feat(supabase): add services and statefulset for database management
feat(synapse): update ingress to use traefik ingress class and bump version feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration fix(taiga): update liveness and readiness probes to use tcpSocket for health checks fix(taiga): change PVC access mode to ReadWriteMany for media and static storage feat(traefik): add icon and ignore rules for traefik service docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments feat(ushahidi): implement dedicated Redis deployment for Ushahidi fix(vllm): update deployment strategy and readiness/liveness probes for improved stability fix(writefreely): pin writefreely image version to v0.15.1 for consistency docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
This commit is contained in:
25
cryptpad/notes.md
Normal file
25
cryptpad/notes.md
Normal file
@@ -0,0 +1,25 @@
|
||||
# CryptPad — Notes
|
||||
|
||||
## Config directory requires emptyDir + initContainer
|
||||
|
||||
CryptPad's `/cryptpad/config/` directory is in the image overlay filesystem and is not writable
|
||||
by the container process even when running as root.
|
||||
|
||||
**Fix**: mount an `emptyDir` at `/cryptpad/config` and use an initContainer to pre-seed
|
||||
`config.example.js` from the image into the emptyDir:
|
||||
|
||||
```yaml
|
||||
initContainers:
|
||||
- name: seed-config
|
||||
image: cryptpad/cryptpad:version-X.Y.Z
|
||||
command: [sh, -c, "cp /cryptpad/config/config.example.js /config-dest/config.example.js"]
|
||||
volumeMounts:
|
||||
- name: cryptpad-config
|
||||
mountPath: /config-dest
|
||||
volumes:
|
||||
- name: cryptpad-config
|
||||
emptyDir: {}
|
||||
```
|
||||
|
||||
Set `CPAD_CONF=/cryptpad/config/config.js` — the startup script copies `config.example.js` to
|
||||
`config.js` on first run if `config.js` doesn't exist.
|
||||
@@ -22,7 +22,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
initContainers:
|
||||
- name: seed-config
|
||||
image: cryptpad/cryptpad:latest
|
||||
image: cryptpad/cryptpad:version-2026.5.1
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
@@ -33,9 +33,18 @@ spec:
|
||||
volumeMounts:
|
||||
- name: cryptpad-config
|
||||
mountPath: /config-dest
|
||||
securityContext:
|
||||
runAsNonRoot: false
|
||||
runAsUser: 0
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop: [ALL]
|
||||
readOnlyRootFilesystem: false
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: cryptpad
|
||||
image: cryptpad/cryptpad:latest
|
||||
image: cryptpad/cryptpad:version-2026.5.1
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: 3000
|
||||
@@ -80,7 +89,14 @@ spec:
|
||||
periodSeconds: 10
|
||||
failureThreshold: 3
|
||||
securityContext:
|
||||
runAsNonRoot: false
|
||||
runAsUser: 0
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop: [ALL]
|
||||
readOnlyRootFilesystem: false
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
volumes:
|
||||
- name: cryptpad-data
|
||||
persistentVolumeClaim:
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
version: 2024.x-1
|
||||
version: 2026.5.1-2
|
||||
defaultConfig:
|
||||
namespace: cryptpad
|
||||
externalDnsDomain: '{{ .cloud.domain }}'
|
||||
|
||||
Reference in New Issue
Block a user