Skip to content

Commit 1248d79

Browse files
michaellzcclaudeampagentfiliphaftek
authored
redis: vendor redis.conf and auto-size maxmemory from the memory limit (#922)
## Summary Add **opt-in** Redis configuration management and memory sizing. Both Redis images default to `maxmemory 6gb`, which can exceed a smaller pod memory limit and cause OOM kills before eviction runs. `redisCache.config.enabled` and `redisStore.config.enabled` both default to **false**. Default deployments retain their image configs, custom mounts, authentication, and memory settings. All 69 default rendered resources are byte-identical to current `main`. Enable either service independently, or both: ```yaml redisCache: config: enabled: true redisStore: config: enabled: true ``` When enabled, the chart vendors the pinned images' Redis config, renders a ConfigMap, and mounts it at `/etc/redis/redis.conf` using `subPath`. The image entrypoint is unchanged. The chart appends `maxmemory` at `config.maxmemoryRatio` (default 0.75) of the container memory limit, unless `config.maxmemory` is explicitly set. Ratios must be greater than 0 and less than 1. Missing or unrecognised limits, and `sourcegraph.localDevMode`, skip auto-sizing and retain the vendored 6gb default unless explicitly overridden. Other options are `existingConfig`, `maxmemoryPolicy`, and `additionalConfig`. All config options are ignored unless `config.enabled` is true. Chart-managed changes trigger a rollout through a checksum annotation; existing ConfigMaps and Secret-mounted files require a manual restart. ## Before opting in - The chart-managed file replaces image-baked configuration, including custom authentication, ACL, TLS, and persistence settings. Keep management disabled to preserve those settings, or migrate them explicitly before enabling it. - Existing custom config mounts remain valid by default. When opting in, remove conflicting mounts and use `config.existingConfig`, or leave management disabled. Render-time guards explain conflicting mounts and reserved volume names. - `additionalConfig` and `existingConfig` use plaintext ConfigMaps. For credentials, leave management disabled and use a Secret-mounted config. Configure client credentials and `redisExporter.env.REDIS_PASSWORD.valueFrom.secretKeyRef` as appropriate; readiness alone does not verify exporter authentication. - At the default 7Gi pod limit, opting in lowers the Redis cap from 6GiB to 5.25GiB. Cache evicts earlier; store retains `noeviction` and rejects writes sooner when full. An explicit `config.maxmemory: 6gb` restores the old cap if the pod has enough memory. Auto-sizing reduces but does not eliminate OOM risk. - Without opting in, the old 6GiB limit and its OOM risk with smaller pod limits remain unchanged. Leaving management disabled is a no-op for existing deployments that have never enabled it: no new config, mounts, checksum, or Redis pod-template changes. Turning it off after enabling it is different: removing the managed mount and checksum changes the pod template and restarts Redis. Unrelated changes in a chart upgrade can still affect an instance. See [Enabling Redis config management](https://github.com/sourcegraph/deploy-sourcegraph-helm/blob/michaellzc/redis-maxmemory-include-directive/charts/sourcegraph/README.md#enabling-redis-config-management) for configuration and migration guidance. ## Verification Final opt-in revision, after incorporating current `main`: - `scripts/ci/lint.sh`: all four charts pass. - `helm unittest charts/sourcegraph`: 30 suites, 173 tests, and 12 snapshots pass. Tests cover default-off behavior, independent cache/store opt-in, parser cases, ratio validation, local-dev mode, existing ConfigMaps, Secret mounts, collision guards, and checksum/mount wiring. - Default render: all 69 resources are byte-identical to `origin/main`. Enabling both services produces byte-identical manifests to the previously tested enabled implementation. The updated regression tests reject the old enabled-by-default behavior. - No-op compatibility: whole-release renders match `origin/main` byte-for-byte for omitted flags, explicit `false`, existing resource/image/argument/annotation overrides, and existing Secret-backed config mounts. - Disposable kind cluster: default-off, cache-only, store-only, and both-enabled configurations all passed. With cache/store pod limits of 512Mi/256Mi, enabled services reported caps of 402653184/201326592 bytes; disabled services retained 6442450944 bytes. Mounts and checksum annotations appeared only on opted-in services. All eight pods were ready with zero restarts. - Helm docs regenerated; clean worktree and `git diff --check`. Runtime checks performed on the same enabled implementation before changing the defaults: - Cache handled 12,000 writes of 64KiB, evicted 5,394 keys, and had zero restarts. - Changing the ratio rolled both pods to the new caps and preserved store data. - Local-dev mode retained the vendored 6GiB cap. - Secret-backed authentication rejected unauthenticated requests, passed the chart's real readiness probes, and reported `redis_up 1` on both exporters with Secret-backed exporter credentials. These follow-up runtime checks cover Redis, not a fresh full Sourcegraph deployment. The original PR reported a successful full-chart kind deployment; that older result is not a new run of this revision. ## Checklist - [x] Run chart lint, unit tests, render comparison, and Redis runtime checks - [x] Update the changelog - [x] Document opt-in behavior and migration warnings in the chart README - [ ] Update the external Kubernetes update documentation, if required (not changed in this PR) --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Amp <amp@ampcode.com> Co-authored-by: Filip Haftek <filip.haftek@sourcegraph.com>
1 parent 2116c9c commit 1248d79

13 files changed

Lines changed: 948 additions & 0 deletions

‎charts/sourcegraph/CHANGELOG.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ Use `**BREAKING**:` to denote a breaking change
88

99
## Unreleased
1010

11+
- Added opt-in Redis config management through `redisCache.config.enabled` and `redisStore.config.enabled` (both default to `false`). Default deployments retain their image configs, custom mounts, authentication, and memory settings. When enabled, the chart mounts `/etc/redis/redis.conf` and supports `existingConfig`, `maxmemory`, `maxmemoryRatio`, `maxmemoryPolicy`, and `additionalConfig`. See [Enabling Redis config management](README.md#enabling-redis-config-management) before opting in, especially when using custom images or Secret-mounted configs.
12+
- With Redis config management enabled, the chart sizes `maxmemory` at 75% of `resources.limits.memory` to leave room for overhead; this reduces, but does not eliminate, OOM risk. Ratios must be greater than 0 and less than 1. Auto-sizing is skipped in local development mode or when the limit is absent or unrecognised. At the default 7Gi limit, opting in lowers the effective cap from 6GiB to 5.25GiB: `redis-cache` evicts earlier, but `redis-store` uses `noeviction`, so its write-error ceiling drops too. Set `redisStore.config.maxmemory: 6gb` to keep the old ceiling if the pod has sufficient memory.
1113
- Added a `network-policy` example, which limits Executor and Executor job pods to the frontend API
1214
- Corrected the external object storage examples to configure the shared store for frontend, worker, precise code intel, syntactic code intel, gitserver, and searcher, including credentials or workload service accounts as required.
1315
- Removed the unused application ports from the precise and syntactic code intel worker Deployments and Services; health checks and Prometheus metrics continue to use the debug server on port 6060.

‎charts/sourcegraph/README.md‎

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,62 @@
77

88
Visit the [Helm docs](https://docs.sourcegraph.com/admin/install/kubernetes) for guidance on using this chart.
99

10+
## Enabling Redis config management
11+
12+
Redis config management is **disabled by default**. Upgrading the chart preserves
13+
existing image configs, custom mounts, authentication, and memory settings.
14+
The standard images retain their 6GiB cap, which can cause OOM kills if the pod
15+
memory limit is lower. Opt in for either service independently, or both:
16+
17+
```yaml
18+
redisCache:
19+
config:
20+
enabled: true
21+
redisStore:
22+
config:
23+
enabled: true
24+
```
25+
26+
For each enabled service, the chart mounts `/etc/redis/redis.conf` and sizes
27+
`maxmemory` to 75% of the container's memory limit. At the default 7Gi limit,
28+
opting in changes the cap from 6GiB to 5.25GiB. `redis-cache` evicts earlier;
29+
`redis-store` keeps `noeviction` and rejects writes sooner when full. Set
30+
`redisStore.config.maxmemory: 6gb` to retain its old cap, provided the pod has
31+
enough memory for Redis overhead. Auto-sizing reserves headroom but cannot
32+
guarantee against OOM kills, particularly during persistence operations.
33+
34+
Before opting in:
35+
36+
- **Custom images:** the mounted config replaces the image's config, including
37+
any `requirepass`, ACL, TLS, or persistence settings. Leave
38+
`redisCache.config.enabled: false` and/or `redisStore.config.enabled: false`
39+
to preserve the corresponding image config. Otherwise, migrate those settings
40+
explicitly; image-baked authentication is not inherited.
41+
- **Existing config mounts:** either leave config management disabled and
42+
keep your `extraVolumes` / `extraVolumeMounts`, or remove those mounts and set
43+
`config.enabled: true` and `config.existingConfig` to the name of a ConfigMap
44+
with a complete `redis.conf` key. An existing ConfigMap bypasses all chart
45+
sizing and directive overrides.
46+
- **Secrets:** both `additionalConfig` and `existingConfig` use plaintext
47+
ConfigMaps. For a config containing credentials, leave config management disabled
48+
and mount a Secret at `/etc/redis/redis.conf` with `extraVolumeMounts` instead.
49+
Configure the clients' `connection.existingSecret` and the exporter's
50+
`redisExporter.env.REDIS_PASSWORD.valueFrom.secretKeyRef` as appropriate.
51+
Redis readiness alone does not verify exporter authentication; check `redis_up`.
52+
53+
While config management is disabled, all other `config` options are ignored,
54+
including auto-sizing, so you must size Redis memory yourself. With management enabled,
55+
an explicit `config.maxmemory` takes precedence over auto-sizing, and
56+
`additionalConfig` is appended last. Supported memory limits are plain byte
57+
counts or numbers with `k`, `M`, `G`, `T`, `P`, `E`, `Ki`, `Mi`, `Gi`, `Ti`,
58+
`Pi`, or `Ei` suffixes. If the limit is absent or unrecognised, or
59+
`sourcegraph.localDevMode` is enabled, the vendored 6gb default remains unless
60+
overridden explicitly.
61+
62+
Chart-managed config changes restart the Redis pod through a checksum
63+
annotation. Changes to an existing ConfigMap or Secret require a manual pod
64+
restart because `subPath` mounts do not update in running containers.
65+
1066
## Configuration Options
1167

1268
Reference the below chart for all available configuration parameters.
@@ -301,6 +357,12 @@ In addition to the documented values, all services also support the following va
301357
| prometheus.storageAnnotations | object | `{}` | Optional annotations to add to the `prometheus` PVC |
302358
| prometheus.storageSize | string | `"200Gi"` | PVC Storage Request for `prometheus` data volume |
303359
| prometheus.storageSubPath | string | `""` | Optional subPath for the `prometheus` primary data volume mount |
360+
| redisCache.config.additionalConfig | string | `""` | Additional raw redis directives appended to the vendored `redis-cache` config. Notes: This is expecting a multiline string. It renders into a ConfigMap in plaintext, so do not put secrets such as `requirepass` here or in `existingConfig` (also a ConfigMap). For secrets, set `config.enabled: false` and mount a Secret using `extraVolumeMounts`. |
361+
| redisCache.config.enabled | bool | `false` | Opt in to a chart-managed Redis config and automatic memory sizing. Disabled by default to preserve image-baked configuration and custom `extraVolumeMounts` (including Secret mounts). When false, all other `config` options are ignored and auto-sizing is disabled. |
362+
| redisCache.config.existingConfig | string | `""` | Name of an existing ConfigMap for `redis-cache`. It must contain a `redis.conf` key. When set, the chart-managed ConfigMap is not rendered and this one is mounted instead, so the chart no longer sizes `maxmemory`. Mutually exclusive with `additionalConfig`. |
363+
| redisCache.config.maxmemory | string | `""` | Explicit redis `maxmemory` for `redis-cache` (for example `6gb`). Overrides the auto-computed value. Empty means compute it from the container memory limit. |
364+
| redisCache.config.maxmemoryPolicy | string | `""` | Override the redis `maxmemory-policy` for `redis-cache`. Empty keeps the vendored default (`allkeys-lru`). |
365+
| redisCache.config.maxmemoryRatio | float | `0.75` | Fraction of `redisCache.resources.limits.memory` used for `maxmemory` when `maxmemory` is empty. Must be greater than 0 and less than 1. Ignored when no memory limit is set or `sourcegraph.localDevMode` is enabled. An absent or unrecognised limit keeps the vendored 6gb default; use an explicit maxmemory if needed. |
304366
| redisCache.connection.endpoint | string | `"redis-cache:6379"` | Endpoint to use for redis-cache. Supports either host:port or IANA specification |
305367
| redisCache.connection.existingSecret | string | `""` | Name of existing secret to use for Redis endpoint The secret must contain the key `endpoint` and should follow IANA specification learn more from the [Helm docs](https://docs.sourcegraph.com/admin/install/kubernetes/helm#using-external-redis-instances) |
306368
| redisCache.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":999}` | Security context for the `redis-cache` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) |
@@ -320,6 +382,12 @@ In addition to the documented values, all services also support the following va
320382
| redisExporter.image.defaultTag | string | `"6.0.0@sha256:b2ec48fc6adef31f36d525170138dec303c1c0c20c530d659f1fb7c6c54698af"` | Docker image tag for the `redis-exporter` image |
321383
| redisExporter.image.name | string | `"redis_exporter"` | Docker image name for the `redis-exporter` image |
322384
| redisExporter.resources | object | `{"limits":{"cpu":"10m","memory":"100Mi"},"requests":{"cpu":"10m","memory":"100Mi"}}` | Resource requests & limits for the `redis-exporter` sidecar container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) |
385+
| redisStore.config.additionalConfig | string | `""` | Additional raw redis directives appended to the vendored `redis-store` config. Notes: This is expecting a multiline string. It renders into a ConfigMap in plaintext, so do not put secrets such as `requirepass` here or in `existingConfig` (also a ConfigMap). For secrets, set `config.enabled: false` and mount a Secret using `extraVolumeMounts`. |
386+
| redisStore.config.enabled | bool | `false` | Opt in to a chart-managed Redis config and automatic memory sizing. Disabled by default to preserve image-baked configuration and custom `extraVolumeMounts` (including Secret mounts). When false, all other `config` options are ignored and auto-sizing is disabled. |
387+
| redisStore.config.existingConfig | string | `""` | Name of an existing ConfigMap for `redis-store`. It must contain a `redis.conf` key. When set, the chart-managed ConfigMap is not rendered and this one is mounted instead, so the chart no longer sizes `maxmemory`. Mutually exclusive with `additionalConfig`. |
388+
| redisStore.config.maxmemory | string | `""` | Explicit redis `maxmemory` for `redis-store` (for example `6gb`). Overrides the auto-computed value. Empty means compute it from the container memory limit. |
389+
| redisStore.config.maxmemoryPolicy | string | `""` | Override the redis `maxmemory-policy` for `redis-store`. Empty keeps the vendored default (`noeviction`). |
390+
| redisStore.config.maxmemoryRatio | float | `0.75` | Fraction of `redisStore.resources.limits.memory` used for `maxmemory` when `maxmemory` is empty. Must be greater than 0 and less than 1. Ignored when no memory limit is set or `sourcegraph.localDevMode` is enabled. An absent or unrecognised limit keeps the vendored 6gb default; use an explicit maxmemory if needed. |
323391
| redisStore.connection.endpoint | string | `"redis-store:6379"` | Endpoint to use for redis-store. Supports either host:port or IANA specification |
324392
| redisStore.connection.existingSecret | string | `""` | Name of existing secret to use for Redis endpoint The secret must contain the key `endpoint` and should follow IANA specification learn more from the [Helm docs](https://docs.sourcegraph.com/admin/install/kubernetes/helm#using-external-redis-instances) |
325393
| redisStore.containerSecurityContext | object | `{"allowPrivilegeEscalation":false,"readOnlyRootFilesystem":true,"runAsGroup":1000,"runAsUser":999}` | Security context for the `redis-store` container, learn more from the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container) |

‎charts/sourcegraph/README.md.gotmpl‎

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,62 @@
77

88
Visit the [Helm docs](https://docs.sourcegraph.com/admin/install/kubernetes) for guidance on using this chart.
99

10+
## Enabling Redis config management
11+
12+
Redis config management is **disabled by default**. Upgrading the chart preserves
13+
existing image configs, custom mounts, authentication, and memory settings.
14+
The standard images retain their 6GiB cap, which can cause OOM kills if the pod
15+
memory limit is lower. Opt in for either service independently, or both:
16+
17+
```yaml
18+
redisCache:
19+
config:
20+
enabled: true
21+
redisStore:
22+
config:
23+
enabled: true
24+
```
25+
26+
For each enabled service, the chart mounts `/etc/redis/redis.conf` and sizes
27+
`maxmemory` to 75% of the container's memory limit. At the default 7Gi limit,
28+
opting in changes the cap from 6GiB to 5.25GiB. `redis-cache` evicts earlier;
29+
`redis-store` keeps `noeviction` and rejects writes sooner when full. Set
30+
`redisStore.config.maxmemory: 6gb` to retain its old cap, provided the pod has
31+
enough memory for Redis overhead. Auto-sizing reserves headroom but cannot
32+
guarantee against OOM kills, particularly during persistence operations.
33+
34+
Before opting in:
35+
36+
- **Custom images:** the mounted config replaces the image's config, including
37+
any `requirepass`, ACL, TLS, or persistence settings. Leave
38+
`redisCache.config.enabled: false` and/or `redisStore.config.enabled: false`
39+
to preserve the corresponding image config. Otherwise, migrate those settings
40+
explicitly; image-baked authentication is not inherited.
41+
- **Existing config mounts:** either leave config management disabled and
42+
keep your `extraVolumes` / `extraVolumeMounts`, or remove those mounts and set
43+
`config.enabled: true` and `config.existingConfig` to the name of a ConfigMap
44+
with a complete `redis.conf` key. An existing ConfigMap bypasses all chart
45+
sizing and directive overrides.
46+
- **Secrets:** both `additionalConfig` and `existingConfig` use plaintext
47+
ConfigMaps. For a config containing credentials, leave config management disabled
48+
and mount a Secret at `/etc/redis/redis.conf` with `extraVolumeMounts` instead.
49+
Configure the clients' `connection.existingSecret` and the exporter's
50+
`redisExporter.env.REDIS_PASSWORD.valueFrom.secretKeyRef` as appropriate.
51+
Redis readiness alone does not verify exporter authentication; check `redis_up`.
52+
53+
While config management is disabled, all other `config` options are ignored,
54+
including auto-sizing, so you must size Redis memory yourself. With management enabled,
55+
an explicit `config.maxmemory` takes precedence over auto-sizing, and
56+
`additionalConfig` is appended last. Supported memory limits are plain byte
57+
counts or numbers with `k`, `M`, `G`, `T`, `P`, `E`, `Ki`, `Mi`, `Gi`, `Ti`,
58+
`Pi`, or `Ei` suffixes. If the limit is absent or unrecognised, or
59+
`sourcegraph.localDevMode` is enabled, the vendored 6gb default remains unless
60+
overridden explicitly.
61+
62+
Chart-managed config changes restart the Redis pod through a checksum
63+
annotation. Changes to an existing ConfigMap or Secret require a manual pod
64+
restart because `subPath` mounts do not update in running containers.
65+
1066
## Configuration Options
1167

1268
Reference the below chart for all available configuration parameters.
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Vendored from the `redis-cache` image (`/etc/redis/redis.conf`).
2+
# Source: sourcegraph/sourcegraph docker-images/redis-cache/redis.conf
3+
# Seeded from image tag 6.0.0. Keep this file in sync when the image tag changes.
4+
#
5+
# The chart mounts this file over /etc/redis/redis.conf, so the image entrypoint
6+
# (`redis-server /etc/redis/redis.conf`) reads it. The chart appends the computed
7+
# `maxmemory` and any `redisCache.config` overrides after this body.
8+
9+
# allow access from all instances
10+
protected-mode no
11+
# limit memory usage, discard unused keys when hitting limit
12+
maxmemory 6gb
13+
maxmemory-policy allkeys-lru
14+
# snapshots on disk every minute
15+
dir /redis-data/
16+
appendonly no
17+
save 60 1
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
# Vendored from the `redis-store` image (`/etc/redis/redis.conf`).
2+
# Source: sourcegraph/sourcegraph docker-images/redis-store/redis.conf
3+
# Seeded from image tag 6.0.0. Keep this file in sync when the image tag changes.
4+
#
5+
# The chart mounts this file over /etc/redis/redis.conf, so the image entrypoint
6+
# (`redis-server /etc/redis/redis.conf`) reads it. The chart appends the computed
7+
# `maxmemory` and any `redisStore.config` overrides after this body.
8+
9+
# allow access from all instances
10+
protected-mode no
11+
# limit memory usage, return error when hitting limit
12+
maxmemory 6gb
13+
maxmemory-policy noeviction
14+
# live commit log to disk, additionally snapshot every 5 minutes
15+
dir /redis-data/
16+
appendonly yes
17+
aof-use-rdb-preamble yes
18+
save 300 1

‎charts/sourcegraph/templates/_helpers.tpl‎

Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -312,3 +312,66 @@ checksum/auth: {{ toJson $checksum | sha256sum }}
312312
{{- $checksum := append $checksum .Values.redisCache.connection -}}
313313
checksum/redis: {{ toJson $checksum | sha256sum }}
314314
{{- end -}}
315+
316+
{{/*
317+
Resolve the redis `maxmemory` directive for a service.
318+
Usage: include "sourcegraph.redis.maxmemory" (list . "redisCache")
319+
320+
Resolution order:
321+
1. <service>.config.maxmemory, used verbatim.
322+
2. floor(<service>.config.maxmemoryRatio * <service>.resources.limits.memory),
323+
rendered as a plain byte count, unless localDevMode removes the limit.
324+
3. Empty string, when there is no memory limit or the quantity is not
325+
recognised. The caller then emits no `maxmemory` and the vendored default
326+
stands.
327+
*/}}
328+
{{- define "sourcegraph.redis.maxmemory" -}}
329+
{{- $top := index . 0 -}}
330+
{{- $service := index . 1 -}}
331+
{{- $values := index $top.Values $service -}}
332+
{{- $config := $values.config | default dict -}}
333+
{{- if $config.maxmemory -}}
334+
{{- $config.maxmemory -}}
335+
{{- else if not $top.Values.sourcegraph.localDevMode -}}
336+
{{- $limit := dig "resources" "limits" "memory" "" $values | toString -}}
337+
{{- $number := regexReplaceAll "^([0-9]+(\\.[0-9]+)?).*$" $limit "${1}" -}}
338+
{{- $suffix := regexReplaceAll "^[0-9]+(\\.[0-9]+)?" $limit "" -}}
339+
{{- /* Kubernetes quantity suffixes: binary (1024^n) and decimal (1000^n). */ -}}
340+
{{- $units := dict "" 1.0 "k" 1e3 "M" 1e6 "G" 1e9 "T" 1e12 "P" 1e15 "E" 1e18 "Ki" 1024.0 "Mi" 1048576.0 "Gi" 1073741824.0 "Ti" 1099511627776.0 "Pi" 1125899906842624.0 "Ei" 1152921504606846976.0 -}}
341+
{{- if and (regexMatch "^[0-9]+(\\.[0-9]+)?$" $number) (hasKey $units $suffix) -}}
342+
{{- $ratio := 0.75 -}}
343+
{{- if hasKey $config "maxmemoryRatio" -}}
344+
{{- $ratio = float64 $config.maxmemoryRatio -}}
345+
{{- end -}}
346+
{{- if not (and (gt $ratio 0.0) (lt $ratio 1.0)) -}}
347+
{{- fail (printf "%s.config.maxmemoryRatio must be greater than 0 and less than 1" $service) -}}
348+
{{- end -}}
349+
{{- $bytes := floor (mulf (float64 $number) (index $units $suffix) $ratio) -}}
350+
{{- if gt $bytes 0.0 -}}
351+
{{- printf "%d" (int64 $bytes) -}}
352+
{{- end -}}
353+
{{- end -}}
354+
{{- end -}}
355+
{{- end -}}
356+
357+
{{/*
358+
Fail the render when a service's extra volumes or volume mounts collide with the
359+
chart-managed redis config mount. Without this the collision only surfaces as an
360+
opaque "must be unique" rejection from the API server.
361+
Usage: include "sourcegraph.redis.assertNoConfClash" (list . "redisCache")
362+
*/}}
363+
{{- define "sourcegraph.redis.assertNoConfClash" -}}
364+
{{- $top := index . 0 -}}
365+
{{- $service := index . 1 -}}
366+
{{- $values := index $top.Values $service -}}
367+
{{- range ($values.extraVolumeMounts | default list) -}}
368+
{{- if has .mountPath (list "/etc/redis/redis.conf" "/etc/redis" "/etc/redis/") -}}
369+
{{- fail (printf "%s.extraVolumeMounts must not mount over /etc/redis/redis.conf; the chart now manages that file. Move your custom redis config to %s.config.existingConfig or %s.config.additionalConfig, or set %s.config.enabled=false to preserve your existing mount." $service $service $service $service) -}}
370+
{{- end -}}
371+
{{- end -}}
372+
{{- range (concat ($values.extraVolumes | default list) ($values.extraVolumeMounts | default list)) -}}
373+
{{- if eq (.name | toString) "redis-conf" -}}
374+
{{- fail (printf "%s must not define a volume named 'redis-conf'; the chart reserves that name for the redis config mount." $service) -}}
375+
{{- end -}}
376+
{{- end -}}
377+
{{- end -}}

0 commit comments

Comments
 (0)