Skip to content

Add Helm chart for Kubernetes deployment - #667

Merged
stefanbenten merged 4 commits into
dutchcoders:mainfrom
Adri3nParra:main
Sep 24, 2026
Merged

stefanbenten merged 4 commits into
dutchcoders:mainfrom
Adri3nParra:main

Conversation

@Adri3nParra

Copy link
Copy Markdown
Contributor

Hello, I built this for my work since the project only offers Docker-based deployment today with no official Helm chart.

The chart supports all 4 storage providers (local, S3/S3-compatible, Storj, Google Drive) and comes with secure defaults (non-root, read-only filesystem, capabilities dropped). Ingress, Gateway API, HPA, NetworkPolicy, HTTP auth, and ClamAV integration are all optional and independently configurable.

  • Local storage with PVC: tested, working
  • S3 with MinIO: tested, working
  • Storj: not tested — no access to a Storj account
  • Google Drive: not tested — requires OAuth credentials I don't have available

Help testing Storj and Google Drive would be welcome.

@francescayeye

Copy link
Copy Markdown
Collaborator

hello @Adri3nParra

thank you very much for the contribution: unfortunately I've no possibility to test your helm chart or maintain it, on top of reviewing your PR.
I won't be able to merge your PR for this reason, since I don't want to end up in the same situation as with the PR for the NIX Flake (#424).

:(

@stefanbenten

Copy link
Copy Markdown
Collaborator

@paolafrancesca I am happy to maintain and test this over the weekend 👍

@Adri3nParra

Copy link
Copy Markdown
Contributor Author

If you encounter any issues during your tests, don’t hesitate to let me know, I can also take a look on my side to help you.

@stefanbenten stefanbenten left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delayed review @Adri3nParra !
Some smaller security suggestions, otherwise looks sane to me!

Comment thread k8s/transfer.sh/templates/configmap.yaml Outdated
Comment thread k8s/transfer.sh/templates/configmap.yaml Outdated
Comment thread k8s/transfer.sh/templates/configmap.yaml Outdated
Comment thread k8s/transfer.sh/templates/deployment.yaml Outdated
Comment thread k8s/transfer.sh/values.yaml Outdated
Comment thread k8s/transfer.sh/values.yaml Outdated
Comment thread k8s/transfer.sh/values.yaml
@Adri3nParra

Copy link
Copy Markdown
Contributor Author

Hello !

I addresses each comment, to sum main fix :

  • S3, Storj and HTTP auth credentials set as plain values go to a chart-managed Secret, and the Deployment reads them through secretKeyRef
  • fullnameOverride defaults to ""
  • gdrive: basedir holds the Drive folder name, and the data volume sits at localConfigPath so transfer.sh can write there

Minor change :

  • Optional gdrive.tokenFromSecret to mount token.json from the Secret and skip the interactive OAuth flow
  • checksum/config and checksum/secret pod annotations, so config and credential changes roll the pods
  • The chart refuses to render when httpAuth.enabled has no usable credentials, because the server turns auth off in that case
  • tcpSocket liveness/readiness probes: the IP filter covers probe requests too, and kubelet got a 403 from the node IP whenever security.ipWhitelist was set

All is validated with lint and template command from helm on local

@stefanbenten

Copy link
Copy Markdown
Collaborator

@Adri3nParra All your commits are unverified/unsigned. Could you kindly check them?

@Adri3nParra

Copy link
Copy Markdown
Contributor Author

Done, all commits are signed now. Bit of insomnia, it's 4am here :)

@stefanbenten stefanbenten left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the PR and effort! @Adri3nParra

@stefanbenten
stefanbenten merged commit 415fddd into dutchcoders:main Sep 24, 2026
6 checks passed
@Adri3nParra

Copy link
Copy Markdown
Contributor Author

Thanks for merging @stefanbenten

Would you be interested in a follow-up PR that publishes the chart to GHCR on each GitHub release ?
On your side it would mean making the package public after the first run, and cutting a release to ship it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants