Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion charts/gitclaw/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: >
GitClaw — agent-first self-hosted Git service (Gitea fork, MIT).
Minimal single-pod chart for bp-001 Ops Foundation smoke.
type: application
version: 0.1.0
version: 0.1.4
appVersion: "1.22.0"
maintainers:
- name: Scalytics Platform Team
Expand Down
4 changes: 4 additions & 0 deletions charts/gitclaw/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,10 @@ spec:
- name: gitclaw
image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
{{- with .Values.containerSecurityContext }}
securityContext:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- { name: http, containerPort: 3000 }
- { name: ssh, containerPort: 2222 }
Expand Down
28 changes: 28 additions & 0 deletions charts/gitclaw/templates/pvc.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
{{- if .Values.persistence.enabled }}
# pvc.yaml — PLAN-01 P27 + iter-6 PR re-add.
#
# The deployment.yaml mounts /data at .Values.persistence.enabled
# but ships no PVC manifest of its own. Without this template the
# chart references a PVC that nothing creates, the pod stays
# Pending with "persistentvolumeclaim not found", and helm upgrade
# times out waiting for the pod to become Ready.
#
# Re-added on iter-6/E-03-E-04-combined to keep `helm install
# gitclaw` self-contained.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: {{ include "gitclaw.fullname" . }}-data
namespace: {{ .Release.Namespace }}
labels:
{{- include "gitclaw.labels" . | nindent 4 }}
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: {{ .Values.persistence.size | quote }}
{{- if .Values.persistence.storageClass }}
storageClassName: {{ .Values.persistence.storageClass | quote }}
{{- end }}
{{- end }}
30 changes: 28 additions & 2 deletions charts/gitclaw/values.yaml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
image:
repository: ghcr.io/kafclaw/gitclaw
tag: latest
# Local-only / NAS-pinned (PLAN-06 E-03 / audit F-1). Iter-8 flips
# to ghcr.io. No v-semver tag on NAS yet; pinning to the latest RC.
repository: 192.168.0.131:5100/scalytics/gitclaw
tag: "2026.05-rc1"
pullPolicy: IfNotPresent

service:
Expand Down Expand Up @@ -36,11 +38,35 @@ probes:
initialDelaySeconds: 10
periodSeconds: 10

# Pod security (PLAN-06 E-04 / audit F-4).
#
# DOCUMENTED EXCEPTION TO PSA-RESTRICTED. GitClaw wraps the upstream
# Gitea image, which uses s6-svscan to manage child processes. s6
# requires its supervisor to start as UID 0 to open the directory at
# /etc/s6/.s6-svscan/lock; it then drops to UID 1000 via s6-setuidgid
# for the actual gitea process. Pinning runAsUser at the chart level
# breaks the init sequence with `unable to open .s6-svscan/lock:
# Permission denied` (PLAN-01 P27, observed 2026-05-19).
#
# Consequence: GitClaw cannot be deployed into a namespace labelled
# `pod-security.kubernetes.io/enforce: restricted`. Operators who
# need PSA-restricted compliance must either:
# (a) deploy GitClaw into a separate namespace at PSA `baseline`,
# (b) replace the Gitea image with a non-s6 variant, or
# (c) disable the chart (gitclaw.enabled: false).
#
# fsGroup chowns the data volume to gid 1000 (the `git` user inside
# the Gitea image) so the PVC mount is writable by the dropped UID.
podSecurityContext:
fsGroup: 1000
runAsUser: 1000
runAsGroup: 1000

# Container-level: explicit empty block so consumers can override.
# The main gitclaw container starts as root (s6 requirement) and drops
# inside the image. capabilities.drop ALL would block s6-setuidgid.
containerSecurityContext: {}

serviceAccount:
create: true
name: ""
Expand Down
Loading