From feec8c1e60e90aeda56db7d2aaf836be5d9ea66a Mon Sep 17 00:00:00 2001 From: Josh Date: Sat, 6 Jun 2026 06:35:51 +0330 Subject: [PATCH] Fix chart image pulls for kloud-csi installs. Use a valid livenessprobe tag, default the driver image to appVersion, add imagePullSecrets support, and publish GHCR packages as public after CI builds. Co-authored-by: Cursor --- .github/workflows/build.yaml | 10 ++++++++++ .github/workflows/release-chart.yaml | 7 +++++++ README.md | 3 ++- charts/kloud-csi/Chart.yaml | 2 +- charts/kloud-csi/templates/controller-deployment.yaml | 4 ++++ charts/kloud-csi/templates/node-daemonset.yaml | 4 ++++ charts/kloud-csi/values.yaml | 8 +++++--- 7 files changed, 33 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 8cc7580..d067f40 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -21,6 +21,7 @@ jobs: - name: Container image name (GHCR is lowercase) run: | echo "IMAGE_NAME=${REGISTRY_HOST}/$(echo "${GITHUB_REPOSITORY}" | tr '[:upper:]' '[:lower:]')" >> "$GITHUB_ENV" + echo "APP_VERSION=$(grep '^appVersion:' charts/kloud-csi/Chart.yaml | awk '{print $2}' | tr -d '\"')" >> "$GITHUB_ENV" - uses: docker/setup-buildx-action@v3 @@ -38,6 +39,7 @@ jobs: with: images: ${{ env.IMAGE_NAME }} tags: | + type=raw,value=${{ env.APP_VERSION }},enable=${{ github.ref == 'refs/heads/main' }} type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }} type=sha,prefix=sha- type=semver,pattern={{version}} @@ -51,3 +53,11 @@ jobs: labels: ${{ steps.meta.outputs.labels }} cache-from: type=gha cache-to: type=gha,mode=max + + - name: Make container image public + if: github.event_name != 'pull_request' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + owner=$(echo "${GITHUB_REPOSITORY_OWNER}" | tr '[:upper:]' '[:lower:]') + gh api --method PATCH "/orgs/${owner}/packages/container/kks-csi-plugin/visibility" -f visibility=public diff --git a/.github/workflows/release-chart.yaml b/.github/workflows/release-chart.yaml index 93cd6fc..4771559 100644 --- a/.github/workflows/release-chart.yaml +++ b/.github/workflows/release-chart.yaml @@ -58,3 +58,10 @@ jobs: for chart in "${charts[@]}"; do helm push "$chart" "oci://ghcr.io/${owner}/charts" done + + - name: Make OCI chart public + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + owner=$(echo "${GITHUB_REPOSITORY_OWNER}" | tr '[:upper:]' '[:lower:]') + gh api --method PATCH "/orgs/${owner}/packages/container/charts%2Fkloud-csi/visibility" -f visibility=public || true diff --git a/README.md b/README.md index 0087230..85fac22 100644 --- a/README.md +++ b/README.md @@ -139,7 +139,8 @@ Helm fails at render time if `serverURL` or credentials are missing. | Value | Default | Description | |-------|---------|-------------| | `image.repository` | `ghcr.io/KubelanCloud/kks-csi-plugin` | Driver container image | -| `image.tag` | `latest` | Image tag (defaults to chart `appVersion` if empty) | +| `image.tag` | *(chart appVersion)* | Image tag (defaults to chart `appVersion` when empty) | +| `imagePullSecrets` | `[]` | Pull secrets for private registries such as GHCR | | `existingSecret` | `""` | Use an existing secret instead of creating one | | `existingSecretAccessTokenKey` | `access-token` | Key in the secret holding the token | | `driver.name` | `storage.csi.kloud.team` | CSI driver name | diff --git a/charts/kloud-csi/Chart.yaml b/charts/kloud-csi/Chart.yaml index 10902a7..aa80dfa 100644 --- a/charts/kloud-csi/Chart.yaml +++ b/charts/kloud-csi/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: kloud-csi description: Kloud CSI driver for kks persistent volumes type: application -version: 0.1.0 +version: 0.1.1 appVersion: "0.1.0" kubeVersion: ">=1.28.0-0" home: https://github.com/KubelanCloud/kks-csi-plugin diff --git a/charts/kloud-csi/templates/controller-deployment.yaml b/charts/kloud-csi/templates/controller-deployment.yaml index 3269881..42629e8 100644 --- a/charts/kloud-csi/templates/controller-deployment.yaml +++ b/charts/kloud-csi/templates/controller-deployment.yaml @@ -27,6 +27,10 @@ spec: {{- end }} spec: serviceAccountName: {{ include "kloud-csi.controllerServiceAccountName" . }} + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} {{- with .Values.nodeSelector }} nodeSelector: {{- toYaml . | nindent 8 }} diff --git a/charts/kloud-csi/templates/node-daemonset.yaml b/charts/kloud-csi/templates/node-daemonset.yaml index defe5e2..3547633 100644 --- a/charts/kloud-csi/templates/node-daemonset.yaml +++ b/charts/kloud-csi/templates/node-daemonset.yaml @@ -26,6 +26,10 @@ spec: {{- end }} spec: serviceAccountName: {{ include "kloud-csi.nodeServiceAccountName" . }} + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} priorityClassName: {{ .Values.node.priorityClassName }} hostNetwork: true hostPID: true diff --git a/charts/kloud-csi/values.yaml b/charts/kloud-csi/values.yaml index a6e3efe..12b6226 100644 --- a/charts/kloud-csi/values.yaml +++ b/charts/kloud-csi/values.yaml @@ -14,10 +14,12 @@ nameOverride: "" fullnameOverride: "" image: - repository: ghcr.io/KubelanCloud/kks-csi-plugin - tag: "latest" + repository: ghcr.io/kubelancloud/kks-csi-plugin + tag: "" pullPolicy: IfNotPresent +imagePullSecrets: [] + serverURL: "" accessToken: "" existingSecret: "" @@ -38,7 +40,7 @@ sidecars: tag: v2.12.0 livenessProbe: repository: registry.k8s.io/sig-storage/livenessprobe - tag: v2.13.0 + tag: v2.13.1 storageClass: enabled: true