcegraph/templates/syntactic-code-intel/worker.Service.yaml @@ -21,9 +21,9 @@ spec: - name: http port: {{ .Values.syntacticCodeIntel.properties.workerPort }} targetPort: http - - name: debug + - name: http-debug port: 6060 - targetPort: debug + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: syntactic-code-intel-worker diff --git a/charts/sourcegraph/templates/syntect-server/syntect-server.Deployment.yaml b/charts/sourcegraph/templates/syntect-server/syntect-server.Deployment.yaml index c21ba7e6..7d6e0712 100644 --- a/charts/sourcegraph/templates/syntect-server/syntect-server.Deployment.yaml +++ b/charts/sourcegraph/templates/syntect-server/syntect-server.Deployment.yaml @@ -67,8 +67,10 @@ spec: initialDelaySeconds: 5 timeoutSeconds: 5 ports: - - containerPort: 9238 - name: http + - name: http + containerPort: 9238 + - name: http-debug + containerPort: 6060 readinessProbe: tcpSocket: port: http diff --git a/charts/sourcegraph/templates/syntect-server/syntect-server.Service.yaml b/charts/sourcegraph/templates/syntect-server/syntect-server.Service.yaml index 14222ccd..9cc5b9fa 100644 --- a/charts/sourcegraph/templates/syntect-server/syntect-server.Service.yaml +++ b/charts/sourcegraph/templates/syntect-server/syntect-server.Service.yaml @@ -20,6 +20,9 @@ spec: - name: http port: 9238 targetPort: http + - name: http-debug + port: 6060 + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: syntect-server diff --git a/charts/sourcegraph/templates/worker/worker-executors.Service.yaml b/charts/sourcegraph/templates/worker/worker-executors.Service.yaml index 2fa4f079..688faa88 100644 --- a/charts/sourcegraph/templates/worker/worker-executors.Service.yaml +++ b/charts/sourcegraph/templates/worker/worker-executors.Service.yaml @@ -17,9 +17,9 @@ metadata: name: worker-executors spec: ports: - - name: prom + - name: http-debug-exec port: 6996 - targetPort: prom + targetPort: http-debug-exec selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: worker diff --git a/charts/sourcegraph/templates/worker/worker.Service.yaml b/charts/sourcegraph/templates/worker/worker.Service.yaml index d3e86c3f..9f4b8a29 100644 --- a/charts/sourcegraph/templates/worker/worker.Service.yaml +++ b/charts/sourcegraph/templates/worker/worker.Service.yaml @@ -20,9 +20,9 @@ spec: - name: http port: 3189 targetPort: http - - name: debug + - name: http-debug port: 6060 - targetPort: debug + targetPort: http-debug selector: {{- include "sourcegraph.selectorLabels" . | nindent 4 }} app: worker From fa1fd7fbf60fd46f9cad6f363066dc0f6afa20e4 Mon Sep 17 00:00:00 2001 From: Marc LeBlanc Date: Thu, 23 Oct 2025 17:50:48 -0600 Subject: [PATCH 6/6] Adding missing Redis metrics ports --- charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml | 2 +- charts/sourcegraph/templates/redis/redis-cache.Service.yaml | 3 +++ charts/sourcegraph/templates/redis/redis-store.Deployment.yaml | 2 +- charts/sourcegraph/templates/redis/redis-store.Service.yaml | 3 +++ 4 files changed, 8 insertions(+), 2 deletions(-) diff --git a/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml b/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml index 4d6eb515..fc00f487 100644 --- a/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml +++ b/charts/sourcegraph/templates/redis/redis-cache.Deployment.yaml @@ -110,7 +110,7 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - name: redisexp + - name: http-metrics containerPort: 9121 {{- if not .Values.sourcegraph.localDevMode }} resources: diff --git a/charts/sourcegraph/templates/redis/redis-cache.Service.yaml b/charts/sourcegraph/templates/redis/redis-cache.Service.yaml index d8ca9e4f..301034b5 100644 --- a/charts/sourcegraph/templates/redis/redis-cache.Service.yaml +++ b/charts/sourcegraph/templates/redis/redis-cache.Service.yaml @@ -18,6 +18,9 @@ metadata: name: redis-cache spec: ports: + - name: http-metrics + port: 9121 + targetPort: http-metrics - name: redis port: 6379 targetPort: redis diff --git a/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml b/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml index 958f0aeb..d1697741 100644 --- a/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml +++ b/charts/sourcegraph/templates/redis/redis-store.Deployment.yaml @@ -109,7 +109,7 @@ spec: {{- $item | toYaml | nindent 10 }} {{- end }} ports: - - name: redisexp + - name: http-metrics containerPort: 9121 {{- if not .Values.sourcegraph.localDevMode }} resources: diff --git a/charts/sourcegraph/templates/redis/redis-store.Service.yaml b/charts/sourcegraph/templates/redis/redis-store.Service.yaml index db72b306..eef4feea 100644 --- a/charts/sourcegraph/templates/redis/redis-store.Service.yaml +++ b/charts/sourcegraph/templates/redis/redis-store.Service.yaml @@ -18,6 +18,9 @@ metadata: name: redis-store spec: ports: + - name: http-metrics + port: 9121 + targetPort: http-metrics - name: redis port: 6379 targetPort: redis