{{- if .Values.enterprise.enabled }} apiVersion: apps/v1 kind: Deployment metadata: name: {{ .Release.Name }}-enterprise-auth labels: {{- include "sentry.labels" . | nindent 4 }} {{- include "sentry.selectorLabels" (list $ "enterprise-auth") | nindent 4 }} spec: replicas: {{ .Values.enterprise.replicas }} selector: matchLabels: {{- include "sentry.selectorLabels" (list $ "enterprise-auth") | nindent 6 }} template: metadata: labels: {{- include "sentry.selectorLabels" (list $ "enterprise-auth") | nindent 8 }} spec: initContainers: {{- include "sentry.waitForTCP" (list "postgres" (printf "%s-postgres" .Release.Name) "5432") | nindent 8 }} containers: - name: enterprise-auth image: "{{ .Values.enterprise.image.repository }}:{{ .Values.enterprise.image.tag }}" imagePullPolicy: {{ .Values.global.imagePullPolicy }} env: - name: ENTERPRISE_SESSION_SIGNING_KEY valueFrom: secretKeyRef: name: {{ .Release.Name }}-enterprise-auth key: sessionSigningKey - name: POSTGRES_ADDR value: "{{ .Release.Name }}-postgres:5432" - name: POSTGRES_DATABASE value: sentry_metadata - name: POSTGRES_USERNAME value: sentry - name: POSTGRES_PASSWORD valueFrom: secretKeyRef: name: {{ .Release.Name }}-postgres key: password {{- if .Values.enterprise.oidc.issuerURL }} - name: OIDC_ISSUER_URL value: {{ .Values.enterprise.oidc.issuerURL | quote }} - name: OIDC_CLIENT_ID value: {{ .Values.enterprise.oidc.clientID | quote }} - name: OIDC_CLIENT_SECRET valueFrom: secretKeyRef: name: {{ .Release.Name }}-enterprise-auth key: oidcClientSecret - name: OIDC_REDIRECT_URL value: {{ .Values.enterprise.oidc.redirectURL | quote }} {{- end }} {{- if .Values.enterprise.saml.idpMetadataURL }} - name: SAML_ENTITY_ID value: {{ .Values.enterprise.saml.entityID | quote }} - name: SAML_ACS_URL value: {{ .Values.enterprise.saml.acsURL | quote }} - name: SAML_IDP_METADATA_URL value: {{ .Values.enterprise.saml.idpMetadataURL | quote }} {{- end }} ports: - name: http containerPort: 8082 readinessProbe: exec: command: ["/enterprise-auth", "-healthcheck"] initialDelaySeconds: 5 periodSeconds: 5 resources: {{- toYaml .Values.enterprise.resources | nindent 12 }} --- apiVersion: v1 kind: Service metadata: name: {{ .Release.Name }}-enterprise-auth labels: {{- include "sentry.labels" . | nindent 4 }} {{- include "sentry.selectorLabels" (list $ "enterprise-auth") | nindent 4 }} spec: selector: {{- include "sentry.selectorLabels" (list $ "enterprise-auth") | nindent 4 }} ports: - name: http port: 8082 {{- end }}